Cybersecurity Implications of Generative AI Platforms – Jim Reavis, Cloud Security Alliance
Cloud Security Alliance CEO Jim Reavis dives into the cybersecurity implications of ChatGPT and other generative artificial intelligence (AI) platforms that are under development.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Jim Reeves. Who's CEO for the cloud security Alliance and we're talking about the impact generative AI platforms such as chat GPT will have on security. Hey, Jim, welcome the show.
Hey, thanks for having me. On the one hand people will tell me the sky is falling the bad guys are gonna use this and all hell's gonna break loose and society as we know it may come to an end on the Other Extreme. We have security folks are saying this will level up playing field and we've never had a better opportunity and there's probably some truth in the middle somewhere.
What's your take on what's going on here from a cyber security perspective. Yeah, I think it is sort of that Middle Road that we are currently experiencing right now. This is certainly like the biggest topic probably in in all of Technology right now and I certainly know it's a big Board Room issue from all the conversations.
I've had so look when you have a new technology and you could argue whether how new it is but it being delivered as a service like Cloud many years ago. It opens up the ability for experimentation to basically all of humanity. And so you are seeing the examination and usage of this for for good for bad.
And so with any new technology like that. You just can't put your head in the sand you you figure out how to use it most productively how to limit the negative uses of that technology. And so that's really our focus is let's not panic.
This is not the Matrix. And as I said, Previously if we work really hard in putting guardrails into sort of this childlike version of AI maybe it'll grow up to be a responsible AI adult. And the issue is that there's going to be a lot of these children running around.
I mean everybody talks about chat GPT, but everybody I talk to has got some sort of research project involving a large language model on a narrower set of data and that stuff maybe wind up being more useful and maybe more troubling. Oh, I think we're gonna have a huge amount of innovation and you know, essentially they've thrown a lot of Hardware a lot of Technology on this, you know, Moore's Law continues to have those sorts of benefits and you're gonna see the scenarios of generative AI actually building more generative AI it's doing a lot of coding right now. So I'm seeing a lot of really cool things that are happening but it is it is hard to say who's who's going to sort of win the market and and because there are a lot of interests what's really important to me to Circle back on is this is AI delivered as a service and when you have that you're going to not just have the creators of that technology that are enabling that I think Microsoft's most well known right now for having AI integrated in Azure, but it's the fact that Gonna have thousands and thousands of entrepreneurs and other sorts of organizations that are going to create their own ai-enabled applications large corporations are going to create ones for their own use.
So you're going to have this huge ecosystem of applications very rapidly and so a few examples of it this week on the on the showroom floor or more actually just in discussions with some entrepreneurs on on what they're doing. So it's just kind of giving you just sort of a brief thumbnail sketch of what's gonna happen in the future. But again, it's AI is a service open to everyone and so the The Innovation is we're just gonna be looking at it week by week this year and just gonna be amazed at all there.
Here's a new way to use it that we hadn't thought of Is this going to be a case of letting a thousand flowers bloom or do we need to take a minute and have a conversation about how all this stuff is going to come together? I think we need to do it at the at the same time you have to do this simultaneously. I just I don't think there is sort of a divorce to small group of ethicists or other sorts of experts that can just tell everybody.
Okay slow down. Let's go take a look at this. I don't know who would do that and and frankly, I don't think it's it's feasible because that people will cheat and there's people who would take any sort of a pause as they opportunity to maybe make some advances in their own AI technology.
They're working on I think if you actually have that thousand flowers blooming and you have a bunch of use cases right now that people start working with and we create some broad-based awareness and guidelines and best practices that I think that's the best way again because I don't see this is Matrix level technology at this point. So if we really understand all the ways, it can be used and people are going to use it and work. To secure those areas then I think we're going to find that we're just going to have that Corpus of knowledge that's going to allow us to as it gets more advanced to have better ways to to deal with it.
So that's the Pandora's Box is open. And so let's go make the best of that situation. We know that in cybersecurity you are going to need AI to fight malicious use of AI so we got to kind of go on that.
There's really not another way to go look at it. So again don't panic let's take that Middle Road and there's no no reason for an organization to go wildly adopting AI without like really understanding how it actually solves the business problems they have so you take a look at that. You understand what it is you're trying to solve but I do think that it's it's a smart idea to be experimenting with it and and again doing that carefully and making sure you're not doing things like putting intellectual property or special things Privacy Information citizens information personal information out there.
You got to have some some really good controls around those things. But yeah, I think it's it's experimentation right now and let's let's be ready to counter the actions of the malicious attackers, which we haven't seen yet a big way of of AI as a service malware, but we have to expect it's coming pretty soon. Aren't we somehow finding ourselves in the equivalent of a cybersecurity AI arms race because the bad guys are going to be playing with this as well, right?
Yeah, well, I think we are we have been in a cybersecurity arms race for some time. And this is somewhat of a of another Frontier another front in the in the in the war that we're gonna see this this battle on but you know, we've seen this with with Bots and botnets and just about anything you can sort of think of that that so much of vulnerability scanning and and there's I'm old enough to remember when in encryption was considered to be Munitions and for export control by the US government. So yeah, we're we're in that that cyber security is National Security more and more and this is a new front in that war.
Do you think it will drive more of the focal point for cybersecurity into the cloud because we need a significant amount of data to train the model and that's not going to happen with the average Enterprise won't have enough data to do it on their own. So does that kind of force the issue? Yeah, I think there's there's a a data issue for these large language models and and you're gonna see a lot of different ones where hey maybe a smaller data set is is good for specific things you're doing but by and large the the size of data and the hardware requirements this point I think are going to sort of drive this to be delivered as a service.
Why why do it any other way even if you can afford it, I think there there is there are not so profound. I think that you wouldn't sort of do it that way. So that's that's how I expect to see it sort of evolve and and roll out and it's just I think we're gonna see a lot of interesting applications coming out of that.
Should cybersecurity folks be studying prompt engineering now or will there be tools that make all this accessible at a higher level of abstraction? Oh, I think that cybersync the The Rankin file cybersecurity professionals that need to understand how to use this understand how it works. Just one example.
I I saw an organization developing a a cloud incident response system. That's using chat GPT to take in indications of compromise and and have it come back with very specific custom playbooks on how to respond for that specific issue. And so whether you're you're a developer that's like creating those tools you're seeing more and more of experts that are having to be somewhat of coders and doing so many mashups and you know as part of how how devops is working.
And so yeah and you got to do that in the cloud. This is really really gonna be primarily cloud-based. So the The technology companies they need to put it pretty rapidly on their roadmap to see where this will enhance their Solutions and and and enable more automation.
But then the rank and file cyber security professional certainly, they they need a level of Competency in how you use this and how you do integration whether you're using directly at the prompt or your trying to integrate it with apis, you need to understand how to use it because you're just you're not going to be able to keep up particularly when you see that wave of both good usage, but also malicious usage. I I would anticipate it's going to just We're not gonna have enough bandwidth in the typical sock to handle it without using using generative AI in a in a wise way. Is the whole pace of security going to accelerate then because I'm gonna have the incident response ready to go.
I'm probably gonna push a button to automatically execute it and all this is gonna happen maybe faster than the average human is able to keep up with so is this gonna be Machine versus machine and we're just gonna set our strategies in place, but ultimately the execution now is left in the machine. Yeah. Yeah, I mean we do have a fair amount of Machine versus machine right now and we examine the logs to just understand the health of how those things work and as the blocking working correctly and are we noticing some exfiltration we're noticing that after the fact if the machines did did the right job but you're your points will take it just it really takes it to the next level.
And so then you are looking at those those indicators of maybe a closed loop automated system. You're you're looking in different areas and maybe at more of a metal level and you're looking at you know, what how did it handle thousands of potential incidents versus maybe a handful. So so yeah Pace Paces definitely the the bandwidth the the volume is what we can expect to to grow but I think you know again understanding this understanding how it works and understanding how you can use it to take some tools.
It's it's not gonna it's gonna not change the principles of how these this the sock or the the Security Experts have to operate but they're tooling is going to be different. They're going to be examining just like different data sets to understand the health of their systems. What do you think will be the ultimate impact on this chronic shortage of cybersecurity personnel, we've been dealing with for the last few decades.
Are we gonna be able to kind of reduce that because the folks we have in place are going to be that much more efficient. I think that sort of Nets itself out and you're you're gonna still have this shortage issue you are you're going to make these these people more efficient, but they are gonna have a bigger job too. And so I think that's still Workforce is still critically important.
I think it's what's really important for if people are thinking because this was a question that came up a couple times at RSA is chat GPT and things like that. Is it going to automate cybersecurity professionals? It's gonna put them out of a job.
It's absolutely not as far as like I can see it's going to allow them to definitely do more but their job is growing and so we still are gonna have that Workforce issue that problem right now and and I'm seeing a lot of really good things in terms of hey, let's go in more of an apprenticeship model and let's let's sort of streamline some of that education and that readiness But yeah, I think it's sort of Nets itself out and we're still going to find we need more cybersecurity professionals. All right, folks Sharon here. The roles are going to change but we're all gonna continue to report for work as usual.
Hey Jim. Thanks for being on the show Absolutely pleasure being here right back to you guys in the studio.