Back
Nataly Kremer
Chief Product Officer & Head of R&D, Check Point Software Technologies

CW2023 AI & Cyber: How AI is Shaping the Cybersecurity Battlefield? Nataly Kremer, Check Point

🎥 Feb 28, 2023 📺 TAUVOD ⏱ 17m 👁 167 views
CW2023 AI & Cyber: How AI is Shaping the Cybersecurity Battlefield? Nataly Kremer, Chief Product Officer, Check Point This video is part of a playlist:   • CW2023 AI & CYBER   💫 💫 💫 💫 💫 💫 💫 💫 💫 💫 Subscribe to Tel Aviv University's official YouTube channel to stay up to date on all our new videos, lectures and events: http://bit.ly/tauvod-sub Tel Aviv University's official website https://english.tau.ac.il/   / verification  
Watch on YouTube

About Nataly Kremer

Nataly Kremer, Chief Product Officer and Head of R&D at Check Point Software, spoke at Tel Aviv University's CW2023 AI & Cyber event on February 28, 2023, about the role of artificial intelligence in cybersecurity. She described using ChatGPT to write a speech for her daughter's fifth-grade graduation, noting that other attendees had done the same. Kremer recounted a story of a friend who fell for a phishing attack despite suspicion, and argued that AI tools lack human intuition. She stated that "the attackers — all you need to do today to build an attack is to have a criminal mind and an AI tool." Kremer emphasized the importance of data quality and low false-positive rates in evaluating AI-based security solutions, advocating for prevention over alerting security teams. She said that an external certification team tested Check Point's solution and found it "99.7% effective, and that's only happened because of AI." Kremer joined Check Point after 12 years at AT&T, where she led its software and delivery organization and served as general manager of AT&T's R&D center in Israel.

Source: AI-verified profile updated from Nataly Kremer's recent appearances. Browse all interviews →

Transcript (26 segments)
H
Host0:02
Next we have Nataly Kremer, Chief Product Officer at Check Point. Nataly joined Check Point after 12 years with AT&T, where she led its software and delivery organization and was the general manager of AT&T's R&D Center in Israel. Welcome, Nataly.
N
Nataly Kremer0:25
Hey everyone, thank you for coming today. So it seems that AI is everywhere, right? Just a few days ago, my daughter graduated from fifth grade at school, and I was asked to present and talk as one of the parents. I had a slight problem: I just came back from a red-eye flight, so I was very tired, didn't have a minute to prepare anything. So I did what I always do in the last year in times of desperation, which is go to ChatGPT, right? So I went to ChatGPT, I asked him—for me, Chat is him, we are already friends, it's not an 'it'—so I asked him to save me and prepare a nice pitch that will impress everyone. I was super happy, came to school with my ChatGPT speech, and just to find out that the kid that had to present also used ChatGPT for the speech, the teacher used ChatGPT for the speech, and basically all of us were carrying speeches written by ChatGPT, which made me think: why don't we have bots to listen and applaud to all these ChatGPT instead of attending this boring event, right? So definitely there is room for improvement.
AI is just one example that we all like to talk about, but AI is there everywhere. We can see more and more usage of AI in personalized life, but also at the workspace, right? And we see it's growing, and we see more and more technologies. We all talk about generative AI, but we know there has been a lot of progress also on deep learning, and all of that together is growing rapidly, more than any other technology that we know.
Today we'll talk about cyber and AI, and I'll give you just a few words of background. I'm leading the product development, research, and technology at Check Point. Check Point has been a leader in security for over 30 years, and more than a decade working on AI technologies to protect our customers. We have more than 100,000 customers, from small customers to giant customers that are part of the Fortune 500, and we do all of that to protect our customers in the best way.
So how do AI and cyber relate? Where do they meet? First, of course, the attackers: all you need to do today to build an attack is to have a criminal mind and an AI tool, right? Which is a problem. Luckily for all of us in the room, AI has made a tremendous impact on how we, the defenders, are defending and protecting the customers and all of us. AI has made a tremendous impact on how we are protecting every aspect of the cyber landscape, and I'll talk about that in a minute. And of course, our heroes, right? The security teams that we have are already leveraging and are going to leverage significantly AI to do more automation and accelerate the SOC. So let's start by talking about the attackers.
What you can see here on the slide is just a sample that our research team at Check Point published, and you can all find it online. Just in the last year, we've been monitoring the use of attacks, the use of AI in attacks, very closely, and we can definitely say it's extremely easy to bypass GPT restrictions, OpenAI restrictions, and anyone with a criminal mind can get a full attack, can get a full infection flow using ChatGPT, can create backdoors and run scripts that are based on AI, and that can be done very easily.
Now, I didn't come here to depress everyone, so I will say that the bright side is that today it's very easy for professional, strong security tools to stop these attacks. And the reason for that is that this type of attacks are basically built on learning the history of attacks, and they are not very innovative, right? So if we have good security tools today, we can stop these attacks easily because they just imitate other attacks that we have seen before.
Of course, attacks are becoming much, much more sophisticated as we go. The attackers also use any AI technology to test how impactful and fine-tune their attacks, so they are learning and improving. And we can see in hackers' forums that there are bots offered that are using OpenAI for attacks.
So what do we do? What do we do on the prevention, and how AI helps us? First, I would say it all starts with data, right? We need data, and the AI technologies are already there. Everyone can get the best AI technology. What makes a solution stronger than others? The competitive advantage is the data. We have trillions of data, and we'll talk about that, and I'll show you numbers in a minute. But that makes the moat diversified. Your data makes it more impactful, and we collected at Check Point what we call the brain. The brain is our ThreatCloud. It's connected to all of our enforcement points. So think about all the network information we have, our endpoints, our email, the mobile security solutions—all of that, we collect inputs and data from that, that allow us to build the best AI.
Our brain is divided into two lobes. The right lobe is not based on AI, and there is lots of value also not based on AI, which is what we already know, right? We have three million, trillions of IOCs, indicators, and artifacts that we can use in order to know whether something is good or bad. So first we go to the right brain, ask ourselves: do we know that already? Have we seen that before? If so, we can come up quickly with a good or bad answer. If we don't have an answer, then we go to the left side, the left lobe, which is basically based on AI, and this is where AI comes to play.
Here we use all the data that we know from the known side to get back with an answer within less than two seconds. Let me give you some numbers so you can understand how significant it is. We have two billion websites and files we see them every day, two billion every day. We train our AI based on that. We use it for the right side, we use it for the left side, and we continually update the model and train the model based on this data. We have more than 70 million emails, more than one million online forms that are used daily to build a better AI. Using all of that, we got just this general, we got a result from an external certifying team that tested our solution to find that it's 99.7% effective, and that's only happened because of AI.
So how does it work? How does the magic happen? We have more than 40 engines that we run in parallel. Based on the security use case, we can run some of these in parallel and get a score within less than two seconds, a score that will tell us if something is bad or good, and then we can learn after that again.
Let me give you a few examples just so it all makes sense to you. Let's start with phishing. I start with phishing because this is something that we all experience every day. I'll tell you a story: a few months ago, a friend of mine called me. It was during Purim, which is a Jewish holiday very similar to Halloween. So think Halloween. She was waiting for a costume from Amazon, and she was waiting to get the package for her daughter. And she got a message saying, 'Hey, there is a problem with your delivery.' It was from the Israeli Post. 'There is a problem with your delivery.' You all know these messages: click here, pay an additional fee, and you'll get your package on time.
So she clicked, and when she opened the site, it looked a bit off, you know what I mean? It looked a bit funny. And there was a voice in her head saying, 'Hey, something is strange,' but she was so worried that she won't get the costume for her daughter for Halloween on time, so she filled in her credit card details. And then, just after she pressed enter, she called her bank and canceled the credit card. And when she told me, I asked her if she knew it was a phishing attack, why did she fill in the credit card details? And she said, 'Well, there was a voice in my head, but I was so nervous I had to do that so nothing will happen to the package. And only once I finished, I had a minute to think and to listen to the voice in my head and understand this was a phishing attack.' And this is something we see from many of our customers.
So using AI, we were able to expedite and improve our results on phishing. And one of the interesting things about that is that many, many companies are doing well in stopping phishing attacks where the brand spoofing is for global brands. So think about the Amazons, think about FedEx. But what we've seen in our research is that there are many attacks that are using local brands, and for local brands, the AI machine didn't identify the different local brands, like it happened to my friend, right? She used the Israeli Post, and the solution they used in their company didn't identify it. So what we did is we trained our AI to learn these different local brands. So with NLP and our AI machine, we were able to identify this, and you can see here it's the same campaign but just different local brands, and that helped us to identify also in new countries.
Another example of attacks we see more and more today is supply chain attacks, where we see developers downloading malicious code, incorporating that into their product, and eventually publishing a product with malicious code inside. What we do here using AI is we identify the patterns already during the download, so very, very early. You can see here this is the first step, against others that are doing it later. Even in the first step, where the developer is just downloading the package, we know to identify it based on AI.
Well, another problem we see is that we see more and more sophisticated attacks that allow the attackers to have better command and control connection and data thieves. And for that, they are using basically changing the DNS, and we need to be able to have better and better DNS engines. And what we do here using AI, we saw that we can multiply by five our ability to identify these malicious domains compared to reputation tools. And the way we do it is that we basically identify domains that are generated in runtime to avoid these traditional tools, and we identify like a different language, the domain language, and the AI can identify that. And we can also identify cases where they use the subdomain for tunneling to provide information to command and control.
And last, I would mention also the cloud, right? We have lots of POCs using AI with the cloud, where we can identify workloads and containers behaving differently, identify anomalies. We can also fine-tune and have better granularity of the connections, right? We look at the traffic between different workloads, and we can improve the profiles for that. It's very similar to what you see on Netflix, like we can see one workload and see that it's similar to another, so we can say, 'Hey, this workload is similar to another, it can use the same profiles,' instead of having to define that. Same as you see on Netflix, where the Netflix engine will say, 'Hey, this person is watching something similar to another person, let's use that recommendation.' So same that we can do on workloads, and we are already doing.
Let's spend the last minute just to talk about SOC automation. So AI is going to change how we are all working, and it's going to change how all of our security teams, what I call the heroes, are doing. Using AI, we can develop faster, we can have more automation, we can define autonomous profiles. Let me show you an example. So this is just one example that we used today in our network firewalls, where we identify IoT devices automatically. We identify the IoT devices based on AI, based on the network patterns, then we can automatically assign the right profile for them, and the admin doesn't need to do any work. So that's one example, and we'll see it more and more.
Another example is what we do on SOC, where we see more and more efficiencies in the way our SOC teams can work. We can have graph analysis that will get better visualization of the attacks, that will help the SOC team do threat hunting much easier and automatic. We can have already event correlation and co-pilot for threat hunting and automatic response. So that's going to change as well.
And to summarize, I would say you can all see the cartoon that basically says we all need AI. 'Give me two AIs, I need AI now.' I don't know why, but I need AI, right? So AI is everywhere, it's changing rapidly. Cybersecurity is changing rapidly. If you combine the two together, you understand you got into a new era, right? And we all need to use new measures to protect ourselves. And the way to do it is to have solutions that are very robust, innovative, and use deep learning for the AI engine, and to have tools that will have a better, richer user experience that will predict what the SOC team wants to do and do it before that. That's it.
H
Host15:01
Thank you, Nataly. Maybe a couple of questions. One is: what are the challenges in implementing AI into prevention in cybersecurity?
N
Nataly Kremer15:14
So I would name two. One, of course, as I said earlier, you need to have large data sets to be correct. AI is only as good as your data. It needs to be diversified, it needs to be private, right? Which is a challenge. Another challenge is on a different area, which is the explainability of the AI. How do you understand what AI did? When people are using AI tools, the AI doesn't have the same intuition as we do. So how do we know that what the AI said is true or not, right? Because we can't really understand the recommendation. So the ability to explain what the AI recommended is something that I think will be and continue to be a challenge.
H
Host15:56
Thank you. And maybe also as an investor, how do you evaluate solutions that are using AI? Is it just based on the performance of detection, or can you know something even before that?
N
Nataly Kremer16:12
So I think—did I say 'data' today already? So I think data is the first part, right? What is the tool based on? Which data set is it? Niche data? How differentiated is it? That's one thing. I would also say, of course, like any other cybersecurity solution, the false positive, right? How do you avoid false positives? We are looking for a solution that does prevention. I think SOC teams are overwhelmed today with all these alarms. I remember that, you know, I have a friend here from AT&T, and I remember that from the other way, right? We have all these violations, and the development team doesn't even know what to start to fix, right? And they just ignore it at some point because it's overwhelming. And so finding a way to protect and prevent instead of keep on asking the SOC team to work for you or the developers to work for you, I think that's the key.
H
Host17:05
Perfect. Thank you very much, Nataly.