It seems that more and more Anti-Virus and other security related business solutions are adding the 'AI' and 'machine learning' buzzwords to their marketing repertoire. However, the only 'AI' I ever saw working was the RITA project, which is available for free.
I was wondering if there really are useful applications to the machine learning that can help detect an intrusion on a network, because it seems that currently, most detection engines are still based on a blacklist of IOC (Indicators of Compromise). If there are popular ways of using AI & machine learning right now, could someone give an example of the detection process?