Thales VP Tim Chang on Rising Bot Traffic and the Growing Complexity of Cybersecurity
Tim Chang, global vice president and general manager for application security at Thales, explains how cybersecurity is becoming more complex as the amount of Internet traffic generated by bots exceeds the amount created by actual humans.
Transcript
Hey guys. Thanks Withrow. We're here with Tim Chang, who is Vice President of application Security for talu, and we're talking about a report they put together on bots who now are apparently are counting for more traffic than humans on the internet.
And a lot of those bots, maybe not for good, but uh, you know, we don't know which ones are bad and which ones are evil until we go investigate. Tim, welcome to show. Thanks for having me.
Appreciate the conversation. So what is going on here with these bots? Because some people will swear there are good bots and others will say just about every bot is bad.
But the one thing I think we can all agree on is there's a lot more of 'em lately and they all seem to be tapping into ai. So if it's already half, at what point does it become three quarters? Will it become all of it someday?
Where are we? Yeah. Right.
And first let's just like, you know, level set on, you know, this concept above bot. And I think, you know, it's this automated software that's built to do, you know, automated things. And so, like you said, some are good and some are bad.
And what we've seen in the, in the last report is, you know, now more than half the internet are these automated programs that are just out there doing things. And so of that traffic, 37% are really malicious and they're trying to do things like, you know, break into your bank account or scrape data from your website or buy sneakers before humans do and sell them on the, you know, alternative markets. And so, yeah, we think, you know, that this problem will probably get worse as these bot operators, the ones that are creating these bad bot programs, uh, get more comfortable with, you know, artificial intelligence where it's really easy nowadays to create a bot that will scrape a website and or, you know, take some data or understand your defenses and, you know, then put that into another bot that will navigate your, uh, defenses.
So, you know, we anticipate that the rise of this automated traffic will continue and that even the, the bad bots will, will continue as well. Is it gonna get harder to detect that traffic? I mean, 'cause you know, from what I see, the AI stuff is getting smarter and smarter and frankly it seems to be helping the bad guys a little bit more than the good guys right now.
Yeah. You know, the every year the tables turn and, you know, I think right now, um, at least here at Tallis, you know, we still have a good grasp on how to detect the, you know, the, everything from the simple bots to the more sophisticated bots or even the ones that are polymorphic, the ones that change constantly. Uh, we still have, you know, a really good, uh, sense of how to detect them, but yeah, over time it's gonna get more sophisticated and more challenging.
And that's why, you know, you know, companies like us that just study this problem, um, you know, are set up well to, you know, help in the future when things get, uh, very complicated. How does that work exactly? How do I detect bots and then how do I thwart them if I don't want them, them for calling on my website or wherever else they may be going?
Yeah, it comes down to how much data that you can get about that particular type of bot and, um, you know, so for example, you know, we have, you know, hundreds of ways to fingerprint a bot and track its lifecycle over, you know, its kind of attack attempts. And so that really helps with determining, you know, what is the intent of that, you know, piece of software and is it normal or is it bad? And if it's bad, then we have different ways to, you know, protect against those types of, uh, nefarious or malicious activities that they're trying to, trying to conduct.
Um, so it comes down to how much do you know about this particular type of threat? And that is a game about, you know, collecting data, analyzing threats, uh, looking at patterns over time. And, um, that in itself is also a very, you know, much of a machine learning AI type of, uh, defense strategy too.
Are each of these bots targeted to a specific task and function, or are they essentially services that are being rented out and people are using them for different use cases? And it's a whole business empire? Uh, it really depends.
It really depends. And it's kind of in both categories. So if you think of a DDoS attack, there's definitely DDoS as a service sites, and those are just automated pieces of software that are launching DDoS attacks.
And then there are ones that are purpose built to, you know, conduct specific activities, uh, against specific websites or properties. And, um, and so yeah, it, it kind of ranges depending on what type of bot attack or uh, malicious bot that you're trying to to to address. Do you think we will create good bots to go battle the bad bots?
Where might that fight actually take place? Yeah, yeah, it's happening right now. It's happening right now.
I mean, every day when you go to like a website for example, you don't see it, but there's a, you know, a battle of bots, you know, happening behind the scenes. And, uh, we certainly have our own. And, um, and, uh, obviously the bot operators have theirs.
And so it just becomes this, um, situation that's becoming very interesting and, you know, um, you know, and, uh, there's also a human element to it all as well. So while you still have these automated programs that are fighting each other there, there's always humans behind that that are taking in data and trying to manipulate each other's, uh, you know, software programs. And so it's a very interesting field right now in terms of, you know, what's happening with, with bots and how to deal with them.
What does a good bot gonna look like in the future with ai? Is that's any different than what we historically have had? Yeah, yeah.
I mean, when you look at the rise of agentic AI and how, you know, you're going to have agents that are operating on your behalf and you know, performing functions, um, you know, those are the good ones that you want to be able to allow to perform those actions and functions. And then, but then it becomes interesting, how do you distinguish now between that and something that's been, you know, now doing something, you know, that's not supposed to be done. And so, um, you know, still again, it becomes a, a question of, you know, how much can you learn about the identity and the intent of that, uh, bot and how quickly can you address the problem that, uh, will surface from the bad ones?
So on the side of the good guys, am I gonna have multiple AI bots that I'm gonna try to manage and orchestrate or assign different tasks to? And this becomes more of a game of orchestration taking place in real time than a human leads, but the work is done by the bot? Yeah, it could, it could, it could.
Right now the way, for example, we operate is, you know, we have a system that, you know, can perform different types of functions like a bot, uh, you know, automatically and detect and, you know, mitigate, you know, certain types of, you know, malicious bots. And so, you know, in the future, maybe we do have an army of, of good bots that are working on our behalf and they're there controlled in a centralized manner. And essentially, you know, that's, um, you know, what we're doing with our policies and, you know, our security rules to really, you know, detect and mitigate that type of actions.
But, you know, is down the road it could, it could all change. And, and you know, that's the interesting part of what we do is we're always trying to keep in the forefront of, you know, new defenses and new techniques to, to thwart these types of, uh, advanced, uh, threats. So collaboration in the history of cybersecurity has always been challenging, but can you envision a world where, let's say that one organization has a bunch of good bots that they have created to go fight the fight and another organization has good bots to go fight the fight.
Can these bots collaborate more and kind of know about each other to go after the bad guys together? I mean, how smart can we get? Yeah, that's a great question.
I mean, we're not there yet, possibly in the future. It's kind of like, um, threat intelligence. Threat intelligence.
You know, we, we, we share data, you know, we tap into each other's systems and we kind of help each other improve, uh, each other's, you know, defenses, um, through kind of a threat intelligence, uh, ecosystem. And so, who knows, maybe down the road there's a similar thing for bots and there's a, there's a way to share the good bots that are working and that we can all kind of, you know, help each other, uh, defend against something that's, you know, very, very complicated. But we're not there yet.
But that's a interesting idea. So one of the best practices that people are putting in place to defend against the bad bots, what are you seeing the smart folks doing that you wish everybody else would kind of do more of? So it's, um, yeah, it's a good question.
It's, it comes down to a matter of best practices. I think. Uh, the first thing is you have to assess your entire landscape, not just, um, web applications, kind of like what I've been implying here, but they're also APIs.
Uh, APIs are ways for applications to speak with other applications or other ways for programs to speak to other programs. And these APIs represent a very large attack surface for bots. And so when you consider kind of how to build up some defenses, you have to take kind of the cell stick approach and consider all the ways that a bot can actually attack your type of, um, you know, digital ecosystem.
And then once you have that kind of assessment done, then you start to implement, uh, different techniques and you have to observe kind of behavior. And our suggestion is, is always, you know, when kind of defending against bot, don't always put all, play all your cards at once. Um, 'cause then that kind of reveals your defenses, uh, right away.
So start to, you know, defend in simple ways and determine how does a bot respond to that and then, you know, deploy another defense. And so as you layer on the defenses, it becomes even more complicated for a bot to navigate around that or understand how you're playing defense. Uh, and so that's always a great way to kind of manage, you know, these types of attacks.
Some would say that API security has been their redheaded stepchild for security as long as anybody can remember. Mm-hmm. Will the rise of bots and AI kind of drive people to look at this more seriously and kind of think through what their defenses actually need to be for an API endpoint?
Oh yeah, definitely. I think, um, at least what we see is certainly more interest in API security, and we really believe that's due to, you know, how automated traffic is leveraging these APIs where nowadays, you know, we're seeing a lot more API traffic than, uh, web traffic. And so a lot of that is, uh, automated traffic in itself and a lot of sensitive data flowing through APIs.
So, you know, first having better visibility into, you know, where APIs are and then understanding how they're being used and then detecting threats and then defending against them that entire governance and security is, uh, really important. Uh, for, for a really mature API security program. Is there anything that telco should be doing that they're not doing these days to help in this fight?
Because, well, a lot of these bots are accessing some sort of network somewhere and somebody should be able to see something, but, um, what kind of conversations can be had there? Yeah, you actually, you know, bring up a good point, right? We, we work with a lot of telcos actually in kind of this space, and it's very similar, you know, it starts with just understanding what your attack surface is.
So being able to detect, you know, any type of attack against either your website or API, uh, whether that's a technical technical attack or volumetric attack or something more sophisticated, you have to have that complete, uh, understanding and, um, almost like visibility into everything. And then especially for telcos, they have to understand like how that, you know, attacks are being kind of where they're coming from. Is it better to, you know, protect it, uh, you know, where it is or understand kind of like, you know, the properties of it before you start to put some protections in.
So, you know, we work with a lot of telcos on, on this type of problem, and, um, the techniques are actually very the same, but the, the scale of the problem is, is, uh, much larger, especially in the telco world. Last question, but it seems like more organizations are putting in place one amount of bots. They're AI agents to do various tasks.
Have we thought through what it will require to secure those AI agents? Because it seems to me the level of risk is higher because the AI agent is running an entire process or could run a process and that entire process could be hijacked by another bad bot you that's attacking the good bot. So is this whole game getting elevated?
Yeah, I think for us it it, it comes down to identity and having to understand what is the identity of that application, that agent, that bot that's trying to perform a specific type of action. And so at Tallis, actually, we do have, um, different parts of our portfolio that are geared towards application security, like my business as well as identity and access management and data security. And so the actual, you know, solution to identifying these agents that are either trying to do, you know, good things or bad things could be solved actually by not just one solution, but a combination of solutions to kind of put together a really compelling way to detect these types of, you know, agents and, you know, be able to address, you know, various use cases, not just, you know, are they logging in and doing something malicious, but are they now accessing information that they shouldn't do or haven't accessed that information before?
And so, uh, because of I guess where Tallis is positioned, it's, it's very interesting how, um, you know, kind of this new AI security use case is evolving and how, um, you know, one solution may not be enough. And so we're keeping an eye on it. Um, it's all evolving really fast, but I think, uh, it's all very exciting at the same time.
All right, folks, you heard it here. Well, exciting is one word for it, but at the very least, the cybersecurity threat landscape is evolving once again. And so too will our defenses.
Hey Tim, thanks for being on the show. Thanks very much. All right.
And back to you guys in the studio.