How AI is Changing Vulnerability Management
Everybody is kind of freaking out about AI autonomously discovering zero-day vulnerabilities, but the reality is that the bad guys are already using these tools to shrink our patch windows to near zero. Barracuda Networks CISO Arve Kjoelen explains that while we’re going to see a massive short-term spike in CVEs as AI scans existing software, the technology will eventually help developers release much higher-quality, secure code from the start. Until that stabilization happens, folks, security teams will have no choice but to rely on AI-driven automation to remediate threats at machine speed before manual patching efforts become entirely overwhelmed.
Transcript
Hey guys, thanks for the intro. We're here with Arve Kajolan, who's the CISO for Barracuda Networks, and we're having a little chat about, well, the implications of things like these new AI tools for discovering vulnerabilities are going to have on patch windows. Arve, welcome to the show.
Thank you. It's good to be here. I think everybody's kind of freaking out about the fact that AI can discover all these vulnerabilities, and a lot of them are unknown or zero-days, as they like to say.
But I don't think we've concluded what happens on the other side of that equation, because the bad guys will be using AI to create exploits for those vulnerabilities faster than ever. And it looks like all those patch windows that we counted on to buy some time to go fix things before something bad happened are closing. So what are the implications of all this from your perspective for both security teams and the developers that they got to support?
Oh, I think if you begin with where you started, which is the patch windows, those are going to shorten and they will continue to shorten, and that's the unfortunate thing for the defenders. We should expect to see a bump in the number of vulnerabilities, the number of CVEs that are published, because these LLMs are just going to be more effective than humans in finding those vulnerabilities. So when that happens, that will put stress on software vendors who find those vulnerabilities and have to patch them, but also on customers who have to patch them in the running instances of their software.
Is it your sense also that maybe the AI coding tools in general are getting better, and maybe as we go forward, the quality of the applications we're deploying could actually improve, but there's going to be maybe a gulf between now and then? Yes, that's exactly what I think will happen. We have done some modeling internally and looked at what would the curve look like over the next few year in terms of the number of vulnerabilities.
Because the AI tools will begin to work through the software that has already been released, and it will find vulnerabilities in that software, and then over time, the number of vulnerabilities in that software that's already out there will go down. But the other thing that will happen is that as software vendors use AI tools internally, they will find vulnerabilities in their new software before it is released. So the software that begins to be released to the public will be of higher quality and will have fewer bugs to be found.
So we will see a bump in the short term, and then with time, the number of vulnerabilities will actually level out and should stabilize at a level that's lower than where we are today. So we're looking to get to a good place in a couple of years, but in the meantime, we will have more work for all of us. There's hope for us after all.
It also seems, though, that the nature of the game is fundamentally changing, and I'm saying that because all these decisions now appear to be happening at machine speed. And the days when I could, as a security team, well, at the time it seemed very stressful, but maybe looking back at it now, it all seem downright leisurely. But can I keep pace with all of that, or have we reached a point now where humans are going to need some form of AI to manage all this because, well, it's just happening too fast at too much scale?
Yeah. Software vendors are looking to add AI capabilities to what they have. That will happen both on the vendor side, so vendors, as they are looking for and are patching vulnerabilities, that will happen automatically using AI.
There will be humans in the loop, at least for the short term, but the number of vulnerabilities that will be found will be such that doing all of the remediation work with a human is going to be too slow. And I think as a customer, we are already seeing that customers are getting better tools available to them to manage their security. Our own products have AI features built in which accelerate and automate, and other vendors are doing the same thing.
So we can't do things the way we did it in the past, but tools will be available to do it better in the future. Is it your sense that the stress on security teams will be higher or less going forward as we kind of move into this brave new world? It will be higher, and it's for a couple of reasons.
One is the pace that we already talked about, that things will go faster. But for everyone, not just in security, but everywhere, adapting to AI and understanding how you can use that internally, in more ways than just as a chatbot companion who can accelerate things for you. Adapting to AI internally is going to take a real change for companies, and I think that security teams will have that to add on top of all of the other things that they need to do.
Will we be able to buy some time by maybe applying some mitigations or controls in near real-time while we wait for the patch, which hopefully is coming in a matter of days instead of weeks? But should we be thinking about this in terms of grades of levels of security and things we can do short-term and long-term? Yeah.
Prioritization is important. There are 40, I believe about 48,000 vulnerabilities or CVEs were published last year. That is a large number, and no one has the time to look into every one of those vulnerabilities in detail.
Generally, they are prioritized by something called the CVSS score, so they're on a scale of zero to 10. The problem is that even if you do the cutoff at, say, nine, and you want to prioritize just the critical ones from nine and aboveYou're still talking about more than 3,000 vulnerabilities last year. So there are prioritization schemes available that make that better.
One is known as KEV. So the CISA maintains this list of known exploitable vulnerabilities, and there are about 1,500 vulnerabilities on that list for all time. So that's one way to look, and there's another prioritization scheme as well, known as EPSS.
And you put those two together, companies really need to focus on what are the vulnerabilities that are on one of those two lists, or that have a high score on EPSS and are on the KEV list, and remediating those first. So you can reduce the risk quickly in the beginning. I think no matter how you cut this, there's going to be a level of investment required.
" So what's your best advice to folks about how to have that conversation? So that's a great question, and something that we should all think about. The way I look at it is we don't want to overplay the importance of what is going on.
The number of vulnerabilities has been going up for years. It was 40,000, the year before it was 48,000, it was in the 30,000s the year before that. So this increase in velocity has continued to happen.
And while Mythos and the LLMs introduce a level of uncertainty, I'd like to draw the analogy back to what happened many years ago before vulnerability was really a practice and an industry. Back then, there were two individuals, one by the name of Dan Farmer, the other one was named Wietse Venema. So they were security researchers in the security industry.
Dan Farmer was working for Silicon Graphics. They released this new tool that was called SATAN. It was the first freely available vulnerability scanner.
It stood for System Administrator's Tool for Analysis and Networks. People were scared back then, too. The law enforcement was concerned that it could be a national security risk.
Dan Farmer ended up parting ways with Silicon Graphics, where he works. There was a lot of pushback and a lot of desire not to release that tool, because it enabled you to sit in the comfort of your chair and get a list of vulnerabilities on a remote system. But if we now fast-forward 20 years or more since when that happened, vulnerability management is a thriving industry.
Wiz, Tenable, all of these companies are in the vulnerability management space and are doing well in helping protect companies. So there are always two sides to this. There's the scary side and the attackers using these tools, but then there's also the side that lets proactive users and proactive CISOs take the steps that they need to secure their environments.
I think we're taking some comfort in the fact that with Mythos, at least, there's some effort to control who has access to this. But should we also just be realistic here and conclude that, well, it's just a matter of time before the open-source models follow suit and have a similar capability, and that will get downloaded by both people for good and for ill? That is what I would argue.
That's exactly what I would argue. These tools will become available to everyone, and by withholding them or restricting access to legitimate users, we're postponing the inevitable, and we may even run the risk of keeping some organizations from better securing their environments because they do not have the tools available. I think one of the perhaps maybe dirty little secrets of our industry is there's not often a lot of love lost between the security teams and the developers.
" But are we at a moment in time, maybe, where these two groups have a vested interest in maybe working more closely together because we are going to see this massive spike in vulnerabilities, and everybody needs to lock arms? I have seen a lot of improvement over the past few years in the relationship between engineering groups and the security groups, and I think there's more and more recognition that there are common goals and common interests in securing your tools. Four, they intersect in several areas, and one of them is quality, for instance.
So by always using the newest libraries, newest systems, newest kernels, you are going to be producing code that runs better and is more reliable. So there are multiple reasons to always try to be on the latest versions, and that minimizes both vulnerabilities and enhances quality. You've been at this a little while.
What do you see people doing today that just makes you shake your head a little bit and go, "Folks, I wish we could be a little bit smarter about that"? I would love to understand how we could prevent sprawl. So one of the risks we see today, it is not individuals doing something that they should not be doing, but the technology is just becoming more and more complex and resides in more and more places.
And so you may have companies that have hundreds of accounts in AWS, and they have hundreds of subscriptions in Azure. Their systems are of a wide variety, their Microsoft systems, their Linux systems, and so on. The development, the products are built in different development stacks.
And when you put all those things together, as a security professional, you don't have a single solution that you can apply everywhere, because your solution only applies to a portion of your environment. So sprawl just makes things difficult to manage. It is part of life and something that we'll continue to deal with asWe get new cloud providers as we get new ways of getting more sprawl.
But it's also what drives the business and what drives all the exciting new capabilities we have. To your point about that, one of the things I also see that folks struggle with is they don't always have an appreciation for the dependencies that might exist in their software because somebody used some sort of open source component somewhere that is maintained by somebody who isn't part of their team, and then suddenly there's an issue and there's nobody out there to go fix it because, well, that maintainer is already overwhelmed trying to just keep his own systems up and running, never mind actually fixing software. Do we need another approach to the way we think about using open source software?
There's a lot of data available already on open source software that I think that is enough to give us a sense for which packages are suitable for use in an environment and which packages are not suitable for use. Some of that relates to what type of license is the software providing, but also the history of that open source software. So some of the biggest software used all over the place is open source.
Apache open source for many years. Many types of operating systems, open source. So it's a matter of doing your own due diligence before you start using something.
Not using the latest and, as you say, not using something that's perhaps just supported by one person on a part-time basis, but using things that have a good reputation and a history and a track record of providing updates and patches when those are needed. We've seen this in Europe at least, where there's more regulations talking about application security specifically. As we have more vulnerabilities that are discovered using AI, do you think we'll see more regulations around the world, or how will governments react?
I see no reason to think that the current path will change, which is a move towards more regulations. At this point, there are some fairly substantial regulatory regimes in place that are relatively new. So there will be some time while companies absorb those.
So those are the CRA, for instance, in Europe and NIS2, so those are two of the regulations in Europe. And similarly here, we are seeing GovRAMP and we are seeing FedRAMP and different certification regimes which are not mandatory for doing business, but they're mandatory if you want to do business with certain types of entities. So as those get absorbed, and once industry gets to a point where they have absorbed and are complying with most of those regulations, I think the screws will be turned again and we'll see them tighten.
All right. Last question, my friend. In the age of AI, there's a lot of talk about the cybersecurity profession and whether or not there is a profession going further, or will everything be automated?
So at this point, would you advise people to get into the cybersecurity space, and if so, why? I would. The cybersecurity space is a great space and will continue to be a great space.
The challenges that we've already talked about today, they will not be solved tomorrow, and they will not be solved in five years. They will continue to persist. Someone going into the cyberspace needs to be prepared for this continuous learning journey, because things will continue to change, and they will continue to change quickly.
But it is rewarding in terms of the type of work that you get to do and being part of protecting your own company and the industry in general. All right, folks. Well, you heard it here.
There's a phrase about "May you live in interesting times," and the one thing for sure is cybersecurity is going to remain interesting for years to come, and it's going to need people to make it all work. Hey, Harvey, thanks for being on the show. Thank you, Mike.
And back to you guys in the studio.