Securing the AI Frontier: Understanding AI Attack Vectors TY Page

Securing the AI Frontier: Understanding AI Attack Vectors

Transcript

Thanks Chris. Assuming let's share my screen. And I may have changed the title just a touch. But welcome everybody. Tracy Walker here to talk a little bit about AI. Not a very popular topic right now at all. So sorry if this might be a little boring sarcasm intended there.

First, this is kind of what we're going to cover today in this, kind of talk a little bit about what everybody is already seeing. So where AI can help APSEC mitigating your own risk with AI and LLMs, and some practical advice here as well, depending on where you're starting. I think, Chris, do we have a poll that we can start off with? We do. I'm left right now. So B to B.

looking out for a Polish Republic on your screen right here. Yeah, it did. Thank you. So basically, and I've got three or four poll questions. This first one just kind of gives us an idea. Without really knowing what everybody's level of experience is with AI, how much you are or are not doing with AI, for a general webinar like this, kind of difficult to not cover some things that some people are probably already going to know.

So I'll await some of the poll results there. That'll give me a little bit of a clue. And then while you're answering that poll question, I'll just do a quick introduction of myself. So again, my name is Tracy Walker. I joined DefectDojo last July. So I've been with the company for, coming up on seven months, or eight months actually, if you count the month of July, the zero. But,

Yeah, so have been with the DefectDojo for a short time and have spent about 30 years plus in information technology. The first 20 years was mainly software development operations, a lot of internal IT, some management within there and executive management, etc. But and a lot of consulting.

which really kind of taught me a few things about ego and knowing what you know and what you don't know and things like that. So in the terms of AI, let's just be real clear. I am not an expert. I have used AI tools probably for about the last year for various things, presenting documentations, helping my daughter get through college, things like that.

but also writing some code and code help, co-pilot, things like that. So I have some experience using it. I have some practical experience trying to use it in situations where maybe it wasn't the best choice of a tool and then you get a lot of spin and issues that you can run into. So that's the very first thing. I'm coming into this probably at a lower level than everybody else on this call. And so I've kind of.

created this webinar with that assumption that for some folks, I may need to catch you up a little bit. Other folks, you may see some of this and be like, yeah, duh, we know this. But we'll try to get you to the end to at least give you some practical things. And if we have some time, I can even show some of the ways I've been using AI tools for real work, mainly on the open source version of DefectDojo.

Um, so what was our poll results? Do we know looks like around 65% said yes. And then 35% said no. Okay. Awesome. That's really good to know. Thank you.

So we're going to start off talking a little bit about what everybody is seeing in a software development. I would even say for some of those who said, no, it's not being used here.

DeepSeq and some new LLMs that are now kind of emerging as this is better than that, uses less power and all these kind of things. So these are dated. This all comes from a GitHub research. These statistics have been quoted just about everywhere in lots of different publications and things like that. If you want to go and look at this particular PDF, it's available, has a lot of great statistics in it, and really kind of confirms a lot of the things that we're seeing.

Again, eight months ago, this number is absolutely low for the number of environments using it. 40% of new code is being generated by AI. This is based on their study, meaning new code, not necessarily code that's existed before, but probably closer to half of all the code now is being AI generated. 50,000 organizations at that time had adopted GitHub Copilot.

This is probably the most popular AI assistance tool for code completion, it'll finish your lines of code. I've seen users talk about, they hit tab three times and they had a PR. So this can be very, very efficient and a lot of people are using it. And then this was the one that I think was kind of the most important that in the study that this particular blog kind of goes through, and this was done with Accenture, but...

Some of these numbers may be skewed in some ways, but I still think that this has a big indicator in when 96% of developers install the IDE extension into their IDE, Visual Studio, whatever it may be, and start receiving and accepting suggestions immediately, that's pretty much everybody.

There are two different kind of categories if you wanna think of it, of how developers are using or how development is using AI. The extension with the copilot, this is what we're looking at here. So this is in Visual Studio, mainly for autocomplete. So direct code generation, right? A person using it to generate code, function implementation from comments. So being able to add code or kind of create a structure and then having the LLM generate code for those sections, or when you're adding, modifying code, generating test cases.

Code comments and documentation, one of the things that humans don't do as well, or consistency, or when you're under a deadline, you stop kind of commenting on your code and things like that.

And of course, refactoring and even conversion of code, that kind of thing. So direct code in generation or within a SDLC. So the visual that we have here, this is kind of that infinity, agile DevOps kind of flow, we're always just flowing, whether your sprints are quarterly, weekly, daily.

But all of these opportunities for all of these different places where we have security tests and things like that, that's what DefectDojo aggregates. But within that workflow, doing automated code review, dependency analysis, so all of these things that we're talking about here within the flow, usually you're doing some of these things anyway and maybe the tools that you're using have added some AI components.

but definitely adding AI components to all the things that we're already doing. And that's a theme.

The impact on software development. So this also comes from that, actually, this will come from that same blog. So there's some additional, what are the positive impacts of software development? Increase in productivity. This is really the quantity of code, not so much the quality of code. So just in matter of number of lines of code have been increased by 25%. Reduction in boilerplate code.

So boilerplate code is repetitive code that doesn't really add any extra functionality. But reducing that is actually a good thing because this can take a lot of time just to manually, a lot of people will even automate building a lot of boilerplate code and templates and things like that. But reducing that is actually a positive thing. Faster code completion. So this marks basically spending half the time, right?

So we're in creative, we're doubling our speed, if you will. Not necessarily, doesn't necessarily translate one-to-one with developer productivity, because when that code completion is happening for us or the AI is building these things, sometimes then you also have to troubleshoot that code. And when you're troubleshooting code that you didn't actually write, it's a little bit more challenging, because troubleshooting means you really have to understand what it's doing, understanding what the LLM generated for you and what it's actually doing.

So sometimes that also can slow you down extra troubleshooting because you're kind of having to catch up to what is this thing trying to achieve here and think so yeah, could be twice as fast, but you may spend a lot of that time also troubleshooting, dealing with hallucinations and things like that.

And this is a repeat because I want to repeat this anytime developers get exposed to this, this is a tool we will use. It's that's just the way it's going to be. If it makes me faster, if it can automate repetitive tasks, of course we're going to use it and whether we're admitting it or not in an environment or not.

So the majority of code that were on all of those statistics that we were looking at in those previous slides was for adding code, not changing code, not updating code, not necessarily refactoring code, or especially deleting code.

The code suggestion algorithms are incentivized toward acceptance. This is a pretty important thing to understand that it's trying to get you to use what it suggests. And so it's really kind of, I struggle with this word incentivized, prioritized, you know, how is it being rewarded from this? Well, because it was successful. If you took the suggestion, that must be a successful.

Sometimes wanting to be accepted is not always the best approach, whether in life or AI. So you kind of got to be cautious. You may not be getting all of the suggestions. You may not be getting the best suggestions, but you're getting the one that the AI thinks that you're going to accept.

There are two different kind of categories if you wanna think of it, of how developers are using or how development is using AI.

Alright.

So takeaways, did I? Yeah, takeaways. These are pretty easy. This is one of those duh moments. It's here whether you like it or not. There isn't any part of the SDLC that AI is not going to affect. Significant productivity gains have been experienced and seen especially for junior level programmers. So sometimes using the AI tools speeds the junior folks, the less experienced folks up faster.

from all sides because as we add AI artificially generated code, we're also introducing potential a lot of security risks, some that are very familiar to us, things that we're already dealing with with human-generated code.

this will come from that same blog. So there's some additional, what are the positive impacts of software development? Increase in productivity. This is really the quantity of code, not so much the quality of code.

All right.

If it takes me 15 minutes to detect an incident, well now it's maybe down to seven minutes, right? So we're decreasing the amount of time needed to detect things.

If you really look at these integration points, this is just your SDLC, right? It's the systems, it's how you're changing those systems, those applications, your development lifecycle, your operations that are taking place.

So the one that I liked the most was the documentation and the knowledge base maintenance. As these things happen, sometimes in the heat of firefighting, we don't actually go back and document the root cause and all of that kind of stuff.

If you've ever been through one of those exercises where developers are given the exact same requirements and they build a quick application and it is two completely different applications, that experience of, you know, every environment is unique, not just different, unique. Now this seems obvious. Some will be going, duh, but this is where your humility comes in coming into an environment thinking that, well, I did it this way at the last three companies, it's sure to work here. Not necessarily.

So this framework is extensive. I brought up a couple, there's a lot of different components to this. And I would be shocked that anybody would even attempt to try to implement this whole thing.

And when you started watching the videos, because some of them had like 200 views and 500 views, but they were all released in the last five days.

But alas, even when using AI tools to try to build this, I'm still working on it.

Well, you know, you can't have a CIO with root, right? But the thing that I have learned, especially through the consulting, every IMT environment is unique.

If you've got open source, publicly available code, that's a less risk. But the internal code, anything that's proprietary, proprietary information, you don't wanna be copying, pasting that into an LLM for any reason because that becomes part of that training model. You could really become exposed at that.