Building Future of AI-Native Cyber Defense w/ Sasan Padidar
Watch episode on YouTubeSasan, it's so nice to finally have you on the Noise to Signal podcast. It's been I've been wanting to have you on this show for a long time. Finally, you're here. typically the way I go into these interviews, Sasan, is I go into the background of the I go into the background, talk about the history, learn more about the guests and then go from there. you've been in this industry for over you've been in this industry for over 20 years, but I don't think you've ever spoken about your journey, your history.
your background in any c sort of details. So I think you know that that would be a good place to start. Maybe let's start with your background. Where are you from, what you have been doing for the last twenty years.
Sure, yeah, that's that's great. Thanks. Thanks for having me. Yeah, I'm I'm originally from Iran. I I left when I was a kid and I mean, you know, went to school in the UK and eventually ended up in the Bay Area. always, you know, fascinated with the startups and computers in general. Like I started programming at a very, you know, young age and been just I just love the stuff. Like love building startups, working on technologies and and yeah, so
That's basically where it all started from.
How are how are things going Iran? It must be a very difficult time for you to you know, like see all the things that are happening in Iran, in Persia. How are how are things are things are settled, ka
Yeah, it's it's difficult. I mean, it's hard to get used to it, but I I th I think at this point I'm so sorta got used to it. But it's really tough because like every day you come in, you know, there's like some negative news coming in and you have family there and obviously, you know, it's hard to to focus with you know so much going on. But
There's really not much you could do, you just gotta adapt and learn how to deal with it. And I think I'm just getting better at it. But I mean getting better at basically directing my attention and focus on on work.
I think this the I think the resilience is a is a true attribute of most Persians or I've met. I think this is like a very true trait in most of the Persians I've ever met in my life. Because if you think about it, you know, the with all the things in that are happening in Iran, you also had a second kid or first kid, or you had a first kid as well, right? So mm it almost feels like you know, when things get
Perfect.
Better or comfortable, you get uncomfortable. Is there any truth to that?
yeah, for sure. Yeah. I I don't know like w why, but every time you know things get a little too comfortable, I start, you know, thinking about the next thing and it gets a little uncomfortable until I'm in a in another sort of a new situation. but yeah, with the kid and everything going on and it's just like every day is a is like training for me to learn how to focus and manage my time.
So far, my earliest my earliest memory, my earliest memory of you is as a as a product builder. The first time I met you was when you were building a very innovative company, around container security. container security, FlawCheck I believe was the was the company that you were building. what made you build
the solutions around container security at that time because this was like very early days of container security. No one knew what a container is. I mean Docker was picking up, but apart from that there was not much known. But you decided to start a company around that problem. What was going on in that time?
sort of like it it wasn't like we we started out building a Docker security solution and basically what happened was we was like all we wanted to do is start up, you know, opportunity kind of came along and I decided to start a company with my co-founder and we started basically building a malware engine. and you know, malware was like thought to be a solved problem at the time, but but what was happening was
Everything was moving to the cloud. cloud was a very new thing and people were like thinking like how do we use cloud to you know store files, share files. And our thinking was what would happen if because there's the volume of data in the cloud is like so much. we thought like, you know, what's the best approach here? And the thinking was okay, let's bring the malware engine to the files where the data addressed is and have it scanned.
you know these files setting address but because previously it was either files in motion or data in motion or files on on the endpoints that we are being scanned when we were like you know let's scan it at the source make sure it's like safe and then you know basically offer that kind of a solution in in that process meeting customers and talking to prospects folks started asking us like
Can you put this in a Docker container? And that was the very first time we ever heard the word Docker. And we're like, what's Docker? I mean, we got into it, and that's basically where we saw the opportunity that Docker had a ton of vulnerabilities in these container images that were being built because effectively they were operating systems packaged in a container with some application running on it and
Obviously nobody thought about scanning them for issues. so we had the
I think there were no sensors available as well for scanning containers at that time because this was a new type of this was a new type of an asset. You know, this was not an EC2 instance, it was not it was a completely new kind of a system. I don't think you could even SSH into it. Like you could not even scan it. And so you had to like completely new way of doing these things.
Exactly. Yeah, because it was a
Yeah, exactly.
Exact exactly.
Exactly. So so our sort of engine was a b effectively a headless parser for files. So it was very well suited to address containers because containers are just files and with some end caps simulation around them to run on the host safely. So that was basically but but you know traditional scanners either required SSH so they could SSH into it or you wouldn't install them. But
Neither of those things would work in containers. So our solution was basically just the way we were doing the malware thing was basically get into the container, look at the state of the container as files, process these and generate a report for it. And when we started doing that, like we were just finding so many problems that people just had no idea about. And we know we started getting some traction on the product.
And you could you could do this offline. You didn't have to like literally log into the container. You could literally just look at the container image files, scan the file system or the layers of the file system and then find the running packages or install packages and do a quick assessment as well. As well.
Exactly, exactly. So so basically what happened was we thought about okay, so containers were meant to be so before this, like the there was no dev sec ops or there was no shift left yet. So it was basically the idea was developers were using containers because it was very agile. We could build these containers, push it out, deploy it, and they don't have to wait for anything. So our model was you you can make the processes slower for the developers because that's the whole point of Docker.
Yeah.
So what we decided to do was, which I believe we were the very first product that did this, which was we basically build a container registry where you could basically store these container images in. And we were doing the scanning inside the registry. Again, very much like the the model I mentioned earlier, we want to bring the scanner to where the data is.
we basically followed the same model, built this registry, and we make sure this registry is the most secure registry on the market at the time. We had RBAC, we had all these enterprise features that you would require. but then also we had the ability, like the moment you push a container to us, it will automatically get the scan. So the visibility that was missing for the security teams because developers were booming so quickly, was all of a sudden there, where they would log into our registry and see.
Mm.
the state of all the containers and the findings that we have on each one of them.
There are two things I'm going to follow up on. One is there was this there was this misconception that Docker is secure because these containers are immutable. And so so these are very secure systems. That was one misconception from my point of view. And the second misconception was these are these container images are small because what I was seeing at that time was essentially people were kicking a VM and putting that in a container and but you would have like a
fifteen gigabyte container image instead of like the promise of the container, which is like supposed to be like very lightweight, has only the basic binaries that you need. it is very prescriptive in the sense it only has all the components you need to build the application and then you go from there. At least that was the promise of containers. I didn't see that. My so my question is,
You did you started off with the malware engine. Were you also seeing a lot of malware in these Docker containers? How are they getting deployed and distributed into enterprises?
Yeah. So what was happening was the realization that we had was because prior to this startup, like I was working at a mobile security company where we were scanning iOS and Android apps. And basically the moment there is a distribution center where attackers can build something and put it there and hope for other people to download it, they would definitely do that. So in the case of Docker, there was Docker Hub where you could basically build any image, anybody can build an image, put it up there.
It could you could build MySQL, Postgres, all of these popular open source applications, package it as a container, and put it up there. And then there is obviously no trust who is building these containers. And at the time there was no official like like like channel. It was like everybody was building their own containers. So we we sort of kind of guessed there's gotta be attackers trying to get malware published in from Docker Hub.
And the moment we started the scanning, we actually started seeing a lot of malware in containers, as well as basically custom-built images that had security problems by by design. So either they could backdoor into it or they could do a command and control type of you know attack. So that that was very common. And
you know, Docker eventually like got better and they added their own scanning to these registries to kind of protect against it. But but to this day is is a very lucrative way of getting you know a lot of you know malware distributed quickly because you could just just do like we saw a lot of these where they were doing typos squatting kind of attacks where like they spelled MySQL slightly differently and people would accidentally pull that down. And very recently I saw similar attacks that still go on.
Yeah, the supply chain the supply chain attacks if if you look at what is happening in the age of AI, that has essentially gone like exponential. And I think this were these were the early sta this, you know, the supply chain attacks in Docker containers were like the early stage of supply chain attacks. you know, my sense is and correct me if I'm wrong, and even today I I feel I struggle with like understanding the concept of how well these
So
containers are built, deployed, orchestrated and so on. Did you spend a lot of time educating the market around this container security problem? First of all, people didn't know what the containers are and then you're talking about container security. How was that process? You're a tiny startup, like you know, a small team and the onus of explaining this entire category of solution must be a big challenge.
exactly. Like like I mean it wasn't it was more difficult than I was in initially imagining because I thought, you know, people are keeping tabs on these things, but I mean obviously everybody's busy with their own you know jobs. So it's you can't expect that. So it was a it was a big eye opening moment for me where I that was the first time I was like seeing like what market education really means. because there
if the the you know the the community was very active like there were all these technologies coming at the at a very fast pace there were like Kubernetes there was like Mesosphere there was like all of these like orchestration systems so there was just a lot coming you know it was very much like today with with AI it wasn't it wasn't like quiet and just like Docker popped up but but it was just so many things happening. So and security usually is not top of mind for developers. So exactly
Especially the first stage of a transformation. Even I think I crossed this similar with AI too, when you know these systems were getting deployed and now they are like, AI, the the security of AI is a big deal. But first the first phase of any technology tr technology transformation, A security takes a backseat. As soon as it gets adopted, then people are like, What about security? What about RBAC? What about all these different things, right?
Exactly. So so it was very much like like now but for you know, years ago about Docker. and so that was difficult, you know, just explaining what Docker is and it could have security problems because everybody thought okay Docker is immutable, what kind of security problem could it have? But then turned out it was. I mean, it is immutable, but people found ways to escape the containers, get out the host, breach other containers, like like the you know.
That was the big deal though. That was the biggest deal because once you break out of a container, you could take control of the Docker host, then you have control over all the containers. That it is like you could have you could have ten thousand containers spun up, but then all you have to do is escape the container, get onto the Docker host, then you have complete control over the entire thing. I don't think people appreciated it. granted it was these exploits were difficult to do, but it was still a possibility.
That's it. Yeah, exactly.
Exactly, exactly. So I mean attackers always find ways. So people figured out how to quickly and easily escape the containers. Is it still there are there are vulnerabilities in this area? And you know and you know, like anything, like anything is really attackable, like they're not really super secure, the way like even even if you design it, people find ways. So it was that was you know basically what happened to Docker.
And so our solution, you know, but but the the the the thing I want to highlight is like the you know advanced attackers coming and like looking at these things take time, like you know, they want the adoption before they actually get into it and use these techniques. So we didn't have any of this, you know, published at the time. So it was very difficult to justify that you know containers aren't as safe as people think they are, but because no breach had happened.
but then after the breaches happened people realized but by the by then like we were already in talks with Tanamo as a partnership.
Is is that the reason is that the reason you're looking for a bigger partner to get to make container security much more mainstream? Because you know when you started it was a very tiny market.
And and you know maybe p scaling scaling a scaling a new category would be difficult to do it independently. Because that's the time when I first met you as well. I was doing something internal I was doing some internal projects at Tenable around container security and Docker and you know, the recommendation was, you know, for me to like do a due diligence on your startup and then we ended up acquiring your startup. I saw what you guys are built, it was pretty cool. how was the how was the transition to Tenable like?
What what did you come thinking in?
so we initially, like I said, we were trying to partner with Tenable because we thought you know this could be a really good partnership for us. we knew the founder of Tenable, Renault, and we were, you know, talking to him and he knew very clearly obviously is a very technical guy and is founder of Nessus. He knew Nessus couldn't really get into containers because of all these challenges around how containers work. So so there there there was that like initial
Yeah.
you know connection that that we had with with tenable and and you know it seemed like really the company was thinking in the right direction they wanted to basically bring containers to a much wider audience and by the time you know containers were very much adopted in a lot of development teams so we started a conversation it sounded like a really good opportunity. the partnership turned into an acquisition and I was like very excited to to join Tenimal.
I hadn't worked at the big company, you know, I was always worked in the startups up until that point. And at all in the Bay in the Bay Area. so this was my first interaction with an East Coast based company and and a much larger company. and
Is the culture different between west coast and east coast? Is the culture different?
very different. At least at the time, like like the Bay Area was, you know, very hardcore, you know, all about like the tech and building. but but when I came into Tannehill, I felt like the environment was much more slower paced. you know, I people people think I think the opposite about East Coast and West Coast, but when I got into Tenable, I felt like the culture was very relaxed and folks were very welcoming and you know, wanted to kind of work together. And you know,
basically that was when I transitioned into a manager. I never was a manager. I was a director at Tanovo. And that was a big change for me because I wasn't doing any people management necessarily in my previous jobs. And so so lots of new things for me to learn, lots of new situations I I I got into and but it was you know a lot of lessons that that I you know learned at Tanamo but
You know, they once we joined, like I thought, you know, we're gonna like get a huge team and then like a product manager like officially assigned to us. but I realized that that wasn't gonna happen initially. So I still was, you know, in the code and then also trying to hire, trying to build a team, trying to figure out like how do we align ourselves with ten of strategy. all of that was tough. And also you know, things that that just I had no idea about before going into Tenochtitl.
And you also you also joined Tenable at a very critical time in the sense that Tenable was transitioning from an on-prem model to a SaaS model. It was primarily before that time, Tenable was a very on prem company. We had products like Security Center and Nessus, they were predominantly on-prem. And the the discussions for Tenable Cloud or Tenable I.O. were just getting started.
But you were completely built on on the cloud, you were essentially a SaaS solution. So how was that transition to
Gotta do the time well thing, right?
Yeah, whatever that.
Yeah, so you you know when you joined Tenable, it was a very you joined Tenable at a very critical time and because Tenable was primarily an on prem solution. We had Nessus, Security Centre, many of our products were very on prem and you had the benefit of being born in the cloud. You were a completely SaaS solution and bringing a SaaS solution to a very on prem company. How was that transition like? Was it seamless, a lot of struggles? Because you know, the data model is completely different when you go from on prem
To cloud, how was that transition like?
It was tough. It was very tough. And like I've you know I prior to this I'd I'd I hadn't really worked on like on truly on prem software. Like this was my my first time, like, you know, cloud has been there for like, you know, since I think two thousand and eight. So I've been, you know, mostly everything like I done recently was on the cloud. So when I got into Tanwall it was it was like there's this like officially like real, you know
monolith that's on prem and then trying to bring it into the cloud. But then also my product was built with like all these cloud capabilities. We had, for example, like full RBAC, we had multi-tenancy, all of that. But after we joined we realized we have to remove all these features because it wouldn't work in in Tenable. Like even though they they really wanted these features, but it couldn't work with the architecture that we had at hand. So
There was a lot of like pain in in trying to figure out like how do you bring this monolith into the cloud. And the the team's decision initially was to basically replicate that same architecture into the cloud, which was basically a model. Yeah, exactly. Like a major lift and shift. And we I was like, okay, but but then the problem was like
Hmm. What is it called? Lift lift and shift? What is it called?
the the biggest problem is really the data model and the database because like on in the on-prem world you usually have a single database that can serve that one customer. But when you go to the multi-tenant sort of a situation in the cloud where you have you know a single database serving many customers, a lot of things break. So that was the big pain at Tenable, like trying to figure out how to make this single database sort of application work in the cloud.
It was very difficult and ultimately I think it didn't quite work. So we had to figure out what do we do in t in this situation. So and and that was basically one way some of my team was tasked to to help me.
Do you have any fun stories from your time at Hanamo? Any production deployments gone wild?
not production deployment. Like the funniest story I have, like which was a real, like not like funny now, but wasn't funny back then was basically we come in one morning and over the weekend and one day we come in and then we get paid by by our CTO at the time, saying basically there is a hundred K bill that that we got from AWS overnight. Like what happened? And
I was like, I've just nothing's changed. You know, we haven't changed the architecture. We haven't on more than anybody knew. so you know, everybody's like scrambling to figure out what happened. And turned out like one of the developers accidentally committed their cloud key to their Git repo. And some attackers picked it up and started mining crypto in the cloud. That was a he
Big deal back then, like everybody's looking to to mine crypto and find, you know, cloud keys where they could like leverage the cloud to do this via containers. So the crypto miner was in the container, they launched a lot of these containers and did crypto mining. So that was that was like a big shock, because like lots of different kinds of attacks and risks. This is like very common these days, but back then, this was very surprising. It was like
We had to see this kind of a thing happen this quickly and this easily. so that was that was a fun week that we had trying to figure out what happened, how to avoid it, how to make sure this is never gonna happen again.
You know, the funny thing is you started your you started your container security journey building malware engine and you finally end up building a container security solution and then the attackers find out a way to use your container security engine to deploy malware and do crypto mining.
That's so funny. That's so funny that that happened to you. If it have happened to somebody else, it would have not been that big of a deal. But like if imagine starting starting building a product product around malware engines and then your product gets used to actually deploy it for malware.
I know it's coming full circle. I don't know if you
Why? and then if I remember correctly then you
Exactly.
Finished your work, you transitioned your solution to tenable, scaled that solution at tenable. then you went to CrowdStrike. What happened there?
Yeah, so I got comfortable again in a teleport. My team was on the autopilot, you know, there were things, you know, settled, product was working, we structured the team in a pretty good shape and you know, effectively like the team was running itself. and then what happened was Crowd Strike you know at the time was
Like looking at the cloud, they wanted to expand their EDR solution and you know, offer new modules on top of Crowd of Strike platform. And I they came to me and said, like, you know, come join us, do a comp do a startup within Crowd of Strike, you know, come start this group. you get a blank check from us to to build and do whatever is needed to make this happen. And that was a really interesting challenge for me. I'd never
been in a situation where they you know I have a blank check effectively. I had my own recruiter, I had my own dedicated program manager and and a blank check to go hire and as many people as needed and built the product. It was too hard to to pass on that. So I was like sure that this sounds really interesting. So I joined Crowder Strike and then immediately COVID happens. So
And then for effectively two years, like we are working remotely and like all of everything that we've done would happen like completely remotely without ever meeting anybody.
That's the starting anything new at the start of COVID is the worst thing that can happen to a product into a product builder or an engineering leader because one of the most important things as you're doing these big build outs is you need to have your chemistry with your team. You need to have these engagements with your team. You have to have personal relations with your team. Otherwise it becomes a very transactional thing.
Right? Like if you don't know the team really well, it becomes very transactional. do this, this sprint we are doing this. No one really understands why we are doing what we are doing. There is very little shared understanding across the team because the team is not just you and the engineers, the team is also you, the engineers, the QA cycle, the PMs, the UX team. sometimes you have to bring in the exec team and so on. It's a very difficult thing to pull off.
I don't know how companies did it. I mean, I was doing I was also in the mid middle of building the products at that time and it was a very difficult thing to pull off. So, how was that transition for you?
So I mean it it's it's not easy, but it wasn't too bad at Crowd of Strike because Crowd of Strike's brand is so well known, which is like again another thing I never really experienced. they they're like probably the best and well known most well known security company. And the brand is like everywhere, the F1 races, like you know, people know Crowd of Strike. So this
Did you go to any of the death fund races, Sasan?
Yeah, did they get invited to those during COVID? But but yeah, so like I said, I had this you know really strong recruiting team and we got a lot of interest of really top-notch people wanting to join the company and joining us during COVID. and and then basically I was very lucky to get all a lot of very senior engineers joining my team.
And I feel like when you have senior people on the team, they can really own a big chunk of work and really deliver it end-to-end. And and like that was like one component of it. And then the secondly was the CrowdStrike software development lifecycle was very well established. And CrowdStrike was a remote company before COVID. So basically we had like this process of like following projects and making sure updates come in, making sure everybody's on track.
And so all of this you know combined together made it like very achievable, but but achievable at a very high quality. It wasn't that that we were scrambling to figure out what to do, like like a lot of instruction was already in place. And and then mostly you know, we we hired the folks, we managed to basically build the product, launch the first version within six months of me joining Crowd of Strike and
completely building a brand new module on top of the platform. This was the very first module. And
Like this was the first module outside of EDR. There were no other products on the platform.
Exactly. Exactly. I was the first, yeah. And we were and then within three years we won Forrester leader for cloud security and and you know basically you know a hundred million ARR within three years all because of this foundation that was provided and was available for us.
So you were very successful at CrowdStrike. You built you know, you were hired to do this cloud security solution, you built this our cloud security solution, you make it the number one solution in cloud security, you get it to like millions of dollars in ARR. And then you started to leave again. What happened there?
I got uncomfortable again. Yeah, so keep getting uncomfortable then it made things get comfortable and but then but then this time it was it wasn't just that, it was it was AI. AI basically showed up and in a whole of my career I've never seen something so foundational to happen in technology like like
Not just because like, you know, you could talk to a chat bot, but because the technology is so different foundationally that completely changes everything. And when I basically saw this at Dora Crowdestrike, I basically had you know very early insights from NVIDIA in terms of what was coming. when we were partners with NVIDIA at Crowdestrike.
I was like, I have to give this a shot because this is a generational shift. I really want to learn it. I want to figure out how to use it. there were a lot of blog posts coming out at the after Chat GPT launched that basically what how can we use it in security? And nobody had an answer. Like what do we do with Chat GPT in the world of security? So people were just thinking, you know, okay, we use it to summarize the stuff and that was that was it. so nobody really knew how to use it.
So I was like, I have to give this a shot. I just can't focus if I'm not doing this. So I I left and started a long experimentation phase to try to see how we can leverage AI to really do things differently. Because when you get into AI, like and you're actually building with it, one thing that you'll you realize is like everything that I had learned over 20.
30 years of like coding and building this stuff, effectively no longer relevant in terms of like all these skills. for example, you like writing like using AI to write code, for example, like all of the training that the programming programmer has gone through is basically like writing clean code, writing good code, like structuring the code. there was a lot about the code itself.
Mm small. How so? How so?
that that really had nothing to do with the ultimate product like like how do you do the coding but now that ai is doing that like as a as an as an engineer what do you really think about what do you really do and it's it's a mind shift that that you as a you know person building products with ai have to go through to fully understand the power of it and and this was basically this became kind of clear to me during the experimentation phase that I had with AI.
to really understand how powerful it is and if I change my own mindset in terms of how I look at problems, what could be the ultimate outcome that we can get out of these systems?
Were you did you think did you think it is not feasible for you to do this while you're working at CrowdStrike so you have to take a break or something on those lines and then do it? Because you know, you know, with you are at a senior leadership position within CrowdStrike. You c it cannot be like doing side projects and doing your work. so I guess my question is, is that the reason you took a break and then experiment with AI?
partly, yeah. I mean, obviously no, I was I wasn't an IC. I started as an effectively as an IC but but wasn't an IC anymore. so didn't really have the the time. But but besides that, like one thing that came very was very clear to me is that AI requires a completely new look at how you do things. Like like you could obviously add AI to anything these days, but but AI effectively being something that
you know you know you truly to truly unlock the value of AI and capabilities of AI, you really need to to start from scratch. And this this was the thing, the hunch that I had, which I sort of proved to myself during the experimentation phase that I
Did you have any did you have any early success in your experimentation or
Yeah, I mean like I like there were a lot of like failures, you know, just like a ton of failures, but so there was like you know, there was rag, there was graph rack, vector search, all these like things that people were talking about. And then on top of that, there's all this hype as well, like from humans that I feel like hallucinate worse than AI, to be to be honest with you. Like they they just
So you're saying so you're saying humans hallucinate worse than AI? Is that what you're saying?
Yes. Yes. Because they just like make these outlandish claims and they're like, you know, you know, we're gonna may build AI factories and like, you know, we're gonna do all these crazy things and magic beads all around and it's just like BS in in my view. Like it's like really not realistic and the hype has I feel like it's done more damage to what AI could do than than really if people actually look at AI very closely to see what it could do for them.
Is that I mean I I I I acknowledge what you say. I mean there one of the ch one of the challenges with AI is obviously in the earlier days was it was it was hallucinating and I saw this firsthand as well where there were all these outlandish claims that are getting made on you know how graph rag or rag is like the solution of the future and it's a solved problem and it's all
Up and to the right from here, everything everything looks great. And then when I was doing my experimentation, I realized like, you know, the results are not accurate, the systems are way too slow. You had no good sense of which models are good at what doing one. You know, there are some models that would do really good summarization, but then the reasoning was poor. obviously they got better over over a period of time. is your is your sense that
Doing AI really well is essentially like a hardcore engineering problem rather than just using the models and just giving it some context and and then going from there.
yeah, I think so. Like like if you really think about AI, you know, all AI has a lot of problems, right? Like it's a it's a very raw technology, right? Like, you know, if you get a database, you know, you know, you could do a lot with the database, but but on its own if you don't use it effectively, it's not gonna work for you, right? Like if you don't get the data modeling right, if you don't if you don't get the you know the the the schemas right, it's just not gonna work.
So I feel like AI is also very similar in a sense that it's a raw powerful technology, but you have to bring in engineering best practices to it to effectively get the best result out of it. Like for example, how you structure the data, how you you structure your APIs, how you like connect the the various different pieces of data together where AI could
the context. You bring the context in as you're going through the data is also very critical.
Exactly. Exactly. Exactly. So all of that really comes from like engineering best practices and system design work, which I think you know, as like as as a product in person and as a like engineers, like you know, granted we are not writing as much code anymore, but but but but these the skills that we learn writing code and figuring out how code really works effectively and how data really works with the code, all of these are
hundred times more important now in the world of AI than it was before. So so I feel like you know it's it's truly system design and engineering problem to effectively be able to extract the most value out of AI.
So when you say when you say system design, is this also about building the right harness around the data, the tools that you use, building the right tools? Because if you look at some of the latest tools that are out latest products that are out there, they're you still using the same data, but they're able to effectively reason on their data. The way I think about this is, you know, we have gone from a dumb file cabinet to a file cabinet that can reason with the data. And I think
One of the important things to do there is to build the right harness so that you can extract the right value from the data that you already have. Is that what you mean when you talk about system design?
yes sort of. Like like I feel like, you know, basically building harness is effectively sort of the the architecture that you have for for the problem that you're trying to solve. And the an analogy that I like to sort of use is like, you know, if you think of an accountant, like what an accountant does, the job is still exist, accountants are still there, but their tooling that they use in nineteen fifties is very different from tooling that they have now.
So they they use like Excel to do things, and then now they've connected Excel to Cloud and they're still, you know, achieving their outcome. So I think in the world of like AI, you have to take a few steps back, look at the entire problem that you're looking at. Like, like what is the ultimate outcome that you're trying to accomplish and design for that and design it with the assumption that a human is not gonna be in the loop, because that's when all of these
interesting insights starts sh you know emerging from this problem where you know for example in the accounted example like if the accounted like it is not really personally using Excel and is connected to to Cloud for example and the cloud is like effectively running it the sort of tooling that you need for that is very different than the type of tooling you would need for a human to to to kind of get get into it. So basically
in in this world I would say like like the the hardest is effectively thinking through all these problems ahead of time and making sure you have placeholders for all these tools as you develop the product.
Okay. So Sonia's been building cybersecurity products for twenty years. now you're building cybersecurity products with the help of AI. we've obviously seen all the hype with Mythos. what in your sense, what is the future of cyber defense with AI?
so I think I think you have to you know think about this you know f way more broadly, right? Like like I feel like there are really two categories to the problem. there is, you know, one is obviously defense in terms of like, you know, like runtime, like what's happening right now in the in the systems and the environment. And then there there is defense in terms of like you know app sick.
code, you know, current posture of like your your environment. So
You so whole sorry to interrupt, but do you think this is like the security of AI and AI for security? Like those are the two broad categories to think about this in terms of using AI for cyber defense? Like one is like, you know, the problem that you had with the container security. like, you know, the containers, you build this technology, containers you realize are not safe, then there is the security of the containers. And then the the the the other aspect is the container say security itself, right? So
do you think the threat from the me methos like models is real?
I think I think the threats are definitely real. you know, in in a sense like Mythos is you know, when we started a company we didn't plan for like Mythos, but we had clearly saw this go was going to happen. Like models will get better and you know the cost of and the skill required to pro compromise systems over time will go down. Like that's a given with with the advancements that
Is this like are you are you saying that this would be, you know, this would be true for like zero days or is this like the known vulnerable days as well?
I think both. so zero days, like I I think there's been a lot of hype around zero days, like what Mythos could do to find zero days, and you know create exploits. But but you gotta look at it from attackers' perspective. Attackers are cost sensitive, they don't wanna spend too much money, and they don't necessarily go after the most complicated attacks. They they they look at the most the easiest attacks. So knowing vulnerabilities is the easiest.
This yeah, this is the biggest misnor this is the biggest misconception in in cybersecurity is that the attackers are looking for zero days to break in. I mean there are hundreds of thousands of vulnerabilities that are out there, they just want to get a get in. And the the cheapest way to get in. So and most of the break ins happen with vulnerabilities that have been known for years.
If not months and I've still s I have seen examples of log for shells still getting exploited. I've seen open SSH and regression vulnerabilities still getting exploited. These are exploited these are exposed to the internet. If you do a showdance search, you'll still find all these vulnerable systems all across the world. The problem is the quality of exploits may be not good. Maybe that will get better with A AI as well.
Exactly.
Exactly.
Exactly. No, I think I think all of that is gonna true and is is still going to to happen. Like if you go look at the existing vulnerabilities out there that nobody truly had time to write the exploits for, you would look at AI to see if AI could write the exploit for you quickly at low cost, which it can definitely do, based on you know some of my own research. it is a very achievable thing. So folks will do that, but then besides this,
One of the other things that AI is giving attackers is the ability to automate their reasoning, automate their hunting. So previously, like, you know, attacker would basically, okay, they have the exploits now, and now I need to go look and find a way in, which takes time, right? Like you want to run the scans, you know, see what ports are open, what IPs to go target, you know, where where to look. But now AI effectively automates all of that.
So they don't really need to reason on any anything. Like they just write their agent, let the agent loose, the agent find a way in to some organization because of some outdated server or some server that's not being monitored or some dev environment who people are not paying attention to. And they find the way in. And and this is like this is what I think is going to happen more and more frequently and more and more at the speeds we've never seen before. So
Speed, I think, is really the key defense that if you are in cyber and you're tasked with increasing the defenses of whatever organization is you have to think about the speed the attacker is moving at, not some Gardner defined category and the products you have in those categories. Like that's just not gonna work. It is all about the speed and emulating what the attacker would do.
Do you think the cost of defense will go up as the cost of AI native offense goes down? What what you're essentially saying is that the attackers have all these models to create exploits, launch exploits, to either d do the reconnaissance, do the reasoning, find pathways to get into systems for the fraction of a cost. If that is the case, what do the defenders do?
Sasan (46:20.786) I I mean it it's really like it it's if you think about it, like the the the problem that we have in security at the moment is like we have all of these like sort of Gartner defined categories where there are method breed products for each one of them where you go buy a product for cloud security or you go buy it for identity or you know you buy an endpoint detection solution or a vulnerability management solution. So which is which is all good. Like, you know, these products are good, they do the job.
But but one thing that I feel like with in the world of AI is different is like AI is forcing us to rethink how we operate. the attackers leveraging AI, they can automate and reason across many signals, many different domains. Like they could see a cloud security problem here, they see a vulnerability here, they see a mis domain misconfiguration over there, they see some random identity that could be used.
And they connect the dots across all of these and then they perform their their their attack. So as defenders, I feel like at the moment defenders are at a disadvantage, and at the moment the cost of defense is far higher than cost of offense. but I think as we kind of go through what's coming with with when attackers are enabled they are using AI, we need to basically go after like solutions where
we could operate like the attack here so we could see things at the same speed, remediated at the same speed, and have the protections in place. This doesn't mean you're 100% protected by the by the way, like because they are continuously looking at open source software, trying to find zero days. But then as defenders you go think about okay, I now operate with that assumption that there are gonna be more zero days than I've ever seen before in all of these open source applications that are out there.
So what do I do? I look at like network is you know segmentation, I try to reduce the blast radius, I just work with that assumption that something may get breached here with a zero day. So all of these things are reasoning and thinking that defenders need to do, and given the volume of the infrastructure and findings and all of the things they currently deal with, they really need to leverage automation and AI to prepare themselves for for what attackers are currently doing.
You know, what you are seeing is analogous to what we are seeing in the traditional war as well.
the the the structure of typical warfare has now changed with things like drones. You could have like a five hundred dollar drone that can take out like a hundred million dollar tank. Right? So I feel like the same analogy is playing out here in in terms of
In terms of cyber defense. I think organizations have to think differently, in terms of how to build defensive systems. maybe maybe the maybe the complete architecture of defense, cyber defense changes as you know the AI and more AI native tools for offense takes takes hold. Sasan, is this the kind of product that you're building?
Yeah, sort of I get it. Yeah, pretty much. Yeah. This is the the kind of product we we are rebuilding and you know it's it's been, you know, pretty interesting kind of going through all of this, but it's it's a fast moving p space and lots of changes are happening, but when we are trying to get in a good position to be able to help the defenders.
When are you when are you going to tell me about it?
I thought you know about it.
So San this has been this has been a fun interview.
So nice. Thank you.
Thank you. Yeah, thanks for having me.