Stuart McClure1:10
Chief Executive Officer, President, Cylance Incorporated. I always get really scared when my head's that big, so let my nerves settle out here. Good morning everybody. Well, thanks so much for having me. I have the dubious honor of talking to you early in the morning and talking about math. So for those of you like me that mathematics weren't your A-pluses across the board, I'm hoping to make it a little simpler, because I do believe it is probably the best hope we have inside of security to change the way that we detect and prevent the most malicious of attacks. So let's get right to it.
One of my favorites was Plato, and he often was quoted as saying, 'We can easily forgive a child who is afraid of the dark. The real tragedy of life is when men are afraid of the light.' And what constantly comes back to me conceptually is this idea of the allegory of the cave. If you're not super familiar with this concept, it's real simple. Basically, as Plato puts it, the scene: you have prisoners bound and shackled that can only see silhouettes or shadows inside of a cave, and what they see is what other people are projecting up onto the wall of the cave. This is all they see for their entire life, so of course to them that is their reality. One prisoner is freed, goes outside, sees the sun, feels the fresh air, and coming back into the cave trying to explain what he's seen, he was of course rejected out of hand because they couldn't understand that concept. The modern day equivalent of this, or at least past 10 or 14 years, is The Matrix, right? The red pill versus the blue pill decision. And this is one of the biggest challenges I think we have as an industry: we have built an entire security mindset based on a reactive paradigm. And what I mean by reactive is we have to see an attack and identify it via human analysis. We have to be able to look at that victim, how they've been victimized, and then we have to figure out a way to programmatically build into products or into services, managed services like anyone was talking about, a way of detecting it going forward with all the new customers and the new victims. And that is by and large, I believe, our biggest problem. And what that's created is this iceberg effect, where you've seen all the statistics, I'm not going to beat you to death with it, but what's happened is what we see is really just a small percentage of what is actually happening out there. And the proof really is when you get to a place where you're detecting... talk about that. So what's happened because of all of this is, by and large, people have thrown in the white flag, thrown in the towel. They've said, 'Look, I give up on trying to prevent this stuff. I can't. It comes in too fast, new techniques, new forms of it, new shapes of it. I just give up. What I'm going to move to is a respond scenario.' Right? I'm sure plenty of you have felt that, where we're just going to get the best slop bucket around, right? The fastest team to go clean up. We're going to detect the problem, we're going to clean up faster than anyone else, so it's the mean time to remediate, right? And that's how we're going to... And what we've got is basically this: if you don't recognize, this is of course pig with wig. You could put lipstick on this thing all day long and it's just going to be as ugly as it always has been. You're never going to actually improve. So how do we do this? I often get in trouble with this concept, so don't feel bad if it stirs a little bit in you, but I've often joked, half so calf serious, that about there's been about 10 original ideas in the history of mankind. And I actually brought this topic up so stupidly at a family Thanksgiving dinner once of my girlfriends at the time, a long... At some of the spaces that have applied math and statistics, what we realize is that it's been applied in a lot of different industries, from the insurance industry, the trading industry, the genome sequencing, drug pharmaceutical industry, even to the high-tech industry. It is everywhere. Math and science to determine the best searching algorithms for what Netflix you want to go into, to recognizing your voice and your commands via that voice recognition, to drone piloting and flight stabilization. You name it. So why haven't we really applied this model to the world of security? So if we did, and said, 'Okay, look, we built a science and a math around the world as we know it, why not apply it into the world of security?' And when you do, what you end up getting is an amazingly powerful technology that allows you to not just detect what's already out there today, but to detect what will be out there tomorrow without any changes to it. So let me give you a quick scenario. We do this every day, by the way, just so you know, all unconsciously. So this is Bob. My daughter, my youngest daughter Jillian, loves to call everybody Bob, so that's Bob. And let's say you know Bob, and Bob comes in and says, 'Hey, how's it going today?' Holds out his hand, shakes hand, you say great. Crying out loud, right? Well, I guess we kicked that now, but you get the gist. And he holds out his hand. Now what do you do in that moment? You might give a split millisecond pause, right? How well do I know Bob? Am I going to insult him if I don't shake his hand? He's showing signs of badness, but we don't know really what it is. He's sweating, bloodshot eyes, runny nose, coughing. We don't know if it's something really bad or if it's just simple allergies. Well, what if we could actually know? And we do this subtly and unconsciously within our own brains through our what I call our experiential database that we collect over the years and decades. What if we could take Bob's DNA, go down to Atlanta, run through the CDC, actually catalog, collect, document, and actually mathematically prove out that DNA? What if we could then, when we saw Bob the next day, actually simply query his DNA and say, 'He's most likely sick, and he's most likely sick by some form of virus or bacteria, it's not just an immune system reaction'? Well, this is in large part what the Human Genome Project has done over the years, and it's what we are starting to find in security being very effective.
In Bob's case, you have to collect as many healthy DNA samples as humanly possible. In the security world, it's files, it's executables, it's anything that would be a potential executable element for compromise onto the endpoint. So we collect over eight terabytes of data, both known good and known bad. We vet all of that data, and that would include all the files you see here and many more. Then we extract as many features of those files as humanly possible. We are now over 5 million features. So 5 million features. If you think about the features we were... whether or not to shake their hand. So we detect and we map about 5 million now. Third, we transform all of that data, the feature extraction, we vectorize it, okay? And we train our machine learning models for what is good and what is bad. And because you have so many files with so many features, you have an amazingly accurate way of determining what is truly bad and what is truly good. At this point, you can classify whether or not this new file is either well trained as good or trained as bad, and you can also cluster, so you can tell... clustering that is incredibly powerful to give you context around that particular file on the endpoint. And all of that is by and large automated and done in real time. So the next time you have Bob come in with the symptoms, and you're applying it now to our world of security and files, that extraction technique is probably one of the most important aspects of what you do in machine learning. It's taking as many characteristics and features of each set and mapping them definitively to the target. So as I mentioned before, we have over 5 million features. And what is a feature? I often get that request. I get two real questions. One is... element either in memory or from disk into memory, and it's incredibly powerful because it is a simple processor exercise. There is nothing complex, there's no heavy lifting. Simple i3s can handle it great. So extracting as many features as humanly possible, we map to a total space of over 5 million, but on the endpoint it's 2.8 million. We can also extract the disassembled code and map that as a feature as well, and that's in large part also how we're able to get to such large numbers in our feature set. So once the features are extracted, we then transform, of course, and we'll vectorize it, right? And we train on bad and you get a very, very large vectorized number that can then be used to determine when a new sample comes in to your system and tries to execute. Like, let's say you click on a link, right? That's a water holing attack, or you open... not you, of course, none of us, but your users click on an attachment in an email that's slipped through all the filters. Well, we can then determine whether or not it matches statistically to the good or it matches statistically to the bad. And when it matches somewhere in the middle, we can call that out too, and we can do further... So that vectorization process is really quite simple. It's complex in terms of its size, but it's simple in terms of concept. You basically boil down all those features into a mathematical number, a matrix of a number that can then be fed into our machine learning now. So this is what you get. This is a visual of a large sample set with three features, that's it, three features, right? And it's things like file size and a certain import that we looked for and one other. Now this is simply three features. Imagine now, of course, machine learning handling 5 million features... to tell us this. So everything to the left of the hyperplane is bad, everything to the right is good, based on our training set. So when a new sample comes in, it can easily map to the left of the hyperplane as bad or the right which is good, and we can determine that in a matter of milliseconds with the technology today. And this is what makes it so powerful, because we don't have to see what comes out tomorrow to react today. We can react right now. So that's why we can be so effective detecting zero days, advanced threats, APTs, you name it. And honestly, this science... respective products and feature sets. So the other concept I want to make sure I communicate here is that hyperplane. The real question is how do you find that hyperplane, which is that line right between the good and the bad? And it's the second most frequented question of me behind 'what features you extract.' And really, there have been a number of agencies, government agencies for example, and some companies that have tried this and failed. And while I don't know the specifics of every single project that's been attempted and failed, I can tell you what I have discovered is that most people don't collect enough features. They usually rely on 100 features or 300 features or something very, very... world, let's say just of a map, and you wanted a machine to determine the lowest point inside that topographical 3D map, you would use an algorithm called gradient descent, and it would take basically all the XYZ coordinates and it would allow you to determine where at the bottom of that is. That is effectively what the technology within our machine learning system does. That's one of many. We have four different algorithms that we combine together in what's called an ensemble model. So applying all four plus algorithms gets incredible accuracy and predictive capability. So at the end of the day, what we are doing and what the industry is... prevent and control execution at that key decision making point to be able to allow it or block it, or just alert if it is bad. And that's at the heart of it, because we really believe victimization occurs at the endpoint. It's at the end node, the laptops, the virtual desktops, wherever it is. The user, as Andy mentioned before, right? The user is the new perimeter. 100% agree. Because the user can click on anything, the user can open anything, the user can plug anything onto into their asset. And what our industry has done is, because we've been so reactive, we couldn't fix the core of the problem, which is that bad things... or we'll have a USB device control, a component, we'll have a social engineering whizbang widget, right? That detects whether or not your users are going out to Facebook and clicking on stuff or doing malicious stuff, even insider threats, right? But all of these techniques require one thing to occur, or you will not have victimization, and that is execution at the endpoint. And it's that execution at the endpoint where we capture it, where we stop it, and where we analyze and look at what's trying to execute before we allow it to happen. And what that does is create an incredibly effective platform for determining and preventing... services and products. I basically boil it down into these four categories. You have kind of reporting and auditing, you have control of privacy, you have denial of service, and you have control of execution. And for the most part, every technology, every service can be included into one of these four buckets. But at the end of the day, if you control execution, you remove the threat surface area so dramatically that you are now able to be truly predictive and preventative without the headache of a patient zero. And you can start to think about the layers that you currently have in place... on the problem. So we would get the email from a customer that got hit despite our technology being on there. We would rally the troops, we would respond quickly, we'd figure out why they got hit, we would write a new signature, a new update, and we'd get it out there. And we were very happy, right? But the other day, you still had victims. You had one or a hundred or a thousand, or whatever it was. And that's just unacceptable. It's because we were reactive. We as an industry have been reactive. But what we have to do, and think of it as, is that we can actually do all of that far more effective with far fewer eyeballs, and we can now apply that into our technology to... you, the audience here and the world, to do one more thing: don't trust the vendor, trust the math. And it's our job, our duty, to help explain the math and how it works and how effective it is, so that you can get there. Because we've certainly seen throughout history how math and science have been able to advance all of us and our civilization and industries. So with that, I will just wrap up. For a little bit more detail, Cylance math white paper, you can go to our blog and Twitter, which we cover all of this every single day as we find new attacks with the technology. It's really kind of exciting. I'm like a kid in a candy store. I wake up every morning, it's like Christmas morning, and go into customer drive with my.cylance.com. Okay, with that, unless there is a question or two, I will thank you very much for attending.