AI and Cybersecurity: Risks and Rewards
Key Points
- AI‑generated text can produce highly convincing phishing emails, undermining traditional language‑based detection methods.
- Generative AI can automatically write code, which means it can also create and embed malware or backdoors into software if not carefully reviewed.
- Hallucinations and prompt‑injection attacks cause AI systems to supply false or manipulated information, amplifying misinformation risks.
- Deep‑fake technology can replicate a person’s appearance, voice, and mannerisms, enabling realistic identity spoofing and social‑engineering attacks.
- To mitigate these threats, organizations must verify AI outputs, guard against over‑reliance, and implement robust security controls while still leveraging AI’s productive capabilities.
Sections
Full Transcript
# AI and Cybersecurity: Risks and Rewards **Source:** [https://www.youtube.com/watch?v=cjy5jpRS_S0](https://www.youtube.com/watch?v=cjy5jpRS_S0) **Duration:** 00:09:58 ## Summary - AI‑generated text can produce highly convincing phishing emails, undermining traditional language‑based detection methods. - Generative AI can automatically write code, which means it can also create and embed malware or backdoors into software if not carefully reviewed. - Hallucinations and prompt‑injection attacks cause AI systems to supply false or manipulated information, amplifying misinformation risks. - Deep‑fake technology can replicate a person’s appearance, voice, and mannerisms, enabling realistic identity spoofing and social‑engineering attacks. - To mitigate these threats, organizations must verify AI outputs, guard against over‑reliance, and implement robust security controls while still leveraging AI’s productive capabilities. ## Sections - [00:00:00](https://www.youtube.com/watch?v=cjy5jpRS_S0&t=0s) **Untitled Section** - ## Full Transcript
what are two of the hottest topics not
only in I.T but in society these days
well if you said artificial intelligence
and cyber security
I'd agree with you both are really hot
in fact even your non-technical friends
have heard of these and may be talking
about them and asking you questions and
I'm going to suggest to you this
intersection between the two even hotter
still so what are we going to talk about
in this video I'm going to talk about
what from a cyber security standpoint AI
can do to you and what it can do for you
so let's take a look at that I'm going
to start with some of the downsides
first and then we'll conclude with some
positive things on the downside what
could AI do to us from a cyber security
standpoint well it turns out that a lot
of times we're able to tell about a
phishing attack because the English
language of the rider is not so good
it's not their first language however
you could now go into a chat bot and use
it to generate very natural sounding
language even though you might say but
but Jeff there are Protections in some
of these chat Bots that if you tell it
to write you a phishing email it won't
do to it there are also ways of
re-engineering your prompt so that you
can get past that so this is one area
where phishing attacks are going to get
better and the ways that we've been able
to detect them in the past are not going
to be so effective anymore
what's another thing well on the
positive side this generative Ai and
chat Bots and things like that are able
to write code for us so if I want to I
can have it write code and do it really
quickly and effectively it also means it
could write malware as well it also
means it could insert malware into the
code that I have it also means it could
insert back doors into the code that I
have so we got we have got to also
verify when we ask it to write code for
us then in fact the code that it's
giving us is pure and is doing what we
intend for it to do
another thing it could do to us
misinformation
how does this happen well these are
generative AIS so one of the things that
they suffer from is this issue we call
hallucination where it may make up
information or conflate two things that
are not really related to each other and
give a false impression also we could
have a determined attacker who is doing
what's known as a prompt injection where
they're inserting bad information into
the system or they're attacking the
Corpus that is the body of knowledge
that the system is based on and if they
were able to do that then what comes out
would be wrong information so we have to
be careful to guard against
over-reliance and make sure that we're
verifying and testing our sources so
that we can make sure that they're
trustworthy one other example I'll give
you here and there are actually many but
I think this one's particularly
interesting is this idea of a deep fake
a deep fake is where we basically have
an AI system that is able to copy your
image and likeness your mannerisms your
voice your appearance all of these
things to the point where someone is
looking at a video of you and they can't
tell if it really was an actual video of
you or a deep fake where we could have
you saying things that weren't true and
therefore if we're going to trust this
kind of system we need a way to verify
these things but right now the Deep fake
technology has gone so far ahead in a
very short period of time that it's
going to be hard to verify those kinds
of things
okay we've just talked about what AI can
do to us now let's look at some
positives what can AI do for us in the
cyber security space it turns out a lot
in fact we do a survey each year that we
call the cost of a data breach survey
and the report that came back this year
indicated that the number one thing you
can do to save on the cost of a data
breach and improve your response time is
the extensive use of AI and Automation
and here's what it can do on the one
hand it can save on average 176 million
dollars per data breach with the average
data breach costing four and a half
million that's a significant savings
it can also cut down the mean time to
identify and contain a breach by a
hundred and eight days that makes a big
difference so we know this is effective
now what are we doing to make these
kinds of results well it turns out a lot
of what we do in this space is to do
better analysis
we're going to analyze large data sets
lots of information that we have out
there it's very hard to find patterns if
I give you a whole large data set but if
I use a technology called machine
learning I can do a lot better job of
spotting outliers and anomalies which is
what we want to do in security a lot now
I mentioned machine learning what is
that well if you think about AI in
particular as this large sort of
umbrella term with a number of
Technologies involved well Machine
learning is a subset of that that
specifically deals with some of these
kind of analyzes that I've just referred
to machine learning is what is often
used in the security space we do it a
lot because again it's very good at
spotting anomalies and outliers and
patterns and that's what we need a lot
of in the security space so we're doing
a lot of this today and a lot of these
results come from leveraging machine
learning which is a subfield of AI what
else I mentioned automation well AI can
help us in the automation task as well
and I'll give you a few examples coming
up but some of the things it can do is
anticipate what we need to do next and
some of those kind of things really
start coming in from the area of deep
learning which is a subfield of machine
learning and then now this really new
area that everyone is talking about
these days Foundation models or you may
hear them called large language models
generative AI chat Bots they all exist
in this space down here what can we
start doing as I said security has
mostly leveraged this in the past what
can we start doing to leverage some of
this stuff going forward well it turns
out a lot of things because one of the
things that Foundation models are really
good at is summarizing
they can be fed a lot of information and
then it can give you a very quick
summary of that why would that be useful
well if you've got tons of documents
you're trying to review it could give
you the net the cliff notes of that
another good use case for this would be
incident summarization and case
summarization if I'm seeing lots and
lots of cases in my environment this
kind of Technology could be used to tell
me what are the trends among those cases
are these things all related or are they
all very different and my guess is
they're probably at least a few things
that are similar about these so that's
an another nice use case that we'll see
coming in the future from generative AI
Foundation models into cyber security
some other things we can do we know
these kind of chat Bots are good at
interacting
so you can respond to them in natural
language you don't have to format your
queries using a particular query
language or using a particular syntax
you use the natural language that you're
used to so for me I would state in
English
what are we being affected by this
particular kind of malware and maybe
what it could do is build a query for me
that I can then run into my environment
and it comes back and tells me am I
affected or not and I can then ask more
questions tell me more about this kind
of malware what kind of indicators of
compromise are there that are associated
with this all of that stuff gives me a
very easy intuitive way to get
information that is highly technical out
of the system and do this much faster
another thing we might want to do is
generate playbooks
playbooks are the things that we use in
incident response when we're trying to
figure out what do we need to do once
we've had an incident so generating
these on the Fly generative AI
generating playbooks you can see where
there might be some type of crossover
this is a good use case also for this
technology so expect to see more of that
and in fact there could be other types
of things where we're using generative
creative technology because these things
really are creating for instance with
threat hunting
a threat Hunter is basically coming up
with a hypothesis and saying I wonder if
someone were to attack us maybe they
would do the following things
and we have a limitation in terms of our
imagination sometimes the bad guys may
dream up scenarios that we don't so it
might be useful to have a system that
can dream up scenarios we didn't think
of using a generative AI to generate
hypothetical cases that we then go out
and automate and do a threat hunt in our
environment this is all really super
exciting stuff I think and it shows
exactly what we'll be able to do in this
space because what we want to be able to
do is move away from being purely
reactive to a more proactive
way of doing cyber security and that's
the good news in this story we've got Ai
and cyber security and if they're
working together as you see here we can
end up with a more proactive Solution
that's more cost effective and keeps us
all much safer
thanks for watching if you found this
video interesting and would like to
learn more about cyber security please
remember to hit like And subscribe to
this channel