John Hammond on AI’s Role in Enhancing Cybersecurity with the U.S. Military
John Hammond, principal security researcher for Huntress, dives into how AI platform providers, in collaboration with the U.S. military, can commit to improving cybersecurity.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with John Hammond, who's principal security researcher for Huntress.
And we're talking about this deal that the United States military and other arms made with open AI and its impact on cybersecurity and maybe what we should look forward to. And man, who knows, perhaps even worry about. Hey John, welcome to the show.
Hey, thank you so much, Mike. Happy to be here with you. I think everybody's talking about this AI arms race that we're involved in when it comes to cybersecurity, the bad guys are using it, the good guys are using it.
The good guys are hoping that they'll benefit more than the bad guys. But where does this deal with, um, open AI and the United States government fall into play in that spectrum? What should we expect?
Oh, well, hey, I, look, I'll be the first to admit, I know this is a little bit subjective and there's a certain amount of nuance here, and it's kind of look where, where do you stand? What's your opinion? What are folks thinking?
Uh, but if I may, I think my hot take is, look, the, this makes sense. This makes complete and perfect sense. Hey, we could have probably seen this coming.
Uh, we're getting smart on this AI stuff. We're at least innovating and rapidly developing, hey, new things that could be really cool and could really advance our world society, civilization and technology. So I think it in, in my understanding, you know, it makes sense to have a little bit of a gut check in there with some, at least communication and hand in hand with Sure.
Government, military, Pentagon. Uh, in my mind, I think this is sort of a natural progression for all the growth that we're kind of cruising into. But what's, say you, Mike, am I barking up the wrong tree or do you think that's a common opinion?
Well, My question to you would be, is the government getting more involved in cybersecurity? We have seen them go after with some of their partners in the uk, various syndicates and gangs. We also saw them, uh, get a court ordered, uh, clean up some people's routers who were being used in a botnet that the allegedly occurred out of Russia somewhere.
Um, my question is, is, you know, are we gonna see governments around the world get more aggressive about cybersecurity in general and leverage AI to either better defend us or in some cases, uh, counter attack? Oh goodness, there's a lot to run with there. Uh, hey, the first part, I think, yes, uh, short answer, I, I do think, uh, we will see a little bit more proactive effort and action from hey, those law enforcement bodies or government, et cetera, to play a part in the cybersecurity landscape, uh, to just as you mentioned, look, go do interdict, go do some seizures, go lock bit ransomware.
I know that's been a little bit of the news currently of, hey, another gangs and cyber crimes indicates, can we go and really make a difference to either shut those down or perform some takedowns? Um, I think that's happening. It's already been happening and we will probably continue, but truthfully, glass half full optimist here.
I think that's the right move. But now to your latter point, when we mix and blend in ai, the artificial intelligence conversation, I see that, um, obviously that'll play into cybersecurity in two different ways. There's offense as you mentioned.
Can we explore that hack back, quote unquote opportunity and defense boarding up the windows, locking the doors, and making things more secure. Uh, hey, what should we run down first? I feel like the, there's a whole lot to chat on.
Defense offense. Well do both, but maybe defense first, Mike. Yeah, Let's do defense first.
Do you think we will benefit more than we might stand to lose versus the bad guys using AI versus the good guys? And I'm asking the question because almost everybody I talk to says the same thing about cybersecurity. If only we did the fundamentals better, well, we're gonna do the fundamentals better.
So can AI do the fundamentals for us? Ooh, I like the way that you framed that because absolutely, uh, in my mind, I think, look, ai, artificial intelligence, whatever, we boil it down to, oh, machine learning, Hey, I don't know, just kind of taking action based off a giant data set, training models, et cetera, et cetera. It's really good at baselining and benchmarking information.
So in my mind, I see a real strong defensive use case of just kind of normalizing and knowing what's the ordinary on your network in your business, on the company architecture and infrastructure, the cybersecurity posture of anything. Sure, mom and pop shop, fortune 500, company, government, municipality, whatever. I think that's one good use case of being able to baseline and benchmark and then using AI to better detect anomalies, something off, something malicious, something that should not be there in the network, or some activity that could be nefarious.
Um, but I really like the way that you frame that when we're thinking, Hey, maybe we could use that, uh, in a whole lot of different use cases. I, I would certainly think that that's a strong effort for ai. How far can we go?
And I'm asking the question 'cause we live in a quote unquote free society, but, um, in theory, the government could detect, uh, that there's an issue somewhere. And today they might send you a note, they might not send you a note, but, um, they could go fix it themselves if they wanted to. Uh, they clearly have the capability and in some ways, um, which is the greater good versus evil conversation one is, you know, are they intruding on somebody's God given?
Right? And on the other end of it, are they protecting us from somebody who's just irresponsible? Yeah.
That is a wild and fascinating conversation. And we, we've seen some examples of that. And not to get too nerdy, but if we harken back to a lot of like the Microsoft Exchange exploitation days or Half Nim, if folks were familiar with that, we saw law enforcement, FBI, department of Justice go and use the vulnerability en mass taking advantage of it to patch the vulnerability, like as if you were exploiting it so that we could protect it and secure it, which is an odd peculiar thing.
I don't think we've seen that effort before, or at least not often. But again, maybe that's a good thing if we're willing to say, okay, is that something that we're comfortable with in that, yeah, the depth and the the reaches that we'll go to, but pouring the AI conversation, will we ever get to a point of doing that automatically? Hey, we've gotten the know-how in smarts to say, look, this vulnerability could be used to patch the vulnerability.
I wonder if sure. We, I don't know, imagine our chat GPT or our GitHub co-pilot equivalents or anything to make that a reality smooth and streamlined. What do you see the bad guys actually doing?
On the one hand, are they just going use AI to increase the volume of their attacks, or will they actually become more sophisticated? And I'm asking the question because it takes work to be more sophisticated. And frankly, if they can succeed doing next to nothing, why are they gonna do something more complicated?
Yeah. Uh, so I'll try to have a, a levelheaded answer on that. 'cause a thousand percent yes, absolutely.
Obviously threat actors and adversaries can use that to amplify their attacks. Look, hey, you could say chat GBT, please develop a phishing email for me. And you might need to strong arm it because it'll say, Hey, that's inhumane.
You might say, Hey, draft out this scenario where an HR employee is gonna receive a resume and they'll need to go open the documents, blah, blah, blah, and it'll spit it out. But then you can say, cool, thank you. Now make 10,000 of those unique, different, tailored to any specific customer, victim, business, organization, user, blah, blah, blah.
And that maybe you say, Hey, here's the source code to an application that I want to exploit. Can you make sense of it and find vulnerability? Can you weaponize and exploit, yada, yada, yada?
You have to provide it that information. So it just supplements what a threat actor adversary might do. And if we go all the way to the end of the spectrum and we say, Hey, can AI just figure out a zero day?
Could, could it come up with some new groundbreaking exploit that we'd never seen before? I'll admit I don't, I don't think so. No.
'cause it needs to have the training data, it needs to have the mold information after it. It wouldn't be able to just pull that out of thin air like magic. So it is nuanced, but I don't see it as some amazing, incredible boon for threat actors.
It will just speed them up and help embolden what they already might do. Do you think they're gonna take and build their own LLMs and show it a bunch of malware and say, go build me more efficient malware that, you know, based on what you've seen here? Yes.
I, I think that is a, a more than likely probable reality. And I would think that's already being done. You see some silly, I don't know, conversations and chatter, Hey, we've made worm GPT or we've got black hat LLM uh, stuff to be fine tuned and tailored for more of that nefarious cyber crime purposes.
Uh, but I think you'll kind of find the edges and the walls of that pretty quick. There's only so much runway that you'll have with it because again, it relies on known information. Uh, it's not gonna pull out of thin air the something new that could be used for mass exploitation.
It still has to have a human in the loop to an extent. Um, is the cybersecurity game changing? And I asked the question because, you know, we always thought it was somewhat stressful, but, um, in by comparison it may have been a more, uh, shall we say, uh, quaint time when we would hunt for issues, um, in measure that in, you know, days, sometimes weeks, and now this is a game played in hours and minutes and even seconds.
So that's the whole pace of this thing accelerated. And are we as humans prepared to deal with that? Or do we need the machines to take care of it?
Ooh, very good question. I, I think we're getting better. I think we are getting smarter, sharper, faster and stronger at responding to emerging breaking cybersecurity incidents, breaches, whatever words we want to use.
Uh, look, I've been chasing this whole screen connect vulnerability, uh, some of the current events the past couple days, and that feels like it's lighting the internet on fire. Uh, and I'll say, Hey, I'm a human being and I'm pretty tired. Uh, hey, running low on sleep and running on fumes.
If I could offshore that, hey, put it to a little chat GPT AI model, I'd appreciate the extra help. Um, but I'm sorry. Look, that is all to say.
I think when we've seen what would've been hot exploit summer or hot zero day summer is kind of a cutesy thing we've come to hear these days. It just goes to show that we're getting better at detecting things. We're getting better at responding to things and jumping into the action to go again, lock the windows or lock the doors, board up the windows and make sure things are protected.
Um, but if we can use AI again to supplement us with that more power to it, I think that's a great and good thing. Are we getting better or are we just detecting more? Because, you know, I kind of sometimes feel like it's the Coast Guard where, you know, they're every 10th boat, they find more drugs, but you know, if they look harder, we might find even more drugs.
So, you know, now not to mention the entire submarine that just went by with, you know, times of Yeah. Oh, it's, you get into a very interesting philosophy conversation of, look, are we on this treadmill? Are we ever going to solve cybersecurity?
Are we ever going to, I know, get to the point where we've fully stopped vulnerabilities and we are perfectly secure? Uh, no, I, I don't, I don't know. I don't think so.
I think the cat's outta the bag. The damage is done. We can't close Pandora's box with some of this stuff.
But the stronger that we can get in that detection effort, which I think we are improving on, um, and the response and the messaging and the sharing of threat intelligence, the partnership and collaboration, that's I think really where the rubber meets the road and we are getting that success Mm-Hmm. Uh, it's being able to work together. And if I may, I'll, I'll go out on a limb and say, I think that's why it could be a good thing for open AI in this Pentagon partnership.
Look, uh, it takes a village. So we all gotta be playing in concert, in cybersecurity. We are all concerned sometimes about whether or not AI will take our jobs, replace us.
That conversation is ongoing. But I posit the opposite. Who in his right mind wants to be a cybersecurity professional without help from ai, ai True enough.
Again, it will speed up and supplement. And I've come to it. 'cause sometimes, you know, when we want to maybe sort of showcase our strengths and what we could do as security researchers or analysts or reverse engineers and malware threat hunters, uh, when you say, Hey, I just used chat GPT to do this, and it cranked it out, it's almost feels like a blemish, it almost feels like, oh, I'm embarrassed to say this robot handled it all for me.
I gave it to the Terminator. But it's a tool. At the end of the day, it is a tool to accomplish a task to do what we need to do to protect and it makes cybersecurity better.
Uh, so I'm all for it. Uh, I think it, you're right on the money. Hey, it would be really great if we could get that extra assistance and I'm cool with it.
Do you think the chronic cybersecurity talent shortage will be behind us? 'cause we can rely more on the machines to help the handful of folks We do have, Um, if I may, I I would say no. Um, because I do think sincerely, there's still the need to have the human in the loop and that can't be replaced.
And, and that's just maybe a jaw and opinion. Maybe that's just me. But I think at the end of the day, it comes down to a question of responsibility and decision making as to what gets done as to what happens whether you flip the switch on making some security implementation.
We might not always be comfortable giving that decision making to an AI or to some automated being. I think maybe some CISOs, maybe some top dog CEOs, they probably prefer to call the shots. Uh, and if we boil that down sure.
Bring it to the level of SOC analysts or incident response captains. Hey folks in the weeds in the trenches on this, they'd still like to be running the show, not leaving it to the LLM mm-Hmm. Bringing this full circle.
We started out talking about the government and ai. How do we know that the government is gonna use these technologies for the purposes that they are assigned for? And that we don't wind up in a world where, um, you know, surveillance activities that are not sanctioned by a court are conducted on our own cysts.
Yeah. And this is where I think we get to some of the asterisk or, or gray lines, because I know an open AI shared this messaging of the partnership. They're saying, look, I know it, it might be surface level spooky when we say, Hey, we're gonna be working with the Pentagon and military things, but they said outright, we will not use this for weapons and arms and, and we can get that out in the open.
That's, that's the white elephant in the room. But clear, uh, and to be honest, I, I can understand why, you know, they'd make that statement. 'cause it, I'm sure it could in some cases, be used for that innovation and technology for that new developments and r and d.
But, uh, at the same time, I feel like this could very well just be used for structure and organization and catalog and archiving. Hey, what soldiers are here wearing there? What are they up to?
Do we have reports in this area of operations? Et cetera, et cetera. Uh, I don't know if we get into the doom and gloom conspiracy theory paranoia where we think, oh, the world's gonna get turn into the Terminator movie.
Um, and hey, robots are pulling the trigger and surveillance left and right. But that feels a little too far. Like, um, what maybe the media has gotten us to think, I know that that might be a certain stereotype or paranoia.
Uh, I think we can be strong, mature adults and be thinking like, look, we are gonna put the, the guardrails on this to make sure that dissuade, that's not a reality that we'll see come to life. But truthfully, that's in the hands of the innovators and open AI in the Pentagon and others in the scene, uh, charging forward and making that growth, making that innovation. And brucely, there are other governments around the world where, um, those issues are, are niceties, are not as troubling, and they're gonna be using this technology to do whatever they see fit.
True. All right. Well folks, as an old adage in cybersecurity, it says, if you can imagine it, somebody's trying it no different with ai.
So there you go. Hey John, thanks for being on the show. Thank you so much, Mike.
This was a real treat. All right, back to you guys in the studio.