AI Leadership Insights: Cybersecurity’s Black Box Problem with Ken Gramley
In this episode of the AI Leadership Insights video series, Amanda Razani speaks with Ken Gramley, CEO of Stamus Networks, about cybersecurity’s black box problem, how AI is compounding the issue, and how business leaders need a new approach that leverages the benefits of AI, while prioritizing extreme transparency.
Transcript
Hello, and welcome to the AI Leadership Insight series. I'm Amanda Ani, and with me today is Ken Gramley. He is the CEO of Staus Networks.
How are you doing today? I'm doing great, Amanda. Thank you very much for having me today.
Happy to have you on the show. And so can you share a little bit about the company and what services do you provide? Stanis Networks is a network security company.
We have been providing, um, network detection and response products. We are, uh, a leader in, um, I would say that area in our roots are growing out of an intrusion detection system past, um, and then building that system into network detection and response. Uh, we are more heavily into Europe from our customer base than the us.
Um, we are, are, um, entering the US market right now, I would say. But we are, uh, we have central banks as customers in Europe, eu, governmental institutions, other, uh, other governmental agencies. Um, we're pretty big in financial institutions, a little bit in manufacturing, um, as well.
And, uh, very happy to be able to help our, our clients out. Wonderful. Well, our topic of the day is cybersecurity algorithm transparency and explainable ai.
And I wanna start out by saying, uh, or having you explain, please, what is the black box problem as it relates to cybersecurity? Can you explain that? Sure.
So the, the blacks, the black box issue has to do with how well vendors, um, explain what and why they have detected something. You know, it's one thing to find out that, okay, I have this particular, um, IP address and it has a problem. Often what happens is a tool will tell you that there's a problem there, but then it is left up to the incident responder to try and figure out what happened and why there is a problem.
And if the tool would tell you exactly why it detected it and what it found about the detection and why it's saying, you need to go investigate this, that would save, um, those incident responders time. And obviously time saved is a good thing. So the, the challenge is duplication of effort because the, the vendor who provided that knows what it is.
Often they say, oh, no, no, no, I can't tell you how we detected it, because that's our secret sauce. And so, uh, any vendor who's willing, I, I believe vendors should be willing to basically be much more transparent in how that detection is done, because it saves their customer time in the long run. Yeah, absolutely.
Having to spend all that time trying to figure it out when they could just go straight to it. Exactly. Yeah, that makes sense.
So now we're gonna talk about the introduction of ai. And now as we're seeing AI integrated into everything, this causes more things to think about, more issues and concerns. What are a few of those?
Well, I think AI is, um, exacerbates the problem because it is even harder with an AI algorithm to explain it to a customer and to explain why it found something wrong. Um, you know, one way to look at it is AI is really good at finding outliers. And AI algorithms themselves tend to put out a, okay, this is, you know, a zero to one scale.
How do you then backtrack that into, okay, this is the reason for that output. And, um, it also gives, uh, vendors the ability to just say, oh, I'm sorry Mr. Customer, just trust us.
This is bad. Trust us, it's bad now. Go look.
And, uh, you know, AI does a good, I would say, improves the problem of noise that that security has generated, you know, since its beginning. But it doesn't solve the problem of noise. It just provides a different type of noise because every outlier out there is not necessarily evil.
Um, and, uh, transparency in those AI algorithms would also help the, uh, uh, incident responders be able to save time and understand what is going on. So what tips do you have for business leaders as far as putting more transparency there and approaching, uh, and leveraging the benefits of AI while being more transparent? Well, I would say, you know, look to your vendors to both, um, tell you why they come up with the problem that they came up with, how, what evidence they use, and then provide that evidence along with the issue so that you don't have to go searching for it yourself.
Things should be packaged up together where you provide, here is the incident, here's the timeline of the incident, here are all of the components that happened. Here are the P caps that go along with it. The more you can bundle all of that together for your customer, the easier the incidents incident response effort is for them.
Do you foresee there being, um, you know, if this continues to be a problem where there's this back and forth with a vendor and it, and it's a lot more effort, do you think the companies themselves will start creating their own tools so that they can just, um, leave the vendor out? Well, I think the companies have, um, always have a build by decision they need to make. And often it's some combination thereof, um, where they will, they will do some of their own algorithms on top of their sim or or whatever other tools they have, but they have always at, at the same time, needed some level of tools from vendors because there are pieces of it that are very hard to build yourself.
And then even once you have built a tool, you have to then maintain that tool. You have to worry about keeping, um, keeping the right, uh, skill sets on board. And, you know, if you're a, if you're a hospital system, do you really want to have software?
How many software engineers do you want on your staff to be able to keep your tool set up and running so that, that's a challenge to the build it yourself. But I certainly understand when customers have done that because of the frustration that they have had with the vendors that they've used. Mm-hmm.
You're absolutely right though then, you know, some company that's really not a technology company at all is now becoming one. You know, just to try to have their own tools, that'd be difficult. Right.
So as AI advances so rapidly, what do you foresee in the future as far as it relates to cybersecurity? Well, I, I think there's, um, there's been a lot of talk recently about the autonomous SOC and the idea of aggregating all data into one place and then putting AI on that data, um, at a data lake level. The, um, I mean, traditional sims have kind of attempted that I think haven't done a very good job of it, which is why there are some next generation people out that are attempting to do it.
Um, and while I'm not sure that we will ever get to an autonomous sock, like we will get to an autonomous car, for instance, the, uh, although the, uh, um, uh, a shout out to, to, uh, um, Sentinel One on that comparison. I don't know if you've seen that video, but it's a very good comparison between stages of an autonomous sock and stages of driving. Um, I don't know that we'll ever get to the point where a sock will truly be autonomous, but the more we can do to remove the drudgery and the low level work from SOC engineers so that they can focus their effort on higher level issues, the better off all of the industry will be.
So I, I see that as the, as the, the goal that, um, vendors are trying to help their customers get to. And at the same time, um, having the, uh, having the, uh, AI applied at that higher level where you can see all of the data. The, the challenge that you have with putting AI on point tools, whether it's network or endpoint or email, it doesn't matter, is those tools only see part of that data, right?
So AI on an end tool is an, on an endpoint protection tool, for instance, is a great thing, but it doesn't have the ability to aggregate what's going in on the network, which is ground truth. Same thing with network. We can put AI on our product and we have machine learning algorithms to do certain things, but we don't see what's going on on the endpoint and we don't see, you know, what, uh, um, you know, what processes are being created by which, which executables, which an endpoint tool can see.
So applying that AI at the data lake level makes a lot of sense for, because AI is good at, at searching through huge amounts of data that, you know, the typical individual person can't do. That's, that's its strength. And so having it at that higher level makes a lot of sense, which means having a bundle, a, a, a set of tools that can feed into a data lake or something where that AI is then applied, such as what SentinelOne is trying to do with purple ai, I think is a great future path for our industry.
Mm-hmm. A huge time saver and, and potentially more accurate as well. Exactly.
Exactly. And what was that video again? Um, share that again.
Uh, Sentinel, if you search on the Sentinel one video for, uh, uh, their autonomous sock, there's a, a, um, sales engineer who did a great job comparing the autonomous sock to autonomous driving and the different stages of that and where they believe they are in the autonomous sock stage, but also in, um, uh, how that kind of maps to people's understanding of autonomous driving. And so I think it's, it's good for people who aren't heavily into the industry to, as a good takeaway to on a big picture, understand it. Awesome.
I'll have to go look for that. Yeah. Well, if there was one key takeaway you could share with our audience today, what would that be?
Well, I think it's to make sure that the vendors that you're using are providing, um, clarity in the detections that they have on why they detected what they detect and are providing the evidence to go along with it. And, uh, um, you know, we, we at Staus try very hard to do that. We have always been known, and one of the things that our customers really like us for is the clarity and the data that we provide and the amount of, um, uh, well, well first off, the amount of data that we provide along with the detection, um, and the fact that you, they're not dependent on other tools to do correlations after the fact.
We correlate everything right up front when we, when we provide it to you. Um, so I think the more that vendors can, can, uh, provide that level of transparency, whether it's on their AI detection or their traditional detection, I think the, the better off all our, the industry will be. Wonderful.
All right. Well, thank you so much for coming on the show and sharing your insights today. Thank you, Amanda.
I appreciate the time. And thank you to our audience. Stay tuned.
There's more.