LogRhythm’s Sally Vincent on Malicious Botnet Activity
Sally Vincent, senior threat research engineer for LogRhythm, warns that artificial intelligence (AI) is likely to drive a surge in malicious botnet activity that will overwhelm existing cybersecurity defenses.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Sally Vincent, who's senior threat research engineer for Log Rhythm, and we're talking about the impact AI is gonna have on all these botnet networks out there that were a threat to not just us individually, you're probably society at large.
And what might be done about all this. Sally, welcome to show. Thanks, Mike.
So what are we not fully thinking through here? It seems like, uh, we're know for sure that the bad guys are using ai, but hopefully the good eye guys are too. Um, but are we gonna look at some of these, you know, an explosion of the size of botanists because AI and or network's gonna be overwhelmed, or what's your assessment of the threat?
Probably, um, I mean, my prediction is that yes, AI is going to really expand the scope and the damage that botnets can do. Luckily, we're not quite there yet, at least from what I've seen. So there are different types of botnets.
So you've got botnets that are like your traditional distributed denial of service. You've got botnets that are doing things like posting on social media. And while for sure we've seen AI powered botnets on social media, um, like the Fox eight botnet, I'm not sure if we've even seen a denial of service, um, botnet controlled by AI quite yet.
I've heard of some for sale, but I'm not sure if that information is good. So we might have a little bit of time to get prepared. We're already struggling with those types of attacks.
And, uh, usually our best defenses, we turn the DNS server off and switch it over to a whole other set of infrastructure resources. And that's far from elegant, but that's how we get things done these days. How big can these attacks get and how sustained do you think they can get?
Well, um, the thing that AI will really do for distributed denial of service is it will take control out of human hands, which can easily make mistakes. They get tired, they don't like to do things like scripting on the fly or running scripts. So you're gonna see one larger botnets botnets that can attack for a longer span of time, and that can change their tactics from like one type of denial of service to another, um, on the fly, as well as potentially do things like scanning for vulnerabilities.
So things could get fairly bad, but really the defense against that is just tightening up the basics of, um, web application and website defense. And then as security providers, we really need to, to step it up and to start using more innovative technologies to look for things like botnets, because the botnets controlled by AI are not necessarily going to look like traditional botnets. They're going to be able to change their form and thus be harder to detect.
All right. Well let's take that apart for a minute. Uh, 'cause there's two aspects to that.
I hear all the time that we should do better with our fundamentals, and yet we never do better with our fundamentals. So what is the problem and how do we get folks to take that whole issue, I guess, more seriously than they currently are? Well, I, I think things are better for, for people in SOX and for CISOs getting more access to higher levels of, um, of administration, talking to more C levels.
And I, I think security is in the forefront, but, um, I think especially these days, you see a lot of things marketed as, oh, you know, this AI solution is a magic bullet for everything, when really we just need to put in some basic solutions that work and, and start with that. Some of the simplest detections, like one of my favorites of all time for, for many attacks, including some potential AI attacks on, on passwords and things like that. It's just looking at the origin location of a login and alarming on that.
If it's from Russia, throw up an alarm, you know, have input validation for your web application, simple things like that. So I, I think it's a little bit of staying away from, from the glitz and glamor of what's being advertised as, as new and hot, which is important, but just making sure you have your basis covered. All right.
Well let's talk about glitz and glamor then. Everywhere you see these days, somebody's saying we're gonna have AI will help the defenders maybe more so than the attackers. What's your current assessment of the, uh, state of ai and are we in some sort of AI arms risk?
A little bit, yeah. Again, I don't think we're, we're quite to the, you know, Skynet levels of, of AI is, uh, the security cameras in my home, their AI still loves to identify raccoons and dogs as people. Um, so we're not quite there yet, but, um, a lot of security companies, you know, my own included, are looking at machine learning, um, as, as as threat detection.
And already, like when we're talking about distributed denial of service, some CDNs like I know Cloud flare has, um, an AI solution or the AI is part of their solution. So I think we're getting there. It's just, are we faster than the bad guys, which is really hard to tell.
To that end, we saw recently where the government went to the courts and got a court order to remove botnets that had taken over home routers and things of that nature. And it was kind of an interesting development. But do you think we're gonna see more of that activity as we scale up with the AI and the size of the botnets?
Do we need, um, a higher level of intervention from folks to go remove those botnets? 'cause otherwise they can be there for months before the people actually own whatever router or switch is running, realize there's even an issue. Well, trying to, to govern what cyber criminals are doing is pretty hard, especially because a lot of those criminals are located overseas.
But I suspect we'll see more. I mean, the proliferation of, of IOT has really been a boon for botnets, um, and really made it quite a lot easier. Now you can have like a mechanical toothbrush, you know, performing a part of a denial of service attack or something like that.
But, um, yeah, I think there's needs to be more monitoring of the internet of things for sure. Um, especially if you're a, you know, a professional organization, you know, monitor the traffic from your routers, monitor the traffic from your security cameras. Like, I can count multiple times when I've seen compromised security cameras.
Do the people who own those devices have a responsibility to the rest of us and to make sure that their devices are not being compromised for use in a botnet, or are they just some unwitting victim and, you know, we all have to suck it up as a society. I, I think that the companies that provide some of those tools need to build in better protections because most consumers to, to be honest, are not going to be able to really understand what that is, much less protect against it on their own. Yeah, I have no idea how many end points are in my house, much less whether or not they've been compromised for the use of somebody's botnet or, or another.
But I guess occasionally if I feel like my television is being compromised, I turn it on and off in hopes that that might do something. But I think that's about the extent of what most people are doing on the home front. I wonder.
Oh, for sure. Yeah. I wonder though, um, maybe we do need a more proactive approach.
It's gonna be something like we've the government or somebody has noticed that there is an issue. Uh, we've sent you an alert to set issue and you have still not done anything about it, so we're gonna do something about it. I mean, you know, what is that, uh, short of, you know, a totalitarian exercise, but how do we kind of get maybe a little more aggressive?
I think putting out some guidelines, um, might help, but yeah, governing and, and putting out you need to do this or you're going to be in legal trouble is a, is a line I would not wanna touch. Okay. So what's your best advice to folks as you kinda look at this issue in the current state of, um, botnets?
I mean, your company provides one of those, uh, sims, uh, security information event management system. For those of you who have forgotten, um, what should folks be doing? I think people should just be knowledgeable of all of the devices that they have in their home.
I mean, whether you're a individual or whether you're a company, know what kind of devices that you have in your home, in your network, and just make sure that this best security settings are set on them. There should be some device setting somewhere, you know, in the manual, on the website that say, these are the security best practices and try and follow those. And I think that's a good start.
All right, folks, you heard it here. I think what she's kind of saying is we all need to buckle up because things may get a little worse before they get better. And in the meantime, it's our responsibility not just to the organizations that we work for, but to each other, to not let all our toys get compromised and servers and everything else that we put out there, and for the use of some malicious activity that harms us all.
Hey Sally, thanks for being on the show. Thank you. This was a fun one.
All right, back to you guys in the studio.