Rachel Jin on Using AI to Predict and Disrupt Evolving Cyberattacks
Rachel Jin, chief enterprise platform officer at Trend Micro, explains how multiple forms of artificial intelligence (AI) will be used to predict and disrupt cyberattacks even as they grow in volume and sophistication.
Transcript
Hey guys, thanks for the throw. We're here with Rachel Geno's, chief Enterprise Platform Officer for Trend Micro, and we're having a chat about AI and maybe how it will help the defenders a little bit more than just the adversaries, because we might be able to maybe see how these attack patterns are developing. Rachel, welcome to show, Welcome to have, thank you for having me here.
No worries, no worries. Um, so explain, I think we're all kind of obsessed these days with what the bad guys might be doing with ai, but is there a, a future where we might be able to say, level the playing field thanks to ai because we can see what they're up to and react to it faster than they can do it? Yeah, so, uh, I think, I think AI is really changing a lot of things and, uh, um, it's not just, uh, you know, changing our cyber defense strategies, it's also helping changing a little bit, you know, like, uh, the, uh, the attackers part.
Uh, so, um, what we see is, um, what do we see is, um, so, um, like cybersecurity, LLM it is kind of evolving from, you know, the passive tools and into, uh, very active participants, um, in the threat defense. And right now, for example, you know, a lot of, most of the l LMS are used for summarization, enrichment, and automation. Uh, but the next frontier, what we see is the predictive modeling and the, for example, like trend micro.
And we are training our, um, our models to recognize not just the, you know, non threat patterns, but the behavioral, uh, signals that indicate intent. And, uh, recently we also have, uh, some of our innovations like digital twin initiatives. This is also major step forward and it also allow us to simulate, you know, enterprise environment.
And, but you know, with that said, and LLN is also helping attackers, which we see recently, we looking at our detections and, uh, you know, in the backend we see, um, a lot of threats coming from, you know, very productive way and that the amount and quality is also totally different. And so, uh, we do see that, uh, uh, this is also helping redefining about a lot of attacker behaviors. So this is the interesting timing, Mike.
So if I understand what you just said is a combination of not just all these gen AI models, but it's also advances in the predictive models that enable us to kind of see the patterns that the bad guys are using, even though the volume of those attacks seems to be increasing exponentially. Is that a fair assessment? Yeah, this is fair because, uh, based on our email security detections and recently we see, you know, um, this is like, um, this is like amount of the email detections become so large and huge then, uh, much, much bigger than before.
And in the past we don't see this amount of threat. And of course this is also related to different geolocations. They have different dynamic.
And the other thing that we see is not just, you know, the quantity, it's also about the quality. And um, you know, um, there's one very efficient attack, which is like the social efficient, you know, social related email phishing. And in the past attackers they need to take time to analyze, um, all the, you know, social related, you know, uh, context related to the person or related to the organization and related to the asset.
And today with ai it's so easy to connect the dots and get all the context. For example, AI is just so easy to get, you know, even external intelligence as well, what you are talking about in linking and what you are, you know, posting Facebook and also internally and what, what is the ongoing, you know, information is flowing and so they can jump in with the right context. And, um, the right context is kind of, you know, the fraud context to our customers.
How quickly will all this be happening? Because right now what seems to happen is folks will get a bunch of data and they'll get an analyst in the SOC who will go looking through that and kind of try to discern some patterns and maybe apply some policies. But it's usually well after the fact, are we moving more towards a scenario where policies will be instantly applied and then we'll analyze it later to see what it was really all about?
'cause the machines are gonna run faster than we humans can keep up with. Yeah. So, um, I think I would say this is moving very fast and, uh, let's say the, the pace of AI innovation is generally fast and, um, super, super fast that, you know, comparing to before.
And the defenders, um, need to be, just need to be very agile. And the key is to, you know, embed AI into the operational fabric of the cybersecurity. So not just as a void on a tool, but as a core capability.
So, um, like, uh, what we are doing, uh, to micro is, uh, we are doing it this, uh, across multiple layers. And for example, AI helps us triage the alerts, correlate signals across hybrid environments, surface, uh, very high confidence threats in real time. But it's not just about, you know, automation, it's also about intelligence.
AI can help defenders understand why behind an alert and, um, not just the what. It's, that's the game changer. And we are also like investing in some, um, you know, self explainable AI so teams can trust and also act on AI driven insights.
And so the, the whole goal for defenders like us is, you know, using AI as a trust, trusted partner and, uh, one that can enhance human adjustment and, uh, accelerate response and reduce fatigue. And, uh, defenders don't need more data, they need smarter data. And that's where, you know, AI shines.
And for the attackers part and ai, whatever I say in the defenders, attackers are also smart. They can also utilize AI to help them, you know, get better data, get better intelligence. So this is a really, uh, interesting time is, uh, we need to know how to utilize AI as our partner to work for Defend and, um, continue defending, you know, uh, with the attackers cyber attacks with ai.
Mm-hmm. And to your point about multiple layers, I'm assuming that we'll also see AI agents in that mix and they will be consuming, uh, output from both predictive models and from generative AI models and causal models and all kinds of fun stuff that's out there. But how will all that get orchestrated?
Where will the intelligence be that kinda enables me to talk to the agents and have them go do something in a way that is, shall we say, cohesive and comprehensive? Yeah, so, uh, for the, I think this is about AI agent agents and also about the agent ai. And, um, there will be a lot of AI agents in the world and in different organizations, and because people say, Hey, you know, yesterday we only work with human, and tomorrow we work with AI agents and the human.
So it's, it's also the, you know, the industry evolvement. And so a lot of people, they are building their agent AI system and that can act automatically and that can also incredibly, you know, powerful. Um, but they also introduce new risk.
And this, for example, these, you know, AI agents or you know, agent AI system, they can make decisions, they can take actions, they can even interact with other agents, which means their attack service is dynamic and also and often, you know, uh, unpredictable. Yeah. So to safeguard them and organizations need to rethink, uh, traditional security models.
Um, for example, we need to apply, uh, thrive modeling to AI agents just like we would for any other critical assets. And, um, we also can start to using some of the, you know, digital twin is not just the physical digital twin. It could be cybersecurity, digital twins, to simulate how these agents behave and their stress and their attack.
And also in very complex environments. And all of these agents, you need to have a orchestration, you know, layer to make sure every agent they are running, you know, built fully together and coming up with, you know, uh, one mission and to be completed and sometimes by one agent, sometimes by multiple agents. That's why a lot of PE people, they put, um, orchestrator agent on top of all of these AI agents, this is really based on your need.
And so, um, I think, uh, AI agent is there and uh, even actual micro, you know, uh, a lot of our organizations, not just the technical team, they started to build their AI agent. They also build their orchestration layer on top of this AI agent to make sure, you know, all of these AI agents can, you know, be, behave, uh, can action, and, but of course always think about the risk. And this is also new risk coming from AI agent even coming from the MCP servers as well.
And those AI agents will need to talk to, not just each other in the sense that they belong to trend micro, but third parties as well, I'm assuming. So can we get to a model that kind of looks like this, where there may be some predictive analytics that tells me that, uh, there's a wave of an attacks coming that are aimed at this particular vulnerability, and then I can pass that on to an agent from the app dev or IT ops people who will then go fix that before it hits. And that's kind of the closed loop that we're trying to get to.
Yeah, that's a great question. So, um, yeah, agent is not just, uh, you know, trend micro saying this is entire ecosystem and I think that's also why there's MCP coming up and this is like building, you know, the new protocol to connect all of these world. Yeah, this is this, this is also something that I talked with the team, uh, who is doing, you know, the API, um, integration in the past.
I say, Hey, this is the new world in the past, the traditional way it's API integration. Now it's all about, you know, MCP as the new protocol and how to collaborate with all the AI agents. And so this is the whole ecosystem.
It's not just the micro thing. And micro could have our AI agent to perform different things. For example, we have our AI agent to digest the logs and also, you know, analyze, analyze logs and which is part of our genetic SIM features.
And we use AI agent to do the auto coding and behind the scene so we can support so many third party logs and ecosystems, these data just getting in. And this also means that whenever we achieve anything, we need to think about ecosystem. That's also, you know, we know customers environment, a lot of time, customer environment, they have 50 tools, some customer has 100 tools and all of these tools coming together that could help our customers.
So I do think, you know, uh, no matter what AI agent we build at Micro and uh, it's also we need to make sure everything is a ecosystem friendly and also ecosystem fit. Alright. What's your best advice then to folks about how to get ready for all of this?
I think everybody's kind of getting the general idea that there's gonna be AI agents, they need to be orchestrated and we're kind of have a new way of managing it and security, but what should they be doing today to get ready for that now? Yeah, so I can give, I will try micro example. Yeah.
For example, this is nothing related to security, but of course we'd want everything to be secure. Yeah. So this is about, let's say, you know, what we are doing today, Atmic, we have half of our code is generated from AI and a lot of AI agents behind the scene.
And we deliver, we build our product software and we deliver the software to our customers. And so we actually have a lot of different AI agents today and we have AI agents sitting in the developer side. We have AI agents sitting in product manager side, we have AI agents sitting in the marketing side.
We even have AI agent to provide intelligence for our sales seller. So this is the entire ecosystem. I'll give you one example is for example, if I understand this is the customer problem, I use my AI agent, my product manager, AI agent, to generate the requirement.
And also furthermore is the, another AI agent will help me generate the mockup, the UX mockup, how we will solve the problem. And also furthermore, we can generate an MVP product for our customers to do. The quick validation, which I feel we still need a lot of developers involved today, is if we want to build, you know, you know, thorough and, uh, comprehensive, you know, production environment, we, today we need developers in, I, I think I can imagine the future.
It'll also be, you know, uh, quite improvement, uh, have a lot of improvement as well. But these are all how AI agents is changing us. And even our HR can build their robot today and build some robot and looking at all the resumes.
And in the past they have thousands of resumes coming in and now AI agent help them to filter out. So I feel for everyone, this is also my advice to my team members. Every single, you know, person, employee, yeah, needs to start to build your AI agent to make sure you know, you know how to work with your AI agent because that productivity is like, you know, um, um, phenomenally, you know, like changed.
And also, you know, one amazing things I really like AI is in the past, if we want to be a domain expert, it takes time. You need so many years to learn this domain. You need to learn so many years to learn this domain.
And now AI kind of lowered this bar. For example, I see some financial report, AI help me understand what's the context. I see this kind of you another domain.
AI helps me understand that this domain so easily. And also the interesting thing is AI is also can correlating all the different domain knowledge and tell me what's going on. So that also reduced a lot of time and effort.
So for everyone, I will really encourage everyone start to have your AI agent start to think about, you know, how you can utilize AI to make a better you. So that's my advice. All right.
I like that idea. Make ourselves a better you. But coming back to security, I think the important thing to remember is an ounce of prevention is still worth a pound of cure.
And in ai, we need to do that now in real time. Hey Rachel, thanks for being on the show. Thank you.
All right. And back to you guys in the studio.