Data Lakes and AI in Cybersecurity with Anvilogic’s Karthik Kannan
In the wake of picking up an additional $45 million in funding, Anvilogic CEO Karthik Kannan explains why data lakes and artificial intelligence (AI) will play a pivotal role in improving cybersecurity.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Karthik Kaing, who's CEO for Anvil Logic, and we're talking about the interest raised an additional $45 million in funding to bill Data Lakes that will be applied specifically to cybersecurity and all those security information event management slash what we call sim platforms because well, we need all that stuff for ai.
Karthik, welcome to the show. Thank you, Mike. So outline the plan, if you would.
As I understand it, you know, most of these AI platforms are only as good as the data that they take in and it directly correlates to the output, and we've been a little skeptical of the usage of AI and cybersecurity anyway. So what's your view of how all this plays together? Sure.
Well, first of all, as you rightly said, it is about the data and how you normalize and make sense outta the data before any kind of algorithm can help you. So first things first is architecturally being set up the right way. And that's what we built here with our multi-data platform sim.
And the logic has the ability to create an analytics layer and a workflow automation layer on top of where the data sits today. Architecturally, uh, legacy systems are built in a very monolithic way in that all of the data needs to come into one place and there's proprietary technologies built on top that layer, layer on top and then bring you analytics and which you have to custom build yourself for the most part. Also, what we've done is shattered that monolithic paradigm.
And what we built out is a multimodal approach to the problem. So you can have some of your data and a legacy like Splunk, some of your data, the newer cloud, what we also call dark data coming into a snowflake through our pipeline, and then an logic, uh, conveniently correlating across all of it. So you have the benefits of maintaining, uh, a cost, um, uh, and reducing cost.
You don't have a vendor lock-in problem like you would have had in the past, and you're leveraging newer platforms like Snowflake that are geared better for AI workloads. So once we get this architecturally in the right place, now you can get AI to work for you. For example, we have, you know, built in algorithms for purpose built for security threat detection.
They can fire better with the data and the data warehouse that we are able to set up in a snowflake and leverage some of their inbuilt functions to deliver better AI based detections. We have a copilot approach that automatically, you know, works for you and behaves like a pure analyst so you can do your job much faster. So all of these are brought to bear in this fresh new architecture that we've built.
So am I moving data or am I just kinda in a federated way taking advantage of things like, I don't know, data virtualization to kinda create some metadata that I can therefore analyze and act on? Yeah, That's a, that's a great question and point. We don't necessarily need to move any data around, uh, because we like to work with the laws of physics, right?
There's natural gravity that data has and when it settles somewhere, who are we to kind of pick it up from there and move it elsewhere? And why should we? So when data naturally sits in places, for example, in S3 buckets or in a snowflake, uh, data lake or in a legacy, you know, Splunk let it sit where it sits.
We don't need to move the data around, let us query what is needed because we are purpose built for security threat detection. We know what sort of signals we are looking for and our AI hunts for those signals that we are not looking for. So we are being very purpose built and specific and deliberate in our approach here.
So we query what we want. And then the metadata, as you rightly put it, those are the ripe signals on top of which you can build more scenarios, you can do some threat hunting and let your AI go and find net new things that you weren't looking for. So that's really the new name of the game in our opinion, is let the raw data sit where it sits, but let's build a layer of intelligence on top and then do all of your hunting notebook style or otherwise on top of all of that.
So elevate the game, so to speak, so we get better results for the investments we make instead of kind of hunting for that, um, needle in the haystack. I feel like this has been the root cause of our cybersecurity woes for a long time. I mean, we have seen any number of platforms.
Everybody has five, 10, maybe 20, and they typically have something in them that would've identified some anomaly indicative of a breach or the breach itself. But we're unable to correlate that. And so we're, we kind of miss it until somebody calls us up and says, Hey, you know, did you know that a million records of yours are on the dark web somewhere?
So has this kind of been the, the missing link in our cybersecurity strategy because um, you know, it's been plaguing us for as long as I can remember. Yeah, you are a hundred percent right, Mike. Uh, you know, you can date back to, you know, the, the target breach from 2014.
It's been 10 years now. And you're right, FireEye did have signals in there that if you were looking for, you would've found. So in almost all cases you have some sort of data or signal that was there that was missed because of the fatigue and the volume of things that you have to go through.
So we were able to automatically sift through and automate some of the mundane and give you the better signals. The chances are infinitely improved to uh, be able to find what you needed to in time. So that's really what we are trying to do here is get your data architecture set right first present to you a first level we call identifier level detections that are the signal of, uh, base.
And then you build on top of that net new correlations or what we call scenarios so you can get better at detecting. And you don't have to do all of this humanly. All of these don't have to be pre-written, of course you have to have many pre-written and deployed.
But this is where AI comes into the picture too, where it can start to look for those kinds of patterns, signals that you've been training it to. So even if you didn't have a detection in place, um, you know, a product for instance, that we have called insights delivers value through AI to find net new things to you that your detections you don't have detections for. But we find something that has a pattern that we believe resembles that of an adversary and we surface it up, we spotlight it.
And so the customer can then say, look, I like that. This is what I'm gonna start my day with. I'm not gonna start my day with the raw data and hunting and ad hoc querying.
I'm gonna start from a richer point of view and then work my way back from there. So this vastly improves the accuracy. No, we are never done, right?
We are never a hundred percent, but if we can continue to keep improving, then uh, we are, uh, moving in the right direction. Another important point there is a lot of organizations knowingly do not bring data into their legacy for cost reasons, licensing cost reasons or sheer complexity of bringing such data in from the cloud into, uh, a legacy which is typically on-prem. So there is that dark data that we go to first as a use case and we say to customers, look, there's a lot of dark data that you and I both know exists.
Let's start with that. Let's augment your Splunk with the dark data. Going to snowflake with logic, connecting and being that unifying fabric that dramatically improves your posture as well.
How do we do this? And I'm asking a question 'cause I can hear the cybersecurity people now. They're gonna be skeptical of the fact that something can do that level of correlation.
'cause there've been problems this a long time. And to your point, the fatigue can be traced back to the number of alerts and I wind up chasing my tail. So what's different now than what we've been saying in some cases for years?
Yeah, well first things first is the architecture. Such a multimodal architecture has not existed before and the logic invented it. So now we are able to query across and correlate across multiple systems of record.
That's number one. Number two, right from the get go, we didn't just wanna build a an automation platform, we wanted to embed it with content. So we have x soc practitioners on the team developing this with us.
So they, they bring an armory of detections straight out of the box. There's 2000 plus detections, for example, that are built out of the box available to deploy in our platform. So we are not just bringing you a platform that you can then go build your own detections on.
We also bring those detections and they are purpose-built multi multiple versions for different kinds of, uh, correlations and combinations of data sources. So these are continuously built and tuned and we have auto tuning capabilities in the product tool. So we believe the future is such a platform that is not only multimodal and work across architectures, but also has content embedded in it.
So it facilitates your detections. So that's, these are all what's different. And then you layer on top of that ai, now AI can actually work on better data and better normalization so it can produce better results for you.
So that's kind of the three, uh, levels that we have brought here that we think are the next generation of, uh, why this will make a difference. Where do the AI models come in there? There's predictive generative, and that is other things.
Yeah. Also, or whatever that's gonna be do. Is that something you're gonna provide or you're just making it easier for me to invoke those through APIs and using the data that's in the platform using rag techniques or whatever it may be?
How will that play out? Yep. All of the above, frankly, Mike, all of the above.
There's no one, uh, easy answer. We are not gonna bring you everything naturally. We are gonna bring you the, uh, platform and that's why we call it a platform, because you can build, you can build on top of that, it's extensible, but we have to give you the base levels.
We have to give you some advanced levels too. So yes, we embed algorithms into the platform. So there's predictive, the traditional predictive predictive style, and then there is the generative style.
Both are embedded and both are available in the platform. Now, you can go above and beyond that. We provide a notebook style experience for you to go do your own ad hoc building on top of the structure, because the biggest part, as you well know of the, the hardest part of any data scientist is to bring the data into a shape that can be then fed into an algorithm.
Because if the data isn't in a shape that is consumable, uh, you can have the same data scientists produce two different results on two different days with the same data just because it's not in one shape. So once we bring it all to you in a certain shape, you can run your own algorithms too, because who are we to say that we have the best and the only algorithms you will ever need. So our platform makes it a possible for you to run on top of that too.
Build your own custom detections and algorithms. So it's the best of both worlds. So that's why I say all of the above, Mike, because you hit upon all of it, right?
All of those components are important. The data and organization is important. Not having hidden doc data is important.
Having a platform, an extensible platform to run beyond the algorithms that come out of the box is important. So a notebook style hunting experience is important. So all of the above, I think, uh, that is the formula A lot of folks are concerned about.
The bad guys have access to ai, but, um, so the good guys and who do you think might benefit more from AI at the end of the day? Well, I think we have to do what we have to do, right? It's often said the bad guy has one time to win and we have a hundred times to win.
Um, and that's the burden we carry against the good guys. But that's, you know, why I think companies like us get funded, right? With the, you know, money, like $45 million.
It can be spent in a variety of good ways to continue to build after all the same technologies are available to both the good guys and the bad guys, right? So there's no reason why we cannot continue to win, but we have to be on our guard every single day. And the easier we make it for our people, our so practitioners to not have to be developers at the same time, that's our job.
So they can do their job better, which is to be smart practitioners who understand the threat landscape and adversary patterns. Let us allow them as vendors of technology to focus on that. Let us take the rest of the burden outta the picture so we can be the technology providers to them, they can be the security practitioners.
Until now, it's been the case that the platform providers just pro provide, you know, a, a platform and then the develop the, so practitioner has to be both a developer and a SOC practitioner at the same time, and sometimes a data scientist. Now that's impossible. Now we are not giving them tools they need.
So we are saying let's automate, we take care of that burden. You just focus on being the security practitioner that you are. So the programming part, the data part, all of that is taken care of by us.
What impact will this have on the cybersecurity shortage that we've been dealing with for as long as anybody remembers? I, I wonder if a lot of the effort is just on manual toil, that if we eliminate, maybe we don't need 3 million more cybersecurity professionals, we'll always need them, but, um, can we get better smarter about this? A hundred percent You answer the question yourself.
This is, this is exactly what we say is that shortage is because we expect too much. We want them to be data architects. We want them to be programmers, sometimes data scientists and then practitioners too.
And then we lump practitioners into one group. They're not one group at all. First of all, if you took away the burden of the other surrounding stuff, then the practitioner need for practitioners is not that many.
And the practitioners themselves also are different people, right? We, we just lumped them into one big group. There are detection engineers, there are hunters, they are rinsed and responders.
You know, there are just triage investigators. This, we've gotta empower all of them. And then if you do that, then I don't think it's a shortage.
We have talent and we have now technology to support the talent. You know, we've always been right from the beginning as one of our bigger, uh, customers, uh, often calls us a force multiplier. And that's what I, I think we have the burden as technology vendors to be, is to be a force multiplier so we can help those organizations, you know, not need the 10, 15, 20 practitioners rather four, five, or six and use technology to amp it up.
How do I figure out the ROI math to justify this investment? 'cause a lot of a organizations are under pressure from a budget perspective, but, um, in general, it, it's hard for the security people to kind of prove the negative, right? So how do I kinda go to the board and say, we need to make this level of investment.
And here's what I Think the first thing is to, um, have a more, uh, tangible, uh, ROI calculator that is more in your face with hard facts. See, sometimes we have this, uh, habit of, and we ourselves have been guilty of is to say how much more value we provide that would've taken you five practitioners to do. And therefore the ROI is a half million because we don't require you to have five more practitioners.
While that is true, now, we've really, uh, uh, gone to a slightly different, uh, uh, more of approach, which is, let's start with the hard facts. When we show you to architecturally what you were spending, putting data into a legacy like Splunk, and now bringing net new dark data into a, uh, data lake like snowflake through our ingest pipeline, just the cost economics of that architecture are a pure statement of fact. We are not adding any kind of, uh, you know, neg, uh, uh, uh, you know, approximations or assumptions, hard facts.
First, let it, let us show you architecturally how you can save a ton of money to almost make it as one CISO called it a self-funding project. That's the good beginning right there. Now I say I'm saving costs and architecturally more modern.
Now let me up the game and do better. And therein comes the, at that point comes in the post multiplier effect, which is a true statement, right? I mean, you, you wouldn't need as many analysts if you had an automation platform like ours.
All right folks, well, you heard it here. Begins with the data. Ends with the data.
It's always been about the data. We just get a little sidetracked sometimes. Hey Kar, thanks for being on the show.
Thank you so much. Thanks for having me, Mike. Alright, and back to you guys in this team.