Zscaler’s threat research and incident response team says that it is harnessing the power of artificial intelligence (AI) and large language models (LLMs) to predict breach paths by performing impact analysis while recommending policies to prevent future attacks. The vendor plans to productize this prediction capability, which has been used internally.
Zscaler collects more than 300 billion records and transactions per day from multiple sources, including network endpoints, partner feeds and threat signals, which can be fed into its proprietary AI engines and LLMs to continuously learn from changing cloud-based policies and logs, allowing Zscaler to understand and predict how and when malware will progress, according to Zscaler Product Manager Sanjay Kalra. He likened this method to a doctor’s experience diagnosing and predicting disease progression.
“We have data from all our 7,000 customers and general records. So when we see a malware, we know the progression for that malware,” Kalra told SDxCentral.
Once malware shows up in one customer’s system, Zscaler can see that same malware across its customer base too, he said. “So I can tell this customer, even though he might be in his early life cycle of this breach, based on what I've seen in other places: this is how it's going to progress for you.”
He added this proactively security approach is fundamentally different from the industry’s conventional reactionary strategy. Zscaler’s approach focuses on breach prediction and prevention rather than remediation post-compromise.
“The key differentiator for Zscaler is the data. The amount of data and the quality of data is what makes the AI unique for Zscaler, because we can use all these signals to help you with predicting breaches. And once we do that we're also using that information to recommend policies for users on how to prevent or how to safeguard against breaches,” Kalra said.
This capability allows Zscaler to recommend preventive measures and potential policy changes. “We're learning the policies of every customer. We know what is the right policy to deploy to prevent this breach from progressing. It’s like taking the right medicine that [the patient] needs to take to prevent it from going to the next level,” he added.
Is this breach prediction accurate?Kalra admitted the prediction is not 100% precise, and this predictive model is probabilistic, meaning it increases in accuracy as more data points become available. “But given the vast amount of data we have, we can come very close to predicting and helping you prevent spreading.”
He added the prediction is designed to offer timely advance information, especially to customers earlier in the breach lifecycle. “It's a promising model. It's not going to be [100%] accurate, but as you get closer, it becomes more accurate. But then what happens is that it gives an advantage over people who are earlier in the lifecycle.”
Currently, the breach prediction tool — Security Autopilot — is used internally by Zscaler’s ThreatLabz team. The vendor reports that it has assigned a team to make it into a product, allowing a broader customer base to use it. Kalra didn’t reveal the timeline for the productization.
More generative AI-powered featuresOn top of the breach prediction tool, at this week’s Zenith Live 2023 event, the vendor also introduced Zscaler Navigator, a generative AI-powered interface to enable customers to interact with Zscaler products and access relevant documentation details using natural language and multi-model data loss protection (DLP) that protect customers’ data from leakage across various media formats beyond text and images, such as video and audio formats.
“Zscaler Navigator actually enables a natural language interface for our administrators and Multimodal DLP helps data leak protection in text, audio, video and images,” Zscaler Syam Nair said during his keynote address. “We are using our own trusted LLMs based on our own log data for advanced breach protection.”
Comments