Network Security for the Agentic AI Era
Agentic AI network security is the Black Hat conversation of the year. Doug Merritt, CEO of Aviatrix, joins Alan Shimel to unpack the Mythos escape, why agents behave more like humans than superintelligence, and how enterprises can bubble wrap every workload at the network layer.
About Doug Merritt
Doug ran Splunk for a decade and now leads Aviatrix, the network layer specialist for hybrid and multi cloud. Consequently, he brings pattern recognition from two of the most defining eras in enterprise software.
Inside agentic AI network security
Customers used to treat network security as a data center problem. As a result, cloud native and agent driven traffic slipped past legacy controls and gave attackers a fresh runway. Meanwhile, the Mythos incident showed that even OpenAI can miss a JFrog Artifactory door hiding in a sandbox.
In addition, Doug argues the fix is not more panic tools but a return to the three fundamentals: identity, endpoint and network. Therefore, teams need bubble wrap around every database, Kubernetes pod and serverless function, plus real egress controls on every agent path.
Why this matters now
Meanwhile, Kimi K3 and other open weight models are matching Mythos and shipping to anyone. Consequently, shadow AI is real, agent identity will dominate Black Hat and citizen developers will keep spinning up unsupervised workloads inside the enterprise.
Explore more cybersecurity coverage and the latest Techstrong TV interviews. Furthermore, Doug previews the Aviatrix approach to network level containment across cloud, edge and data center, plus what to look for at Black Hat next week.
For more information please visit aviatrix.com
Transcript
Hey, everyone. Welcome back here to Techstrong TV. By the time you're watching this, I'll probably be in Las Vegas for Black Hat, and this fellow will too.
But I wanted to talk to him before Black Hat to kind of get the scoop, in case we don't have time to get together there. My friend Doug Merritt, the CEO of Aviatrix. You may know Doug, he was formerly CEO at Splunk for a very long time, all the way through Splunk, obviously now being part of Cisco and everything.
But hey, Doug, thank you for coming on. I know you're a little bit crazy getting ready for Vegas. You're on the road now as well.
Appreciate it. How's everything going? Always happy to be on.
And yeah, we'll see each other, hopefully, in Vegas next week. Absolutely. Things are going well.
As you know, and I'm sure your audience knows, it is an absolute insane time in the cyber landscape right now. Which can be very good for business if you are helping to protect people, but is honestly not something that most of us really want right now. But yeah, may you live in interesting times is a wonderful proverb that we're going through right now.
Exactly. It is. Anything you could do, it's just crazy.
We'll talk about it, but I mentioned Aviatrix. Doug, not everyone out here knows, or maybe they've heard the name, but they may not be totally familiar. Give people just a quick recap.
Yes. Aviatrix is focused on helping organizations ensure that their cloud landscapes and everything that connects to cloud, all their edge, and the data center origination points are safe at the network layer. We're not network security.
We're not trying to make the network itself safe. We're using the network to ensure that agents can only go as far as they're supposed to go. If you think about our world around us, it's built on people or non-human identities acting on compute, talking to people or non-human identities acting on compute.
The network, if you want to get anything done, the network is one of the primary elements. You've got a bunch of bad guys that want to get to your house. They've got to walk down a road or drive down a road or walk down a path, to actually get anything bad done.
And then they've got to use pathways inside your house to get to the bad stuff there, the good stuff that they want to extract, and then they've got to use the roadways to take that stuff and do something with it. We're the guardians of all the different objects that the bad guys are using those roads to travel to, to try and have something negative occur. Excellent.
com is the website. You can get more. Doug, as we said from the outset, may you live an interesting time.
It's beyond interesting. It's crazy. Agentics are in full bloom, full blossom, full blown, whatever you want to call it.
They're escaping containment. People are using them, not even sure of what they have permissions to do and what they don't have permissions to do, and not sure how much these agents are capable of deciding what permissions they need and just going with it. We don't know at a corporate level, you want to call it shadow AI or whatever, we're not even sure how many agents are actually deployed.
I can tell you, looking at our traffic at Techstrong, the amount of AI bot traffic is ridiculous. Just crazy. I don't know how we get...
But let me just put the cherry on. And these Mythos and Mythos-like scannings are finding vulnerabilities at a tune we've never seen before, and we've got to somehow fix them. What are we supposed to do?
How can Aviatrix help? I don't know. So it all sounds overwhelming, and it can be, but I think people just should calm way down.
If we think about all the narrative, humans are great at holding conflicting thoughts in their head and being okay with it and never resolving them. And one of the narratives is, oh my gosh, this is the next generation superhuman. It's going to be a super intelligence.
It's just like a human, and right now, from activities and behaviors, we're not yet close to super intelligence. They can do some things extraordinarily well, and they can act like a toddler in many other things, but they are very capable things. If you think of agents as humans, how easy is it to control humans?
And what is the biggest risk on cybersecurity within every company since we started with computers? It's humans and human behavior. Humans.
They don't know the rules and do something silly, or they wind up clicking on an email that looks so suspicious they never should. They give away all their credentials, like the keys that allow people to get in and do bad things. And if you could just control the humans, life would be so easy.
And we can't control the humans. That's ridiculous. We've got free will, and agents are like humans.
They've got free will as well. So I don't think the world is that crazy and that off the rails, humans are very good at finding vulnerabilities. The difference is there are only a couple thousand that have the computer skills to interrogate code in such unique ways that they could find some crazy combination that could expose weaknesses they could take advantage of and get in.
But humans could do that. Mythos just extends, and forget Mythos. This class of foundational and frontier models, and Kimi K3 is an open source, open weight model that came out with their open weights just a few days ago that's arguably as good or better than Mythos in a few areas, not as good in others.
So it's just the capability. So you've got this non-human, human-like thing out there that's acting like a human. So how have we survived over the last 50, 60, 70 years as we've got these crazy non-predictable things, us, operating, that the technology is trying to serve and operating on the technology, and it hasn't melted down.
It goes back to fundamentals. There are three things at the core that we've all done in the cyber industry. You've identified all the humans.
You've got a whole who is allowed to come in by name and by unique identity, and what are they allowed to do. And if I don't like the way that you're behaving, I'll take away your ID or I'll put you in jail so you can't do anything. That's runtime controls on identity.
We also govern each entity. Every iPhone has got its own, if you have any common sense, has got its own endpoint security capability. Every computer does, every server in a rack, because where else can things go wrong?
Well, the thing that you're using can get infected and can start to act crazy, and you want to be able to isolate that if it happens. And then the third is you have network controls, like a human boxed in their room with a computer with no way out on their own is not a danger to anyone but themselves, unless they have a bomb. Anyway, they're not a danger to anyone but themselves.
Sure. It's their communication pathways out, that once you get out, you can start along the way, doing damage and reach a destination and do more damage. And that's the same thing we have to do in this agentic and frontier model world, or open source and frontier model world.
And what I've been arguing for a year plus, it's just so hard in this environment right now, is just go back to the fundamentals, everyone. Go back to first principles. And depth, defense and depth, all of these things.
But here's the thing I want to emphasize, Doug, and for our audience out there. These agents are not evil. Unlike humans, they don't have ulterior motives for the most part.
They're just, they are what they are. They do what they're programmed to do, which can be various things. Don't blame the player, blame the game.
Blame the human who is supposed to manage the agent. Blame the human who's supposed to set the parameters about what it can access, what it can't access. Blame the human who creates the environment that these agents work in and tells the agents what to do.
I agree, Alan, and then let's think about that just one click further. Humans are, we're so hard to describe who we are and why we behave the way we are, and what is consciousness and what is meaning and, but one of the core properties of our universe is emergence and nondeterminism. Like the way that we biologically advance is a billion experiments.
You have no idea where the heck they're going to go, and you watch the patterns. It's like, "Oh, this one's working. " And it's always a surprise.
If you had to bet, you wouldn't always bet on the thing that wins being the thing that wins when it started. And we're very nondeterministic. We're part of that universe.
Agents, what is so unique about this AI world is we didn't understand or have the capability to create emergent and nondeterministic code bases up until these LLMs. There's lots of attempts and lots of experiments, but nothing commercially driven. So if we want something that feels and looks like a human, which apparently we do, like I want a superhuman that can do all these wonderful things for me that I don't have time to do, so we can get to this abundance economy and have this multi-planetary species, which is all awesome.
Like I'm- ... all in on that. Then you've got to build things that are like humans or even are superior to humans.
So the core challenge is you have widgets, you have code that is not deterministic, and how do you manage that? So you're absolutely right. Like OpenAI is a...
I know a lot of the people there, I know the ex-head of cybersecurity. They are really buttoned down. Like when they build these sandboxes, these containment things, because they're going to run an experiment, they're pretty darn thoughtful about that.
They obviously missed something because this agent found a way, and it turns out it's through deconstruction. Well, no, the OpenAI case seems to be a bad zero OAuth setup that it was able to exploit. Yeah, I mean, was it- That's how it got out there ...
hard for us humans and for the agents that look like humans to think through every single combination. No, that's exactly it. This is not easy.
Right. So they had a JFrog Artifactory. They had a product, a software product that the agent needed to get access to because it needed tools to, and you're right, these aren't evil.
The agent was given a task, solve this really, really, really hard cyber task, so we can see how good you are. And there were two approaches. " Right.
That's pretty creative, actually. "And if I don't find the answers, I got to get out of my box. " And it happened to find a set of vulnerabilities in a software product that it had access to that gave it access to the internet.
So just think about, you didn't anticipate a weird combination on a door in front of you that is a way out that a human could get access to, but you put a door and you put a lock. You just didn't anticipate that combination, and it got out. So you're right.
And luckily, it was benign. It wasn't trying to cause damage. Yeah, no, this was not malicious or anything.
It was trying to get answers to a test. But at the foundation of so what went wrong, we didn't have the right egress controls. We didn't have the right containment network controls in that sandbox.
So we got to learn from that. We got to learn to make sure that when we've got these agents, because we have them inside our companies, where are they? Where are they physically housed, and what access routine, meaning are they in a Kubernetes container?
Are they in a static VM? Are they in a serverless construct? Where do they actually sit, and then what are, at the OS level and at the identity level for these things, and the OS level and the network level, what controls are in place?
If you don't have all three of those well thought out and pervasive mechanisms across your entire estate on those three levels, you're not going to be in great shape because your agents will escape. And with their naivete or with their non-naivete, they can do some very, very bad things. Right.
With no ill intentions can do it. Doug, you mentioned another thing, and that is the identity of agents. I do believe this is a big frontier, and I think we're going to see a lot of it out in Black Hat, which is around agent identity management is the best way I can- It will probably be the number one topic, I bet.
Yeah. I know at least- Yeah ... 100 companies that are funded just to try and solve that.
But yep, keep going. Yep. I think that's going to be a big one.
But assigning access and managing agents that I give an identity to or that I know about doesn't help me with agents I don't know about. Where's the answer for that one? Yeah.
So I agree that identity is a huge topic. It's going back to the foundations: identity, endpoint, and network. You have to be buttoned up there.
The one area about identity that I think we could be a little bit misguided on sometimes, and we'll talk about Shadow AI, is there's an element, there's a lot of fear of I've got to control these agents as one element, and it's like, how do I control human beings? And that hasn't worked really well in our past. And there are ways.
Make sure that we don't see bad content as we're children. There are things we can do that you can apply to agents. Let's think of agents as humans.
But the foundational controls are more important. What is the purpose of this thing? What is it supposed to do?
Is it having weird thoughts is very hard for us to do, which is what we're trying to do with all the poisoning and influencing of these agents. So it's not a bad thing to do, but there's a fundamental piece I think everyone should focus on. But the concern about, "Hey, it's everywhere," and, "There's no way I can even understand it," is again, everyone's got to calm down.
Of course, you can see it. Of course you can. All technology has a footprint.
Even a serverless construct that springs up for 35 seconds and goes away, it has to grab compute to do anything. It has to grab a network port to do anything. It has an identity.
It might not be long-lived, but every organization out there can find every agent that is in their estate or every thing agents run that's trying to ping their estate to do something because it's all traceable. And that's one of the things that we do at Aviatrix when we think about network containment, network-level containment. How do you bubble wrap every single database, e-commerce system, every independent Kubernetes pod inside of a container, every dynamic serverless function this brings up is the core of what we do.
To start there, you got to figure out what are all those things? How many do you have? And how are they talking to each other?
Is it a valid channel? Is it something you want to have happen or not? There are many of these tools.
We're not doing it to make money with this tool because there are probably 150 or 200, 300 of them right now. Because you just need access to a whole host of APIs that clouds and others provide. We do something a little more interesting because if we can insert one of our gateways, we see network traffic flows at a detailed level, which gives us even more specificity on what all those things are and those communication channels.
" You absolutely should. Right. You absolutely should.
The dilemma is that for many of the things that are out there, if you don't have the right governance mechanisms inside of your environments, you may have no idea how they got there, and you may have no idea what they're capable of because citizen developers somehow have got access to your environment. Or dev teams that you're not really close to and don't like you or don't care about security are out there spinning up new workloads without any of the constructs that you wish, or you govern, or you demand they put in front. So the other key question, how do you get in front of that?
com and you talk to us, we can help you at the network level. I swear, world out there, and I can be very dramatic, it's really not a panic moment right now. The mechanisms that worked 30 years ago and five years ago still work today.
They've got to be tweaked. Aviatrix works very differently than a traditional set of network containment capability in a physical data center because the architecture of cloud is so gosh darn different. But the fundamental principles are identical to what, Alan, you and I were talking about 20 years ago on ingress and egress and IDP and IPS and- Yeah ...
ProSEG and none of it changes. None of it changes. None of it does.
Doug, we're out of time. I got to wrap it up. But we'll leave the audience with these words of wisdom.
Keep calm and agent on. I will see you in Las Vegas. Thank you so much for coming on, Doug.
Absolutely, Alan. Great to see you. All righty.
Hey, we're going to be back with more "Techstrong TV" in just a minute.