Navigating Uncharted Technological Waters with Troy Leach | Qualys QSC23
Transcript
This is Textron tv. All right. Welcome back to the Quala Security Conference in the Americas.
We're here with Troy Leach, who's chief Strategy Officer for the Cloud Security Alliance, and we're talking about the Mariners Guide to securing AI in the age of the cloud. Troy, welcome to the show. Thank you very much.
Appreciate the invite. Well, let's just dive in. Yeah.
What is the Mariner's guide and what do we need to think about here? Yeah, So, uh, for my keynote here, I, I use a nautical theme 'cause I was thinking that, uh, the ocean is very relatable to where we are with cloud and ai. So we know that we've probably only explored 20% of the ocean sea floor, and there's a lot of opportunity, there's a lot of fear of what's out there, and you get that a lot with, with both those technologies.
There's opportunities for us to be able to do medical advancements that we've never even thought about, and other opportunities for ai. We see that cloud computing has already revolutionized the industry, uh, but there's so much more that we can be doing. So I thought, you know, what we really need to think about is, is humankind has been on the water for centuries, but the reality is we still don't know much about it, and we're always constantly discovering new things.
And I think, you know, that's where we're gonna be with for AI for a while, even though everything's advancing so quickly. We see in the last week these advancements with open AI releasing, uh, GPT, uh, turbo, uh, GPT four Turbo, and now it's able to consume 128,000 tokens and has logging and updated, uh, to April of this year. There's so many things that are happening so quickly, and regulation happening very quickly, as well as people really have a fear of how this technology could be used for bad.
Right. And it's just like the ocean in the sense that we keep throwing stuff in it and we don't know what's in it. Right?
That's right. That's right. You know, I'm, I'm a diver, and so, and I gave a diver's analogy while I was on stage, but I, I think that's the reality is, is even though you're diving even some of the same places based on drift currents, I'm really going nautical on you now, but, you know, based on drift currents and all these changes, never, nothing's ever the same.
And this dynamic technology we've created, nothing will ever be the same. You can ask the AI something two weeks later and how it's been trained and how it's evolved. It's going to have, give you, uh, produce a different answer.
And so I think it's, it's really a, a good analogy because there's so much more to explore. We have seen with cloud security that, you know, the core issue is developers provision these infrastructure services and they don't have a lot of security expertise, and then we're surprised when something bad happens. It turns out data scientists have even less cybersecurity expertise.
Mm-Hmm. So, um, do we need to train these folks? How should we go about this?
Yeah, no, it's a, it's a really good point. And I think the cloud security, um, has really matured in the last few years. I, I think we're starting to see this, this revelation by CSPs that I do have accountability, uh, for the data that's within my customer's environments to an extent.
And, and that that's a shared security responsibility that we have to negotiate and understand. And I think you're seeing regulators all around the world starting to make these types of, of accountability. Um, as well, we see Dora in the Europe, the Digital Operational Resiliency Act, which will go in effect in, uh, Q one of 2025 saying that any financial institution that's using one of these third party cloud providers, there's gonna be some responsibility for them to show and demonstrate they have due diligence of protecting regulated financial data.
I think in the AI sense, uh, we're gonna see a lot of these, uh, SOC analysts using a lot of prompt engineering and starting to discover and learn, how do I use it? How do we train our marketing department not to take our customer's sales database and put that into our models or into a worse a public model? Uh, because there's really just a concern about how we get that information back.
I love the recent announcement by Microsoft and OpenAI about, uh, having this copyright shield. And so if, if there is some accidental disclosure of data into a model, uh, working with some of these, uh, more larger large language models to, uh, be able to extract that back. How do you untrain a model?
Uh, I think that's an area in the guardrails with that. So at, at CSA, that's what we're working on. We have a AI safety and trust initiative.
We've just launched it, uh, with many of the large players. It's no surprise that that ai, and there's a codependency between AI and CSPs, right? Because in order to have that scalability and, and computational power of, of a good large language model, you need to have that infrastructure that a Microsoft, a Google, Amazon, whomever, uh, can provide.
And so, so we're seeing that, um, it's no surprise that AWS is invested so much in Anthropic, Microsoft's partner, um, and has this relationship and ownership of open ai. So we're gonna see more and more of that where, um, these large, um, hyperscalers are going to be, uh, really avant guard in how we produce large language models for the public. Mm-Hmm.
We've had this concept of a shared responsibility in the cloud. Hmm. Um, you know, it's a little uneven, but, you know, generally kinda works.
How would that model be applied to AI then? Uh, that's a great question, and that, that's what, uh, we have this recent launch of a research working group and a new model that we're trying to build, uh, very similar to our cloud control matrix that we built 10 plus years ago for cloud. We're trying to do the same now for, uh, gen generative AI and large language models.
And, and that's really where, um, um, it's so more complex. You know, before, uh, we had just infrastructure as a service, you can, it's physical premise under get your, um, concepts and understand that I think, um, you're gonna see the same type of, of, uh, similarities. And that's why we're building a model for, for securing, uh, AI is, is we're gonna see that you're gonna have this rapid application development and SaaS dependency.
I think going forward, almost all SaaS development, it will just make sense that there will be a high dependency on large language models because software developers are going to want to have personalized for every type of user that they have, you know, this very unique, uh, custom made for that user. And the user's gonna get, uh, used to that, right? The consumer is going to expect to have, Hey, this organization, this company, uh, provides this type of very unique experience for myself.
I want the same with all of the, uh, commercial enterprises that I work with. And so we're gonna see that, um, this need for how do we take and create that unique customization with personal data and still protect it and, and contain it in a ai, um, model. And it's going to be, it's gonna be hard.
Uh, I think it, it's gonna be very difficult. We're on the, just on the cusp of it. But you see this week, just in the last seven days or so, uh, there's an executive order from the White House on a AI trust and safety and looking at NIST to be able to provide some of that type of guidance that you're asking about.
We see that, um, in the uk they had the, uh, uh, black slavery, uh, declaration that was signed by, uh, I think 29 countries, including the US and China about we need to have AI safety guardrails, but we don't have 'em yet. And, and so that's what I think as a community, you see a lot of work that's happening. I mentioned this darpa, um, again, ourselves at CSA where we're trying to get all the right people together and, and make sure that at first we have just, are we talking about the same thing?
Do we have a collective nomenclature? Are we seeing and have the right vernacular saying the same thing? And I think we, that's possible.
And once we have that defined, I think we can start looking, uh, better at, at all these other, um, elements of security and and risk that, that I talked about on the stage today, uh, from Vishing and, and deep bakes and, and all these type of, uh, really scary attacks that, that are already materialized. They're already exist in the wild. Today We embraced a concept called DevSecOps to try to make cloud applications more secure.
Yeah. We use machine learning operations to build these AI models. Yeah.
So do we need an ML DevSecOps workflow to kind of, you know, make, I know that just flows right off the time. Yeah, I just, It's, it's just very fluid. Um, you know, I'm really excited about how, you know, we talk all about the badge in AI and, and, and these demos that, that have succeeded.
But I, I think that for me, I look at how software development is actually going to be much more robust and more secure going forward, because we're starting to see all the, the threat hundreds out there in AI being able to detect and, and reverse engineer all the code that's coming in to be analyzed already. So rather than a SOC analyst having to go out and search Google, Hey, this looks a little weird. Um, you know, is, is this actually a threat?
I think we're going to get a place where there's a lot of dynamic, uh, reverse engineering of code as we receive it in real time and be able to find new flaws. 'cause one of the concerns I have is of all the software to vulnerabilities that already exist today, uh, that all have been enumerated as ACVE, we've only seen about 3% of them actually be exploited from malicious use. Well now bad actors are gonna be able to use ai.
They're gonna be able to find, uh, in much more real time these, these threats. And, but I think at the same time, we're gonna arm, um, our, our SOC analysts, our other security professionals with a bitterly for the ai, even if it's not detected and enumerated in in public, they'll be able to realize, Hey, we can actually design our code better. We can actually see these vulnerabilities before it actually gets to production a lot better with, with ai.
And so you'll see that it may be maybe a little bit more fluid, they'll come up with a marketing always comes up with a better snazzier name for, for whatever our techniques, uh, come up with. But I, I think you're going to see that it's just going to be in, infused into everything we do is, is a way that AI thinks five steps ahead of us and, and looks to see where those vulnerabilities are and tries to fix them. How does security people insert themselves into this conversation?
Because there's a huge amount of excitement in these organizations, data scientists, developers, they're playing with all this stuff, and you know, the security guy has to stand up in the middle of this and go, hold on, partner. It's a tough conversation. Oh, it's incredibly tough conversation.
And I, I think the, the good news is that we've had about 20 years of experience doing some of this work already, right? So with, with all these other frameworks that, that have come before it, I, I think there's better awareness, especially as some board members have aged out and senior leadership have come up with a more technical background. I, I think there's better comprehension now in some of the younger leadership understanding that, uh, the responsibility to protect sensitive data, um, and in how we apply technology in a smart way, that doesn't mean that, um, there's not people that wanna put on the, their foot on the gas and accelerate a lot of this innovation.
And that, that's where a really comes a concern. I, I heard from an ethical hacker friend of mine who had, uh, gone to a bank, the CEO was very proud of the large language model private, uh, model that they created. And, um, uh, the person was within five minutes able to spoof the, uh, model to convince it that it was now the CEO and the CEO had been replaced and was able to receive all of the employee data and then easily within 10 minutes social engineer and compromise the entire bank, um, in this ethical hacking, um, exercise.
And so I think, you know, there's, there's a lot of excitement, but it comes with a, a lot of, of different concerns. And the problem is the scale. I don't think people, um, understand the scale.
There's a great video out there, it's free on YouTube. Um, it's from, of the people that created the social dilemma, uh, Netflix video, uh, next film, they created the AI dilemma. And it gives an hour talk about, uh, and one of the things they talk about early in the video is about the rubber band effect and how, um, our minds, you know, stretch as, as the, these new concepts like AI come out, it stretch, but then all of a sudden it snaps back because we want to associate it with something we're familiar with.
And I think that's the problem with a lot of these senior leaders is they are trying to, to relate it to something that they know and say, it's not, it's just an advanced Google search. It's just, you know, and they're, they're trying to say we want to be on the, on the cutting edge of it. Uh, but they're really security professionals are have, um, have got to be ahead of this and, and trying to do as much education and, uh, uh, talks with their senior leadership about all the potential threats.
'cause there, there, there's going to be, uh, a lot more data breaches, um, that result from, from just assuming that generative AI is just like any other technology, and it's not, it's it'ss radically different. Will the business people listen? Because I remember talking to one business executive and he basically said, you know, if my security people had been around when the phone was invented, they would tell me not to use it because some data might get out.
So there's a certain cynicism in the world there, There, there is. And, and back in the days when I ran a knock, um, my CEO came in and was frustrated and, and I, I walked him into the server room and I I showed him a cord that if he unplugged that cord would be as secure as possible, which would've essentially disconnected us from, from the world. So I, I, I think there's, there's a balance that, that has to come with it.
And I think part of it for security professionals is as, as much as, as we have concerns, I think it's also, um, AI is gonna be counteracting ai. And so, so for me, I I think it's as much for security professionals to be, uh, on the cutting edge of, of learning how to, um, play with all of this technology. And, and so much of it is so easy to, to get your hands on and, and play with.
I think they're going to, in part, have to be as innovative as the business people to embrace the positive security aspects of machine learning and, and see how, how to combat that. Um, but it's also going, and this is why I mentioned some of these regulatory acts that are happening, I think, um, the world, I think industry as well as well as governments recognize that this is a true threat that people do. There's an excitement.
They wanna embrace this technology and we're gonna have to find a way to, um, uh, curb it responsibly that we continue to innovate. But, but we do not recklessly endanger, uh, civilians or, or data because not AI is not just text, right? It's not just chat GPT we have now, um, the ability AI can see an image, it can reproduce images.
Um, I, my entire presentation here at, at Qualys was all about, um, you used all Dolly three images and it was, it was an incredible, I asked that, show me an image, 'cause it's nautical theme. I said, create an image of a, of a kraken coming outta the water with a siren in the background. And, and just like that, it was, it was generated.
So, um, but we also have these modal, uh, other types of modals that like physical where we start to see that, um, these AI robots that are, uh, New York Police Department just rolled out in the subways of, uh, times Square. The, uh, uh, a five foot three robot that is, is monitoring surveilling, you know, and, and so we're actually now in the presence of physical AI as, as well. And, and so, um, there, there's a lot going on and it's, it's, it's hard to keep pace.
I'm not keeping pace with it and I don't know who has, I need more AI agents to, to help me with that. Will it take a cataclysmic event for us to get serious about this? Because historically we have all known about issues about security, and every time we have to wait for something really horrible to happen, for everybody to wake up and go, all right, we need to do something.
And, and what what has been most worried is historically, um, we're becoming more and more numb to those events and, and, and our time of recovery and time of, of patience shortens. And so, uh, I remember 20 years ago, uh, working in, in the financial, in industry, um, and major data breaches and oh my gosh, we're never going to ever have see an issue like card systems that lost 25 million credit cards. We'll never do that again.
Of course, now, uh, someone, uh, doesn't blink twice when someone says, oh, I lost a hundred million credit cards the other day. Uh, so, so I think, you know, we're, we're, uh, we've become numb to the impact of, of some of these. And I think AI is so different and how it learns and, and how it could possibly have data poisoning and prompt injection.
Um, I, I think we're going to see several, uh, catastrophic events and, and hopefully we'll be more responsible than we have in the past to be able to say, um, we need to innovate, we need to grow, but do it in a way that, that adheres to certain principles. And that's why I like, uh, with uh, this declaration I mentioned that came out in the UK last week is you have 29 countries that say, yeah, this is a problem. We need to have safety guardrails around this and let's make a commitment together to, to do that.
And hopefully we do. Alright folks, there is one piece of good news. If you get into AI security, you're gonna make a lot of money.
Prompt Engineering, Thanks for coming by. Hey, I appreciate the time.





