Enhancing Software Security with AI with Adobe’s Bryan Payne
Brian Payne, VP of Product and Software Security at Adobe, emphasizes the need to prioritize security across all companies. Adobe leverages AI to boost efficiency, enhance threat modeling, and scan code for vulnerabilities, offering developers practical fixes. The company is also exploring agentic AI for secure code generation, making AI central to its defense against evolving threats.
Transcript
Hi everyone. I'm Alan Shimo from Techstrong, and welcome back to our continuing series discussing Software Insecurity with our good friends at Adobe. My guest for this episode is Brian Payne.
Brian is the VP of product and software security at Adobe, and let's welcome him. Hey Brian, how are you? Doing well, thank you.
Thanks for coming on here. Brian, VP product and software security. Sounds like an awesome job, but tell us a little bit about kind of your journey and how you view your role.
Sure, absolutely. So my role here at Adobe is to oversee the security of all the software we produce, and that's our products and all of our in-house software tools as well. Um, and I'd say, you know, I got here throughout my career just focusing on security and software over the years, um, I've been with the government, I've been in academia doing research, and, uh, I've spent the last 15 years or so in the private sector here.
Excellent. So, Brian, you know, a lot of people say Adobe, they're not a security company. Well, you know, to, to paraphrase Mark Andreessen, every company's a security company in today's world, right?
Because we all, we're all potential targets, but when you're Adobe, you have a particularly big target on your back because you represent such a wealth. It is a company that, you know, probably 99% of the global 2000, if not more use Adobe products in one form or another. And, you know, in a a case of kind of eating your own dog food, Adobe Pie has Ed many, uh, security innovations and things today that we kind of, you know, take for granted or is just, you know, best practices really kind of found their way out from adobe's own internal practices on securing your software that everyone uses.
Yeah, so we do a lot of work in-house without being a security company, of course. Um, we focus on the security of what we build, and so, um, while our, our customers are focused on the creativity and the the amazing things they can produce using our products, uh, we wanna make sure that all of their information continues to stay secure and they don't even have to worry about the security elements. It's just in the background for them.
And a lot of that requires us to innovate along the way. Absolutely. Now, Brian, of of course, we've, you know, we've entered into the age of ai Sounds like a, an old song.
It's not Aquarius though. Um, and it, you know, whether you buy into the whole AI hype or not, it certainly is changing the way things are being done here, you know, from in every aspect. It, it promises all kinds of disruptions.
Um, and, and ai, quite frankly, to those of us in the security world, it, it's kind of a shield and a sword, if you will. Right. Unfortunately it is for the bad guys too, you know, that's always the case in security.
Um, so, but you know, the topic of our short discussion today is maximizing opportunities as well as minimizing risk ways to leverage AI for security. If you wouldn't mind, again, without giving up trade secrets or let's not get us ourselves in trouble, talk to us about, you know, lessons learned at Adobe, some of the things you're doing, some of the things you're trying, some of the things you're thinking about along these lines. Yeah, so you're absolutely right that AI can be used by, by anyone.
Uh, it's a tool and you can use tools for, for good and for bad. And I think, you know, in the security world, we're keenly aware of that, that history, that's always been the case with tools. And so, um, one of the things that I see is that it's important for us to, uh, be able to understand how to use them and stay ahead of the curve so that, uh, the, the attackers are not getting the edge right.
Um, at the end of the day, we find that it's very useful to help us scale. Um, I've rarely run into a security person who just feels like they have so much extra time in the day. Um, and so, so the ability to, um, take care of some contextual generation, uh, help us learn faster, help us get to the key points faster, and then let people do what they're best at, right.
Using their brains to solve those security problems, um, that's really the key for us. And, uh, and it comes out in many, many ways throughout our work. Absolutely.
Um, so if you don't mind, Brian, let's, if we could dive, peel that onion back a layer or two, how, how does this manifest itself? What are some of the ways you're leveraging AI to make the Adobe product line secure? I'm sorry, go ahead.
You know, we look at different code bases all the time. If you think about the number of software projects happening at Adobe, it's a common thing where a security engineer needs to look at a code base that they've never seen before, and then come up with an assessment of what security work might need to happen around that code base to make it even stronger. And, um, that can be a challenging pro process to wrap your head around this, but AI has proven very useful.
Um, you can just ask at things like, what end points are gonna stand up when I start this code base, right? Uh, which functions receive untrusted user input? Um, it can help you navigate the code in a way that gets you to a destination much more quickly, um, which is fantastic.
It doesn't mean that it's, it's necessarily replacing the human in these things, but it augments them and helps them work much faster, which is really wonderful for, for our threat modeling work especially. Um, some other examples of things that we've done, um, think about network scanners. Uh, you often need to stay up to date on the latest CVEs the latest, um, proof of concept code to be able to make those scan templates and to know, you know, which systems on your edge might be vulnerable to the latest vulnerabilities.
Um, so we have found that AI is especially effective if you can point it at, um, you know, public information about these things. Um, it can turn around and create those scan till puts rapidly for you, allowing you to more rapidly find those places in your ecosystem and ultimately more rapidly solve the problems of fixing them. We also use it, um, internally for developers.
Uh, we like to give them as much information as we can around the security problems that we find in code and help them to fix them quickly. And, um, we have found that it's much better to provide some context around this is how we think it should be fixed. Um, this is the best practices around fixing it and those things as opposed to just saying, here's the problem.
And in those situations, um, uh, gen AI is actually pretty powerful at being able to, um, put together some of those recommendations so it can actually go into our Jira tickets and augment them, um, so that people can get additional context around the best practices for their fixes and, um, and ultimately get to a, a faster conclusion on them. Excellent. Brian, everyone today is talking about agentic AI and AI agents.
Oh yeah. So Adobe, we're, we're definitely looking at, um, different ways that this can play out. Um, we have, uh, been exploring code generation, um, using some mag agentic AI systems, and one of the interesting things in this space is that, uh, you, you can ask it to help you make code, um, and sometimes it does it in a way that's very secure and sometimes it will miss a few things like, um, like path reversal vulnerabilities or SQL injection, maybe it doesn't quite do the right filtering on that input.
Um, but what you can do then is you can actually tell those systems, here's some additional guardrails I'd like for you to consider before you generate that code. And then all of a sudden the code that it generates, it's the bar is raised in terms of the security quality of the output. Um, in a world where more and more code is likely to be generated by a AI year over year, if we can get ahead of that curve and if we can actually, um, ensure that that code is more securely written than what a human would've done, then we can actually move the needle on security over time.
So I'm very excited about, about that space and where that's heading. Um, we're also using it in, um, more of a chat bot situation, right? So, um, someone can come into our team and ask questions around, Hey, what's the best way to protect my password?
Right? Or, um, you know, any sort of question they might have. And a lot of these things are actually written up as internal policy here at Adobe.
And so it's pretty straightforward for AI to be familiar with all those policies, look at the question, match it, and then respond for them. And, um, that allows us to get answers back to the workforce much more rapidly than, uh, than having a human in the channel all the time. And we can go back and of course, double check do we think it gave the right answer and then kind of train it over time in the cases where maybe it missed.
Got it. Um, Brian, look, you and I have both been around the software world for you many years and we're all familiar with the hype cycle. What about for my doubting promises out here who say, you know what, yes, there's a lot of promise, but today not so much.
If I had to, you know, kind of put your, your finger to the, to the thing and say, Hey Brian, are you really using AI for security today at Adobe? Is it really helping you? How would you answer that?
So I've seen many people doubting in this space. I think I am, I have bit of a healthy skeptic myself, but I will say that, um, I have seen the results as we have played into this space. Um, it's, it's not magic, right?
You can't, um, completely replace what humans are doing in the security space because the very creative endeavor, as we all know, at the same time, the the kinds of things that it can help you with and the way it can, uh, can get there faster. Um, we can't ignore that, right? It is happening on the ground today.
And so for anyone that's, that's maybe a little bit skeptical, I would just say go spend some time playing with it. Maybe talk with some others that are having some success and see, um, why are others excited when maybe you're not? And and I think you're gonna start to realize there are, you know, if you find the right use cases, there are places where this is extremely valuable even today.
One last question for you. Based upon what you've said, would you say that AI is critical to Adobe security strategy go today and going forward? I, I think it's critical in so much as the fact others are gonna be using it against us.
We talked about the attacker element earlier, and so, you know, security has always been this cat and mouse game, this back and forth, and I think we would be naive to continue forward using all of the techniques of yesteryear while attackers continue to progress. And so, yeah, I think it's very important that we use this to keep up. Um, and also, you know, like I said, to, to scale out the, the work we can do, if you can touch more of the surface area of, of the company, then you can keep it all a little more secure, which is obviously a great outcome.
Ai, the newest weapon in the security Cold War, huh. Crazy. Bob.
Excuse me, Brian, thank you so much for, for, uh, coming on here today. For people who maybe just wanna find out a little bit more about Adobe security in general and maybe about how Adobe's using ai, uh, you know, for security, where, where can they get more information? So I would say definitely, uh, you know, enjoy these episodes where we're gonna talk a little bit more in depth about our work.
Um, we also do often speak at conferences, uh, in the, you know, the technical conferences throughout the community. Um, probably too numerous to list, but I would just say keep an eye out for, for Adobe at your favorite security conference. We are quite often there, so Absolutely.
Brian Payne, VP product and software security of Adobe here. Thank you for joining us, Brian, and keep up the great work. Thank you, Alan.
It's been great. All righty.