How AWS Uses AI for Security | RSAC Virtual 2024
Explore how AWS harnesses the power of AI to fortify your security posture in this breakout session. We will showcase real-world use cases on how we build different security onion layers with cutting edge services like Amazon GuardDuty for threat detection, Amazon Rekognition for advanced authentication like facial recognition, and Amazon Inspector for identifying and remediating vulnerabilities. Gain insights into Amazon CodeGuru’s machine learning-powered code reviews for security, Amazon Q’s generative AI capabilities for strengthening security across the SDLC, and Amazon Macie for discovering and protecting sensitive data to maintain compliance.
Lastly we will cover how service like Amazon Comprehend and Amazon Transcribe enhance customer security by enabling sensitive data redaction, threat detection, content moderation, fraud prevention, and secure data handling through AWS’s robust security services and compliance certifications.
Transcript
Well, hello everybody, and thank you. Thank you for joining me, um, in this session, uh, where we're gonna talk about how IAWS uses AI for security. Um, so, uh, my name is Laan Gini.
Uh, um, I'm a lead principal architect for Amazon Web Services for the Strategics account. Um, I was part of, um, um, AWS for, um, for a really long time, uh, several years. Then I was for, uh, I was part the Alexa AI interpretations Data Science and related distributed Machine learning team, um, as well, building the, you know, the, the AI that we use on that side of things.
And then I was also head of architecture overseeing all of the technology we were building at Amazon Studios for, for, for a couple of years, um, before, uh, before joining the strategic accounts, and now predominantly, uh, work with, uh, with Twilio, uh, in the past, um, uh, Pinterest as well. Um, so, um, we do a tunnel work with artificial intelligence. We have done it, it's been in our DNA from the very beginning.
Uh, and, um, and, you know, it's really intertwined with a lot of our services. And today, really, I'm gonna be, um, talking about, um, how we, um, how we use, um, artificial intelligence and machine learning, um, in some of our services. And I wish I could, uh, I could even like encompass even more.
Uh, and, you know, I had to kind of select, um, you know, a few, uh, key areas which I think are, are gonna be interesting to you, uh, um, and, um, will, um, hopefully, you know, peak both your interest as well as, um, um, you know, make you more energized to, to take a look, uh, try these things out. Um, so gonna start off with, um, looking at our managed services, um, managed AI services and how they help in certain, you know, security concepts such as advanced authentication, content moderation and compliance. And then we're gonna move on to the, um, infrastructure, um, and data, how we kind of, um, do in intelligent threat detection, how we discover sensitive data, how we detect, uh, vulnerabilities, and then move on to, um, uh, code as well as business productivity on how we, um, you know, make sure that, and use AI within both, um, you know, uh, uh, uh, DevOps and, um, you know, uh, CDCI, as well as the, um, how we use it to generate, uh, you know, code and, and increase productivity, um, or for your developers, uh, engineers and so on.
So, um, let's start off with the master authentication. So, one good thing to consider, um, we have what we call the digital fraud era, right? Fraud is very costly, uh, to all of us, right?
Studies have shown that impact of fraud is felt across organizations. Uh, the market is expected to grow from 21 billion to 75 billion, uh, dollars by 2028 according to Bloomberg. And then rapid market growth is fueling a 282% increase in account takeover activities.
And those scams are not cheap for the company. 75 4% of organizations, the target of these scams in excess of $50,000. If you multiply that by the number of scams that your company may face into a single month, it's gonna come to, um, quite a bit.
Um, so you know, what we have with Amazon, you know, recognition, um, and what we can, you know, reduce and challenges we can tackle are costly operations data and process complexity, um, and, and lack of expertise. Um, you know, those are the things that, that you don't have to worry too much about. You know, if you, you know, need features like, um, uh, from a, you know, computer version perspective, um, uh, such as face liveliness, face detection, uh, analysis, uh, face compare and search labels, content moderation, which we're gonna touch on later in text detection, but also custom labels, uh, um, celebrity recognition and video segment detection.
Uh, we're gonna focus now on the face loveliness, face detection and face compare and search, and how that works with identity verification on Amazon recognition. So you can see here, um, you know, the, the actual, um, you know, onboarding of users, um, whether that would be, you know, using cameras, uh, and, and scanning the, um, ID documents and all. Um, so it would, um, verify liveliness of the user, compare the selfie picture with the ID card picture, search selfie pictures against, uh, your collection of user faces, and then at the same time, validate the quality of the image, classify the ID document, extract the, uh, uh, ID data, and then, you know, onboard, uh, users this way or authenticate them, um, as they're coming through.
Um, so, um, let me just start this. Yeah. Um, you can, uh, check the face loveliness, which means, uh, analyzing real, uh, time selfie videos with loveliness confidence scores, detect presentation attacks such as printed photos, images, or on digital screen.
And 3D moss, uh, detect injection attacks from dfas, virtual cameras record and manipulated videos and, uh, develop, um, applications using all of this, right? We have extensive SDKs. We have frameworks like Amplify and Cloud api, so there's quite a bit, um, you know, to use on that end.
Um, if you look at the face detection analysis, we have, uh, we can, you know, provide demographic data such as age range, gender facial landmarks, um, image quality, brightness, sharpness, emotions, uh, that are expressed as well as general attributes like face occlusion, smile, how open your eyes are, and, uh, what is the direction, like the pose such as the pitch, uh, eye direction and so on. Um, we can do face comparisons around similarity, um, between certain phases and all, um, which can kind of, um, you know, which are gauged in percentage. And that way, you know, you, you can actually, uh, you know, uh, get and, you know, across all of your corpus of data, um, e even more, uh, you know, and, and more secure and better ways of identifying, um, you know, people.
Uh, and then the, this phase search, right? We have an index that has, you know, 20 million faces per collection, and you could be searching through multiple collections, um, at the same time. Um, and, um, you know, this is all using, uh, create collection, um, API.
Um, you can create, uh, collections of faces, um, with vectors representing facial features. Um, and then, uh, you know, once, once that is done, then you know, the, the, the, the, uh, you actual, you know, searches are performed. Um, so a way it can be used, user authentication, avoidance of deduplication of account registration, and known bad actors, right?
Once somebody has been identified and flagged as an account duplicator, they will get marked as a bad actor and it'll be flagged. Uh, this is what, uh, extraction of the ID data looks like, uh, right? Um, it has 95% accuracy for US driver licenses and passports.
Um, uh, we've done a ton as well, and I urge you to take, take a look at that for other IDs around the world. There's no templates, configurations required, um, outputs and normalizing these field names as you can see. Um, and, um, yeah, it really kind of consolidates all the diverse ID document fields into norm, you know, um, as, as it's coming through from various different places, um, and, um, or, you know, scans rather.
And it's, um, as works in supportive format such as tiff, p and g jpeg. Um, so that's, that's kind of, um, you know, um, Antoine, I showed you, you know, um, what that workflow looks like, how that, what that, um, um, face detection and recognition, um, uh, works towards, uh, you know, both, um, you know, authentication or onboarding. Uh, and then how that, um, how that data as well gets extracted, um, such as IDs and, uh, in conjunction with it.
Um, now we're gonna kind of look at the, um, how we can, um, in ever popular generative ai, uh, you know, uh, establish trust and safety with Amazon comprehend, but not just, we are gonna touch on, you know, um, also, um, you know, how we, um, how we do content moderation and so on and so forth. And a lot of these things, uh, you know, uh, work hand in hand. So we have fine tuning and rank, uh, rank kind of from, uh, using private data that, you know, results in variety of foundation models that are being used, uh, currently today by, um, you know, enterprises and then, you know, various users, internal, external groups and so on.
We'll have chat some prompts and then get, um, um, results back. Um, so the, these are the areas that, um, you know, specifically are of concern around, you know, how, which data we kind of pulling in for fine tuning. Um, and then, and then what are, what is then being submitted, um, in chats and prompts and what's, you know, what type of responses are we getting back, you know, if we can't anticipate that as, you know, from, uh, the, the, the larger LI models and so on and so forth, right?
Um, so, um, type types of issues that come up at PIR, leaks, prop, proprietary data leaks and so on. Unwarranted usage, onsite requests, uh, brand, you know, risk of like, you know, using toxic language compliance, maybe, you know, um, infringing upon, um, the, the rights of specific brands and so on. Um, so how does comprehend work, right?
Um, with all types of media documents, email chats, social phone calls, more and more. Um, we have, you know, um, various different ways. Um, you know, uh, a variety of APIs including pre-trained APIs that work out of the box in custom models, uh, that, you know, customers like yourself can build to support your organization.
Um, so, you know, you can identify entities, classify documents, determine the language or the text, extract, key phases, phrases, and then, um, understand the senti sentiment of the text and more. Um, but now trust and safety, um, you know, were, were the new features we've, uh, including, um, you know, ensuring data privacy, filter toxicity, uh, prompt safety and so on, are the new features that we've, um, you know, uh, released in the past year. Um, so, um, what does that kind of, um, what does the comprehend PII detection look like?
This is it, right? It, it picks it up, um, and then figures out, aha, this is, this is the name, this is the social security number. This is the, uh, you know, date of birth or date time.
This is the credit card number, bank account numbers. Um, so, um, so when you run it, it returns these labels of identified PI entity types, and, uh, and you know, then you kind of, you, you can, um, use it as input text, um, um, you know, um, and, and have any type of loose input text like you see on the left hand side, uh, that results in, um, in all of these entities identified. Um, and then, um, what type of PI elements can it detect?
Yeah, financial, personal, um, you know, technical, national and other. Um, so bank account numbers, bank accounting numbers, address, phone, email, age, um, username, password, URL access key, secret key, I guess one, some of the, uh, kind of kinda recent, you know, uh, well, some of the things that, that people inad inadvertently can share, uh, or can accidentally find themselves, um, you know, in, in the corpus of data there where it shouldn't be. Um, so, um, yeah, and then coming to toxicity, um, and this is the, you know, we've introduced this last year, um, where we can detect profanity, hate speech, sexual, uh, um, content, uh, graphic violence insults, um, uh, and abusive, um, text.
Um, so, um, what does it do? Um, you know, so, you know, we kind of, um, have these, um, I unsafe prompt categories such as malicious intent, generational offensive and discriminatory or legal content, and, uh, request, uh, advice on medical, legal, political, controversial personal or financial subjects, which is, I think, fairly important in moderation. Um, so those are the, you know, uh, the type of things and type of, you know, safe, unsafe classes that you can determine, um, what does that look like, climbing grand scheme of things, um, um, and hard works with large language model models.
And those of you that use Lang chain, I know some that, some are pro some, I guess we can totally have this, uh, you know, uh, conversation around, uh, the benefits of blank chat. I think it's a great thing, uh, and how it actually works with Amazon comprehend moderation chain. So text comes in, then trust and safety is applied, um, prior to fine tuning or inference.
And then trust and safety is applied, um, as, uh, um, as that is returned, uh, um, as taxed back. Um, so these are the, you know, the, the, the common customizations, um, like toxicity configuration, um, threshold, um, PI configuration, which shows there that's looking for SSN, and, you know, setting reduction on masking of characters, prompting prompt safety configuration threshold, and then moderation con, you know, uh, uh, config such as, you know, Hey, we want this, uh, toxicity config, PII config and prompt safety config that we've just defined above, um, to be part of the, you know, um, and executed as part of the more, uh, moderation. That's kind of the set of the workflow.
What does that workflow look like? Yeah, so once the text comes in, toxicity checks, um, um, whether it's it's present or not, if not, it stops it. If, uh, if no, then it goes to a PII check, um, checks, whether it redacts the PII entities as we've instructed it, uh, in configuration.
If not, then it goes to the safety check, uh, before now presenting it back, um, you know, to the, to the user, right? So, um, and, and, you know, so, so kind of that kinda shows you how to control this. It's not so much that it, uh, you know, um, that it, that it, um, affects so much the free use of, you know, specific, um, l LLMs.
It's kind of how it, how you build security around it to ensure that, uh, your users are safe, um, brand is safe, and, you know, content that, uh, that you're providing is safe. Um, how does that work with content med, uh, with Amazon recognition and transcribe, right? So we have communities like gaming, social media, e-commerce, marketing, advertising, broadcast, media, and education.
I'm gonna take you through a couple of examples of what this looks like and how that works with imaging, video, text, audio, um, how it helps with, um, you know, uh, human review and so on. Um, and, um, and how we use various services to do so. Um, so if you look at this, these are, you know, again, all of our, uh, um, uh, some of our rather main AI services, fully manage, right?
Such as recognition, we went over that for, for both image and video. Then, um, translate, um, uh, and transcribe, um, to a SR service, and then how that works with comprehend and, uh, Amazon augmented AI to provi provide moderated content that flows back into the community. Um, so first, uh, recognition content moderation, API, it has all these categories such as explicit on non explicit nudity and intimate parts, and then has all of these ex, uh, um, secondary, uh, or second level categories, as well as the third level categories that you can see in front.
Um, and, um, which helps accurately analyze, right? Generated, you know, you either AI or user generated media. And so, so, you know, you can use it across both, right?
Um, and, um, and, and these, these are other categories, swimwear, underway, violence, uh, visually disturbing, you know, images, videos, drug and tobacco or alcohol, rude gestures, gambling hate symbols. And I'm gonna show you kind of how that, you know, um, works and looks, um, in real life. So this is kind of the, uh, the image that could be fed into the moderation label, uh, or rather moderation, API.
And then these are the moderation labels that, um, um, uh, that, that come out as part of the response. Um, so it detects weapons, um, and shows you where and what the sub as a subcategory of violence. Um, and then in addition to that, um, you have also like label detection APRs, which actually identifies what's the, with the weapons, right?
So there's handgun, there's food, there's sweets, uh, coffee, coffee cup, um, right with, um, the, um, prete percentage certainty. Uh, same thing with, um, um, smoking, uh, paraphernalia, right? It could be like inappropriate contenting profile images or user uploaded images.
That's part of drug and tobacco paraphernalia. That's part of drug, drug and tobacco. Um, um, what's his name, um, uh, taxon, um, category.
And, uh, and then together with that, we can also recognize, hey, what, what is this in context of, okay, this is a context of a person, a male, with headphones that are smoking, uh, with this paraphernalia, um, it gets a little bit like, Hey, some things may be okay or not okay, depending kind of on the, um, you know, um, specific, um, uh, you know, guidance and compliance aspects such as, okay, alcohol, alcohol use, and drinking, kind of being categories here that are being detected. But hey, once you actually look at, cool, there's a glass beer and there's a person, um, uh, you know, that, that is, uh, a male that is, um, uh, uh, enjoying that, but also we can look at, hey, this person is, you know, in age range of 35 to 43, um, you know, smiling. So it could, you know, it's of legal age.
If it's presented to people of, you know, that, that shouldn't be seeing these images, they can't see it. But for the people that can readily consume this content, it should be fine. So these are the type of, you know, decisions and things and that you can make.
Um, and some of the things like, Hey, this is, you know, uh, this could be like a sports image that, you know, uh, um, shows it non explicit nudity, uh, of a male, but like, again, we get the context and what is being done, and there's a wrist rush, so we know that there's a product placement of a sort. Um, and then you know, what the age of a person is, um, and that, and what's in it. Same goes for, um, you know, rude and inappropriate behavior.
Um, in this, in this case, we see the, the middle finger being used as a rude gesture, uh, and the context in which, uh, you know, how this is being done and what's in it. Um, other things that can help with content moderation. Uh, um, you know, we have the text, uh, detect text a p, which can, you know, surface text that is in there, and then validate against that as well.
Uh, detect, uh, different labels, which you've seen detect faces, which you've seen. And then, um, you know, the customer duration, API, uh, which can kind of use, can use it to find cu customer specific objects. So, so things that are more, most important to you that need to be detected.
And a key part of this, uh, workflow, de determining whether something should go and flow out as in response, right? Um, of, of either content is generated or posted. Um, so how does the transcribe toxicity detection now work?
Um, so, um, transcribed right as being our, uh, ESR service that, um, you know, um, that with, with many features that you can see from punctuation, you know, capitalization, word level timestamps, language id, custom vocabulary, you know, we've added also the toxicity detection and PII content reduction as well as vocabulary, uh, filtering. And these are the types of top level, uh, categories for transcribe, where it's, um, you know, um, the text, profanity, hate speech, sexual insults, um, violence or threats, graphic harassment or abuse. So, um, this is kind of an example of it in the e-commerce or marketplace, we could be looking at speech, can I, I believe I bought this.
This is kind of in the, um, in, in, in, in the, um, uh, actual, uh, comments, uh, section. For example, this is hideous, right? Uh, uh, or in gaming com community, we know have been plagued for years with a lot of toxicity, you know, about, and cyber bullying and harassment.
Um, then we can also, uh, detect things like, um, you know, smoking and, um, um, um, logos that, that, um, as well as vi violence of weapons that either di you know, directly or inadvertently, um, generative AI models, um, have, have created. Um, and, um, and kind of, you know, how we use this in conjunction with, um, you know, with, uh, uh, and I'll talk more about, you know, SageMaker as well, right? Um, uh, one of the techniques right around how we can, um, um, manage both what's coming in as input and then what, um, you know, um, a large visual model can create as an output in how we can effectively manage, uh, and moderate that content on both ends.
Um, so jumping onto the infrastructure in intelligent threat detection, um, yeah, a lot of the times we are plagued with a lot of alerts. Operationally, this is a big headache, a lot of issues. Uh, so we have, um, created several services, uh, all of which, you know, using ML AI behind to continuously improve upon itself and learn as well as pick up new things.
Um, so Amazon guard duty, which is, uh, you know, detects, um, threats and anomalous behavior, Mac C, which allows you to discover sensitive data and inspected that, that, uh, helps detect, uh, vulnerabilities and how they work in a context of the AWS security hub. And, um, you know, and as an output to, you know, um, other services like the Amazon detective that investigates these events and findings and Security Lake, which can be used to normalize and analyze this security data, right? So, um, mentioned guard duty and, uh, you know, anomaly detection, um, and, um, um, hard works.
Um, again, fully managed service. Um, it has very unique d uh, capabilities around detection and fully powered by am, uh, machine learning and, uh, threat intel that, that, uh, that is supplied as well as threat intelligence from us, as well as our leading third parties and partners. Um, and, um, and it works, um, you know, really well around, uh, you know, um, you could, um, using foundational data sources, whether it's, you know, network, VPC, flow logs, network logs, DNS logs, uh, cloud trail events, uh, audit events, and, and, uh, uh, our, uh, identity and access management, um, in a, uh, uh, data as well as the, you know, workload protection around, you know, s threes, what's in, uh, our Kubernetes EKS, elastic Kubernetes service audit logs, Aurora, uh, login events, uh, Lambda, which is a serverless function, uh, service and so on.
And then how do we then, um, digest that and then provide security findings that are then used, uh, for integration remediation, um, you know, aspects. So I mentioned S3. This is a objects storage service, you know, um, or, or, you know, data would be, uh, normally stored RDS, you know, relational database service, um, uh, the Kubernetes EKS protection, uh, right for Elastic Kubernetes service, Lambda, um, runtime monitoring and map, and including malware protection.
And all of these things, if you look at the flywheel, right? Kinda work in a circle. Um, you can use this comprehensive set of APIs, and then you can remediate the threats and then securely report, you know, um, deploy these business critical applications.
Um, introduce more, you know, operational efficiencies more and more. And then, uh, continue to continuously monitor and protect your workloads, right? So how, how you using, you know, um, guard duty, um, uh, in this case, um, you know, is to detect suspicious activity, um, assist, um, analysts in investigation and automating remediation, how to protect against ransomware, uh, container workloads, and also achieve compliance, right?
Like P-C-I-D-S-S and so on. So, second thing is now we've, we have a way of con, you know, not just, not just continue, uh, um, um, addressing and continuously remediating any issues around network and infrastructure, but also how we do this now with data with MAC C, right? So we have growing a lot of volumes of data we are dealing with.
Um, so it's a data security service, or used to call it data loss prevention back in the days, right? Um, that discover sensitive data using machine learning and patterns, um, and pattern matching, and then provides the visibility into these, you know, uh, security risks. Um, and, um, you know, customers can use it to manage, you know, data security and, um, improve their security posture, right?
For, um, S3 for our object storage service. And, um, yeah, you can automate this, uh, the, this discovery of sensitive data and classification of it. Um, you can, um, make sure that, you know, we can abstract a lot of this complexity and infrastructure to make it a lot more cost effective.
Uh, and then, um, you can assess all of your inventory as well. What is everything, what you know, especially for security and access controls. And then you can, uh, reduce the triage time that you need to do.
Uh, so you could be, um, you know, you could be sending these findings to Jira Slack. You could be tagging buckets with seven, you know, sensitive data. You could be showing it via our, uh, reporting, uh, service Amazon QuickSight and visualizing it.
And then, or you can take actions with orchestrations, various different orchestrations service, you know, example is, uh, STA functions, but you know, you can use anything else really. Um, what does this look like? Um, yeah, as I said, makes the automate sensitive data and discovery, and then kind of can show you this in a very, uh, you know, uh, specific EAP way to show what's, you know, what's what type of sensitive data, um, you know, is, is where across the buckets, um, um, um, such as PII and so on.
And, um, you know, and, and you can kind of, it's fully interactive, so you can kind of, you know, click through and find out more and, and get more into this data map. Um, you also have, you know, um, um, dashboards like this where, you know, allow you to gain kind of, um, this whole, um, um, uh, visibly more cost efficient way into the sensitive data. So it shows you here, as you can see, hey, percentage of sensitive data, nonsensitive not yet scanned, what's unclassifiable, what's where the access has been denied, and which ones are with classification errors, how many back buckets were scanned?
And you can really kind of draw, drill into the specifics in there. And like I said, you don't have to rely on these, um, you know, specific, um, um, dashboards. You can use them, but you can also feed that data into whatever dashboard service of your choice.
Um, and this is another way, yeah, it's, uh, can show you which, what is publicly accessible, what's, uh, publicly, worldwide writeable, what's, uh, publicly world, uh, uh, readable, what's not publicly accessible. How many, um, you know, where the default encryption is disabled, uh, where it's not required by li you know, uh, by bucket policy, what's been encrypted, what's been encrypted by default, uh, yeah, this is for, you know, um, whether it's kind of, um, um, in the service side on, on kind of S3 side or using our, our key management service, uh, and so on. And then, you know, kind of what's been shared, what hasn't been shared.
So these are the, the level of details that you can get, uh, for your buckets. Um, and then on the reducing the triage time, this is kind of, yeah, you can actually look at, um, um, you know, all sensitive data, you know, uh, kind of, um, uh, a actual, uh, reporting on, on it. And, um, and see whether, um, you know, specifically, um, uh, you know, and, and, and again, you don't even have to worry about the findings so much if, if, uh, because, you know, we make sure that they're all encrypted using, um, your, uh, managed keys, um, using our, you know, key management service, or you could be using, uh, you know, generated keys on that end.
Um, and they're all temporarily viewable, you know, within, uh, Mac C console after they're being, um, re, you know, uh, retrieved, and then they disposed of. So, um, you don't have to worry again that, that this is shared beyond, um, you know, what, uh, what you see, um, coming to the, yeah, detecting vulnerabilities with Amazon Inspector. Uh, this is our automated vulnerability management service.
Um, it continuously scans your, you know, workloads for software vulnerabilities, unattended, uh, network exposure, um, and then it, uh, you know, it, it, it contextualizes these findings and then presents them on how you want to take action. And that can be third parties, it can be whichever, uh, services may be running on what, uh, any other platform or whether you wanna fan it out, um, to a larger, you know, set of services that need to consume it. Um, so yeah, um, these are the use cases will, um, um, automatically discover all workloads and continu, see scan for them that will look for common vulnerabilities and exposures information and network accessibility.
Um, and then it'll support, also support, um, compliance, you know, frameworks like, um, N csf, cyber security framework or standards such as P-C-I-D-S-S and others. Uh, and you can actually have a full, you know, full list of all of those. And then you can also embed this, uh, scanning in your developer tools, um, you know, and, you know, um, um, um, you know, any, any type of monitoring of resources.
Um, and then you can automate these actions through Security Hub, um, or, you know, take it through, you know, as they kind of come through Event Bridge, um, which is, you know, kind of our bus service that allows you to, um, you know, um, take actions via, um, orchestrator or direct steps, you know, through our functions, for example, or export this out to, uh, S3 for, you know, long-term retention or for reports or to a, you know, again, security lake, data lake and so on. Um, in, um, code security analysis, um, we have code guru, um, offer plagued by, Hey, um, we need to have the high trust with pipelines, um, uh, you know, a blocked when higher critical vulnerabilities detected, uh, but often kind of that goes down the line, uh, where you have low precision lenient enforcement or vulnerable applications, right, that lead more to low trust. Um, how do we kinda look at that?
Um, so in this code example, we have MD five that is used as a way that leads to vulnerability on the left top, left side, and in a way that does not lead to vulnerability on the right. Um, MD five is prone to collision when used for encryption. This can lead to a vulnerability, and this is what is kind of done on the right.
And MD five method is part of the, you know, pseudo random number generator method in life 20 on the left, that method can, uh, can be seen in detail in life four on the left, right? Um, so MD five is not prone to any issues when use for regular random number generation, as is the case on the left. Um, so we have, you know, service that not only learns and knows these things, but that that continuously learns new, uh, new tricks of, you know, uh, of figuring this out.
Um, so we lose a lot of valuable time in mis investigating false positives a lot of the times. Um, and that's why it's important to consider services like Code Guru. Um, uh, so it can, um, allows you to integrate very flexibly to triage and prioritize to remediate and produce closure on bugs.
Um, this is an example of kind of how it, uh, it, it fits into our pipeline services code, commit code, uh, code CodeDeploy, uh, sorry, code Bill CodeDeploy and, and running into, you know, and kind of where it sits, how does ID scan CLI integration, uh, with these, and, uh, and then, um, in the inspector code that is running for, um, like civil services in production, for example. Um, now this can be any, any set of, you know, CDCI services on your end right now. We cover Java, Python, um, JavaScript, and, uh, all of these things that you see, um, and, uh, we continue to do so and we continue to increase that coverage.
Um, last thing, um, and, uh, is the, our, uh, AI assistant, uh, Amazon queue, uh, queue, I believe is after the, I think, queue in Star Trek. I'm not sure. Don't hold me to that, okay?
Um, but, uh, but basically this is an all encompassing AI and system that we've created. Uh, as you know, this is, you know, I don't need to convince you on how important this is, right? Um, um, you know, generative AI has become now embedded into both, uh, you know, uh, Apple's operating systems and, and phones and devices as well as everything else.
Uh, so, you know, it's been done by other, uh, both manufacturers and companies and so on. And it's, it's, it's, it's a, you know, this, this monster is out of the package and it's not gonna come back. It's out of the box right out of Fundera's box.
And then, you know, um, so this is, uh, you know, uh, these are probably more conservative numbers, um, around things. I think it's just gonna, you know, increase exponentially. Um, and, uh, um, what we have, and what I kind of wanted to touch on briefly is, um, we have a really good foundation around both our silicon and, uh, existing leading GPUs that we use, um, with Amazon SageMaker that automates, uh, you know, full ML ops pipeline end to end.
Um, we have things like ultra clusters, um, elastic fabric adapters. Again, I I point to look at it at capacity blocks, uh, down to kind of, uh, on Nitro and neuron, uh, you know, as, uh, again, um, um, on urine SDK and, uh, you know, nitro from, uh, hypervisor perspective, uh, where we have done a ton in optimizing, uh, you know, ML workloads and how best to, uh, you know, provide for training and inference. And then we have managed services like Amazon Bedrock, again, um, employee to look at it, uh, that, that employs, you know, guardrails agents and customization capabilities with, uh, a plethora of different LMS that keep adding more and more and more.
And you don't have to worry about, you know, how this infrastructure is used for training your friends and, uh, for, for fine tuning and pre-training. Um, so, um, again, and on top of that, we've built the Amazon queue, uh, suite of products. Um, so, um, yeah, this is, this is really addressing all of these challenges, uh, that you've seen, um, and getting the most value out of your data, finding the right thing, finding the contextually, right, having the, you know, proper response in that.
And that can productively help you on how this data is then being, um, consumed and utilized. Um, and then, you know, it respects your, all your existing governance identities, roles. Um, it also, we don't use content, your content to improve underlying models for others, right?
It is only used for you. Um, and, and, um, it helps you unite all of your data sources. It's available where you work, you know, um, and, um, you know, you have, we have some of the best and highest, um, um, SW benchmarks and security scanning capabilities that outperforms all publicly be marketable tools.
And, um, and this is gonna continue, right? Um, you know, you can work, you know, use it with, um, um, IDs docu, you know, different, um, um, uh, documents and, uh, um, you know, formats and, um, um, you know, slack teams, um, for developers. Um, you can, uh, use it within QuickSight Amazon Connect, and I'm gonna kind of touch on that.
Um, so you have the Amazon Queue business and Amazon queuing QuickSight, which is kind of really geared towards, uh, business productivity. Um, and, uh, you know, helping you with QuickSight is, you know, all the reports and numbers on how best to find, uh, exactly the types of reports, uh, and data that you need to consume. And for business, it's really all of the data, all of the documents, all of the right answers that you need to do your job developer, right?
It assists both developers and IT professionals, not just in coding, but testing. This is kind of code whisper is really for our code generation and other things, but evaluating, looking, uh, testing, upgrading applications, um, from different versions of Java, for example, uh, to diagnosing errors, um, uh, you know, performing security scanning fixes and so on. Um, and, um, you know, it's, this is queue developers more like a chat model to like, you know, the, the, the, the generative, uh, you know, code tool as well.
Uh, like I said, code Whisper, um, that is, is incredibly accurate with use on our services, but as well as other services and more general application of it. Um, so, um, glass Bit is connect. Um, connect is, um, you know, it works to, um, you know, kind of integrate with Amazon Connect, uh, which helps, you know, customers and service agents provide, you know, quicker service using real time conversation with customers.
So it basically brings about different helpful things based on the conversation, um, to help, um, the, the, the humans, the customer service agents provide better answers, not just like, oh, just send those out directly to the customers and all that. But it can, it can be used like that too, but, you know, this is probably a better use case. So end-to-end, this is where we are.
Um, this is how we, um, do, um, all of, um, um, you know, and this was a really a lap around using AI and AI services for security in various different aspects. Um, there are a lot more in, um, um, you know, both services and concepts and, uh, and solutions, uh, for machine learning, um, in our stack of, um, you know, um, uh, in, in our technical stack of things. And then it's, it's, it would, I would really employ you to take a look at it at a lot of these things are on our website, um, um, or reach out directly, um, be more than happy to, you know, go into the details on, um, any of the, of the things you've seen today, any of the things that you haven't seen and you know, you would like to find out more.
So thank you very much. Uh, this is my email. Very easy.
com. Um, and have a wonderful day.