ML/AI Adoption in Cybersecurity – May Wang, Palo Alto Networks
Dr. May Wang discusses ML/AI adoption within the field of cybersecurity, how it has impacted her day-to-day, and what role she plays in advancing its utility within the industry as threats constantly evolve. She belongs to the 1% of female leaders in c-suite roles within the cybersecurity field and has over 20 years of experience in the industry.
Transcript
This is texturing TV. Hi everyone, welcome back to another text on TV session here. I have I'm really happy to have a new guest first time guests on our show today.
This is Dr. May Wang. Oh, excuse me, Dr.
May Wong, and she's with Palo Alto networks Dr. Wong. Welcome to Textron TV.
Thank you very much Adam for having me. It's my pleasure to have you on so. Well, I introduced you as Dr.
Long. So obviously that cats out of the bag people know a little bit about you. But why don't you tell them a little bit of your story if you don't mind sharing?
Sure, my name is May Wang, and I'm the CTO for iot security at Palo Alto networks. I joined Palo Alto networks about three years ago through acquisition of a startup called zingbox and I was the co-founder and CTO for zingbox where we provided iot Security Solutions based on machine learning. excellent, excellent and So your CTO for iot and look this is an area where we're seeing.
I forgot what the latest number I saw was by 2025. They'll be 55 billion. Devices something like that connected.
Yeah, they're all kinds of predictions estimations. But one thing we know for sure is they're increasing amount of iot devices in this world and based on different estimations. They're roughly about the number filet devices we have now in the world is about twice amount of the total world population somewhere around the lowest as nation is about 11 billion and some higher estimation about 14 billion somewhere via the right 7 billion people, but that number is it's not plateauing that number is you know on a ski hill kind of incline in terms of going up.
Yeah. It's definitely increasing dramatically every year and with this huge amount of iot actually at every second. We're seeing more more devices connected online for example in healthcare.
Seeing about 40% of new medical devices are connected online compared to several years ago. Only 20% of new medical devices are connected online. Yeah.
Absolutely, you know we were interviewing someone in healthcare security couple of weeks ago. Two months ago and they basically said look, there are three networks that every Health Care Facility every hospital. One network is sort of your traditional 18 Network.
The printers are on there the AP team AR, you know, you traditional office kind of workers. a second offer a second network is just the it devices everything from the from the IV pump to the MRI to the heart monitors and all these things, you know, they almost You almost almost demand their own network now because they're on network. And then thirdly it's kind of the doctors and those people because they don't follow any rules and you can't afford to put them on to the like, let's say the iot networks because that's Mission critical stuff.
And and so the the challenge in healthcare is you got to manage three different networks, and it's hard enough managing one network frankly, but That's just one example manufacturing Science and Technology Beyond Healthcare. Even at the home. I have near 50 IP addresses used at my house.
I've won house. It's my wife and I right what do we need? 50 I but I I looked I happen to look in my you know router look at my router tables and devices.
There are 50 devices connected there. Right? And you know, some of them are The Usual Suspects computer phone or tablet but most of them are it they're the refrigerator and the audio and the TV and you know, all these devices so, you know in most household they don't have a it expert like yourself, you know, I know what do they do?
Yeah, these it iot devices are being used by, you know, everyday people they now necessarily have the it expertise or security expertise. Even Enterprises or organizations, like hospitals. Lots of it iot devices are actually broadly not by the IT department.
They can be brought in by finance and procurements facility or in even a hospital. We call them biomed. Or bioengineering team who are in charge of these.
Medical devices but not necessarily they have the expertise of it or security and lots of these devices because they're specialized medical devices. It department is not even allowed to touch these devices. So who's going to be in charge of the security of these iot devices is a big question actually lots of child.
Well, and also the nature of these devices Dr. Wang have changed too, right, you know back when I first got into security. I for instance.
I remember going to the US Geological Survey Department of interior. and talking to them about securing, you know, they have they have sensors on the top of the mountains and on the bottom of the ocean to sense for earthquakes and stuff like this and we talked to them about securing Those sensors and they will Aghast, right? Why would we send why would we secure them?
We want them to be open. This is science right No One's Gonna hack them No One's Gonna bother them. But you know what people do they can today's iot devices have a lot more Headroom.
They're made to be updated over the net and that. It's a double-edged sword that also gives people a chance to go in there and do bad things. Yeah, exactly and also lots of hackers can leverage these iot devices as a stepping stone as well to get into your critical infrastructure to get into your sensitive data.
And also when these iot devices are hacked, we're not only talking about privacy and data leakage Etc because lots of these iot devices are in critically infrastructure. So when these devices are hacked we're talking about life or death. Yeah, we're especially in healthcare and in critical structure infrastructure iot devices, it can really interrupt operations and business.
It could happen in a centrifuge Factory China spin up uranium even or something like that. Yeah, they're plenty and I said it's happened. Dr.
Wong that we want to talk a little bit today though about what's the future of securing these devices utilizing Ai and ML and look Ai and ml are too loaded. There's only two letters but there's a lot of controversy are they real? Are they not real?
Is it ready for prime time? Not ready? When's it going to be ready?
I'm interested in your take on this. Yeah Ellen. So we all know there are laws of increasing amount of attacks from based on the data.
We can see from Palo Alto networks. We actually see three times more attacks compared to a couple years ago before a covid era. I think it's because these whole pandemic situation really expedite the digital transformation laws of things lots of operations.
Lots of activities are forced to move online. So now we're talking about more people are connected online more devices are connected online people stay longer online people are doing more activities online. So, Not surprisingly the attacks.
Number of attacks are is increasing as well. So facing all these increasing amount of attacks more complicated attacks and How we are? How more advanced attacks how we're going to protect our devices our users our data?
And we need something that can provide automatic. protection That we need something that can scale up to tens of billions of devices. And we also need something that can prevent zero-day attacks from happening not so the traditional signature-based security.
Itself is not enough anymore. So we need a new to a better too. That's where machine learning comes in very handy.
Machine learning has been applied in multiple other areas like image processing natural language processing but we still yet to see the full potential of machine learning in cybersecurity We Believe Apollo networks Here We Believe AI machine learning is the future as we said. We are seeing so many devices so many users coming online when good part about that is at the same time. We're also seeing huge amount of data, especially coming from these devices these iot devices.
That we're seeing huge monody that we either couldn't see before or we couldn't see in such real time. And we know machine learning their favorite candies are data. So we feed this huge amount of data into our machine learning models so that we can train these models to better detect these devices to better detect abnormal behaviors.
And we think data and machine learning are the future for cybersecurity and I can certainly Alan I can certainly talk about the unique challenges. We're seeing when we apply machine learning to cybersecurity. I can also talk about common challenges machine learning apply to all areas, but these challenges can be more severe in cybersecurity.
We from our years of Applying machine learning to real world to real field. to protect loss of customers lots of data loss of users and lots of devices. We actually summarize the unique challenges when we are applying machine learning to cybersecurity.
I'm happy to share that. Absolutely. Yeah.
They're interested and I tell you they are interested. yeah, look, this is a There's a topic we're not going to cover in a 15 minute interview exhaustively, right? Can we?
Talk to long. Is there a place we could send our audience to just at least start? Kind of digging in here and really understanding.
These issues and and possibilities you can't defend what you don't know you got to know. Right in order to get smart with it. We give a if you wouldn't mind a road map for our folks.
I would audience to get started. Yeah, sure. com that we have tons of.
materials documents videos talk about machine learning to cybersecurity because now we're basically applying machine learning to almost every single product. With from palato networks to afford cybersecurity. Yeah.
right, so if you don't mind it if it's too much right now, we maybe We put give us a start off for people at a high level. Yeah sure, um as as we mentioned so we do find from not only from the research from our research lab, but also from the very broad deployment at our customer base that we do find that machine learning can be extremely helpful. When it comes to detecting zero day attacks, when it comes to automatic identified devices profile devices and detect an abnormal behaviors.
Just give you just a silver quick examples. For example, the first thing actually when we talk to lots of customers loss of them are very into the first question. They're very interesting is can you tell us how many devices I have on my campus and any given moment because their devices come and go their devices brought in by different departments.
Their device is non-managed by it department at all and people used to use Excel sheet or people go out get onto the floor twice a year to check out their inventory and we know given today's Dynamic environment that's not enough and takes huge amount of manual effort. So from machine learning, we actually can automatically once you deploy our software we can automatically identify and profile. What are the devices connecting to your network what these devices are.
And give you very accurate. Acid management inventory at any given moment and because as Alan as you know, there can be so many different kinds of devices. They use different Hardware different software different applications different protocols Etc.
So it's very important to have this real time and dynamic and accurate. Identification can tell you what devices you have on your on your Campus Connect to your network. And the second one is once you are can actually identify these devices.
It's very important to Profile these devices. For example, even though you see two Windows systems. One of them can be your laptop.
The other can be x-ray machine the controlled by windows and only when you know what these devices are you can actually profiling these devices, you know, what kind of policies you should put in. You know what these devices should do. If it's your laptop, you can go to YouTube.
You can go to Facebook. You can go to shopping sites Netflix, whatever but if it's a window system controlling x-ray machine, you better not do those things. You should blog all those activities.
So because we are able to use machine learning to automatically identify these devices provide these devices so we can actually use machine learning to build up a baseline for each device. So whenever there's a normal behaviors happens, we can easily catch them identify them and catch them. So the second one is automatic anomaly detection and the third one is the zero day detection, you know in our traditional security network.
We we take some takes time to build signature. You have to see this attack see this malware once and then you build a signature and hopefully if it happens again, you can capture it but now especially for iot security. We just cannot afford for these attacks to happen even once we have to catch zero day attacks, that's where this Device identification profiling build up the Baseline Behavior matters so much.
So as soon as you see any early sign of normal behaviors, you can easily detect it and catch it. And the fourth one is is for machine learning. It's hard for a human beings to scale up to billions of devices.
Especially given we're so in such. Shortage of Security Experts and it experts Etc and hard to train these talent to keep up the latest attacks and latest Technologies. So the machine learning is actually once we Apply it in say for example, we figure out.
What's the right thing to do for this group of civilians cameras, then we can easily scale it up to millions of other similar civilians cameras to protect them. And the the fifth one is actually the most important one because we can identify these devices. We can profile these devices and do automatic anomaly detection.
We can do zero day attacks. We can scale up the solution using machine learning. The fifth one is policy recommendation.
After we know about these devices we need to give actionable recommendations on to our customers. What shall we do about these vulnerabilities about these attacks? What are the recommended policies we should put around these devices or users or applications and even nowadays still lots of policy recommendations takes lots of menu efforts and lots of new policy recommended can Shadow the old policy can be conflicting with the old policy while machine learning have the intelligence by feeding into huge amount of data.
They can automatically learn from other scenarios. They can figure out what will be the best policy recommendations for this particular user for this particular device for this particular application. so there's just so many benefits and so many advantages machine learning can bring to cybersecurity.
I can just keep talking go on and on but in our website, we actually have even more examples use cases and details that everybody can welcome to check it out. com You know, unfortunately, these are relatively short interviews. I wish we had more time.
I have a feeling maybe if we have any iot security topic. So one of our virtual events coming up we might have to invite you in and and explore this further. But for now, we're gonna have to call a rap.
I want to thank you so much for coming on here on text trunk TV and explaining this to our audience. I hope I hope you guys at home got this go check it out on the website for more and Dr. Wong.
Please come back and keep educating us. We need we need this so it's all good. Thank you.
Yeah, thank you so much for having me Allen if people have particular interesting for machine learning to cyber security. Actually. We just published a Blog if you just search the future of machine learning for cyber security Palo Alto networks, you can see the block is relatively short and we provided insights about applying machine learning to cyber security.
So go check that out as well. All right, we're gonna take a break. We'll be back in a minute here on techstrung TV standby.