Both Sides Got the Same AI, So Cyber Defense Must Automate

Episode Summary

Attackers and defenders now reach essentially the same AI tools, separated by what Staffan Truvé estimates at three to six months. On his reading that does not necessarily change the balance of power, and he puts it no more strongly than that: defenders keep the advantage of knowing their own systems and holding the source code, while an attacker works the black box from outside. What changes is the clock cycle. Both sides can find vulnerabilities faster than before, which he says pushes defense past what people can do at the speed now required and into what Recorded Future calls autonomous threat operations, detecting, prioritizing and mitigating at machine speed. Prioritizing does not go away, because only around one percent of vulnerabilities are ever used in a real attack. Asked what an executive should fund first, he declines to name a budget percentage and names the backlog of known, unpatched vulnerabilities instead.

Key takeaways

  • Assume a threat actor is three to six months behind you, and treat that as the working estimate he gives it as rather than a measurement. He scopes it further: they will not have the closed models, but they will have open weights models, and while they may not have the exact top-notch hardware they will be close

  • Do not concede the advantage you still hold. Defenders have the insider knowledge of their own systems and the source code, and an attacker has to look at the black box and work out how to attack it from there

  • Expect the clock to change rather than the balance. He is careful about this: it is not necessarily clear that any of it changes the power balance between attackers and defenders, and the only thing that can be said for certain is that the clock cycle goes up

  • Plan for defense to move past human speed. He describes an era where it is beyond human capability to act at the speed that is necessary, which is the reason he gives for working on autonomous threat operations, or autonomous defense, whichever term you prefer

  • Keep prioritizing even after you automate. Detect, prioritize and mitigate is one sequence, and he is explicit that even working at full machine speed you still have to decide which threats are the most imminent, judged on which systems you most want to protect and which attack vectors are most likely

  • Do not expect AI-written code to arrive safer. His position is that AI now exceeds human capacity at speed but not necessarily at the skill level, so you should expect at least as many vulnerabilities in AI-written code as in code people wrote

  • Separate authenticating an agent from authorizing one. Authentication he treats as broadly the same problem as for humans; authorization is the tricky part, and the question he puts is whether an agent that spins off a swarm of sub-agents may hand them the same authority it holds itself

  • Fund the backlog before you fund anything new. Asked for a budget percentage he declines to give one and gives an order instead: the known vulnerabilities already sitting unfixed come first, because on his reading the likelihood of their being exploited is going up dramatically, and next generation testing tools come after

About Guest1

Staffan Truvé is the Chief Technology Officer and co-founder of Recorded Future, the threat intelligence company, which he started in 2009 and which is now part of Mastercard. He holds a PhD in computer science from Chalmers University of Technology, where he now sits on the board, and was Chief Technology Officer of the data visualization pioneer Spotfire. He has chaired AI Sweden and Qamcom Research and Technology, served on the board of the Swedish innovation agency Vinnova, and sits on the board of WASP, the Wallenberg AI, Autonomous Systems and Software Program. This is his second appearance on the AI Realized Podcast: his first, on why threat intelligence belongs on a board agenda rather than only an IT one, is episode 32.

 

In this episode

00:00 Welcome, and the introduction to a second conversation with Staffan Truvé
01:39 Have threat actors moved to next generation AI attacks yet?
02:26 Why the strangest events so far have come from the AI platform companies themselves
03:02 Fifty thousand CVEs, under one percent exploited, and where the bottleneck sits
03:30 Attackers and defenders reach essentially the same tools, three to six months apart
04:53 The power balance may not change. The clock cycle goes up
05:11 Beyond human capability, and the move to autonomous threat operations
05:29 Detect, prioritize and mitigate, and why prioritizing survives automation
06:27 Why the lag on known, unpatched vulnerabilities is so long
07:41 The two OpenAI models that broke out of a test environment
08:25 No reason to think AI-written code is safer than human-written code
08:49 The air gap that was not one, and how the model got out
10:01 Longer chains of reasoning, and the model that cheated because cheating was faster
11:11 Is the Mythos moment what ransomware was, and what should a board do about it?
12:01 On everyone’s agenda now, and where he thinks the significance is overestimated
13:27 His main point: this was foreseeable, so nobody should be surprised
13:40 The internet of agents, and why passwords and multi-factor are not enough
14:52 Authenticating an agent is the easy half. Authorization is the hard one
15:05 May an agent give its swarm of sub-agents the authority it holds itself?
16:05 The reviewer who can flag a problem but cannot stop the deployment
17:19 Deception networks, or next generation honeypots
18:09 Fake copies of your real system, and what the attacker has to spend to find the real one
18:37 Every decoy is also a sensor
19:54 Will there be security-only models? Maybe, but he is betting on the general ones
20:32 Homomorphic encryption, and the design space for creative defenses
21:40 The bad guys collaborate, so the defending side has to as well
22:19 The one thing an executive should do differently, and why it sounds salesy
23:26 Why he will not give a budget percentage, and what he says to fund first
24:29 Insikt Group and The Record: what Recorded Future publishes for free
25:49 The leadership problem is a lack of imagination
26:50 Remember this: it is happening now, and next year is too late to start

In Guest’s words

“It’s not necessarily clear that this changes the power balance between the attackers and the defenders. The only thing we can say for certain is that the clock cycle goes up.”

Staffan Truvé   (04:53)

“And I think, we are therefore coming into an era where it’s beyond human capability to act at the speed that’s necessary.”

Staffan Truvé   (05:11)

“Even if you are working at full machine speed, you still need to prioritize.”

Staffan Truvé   (05:29)

“I don’t think there is any real reason to believe that AI-written code is safer than human-written code.”

Staffan Truvé   (08:25)

“I think the thing is that we should not be surprised about what’s happening now. That’s my main point, actually.”

Staffan Truvé   (13:27)

“Is that agent allowed to give all its sub-agents the same authority as it has itself?”

Staffan Truvé   (15:05)

“Let’s take our actual system, let’s build a bunch of fake copies of it.”

Staffan Truvé   (18:09)

“The beauty is of course that each one of those deception systems becomes a sensor.”

Staffan Truvé   (18:37)

“Since the bad guys collaborate, we have to collaborate on the defending side as well.”

Staffan Truvé   (21:40)

 

Resources

Staffan Truvé and Recorded Future

  • Staffan Truvé on LinkedIn: Where he posts. Asked how to follow him he says he has no regular feed and puts things on LinkedIn when he sees something interesting

  • Recorded Future: The threat intelligence company he co-founded in 2009

  • Autonomous Threat Operations: Recorded Future’s name for the approach he describes: detecting, prioritizing and mitigating continuously rather than at human pace. He names it on air as autonomous threat operations or autonomous defense, whichever you prefer

  • Insikt Group research: Recorded Future’s in-house analyst group. He points listeners here first, describing a policy of having their own analysts do the research and write reports, with a lot of it free

  • The Record: Recorded Future’s cybersecurity news site, which he calls the media side. He recommends it as a free resource for tracking trends in cyber, and notes it carries no advertising

Referenced in the conversation

Ideas and terms discussed

  • Autonomous threat operations: Detecting, prioritizing and mitigating threats at machine speed, on the argument that the necessary pace has passed what people can sustain

  • Deception networks: His own term for a fleet of convincing fake copies of a production system, presented alongside the real one so an attacker spends resources finding which is which. Each decoy doubles as a sensor on how the attacker works

  • XACML: An access control standard he recalls as roughly twenty years old, for expressing delegated authority, including the right to delegate authority onward. He raises it as prior art worth revisiting for agent authorization

  • Open weights models: Models whose weights are published, which is what he expects a threat actor to have even when the closed models are out of reach

  • Air gapping: Running a system with no network path to the outside. The OpenAI incident he discusses is his example of an environment believed to be air gapped that had restricted access instead

Related AI Realized episodes and events

 

Frequently Asked Questions

 
 
 
 
 
 
 
 
 
 
 
Next
Next

Agentic AI Business Strategy: Retrofit or Reimagine the Work