Amazon Web Services (AWS) is harnessing the power of custom large language models (LLMs) to improve its internal application security processes, while using generative artificial intelligence (genAI) and LLMs to help customers effectively manage security vulnerabilities and streamline their security investigations, according to Amazon Chief Security Officer Steve Schmidt.

“LLMs and generative AI are the newest tool in the chest to help improve security outcomes,” Schmidt said during his keynote speech at AWS re:Invent 2023. “GenAI plays a new and different role when compared to automated reasoning or other forms of machine learning.”

Schmidt used internal security reviews of AWS code as an example, explaining how the vendor is using a custom LLM to accelerate these reviews. “The model identifies potential security issues, which are application security engineering team then use as a guide for their review.”

“The sheer number of code reviews we've conducted over the years and the scale of our code base, make it possible to effectively train and finely tune this model,” he said. “At AWS, we see issues that simply don't happen in other environments because of the incredible scale of our operation. And this model is understanding of our specific situation helps deliver actionable outputs that accelerate our AppSec review process and the software development process overall.”

Integrating genAI into Amazon Inspector and Detective

In addition to the internal use, Amazon also added generative AI-powered security capabilities to its Amazon Inspector and Amazon Detective services.

Amazon Inspector is a vulnerability-management service that continually scans AWS workloads for software and code vulnerabilities and unintended network exposure. The vendor now expanded the code scanning for AWS Lambda functions to include assisted code remediation using generative artificial intelligence (AI) and automated reasoning.

“This service uses machine learning models and automated reasoning to help you identify code vulnerabilities and provide guidance that you can use as part of remediation,” Schmidt said, “Generated AI can help take the solution one step further.”

The new feature “uses generative AI to help developers reduce the time it takes to address security issues within their code. In addition to the details they previously received about the issue, this new functionality creates in-context code patches for multiple classes of vulnerabilities to address these issues,” he added.

Also announced at the AWS re:Invent 2023 event, the Amazon Detective team took a similar approach to provide finding group summaries using generative AI that automatically analyzes finding groups and provides insights in natural language to accelerate security investigations.

Amazon Detective service automatically collects log data from users’ AWS resources and uses machine learning, statistical analysis and graph theory to build interactive visualizations for faster and more efficient security investigations.

“This new generative AI capability uses that context to generate a narrative of the issue, helping to bring a broader perspective and more security knowledge to bear,” Schmidt noted. “The capabilities summarize the data like a readily available expert with very broad security training coupled with specific knowledge of the individual investigation currently underway.”

How to use generative AI safely and appropriately

To use generative AI and LLMs securely and appropriately, Schmidt suggested companies answer three key questions that shape the alignment of security needs within business workflows when using these technologies:

  1. Where's the data and can the data be exposed through the LLM use? Schmidt stressed the importance of understanding how data is handled, both for training and the daily use of LLMs. He pointed out that the quantity of data fed into a model directly influences its predictive capabilities. Meanwhile, security teams should also be aware of the exposure of data while using LLMs, particularly during the training phase. He emphasized the need to maintain encryption of data both in transit and at rest and minimal permission scopes for data access.
  2. What happens with queries and any associated data? Organizations should recognize that training data isn't the only sensitive information. Schmidt highlighted the query itself can also be sensitive and should be part of the data protection plans. “There's a lot you can infer from a question that a user asks.”
  3. Is the output of the generative AI models accurate enough? Schmidt noted that the quality of these outputs is steadily improving. From a security perspective, the use case defines the risk.

These three questions “guide how our security teams think about generative AI and LLM services for the use of our business,” Schmidt said. “Our internal Amazonians use these tools. You should answer the same questions to ensure that you're meeting your own company's security requirements. The answer to these questions changes depending on the modeling question and how that model is delivered.”