Generative AI’s Role in Cybersecurity Sumo Logic’s John Visneski
Sumo Logic CISO John Visneski dives into what cybersecurity teams can realistically expect from the latest advances in generative artificial intelligence (AI), in an era where skills and resources are likely to be constrained for the foreseeable future.
Transcript
This is Textron tv. Hey guys, thanks for the prayer. We're here with John Eski, who's CSO for Sumo Logic, and we're talking about, well, what's real and what's not real about AI and cybersecurity these days.
John, welcome to show. Yeah, great to be here. Thank you for having me.
The hype cycle is at the top of the curve, maybe even over the top of the curve, but, um, we've had enough time now to play with AI and apply it to cybersecurity and, um, there's clearly some interesting benefits, but it's not clear to me that, uh, cybersecurity's gonna be be all and end all of, uh, everything we need in the age of AI because well, it looks like we still need people. Absolutely. Absolutely.
I mean, and I think the concept of, of what's real and what's fake and, and, and the concept of AI watching isn't necessarily a new thing. Um, you know, I remember maybe, you know, 5, 6, 7, maybe even 10 years ago, you know, going to Black Hats and RSAs and a lot of the conferences and, and it became sort of an inside, inside joke in the C cell community that when you saw AI on a bumper sticker on someone's slide or in their booth, um, that they were probably, uh, selling you a little bit of snake oil. But, but with open AI and with large language models and, and sort of their application both in, in people's personal lives and in their professional lives, um, you know, being able to tell what's really AI and what's not and, and which companies are actually selling you something, um, that takes advantage of the top of the, of the technology and which companies are, are just trying to keep up with the Joneses for their marketing materials, you know, becomes a really important question for us to, to solve, not just as security practitioners, but in business in general.
And there's different degrees of this. Some folks have put their product literature into an LLM and uh, that makes it easier for me to not read the manual. Okay, that's a nice, but that's not quite the same thing as using an LLN to look for vulnerabilities or to, uh, gimme some sense of, um, what actions I might take.
And now of course we're hearing more and more about things like agent ai and so, well, we should have AI agents that perform specific tasks, but that's a work in progress as well. Where are we on this journey from your perspective? From my perspective, I think we need to slow down a bit in terms of thinking that AI is gonna be a silver bullet that helps us solve, uh, manpower problems, resourcing problems, you know, especially in the security space.
A lot of the literature you're gonna read right now in terms of, of up and coming com companies is this concept that we're gonna use AI to replace our tier one and tier two SOC analysts, and we're gonna have smaller teams. And, but I think to a certain extent that's right. Um, I think, I think where, where we are right now is leveraging large language models and things like that to augment the staff that we already have to help them do their jobs a bit faster, um, help them help them do their jobs a bit more efficiently, uh, and effectively, uh, case in point, you know, we get threat intelligence, open source threat intelligence, we get threat intelligence feeds that we pay for.
There's tons of information on the internet about emerging risks. Obviously we get vulnerability notifications that come in from a wide variety of vendors. And, and the challenge for most teams, um, unless you're a, you know, one of the, one of the big players that has hundreds of analysts is that parsing through all that information can take a whole lot of time.
Um, and, and we shouldn't, you know, necessarily, uh, under undervalue or underestimate, you know, the, the capabilities of a lot of large language models just to sort of sort through that information and make us be able to make data-driven decisions a lot faster. Um, 'cause that's, that's a challenge for a lot of our teams, especially small teams or teams that are maybe a little bit more junior. I I think a lot of the tooling that is, that is in the market right now can start helping us do that.
And so maybe like a crawl, walk, run mentality in terms of how can we use AI to help us do our jobs a little bit better and a little bit faster and maybe slow down a bit on the rhetoric that it's just gonna replace us all together. Particularly when it comes to security operations. It almost seems to me we have gone from this point though, where we had a lot of fear and loathing of all things ai.
So now I think there's a lot of folks out there who are probably coming around in the notion that says, well, it may not do everything, but I'm not sure I wanna do this job without it because there's a lot of oil and, and scut work now that maybe I don't have to do. Absolutely. I mean, we, we, uh, those of us have a certain age.
We've all seen Terminator too, and we kind of, I grew up with this idea that, oh my goodness, if AI actually becomes a real thing, all of a sudden it's gonna take over the world, which I think is a bit, it is, it is a bit fear mongering. And, and I think we're getting used to the idea again, that the augmentation that some of these tools can provide you, whether it's writing a paper or whether it's, um, you know, dusting up on, on, you know, large volumes of information in order to do your jobs better, whether you work in security or not. Uh, when you start thinking about the applications in the, in the finance space, when you start thinking about, uh, you mentioned earlier the applications in marketing in terms of being able to leverage the tool to make you run a little bit faster, I think the business implications are pretty profound.
And then I think the other piece of it, especially in the security space is that, you know, as things sort of came out, you know, those of us in the community at first sort of had a, oh my goodness moment of how do we secure this? How do we pro protect against hallucinations? How do we protect against false positives?
How do we protect against the noise? But I think we're, we're sort of coming around to the idea that, okay, those, those problems are almost sort of of trivial if you really sort of, you know, read, read the literature and start figuring out how to put the right controls in place. And I think we're pivoting our mindsets to this idea, um, that we should be using AI for security as, as opposed to just worrying about the security of ai.
Both things are very important. Um, but what we're really gonna get, we're really gonna get our gains, both in terms of our business's ability to move forward and our ability to secure our infrastructure, um, quicker and more effectively is, is using AI for that security piece. Again, augmenting your security operations, um, you know, you know, helping, helping the teams, um, in your engineering development, uh, departments do things more secure faster without as many human touchpoints, I think is a win for everyone.
I think there is some concern about how AI is being used to write code though, because a lot of the developers are kind of taking the output on faith and not realizing that the LLM itself was trained on code from everywhere and code from everywhere has vulnerabilities. And so essentially that output is gonna have vulnerabilities and things may get a little worse before they get better, hopefully. But in the short term, I wonder if the security folks need to double down a little bit more on reviewing that code before it goes up.
Absolutely. And I think it's forcing us to get double and triple down on the basics of application security, whether it's code scans, code reviews, architectural reviews and things like that to make sure that we are, we're checking the homework. I think it's, it's gonna be a profound impact to our security, our, our software development workforce for the exact point that you're, you're making is that as, as junior developers are leaning more and more on the co-pilots of the world and some of the tools that are helping them, um, code faster, um, my only worry is that, that the skills that you're talking about in terms of secure coding and understanding what secure coding looks like and code reviews, those muscles might start to atrophy.
And, and so I think when it comes to the training that we give our junior developers, um, and, and our junior security engineers and the, like, in terms of application security, uh, we need to make sure that we don't forget the basics as we start getting more and more used to leaning on, on artificial intelligence. One, because of exactly what you're talking about in terms of, in terms of, of whether or not the code is, is inherently secure by design, but also from a talent management standpoint, I worry that, like how do you grow a senior software developer? Well, you grow a senior software developer through years of experience actually putting your hands on keyboard and, and coding.
So if all of our junior developers are, or junior security engineers are now leaning on artificial intelligence tools to a degree that they might not start gaining that experience, then, you know, who's the adult in the room that's your distinguished engineer or your principal engineer if, if we're no longer growing them, uh, from scratch. Now, I, I don't mean that to be a doom and gloom thing. I think we, we, as we get more and more literate in terms of how we use AI tools and as university systems and, and education systems writ large are are injecting this into their curriculums, I think we get to a place where the workforce is different.
But that's okay. I mean, we said the same thing, you know, years ago when GitHub came out, we said the same thing years ago when all these other advances came out. It just requires us to be deliberate about how we train and maintain our level of proficiency for our professionals.
Mm-Hmm. Yeah. As some folks say, you know, there is this thing called school and you're supposed to learn things before you come out.
Right. But, uh, yeah. Um, So yeah, I think it, I think it's a, it's an interesting philosophical question.
Uh, I had a, I had a conversation with, um, with a mentor of mine in the security space, and we were talking about college students using chat GPT to write papers. And the philosophical question is, schooling is for teaching you how to think critically and those sorts of things, but if the output is good, um, then sort of what's the big deal? And I think that's a moral question and a philosophical question we all have to sort of wrestle with.
And that goes for the arts, that goes for everything else in terms of where do we draw the line that if I'm learning how to use AI tools effectively and the product or the output of that usage is, is what we're looking for, um, then what's, what's the harm? But again, uh, to your point, you know, does it, does it atrophy in us us in ways where we're no longer able to, uh, to, to exercise those critical skills? I am concerned about, one thing in general is that a lot of the things that we're gonna apply AI to need to be deterministic in the sense that they are done the same way every time this Mm-Hmm.
And I think what we're seeing is a probabilistic approach where, um, it may be right and it certainly won't be the same each time. So how do you inject that into a security workflow where everything needs to be precise and consistent? Well, it starts, it starts with actually getting the subject matter expertise on your team that can, can understand and recognize the metrics that are associated with whether or not, um, the data that you're putting in is accurate and the data that's coming out is accurate and the data putting in accurate is, is sort of the first problem, right?
And so the old garbage in, garbage out, if you trade an LLM internally, um, with, with dirty data, uh, you're gonna end up with a dirty outcome at some particular point. And I think, I think where we need to get to, um, is having the subject matter expertise, either internally through data scientists or things like that, or reaching out to, to consultants that can help you train the models and get your accuracy rates up to a point where you're comfortable that those accuracy rates are, are, are at the bar or better than what you would get from, from humans. And then that, and then speaking of humans, um, I think we should be very careful to try to eliminate, um, a human brain from those loops as much as we possibly, as much as we possibly can.
Because a lot of the, a lot of the tool systems that you're reading out there are saying that they're gonna, like I said earlier with the, with the soc example, are saying that they're gonna be able to replace a portion of your workforce. So if they don't say it explicitly, it's sort of implied. Uh, but keeping a human in that loop to double check the homework and make sure that, um, before we send things into production, there's someone that reviews it for accuracy and things like that, um, I think ends up being what we need to continue to, to double and triple down on so that we don't end up in a place where we're not even aware that we're doing something that's wrong.
Um, and I think, I think that's the, that's the big sticking point with a lot of the tools that are coming out and a lot of the AI washing issues that you're seeing is that like, don't, don't trust the marketing materials that say things that, that sound like a silver bullet or sound like they're too good to be true, because oftentimes they are a bit too good to be true, particularly when they over index on the fact that, um, it's replacing the human element in our systems. Mm-Hmm. Um, as you kind of look around at the defense, um, there's these other people called bad guys, and they do, we're playing around with AI and, uh, maybe getting more out of it than the good guys at this point.
So what's your assessment of the AI and capabilities or adversaries? I mean, I think, I think that's the scariest part that we have right now, right? So, you know, cyber defenses and cybersecurity has always been a, a, an a, uh, asymmetric warfare type of a proposition.
Like the old adage that, you know, some teenage kid in his basement, um, with, with a large enough botanic go against, you know, some of our largest organizations. Um, and, and AI doesn't necessarily, I mean, AI fits sort of squarely into that box in terms of, of the capabilities it can deliver for, for an adversary. I think, I think the advantage a lot of companies have now, especially the large ones, is that, you know, one of the basic tenets of, of building AI models and generative AI models and large language models, and you name it, is it takes a lot of data to train the models, right?
And so I think we're in a, we're in a data and compute race right now, um, with adversaries, which is why you're seeing companies like Microsoft and Amazon, um, ramping up their data center, uh, uh, build outs and construction and, and things like that. I think I, I can't remember exactly the metric, but like Microsoft is building, you know, hundreds of data centers all over the place and it's easy to tell why, right? Like AI is all about having the data and being able to compute.
So I think the hope is, um, that in this arms race, um, the, the, the capabilities of some of our organizations that have large data lakes and quantities of data, summa logic, we have a, a ton of data that we can use to train models that hopefully the arms race is actually benefiting us in that case because we'll have more access to compute. I think the jury's still out on whether or not that is gonna be the case and, and not to, not to be, you know, chicken little with the sky is falling back. I, I think, I think on the horizon and on the near term horizon, we're probably gonna see something, um, that happens that is an ai, a specific AI generated attack that causes some massive damage.
And, and, and hopefully, you know, we have enough, uh, defense in place and we've thought about it enough to mitigate that. But, you know, like everything, you know, we, we, we learned through conflict and we learned through, um, you know, bad things that happened that back to, to ransomware wasn't a huge buzzword until a whole bunch of really high visibility folks got popped. And then we doubled and triple down on how we, we do things better.
I hope, I hope that's not the case with AI generated adver attacks from adversaries, but, um, you know, I wouldn't, I wouldn't hold my breath. So cybersecurity has always been a tough job as we go forward in the age of ai. Do you think cybersecurity teams will be more stressed out, less stressed out, or just about the same stressed out?
Um, I think just about the same. Stressed out. I mean, I think, uh, you know, the, it gets worse before it gets better.
It, as you said is probably, is probably the, the right way to think about it. I think the big challenge that we have, and if you sort of abstract our daily stress about we're responsible for defending intellectual property and data and personal information and everything that, like, those are table stakes, right? Every time we have an incident, um, and any company I've ever been at, I try to remind the team, this is what you signed up for, like, that's why you're here.
Um, but I, but I think, you know, from a very basic level, the way that we can reduce our stress, um, is lean forward with your business partners, um, to start getting conversant and, and start conversations at a strategic level about how your company wants to leverage ai. Um, I think, I think, you know, historically, you know, the, the cliche that the security team or the wizards of no and always telling people what they can't do, and then eventually it causes conflict and eventually it causes stress, and then eventually they don't want you in the meeting. I think this is a real opportunity for us to be thought leaders in the AI space to make sure that as you know, as your business partners, whether they're in finance, hr, you know, uh, customer relations, marketing, yada, yada, yada, as they're bringing AI tools to bear like lean forward and be a good steward of those strategic conversations on how we wanna leverage them as a company because that, that way at the very basic level, you have visibility into the AI tools, what's really gonna cause a lot of team stress is if they don't start those conversations.
Now what ends up happening is that people are gonna go off 'cause they're humans and they wanna do their jobs better and they're gonna start onboarding AI tools. And then you start losing visibility into how those tools are being used and maybe your, your sim or maybe your, your internal security tooling isn't gonna be able to find it. And so positioning ourselves at the center of the conversation, not just from a, we need to secure these tools perspective, but actually be a partner in help helping your organization to use AI for their function.
Um, internally at Sumo Logic, what my team is doing in terms of how we use AI for security is, is doing show and tells and brown bags with our, with our, our, our brother and sister organizations to say, Hey, let's not be afraid of it. Look, we're using it too in order to make our jobs better. So please bring all your ideas and let's get those into the town halls that we can have rational conversations about how we use the technology.
And I think if we do that and if we continue to be not just a part of the conversation, but leaders in the conversation, I think over time that puts us in a position to get ahead of a lot of the risks and reduce our stress levels just a bit. Um, but with it being such a whirlwind right now, I have a feeling we're gonna be pretty stressed out for, for the, for the next, uh, few months, six months, 12 months, two years. Alright folks, I heard it here.
First of all, be reasonable in your expectations, but secondarily, AI is happening. So the choice now is between is this something that's happening to you or for you? Absolutely.
And the horse isn't just out of the barn, the horse is four fields over, so you might as well catch up with it. There you go. John, thanks for being on the show.
Hey, thank you so much. Glad to have, uh, glad to be here and, uh, have a great day. All right.
And back to you guys in the.