Using AI to Prevent Cyberattacks and Fill the Skills Gap episode artwork

EPISODE · Aug 11, 2023

Using AI to Prevent Cyberattacks and Fill the Skills Gap

from Info Risk Today Podcast · host InfoRiskToday.com

In this episode of CyberEd.io's podcast series "Cybersecurity Insights," Aaron Cockerill of Lookout discussed the benefits and concerns associated with generative AI and how to solve challenges related to zero-day attacks, misconfigurations, the cyber skills gap and privacy.

Episode metadata supplied by the publisher feed · Published Aug 11, 2023

Embed this episode

NOW PLAYING

Using AI to Prevent Cyberattacks and Fill the Skills Gap

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Welcome to Cybersecurity Insights, the podcast for the CyberEd.io learning community. Our goal is to bring Cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern Cybersecurity world. Good day, everyone. This is Steve King.

I'm the Managing Director at CyberEd.io. In today's podcast, we have the pleasure of Aaron Cockrell's company. He's the Chief Strategy Officer for Lookout. Over the last few years, Lookout has invested itself of its consumer business and is now a thriving cloud native company focused on delivering converged SASE and secured service edge to the enterprise.

Aaron has been with Lookout for over eight years joining them from Citrix, where for 12 years he ran a 80-person mobile engineering team and built some patented product and held various roles in product management and then Akamai before that and where he led product management and grid computing and earned his master's degree from Stanford and undergraduate degree in engineering from the University of Oregon. So welcome Aaron. Thanks for joining us today. Well, thanks very much.

Great to be here. Great. So let's start with Zero Days. They're bad and getting worse.

How do we stop them? I don't think we're going to stop Zero Days. Zero Days are where we make mistakes as sort of others. But I think that trying to solve them is going to be less of a problem, to be honest.

If you look at where people are placing their applications and data, it's increasingly in environments that are managed by other people and men. So let's use software as a service, for example. And so if you're moving your human resources or CRM infrastructure from on-prem windows machines or whatever to cloud-based infrastructure that's managed by someone else, I think Zero Days in that scenario become less of a problem as the initial threat vector for an attack. And why would that be?

Well, because the people that are hosting this SASE infrastructure are focused on at least maintaining that infrastructure and defending it. So they'll run multiple different versions of servers in order to ensure that that infrastructure can't be attacked with one particular Zero Day. They'll run isolation environments to ensure that Zero Day doesn't allow the bad actors to escape, move laterally into different places. I mean, their whole livelihood is reliant on that infrastructure being secure.

I think it's more likely that we'll see attacks take a change, at least in their initial attack vector. Yeah, so it's curious. So, you know, if I look at what move it in that recent attack, which I think is now we're up to 160, 170 customers that have been affected or that have acknowledged that they're affected, that in many people's minds was a Zero Day attack, though it's exactly the same attack that SolarWinds had before it. I'm curious as to why you think that we can't do a better job of protecting against the inevitable here.

Whenever you've got a third-party product like that with a broad install base, wouldn't you think that you would be a likely target going forward? Yes, but there are, say for example, there are technologies that you could use that are available today to, for example, avoid move it being direct internet facing. That would have been an approach, for example, that let's say move it had been a software service instead of something that was deployed individually. It's likely that the software as a service organization would design infrastructure so that the apps that were internet facing or the aspect of move it was internet facing was more to be able to attack the surface area for attack was narrower, was better understood, and so it would be less likely that that Zero attack, Zero Day, would be something that a bad actor could exploit.

I mean, the more we move from having, I don't know, you know, server infrastructure in a blue room closet that Bob has to update, you know, every now and again, when he remembers to leveraging cloud infrastructure that is managed by other people, I think the more we will see, Zero Days become less of a problem. Yeah, you know, you said some magic words there, you know, that's managed by other people. I'm not sure, you know, we look at, we see attacks all the time on AWS servers, which were poorly configured to start with, for example, I mean, that guy whose responsibility was that, is that Cap One's responsibility, is that the healthcare guy's responsibility, or is that an Amazon responsibility at the end of the day? Yep, and that's, I mean, I think that it will be things like misconfiguration and accounting personation that results in the majority of breaches moving forward.

That would be good. I just, you know, there's so many opportunities. Seems to me that the human factor here is always the biggest problem. And I don't mean that in close shade way, you know, related to fishing, for example, attacks.

But we talk about the, you know, the anatomy of the modern database. We see that, you know, many of these things have nothing to do with malware. They're sort of, you know, living off the land or just enabling direct access to data. Exactly.

And so we're in complete agreement on that one. Like the human factor is not going to go away. And in fact, it's going to be, in my mind, the increasingly easier aspect to employ, to exploit for a bad actor. A great example is the most recent or fairly recent breaches.

I think a group I'd be referring to is Octopus. Crowded traffic referring to a discarded spider. But it involves specifically targeted phishing attacks against people that have access to large data sets. And then using essentially stolen credentials, accounting personation to steal all the data.

There's zero malware involved in that attack. I think that that, you know, we can discuss about it. I think that that's a far more likely anatomy of a modern database. Yeah.

Yeah, absolutely. What beyond, you know, so we all know that chat GPT is going to have a significant impact on phishing, right? But I mean, you know, so all of the reasons why we could discover those things sort of prima facie in the past kind of disappear now that we have, you know, whatever you want to call it, sophisticated English language versions of these messages and so forth. And then, you know, they're part of a, you know, larger social engineering campaign as well.

But there are other threats to, you know, GAI, right? And what do you guys worry about in that regard? I mean, not from using generative AI as a tool to, you know, get access to either credentials or pure, you know, the actual data, but rather as an emerging native threat all by itself. I think that, so generative AI in terms of a tool for bad actors, I think the main focus right now is the one that you talked about improving social engineering attacks and improving phishing messages, especially for non-English speaking bad actors, that sort of thing.

We're concerned about AI, not generative AI, but in more accurately artificial general intelligence, looking at its ability to find vulnerabilities in systems. So I would characterize it in two ways. Right now generative AI, at least the way we think of it, is most beneficial to the bad actors in terms of, you know, crafting messages, social engineering, convincing people to do things that they wouldn't normally do. So that doesn't, that's not just limited to writing better messages.

It's also associated with convincing people to do things that they would not normally do. So, and it's very effective in that. So, you know, convincing someone to, for example, change the account number on their bank account for accounts payable or those types of messages, but not specifically, say, for example, we're less concerned about it, generating malicious code, although it's capable of doing that. And we're monitoring that now, but it doesn't seem as though that's evolving as an area of major concern right now.

But, like I said, we're monitoring it. The generative AI doesn't really have the capability, say for example, of looking at your sassy infrastructure or your cloud infrastructure and searching for vulnerabilities. But I think AI is will evolve in that area, and that's a major concern for us as well. Yeah, I'm sure.

By next Wednesday we'll be here. I don't know about you. It's the fastest product release cycle I've ever seen. With this product, it's just incredible.

I'm more concerned, you know, yeah, I hear you. And all that is correct and all that makes sense. However, when you, you know, when, I don't know, Mary over in investments decides that she wants to see what she can find in the chat GPT LLM world. And, you know, this is absent any corporate policy, right?

We have most companies as of right now have no cybersecurity policy, no privacy policy around generative AI at all. And yet, as we saw with shadow IT, you know, departments are doing whatever they do. And no one's managing or controlling that. And every time that Mary, you know, throws some, you know, trading data that she has out onto that learning model, it becomes part of that corpus of data.

This chat GPT uses along with another 100 million Mary's every minute throwing more data out there. There's a significant privacy issue there, exposure there and a significant IP exposure there. And you'll say that chat GPT allows you to say, you know, don't share that. I get that, right?

But Mary may not know that. So how do you, how do you combat that? Right now, the customers that we have are seeking for us to literally blow up. So the customers that are concerned about that, which is, I would argue, the majority was slightly different to what you described in your introduction.

But my customer base might be self-selecting towards, you know, being more concerned about the risk, but they are typically attempting to block access to generative AI sites for their end users as they try and work out how these tools can be leveraged. Because there's an enormous benefit to be gained by having your employees gain access to generative AI. The flip side, as you point out, is Mary putting next quarter's financials in the tool. And so I think that the right now, the only strategy that we have is around blocking access to those sites, which is not going to be sufficient.

What we'll have to evolve, and this is something that look out focused on, is how to, for example, apply DLP and information filtering, such as things like reduction and so on sensitive information that Mary may not have understood that she was not allowed to share. But let's say Mary is ambitious and clever, and she's working from home, and she has her own desktop right next to the corporate desktop. And she decides, hey, I'm going to get an advantage on Harry next door here, who's we're both buying for the best trader of the month or whatever. And I'm going to, I hear all of that stuff, but I'm just going to grab some of this data and ship it over to my desktop, and I'm going to send it out that way, right?

And there's no control over that, once it's outside of my digital domain that's managed by corporate. So, and I don't think that's unusual, right? I mean, there's that assertive, aggressive, competitive Mary exists in every company in a multiple way by however many you want to imagine, but how do you stop that? That's like the age-old question.

How do you stop the problem, the situation where someone takes a photo of the desktop, a virtual desktop where we used to get asked of Citrix all the time. And he said, I worked at Citrix in the introduction. The, ultimately the human factor is the one that we have to be most concerned about. In this particular scenario, the only way that you can really guard against that is to stop Mary being able to move that information from the unmanaged, sorry, from the managed to the unmanaged environment.

We can do that with things like forced encryption and management of the data to some extent. But like the example that I just gave, if she were to take a photo of a screen and then, you know, optical character recognition. So efficient these days, you can pass it immediately on the other machine and upload it. There's not much you can do.

Yep. That's right. There isn't much. And so it's a, it's a, it'll be an interesting world in which to figure out when has security ever kind of overcome convenience or advantage.

I mean, that's so we won't sit here and debate that, but I wanted to raise it as a concern that I have. And we have, it'd be great if you figure out to do something with, obviously, the data itself is, is where the answer is. But how do you, how do you manipulate? How do you make sure that data's not, not usable in any other format?

Well, of course, there's the flip, flip side of the coin as well, which is, if you don't provide generative IOI, the data, it's going to make up the answer anyway. Yeah. Right. There we go.

So AI flip, flip side of this. AI has tremendous potential for one of the areas that we're terrible at, which is, you know, hygiene and patch management and all the rest of it. Do you have you guys experimented much with, you know, using it to find open vulnerabilities and make up patch lists or, you know, to actually do an auto patch of any kind? Yes.

So also our experimentation is about automating the repetitive and mundane, if you like, in our current, you know, our own products administration, as well as in security best practice in general. So, for example, being able to interact more simply with our administrative consoles to identify, I don't know, the group of Android devices that are out of date from an operating system standpoint, and there is now a known vulnerability for those devices and what to do about it or those types of stuff. So making that easy for administrators, that's a focus for us equally since we mentioned that vulnerability through misconfiguration is a concern. So we're experimenting also with the ability to use generative AI to establish whether systems are configured with vulnerabilities by mistake and what can be done about that.

So a good example is with, so in our business securing the cloud for customers, they typically have hundreds and hundreds of SaaS applications or cloud based applications and every single one of them, because they're targeted at a particular use case, they frequently have very different ways to configure access control and authorization access to data, for example, we think generative AI can be very effective looking across all of those different tools, especially through API interactions where those tools have APIs to establish if there's, for example, vulnerabilities in the way that those applications have been configured. So it takes the, and typically, although I just talked about our generative AI development, can develop hallucinations and give the wrong result, typically we believe AI is going to help us in the areas where tasks are repetitive and it's difficult to see misconfiguration just because of the sheer volume of the problem. Yeah, well, and, you know, we're essentially in beta, right? I mean, it's been five months or something since this thing hit the market.

And, you know, I'm sure that the next release or two will probably solve a hallucinogenic problem. But at the same time, you know, I mean, it feels to me like a lookout product, a suite of lookout products, you know, that you guys that would distinguish you guys from, you know, the rest of the pack in many ways in that. But if I can get that ability to do that, to get those vulnerabilities patched to get the configuration exposed, misconfigurations, at least, you know, give me a list of what they are and what they should be. Boy, that goes a long, long way to moving the needle on securing my environment.

At the same time, you know, all of that sort of automation can play its way into post, well, the post alert analytical side. So you, you know, you've got, and I used to run socks. So I can say this that, you know, it's a worse job in the world. And so you can eliminate a lot of these jobs, it seems to me.

But if you look out on the landscape and you say, okay, this is the evolution of our product suite. We're going to go here and here and here. We're talking about a lot of job elimination, it seems to me. Yeah, no, one of the areas that we've actually been doing research and I've been looking at partners in the sort of startup environment as well, is exactly that essentially having AI look at the typical actions of level one sock analyst.

And if they take the same action for the same problem repetitively, you can very effectively enable that through, you know, machine learning and artificial intelligence and and reduce the number of analysts at level one. Now, that's not, I'm not one of the believers that all of our jobs just go away because of artificial intelligence because that will ultimately alleviate some of the skills gap in the whole cybersecurity space. But I see that allowing us to focus those people on level two, where it actually does require, at least at this stage, human intelligence to make connections and understand what to do in certain circumstances. I see that that there can be a significant alleviation of over time of the skills gap in in cybersecurity in general, if we leverage AI correctly.

Yeah, and I agree 100% that you and in addition to that, whether you know, you'll, in addition to being able to sort of convert level once to level two is you'll reduce the number of level two is required as well, but you'll increase their efficiency, you know, by 20 x right so. And if you move their function over to what it should be, which is detection and response and recovery, then, you know, that will have a big impact and seems to me on that whole process. Well, I see, and they're not necessarily also just moving to level two. They're also, they're going to become responsible for training and models.

Like, so it's, you know, in order for these models to be more and more effective, we need humans to train. We need large data sets and humans to train them. So I see that the roles change a little bit from, you know, fixing the problems to teaching the machines that fix the problems. Yeah, I wonder what would happen, you know, going back to the adversarial side, wonder what would happen if they replaced all of the, all of the malware that's inside our solar wins customers networks, which we know exists in thousands and thousands of sites.

Today with, with code that they generated out of a scenario around like, you know, that got that malware to be smarter, right? It's sort of like, okay, you're there. What are the, what are the cross functional opportunities in terms of vulnerabilities here that were, that, you know, could sort of figure that out better than humans could. Is that a threat that you guys imagine?

To be honest, our research team imagine all sorts of crazy scenarios like that. I don't know if that is one in particular, but absolutely leveraging our official intelligence to develop attacks is something that we are focused on. I think we're fortunate that that type of scenario hasn't evolved yet, but I do believe that unfortunately we're going to be facing scenarios where things like that do occur. I equally believe that as software, you know, gets involved in everything that they're, I mean, the majority of the focus right now from a social engineering perspective is around mobile devices and, you know, gaining access to passwords and that sort of thing for, for the extortion of organizations for financial gain leveraging, you know, the theft of data as software gets more and more involved in all of our lives and arguably even, you know, artificial intelligence, I believe that that extortion is going to move into other parts of our life as well, which is very concerning to us.

And one of the reasons that we're looking at how we can defend the types of devices that you might increasingly become dependent on for other aspects of your life. That can range all the way from, you know, cars to medical devices. So it's, that's an area that we're very concerned about. That's exciting to me.

I'm glad to hear that because, you know, you're absolutely right. It's another level of risk that most folks haven't thought about here, I think, and it's good to hear you're thinking about it because, you know, that's very real and it's right around the corner. So they make movies about that stuff. So final question, I personally believe, you know, that we have happily handed over to Google and Facebook, all of the personal information that we, you know, that they could possibly want.

So I'm not sure. It's hard for me to get excited about the whole privacy world. However, we're seeing more and more and more opportunities for violation of the regulatory agenda that's in place right now. What is the impact from your point of view on data privacy from the influx of artificial intelligence technology?

Oh, I think that you actually highlighted it really well before. The fact that we're, that generative AI has been the most rapidly adopted new technology in history. And in order for it to operate, you have to provide data. It's inevitable that people have been providing it personal data and it's inevitable that that that will be leveraged by the generative AI in its answers.

Now, not in a malicious way, but it's unintentional. I mean, you can manipulate generative AI to act in a bad way when it doesn't think that that's what it's doing. So I believe that if there is going to be a significantly negative impact on our on our privacy while regulators and just the general technology field struggle to understand the implications of generative AI. I think many others have said we've thrown this out in a beta form with, you know, no regulation and no real controls and we're sort of seeing how it goes and trying to understand the implications as we use it literally.

So it's like we're trying to establish what's wrong with the airplane while we're flying along. So there's an aspect of that. I think it generates huge amounts of innovation and I would not want to stop that in innovation, but the capabilities of generative AI so far outstripping, for example, things like, so far ahead of things like regulation and so on that I think it'll be quite some time before we catch up with how to address this from a privacy standpoint. The last thing that I would say though is that there is light from my perspective at the end of the tunnel in the privacy arena.

I think that as people get more and more concerned about privacy, I think that distributed identity and better management of our personal information through distributed identity has a good chance of at least getting parts of that privacy issue under control. Yeah, and thank you for that. I appreciate your perspective. We can talk for hours about this, but we don't have that time.

So thank you, Aaron Cockrell, for joining us today. It was a real pleasure and your super smart guy. It was fun talking with you and I hope to be able to get you back on our show here in a few months and see what you guys have been up to, you know, between now and then I'm sure there'll be 400 other new things that we can talk about. Thank you very much.

This is great. Thank you. And thanks to our audience. Again, this is Aaron Cockrell, the Chief Strategy Officer at Lookout, and we hope you enjoyed the 30 minutes or so that we spent today and look forward to seeing you again next time.

Until then, I'm your host, Steve King, signing off. Thank you for joining us for another episode of Cybersecurity Insights. You can connect with us on LinkedIn or Facebook or send us an email at social at cybered.io. For more information about the podcast, visit cybered.io or with slash podcast.

Until next week, stay safe and secure and we'll see you on the next episode of Cybersecurity Insights. Thanks for joining us.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on August 11, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!