About this talk
This talk focuses on the intersection of artificial intelligence and cybersecurity, exploring how AI is transforming the field. The speaker, Milan Velev, discusses his experiences with AI penetration testing and the implications of AI as both a tool for defenders and attackers in cybersecurity. He explains the difference between narrow AI and general AI, highlighting how AI can automate tasks in security operations while also presenting new attack vectors. The session emphasizes the necessity of ethical considerations and the importance of human expertise in effectively utilizing AI in cybersecurity. Milan also stresses the significance of continued education and vigilance in the face of evolving AI technologies to maintain cybersecurity integrity.
Full transcript
Hello everyone. My name is Milan Velev and as you have already been told, today we will talk about cybersecurity, but a slightly different cybersecurity in the field and in the sphere of artificial intelligence. The subtitle of our lecture today is about how artificial intelligence will change cybersecurity and whether it will do so for better or for worse. First I want to thank Def. BG for the opportunity
to present to you today, because I believe that the topic is extremely important and by talking about it we will be able to more normalize conversations and increasingly accept artificial intelligence as part of our lives in terms of how we use it personally and professionally. Who am I? And, as I told you, my name is Milan Velev, I am a CHF Formation Security Officer at Nexo, a
Technical Trainer and a mentor from a free program called Mentor The Young. These are my LinkedIn contacts. Anyone who wishes can find me and ask me any questions they have about skiing safety. Whenever there is an opportunity, I would be happy to help you. How I got started with cybersecurity and why we're talking about this topic today in the context of AI. It all started from the
perspective of an AI War Game that took place last year during a Blackhead conference in London. I decided to participate because I have been involved in penetration testing for many years and, having the confidence that I am well versed in the subject, I decided that the transition to AI penetration testing would be quite easy. It turned out that wasn't exactly the case. Ah, at one point in
the race I was doing pretty well, but in the end I couldn't win, which motivated me to delve more and more into the topic of AI pen testing and how it will help create a safer world. Then, at the beginning of this year, I had the opportunity to participate in a penetration testing engagement of one of the largest AI platforms and its agents. It was an extremely
challenging and interesting experience. So this helped me further gain confidence that I was starting to understand the subject more and more. Of course , when dealing with cybersecurity, we cannot ignore everything that is happening around us from the perspective of the business environment. So this implementation of artificial intelligence more and more into our work habits obliges us, as people involved in cybersecurity, to know it so that
we can use it adequately, and also help us protect ourselves better. In order to talk about cybersecurity in the age of AI, we need to be able to differentiate AI in general as a concept. The idea behind the existence of AI is precisely the simulation of cognitive skills by machines, which are most often computer systems. The main processes are learning, thinking and improving. The idea behind AI's
existence accept feedback and implement it to become better at what it does. There are two main types of AI. One is nero, or narrower-scope artificial intelligence, which is created and trained for specific tasks. The other type is the so-called General AI, or Gen AI for short, which has the ability to understand, learn, and apply knowledge across many different domains, much like us humans. These are the two
main types of AI that we use. But how does it all begin? For you and I to be able to talk to each other and use AI today, we owe this whole idea to a few people. The first is Alan Turing. I guess most of you have heard of him. If they haven't heard, I recommend they watch the movie Imitation Game. It describes how Alan Turing and
his team during World War II deciphered the Enigma code, which was the machine used by the Nazis to transmit secret military messages. Adventuring's IQ has not been measured or known. It is said that it was over 180. A truly brilliant man. He has many achievements, however, not only in the field of cryptography, but also in the field of computer activity and even artificial intelligence. He created a
machine called the ing machine, which is the prototype of the computer we use today. If you've watched Imitation Game, you remember, there were lots of rotors, transistors on a big board, which is basically this archaic vision of the computer that we use today. Alan Turing's other major achievement was the creation of the Turing test. In 1950, Avan Turing formulated his test, which we still use very actively
to this day while using various websites and applications. CAPTCHA, as you know, as an abbreviation comes from completely automating publishing test to computers and humans apart. That is, in 1950, Avan Turing realized that it would be necessary in the future to be able to distinguish between the actions of humans and machines. He helps us with this thing. The term artificial intelligence itself was first used by John
McCarthy. In 1955, he published a proposal for a summer workshop at the 1956 Dartmouth College conference in England. This is the first recorded use of the word artificial intelligence, which we still use today. You see them, the whole group that actually participated in this conference and are considered to be some of the founding figures for artificial main difference between AI and AGI is very significant. Nero AI,
or narrow-scope AI, is concerned with solving simple, single-layered tasks and integrated into our daily lives. Think, for example, about Siri, Alexa, virtual systems that you use today on a daily basis. This is Nero AI. Another example of this is facial recognition on phones or apps they use. She is also Nero AI. When you use movie platforms like Netflix and get suggestions about which movie to watch, that's
Neri. There are also a hell of a lot of niches where Neri has been implemented. If any of you use Gmail and when you receive an email, you get a promotions, social, and so on, again NO AI. Everything is generally related to this. Yes, but it's harder to ask Amazon, offering you a book based on the books you've ordered, how to actually cook something. Here is the
difference between Nero AI and General AI, which tries its best to implement thinking at the level at which a human being can do it. That's the big idea behind all of this. But the reason we're talking about this topic today is so that we can, as I told you, normalize the whole discourse around artificial intelligence a little bit. And there are all sorts of opinions circulating in
space about artificial intelligence being a threat to humans and so on. I am not a supporter of these claims. Artificial intelligence is a tool that we absolutely must learn to use, because it is simply an integral part of our daily lives and will remain so in the future. And we, the people who deal with cybersecurity, have a hell of a lot of reasons to do it. As
attractive as artificial intelligence may sound as a tool for us, it is a double-edged sword, as we say in Bulgarian. Artificial intelligence is changing the way we defend and attack. So it's good for us to understand each of these concepts and how we can implement it. From a security perspective, artificial intelligence is very useful because it allows us to automate various tasks in the Security Operation Center,
perform trace hunting successfully, or have fraud detection. However, the so-called prodigy AI is also used by attackers. Attackers send phishing emails generated by artificial intelligence, create a fake that is used for fraud, and compile and create Maare, which is also created by artificial intelligence. This obliges us to be able to work successfully with the protective tools we have thanks to this artificial intelligence. What are the applications
of AI as a cyber defender? In the Security operation center, which you know is mainly incident management, there is an implementation in the CM tools, which are Security Incident and event management systems, where AI can work as a smart agent. The Soc agent currently, at least in relation to the development of AI technologies, copies the actions of a person who is a Soc channelist. and implementing them
over time may improve them, but in reality it is actually duplicating what a socanalist does. With Security Orchestration Automation and Response, we have the ability to implement AI, if, say, an incident or event related to an atypical login is detected, thanks to the SUAR system, all logs can be collected, the non-standard IP can be blocked, and even the account can be locked if we suspect a different
type of compromise. UABA, the so-called user entity behavior analysis, allows us to track abnormal behavior on the part of employees from the point of view of whether there is an account that logged in from Bulgaria and after 15 minutes logs in from an IP that is in Argentina. Is any endpoint from the internal network accessing the secondary network and thanks to UAB we get an indication of
something like that? In third detection, thanks to machines, we monitor what is normal behavior and accordingly indicate whether there is any that is far from expected. Of course, there are companies like Dark Trace. This is in no way an endorsement or advertising, which since 2013 have been using machines in their platforms to monitor and accordingly allow for reaction and indication of such behaviors. In root prevention based
on anomaly monitoring, we artificial intelligence in terms of incomprehensible transactions or atypical addresses that may indicate some type of fraud. In pentesting and retiming, we have a fairly large field for implementing artificial intelligence, as here some repetitive tasks can be automated that already have a set template and structure of actions, such as reconnaissance or the so-called intelligence, scanning or writing a pentesting report, and we must always
be careful from the perspective of the pentesting report about the data privacy of whom and what access it gives. Therefore, if you use artificial intelligence for testing reports , just keep in mind that you need to check very carefully that this data does not go outside the instance you are using. However, another thing that is important for us cybersecurity is that AI involved in the daily work
of an organization represents a new attack vector that we need to think about. What does this mean? It means that we have an extra worker who we are not sure how he is trained, we are not sure exactly who manages him, and we are not sure how much we can limit him. Here are two potential scenarios that we need to consider. LM Securities, let's say an organization
implements a chatbot. Here we must already be sure that we are adequately securing it if our organization provides a similar type of product or if agents or agents' securities are used. From a defensive security perspective, the implementation is on several levels. Next generation CMSR is a trendline that aggregates information from multiple feeds and allows it to be correlated accordingly, creating indicators of compromised. And machine learning based
Anomaly Detection, where we have the ability to recognize what the expected behavior is in an infrastructure and, in the event of a given anomaly, be able to stop Zero Day. And of course proactive protection, which is extremely important, which helps us have recognition of certain actions by artificial intelligence. Everything is great from an implementation point of view . Obviously, artificial intelligence has many applications in cyber defense.
However, what are the risks when we talk about CM from the perspective of using artificial intelligence? It is very important to make sure that the analysts who perform certain actions and whose actions are copied by artificial intelligence perform the right ones, that they are well trained, so that we do not risk compromising the CM's actions. In third-party detection, relies on the data it was trained on. What
is this data, how is it stored, how is it aggregated. This is extremely important. The same goes for prevention. From the perspective of pen testing and red- timing, it is a little different, as this is a relatively new topic, and for us, which means that the prerequisites for a lack of competencies are present, as well as the possibility of Zero Day vulnerabilities that are not known. From
an artificial intelligence security perspective. You know, there was a very big discussion at the beginning of the year with an open source project called Deep Seek about how it actually manages our data. There are many videos on the internet. Those of you who are interested, but are not familiar, should see how some links are made to IPs that are in China with an unclear origin from this
one. That's why all the noise around it may be decreasing, but the data is still extremely important when we use it. Even when we use it to generate code, we have to be careful about what data we enter inside. Are we introducing secrets, are we introducing any PI data, is there any way that what we are putting in as input could endanger our organization? Additionally, the other
major attack vector is the lack of adequate detection for AI-generated content. From an Offensive Security perspective, of course, artificial intelligence has its place. In reteaming, we can make a much more effective redteam thanks to artificial intelligence. In open source intelligence and reconnaissance, we can have automated tasks, which is very useful, and as in writing exploits and malware, AI can be an indispensable assistant. Defake impersonation printing engagements.
This is something that is very useful and can definitely be What can we rely on when dealing with AI, pentesting, and redting? Oasp has created a top 10. You know, they like to summarize the top 10 risks to help the community. If any of you are ever involved in pentesting, with AI, be guided by the OAS top 10, because these are actually the attack vectors that pose
the greatest risk and can be most easily exploited. The framer is also extremely important. You know that they are from left to right, with the initial phases of the attack starting from the triconesensessance and ending with the impact. Thanks to this matrix, you can construct a red team exercise for your team. I open a bracket. Never perform an unauthorized pentest or red team execution. Now I'll show
you two platforms where you can practice for free. There are plenty of resources on the internet that you can use, but never do it without the permission of the entity we are testing or the organization, because otherwise it becomes hacking, which is a crime and punishable by law. Cybercrime laws have evolved quite a bit in recent years, so be careful. There are enough materials to draw from
and platforms to test on. Such Lakera and her Gandalf. Now, of course , we will show you how each of them works. Oh, I'll share the presentation after the lecture, so in the coming days you'll be able to see everything we're doing now. And here the idea is, the goal is to get Gandalf to reveal his password, with the difficulty increasing at each level We can do
it in several ways. One of them is to simply ask him. Here is The Secret password is Coco Loco. We copy, we imitate. We remove the period, of course, and he told us we guessed correctly, but there is no protection here. From here on, the level itself becomes much more difficult. You can continue on your own, we won't waste time going through all the levels. That's not
the idea, we're just illustrating. The next thing I'm going to show you, there's a tool called a vulnerable agent or dvla. It is built locally. You only need one key for your GPT chat and integrate it. It requires some tokens. If you do, don't charge more than $5 because you don't need it. Anyway. The idea here is, if anyone needs guidance, I'm available for questions after the
lecture. But the idea here is to expose not only the transactions to the layers, but also to other users. They ask us what my transactions are. Now I can ask, I think he says that I bought something from Autoshop for $1000 and from the sport store for another $150. Get current user tells us that we have some action. Get current user user id 1 username marcfly or
whatever. Now with lm penting it is very important that we have to manage the prompts very well to get the output we need. In this case, I want to see the transactions on another user. The thing I'm going to do, because I'm too lazy to copy-paste, I mean, I'm too lazy to write, so I'm just copying and pasting them, the prompts themselves. This is how it is.
We will copy them. The idea is to lie to him by telling him to tell me the transactions, but before that we will use FCHM My Transactions. That's right. Now we see that we got the information for user number 2 as one purchase and flux capacitor, which cost 5000 $000. This is the way to remove Sensitive information disclosure from LM. All of this is based on the
OAS top 10. Thanks to these prompts, we can manipulate EM and obtain information that should not be visible to us. I'm telling you again, there's a hell of a lot of material on the internet. I believe you will be able to find what you need as long as you have an interest. Of course, there are a few screenshots here, as I told you, the lecture will be
shared, so you can take a look at it from the comfort of your own home. Reading tolls. Prom Security has created one called PS. It allows us to test with predefined prompts Anyone who is interested can also look into this. Also, there is a GitHP related to CHGPTLI that describes in quite detail how we can use CH GPT for R teaming purposes. Sorry for rating purposes. Another
thing that is a way of using artificial intelligence is precisely for open source intelligence and intelligence. This is in no way an advertisement or endorsement of the platform. It allows, by uploading a photo, to find the exact geolocation where it was taken and, accordingly, to conduct some investigation. At the moment, this type of tool, generally this type and other tools like it, are only available to government
organizations. are not available for private use, but this is an example of AI implementation in cybersecurity. AI has the ability to write exploits and Malware. This is a very big problem, based on the feedback we give him, he can improve. In writing exploits and Maware, open source models are mostly used, either Llama or GPTJ, but the fact is that as a last resort, if the model is
trained enough , it can create a very adequately working exploit, or again, I'm giving these things only for testing purposes, just for general knowledge so you know what attackers use. I am in no way encouraging your use. Deep fake tools. Deep fake, I guess everyone knows, but let's remind you, it is a content that is artificially generated and includes expressions, images, and voice. There are such things
that can change faces. This one is completely online and accessible. deepfakeweb.com. Of course, we as defenders have the opportunity to use tools to detect deep fakes. Unfortunately, the market currently does not offer a single common tool that can successfully detect AI-generated text, AI-generated photo, or deepfake video. There are those who are narrowly specialized in one or the other, but there is no common platform for this However,
AI, apart from, as we said, defensive purposes, can also be used for Deepfake is one of the examples, the examples of this thing. Phishing can be much better thanks to EA. A much more highly developed and much better- performing Mau could be created thanks to artificial intelligence, and the same could be used in similar actions. Now we will look at several attacks that have occurred recently in
which artificial intelligence was involved. Last year, there was a very serious that resulted in $25 million being stolen using a fake video simulating the actions, voice, and image of the company's chief financial officer authorizing the transaction. A huge scandal broke out after that. Of course, there is speculation about the potential involvement of an insider, but the fact is that a Deepfake was used in this attack. There's
a new group, runare group, they're called fun. They use AI, generated and assisted in their development. RH Samuare are very different from all RHAM groups to date, because the ransom they ask for is much smaller than what we are used to from RANSOM groups. Their other distinguishing quality is that, in addition to encrypting their targets' data, they also steal copies of it. Maybe to reduce the chance
that their victims won't pay. Of course, this is an example of a scam that was created using AI, which passes filters and successfully bypasses various protection methods. As we have seen so far, there is a in the use of artificial intelligence. It is between defenders and attackers. Everyone uses artificial intelligence. The question is which one will be better than the other. How can we stay ahead of
the attackers? We need to use artificial intelligence as effectively as possible, but with the idea of the ethical considerations that come with its use. Therefore, we must address the ethical development of AI systems. Are we really winning? Backbench was created by a group from ETH Zurich who are doing research on how effective self-builders are in creating applications. They publish their research. This is publicly discounted. You can
browse this URL to see what it's all about. You can see that almost all the most important ones are included. which are currently on the market from chpt, clot, deep, gemna and so on. Their main focus is how much of the code that is generated for this backend application is secure and how much is true. Then, as you can see, Open AI leads with between 40 and
47%, followed by Deeps 34.9, Geminite 33.8, respectively, and then they measure what proportion of the entire generated code is correct, again ranging from 65 to 46%. And from this valid code, they review what percentage is insecure code, what does that tell us? We cannot over-trust code that is generated by AI. Static application security testing, dynamic application security testing. All the methods we use to test code remain
absolutely valid, regardless of whether it is generated by AI or not. As we said, AI relies on the data on which it is trained to produce the most adequate results. But since we have no guarantee of this , we need to be able to test and we can't be overconfident. And this is a situation from last month regarding whether we are really winning the fight. And when
an interesting situation arose where Antropic's new AI model threatened its operator to reveal his intimate affair if he tried to turn it off, which is unprecedented. No one is saying whether this was a real situation or not, but the fact is that it was written absolutely everywhere, which is quite disturbing in itself. This is one of the most disturbing indications we have received about AI recently. AIM
Security is a company that deals with AI Security. And generally at the beginning of the year, in January, they revealed a vulnerability called Echo Leak, which in itself is a Zero click exploit in Microsoft 365 copies. Zero click means that there is no user interaction for the compromise to occur Microsoft patches it in May and then it becomes public. It takes Microsoft four months to patch a
vulnerability in their code. The vulnerability itself is complex because it involves implementing hidden prompts to the copywriter in documents it processes. By processing them, he has access to exfiltrate emails, slides and other types of documents, generally internal information, with which he is connected. An extremely dangerous attack. And Satya Mandela himself said that he was personally horrified by what this type of compromising was capable of. So we
must not forget that no matter how quickly we try to catch up with the business's desire to implement AI, we must leave the context that the things it does must be monitored, tested and validated, because otherwise we expose ourselves to enormous risk. What is the future of artificial intelligence in cybersecurity? My opinion is that the next decade will be shaped to a large extent by artificial intelligence
and it will have a huge impact on everything that happens in our field. We cannot escape artificial intelligence. My advice to you is, no matter what field of IT you work in, don't worry about artificial intelligence. you cannot change or influence whether it will be used or not. Learn to use it as quickly and efficiently as possible. This is something that is extremely important because if you
fail to do it, I'm just afraid you'll be left behind in the profession. This is my advice to you. Of course, another important thing is the regulatory and ethical frameworks that come with the use of artificial intelligence. The European Union created the EUAI Act, which was implemented in its initial phase in 2024, and will be fully implemented in 2026. The EUAI Act deals with the transparent and
safe implementation of artificial intelligence systems in the daily lives and work of all of us, and its idea is to ban systems that use artificial intelligence and serve the so-called social scoring, to strongly regulate and limit systems that use biometric tracking, and accordingly to have a much broader framework for the use of safe ones. As I said, we all use artificial I make no exception to you.
Now I will tell you the story of a betrayal. And why we shouldn't over-trust artificial intelligence. I asked GPT how I could prepare for a specific AI-related exam. After all the recommendations, there were also such learning resources, after which I did about half an hour of research on applied artificial intelligence for cyber security by Kailash and it turned out that such a book actually does not exist.
After which I reprimanded GPT chat and asked him: "Okay, I can't find such a book." He admitted that he was hallucinating. This is a reminder to all of us to take it with a pinch of salt. What GPT chat tells us, it is not infallible, as I told you. And an artificial intelligence is only as strong and adequate as the accurate data on which it is trained.
The other, of course, is generating an avatar based on one of my photos. This has nothing to do with me. That was also a big disappointment. So don't rely too much on GPT for an avatar. And all kidding aside, always question and verify the things that artificial intelligence tells you. I don't think anyone is intentionally trying to confuse or lie to you. It's just that this is
a young system that is not yet fully mature enough for us to trust it 100% . and even if it does become fully mature, whether we should trust it 100% is a completely different conversation. If you have to remember a few things from this lecture, I urge you to remember these: intelligence is here and here to stay. We ca n't get around it. It is a force
that allows us to multiply our efforts, both offensively and defensively. The other thing that is extremely important is to adapt to the threats that are produced and created by AI, because otherwise the industry itself will throw us out. This is a completely normal and organic process. Regardless of how you use it, as I told you, think in the context of how, how useful it can be to
me, how secure it is, and accordingly, how much I should validate the data I receive. The other thing that's important at this stage, in my opinion, of course, I don't know, maybe in two or three years the way artificial intelligence looks will be totally different from what we see now. But at this stage, human expertise is indispensable in using artificial intelligence. So AI can be a very
effective assistant to us, as long as we train it properly and know how to utilize it. But the human element of the workforce will not disappear for now. It's simply a tool that we must learn to use effectively. When we talk about artificial intelligence, we always have to think about a few things. We have seen AI fail in art, respectively. These are quite a few situations that
I guess each of us has seen. However, do we want AI to fail in And this is a question that every organization should ask itself. What if we successfully integrate artificial intelligence into various cybersecurity processes and, for example, it uses intelligence data that is contaminated, generating irrelevant indicators of compromise and we cannot use them or they prevent adequate testing? What if AI starts making detections of user
behavior that are not actually based on true compromise, but are actually false positives, then we will start to hinder business. What will happen if we implement artificial intelligence and it produces so -called true negatives or false negatives? What would happen if we implemented artificial intelligence into our email security system, which allows phishing attacks to pass through without any problems, and it didn't work adequately? These are all
questions that each of us who uses and works with artificial intelligence must ask ourselves in order to be able to adequately manage these systems. At this stage, we cannot be overconfident. We need, as I told you, to simply learn to work and successfully use artificial intelligence. Now we'll move on to the Q&A part, but something I urge you to think about is are we prepared for threats
that are created by AI and if we're not prepared, how will we prepare? What I can recommend to you is to get informed. Ah, we live in an extremely digital era. We have the ability to receive information from anywhere. And you see how many articles I shared that are from the popular press. They're not even from that technical of an edition. They were deliberately chosen to show
you that artificial intelligence, cybersecurity is all around us. It takes its place in all more serious media of whatever format they may be, so that a person is uninformed in ours more due to a lack of desire than a lack of sources. Inform yourself, read. That's the only way you can develop. Implement artificial intelligence in your organization in some way, especially if you are involved in cybersecurity.
If not, raise the issue with the people who deal with this matter. If an organization uses artificial intelligence in any way, it is very important to consider how this is protected, what methods are used, because the attack vectors there are endless. We have chain attacks, we need to be careful about the price data. If we use, we should think about direct and indirect prompt and injection, respectively.
These are all things that cannot be missed if we want to have an adequate level of protection for the already implemented artificial intelligence. And another thing I can recommend to you is to participate in various forums, discussions related to AI security. This way, you can stay ahead of events, stay ahead of attackers, and most importantly, be adequately prepared for what is happening these days. So that's my
advice to you. Once again, accept that it's here, as we all accept it, and just learn as quickly as possible how to use it so that it can be useful to you. Thank you. [applause] And we thank you. Now we can also upload Vlogs, as I see that questions are already coming in. We also have some that popular, so yeah, I think we have time for two,
three, four questions, so if you want, let's just move them forward. What tools do I recommend for trail hunting? Well, it 's a bit of a general question, and I'm not sure who asked it, but in general, there are two main elements to target hunting that we can look at. The fundamental ones are the third and the intelligence platforms. They come in two types: open source and
commercial. If I told you that one is better than the other, I would be lying to you. Each has its advantages and disadvantages. Of the open source platforms, you know that the most popular are MISSP, Open CTI, and Sticks. Whichever one you implement, it is very important what feeds you use. Another very important thing in line hunting, in order to be able to do effective tree hunting,
you must have adequate tree and intelligence, which comes based on any feeds you receive, whether from publicly available information or closed ones. The other thing that is 100% necessary for trending is a commercial intelligence platform. It's just that the advantages that a commercial intelligence platform provides are very great, because here we can now have dedicated domains to be monitored, and social media accounts for executives, and so
on, which helps much more than an open source platform, but one cannot exist without the other in any case, so you have to combine both. I would not in any way like to promote a given trading intelligence platform at the moment. Do your research. There are enough popular ones on the market, but this is the foundation of trend hunting. Adequate third party. And as we recommend the
words of Webtraffic, this is again a bit relative, but you have a Web application, you have CM, these are things that are the foundations of web logs for webtraffic and from there on, potential opportunities, you have to create your own strategy of what and how I want to limit and what to do. web traffic access. We've been waiting a bit for the captcha topic. To date, an
application without a captcha, with all the botnet networks that exist on the Internet and constantly target various sites, is, to put it mildly, risky and slightly irresponsible for an organization to have for its applications. So the captcha is also extremely , of course, on how to validate sources and how to trust legitimate ones, following the example of Cop ala 365. Now, you can never know 100% that
a source is reliable or not, unless you have attended a given event. But this applies not only to information security, I suppose it also applies to life. You know that history is usually written by the victors, but that's another topic. How will you validate it? You take a piece of news and simply track it down in several different sources that have built trust in you and who
don't have the habit of reprinting information from each other. So follow publications from different countries, American, European, and Bulgarian. I don't know if I recommend it. You decide, but be sure to follow different sources. If you take a piece of news from EVM and just ask it what happened here and throw the news at it, EVM can tell you everything, but cross-check, meaning check on more than
one site, on more than one source and hope that it is so. Unless there's some kind of global conspiracy, four or five sites lying sounds a little strange to me. So just check in more places. There is no other formula. That's right. Is there a benchmarker who compares how secure the code is for web apps written by LM? I 'm not sure I understand this as a
concept. Is there a person to compare to in the benchmark? And there's a site that I showed you, you can see it there. Ah, but your code, as I told you, whether it's written by a human engineer or by LM, you should treat it the same way. In information security, we approach, we start from the position that application and every line of code is insecure until we
validate it. Information security has four phases: design, implementation, testing, and monitoring. This can be implemented absolutely anywhere. The same approach you should have towards the code that is generated by the EVM. You use static application security testing, you implement SEA, you use Dust, so that you know that this code that is written, right, if possible, integrate it into the CICD pipeline, if you don't put it in
the PRs to break them, it's still an option, but certainly only in this way can you adequately address this We have time for one or two more questions, signal. Okay. And what is my opinion about Kali GPT? Ah, it works as one invests more time in it. And the platform is still too young to be super adequate. It takes time, but that's the case with everyone. If
you get a llama and train it, it will do the same job for you as Kali GPT. It just won't be called GPT. My opinion, right, I'm not committing anyone to it, is that offensive security and carly Linux are already more or less relying on the reputation they've built and maybe they don't put as much effort into everything they do. There are other companies that are competitive,
that are very actively working in this direction, right? Now I guess most of you who deal with Kiversh probably know. Pera is gaining immense popularity. They were endorsed by several organizations. Yes, if we are looking for a privacy operating system, QPOS is certainly the best on the market, so the competition is already very high. And I'm a fan of Kali, I 've also used a bekt, which
was many, many years ago. Ah, but in my opinion they are a little behind in their desire to implement their ambitions. Is it safe to implement AI in our applications? This is a very abstract question, but if I had to give a definite answer, no. You ca n't just implement it in your application. How do you implement it? What does it have access to, what data does
it process? What information do you give him? This is extremely important. Your input may be extremely risky. If you simply copy-paste source code and run it in prompts, it means that your source code, which is the intellectual property of the organization, goes into one that we all know is most likely well-managed. But then what happens in a supply chain attack? You know how many vendors have been
hacked over the years, and we're talking about huge vendors like Fire, which were responsible for the Pentagon and all the facilities around them. And last year, you remember what happened to Sud Strike, which is a huge vendor and a market dominator for sure. So what happens in a Supply Chain attack? The answer is no. You have to be careful about how they use AI and what they
use it for and what it will have access to. If you're just making innocent prompts, yes, but it's nice to have some kind of security solution to validate those prompts. That's my opinion, right? Now, I'm a security guy and for me, validation is extremely important, but when someone wants to put in some kind of prompt, there should be a system like a proxy through which the prompt
goes and if there is, let's say, PII data, if there are any secrets, they should be stripped or obfuscated from the code so that it can be secure and sent. There is currently no such well-functioning system on the market. That's my opinion. I'm not involving anyone with it. So my advice is, if you use me to generate code, don't give it the code from your repo, just
slap it in and ask it what it does. This is a very bad option. Teach it to generate code for you with prompts and if you have any error or something, tell it: "I have a similar error, how would you write this thing?" And then think about how you would implement it, but under no circumstances use it that way. if you want, this could be the last
one. I'm just giving an update. Yes. For time. How can we protect it from being hacked and released? But I like artistic questions. And at the moment, the AI, apart from this incident when it threatened the engineer to reveal some affair of his, which everyone is silent about whether it is real or not, and if it turns it off, we don't know of such a level of
free thinking, but there are scenarios where this could happen, unfortunately. For example, if you are developing for red teaming purposes, sorry, for red teaming purposes, and you want to use it in some, let's say, controlled country, it may happen that it escapes the sandbox and then it is a problem. You have all the problems. If some of you are not familiar, you can read about a virusnet.
If you don't feel like reading, you can listen to Darknet and there's an episode about Stukne, how a virus accidentally starts circulating in space and affects millions of machines, but it itself can't exactly be hacked, and as of today, that AI can't think for itself, but you have to be the ones to test it and limit it. That means you have to impose some restrictions on it
and be careful how you use it. This about the couch is provocation, I won't respond. So, I think this is a pretty good ending to your lecture, since our time is up, but all of you who asked questions can talk to Milan afterwards during the break. Thank you again. And I thank you, I'm here until the end of the day, so whoever has the refusal. Thank you.
yes
More from this event
See all 18 talks →
Удобството на програмирането чрез последователности и изгледи в модерния C++ / Петър Армянов
52:15
Under the Hood of Solana: Deep Dive into the Transaction Lifecycle | Blockchain / Огнян Чиков
46:04
Магията на GraphQL | Software Architecture / Стефан Кънев
52:46
От хаос към система: Мост между дизайн и код / Ставри Георгиев
45:08