Generative artificial intelligence (AI) is working its way into every realm — and cybersecurity is no exception. Today at Google Cloud Security Summit, Google Cloud increased its efforts to combine AI and cybersecurity with the announcement of several new and enhanced products and partnerships.
The goal is to get the “power of generative AI to be a force multiplier across all security,” Sunil Potti, GM and VP of cloud security at Google Cloud, said in a prebriefing. He emphasized that “generative AI has the potential to reduce the toil of repetitive tasks that plague security teams.”
Notably today, the company announced that it has opened its Google Cloud Security AI Workbench to partners including Broadcom, CrowdStrike, Egnyte, Exabeam, F5, Fortinet, Netskope, Securiti, SentinelOne, Sysdig, Tenable and Thales.
The workbench platform is powered by the specialized security large-language model (LLM) Sec-PaLM, which is trained on a corpus of threat, intel and historical data. It uses AI to find critical vulnerabilities and malicious code submissions, flags unknown threats and helps expedite risk assessment.
Google Cloud, AI and cybersecurityPotti said Google Cloud has been working to integrate AI into its cybersecurity products for more than a decade to both defend itself and its users.
One use case for generative AI is aggregating data from multiple sources to establish complete views of risk. Also, AI can help address the “chronic shortage” of security talent by helping non-experts secure company data and assets, he said.
“The only way we can solve the talent problem is to have a larger pool of people become security people,” said Potti.
These nontechnical supplemental workers don’t have to become security experts, he said, but they should be committed to the cause. If interfaces can be augmented to be more security savvy, “then suddenly you've expanded the pool of people to help you with the security problem.” This, in turn, allows security operators to level up.
“We see the tremendous potential that AI can make in up-leveling developer and security teams,” Loris Degioanni, CTO and founder of security and monitoring platform Sysdig, said in a statement. “In the event of an attack, AI can help everyone better communicate and leapfrog threat actors who are also racing to use AI for their own ill-gotten gains.”
Attack path analysis mimics, thwarts attackersAttack path analysis is a growing technique that essentially mimics how a real-world threat actor could exploit security gaps. This helps security teams identify how and where they could be attacked.
“These tools can enable them to better prioritize security findings and discover pathways that adversaries can exploit to access and compromise cloud assets such as virtual machines, databases and storage buckets,” said Joakim Nydrén, product manager for Google Cloud Security.
To support its customers in this endeavor, Google Cloud is adding attack path simulation to its built-in risk management tool, Security Command Center. This new capability — which will be available later this summer — simulates the many ways attackers attempt to infiltrate a cloud environment, then generates attack graphs for security teams along with detailed information on how to remediate issues.
The center computes attack exposure scores for misconfigurations and vulnerabilities; this measure of cyber risk takes into account how resources are exposed and the path of least resistance for attackers. Security teams can then use those to prioritize remediation efforts.
“It can give better context to everything you do on the cloud,” Jeff Reed, VP of product for cloud security at Google Cloud, explained in a prebriefing.
Customers including Nordnet Bank have used these capabilities in private preview. In one instance, according to Nydrén, the Command Center alerted a customer to a finding related to a service account whose keys were not being rotated. The company’s cloud security manager discovered that while the account was titled “test,” it still provided access to storage buckets.
An attacker stealing credentials for this account could have easily accessed production data. The security manager quickly removed account administrator privileges.
“The attack path simulation enhanced their understanding of the severity of the finding, and helped convince them to make it a high-priority fix,” according to Nydrén.
Monitoring egress trafficProxies are a foundational security element because they monitor egress traffic and provide protection and control.
Today, Google Cloud announced Secure Web Proxy. Now generally available, the tool can help security teams implement zero trust principles and better enforce access policies by limiting egress based on source identity, destination or request types. Organizations can also monitor access to untrusted web services and investigate security incidents.
“It’s aligned to zero-trust principles in terms of reducing access privileges and resources, particularly when they're going external to the cloud,” Reed said.
With the service, organizations configure workloads to use Secure Web Proxy as a gateway, and web requests can originate from virtual machine (VM) instances, serverless environments, containers and workloads outside Google Cloud, Reed said. Policies and rules in the proxy are applied to traffic sent from these workloads.
Organizations can create identity access management (IAM) policies to limit, for example, a service account from sending traffic to specific outbound destinations.
The tool integrates with Cloud Logging to record metrics and transaction logs for requests handled by the proxy. These logs can also be used in forensics to investigate security events involving egress web traffic.
“By using the granular policy controls and TLS inspection, we are ensuring that our cloud applications only access approved external destinations,” Google Cloud customer Mos Saleh, director for cloud architecture and application security at ATB Financial, said in a statement. “Additionally we are able to comply with data security regulations.”
Google addresses threat detection, fraud prevention, API misconfigurations, passkey supportGoogle Cloud made several other announcements today, including the following:
- Chronicle Security Operations now provides threat detection, investigation and response (TDIR) for Google Cloud. This integrates with Security Command Center Premium to collect and analyze data, detect and investigate threats and automate responses to mitigate risks.
- reCAPTCHA Enterprise Fraud Prevention: To better secure financial transactions on applications and websites by preventing fraud with holistic bot management, account takeover and online fraud detection, reCAPTCHA Enterprise now has a dedicated fraud prevention solution. This identifies targeted manual attacks and large-scale fraud attempts and automatically trains fraud models based on behavior and transaction data.
- New capabilities for Apigee’s Advanced API Security that can detect security threats and API misconfigurations. Currently in public preview, the detection dashboards use machine learning models that have been trained on API traffic to uncover abuse incidents, including business logic attacks, scraping and anomalies.
- Passkeys support for Google Cloud and Google Workspace accounts. Now in open beta, organizations can allow their users to sign in to Google Workspace and Google Cloud via a fingerprint, face recognition or other screen-lock mechanism in lieu of passwords.
Comments