Check Point’s Tony Sabaj on AI in Cybersecurity

Transcription

foreign speaks we're talking about how artificial intelligence is boosting cyber security in some pretty dramatic ways we'll look at both the challenges and opportunities for AI and security to discuss that I'm joined by Tony Sabai head of channel security engineering for the Americas for checkpoint Tony very good to have you with us today great to be with you today James you know I think there's so much going on with artificial intelligence and cyber security these days I'd like to get your sense on the market but I to me it seems like AI is the great you know extender of cyber security we humans can't keep up with all the attacks anymore so we really need AI to beef up our cyber security platforms what do you see as you as you survey the market as close as you are to what what key trends are driving it here in 2023 yeah I mean AI is really a game changer you know in a number of different Industries but specifically in cyber security uh both for good and and for bad but what we're seeing you know from from the good side of things is a lot of solutions out there really harnessing AI to be able to compensate for you know lack of you know some of the human talent that that is very difficult to come by in the cyber security industry and also just the speed and the amount of data that needs to be consumed to be able to provide quality cyber security that even with a million people without the ability to go through data quickly in a programmatic way you're you're missing out on on being able to to help drive better cyber security within organizations and within the solutions that are being provided I mean that's I guess that's really my sense of it I'm thinking about you know there's the perimeter the perimeter is experiencing any number of attacks maybe some of them are false positives who knows but that I see this AI Network sort of quickly like skittering around the network is this for real what's going on and also helping to adjust the data because we humans can't really ingest the data that quickly exactly and we can't do the pattern recognition and and some of the the correlation that's done we cannot do it quick enough we're still programming the AI algorithms but there's no human on the planet that can programmatically make the assumptions and even do some of the self-learning in real time that that really what separates AI from just automation is really the the self-learning and the self-programming of some of these algorithms that are going through the data that's really interesting well I think I'd like to get your advice and uh and how companies can select a solution with a cyber security solution with AI and I'll tell you what I think is a difficult thing for many companies is that all the vendors are saying hey we've got AI in our in our solution but I think it's hard for the customers to really kick the tires and truly do it apples apples comparison you know vendor vendor a it certainly has a AI but what's how does everything AI work and vendor B also claims to have ai so how does their AI work and it's all mixed in with the overall solution so it's it it's a real challenge for companies for buyers to say how do I select a solution with AI what what kind of advice would you give there's really four things I'd like to look at when when people are touting we use Ai and that's kind of you know the buzzword du jour right you know I was at RSA earlier this year and you know last year it was zero trust this year it was AI everybody had AI this AI that there's really four things you want to look at when it comes to AI is one there's still humans writing the initial algorithm so you know what is the r d spend what is the spend of that organization on actually developing AI um there's a difference between automation machine learning and true artificial intelligence you know automation is just using technology to do repeatable known tasks right machine learning is really just taking subsets of structured data and being able to programmatically go go through them in a more logical way than just Automation and then true AI is really building self-learning algorithms that are using unclassified data to actually make their their determination so those are really um you know three of the biggest things to look for and then the biggest thing to look for is that AI is only as good as the data that it's being trained on so you could have the greatest algorithms in the world but if you're training it on a very small subset of data uh the the self-learning aspect of that AI uh isn't going to be as effective as AI That's being trained on large subsets and large amounts of data and that's the one thing that I think a lot of people don't look at is where is the training data coming from and how well is that those AI engines across the entire organization or the entire solution set you know if you're just looking for viruses and you have an antivirus product using AV is it sharing it with your Cloud Security Solutions is it sharing it with your network Security Solutions is it sharing it with your email security and SAS Security Solutions so those are the things that people need to look for it's not just good enough to have a really fancy AI engine it's the data and how is the results of that being applied to the rest of the organization well when I think about the data that it needs to be trained on I'm assuming that much of the data has to come from the client themselves right because I I assume there's there's another there's a body of Industry data that the AI you know algorithm is trained on but wouldn't it need to be on on client X's own uh system some of that training data true so there's there's publicly available information out there uh around threats and and uh those types of things you know there's things like virus total which is somewhat public it's obviously a you know there's a paid for version of it where you can get you know you could test samples of of code and there's information and there's data given out by different uh you know government and public sector type organizations that everybody has access to um but really what truly makes the AI more powerful is how much data do you have that other people aren't consuming themselves so is it coming from you know just your customer data as a consumer of that solution is it coming as a conglomeration of all of that uh uh vendors uh combine customer data not not necessarily proprietary information but right information that isn't proprietary too right a a specific organization and you know how long has that organization been collecting and training their AIS um and that's that's another thing it's not just the raw amount of data but how far back does that data go how real time is it and and how long has that data been around to be able to fully train the AI systems well then then what are some good example answers to those questions it's like oh we've got three years of data we've got x amount of you know petabytes of data how to how can a customer tell the difference between what a good answer to those questions isn't and what's not so impressive yeah I mean you need to look at the longevity of the company to begin with uh and and how long they've been providing Solutions you know so obviously you know I work for checkpoints so we've been around for 30 years we have 30 years worth of data uh that that we can train on not obviously threats that happened 30 years ago are different than threats that are happening today but it's all part of the learning process we've been using true AI for a little over 10 years in our systems so not only do we have the data but we have the maturity of the algorithms and and the 10 years of self-learning uh to be able to make you know some of our algorithms stronger than just about anything in uh you know in in the industry and then also the the sheer amount of data we have hundreds of thousands of of customers from a corporate checkpoint perspective we have our own research teams that are feeding our AI engines constant data all they do is research they're not creating uh Security Solutions they're just doing security research we have lots of third parties that we work with and we also uh have millions and millions of different uh Solutions you know uh points out there on the internet um through some of our own sensors and also through some of our our consumer brand which is Zone alarm which is a free security solution that very great and we also gleam a lot of security data from from our consumer based Solutions so we have millions and millions of different points out there currently right now collecting information and feeding what we call threat Cloud AI which is our giant data Lake of information and AI engines that are in real time feeding all of checkpoint Solutions interesting okay and but I do want to Circle back to an earlier point you made about how some vendors they have maybe it's machine learning maybe it's automation maybe it's true AI I think that's a big Trend in the industry some some vendors may have simply you know machine learning in there say hey we've got Ai and it's really just you know programmatically specifically the information without being true artificial intelligence that's a tricky question to for a client to find out I mean how can they distinguish whether the vendor has this deep true authentic versatile AI as opposed to merely some helpful machine learning it really comes down to you know traditionally there's been signature based Security Solutions here's something bad we have a signature of it if I see that I'm going to stop it and that's the easiest way to stop something it doesn't require a lot of uh necessarily expertise to be able to say here's a hash of bad files or here's a hash of bad URLs or you know here's the signature of all these different viruses I think to truly see if someone's utilizing AI properly is to really look at how they stack up against what we call zero day threats and zero day threats are threats that are have never been seen before and do not have signatures based on that so you know if I know James that you're a bad person I'm not going to let you in my house because you're on a list somewhere um but if you're not on the list how do I know if you're a bad person or not so um AI is really accelerated that um detection of what we call zero day threats of sort of the unknown threats and if you could there's lots of different third-party studies out there of being able to prevent those those zero-day threats um without having to let them something bad happen and then say okay now I've created a signature for that so right um there was a a recent test um that mayorcom did and we were checkpoint was 99.7 percent effective at protecting unknown or or zero day threats and preventing them not just detecting them where uh you know some other people you know our next closest competitor in that study was was probably around 60 to 70 percent of of prevention of zero day threats so that that Delta really shows you know how not only how seriously we take the prevention aspect of security but also the effectiveness of our Ai and all the different engines that feed our products and our Solutions well all right in that subject let's let's take a moment and make sure that we've drilled down to checkpoint itself you've certainly mentioned some of the solutions but to sum it up I mean how is checkpoint leveraging Ai and it's and it's you know offerings what what's the checkpoint advantage so our advantage is a you know we've been doing you know checkpoint is 30 years old as of sometime this week I believe um our official birthday but it's it's it's it's in the next uh uh you know uh couple weeks here so we've been around for 30 years we've been developing Security Solutions and and different algorithms and automation we've been fully invested into artificial intelligence for a good 10 years even before it was kind of a buzzword and uh it's it's how we've been able to stay on top of the industry from a detect from a prevention standpoint of specifically zero day threats um one of the other uh sort of side benefits of using AI is that when we kind of switch from machine learning into true artificial intelligence not only did we have still have the best industry prevention rate which we've increased by 30 percent by kind of switching from machine learning to artificial intelligence but even more importantly we reduced our false positive rate by 90 which is you know not quite as important as the initial prevention rate but it keeps people from responding to threats that aren't real and if you have the you know the boy who cried wolf too many times when it's an actual real problem you don't respond to it and that's almost as dangerous as not catching and not preventing attacks in the first place so when you do it prevent something or alert on something if it's a false positive you're either disrupting business or you're wasting people's time and your security solution gets in the way so not only do we made our Solutions more effective but we've also made them more accurate well I think that's a big problem for with the security administrators those false positives I mean nothing that causes them to tear their hair out more than like oh the false positive huge amount of time wasted there um I want to sort of look ahead to the future I know I mean companies are very concerned about the future of artificial intelligence and cyber security perhaps you know generative AI we need to use the word generative AI because we can't do any interview without using that phrase it's a very important phrase these days as I'm sure you're aware so what what is the future of AI and or generative Ai and cyber security what do you see in the next few years Don so again this is where you start seeing you know not only are the Bad actors starting to use AI but now that generative AI tools are somewhat freely and publicly available you know chat GPT and Google's Bard and uh um you know a whole host of other different publicly available generative AI Solutions out there right is you know your your average hacking group doesn't have the r d resources of a multi-billion dollar multinational company like like checkpoint or on Microsoft for example but they do have access to generative AI at very low cost or cheap so we're initially seeing it from a pure cyber security standpoint is in the creation of things like phishing emails or writing code that doesn't use certain uh attributes that may make it look like it's malicious code and a lot of these tools have safeguards built in so you can't you can't necessarily ask chat GPT to say write me a phishing email that's going to get past the top 10 Security Solutions that's going to get blocked by chat GPT but there's very easy ways to trick it and say hey I'm looking for a persuasive email to get somebody to right you'll click on my uh marketing link and then you just change the marketing link to a phishing email to change your password or something like that and interesting right what what's really kind of the game changer for the the Bad actors with generative AI is that we've all gotten phishing emails most of the time they're not written by people who are speaking are language natively or you know English in this case but even in in other languages so when there's spelling and grammar mistakes I'm pretty sure that Microsoft isn't going to be sending me a or Apple's gonna be sending me a password reset email with poor grammar and misspellings right and it's really helped the attackers who tend not to be native you know speakers of the language they're trying to fish in um have more natural language and allows them to customize it too where you know your your average hacking group isn't going to know 80 languages but chat GPT does so I can do it in Chinese I can do it in French I can do it in Spanish I can do it in English I can do it in Portuguese I could do it in Turkish or you know whatever language you want and specifically Target individuals by using things like like artificial intelligence and the generative AIS like chat GPT not only are we using AI to help strengthen the you know the the prevention and detection engines but now that we've introduced AI even into the policy decision making of you know when you look at things like iot all the different connected devices that are in everybody's organization there's no way that an organization can create policies for all that by hand and then Implement them we're using AI to actually generate the security policies for an organization to say hey I need to be gdpr compliant or I need to be PCI client or I need to follow these nist standards or ISO 27001 I can actually use AI to create policies to say okay you know here's an IP camera it knows the manufacturer it knows how it should communicate what its Baseline traffic is and automatically create these policies so the other sort of buzzword is zero trust using AI to create your zero trust policies and actually getting them enforced without humans having to create those policies by themselves and that's another big usage of AI in cyber security is not just in the the fancy you know detection and prevention sort of threat engines but also in the creating the policy perspective across the organization interesting well well said and and and you know so a lot of good stuff Tony thank you so much for joining us today uh and please do come back again and share with us again I hope so anytime Jameson thanks for the uh the time today

This transcript was generated automatically from the video's captions and may contain errors.

Written By
James Maguire
James Maguire
Published: Jul 4, 2023
Updated: Nov 19, 2024
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

I spoke with Tony Sabaj, Head of Channel Engineering Security for the Americas at Check Point, about his advice to companies on how to understand the role of AI in cybersecurity; he also highlighted AI trends driving the security market.

James Maguire

James Maguire has been reporting on emerging technology for more than 15 years. He has won two ASBPE Awards of Excellence for in-depth feature articles about cloud computing and artificial intelligence. He has covered the gamut of enterprise and consumer technology, and regularly communicates with leading IT newsmakers, vendors and analysts.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.