Cybersecurity, AI and Data Science – David Reber, NVIDIA
David Reber, chief security officer for NVIDIA, explains why it will become simpler for cybersecurity teams to benefit from artificial intelligence (AI) as data science continues to evolve.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with David Reber who's the chief security officer for Infinity? He's also ahead of product security and we're talking about all things related to Ai and cybersecurity. I guess my first question to you.
David is a welcome the show would be we've been here in almost constantly a stream about how chat gpteen all these AI platforms will be the new vein of cybersecurity and I guess I just want to know from you. What can we look forward to from AI in cybersecurity for the good guys? Well, first of all, thanks for having me today and looking forward to our conversation and looking at that there's been a lot of discussions as you mentioned about the adversarial advantages that comes with chat GPT.
One of the things that I see coming with the future and even here now is it's security is in the daily life of everything. We do everybody in the company. The human always has been the weakest link in the equation.
And one of the things as cyber Defenders we need to find better ways to do is get information into the hands of the people that are making decisions in real time. So when you have an admin or a developer configuring something say on an S3 bucket, how can you get them real-time information of good decisions and bad decisions. So the technologies that enable the ability to say automation of writing malware and fishing campaigns can also be used defensively for how do I properly secure this?
How do I make good decisions? How do I know? This might be a phishing technique that is one of those areas that we're really exploring figure.
How do you enable that to the defenders in addition to the standard cyber problems, which is more of a data problem in and of itself, which is how do we process these massive amounts of information and find the needle and the stack of needles when an adversary is in our Network. I think this comes to the heart of we've been talking about now for I don't know the better part of three or four years about Ai and cybersecurity and some people are still gung-ho about it and others are a little more skeptical and I think probably the truth is somewhere in the middle, but I'm the question becomes and what is the current challenge because a lot of folks would say the AI that they see today really only works on some fairly wrote stuff. So, how do we get smarter?
So one of the challenges I think is the it's a dichotomy, right? We need to let the machines do what the machines are good at and let the humans do what the humans are good at and I think a lot of people when we test step into that cyber world or cyber product portfolio. We want this the thing that just works we want the one button click and it's gonna find every malware ever or find every Rogue login into your network and you they want it to just work completely.
So we quickly dismiss it as oh it doesn't work because it didn't find this one use case. What we're finding is we continue to to look at as an industry is starting to figure out well in ai go be able to take terabytes of information down to a handful of events that the human analysts can go additionally respond. We're also seeing it useful in whenever you have a known compromise.
How can you find everywhere where they went on the network? Because you have more knowns in those cases and that's where you're starting to see it start to work start to formulate and work better in addition to being able to answer simple questions. Like Hey, how do I secure this or right secure code?
We're starting to see that that progress and I agree with you on that. The the truth is somewhere in the middle. Right.
The perfect AI is not there today. But the same time it is helping accelerate human capacity more than having nothing. Will is get better because the processors are getting faster and they can look at the data and train the AI better or is it we're also getting better at training these models using less data, and we don't need as much data than necessarily come up with the right answer and that's gonna lead to more rapid advances.
So I mean naturally more processing power is going to help but I think it I think it's more on the latter is knowing what to train it on how to train it how to do it in on supervised ways and then where to apply it and then getting the outputs in an explainable way to those that can take action. I think that last mile part is one of the cases that we struggle with as an industry is how do you get that information that last mile to make it successful successfully used because you don't it's not like a car where you'll know if it's successful or not real real time in in the cyberspace. It's sometimes it's that information in getting it to people Downstream to be able to make those changes.
And we need to change our approach to cybersecurity to take advantage of all this because historically we had a lot of workloads running on premise and we still do but frankly, I'm not sure we could collect enough data to really train AI models for an on-premise environment. So is it going to be easier to secure things in the cloud because we will be able to more easily aggregate the data train the models and kind of see what's happening across multiple accounts owned by multiple companies and we can kind of circle the wagons better. Whether it's cloud or on-prem, I think the coming together as a collective defense across organizations is the challenge we have to conquer together as an industry.
Um adversaries the same adversaries will go after multiple companies. How do you enable that sharing and that training of information that may or may not have sensitive information about your competitor or your partner. So I think those relationships in the way to do information exchange with high bandwidth a high fidelity that doesn't in need intellectual property protections is what's really going to be that that next Evolution cloud and on-prem is just how much compute do you have where how much is a geographically dispersed in data movement.
Those are all technical challenges that challenge is that inter organization sharing so we can have a collective defense against industry adversaries. Early on there were a lot of folks who were like dismissive of AI and cybersecurity in particular. My skills are too good and no machine will never be able to do that.
And I think maybe we're coming to another mindset where people are going. I'm not sure I want to do this job without some help from AI because it's kind of stressful and so, you know are people's minds during a change and go. Yeah and get me some more this AI because this stuff is gonna basically drive me around the bend.
Yeah, and I think what we're also seeing is as even the average Enterprise the tech Stacks are becoming more and more complex for them to do their basic bookkeeping their basics of just sustainment of that Enterprise. So when it used to just be I knew how to secure a Windows laptop with my windows servers infrastructure in my networking equipment that mindset could could apply and could be successful. But now you add in layers and layers of Open Source and a complex supply chain, even for your most basic Enterprises.
You can't hire enough diverse skills to focus on that. That's where I I see the Promise in Ai and we're seeing results in that being able to elevate those critical and those High issues to the defender. So they can process those mounds of information and make those decisions more rapidly even in technology is domains.
They may not be the deep deep expert in where you're sock analysts were before. How do you see all this changing the relationship between the security teams and the rest of the organization we've seen ship left where there's more stuff going out to the developers who may or may not know what they're doing with various application code and we've seen shift right where we're using the IT team then to take over security operations. But as we throw Ai and that makes how do you think this might all play out?
I'm hopeful that it really starts helping go after that philosophy. I mean the majority of security issues is just proper it. Proper operations, right?
So a lot of Security Solutions are putting Band-Aids on bad asset management or they're putting those kind they're going after those areas where you're just weak in those foundational building blocks to run an Enterprise Network. So as we've gotten into devops, right a lot of that automation has helped clean some of that up and what I'm hopeful is that the AI we can continue to find ways to then work smarter. I mean Stevie's are released every single day.
It's hard for our developers to keep up. So how can you use that to prioritize the work in all of those open source projects everything that you use within Enterprise, so we're not just investing in patching just because there's a cve of patching and the ones that are actually exploitable and reducing the time to do that analysis. So when you look at that, it's both proactively getting that information when developers doing development in addition to reactively when things come out how do you help them prioritize the Investments on what to go fix for second third?
Do you think we'll get to the point where I can just walk in the office and ask Alexa? Hey, what are the three things that are likely to get me fired today and which I think first I hope so and that that's where when you look at chat GPT or other things like that. Like it's how do you I big believer every offensive tool can be a defensive tool.
So when we start looking at how can we train it for offensive techniques? We just got to look at the inverse or use that as the way to identify where we have to invest in defensive Investments. So hopefully the answer is yes one day you can say hey what are the most easiest ways into my network and they'll be able to highlight those or the top quickest ways into my network.
Hopefully one day we'll be able to train that model bidirectionally in order to help prioritize for the Defenders. We live in uncertain Economic Times and everybody's trying to figure out you know, does that mean we're gonna reduce spending on security or increased spending on security. What's your sense of the business folks appreciation for cybersecurity these days and they're willing to funded because historically it's always been kind of like, you know, Security was a percentage point on a larger it budget and it never received the change but maybe our minds are evolving.
I do think we're starting to see more regulations across the globe that are trying to put it in in the boards make it front and center and but that's more a forcing function. I'm a big believer in looking at how do you make security lesson Insurance problem of how much do I want to invest based upon what I'm willing to take risk on but more is that business enabler function. I think with with specially AI you're going to start seeing even more sass startups and cloud services come in which credit security is Paramount into the success of those businesses.
You can also offer it as a security features for those companies. So hopefully what we'll start seeing as as the AI takes on and we start becoming more prone to protecting of data in our data Supply chains, you're gonna see a bigger emphasis because data can move and if the data is gone the model's gone. You've just lost your intellectual property.
Versus the I just lost my cloud service. So hopefully we'll see that pivot more. I think what will also start seeing is a focus on rather than a thousand or hundreds of cyber tools.
How do you get into a more narrower portfolio? So for the AI to be successful it has to integrate with the things that the Enterprises have no longer. Will you be able to just have a whole plethora of solutions to go after the problem you're going to see a decrease investment of a bigger portfolio tools is probably that shift that we'll see and I mean it's gone you're in history that way as well.
Do you think the bad guys are discovering AI I mean have we inadvertently found ourselves in something that feels like an AI armatures? Um, I do I do think that they're looking at how do they scale? I mean the age-old challenge has been the attacker has to be right once Defenders have to be right every time as an attacker though.
How can I scale to go after this Enterprises generally required a linear kind of growth with human capacity now, I think with AI how do you tailor your fishing attacks? How do you tailor exploits forgiven environment? It's going to help accelerate the attackers and to your point.
I do think it then turns into that whole who can use AI more smartly with going after whether you're the adversary or you're the defender. You've been doing this for a while. Obviously.
I'm what is that one thing that you see organizations doing over and over from a security perspective and you just shake your head and go guys. Can we just move Beyond this? What are the things?
Is when you invest heavily and you only focus on the most advanced techniques and tactics. You miss the simple things. What I see organizations is they always move on to the new toy the new shiny object and they forget about I still have to invest in knowing where my servers are knowing what my internet footprint is your standard attack surface management capability kind of gets thrown out because it's not the new cool problem.
Or they're looking for the advanced way when in reality identity attacks continue to be the leading Trend, right? The human is continues to be that weakest link. So investing in where you get hit the most.
You can need to not let that go just because you think you got the new capabilities. So do you think organizations should be mapping out something that feels like two to three year plan for cyber security and AI I mean can I predict what kinds of technologies will be coming down the pike and kind of plan accordingly or is this space just moving so fast that you know every day we're gonna wake up and it's gonna be something completely different. What I'm finding is setting up a good data governance in a good governance strategy now in the framework is important.
And the reason I look at that is These were organizations every company that is playing with AI or experimenting all of a sudden they may have a model they want to go take to market with the budding regulations or the hints of regulations around the Globes on explainability in AI trustworthiness in companies expectations. If you're not protecting the development environments from the it tax that we don't even know about today or the ones that we do know about today within within AI you could set yourself up for failure because you don't know where the data came from you trained it on data that you didn't legally acquire or you trained it in a Dev environment that was actually compromised because you're just experimenting today and it's that whole proof of concept to production that if you're not ready for as an organization and then these regulations come in or you find this great customer that but they need that explainability that AI trustworthiness then you're gonna be hampered with being able to make revenue on that quick investment that you just made that awesome finding that amazing. technology because you didn't put some basic guide rails in place is what I I'm seeing organizations the successful ones starting to do.
All right, no conversation about AI is complete without the inevitable question is my job safe or people's jobs going away or what is the relationship between the man machine interface gonna look like in cyber security? I really feel it's the we need to figure out how to make the machines do what the machines are good at and what the humans and let the humans Focus what the humans are good at. I think it's an acceleration of how do you get the relevant data to make the decisions and it's really it's going to be a partnership going forward and how do we be able to scale the humans in the deficit in human cyber capacity that we have across the globe we'll be able to scale that demand to meet the demands more smartly.
All right, folks. You heard it here chances are if you don't have some AI help in the future, you're probably not going to win the battle. Anyway, so you might as well get used to looking for some help.
Now. The only question is is how quickly might it arrive David. Thanks for being on the show.
Yep. Absolutely. Thanks for having me today.
Back to you guys next to you.