The AI Security Edge – Humans, Good Bots, and Bad Bots with Gilles Walbrou | Ep 4
Gilles Walbrou joins Caroline Wong for an insightful discussion on the game changing nature of AI enabled malicious bots and the end of rule-based detection as we know it. They discuss the clever use AI for coding in the experimentation phase, personal experiences getting frustrated trying to pass CAPTCHAs (as real humans!), and the complex multi-step workflow that effective detection systems must navigate – in milliseconds – in order to effectively identify and respond to potentially malicious traffic.
Transcript
Welcome to the AI Security Edge. I'm your host, Caroline Wong. Techstrong TV podcasts feature your favorite video series, industry thought leader, commentary and analyst research on DevOps, security cloud native and digital transformation.
In a podcast format, AI is revolutionizing cybersecurity, both as a weapon for attackers and a shield for defenders. Our podcast, the AI Security Edge, dives deep into the evolving cyber battlefield, where AI driven threats, challenge traditional defenses and cutting edge AI solutions offer new ways to fight back. This podcast explores real world case studies, expert insights and practical strategies for building cyber resilience.
In an AI powered world, you might be a security leader, a practitioner, or an AI enthusiast. In any case, I'm confident that here with us, you'll gain valuable knowledge on the risks, innovations, and ethical considerations shaping the future of digital defense. Today's guest is someone you'll definitely want to hear from.
Jill. Ro is currently leading the tech team at Data Do, where he is building the systems that protect apps, websites, and APIs from bots and online fraud. If you have ever wondered how companies stay one step ahead of automated threats, Gils is right at the center of that fight.
He has deep expertise across cybersecurity, machine learning, and distributed systems, and he's fluent in more programming languages than most of us have. Browser tabs, open, modern c plus plus, Python, JavaScript, Ruby, you name it. But what really stands out is how he brings all that technical depth into real world impact leading teams, defining product vision, and scaling technology to meet the pace of modern threats.
Today we're gonna dive into some really fun topics, including how bot mitigation works behind the scenes, what it takes to build accurate, real-time fraud defenses, and how to stay innovative when the threat landscape never stops evolving. Let's go ahead and get into it. Welcome to the show, Gilles.
We're so happy to have you here. Thank you, Caroline. Nice To be here.
Jill, tell, tell our audience how to pronounce your full name correctly, please. It's a French name, so it's Gil Val. Beautiful.
Thank you so much. Gils. Let's start off with this off.
What is your experience with ai, both personally as well as professionally? So, I'm using AI for years now. I've been, uh, you know, trained when I was a student about ai, especially our network work and all of the technology we had at that time that we're not able to scale as we have today.
Today I'm very excited to use AI on a daily basis. Um, I'm using, uh, gene ai especially to, uh, generic content, for example, when I want, you know, to, uh, start with an id, uh, and generate content, uh, triggering new ideas, uh, on your mind. So I like this kind of ideation process, uh, where you can, uh, easily generate contents and be surprised by the things that you can see from getting out from the AI here.
So I'm using it, uh, personally here for my personal life. Also for the, for the work and, uh, sometimes to have ideation processes with the team as well. I also use ai, uh, now for morning routines.
'cause it's a, it's a good tool nowadays to have, uh, um, automation here. It's easy to build automation with AI nowadays, uh, like, you know, getting the latest trends of something. Um, especially for my work security issues.
Uh, the top of the current security issues are, uh, to quickly summarize, uh, things like, especially research papers. Uh, I don't have the time anymore to read all the research papers. I would, uh, like, so, uh, the new, uh, operators with, uh, return the markets now are able to retrieve the sources so you can, uh, summarize them and, uh, access to the whole content if you want.
So it's really nice and fun to have this kind of morning routines with the content, uh, that's pushed. Uh, we can craft the content to be pushed and it's pushed, uh, to you every morning. So I really like it.
Um, I'm also using AI to generate code for sure, uh, not for production. Um, but I'm using it to generate, generate, you know, POCs or, uh, small steps, uh, of, um, of testers or IDs. I, I would love to, uh, to, to try, as you mentioned, I'm fluent in a lot of languages, but, uh, we are building a software for a lot of different stacks, so having the ability to generate the right, uh, code for the right stack is really, uh, saving me a lot of time here.
And it's not production facing, so I can tweak it, I can play with it and then, uh, move, uh, move forward. Uh, I'm not so much into audio or video, uh, picture generation, uh, feels like a toy to me. I like to, uh, to play with it, uh, with my kids, you know, uh, to, to craft new stories.
I, uh, even to be doing, did that to, uh, design stories for the kids. Uh, but for me, it's a tour. You know, I'm, I'm, I don't use it for work on a daily basis.
Uh, I mostly used gen AI and the new AI stuff to, uh, to generate, uh, content and to think about new ideas. That's so awesome. Um, you know, Gils, I'd love to double click on one topic that you brought up, which is that your person who knows hands-on how to code in so many different languages.
Mm-hmm. And you mentioned specifically that you are using AI to help you generate code, not for production, but for POCs and for some small stubs. And I wonder if you can tell our listeners a little bit more about that.
You know, what happens, you know, you've got an idea you wanna try out, uh, you, you generate the POC, uh, and then what, what is, what is the process for, for you and your team to take kind of something that might start out as AI generated code, and then what does that process look like to get to kind of a production phase? Let's take one example then. Uh, if we want to, um, to try to, uh, simulate a volumetric attack, for example.
So I will, uh, to debug, uh, an issue or to test a limit on, uh, new kind of stack will support. So I will, uh, ask the generate to generate, like, for example, lu a code, uh, for a given stack. Uh, it'll generate the right, uh, code given the constraint I will given.
So, for example, I want to, uh, I want to, um, create HDP request with this kind of, uh, different, uh, headers, volume, et cetera. And the AI will generate the right syntax for the language, but if I just pick it and plug it inside the system, it'll fail because probably it'll miss some built-ins, basic features, uh, APIs that will, uh, miss for this environment. So generally, when we have JavaScript generation, lu generation, it'll expect you'll have some kind of environments you may not have in this kind of systems.
So it's really nice for me. Then, let me take an example. I want to forge, uh, p request, and I want to u on code something I'm missing.
The features I can have the generic to, uh, to generate, uh, nice and short u on code function, not production really. Once again, probably it'll miss a lot of edge cases here, but I don't care for this test. Uh, it's in a few seconds.
I can, uh, fully feel it, you know, and run it, uh, as expected, run my test, and then once again, move forward. So that's the, you know, the ation I have. And, uh, at the end, what I want to extract value from it, like to deliver it as a test, for example, then I can, uh, generalize the, the code.
Uh, in general, I'm seeing patterns I don't like in the outcome of the, the, of the gene ai. So just get rid of it, uh, replace it with my knowledge and, uh, for example, add some parameters to, uh, to make the function free, uh, free, uh, uh, available. So that's the kind of process we have.
So it's, uh, we generate a basic, uh, basic structure and then, uh, start to iterate like we would do as a normal coder if you were to create such a code. Yeah, that's incredible. Thank you so much for sharing that with our listeners.
Um, ails, I wanna move on to kind of our next topic, which is how AI is helping attackers. Um, I think in your role and with your team and the work that you do, certainly you have a front row seat to exactly this. Um, and I'd love for you to tell us a little bit about what are you seeing and how are things changing?
To be honest, that's a game changer. It's a small one today. Uh, good news, it's, it's still early.
Uh, technology is not available to everybody. Uh, it's costly at some point. So, uh, we can see only a smaller subset of the traffic today being impacted by the ai, uh, part at least.
But AI powered attacks are definitely a game changer in the, in the field. So how the foster are leveraging such technologies, uh, it's, um, making them, um, um, able to, uh, craft new kinds of attacks, especially for our job. You know, the, we have a behavioral, um, uh, engine to analyze the, the behavior of the attack, for example.
That's how we can fingerprint the behavior of an attack in general. Uh, the, what we'll see on the market is static. Uh, thing that's are relying on static rules.
You match the rule or you don't match the rule. If you match the rule, you'll be blocked. Otherwise, it'll be a load.
Attackers know that. So, uh, they want to, uh, try to find the right combination of headers, payload that they will, uh, that, uh, allow us, allow them to, uh, get through. So what they're doing, they're putting in place and automate that will generate such things.
Making, try, try, try and fail, try, try. And then they will, uh, slip through. Then they will, uh, what we can see, they will keep these kind of signatures, continue this kind of trend, a small trend to, uh, try to forge the signatures.
And they will leverage a signature one by one. Generally, you can find on market system that will detect such ary volumetric attacks. They will try to, uh, create a signature and block them.
Then it's too late. They would just rotate and use the next signature they found. So it's, this was, uh, possible before with a human code that will try to hack it, and you can, you, you could feel, you know, when you, when you block the traffic, you can feel that, uh, it's a human behavior in front of you that will try to, uh, to find the right combination.
Now we can feel that it's ai, it's, uh, fully automated. So the, the game changer is time, time to adapt, time to, uh, needed to find this kind of combinations and, uh, to be able to scale and attack. That's, that's really game changing.
Uh, we can see on the, on the market, especially for the, for this kind of complex attacks. And, uh, they try to evade every detection system you can find and try to mimic human behavior as much as possible. Next thing we can see, we can see on the field is every system that I'm, uh, charge of, uh, securing an endpoint, one of them is caps and caps.
We could see, we could see that, uh, we moved from human, uh, real human passing, the captures like capcha forms, you know, uh, to, uh, fully automated, uh, anti capture systems. And same here, they are trying to find the right combination to forge the, the right signature to try to pass the capture. And we can see as well a computer vision aided system, uh, where they, uh, they will locate in, they will locate the right, uh, challenge and try to pass it with ai.
So that's, that's a game changer as well. And, uh, the price, uh, and the cost to pass such systems, decrease the loss thanks to ai. Once again, the scale and the cost, hence lots of systems bought as a service on capture service you can find on the market that are packaged to bring, to bring you, uh, a way to evade a specific, uh, protection system for a vendor.
If you want to buy a limited edition product, for example, uh, or to access something on a, on a website. So we can see lots of that. And, uh, that's something we want to bring to the customers, uh, more and more often, uh, to show them the kind of attackers they have in front of them, and to tell them, this is what we blocked.
So to connect the dot between, uh, what they saw, what they feel, and what we are able to know in terms of threat intel plus, uh, signatures of what we blocked. Wow. You know, I have a, I have a funny little joke, uh, to share, which is, as a human, I often encounter captions.
Yeah, for sure. Uh, and sometimes they're hard. You know, sometimes, sometimes I cannot read the letters.
I cannot tell what numbers it is. Sometimes I cannot find all the bicycles or all the bridges. Mm-hmm.
You know, and so, uh, my funny joke is, uh, maybe I should be, uh, using AI or maybe I should be, uh, using a service, you know, uh, capture farm, you know, um, ask some folks, uh, who live in a part of the world where, uh, you know, this is a type of service that they can provide. Maybe, maybe I should hire them so that I can in fact, uh, bypass my own caps that I, that I experienced as a user. Um, so that's just a, that's just a silly, silly joke Read.
And bots are better than you to put the capture. It's, uh, it's no joke, you know? So it's, uh, it's frustrating.
I, I have the same experience, uh, here. So to be presented with a capture, it feels like a gate you need to pass, uh, to show that if you are a real person is not, uh, the best chance in the world. So what we did at, at Data Home is to, uh, expose this kind of challenge.
We have a very simple capture puzzle game. Uh, and it's, the security is not the challenge itself. It's an easy challenge.
Security is how the, the how we are collecting the data, uh, while you are passing the capture. So we present the capture only if we think you are a bot, Ah, To validate you if you, if we think you are a bot. And at some point, I, I would love to put my fingerprint somewhere to say, I don't want any capture anymore.
Take my blood, take my fingerprints, and through them, Don't make me do a capture. You know, what I feel at some point with all the gene AI hype, we can see with the open AI operators, all the agents we can see on the market today, I'm basically sure at some point we'll have to do it for the bots, for the agent. You will have that will, uh, act as yourself on the web.
So I feel at some point, maybe not the blood, or maybe not the fingerprint, but at some point, you'll, you'll tell this thing, this is me, and this, this thing is acting as me. So, uh, let's, uh, make this thing go through on the website, because it'll bring with business. And that's one of the big concerns here for the, uh, e-commerce website.
All the vendors that are exposing, uh, business on the, on the web, what should we do with the AI agents? Is it bad? Is it good?
Is it between? So how we can see where they are, how we can feel them, and how we can hack on them. You know what, that's exactly what we did with the bots.
So it's be, thanks to behavioral analysis, we can do that. So it's not a matter of your headless chrome, or not, probably it will, uh, open AI operator is based on it, so it's bot, okay. But it's a good one that will bring good business, not hurt your business.
So you have to be able to have a signature on it, not based on the network necessarily, but based on the behavior it'll have. And that's one of the key technology we have, mixing those two things to be able to analyze the behavior and create the right pattern to, uh, identify this kind of traffic. This is all automated and this is what, what, uh, why we can scale and block this kind of attackers.
They have ai, so we do, but ours is better. So we can, uh, and at scale, you know, we have all the data, uh, of the traffic worldwide, so we are able to identify the right patterns in the whole traffic. So that's why we can do sometimes better job done our own, uh, customers because we have a wider scope in term of traffic that's a key asset, uh, in this field.
Wow. You know, this is, uh, this is a relatively new concept for me to consider, right? Because of course, for a long time we are thinking about bot versus human, which is which, but now with this introduction of like a new character into the story, right?
Human or good bot or bad bot, uh, and, and perhaps more accurately bought, which is intended for legitimate use versus bought, which is intended for malicious use. And so I think that's, um, that's so fascinating. You know, Gils as a, as a, as a final question for today, uh, and you gave us a bit of a preview.
You said the attackers are using AI and we are also using ai and our i AI is better. And tell me more about that. How, how is AI helping cyber professionals cybersecurity defenders?
In lots of ways? In lots of ways. So first one is to be able to detect fingerprinting.
You know, it's a quite classical, uh, now, so it's a way to, uh, have a kind of a scoring based on a number of features. So you can use HDP error, you can use, uh, the contents. You have lots of features here to, to decide if something looks like a bot when it'll, uh, get on your website.
So it was kind of the worst technology, you know. But behind that, you need to have behavioral analysis, anomaly detection, uh, ways to be, uh, to, to be able to split the traffic in term of different semantics. You know, one example, the ip, we have a whole flow of data to be able to analyze what's going on with the ip.
Is it a hundred percent bot? Is it well known in our database? Uh, like it's fully bot, is it linked to a botnet?
Is it linked to, uh, a ticketing bot, for example, in this field? So we have like expert system, uh, and today, we'll call them agents, you know, uh, dedicated on a part of the job and what we can see today emerging yet again, uh, with the AI technologies, multi-agent systems, so expert system that are well for this one, uh, expert in the ip, uh, analysis. Then, uh, the session analysis then, uh, how the, the session will behave.
Is it a scraper? Like it'll go through the, all the three of the, the website, is it, uh, um, a bot that will, uh, go to the product page, then to the checkout, and to the, to the, uh, the paying segments, uh, very quickly. So all these kind of things you have, we have, um, specialized, uh, AI here that will detect those signals, and at the end they will say, okay, this is looking like a bot with my scope.
Then signaling the signal to the other ones. And we have kind of a consensus here that will detect and we'll say, okay, this is, this is bot for sure. Uh, we have all the red flags everywhere, so this is bot for sure, and we'll provide the right answer to this decision.
Are we sure? Absolutely. Sure, let's block it.
Hmm, maybe, maybe not some. Let's present the caption, see if we are wrong. If we are, we learn from it.
Uh, we, we miss some signals, let's push a dedicated challenge, invisible one, so we can bring more signals here and take a better decision later. So all this is done in a matter of milliseconds, uh, with the technology we have. So it's very fast.
You know, we know that we have adaptative system in front of us, but architecture is very, very fast, and it's self-learning, you know, so that's the key aspect here. If you want to fight against the bot, you can put a lot of humans reviewing the traffic experts like, uh, the one I described. But with ai, you have something at scale very fast, very quickly to decide, and that we can, you can track during time.
That means if you want to provide to customers something that is not a black box that looks like a good decision, you can, we can explain to the customer why we took this decision, which is key as well in the field. If we don't have that, that's a black box. Security experts doesn't like black box, trust me.
They want to have control here. They want to, to be able to build trust with a vendor, and you know that for sure. So that's how I think, uh, ai, uh, is useful for, uh, the security, the cyber defenders today, being able to scale, being able to act quickly, and being able to have expert system that are able to log their decision to expose why we choose to, to do this on the traffic of our customers.
Wow. I mean, you know, when you're talking about being able to go through that whole workflow and to pivot and to give a different, uh, path and a different response, um, you know, in, in just the time that it took you to explain that to us today on the podcast, the system, your AI system has already done this. Thousands, tens of thousands.
Yeah. Maybe hundreds of thousands of times. Yeah.
You know, that, that to me is like, it's like actually a little bit incomprehensible. Like, I don't, like my human brain doesn't really know how to think about that. I think that's absolutely astounding.
Thank you so, so much. You're Welcome. Thank you.
Hey, it's been so much fun to have you on today's podcast. Thank you for taking the time to be with us and to teach us a little bit about your work and what you're seeing, uh, in this constantly changing field. Um, folks, we really appreciate you being with us and listening.
Uh, this is the AI security edge. Um, please, uh, you know, enjoy all of the different episodes, uh, that we've got here for you. Um, we've got, uh, some already, uh, for you to view and we've got many more, uh, coming.
So, uh, we really hope you are enjoying it. Uh, and don't forget to check out the other Techstrong TV podcasts as well. Um, whether you're interested in learning more about DevOps, security Cloud native or digital Transformation Tech, strong TV is your place.
Thanks so much. Thank you, Caroline.

