ChatGPT in Cybersecurity – Stephen Carter, Nucleus Security
Nucleus Security CEO Stephen Carter explains exactly how AI platforms such as ChatGPT will be used for both good and ill in cybersecurity.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're talking with Steve Carter. Who's the CEO for nucleus security we're talking about chat GPT and how it might be used for nefarious purposes Steve while the show Hey, thanks for having me Michael. Appreciate it.
So an AI circles this whole model language platform that people have created for doing all kinds of interesting things is all the rage, but some of that folks in the cyber security world are pretty concerned about how much might be used for something else entirely. So what exactly should we be worrying about? Well, you know for starters, I think it's probably good just to set the stage and and mention a couple of a couple of facts that folks might not be aware of right?
The first is today vulnerability exploitation is the number one threat facing cybersecurity threat facing organizations today. And this is kind of a new thing. Actually I think going back just a couple years.
It would have been credential reuse things like fishing where the top cybersecurity threats and really 2021 was the first year that we saw vulnerability exploitation become number one technique attackers are using the compromise networks and and the number one initial access factor and ransomware attacks as well. So this is really why I think this is such an important topic but should we be worried about it? Right?
That's that's a big question. There are a lot of different angles to that but I would say, you know for starters, it's absolutely something a technology that can and and we'll be The weaponized at some point and and there are multiple ways that tools that tools like chat GPT and Technologies similar Technologies can be used by attackers for vulnerability exploitation. So how exactly would that happen because it's pretty easy to see how it might be used for fishing attacks, but it's not clear to me how it might be used for vulnerabilities as well.
I mean is the thing smart enough to identify them or is it just going to give me helpful hints if I'm a hacker? Yes, so it really does two things two important things one is that it can identify vulnerabilities and code really? Well.
So today you can feed chat GPT source code and it can identify vulnerabilities in the source code in the same way that vulnerability scanning tools, you know commercial vulnerability scanning tools can do and and when you think about okay, well, why is that a big deal? Right? We've had vulnerability scanning Tools around for years.
Well, I mean historically it was really cost prohibitive for attackers to scan open source code repositories or just or just code at scale and that's because the tools that you need to do that are really expensive. And so the potential here really is for chat gbt and I think similar similar Tech to be used by attackers as a potentially free or very affordable static code analysis tool that can identify vulner. All these in codes.
So for example, it might be possible to monitor all open source code repositories and scan them for vulnerabilities and almost near real time as as they're being updated and commits are being made. So that's kind of one angle and then of course, there's the the exploitation side of things and how chat gbt could be used to to help you develop exploits for the vulnerabilities that it helps you find. And I think we're underestimating how many vulnerabilities there really are and all these Legacy applications that we have out there in the volume of cybersecurity technical debt is immense.
So is all that's going to come home to roost now. Yeah. No, that's a great point.
Right when you look at the the national vulnerability database which is really like kind of the source of Truth for all publicly known vulnerabilities in in software. That number is Rising by about 30 to 40 percent each year. So 2022 we saw I think was just over 24,000 new vulnerabilities disclosed to the public and and all you know software.
So that includes of course all your normal Microsoft Adobe type products, but also all of your open source projects just six or seven years ago. I think that number was around maybe seven or eight thousand new vulnerabilities, so it's continuously rising to your point and and just becoming a bigger and bigger problem. So so yes, I would say it is is already come home to roost in the sense that attackers have taken notice and are now putting most of their focus and energy into vulnerability exploitation.
We have not patched a lot of those vulnerabilities. So that happens for a wide variety of reasons. But do you think that we will see developers being asked to patch many more vulnerabilities much faster in the coming year because we are about to have this kind of holy crap Batman moment.
Yeah, I would say in most at least most Enterprises, right? I think developers have already caught on right I think the average developer today is pretty aware of the threats and and the risk out there but I would say that they're struggling to keep up to the point that you mentioned earlier just the sheer volume of new vulnerabilities that exist and on top of it most organizations today. Actually, I think on average on average organizations Develop and maintain over 400 custom applications themselves.
So not only do you have the vulnerabilities and products and open source tools. We have vulnerabilities that your your devout your own developers that work for you are are accidentally building into the software that they're creating for your business. And so you just have such a volume of vulnerabilities here to not just identify and fix but there's a process in between a vulnerability management process that involves really assessing analyzing triage and all these vulnerabilities after you found them to figure out which ones are most important right?
Because a lot of for example in nucleus a lot of the the customers and organizations, we work with have over a million vulnerabilities. So one of the hardest problems just figuring out what do I fix first, you know if I've got a million, how do I stack rank these things and figure out which ones actually represent the highest risk, which is a really hard thing to do. So one of the things that we look at just kind Tying this back into to Ai and exploitation.
One of the top things we look at is is this a vulnerability that's being exploited in the wild today out of the million that you have. It's probably a very very small percent that are actually being exploited in the wild today. What is that going to look like a year two years from now as Ai and and chat gbt type Technologies evolve and can identify and exploit vulnerabilities really at scale much much faster.
Will the good guys be able to use Chad GPT to find the vulnerabilities within their own environment? Hopefully first? yes, and and I would say that that's a great point and you know as as scary as all of this sounds or might sound I don't think it's all doom and gloom in the sense that I think we will have kind of level footing here and and that the good guys will have access to this same Technologies.
The question is especially in the context of large organizations that often move slow and adopting new technology. Will they use it quickly enough, right? If the bad guys start, you know using this today.
How long will it take for the good guys to say? Hey we could we could use the same technology to identify vulnerabilities in our software and and at least, you know have you know, the same type of capabilities as our attackers and large Enterprises tend to move really slow but I think the ones that can move quickly and adopt the technology quickly. We'll be the ones that are better the safest I should say.
Are we involved in some sort of AI arms race now when it comes to cyber security the bad guys are using it the good guys have access to it. Is that kind of where we are and we should just get used to the idea. Yeah, I mean, you know, what's interesting when I when I think of arms race, I really think of who's developing the technology.
So I would say I mean, it's the good guys developing the technology no question, you know companies like openai and there are a lot of Alternatives out there that are you know, open source and things like that. These are all great technology companies. The question is how is their technology going to be used in applied?
And in in that sense? I think there is a form of an arms race and that you know, if I'm let's say a commercial vendor and I'm selling products to identify vulnerabilities. I might very well use chat gbt and and that technology to help me do a better job of identifying vulnerabilities and then at the same time if I'm an attacker, you know to the example earlier.
I might use this technology to now identify vulnerabilities at scale, you know across the that in a way that gives me an advantage over larger slower organizations. And so it's more about the arms race of how is the technology being used not so much how it's being developed or who's developing it? As we go forward what's your assessment of the current state of AI and cybersecurity for a while?
There are people were talking about what we replacing people and then we won't eat all these unfilled job positions, but I don't know if that's a reality or not or what's your sense of? Where are we? I think we're a long way off from that at least in the cybersecurity space, you know, especially on the on the technical side when we look at technology like this, especially chat GPT and how it can be used.
Let's say and in a marketing capacity creating content things like that. There's certainly some concern there that it's going to replace people or you're not going to need quite quite the staff that you would previously but when it comes to the actual technical roles in cybersecurity. I don't see I don't see artificial intelligence replacing people too much.
I think more than that. We will see automation replacing folks because there are still a lot of very manual processes that cyber Security Professionals have to perform and you know, and and the world I live and we're all we're very much focused on vulnerability management and that is an area of cyber security. That's notorious for a lot of manual processes.
But that can be solved just by automation right doesn't really need artificial intelligence. It's just Automation and so on the on the AI side it's you know, there there are features of most cybersecurity products that are leveraging AI but they're just smaller features. So I would say it's it's useful in cybersecurity, but I think we're quite always off from it actually replacing folks and a significant way.
Flipping in the other side which you want to work in an organization that didn't have access to AI for the cybersecurity team because it's a pretty stressful gig as it is today, and maybe I need something to kind of levels the playing field a little bit. Sure. Sure, you know I I think I wouldn't want to work in an organization.
That's not leveraging all the available technology to do the best job. They can at defending at defending organization, which is really the mission of the cybersecurity team and and to that extent there. They're really isn't a lot really aren't a lot of tools out there that are what I'll call production ready to use, you know and and special in large Enterprise context that are that are just you know completely reliant on AI the biggest area that that we've seen AI really shine and cyber security is really on endpoint technology.
So just kind of think of it like antivirus technology where the old technology would just have a list of a virus signatures and that had to be updated and pushed out in the new technology is heavily leveraging AI to identify the A software that is is trying to be executed on computers and block it in real time. And that's super powerful and is a great use of AI but that's a great example of my point earlier and that that didn't replace anyone right the old the old antivirus software was just kind of doing its thing and it was moderately effective the new this next generation of endpoint antivirus is much much more effective leveraging AI but didn't replace, you know didn't replace any people. All right, so we're at the start of a new year.
So everybody has to get their crystal ball out. What are you expecting to see happen? Well, you know like like everyone else is saying there is so much focus and energy being put into into AI right now that I think will see a lot of really creative tools pop up that are using the apis for things like chat GPT to do lots of you know new and interesting things.
I think also we'll see the technology like chat GPT evolve much more quickly because there is such a high such a high interest in it. I think we will see cases of of AI being used in weaponized by attackers, but I don't I don't think it's going to be, you know game changing this year and that sense, but I think more more so we're just going to see a lot of really interesting software and tools pop up that are leveraging Ai and ways that you know, we wouldn't have even imagined just last year. All right function.
I heard it here lots of things happening in the land of AI keep paying attention here and frankly though. I can't be a hundred percent sure that that's actually Steve Carter these days, but I think it's Pinky Promise. All right back to you guys in the studio.