Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

AI Has Changed Attack Speed, Not Security Fundamentals

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals.

cybersecurity maturity

People who know me well know that I am a very direct person and as such, I don’t enjoy overcomplicating terms used to describe straightforward things. In recent months, Frontier AI and other tools have allowed attackers and defenders alike to shorten the time required to identify vulnerabilities and develop exploits for those vulnerabilities. With this has come an awful lot of hype and buzz around the topic of “virtual patching.”

I was on a call with a colleague the other day, and he asked me, “Have I gone mad, or is virtual patching not a new thing?” To which I responded, “No, you haven’t gone mad, virtual patching is nothing particularly new – people used to call it defense-in-depth, among other things.” In other words, the recent press around Frontier AI has given some in the security industry an excuse to create a new term for a security best practice that has been around for decades.

Not surprisingly, good security hygiene and good security fundamentals go a long way toward preventing security incidents and securing applications, even in the age of “Frontier AI.” With so much hype around “virtual patching” going around, what should enterprises focus on when it comes to protecting their applications from vulnerabilities and exploits that come faster than they can patch those applications? While not an exhaustive list, here are a few suggestions of security fundamentals that can help protect applications:

  1. IAM: If an attacker can’t authenticate to an application, isn’t authorized to use it, and can’t bypass authorization (by using BOLA, BFLA, or BOPLA attacks for example), that will reduce the attacker’s ability to attack the application. It is always possible for the attacker to find their way in through any number of means, of course, but our goal should be to have proper Identity and Access Management to make that as difficult as possible.
  2. Network Segmentation: While many applications are meant to be publicly accessible, not all are. If an application doesn’t need to be accessed from everywhere on the network, it shouldn’t be. Leveraging network segmentation to restrict application access to network segments that need it is another way to protect applications from attack.
  3. Least Privilege: Building on the IAM point above, least privilege is one of the more powerful security fundamentals that an enterprise can leverage. The idea is simple – give users only the level of access they need. When it comes to applications, that can mean significantly limiting the ability of an attacker if that attacker is able to bypass other defense-in-depth measures. This is a big win for application security.
  4. Network Security: Any attacker will need to traverse the network (whether the open internet or more restricted networks) to get to an application. Good network security will go a long way to preventing unwanted access to applications at the network level.
  5. Endpoint Security: Sometimes, a compromised employee laptop or mobile device is the preferred hop point to an application. Other times, systems hosting applications can exhibit strange and suspicious signs. In both cases, robust endpoint security can help security teams detect that an application is being attacked. In some cases, endpoint security may even help security teams respond to and mitigate the issue before too much damage has occurred.
  6. Application Security: It may sound obvious, but proper application security at all layers of the application stack (infrastructure, API, AI, and others) is extremely important. There are many ways in which applications can be protected, even if they are vulnerable. It is worth the security organization’s time to understand which protection capabilities make the most sense at each layer of the application stack. Some go-tos are WAF, API Security, Bot Defense, and application layer DDoS protection, though there are others.
  7. Data Security: Encrypting data at rest and in transit is another great tool in the application defender’s toolbelt. The reason is quite straightforward – even if an attacker can gain access to or steal data they should not have, it will be much more difficult for them to leverage it for nefarious purposes if it’s encrypted.
  8. Preventive Controls: Good security policies and the ability to enforce them are another key component to defense-in-depth for applications. It still surprises me (though it probably shouldn’t) how many application compromises are the result of misconfiguration, poor security hygiene, or other such fundamental security oopsies. Ensuring proper preventive controls helps to significantly lower the risk of an application being compromised through means that should never have been possible.
  9. Detective Controls: Detective controls augment and complement preventive controls. Ensuring proper telemetry collection and monitoring that telemetry data for any malicious or suspicious activity is a must. Further, the rate at which attacks evolve in the age of Frontier AI means that we can no longer rely on signatures alone. Signature-based detection needs to be augmented by novel ways to detect potential attack activity that requires attention. One example of this is AI-powered WAF and WAAP solutions, though there are others as well.
  10. Processes and Procedures: Proper processes and procedures are, unfortunately, an often overlooked area when it comes to application security. They should cover areas such as: continual red teaming and vulnerability assessment (quarterly won’t cut it anymore), risk assessment, patching, policy implementation and enforcement, continuous security monitoring, incident response, GRC, and others. Having these important areas documented in a scientific manner leaves less room for error and leads to a vastly improved application security posture.

If you think the above list looks a lot like defense-in-depth, you’re not alone. As I noted above, good security hygiene and good security fundamentals are still the best defense against most security risks, including at the application layer. Given the hype, buzz, and confusion in the industry around “virtual patching”, I thought it helpful to provide a few suggestions of areas where security organizations may want to focus their efforts as the Frontier AI space matures.

Written By

Joshua Goldfarb (Twitter: @ananalytical) is currently Field CISO at F5. Previously, Josh served as VP, CTO - Emerging Technologies at FireEye and as Chief Security Officer for nPulse Technologies until its acquisition by FireEye. Prior to joining nPulse, Josh worked as an independent consultant, applying his analytical methodology to help enterprises build and enhance their network traffic analysis, security operations, and incident response capabilities to improve their information security postures. He has consulted and advised numerous clients in both the public and private sectors at strategic and tactical levels. Earlier in his career, Josh served as the Chief of Analysis for the United States Computer Emergency Readiness Team (US-CERT) where he built from the ground up and subsequently ran the network, endpoint, and malware analysis/forensics capabilities for US-CERT.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

David Cass has joined Grayscale Investments as Chief Risk Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.