Ladies and gentlemen, the program is about to begin. Reminder that you can submit questions at any time via the Ask Questions tab on the webcast page. At this time, it is my pleasure to turn the program over to your host, Tal Liani. Great. Thank you, everybody. Thanks for joining us again. I'm excited to host CyberArk today, a leader in identity security, to discuss AI implications across cybersecurity. We all ask the question: How would cybersecurity be impacted by AI and generative AI, both on the defense and the offense parts? To discuss this, we'll be hosting Lavi Lazarovitz. Lavi is the Head of Cyber Research, where he leads a group of ethical hackers that examine emerging attack techniques and post-exploit methods. Lavi and I share something unique. Both of us have names that no one can pronounce, so after even 30 years, it doesn't matter. I'm very pleased to host Lavi. I'm sure it's gonna be very interesting. The session is a presentation, and I know you're gonna be interested in the presentation. Lavi is gonna take us through examples. It's about 26, 27 minutes, maybe 30 minutes. After that, we're gonna open the lines for Q&A. There's no lines for Q&A, as you know. You need to submit me the questions. You can submit the question throughout the presentation on the portal, and I will read it to Lavi at the end. Erica Smith, SVP, Investor Relations and ESG, will also be joining us for the Q&A part. Lavi's presentation will cover both the advantages and the disadvantages of AI and how it relates to cyber. So, Lavi, over to you. Thank you very much, Tal, for inviting me and for the warm welcome. As you mentioned, it's gonna be super interesting. I have a few examples. You were one of the targets for our research here, and I'll share it with anyone pretty soon. So, let's get right to the session. I'm gonna start with something that you probably all saw. You probably heard about generative AI and the recent ChatGPT developments, and not only classifying data, but generating text, images, audio, and so on. If you follow investment advice, you're giving them, you probably heard about the guy who asked ChatGPT for the best way to invest $100 and then turn it into as many dollars as possible, as you see here on the screen. If you're into cryptocurrencies and Web3, you maybe thought about asking Midjourney, "What does Satoshi Nakamoto, the inventor of Bitcoin, looks like?" Like the guy here on the right. There's been a lot of buzz about AI recently, and with good reasons. Generative AI is incredibly powerful and became incredibly accessible. Today I'm here to talk to you about the attacker's innovation, the other side, and generative AI. Let's move on to the next slide. This incredible leap for AI is, as I mentioned, also available for attackers. There's already been a lot of discussions on how this giant leap in AI technology is changing the threat landscape and driving attacker innovation. As I mentioned today, I'm, I, I would like to share with you a few, a few of those insights on, on those new attack vectors, and especially, the identity security perspective. I'll do it, I'll do this with research and insights from, from CyberArk Labs, where I come from, and other security researchers. Tal mentioned just a bit about, about what we do. I'll, I'll elaborate a little bit more. The team, the research team and myself, we, do... If, if I have to admit it, we, we have a fun job. Our job is to break things. The research team main mission is to play the attackers, attack emerging technologies, authentication protocols, operating systems, and security boundaries in general. We also research and understand deeply new malware and recent attacks. We use our understanding of the attack surface to shape new defense lines around identities, with CyberArk product and innovation teams, close by. We also share quite a bit of the research with the community through our blog, open source tools, and security conferences, and this is also a great opportunity here for me today. So let's get right to it and hop into the next slide. To help visualize where AI technology intersects with the attack chain, I'll take the commonly used MITRE M atrix, which breaks down the different attack techniques to matching categories or tactics, like reconnaissance, as you see here, initial access, privilege escalation, and so on. I'll examine different AI-based tools, techniques, and procedures, this is also called TTPs, and map those TTPs to different tactics and categories while highlighting how the AI TTPs will affect those. Then I'll try to predict, or, I shall say imagine, if you like Midjourney terminology, the upcoming effects of AI on the attack techniques and the threat landscape in a more general sense. So, this is the metrics that you see here with the different categories. And the next slide. One evident intersection we have, we've already seen is generative AI-based deepfakes used to impersonate celebrities or even U.S. presidents. The deepfakes can be used for phishing or vishing, which is the voice version of phishing, which falls under the initial access category of the MITRE matrix. I would like to show you a quick example of how this vishing attack might look like very soon. Just imagine this. I imagine me going over my deck for today with my main messages, and suddenly getting a message from Tal, and I see his avatar on WhatsApp, and he sends me a voice message. I want to show you how it looks like. So let's hop into the demo video. Hi, Lavi. How is it going? I can't wait for your session this week. Erica mentioned that you can help me with your recent research reports. I need them ASAP. Thanks. You can send the link here. I'll see you soon. Thanks. So I played the messages. I sent Tal a message asking where he wants the reports. And, you know, I was probably thinking to myself whether I should check with Tal or I should check with Erica, if I should really share the reports, if this is really Tal. But it's not him. I trusted him, but it's not him. And to create this demo, we actually used AI text-to-speech model that was trained on Tal's voice for media interviews. And believe me, I had to listen to Tal talk about Cisco and talk about his understanding interpretation of the market, which I learned a lot, and also created this short and, I think, very trustable voice sample. Now you can imagine that the distance from here to getting access to sensitive information or credentials is very short. We learned a lot about scrutinizing texts and emails and be wary of phishing attacks. Obviously, not completely, because many people still fall for this attack, but generally, people know that it is risky to click links in emails. Generative AI vishing is yet another instrument that is available for attackers. Now, they can use AI-generated voice to create a sense of trust in their target. In this case, it was me. And I should also say, I also used the model, obviously, to get Tal's approval to use his voice. You should hear that as well. Hi, Lavi. I love that deepfake voice. Feel free to use it on stage. On stage. So you can imagine how such vishing can be done in scale using automated real-time generation of text and text-to-speech models, and you see that we can also generate the approvals ourselves, so it's super, super easy. I'll probably use it in the near future for other requests. I'm not. All right, let's move on to the next slide. Another thing that we're experimenting with is real-time video and audio deepfakes. It could be used not only for audio messages, but also for real-time video chatting. Now, imagine getting a video call from the CFO, the CEO, asking for something in their voice and face. And I wanna show you a quick demo of how that looks like. So you can play the video from the previous slide. Hi, I'm Udi's clone, and I'm very excited to be here, and it's just great to talk to you all. Very excited to be here, and it's just great to talk to you all. Okay, I know it probably felt a little, a little odd. This is a recorded demo of Gal Zror, which is a CyberArk Labs Group Manager, talking to the camera while the model reflects Udi Mokady's image, who is a CyberArk founder and chairman. And just imagine getting a Zoom with that reflection, how maybe a little bit scary at first, and obviously, how it might create trust issues for all of us. We should also take into account that those models become more accurate, more accessible, not so much resource demanding, which means that those will become more believable. The technology can create mass vishing campaigns that could boost the phishing email click ratio that currently stands around 5%-10%. 5%-10% is the ratio of the number of clicks against the number of emails sent in a phishing campaign. Now, think about that. Think about yourself, would you fall for such phishing or vishing campaign? Think about yourself, would you fall for such phishing or vishing campaign? And thinking, "No chance, this is too basic." Then I'll say, okay, the examples that I showed you here today is, is still very specific and tailored and handmade, but, in technology, we have this API-first approach that, that can actually solve this problem. It's possible to create and automate feedback loops, A/B testing, dynamic adjustments, and so on. It might have not worked with you here today, but you already helped a lot just by giving the model inputs that can be used to correct the model.... and now just imagine how many employees are there in, in your company? How many employees are there in Bank of America? This is the number of opportunities that threat actors have, to phish or vish or get initial access. This is just today. It will learn from this attempts, failed or not, and become better to offer any other victims new tests tomorrow. Now, you might ask, what about using AI technology to identify AI-generated voice? And one point, one input for you to consider is that AI models become as AI models become more mature, identifying AI-generated artifacts will not be trivial. It may not be a balanced equation. AI experts predict that AI-generated content will eventually be practically indistinguishable from human-created content. It's trouble for the academy, much like it might be for a security professional. All right, so moving on to another intersection that we can expect, which is generative AI with biometric authentication. Now let's move on to the next slide. Let's switch from attacking the ears to attacking the eyes. Face recognition is now a common authentication option, and generative AI could be used to attack this type of authentication, providing another way for attackers to compromise an identity and gain initial access on an endpoint on a server, and here is one very interesting example for it. One exciting research done in Tel Aviv University attempted to ask whether it is possible to create a face generated by AI, like this one that you see here on the screen, that could be used as a master key for all face recognition authentication protocols and faces. The researchers at Tel Aviv University used an AI model called GANs, or Generative Adversarial Networks. It differs from the model that Midjourney uses, which create images based on text. The GANs model, the researchers built, represents an image using a vector, just a set of numbers defining the image characteristics. It then manipulates this vector, changing it just a bit, to create a different image that might match more image vectors. Let's see how it works at high level. Let's move on to the next slide. They started with a random image and represented it as a vector. You see it at the top of the screen. This vector is compared to other face vectors in the image database. The comparison is then fed to the image optimizer, where the magic happens, essentially. The optimizer outputs a new optimized image vector, which is then used again as a seed for the image generator to create an actual face image. And this face is compared again to all images in the database, and just wash, rinse, repeat. This is the process. Now to the outcome. We'll move on to the next slide. The outcome of this iterative process, executed multiple times on different face recognition algorithms and different optimizing algorithms, produced 9 sets, those are the rows in the on the screen that you see, each of nine faces, each with its own success rate, which you can see under each image. The percent is the number of faces that match this specific face. Now to the best result. Let's move on to the next slide. The best result the research produced is a set that matched more than 60% of faces in that database, and this is remarkable. That means that with this set in hand, a threat actor has 60% chance to bypass face recognition authentication and compromise an identity. 60% means that this attack vector is viable. But still, you should say, "Well, this is a theoretical research." Now, because this is a theoretical research, I want to show you the practical implication, how a threat actor could bypass actual face recognition authentication. To show you that, I wanna focus on a research and a demo that we've done inside of our labs, focusing on Windows Hello, which is a common implementation of face recognition authentication. Let's run through the first part of the demo. I hope that you saw that. Let's run the second part and continue from there. All right. So I'll explain now. What you saw in this demo is that our researcher, Omer Tsarfati, he used an evaluation board. This was the card or the chipset that you saw on the table. On that card, on that evaluation board, Omer implemented a mimic of a Windows Hello compatible camera and integrated his own image vector. And now, as soon as he connected the evaluation board to the laptop, the evaluation board start bombarding Windows Hello again and again with the image vector until it hits the right timing and the machine opens. And that was our proof of concept to show how bypassing authentication, how initial foothold could take place using this set of images that we've seen in Tel Aviv University research on MasterFace. Now, one question that I ask myself, and I also asked Arik Paran, who is CyberArk Labs Director of Machine Learning and AI, is why now? Generative AI models have been around about a decade now. Why did the breakthrough happen just now? The short answer to that is simply scale. What happened recently is just the sheer scale of the learning that takes place, and I want to show you the numbers behind it. So let's move on to the next slide. The graph that you see here shows the number of parameters on the Y-axis. Each notable breakthrough model since 1950, the time aspect of the time dimension is on the X-axis. The number of parameters that each model had to process during the learning stage. Now, in 2019, GPT-2 was released, the previous version of ChatGPT, excuse me, was based on it, and the model size of GPT-2 is about 1.5 billion parameters of text and words. In November 2022, GPT-3 came out, and GPT-3 model size is about 175 billion parameters, and that, that is more than 100x growth in just, in just 3 years. This is, this is remarkable. Let's move on to the next slide, and you can probably already see that the growth here is exponential and very steep. You might also notice that the number on the Y-axis also grows exponentially, which means that the number or the model size curve here is, is super steep, is extremely steep. This growth in parameters is directly connected to advances in cloud computing. This is what changed. This is what's powering more advanced AI features and threats. And what this exponential growth means is that we should expect AI models to become better, much better, and it will happen fast. AI models will be better in creating deepfakes, in creating face images, malware, and so on. It will change the threat landscape, and it will change it soon. And in other words, if you think you wouldn't fall for Tal's fake voice or Udi's deepfake face and voice that we've just heard, you should probably come to CyberArk Impact next year or just follow CyberArk Labs, because those things will change rapidly. And one thing that it's important for me to note here is that any machine learning expert will tell you that it's not only the size here that matters. Training data quality is exceptionally important. As machine learning experts like to say, "Garbage in, garbage out," and in this case, we have billions of parameters in and out. So of course, besides the sheer size of the model, there's a lot to it. What data is processed, how the data is processed, the logic of the learning models. Many brilliant researchers have spent years developing those algorithms that will scale and produce highly accurate results. So it might give us all a little bit room to breathe, but not so much. Every security company, including CyberArk, are making moves now to counteract this change in the threat landscape. All right, let's move on to the... or back to the MITRE ATT&CK and to the next slide. We talked about vishing and authentication bypassing and the initial access, and we can also expect the curve we've just seen to produce highly effective classifying models. I'm sure you remember that last machine learning hype cycle in security, where everyone talked about how AI will be able to identify malicious activity just by sniffing logs in network traffic. Well, and to be honest, we can expect the classifiers to be effective and allow or more effective than blue teamers and threat actors to find vulnerability patterns more effectively. We've already seen plugins for decompilers, which is commonly used by researchers to make it easier for the researchers to analyze binary code by adding code documentation and so on. We can expect vulnerability scanners to leverage AI capabilities, making the daunting vulnerability scanning process more effective. We've seen GitHub Copilot and even ChatGPT generate code, and we can, of course, expect the same with malware. AI harnessed for offensive campaign make an impact on the early stages of the attack and during the pre-initial foothold, and during reconnaissance, malware development, and the initial access, as we see here. Yet, one thing to note here, that it's not clear that AI TTPs or tools, techniques and procedures will make any impact on the later post-initial foothold stages, the privilege escalation, credential access, and lateral movement. It seems that the tools, techniques, and procedure used today will still be effective. Maybe most importantly, what we understand is that it appears that identity, the authentication, the credentials, will still be a prime target, as we see in today's attack... Just to add a quick note here, Microsoft recently released a report on an attack group called Storm that targeted Microsoft, and they targeted their QA engineers in a very clever way to extract sensitive credentials for customers. So just another note or a data point to understand that attackers are after identity still, even in this AI changing threat landscape. So point is, defenders still need thorough intelligence in identity security controls. And one exception to my understanding here that we see about the pre- and post-initial foothold stages. This exception that you see here also noted is polymorphic malware, and I want to touch it just a bit. Let's move on to the next slide. Polymorphic malware is a malware that mutates its implementation while keeping the original functionality intact. Until recently, malware was called polymorphic if it changed how it encrypted its different modules, making it challenging to identify the malware. Generative AI opens the possibility to mutate or actually regenerate code with different implementation. Our lab researchers experimented with creating the polymorphic malware using ChatGPT. By the way, we use ChatGPT not because it's the best AI model to write code with, it's absolutely not, but because it's so accessible and was fun to play with. Let's see a quick example of it in the next slide. We asked ChatGPT to generate an information stealer, a malware, a malware that fetches cookies and password once executed on a machine, and this is what we got. I'm not going to delve into the code. Just by looking at the color coding, you can see that ChatGPT created here two different implementations: the right blue one, which actually worked, and the left, that didn't. During the experiment, we learned that ChatGPT is enthusiastic, yet very naive developer. It will write code quickly, but it will miss the details. It might not import libraries or other dependencies. In our case, at our first attempt, instead of just using Windows API to decrypt cookies, it just used a hard-coded password you see on the red rectangle in line 27, password equal peanuts. The generative AI or ChatGPT just made it up. It assumed that this is the password and tried to decrypt the cookies with it. And, one of the things that we learned from it, based on that experiment, we learned that the concept of defense evasion using polymorphic malware created by AI is viable. ChatGPT didn't do a good job, but other models are doing a good job in writing code and potentially malware. And we can, of course, accept models that are trained on huge code repositories to generate better code, legitimate or malware, as mentioned. And now I want to quickly imagine with you how an information stealing campaign might look like, using a polymorphic malware. And, I have three short or three-part demo here showing a campaign behind the scene. We are usually... We are hearing more about the victims, user organizations infected with information stealers, stealing code, cryptocurrency wallets, keys, and so on. I want to show you how it might look like from the other side, very soon. Let's have a look at the first part. All right, so at the first part of this demo, what you saw is a threat actor choosing a target, choosing the code or the malware he wants to generate. In this case, as I mentioned, information stealer, and a generative AI malware module starting to build that model. And it tries several times until it finds a sample that works, which could be a sample that I haven't seen before in the wild. Meaning that for security agents, it might be difficult to identify this code as malware. This is, this is the first part. Second part will be on how it is deployed on the endpoint and stealing the credentials. So let's see the second one. All right, so what we saw is our victim, Roy, logging in. Immediately, all the cookies are stored within the browser, and the malware now copying it. Last, the last part that you'll see is a simple what we call session hijacking, where the threat actor now use the cookies to access the victim's session. So let's see the third part.... All right. So the last part, as I mentioned, was just a simple session hijacking, with the most important thing or the most, the new thing here is how the malware generated and how it's not detected by any security agent. All right, so I wanna conclude and highlight the bottom line. Let's move on to the next slide. If you're thinking about this relatively simple yet visionary demo and the previous initial access demos, we can learn a few things. The first thing that we can learn is that AI already has, and will continue to have, an impact on the threat landscape. It will change how we find security weaknesses, or at least how effective the process is, how code is developed, and how malware is developed. It will open new opportunities for threat actors to target identities and even bypass authentication. We saw the curve, it will get better and better, and fast. We also see that common techniques, like session hijacking or DLL hijacking, and other techniques for escalation of privileges, or defense evasion, or compromising valid credentials to the bank, to the bank account, to a crypto wallet, and so on, will still be effective and in use. Identity is still a prime target for threat actors. Compromising identity will keep being the most common and effective way for threat actors to move laterally and gain access to data. Lastly, we can see that malware-agnostic defense approaches become even more critical. Meaning that for any organization out there, developing a security layer that not only attempt to quarantine malicious activity, but enforce preventive practices, is critical and essentially around identities. Examples of this include implementing endpoint privilege security, conditional access, restricting privileges on the endpoint, and so on. These malware agnostic controls will continue increasing in value and effectiveness, considering the changing threat landscape that AI brings to the table. AI will also help defenders. AI can be used to counter and or to counter the change in threat landscape. AI and generative AI can and should optimize security controls deployment. Imagine AI generating a policy, security policy, a list of privilege policy that it fine-tunes, so it allow you to work and provides the best or optimal security. I might mention it during the Q&A session, if it comes to that. Harnessing AI to continuously optimizing security boundaries around identities open the opportunity to build a highly effective mitigations for current and future attacks, and this is the bottom line from our research and in that attack. Now, before transitioning back to Tal, I'll let Tal's deepfake clone to do that. So let's hear it. Thank you, Lavi, and now back to Tal Liani's human clone. Lavi- Thank you very much. Lavi, you got me scared. Number one, I lost a lot of weight the last few years. Next time, use a better picture, please. Noted. Number 2, the clone was amazing because it's not just my voice, it's also the way I speak. It—like, for example, I can tell someone I hate you and then say thanks. I always say thanks at the end, and you managed to replicate it. And by the way, for the audience, we never spoke about it. He just got my permission to use publicly available presentations or something. So it's just amazing. So I wanna... First of all, for everyone, if you have a question, please send it via the portal. I wanna ask you a few questions, actually. The number 1 question I have, and while we're getting some questions from the audience, is: What does it mean for corporates? It looks like a giant step up in the threat landscape, and how do corporates deal with it? Meaning they need to have such different capabilities and such different capacity of defending now. How do you see it happening? Will the threat develop much faster than the defense, basically? So, to be honest, and I think that your observation on how fast the threat actors move has always been like that. Threat actors made their move, and then defenders usually had to react. We saw that, for example, when many organizational corporates out there had to face COVID and allow remote access now for employees from remote. Suddenly, or it actually highlighted even more, how the network perimeter is not a perimeter anymore. You can access assets from anywhere, and now something else becomes the perimeter. The entity, the identity, the employee, the service that needs to make the connection is now the focus. So in this case, and I think that you are right to say, threat actors will probably make the move to either create a polymorphic malware or deepfakes to bypass authentication. And one of the things that we highlighted in this deck and in our research is how important it is for organizations to be malware agnostic. Many organizations out there are already, to some extent, malware agnostic. They are not only looking for malware or malicious activity, they are taking action to deploy preventive controls that will give them enough buffer to deploy new defense lines or security controls that will mitigate the new and changing threat landscape. Got it. Your presentation is about identity coming from CyberArk. It's about identity, it's about the risk to identity, right? All types of identity, voice, and visual, etcetera. Can we, because you're such an expert, expand a little bit the discussion to the threat of AI? Can you take us through the threat of AI to other types of cybersecurity areas, threat detection, endpoint, even cloud protection, etcetera. Where do you see the risk outside of identity, which you outlined in your presentation? Where do you see AI being a risk to cyber? So here's one insight that I think we will see and impact other areas of security. We can expect threat groups to leverage AI just like a software company to invest in cost leadership, reduce cost when developing malware, and develop or deploy new disruptors. One, I think, good example for it is the ransomware-as-a-service groups. Those groups develop new ransomware. They have competition by other ransomware-as-a-service groups that sell the infrastructure and malware, and now AI becomes a major tool for them to reduce cost and to build new disruptors, like polymorphic malware, for example. So one area that I expect to see change is the velocity. This is how software companies measure their effectiveness, how fast first they move is to see those ransomware groups, for example, ransomware, evolving more rapidly. Another aspect that I think we'll, we will see AI affecting very soon is not only developing malware, but also developing the ability to evade defensive controls. So polymorphic malware was just one example, but once threat actors have an initial access to a network, they now operate. Microsoft talked about Storm, how they were affected. And nowadays, the threat actors are manually working within the network very slowly to not be detected. And I think that, sort of a threat consultant, will be one of the ways that we'll see threat actors using AI. So it will be much more difficult for threat actors or for defenders to identify threat actors once they are in the network. So sort of, I think the point is defense evasion, and from the threat actor side, it will be a threat actor consultant for them, if you like. Got it. I have a question, one last question, we don't have time. Yeah. The question is, it looks like a complicated and very big task to defend against AI. I mean, the tool is amazing for both ends of the spectrum. Do you think that the market for cyber defense for in AI, AI time, would be a market of small companies or big companies? Meaning, can a small company lift up the kind of the hurdle of defending for AI, etc., and develop tools? Or is the requirement so big that we're only gonna see kind of big companies, big cloud titans, like, you know, some very, very big companies doing it? So I think this is a good question. So first of all, I think that the companies or the type of organizations that will benefit most from this technology is the bigger ones, those are the enterprise. Because they deal with much more machines, much more logs in scale. And AI is really good in digesting data and giving context. And for SOC analysts, having such technology in hand is a game changer. For small organizations, I think it will come because we see that, you know, OpenAI and other developing or AI technology-developing companies lower the bar. They lower the bar in the investment that you need to make in order to get value from it. I think that 5, 10 years ago, we had to invest a lot in the security perspective. We had to invest a lot to build a model that works for us, that allow us to get an insight on, on, malicious activity of identity within the network. Nowadays, the bar is a little bit lower. We have models on the shelf that we can use to make sense of this data. In the next few years, I think that the bar will get lower and allow, smaller companies, you know, I'd say small enterprises, to also, see the value, with, with a better, better ROI on it. Got it. I have to stop it here. Thank you very much, Lavi. It was fascinating, and I'm happy to hear myself, and without knowing I said what I said. But, if anyone has any other question, please send it to me or directly to Erica, from CyberArk, and thank you so much for the time and effort. Thank you, Tal. Thank you for inviting me. It was a pleasure. Great. Thanks. Have a great day. See you all. Bye.
Loading workspace