Future of AI and Security – Ron Bennatan, Imperva
Ron Bennatan, Imperva data security fellow, discusses the implications of AI in security. Ron shares how AI can aid both in developing defenses and creating attacks. He highlights the recent advancements in AI, particularly in large language models and generative AI, that could make phishing attacks more difficult to recognize.
Transcript
This is Textron tv. Well, the great pleasure to be joined by Ron Benetton. Ron is Data Security fellow.
Is that correct? Do I have that right? Yeah.
With Imperva, man. Great title. I love that title.
Uh, so, so we're, we're talking about AI and security and what the implications are, sort of different dimensions of that, Ron. And, you know, in my mind it's kind of easier to think, at least think through what the bad actors might do with AI or already are doing, maybe all the unknown unknowns aren't known yet, but of course, what, what are you, you're thinking about what we're either seeing or what we might see with AI being used as a tool by threat actors? So, you know, I think ai, you know, or any tool for that matter is, is something that, you know, helps all kinds of users.
Okay? It, it can help us when we develop defenses and it helps, uh, the other side when they develop, uh, how to, how to attack things. And so, you know, and that's a very, very shallow statement, right?
It, it almost means nothing. It's like any tool that adds productivity and AI is one of them. I think that in our case, what, what we're seeing in the last, you know, like six to 12 months with, uh, you know, large language models and transformers, and I, I, it, it, it's actually really important to understand, like, by, by the way, I think that what's happening is, you know, I'm, I'm, I'm kind of old, you can see it in my hair.
So I've, I've gone through a lot of, you know, I, I've gone through the internet revolution, like I remember a time before there was the worldwide web and mm-hmm. And, and I see what's, what, what, what some of these, uh, tools are providing as important and as disruptive as the internet is. So, and that's great.
I love it. And, and, and I, and I'm really excited about it for my kids. And, and at the same time, it's, you know, if you really think about, you know, what does the chat G p t, what, what is it good at?
I mean, the fact that people use it for everything, my daughter's using it to, to write assignments in Python, um, uh, or Bard or anything like that. You, I think it's important to understand what it really is good at. Okay?
Mm-hmm. Or, or why is it really new? What, I mean, I, I learned ai, you know, probably 40 years ago in, in university, but it was, it was garbage back then.
Okay? It's not what it is. Now, the thing that this thing is really good at, uh, that, that, that we, we couldn't do before, is everything that has to do with, uh, language, both understanding language and creating language and, and, and language for us as human beings is a fundamental part of our life, right?
Mm-hmm. Language is almost everything. It's what makes us, I think, different than our other animals.
It's, it's, it's, it's, it's communication, it's culture. Okay? Like different languages imply different cultures.
You go to Italy, you can see how the language and the culture are connected, okay? And so I think for the first time, you know, these, these, these algorithms or these machines have in many ways hacked part of our humanity. Okay?
They, they, you know, and it's, it's not, it's not, I, I don't think it's a chance that the, the, you know, forever the, the definition of a certain level of ability, the, the Turing test was the ability of you to sit in front of me or you to sit in front of something else and not being able to distinguish if it's, if it's a person or a machine, I think we're there. Okay? So the fact that the fact that these, these, uh, models are able to understand something in a very deep way, or at least to us, it seems like they, like, they understand in a very deep way and that they can generate output.
That to us looks like true communication and true language and, and true creativity is what is new, in my opinion. Okay? It's not this model or that it, it is this ability to hack.
And I'm using hack not as the word crack. I'm using it as a, not necessarily a bad thing. Create a create hack.
Yeah, yeah, yeah. It, it, this thing has managed now to, to, uh, to hack part of what makes us human. And so, and so, you know, for sure when we use it internally, you know, like we use the generative aspects of it, you know, maybe because it can generate, uh, it, it can, it can increase our productivity by generating, uh, unit tests or code, or, or, um, or, or for example, it's very good at classifying things or giving us attributes.
Okay? And, and forever, you know, we all know that good security is security that's based on attributes and not on hard, very specific, you know, atomic rules and elements. So these are good things, but on the other hand or the other side, it's also a tool that y you know, like, like we all know that phishing attacks are, are, uh, okay, you know, they're effective, they're generally effective, or they have been effective or, or whatnot.
I think this, for example, will totally bring us to a different level because now, uh, it, it, it is going to become much easier to hack the people okay. To do things or, you know, a person, especially an insider, is not necessarily a bad actor, but using some of these capabilities, they will, they could become bad actors, you know, even without being aware of it. And, and I think it, that's, that's the biggest risk that I see.
Yeah. And, and phishing seems like the low hanging fruit in terms of security threats, because they're already pretty darn good at it anyway. And today it's, it is, you, you get emails today, sometimes it's real questionable.
Like, is that a phishing one? Usually I can recognize him, you know, as I think about it, as we get really good on training l uh, LLMs and being domain specific. Are we gonna reapproach a day where, you know what, I'm gonna train this l l m on how Ron speaks and how he uses language when he writes.
Uh, 'cause I've read all the papers. Yeah. And I just did all this stuff, and now I'm gonna do a phishing attack in the organization, impersonating Ron.
And, and instead of the, the, okay, I've seen this phishing attack five times, so no, I haven't seen this one. 'cause it's unique, it's highly adapted to a specific person, company, or situation. Yeah.
You're, you're, you're, you're spot on that, that, um, you know, all, all the methods that today we ha we have or we think about in terms of, um, like, like how to distinguish between the bot and the human okay. All the way to simple things like, you know, uh, all the captions, all the, I'll call you and I'll say something, you know, all that's going away because all these things are, are trivial almost at this point. Mm-hmm.
Um, but, but, but, but, but your example is also, you know, I I I, I can't imagine it's very far from us that like, like I just read the other day, that now they, um, what was it that, uh, you know, they have a model where by the typing by the noise that I make on the keyboard. Mm-hmm. Right?
They can, they can. So, so it, it, it is going to be, um, you know, both like, like a two-edged sword. It, it is gonna be something that helps us and it is going to be something that challenges us.
Mm-hmm. And so, and so the, the question is, who's gonna be faster? Okay.
Who, who's gonna be faster? I think it behooves us, like on the, on, on, on the side that is trying to do good is not to be, not to try to be reactive, meaning not to try to wait until we see what, how these models are being used. Mm-hmm.
But, but kind of to extrapolate from what we're seeing right now and say, okay, be, and, and why do I say this? Because like for years we've had, um, this concept that, that, uh, we need to have, for example, an insider threat program. But because it's usually quite hard then, you know, it's all about the interpretation of, okay, we'll have a program.
The question is what are we gonna do with the program? Okay? Mm-hmm.
The program could be, oh, we'll run background checks. That's an insider threat place, okay? Mm-hmm.
And, and, and I think at this point, um, you know, we have to recognize that, uh, and, and we did go through, like as a general industry, we've gone through a bunch of these cycles, right? The whole concept of zero trust, you know, so we're, it, it, it is, we're not starting from scratch, but, but understanding that language, language communication, culture, uh, creativity is now, um, is, is now going to, I, I, I think it's gonna do two things. It's going to both increase the level of different, of, of some existing threat factors, and it's gonna create totally new threat factors.
So, you know, we, we can't really wait. We have to start thinking about, um, you, you know, what, how have we relied on communication and language and address that? I think, I think that's the new piece.
I, I, I, I agree with that totally. Because when, when we see something as truly disruptive, why it's disruptive is 'cause it disrupts existing mental models and views of the world, right? Practices that we have about how things work.
Now you have to say, okay, well lemme step back. Is my zero trust strategy in a world of generative AI or ai it, what changes? What if I think this won't work anymore because of that?
Why would that be the case? Yeah. So really take all of our assumptions, and I don't mean toss 'em out.
I mean, let's go back and reexamine 'em and say, well, what if that isn't true anymore? What are the reasons why it wouldn't be true? And what would we do if that's not true?
And from that, you'll develop some strategies of, well, we can't, we can't go change everything, just not knowing what's gonna happen. What would be worthwhile to invest our time and money and talent. Exactly.
Exactly. I mean, yeah. I'll give you an example.
Exactly what you said is, is, you know, if we, we go back to basics and we, we examine our assumptions, okay? So for example, we've always had the assumption, or, or, or we've made the assumption that one of the important things is to identify when something is a box versus something is a human. Mm-hmm.
And, and there are a lot of things that we rely on that says, oh, you know, once we identify it as a human, we can act like this. That stuff needs to be tossed out. Mm-hmm.
That, that no longer exists. Just doesn't. Yeah.
So, so if we go back to basics and we say, okay, we know what we, what, what our programs looks like, let's bubble it down into like, what are our axioms, right? It's like, in math, what, what axioms did you base all this out, and if one of them is something that you know, is, is just not gonna exist, we almost have to build the new, like a math, a new mathematical model Okay. Of, of, of things.
And we don't have to wait until everything blows up. We, we can do this. It's not, it's, it's not impossible to do.
I I like the way you say it too, because, you know, sometimes, um, we create our own axioms that really aren't right. Things are this way, and I believe they're always gonna be that way, and I don't know why, but it's just that way. Or we do know why.
So some, those are the ones we definitely need to re-challenge. And then your point about, well, what, what are the things we know that are immutable not gonna change, okay. That we can still build on, let's reassess or assess or, you know, change design, et cetera from that.
So it's, that's why I say it's not a toss everything out the window. We're not there least not yet. Yeah.
Yeah. And the way, the way I look at it is, is, is, um, you know, it's, it's almost like, and again, I I I, I think that we really cannot be reactive on this. It's, it's, it's kind of like, it's kind of like, uh, like, like how does a goalie behave in soccer?
Okay? Mm-hmm. When, when it's not a team coming at, but it's like one person with a ball.
They don't stand in the goal and wait until they, they actually go out of the net, right? Mm-hmm. They don't stay in the net at all, because when they go out of the net, they're narrowing the, the, the angle.
Okay? So, so they, they, they make a, a, a, a slightly smaller area that they have to protect. We've got to do that.
We can't wait and see, you know, how people are gonna be using, uh, these tools. We, we, we have to start now. Fascinating.
And I love that analogy. I hadn't thought about that. That's a great analogy.
Yeah. How we think about the game changes the game. You know, if we can change the parameters, uh, that we didn't know we could change before, and now we can, right?
Yeah. Let's use it to our advantage. Ron's been, uh, fantastic talking with you.
I always love enjoy, love it. And, and this is sort of a thought experiment and that, I think maybe that's the takeaway message is let's do those thought experi experiments around all of this and what it means, which is actually a fun thing to do. It doesn't have to be.
Yeah. Yeah. It is, Right.
It is really kind of exciting to kind of think about this. What if it wasn't that way? Yeah.
What would that mean and how would we react? And let's game that out a little bit. So Ron, Ron, Ben, uh, Ben Benetton from, uh, Imperva.
Thank you so much. I've been tuned, doing too many in interviews this week here at Black. So, uh, it's good.
It's good to talk to an old friend and, and have such a great conversation. So thanks for joining. Thank You, Mitch.
I enjoyed it. Thank you. You bet.