ACSI Labs’ Neil Sahota on Cybersecurity’s AI Arms Race
ACSI Labs CEO Neil Sahota dives into why cybersecurity is evolving into an artificial intelligence (AI) arms race that requires eternal vigilance.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Neil Sahota, who's CEO for ASCI Labs, and we're talking about the AI arms race as it applies to cybersecurity because, well, everybody seems to be delving in, but it's not quite clear who's ahead, who's behind, or for that matter if they're actually doing anything.
Neil, welcome to the show. Hey, thanks having me on. Michael.
Excited to be here. So what exactly are the bad guys up to? Because on the one hand we hear about the potential to use AI to drive cybersecurity attacks in volume and increasing sophistication, and then the rest of us kind of sometimes look at that a little bit and we say, geez, you know, it's already so easy to launch these attacks.
Why would they bother? Because why do they, why do all the extra heavy lift? Well, it's either, uh, obviously they're looking to score a big heist or they're looking to inflict damage, or sometimes both.
And bad actors, uh, unfortunately have gotten the jumpstart in this whole arms race on cybersecurity versus kind of cyber threats. How do you know what they're doing? I mean, do you, have you seen any examples of them using AI and what does it look like?
Yeah, it started with, you know, more traditional attacks, like denial of service and stuff. But with ai, they could do it at a speed and volume that was just overwhelming for most systems. So the good guys, we, you know, started combating that with our own like kind AI cyber warriors and started using AI to figure out other types of attacks and bad actors got more creative.
And so, you know, they're using AI to figure out new types of attacks, which is not just cyber, but they're actually using AI to probe like physical weakness. And even, um, perhaps the linchpin, the whole model is people weakness. 'cause it's a lot easier to hack a person, like as an individual than it is to hack a system.
So does that mean they're kinda using some form of AI to monitor people's behaviors and figure out who's maybe most likely to click on a, on a malicious link or something? I mean, how sophisticated does that get? Yeah, that, that's actually one thing they're looking at.
They, they're AI systems that learned like psychology and neurolinguistics. So the AI can really get to know a person just like the best friend does. So they, they understand kind of your, your language, the way you speak, interact.
They understand the best channels to, to hit you at. They know kind of the right triggers to get you to take action. And, you know, we're seeing more and more of this getting prevalent, unfortunately, with the rise of deep fakes.
You know, there was a financial se, uh, services company recently that was just hit. They were literally on a Zoom meeting. They thought it was a CFO and the CFOs, I think core team seemed, acted just like the CFO said, we, you know, we have an emergency situation, we're gonna wire this money to, you know, cover, you know, whatever cogs cost sold were or something like that.
And I think they wired for like $12 million right away, not realizing they were talking to a dfa. As we go along, it seems like, are they inserting themselves into our workflows to monitor that behavior and collect our processes and figure out what we're doing? Or can they do this from afar?
I mean, you hear the phrase living off the land all the time, but how much access do they need for how long before they can start using AI to kind of create that deep fake that sits in the middle of a workflow? They not, not, they don't need much data at all. I mean, there are tools out there that you, you pull some, you know, video or audio or even pictures off the internet and that's all you really need to take.
I mean, last year there was a crime ring that, you know, would call parents and tell 'em they had kidnapped their child and they called when the child was in school, knowing that most schools don't allow them to have their phones on at the time. And you know, the parent would be like, oh, we'll prove it. I wanna talk to my child.
And they would quote unquote, put the child on. It was really an AI deep fake audio made from their social media and it sounded like they did talk like they did. You know, parents are freaking out, you can't confirm the kid's cell phone is off.
And I think they, they, they did it, I think it was almost a dozen times and they were getting paid like 50 60 grand or ransom before I think, uh, the FBI Interport really started trying to track them down. But that's the level it takes you. You really like two minutes of data now, especially audio or video to pretty be fake.
Yikes. What can the good guys do with AI to help thwart these attacks? 'cause it, uh, hopefully it is an arms race and there is things that, you know, the good guys are doing.
We're trying our best one. One thing that we are doing right now is what we've learned that, you know, DeepFakes, like a lot of things have almost like a unique pattern or fingerprint to them, but the way that that AI is trained, there are some things that kinda reveal themselves as much. Like, you know, how, how do people know if you wrote something or chat, GPT wrote it.
It's the same thing we could try and look for in deep fakes, whether videos, audios, images are a little bit tougher. Listen area, we're trying to also figure out. But, uh, we know that if we don't provide this level of protection, it's, it's one thing like when it happens to a famous person like Taylor Swift or President Biden, but for the average person, like those parents that thought their kids were kidnapped, they don't have a whole lot of recourse.
So we're trying to build those counter tools right now to give people that, that protection and that that option of verification. Do you think, um, we're gonna have to wait for some massive reach for everybody to kinda wake up to this whole thing? And I'm asking the question.
'cause historically we've always chased after emerging technologies after the fact. And of course, you know, we're told all about it for months and months and months and, but it seems like it's not until there's something catastrophic that everybody goes, all right, we gotta get serious. Michael, unfortunately, that that's the, the attitude that, you know, we've always been like a reactive society or, you know, something bad happens, but we're at a point where AI can do things with such volume, such speed, such large impact that if we're not proactively thinking about it and trying to, you know, protect against some of these threats we're it's gonna be too late.
That's the honest truth. Primary is gonna be too late. I I seem to be using this quote a lot from Plato.
I I do like it, but we learn from pain. We have to break that kinda mold because we can't wait for like, oh well 50 million people just got impacted. There's a real no way to recover for those people.
They still are suffering and feeling real pain. Don't jump ahead of these things. What are we gonna do?
And, and in my work with the United Nations, that's one of the things we're actually trying to do with the global regulators is kind of shift that mindset away from reaction to being proactive, which means we have to get good at scenario planning. We have to get good at thinking about, you know, these are just tools. How would people use and misuse them?
And that's just something we, a skillset. We, we were just calling in the beginning of trying to develop, Are we suffering from cybersecurity fatigue? And I asked the question because a lot of the boards are asking questions now, like, well, we invested all this money and are we any more or less secure than we were before?
And I might argue that that might be the wrong question to ask in the first place just because, well, it's not like the bad guys don't change their tactics and techniques. So is this just a continuing, evolving gamer? I don't know if I'd call it a game, Michael, but it's a, it's a nonstop race, that's for sure.
There's, there's no finish line. We know that bad actors figure something out. We find countermeasures better protections.
They find either a different path or different way, you know, d better tools to, to break what we've done. And we then elevate our game. They elevate their game.
It's, it's nonstop. And I get where the boards are coming from. Infrastructure projects are, are the hardest things to rationalize.
There's really no ROI either you kind of do it or you know, what's the cost of not doing business. But the truth is, is look, there's not that many bad actors out there as a percentage of the population, but especially with emerging technology like AI, that can cause a horrific amount of damage. That's the reason we make the investment.
So I wish I had better use for everybody, but it's, it's one of those things that it's just never gonna be ending. It's, you know, what's, what's the old cliche, and sorry to be using a cliche here is the price of freedom is, uh, ever constant vigilance. And that's very true when it comes to cybersecurity.
Well, speaking of that vigilance, do you think AI will make it easier for, uh, nation states and companies in general to collaborate with you with each other to thwart these threats? 'cause I think one of the issues we've had so far is everybody kind of functions in isolation and, uh, the bad guys are just going to town because we don't communicate with each other. Yeah, that's unfortunately true.
And AI has been a boost in sharing some information and different types of attacks. I know that Interpol, my work with them has been a lead on that. There's still a hesitancy to, to share some of these things.
We, we know that, you know, some of these big institutions, whether their companies or universities for example, they get bombarded every day by attacks and they don't want to quite reveal that or what kind of attacks are happening. 'cause one, they don't want, you know, their employees, customers, students, faculty to freak out. And two, they don't wanna know just how much at risk they are make themselves a bigger target.
So it's, it's kinda unfortunately a, a weird balance trying to figure out here is how much to share without trying to increase your risk factor. Are the folks at Interpol and other law enforcement agencies getting more proactive? And, um, I asked the question because the honest truth of the matter is cybersecurity always felt like, well, we know there are bad guys out there, but until they robbed the bank, we can't do anything about it.
So then we go chase after them. But we knew we could see them walking down the street and they were about to rob the bank, but we had 'em wait for them to actually rob the bank before we could do something about it. And can we change that?
We, we could, right? You just, we just need 194 member nations to agree to it. Michael, it's one of, that's one of the big challenges that that's why everyone talks about building a better fence, so to speak.
Better safeguards, better. It's, it's almost like the whole minority report movie, right? Is it really a crime of someone thinks about it but hasn't done it yet?
That's that think a challenge for the legal system. Mm-Hmm. So, you know, is it enough to say that someone's trying to probe the defenses or trying to do something?
I mean, that's gonna be a debate for the legislatures. I, I fear. But that's why the focus for a lot of the cybersecurity organizations and law enforcement has just been around trying to create safeguards and protectors.
Can we get better offensive capabilities? I know there are diplomatic niceties involved when we kind of hack into servers that exist in other countries, but it seems like people are starting to say, Hey, we're not gonna take it anymore, so are we gonna get a little more aggressive? I, I think some of that is happening, whether it's sanctioned or unsanctioned.
I, I really couldn't tell you how much of which of each it is, but you know, you probably heard of more about Michael, the black hat versus the white hat type of hacking. You know, I, I think again, there's no way to effectively regulate that at the moment. And you know, I'm sure a lot of people saying like, well, why would you wanna stop white hackers?
It's not necessarily stopping them, but it's, I think, I think the real or underlying threat here is that, you know, everyone talks about the next war is gonna be in cyberspace and we're building a lot of tools that we're reaching a point where it's, you know, even some of the developers don't fully understand how they work. We could leash something that's very cataclysmic unintentionally. And I think that's the biggest concern when it comes to white hats, black hats.
Well to that point, you know, if I went back in time, uh, there were bank robbers holding up stage coaches and, uh, railroads and those guys got together and put out little bounties for capturing these people. And it was, um, you know, the nice cities of the court thing were kind of, you know, if they were captured great, they would go on trial, but sometimes it never quite got that far. Um, our company's gonna get more aggressive about this because they have so much at risk and, um, they can't wait for the government to actually respond after there's been an incident.
It's a, it's an interesting question, Michael, 'cause there's a debate about that. And the debate is, should they have like their own kind of counter team? And I know that they are using AI for scenario planning predictions to say, you know, probing for their own weaknesses, trying to figure out, you know, new, new types of attacks and they can then create safeguards against.
But there's a growing consensus that the biggest challenge to solve is the people, right? At the end of the day, hackers know it's a lot easier to get the information you need through a person clicking on a phishing link or something else than trying to really break down encryption or cybersecurity systems. And the question really becomes is how do we do that?
We, we wouldn't, you know, try and education, try some of these other things. You know, there's talk about now could we put people into like a metaverse simulation run by an AI where they actually, they do one of these things, they actually see what the overall impact is, would that make them think twice? So I think right now still a lot of the root solution is can we better educate people?
Because that's really the first line of attack for a lot of hackers, right? But bad guys only need to be right once, so even the smartest person gets tired, they will accidentally click on something and um, it's just kind of the nature of the human condition and frankly, you know, 20% of the population probably isn't that smart to begin with. So, um, I don't know, people is, you know, a good place to start, but I gotta feel like there's gotta be some other ways to augment this because, well, those people are humans.
It is very true. And there's, there's talk of leveraging what we call hybrid intelligence that, you know, people are good at things like, you know, first of a kind creativity, something that requires a lot of like, you know, instinctual type of thinking. Machines are really good at processing lots of data and so forth.
And so it's the meld between the two that augmenting our human capabilities with machine capabilities is hybrid intelligence. And can we exploit that in terms of separate protection? Could it not just be educating the person, but can we have like a little ai you know, security guard as your, your buddy that's helping to review your emails and some of these other things and say, hey, whoa, whoa, before you click that link, let's just double check that, you know, and you know, there, there's some merit to the idea.
The challenge is, is twofold in trying to do it. One that the more variability in the system, the more data AI needs to be trained properly and thinking about how much variability there is in a cyber attack. And two, are you training one weakness for another and that, well if, if great they have the buddy system, but if I could figure out how to hack the AI security buddy, does that solve my problem?
Right? Can I then just incentivize the security buddy to have the person do wrong things? Uh, maybe right?
We, we could debate this till we're blue in the face because there's never gonna be a perfect solution. And, and I think that's what we unfortunately have to accept. That's why it's a never ending race.
Alright, Given the imperfect nature of cybersecurity, then, what's your best advice to folks about how to get to where they need to be versus where they are today? 'cause I think a lot of folks are like, they understand that AI exists, but I think they're a little overwhelmed. A again, it it's the see old adage though, trust but verify right there.
One, one thing we've noticed is that, uh, you know, AI tends to be too perfect, like with deep fakes or, you know, some of these things that either they try and create very obvious flaws that seem weird to us or we don't see the flaws at all. So subconsciously it feels weird to us. So if you're feeling weird about something or you gain something that is, it's a lot of money, or there's a link here or something that seems sort of right, still just check it out, right?
Do, do the virus scan, hover over the link, all those things we're, we're taught to do. And you know, if you're worried about being deep fake, you gotta, you gotta confirm somehow there, there's really nothing that urgent that can't wait for, you know, an extra few minutes for that kind of verification. So just trust but verify, be a little guarded.
All right folks, you heard it here. I'm not so sure about the trust part, but the verify, absolutely. I would more maybe argue don't trust anybody and think twice about it and go from there.
Hey Neil, thanks for being on the show. Yeah, my pleasure, Michael. Thanks for having me.
All right. And back to you guys in the studio.