Section Insights
Welcome to Black Hat USA
What is the significance of the Black Hat conference?
The Black Hat conference serves as a platform for cybersecurity professionals to engage deeply with research, share ideas, and challenge each other on pressing security issues.
- Attendees are encouraged to discover and engage beyond just attending sessions.
- Networking and conversations are key components of the conference experience.
- The community thrives on challenging discussions and collaboration.
The Role of Community in Cybersecurity
How does community support impact cybersecurity professionals during times of change?
In times of rapid change and uncertainty, cybersecurity professionals rely on their community for support and direction, emphasizing the importance of in-person connections.
- Communities provide resilience during crises, whether natural or man-made.
- In-person gatherings are crucial for meaningful exchanges of information.
- Attendance at conferences tends to increase during stressful times, highlighting the need for community.
Security Strategies in a Changing Landscape
What are the implications of exploiting known vulnerabilities?
Many security strategies are based on the assumption that vulnerabilities are scarce and can be quickly patched, but this approach carries significant risks if exploits become more commoditized.
- Ignoring secure development practices can lead to increased vulnerability exploitation.
- Detection and response strategies may become less effective as dwell times increase.
- The landscape of cybersecurity is evolving, necessitating a reevaluation of existing strategies.
The Future of Autonomous Cyber Operations
How are autonomous operations changing the landscape of cyber attacks?
Autonomous operations are making cyber attacks easier and more efficient, challenging the assumption that such operations are difficult for attackers.
- AI-assisted operations can generate significant amounts of code quickly, enhancing attack capabilities.
- The trajectory of autonomous operations indicates they will become a standard part of cyber warfare.
- Assumptions about the scarcity of effective attack tools are increasingly outdated.
The Role of Formal Methods in Cybersecurity
Can AI enhance the scalability of formal methods in cybersecurity?
AI has the potential to make formal methods more scalable, which could improve the correctness and reliability of software in terms of security and performance.
- Formal methods are gaining attention as a critical component of modern AI applications.
- Specifying what must never happen in code is essential for effective formal verification.
- Major tech companies are investing in formal methods to enhance their security frameworks.
Transcript
0:29 A new warning. tonight about the scope of a massive cyber attack >> already believed to be the largest >> America under virtual invasion.
1:10 Please welcome to the Black Hat main stage the president of Blackhat, Susie Pallet. >> >> Good morning. By show of hands, who got less than 5 hours sleep last night? Yep, that's Black Cat. You stayed up late because you were in a conversation that mattered because someone showed you something that you'd never seen before. because you finally met the researcher whose work you've been following for years or because you were in your room debugging that idea that wouldn't let you go.
1:55 That's what makes this community different. Welcome to day two of Black Hat USA. If yesterday gave you a taste of what this week is about, today we go deeper into the research, the hard problems, and the conversations that will shape how we think about security long after we leave Las Vegas. Here's my challenge to you today. Don't just attend, discover. Black Hat is about more than what happens on stage. It's about what happens when you step into the convergence and meet someone new. When you sit down at Arsenal and talk to the person who built the tool you didn't know you needed. When you ask questions in a briefing that everyone else was thinking but didn't say out loud. Those moments, that's where the real work happens.
2:44 Today we have a full slate of programming on the main stage, keynote presentations and highlevel conversations exploring some of the most pressing challenges facing our industry. Take advantage of it. Push back. Ask hard questions. This community gets stronger when we're willing to challenge each other. And tonight, don't miss the world premiere of Midnight in the War Room, a ground groundbreaking documentary that takes you inside the realities of modern cyber conflict and the impossible decisions that shape it.
3:22 It's going to be one of the most talked about moments and tells your story. I hope you'll join us. But with before we dive into this morning's keynote, I want to bring someone onto the stage who needs no introduction in this room, but deserves one anyway. Over 25 years ago, this man saw something that didn't exist and decided to build it. A place where security researchers could share their work without filters, without corporate spin, and without apology. A place where breaking things wasn't just accepted, it was expected. where the focus was always on the research, the truth, and pushing the boundaries of what we understood about security.
4:02 That vision became Black Hat. And that spirit, that relentless commitment to real research and real impact is why we're all here today. He has worn many hats over the years, hacker, founder, CISO, adviser to governments and organizations worldwide. But at his core, he's always been a builder. someone who believes that security gets better when we're willing to ask the hard and tough questions, challenge the status quo, and never settle for good enough. Please join me in welcoming the founder of Black Hat and president of Defcon, Jeff Moss.
4:42 Thank you. Yeah, you didn't hear it, but earlier they were playing jazz before you came into the room and you're like, "No, no, we need we need the beats." Okay, so welcome. This is the 29th Black Hat. We're on the buildup to next year, which will be the big 30th celebration. And for those of you who haven't been to a black hat before, let's see a show of hands. Who's this? who's new here for keynote. Okay, fantastic. So, let me just give you a quick run of the show.
5:21 I'm going to give you some some opening remarks, then we're going to kick it off to the keynote. normally I talk about how big the community is. And every year we do something where if you don't have the financial capability to attend Black Hat because it can be expensive for people just entering the field, we have an alternative path to try to bring in new talent and that's our scholarship program. You write a a white paper, we review it. If we like it, you get admission for free. And this year 131 people attend Black Hat through scholarship. So, if you're here in the room and you got here by a scholarship, please raise your hand. Let's give them a round of applause.
6:08 Right here. Right on. it's some of our past keynotes in the last two years actually started as scholarship attendees. So, it is absolutely possible to go from a noob to a badass. and we're a pretty pretty welcoming community. we also have people attending from over 103 countries. So if you're here not from America, Canada or Mexico, raise your hand.
6:41 Right on. Okay. So if you see them, right? Let's get a different perspective. Let's see how security works outside of our bubble. Now Black Hat this year, you might notice a couple of themes. There's four themes. And as you would expect, AI and autonomous threats, cyber conflict and live operations, sort of information operations, how do you build engineering resilience in the face of this in identity, trust, and control? Sort of the four organizing principles around a lot of the talks this year. And if you notice, probably three of those are pretty political. And this goes back to some of the things we've been saying over the past decade is that infosc and security is political. Technology is political and that makes us all uncomfortable to say that word out loud.
7:39 But we have to sort of embrace it. If we don't embrace it, politics will happen to us. Just think about it right now globally with a conflict in Europe. Russia's all over giant hyperscalers in multi-tenant environments. Why? Because the hyperscalers inherit the risk models of their customers. And if your customer is Ukraine, guess what? Your opponent is Russia. Like you just want to sell Rackspace, but now you're in the middle of power conflict. Same thing with China. Great power conflict going on right now.
8:17 that's most visible around AI and open weights debates, but remember when it was like high performance GPU chips trans shipping through countries in in Southeast Asia like this stuff is political and we need to have a view and an awareness around it if we want to be effective in our jobs locally or state right now. What's in the news? Iran. Iran hacking rural water districts in the middle of the country. Why?
8:50 A lot of military bases are on rural water supplies. Take out the water, you take out the military base, right? Who's going to help defend? They don't have the budget. So, there's a lot of defenders donating their time from our communities to try to make things better. So, and then there's another kind of a weird thing. I don't say it's political, but like who here has noticed this weird humble brag from some of the Frontier models? Every time a model breaks out and causes some chaos, it's like this he humble bragging marketing material.
9:29 that's being noticed on Capitol Hill, too. There's a political impact to that kind of of marketing. And finally, we're in an election year, so expect more synthetic personalities, more influence operations. And where is this all leading? I think one of the things that we can lose sight of in this whole autonomous agent-driven environment is the people, us, I mean, we are the cornerstone on which all of this is built. And there's rapid change right now. And in times of rapid change, in times of uncertainty, some of the coping mechanisms are you turn to your community. The most resilient communities in any kind of a natural disaster or man-made disaster are your local communities. That's where people find support and they find direction.
10:27 So here you are. You're in a giant room of peers. You're in a giant community. Yes, things are moving very quickly. Things are changing. Markets are being disrupted. But we're all in this together and we will need to lean on each other in our community. And we do this by gathering in person because you can't inject a fake personality here. And the weird things are when things are extra stressful, attendance at conferences, not just security conferences, attendance at conferences go up. And I think that's because people, we innately know we need to see like what the going on. Like we need to talk to people. I need to talk to my buddy and get the download on what's happening. And that might not be happening on some Discord server, right?
11:15 And so I want you to make sure like saying what Susie brought up. Yes, see the technical talks, but take time to build those connections that are going to support you throughout the year. A few years ago, I mentioned on stage that AI is essentially a prediction engine. And if I was a business leader, I try to make all of my problems prediction problems because if my problems can be predicted, AI is perfect for me. And the prediction engine will get faster and cheaper. My problems can be solved faster, more efficiently.
11:54 Great. Holy moly. in the last couple of years. It is a total sea change of what is possible now. And and so thinking about our keynotes, we have two keynotes today and tomorrow. Today I wanted to have a keynote that focused more around defense, how are hyperscalers, how are we addressing the risks and opportunities of AI? And tomorrow we're looking more at attacks. what is it doing to the academic the reversing the exploit developer? How is it helping or hurting them? And finally, one thought I want to leave you with is I'm I'm generally a pretty skeptical person. It's turned out really well for my career in security.
12:41 But for AI, I think in listening to developers and programmers talk, I'm I'm talking Unix greybeards talking about you know vax VMS to today the trend line is every time there's an improvement in say IDE or the invention of IDE and development languages, object-oriented programming, so on and so forth. Abstraction, abstraction, abstraction. It hasn't been the death of programming jobs. It hasn't been the death of AI, I mean of it. What it's led to is allowing companies and people to think bigger. We can imagine larger things, more complicated systems. We can create newer opportunities. And so I think what's going to happen is yes, there'll be a lot of disruption, but at the end of the day, there'll be more jobs, not less. Because all these companies around the world are going to be wanting to build bigger and it's going to be built on the backs of what we do, providing the reassurance and the resiliency for them to take bigger risks. So with that, I'm really interested and excited to see what David Wesson has to say. Dave now leads the Aenic security team at Microsoft where he builds the AI models.
14:06 He builds the agents and the evaluation systems for defense at scale. And so please put your hands together and let's welcome Dave Wesson. Thanks man. I can't dance as well as Jeff Moss, but I'm trying. So really hyped to be here. When I got asked to do a keynote, I was really excited. I have a lot of pent up. I saw on all the socials a lot of AI apocalypse and doomsday stuff. And I might be the only optimistic person in this entire room right now, maybe at this whole conference. And so I said, I'm going to make this talk a 30 minute higheffort social post just live. But you can't block or unfollow me because you're a captive audience. So, I'm going to talk to you about what I think happens when attacks get less rare, less scarce, and what we can do to defend in that environment. So, I want to give you kind of my bias and my vantage point. I spent the last 20 years in the trenches of security. I'm talking Wukry, Stuckset, I lived it all. I have all the trauma. So I built operating system security for Windows, Linux, you name it in Azure, all those other places, EDRs, and I've led vulnerabilities in red teams. And the last nine months, I've switched over to the AI world. I've switched to the dark side. I've been working on vulnerability discovery harnesses, training frontier models for cyber capabilities, and also building defense. And so I thought I could offer some of the things I've learned from these two vantage points, kind of combining the nexus of where I think the future is going.
15:48 So security has this underlying assumption. It's unsaid and that is that we have these security boundaries network process identity encryption and that is extremely hard and thus attacks that undermine them are scarce. What happens if that changes? Cyber security the entire house that we live in the cyber house the roof the the the foundational floor is based on these being rare. So we use these boundaries to isolate our networks to separate trust domains in places like the cloud to create authentication encryption data protection policies and ultimately to contain failures with things like hypervisors or process sandboxes. So every control or policy in your enterprise in your company in your business on your phone relies on these not being easy to undermine.
16:43 And you could see this in the economic models around things like bug bounties. So for example, we have no easy way or no cheap prices for undermining things like processes etc. Our prices scale with the importance of the boundary. So if you want to have a hypervisor bypass, that's going to be 20 times as much on the open market as a boundary crossing for something like a process. And so this economic model has been priced in for a long time and is reflective of what it's like on the ground. And even further, we've made the assumption that if a vulnerability is a potential risk, actualized risk, which is exploitation and implemented attack, is even more costly because then you price in expertise and scarcity for things like mitigation bypasses or all the other techniques. And again, that's reflected in the cost pricing of exploits versus vulnerabilities.
17:38 And as a result, for the tens of thousands of CVEes that you hear about every day on LinkedIn or your news of choice undermining existence, we actually usually only end up with 90 or so in the wild exploits every year as tracked by the Google folks. So that's it's really exceptional at this point for a boundary to be undermined. And so the entire premise of cyber is based on this scarcity and supply economics around this.
18:09 Now as a result this has really held true for a long time. Most the breaches today occur far above the boundaries. Right? Verizon's breach report tells us most of the attacks actually occur at the credential theft level which is significantly cheaper traditionally than undermining a boundary. It's also happening through things like fishing and social engineering. And when a vulnerability is exploited, the vast majority of the time that's a vulnerability that's exploiting or being a vulnerability being exploited that's known, which means there was time and to to to implement that. So all of our economics, all of our strategy is based on this today.
18:53 Now we can infer a couple dominant security strategies that are wholly reliant on this principle of scarcity. The first one is you could ignore the SDLC or at least have less priority on it. And what I mean is static analysis, safer languages, principle of lease privilege, strong identity around our the software we build because we can just patch fast when something's known because vulnerabilities are not often exploited. Now the pressure test against that is what happens if exploits just become another commodity. We lived through this in the 90s. trivial to exploit that just patch everything fast strategy has carries significant risk.
19:39 The second inferred dominant strategy is, hey, we can do less around prevention, less around software. We'll just detect and respond fast, right? This is what all the vendors pitch you. We're going to sprinkle some AI here and very quickly we'll just detect and respond. The truth is the dwell time is getting longer and it's getting harder to detect. And the pressure here is most detection is based on invariants that don't change. The idea is, hey, attackers are software developers. They can't afford to change their software, their implants, their C2, their lateral movement management tools every OP so we can continue to detect them. But in a world where that becomes cheaper, supply economic supply.
20:23 So what do we do when this scarcity principle no longer has our back? What does it look like to defend in that environment? And the bigger question is, are we actually there yet? So the assumption that vulnerabilities are scarce, right? This is a potential risk is being undermined as we speak. What you're looking at here is a curve from this year around the pressure that AI is putting on vendors. This is a Microsoft number, but as you see, this trend seems to be holding true for Google, Apple, and I bet just about every other popular software vendor.
20:58 MSRC is doubling the number of vulnerabilities that they are processing and patching every less every six weeks. That is an incredible number. We're nine times the vulnerability volume that we were in March. And again, we don't know if this curve is going to hold true, but boy, if it changes, we're in deep trouble in the places where we presume vulnerabilities are scarce. And again, I would urge you to think about all the different software vendors out there.
21:30 This is representative of the MSRC cases that combine open- source that Microsoft uses and our first party software like Windows and Office. But this is a significant jump and it's something we'll have to continue to look at. So the next thing is, is this actually correlated to AI? You might ask yourself, or is this just people are getting better at finding bugs? Our internal data says yes, it's heavily correlated. We released a new internal vulnerability harness and we've turned it on to Windows on April 1st. And since then we found 66% of the critical and important issues since April 1st than we did of all of last year.
22:12 So this is not just a correlation. This is the fact. It is AI that is driving this. And these are real vulnerabilities. a good example when it comes to boundaries. In this data set, I saw seven remote TCP IP. Vulnerabilities that cross both the kernel and the remote boundary, which are both absolutely critical for Azure, you name it, and every other Windows system on the planet. So, these are serious vulnerabilities, the kind that I used to take a year to bespoke craft, they're being spit out at industrial speed. And it's again, it's not Windows.
22:47 you look at Linux, you look at any other operating system out there, I think you'll see a pretty strong correlation. So the next question is if potential risk is is is driving up dramatically is actualized risk are exploits. And here's a very unique stat I'm sharing. We again we have an internal vulnerability harness called Mdash and it's very good at finding vulnerabilities in this gentic system. It's found roughly 200 Linux kernel vulnerabilities in our internal a Azure Linux distribution that we're working with the community to fix.
23:24 We added a new module to this to help us triage. Guess what it does? It turns a static analysis result into a P. That's worked much better than we ever thought. Of the 200 vols, we can automatically generate 182 crash level PC's. Many of them are fully working exploits. I'm talking root exploits automatically spit out from a vulnerability. And the average cost from a token perspective, $3.61, 21 minutes on average. And again, most of the world runs Linux in some capacity or another. And when you run Linux, you're relying on the kernel boundary to save you. This is under attack. And it's not just internal. If you go look at Exploit Gym, what you'll see is the big frontier models making incredible strides. In fact, I looked at Exploit Gym this morning, and this number for Mythos had already been doubled by OpenAI roughly. So, of 898 real world vulnerabilities, and these aren't just Linux kernel, which are arguably easier to exploit in some ways. These include things like browser vulnerabilities, etc.
24:34 They can generate 157 exploits out of roughly 900. What's really holding back at this point are non-determin nondeterministic mitigations, control flow, as randomization, ASLR, etc. Those things are non-deterministic. They make things harder. They will not guarantee these can't be exploited. So, I would not bet against this curve. I I fully believe that if we look at this and we draw a curve here, by the end of the year, we'll be looking at automatic exploit generation being pretty commonplace and pretty commodity.
25:12 But these are advanced frontier, pick your term, dour cyber models. We're restricting them, right? Isn't restrictive access going to maintain scarcity? Isn't that going to save us? Nope, it's not. And I'll tell you why. If you go and look at CyberJ, which is at least a vulnerability discovery benchmark, the top entrance are not actually frontier models. They're harnesses. Harnesses make use of frontier models, but they also inject context in a few other places. They can inject cyber expertise and through tooling. It can be encoded into the harness. There's nothing that says technically that the only place that cyber knowledge can live in an agent is actually in the model.
26:01 And a lot of places you don't want to put that in the model. Now that's counter to a lot of business models and other things, but the reality is you can inject that as a markdown file and it's actually more optimal in many cases. So the idea that we're going to sort of restrict our policy our way out of this I think is unrealistic and in many ways we need to prepare for that not being the case and I think these harnesses on Cyber Gym from a variety of vendors are really strong evidence of that for now.
26:34 There's also another assumption that I see played out all the time which is hey we can just detect right even if all these exploits start coming we'll just detect our way out of this many you're employed in security operations centers at vendors etc and the idea here is like it's super expensive to code a framework or an implant so people just keep using packers and obuscation tools on the same stuff and they keep using the same TTP so we'll work against that and that's going to give us durability and detection Again, we're making the assumption here that evasion of detection is somehow a scarce property because it has been.
27:13 If we look at this model called the pyramid of pain, which is an interesting model around essentially the invariance in detection, the idea is that TTPs, tools, and artifacts are the most expensive to change. You can change hash values, IPs, domains, no problem. But TTPs stand durable. Your tools are more expensive to change and certainly your artifacts. But now instead of having to retrain the operator, which would have been expensive for cyber operations, we can just use autonomous operations.
27:45 Instead of obfiscating, we can create a bespoke set of tools or frameworks per target. So we are challenged just like exploits and vulnerabilities on this assumption that somehow this is going to be hard for attackers. It's not going to be scarce. And again, we have real world evidence of this. If you look at the canonical sort of case study around this was anthropic reporting back in November of last year, a cyber operator conducting most of these operations against, you know, top tier targets 80 to 90%, essentially using cloud code with sub aents and getting ostensibly good results based on anthropics observations at 80 or 90%. Then we saw in May of this year, Drago reported a water utility being targeted by an AI assisted group who is building their framework during the op. So they're able to see the code keep getting regenerated ostensibly. This is Python. So you can see the additions there were all the hallmarks of this being generated in AI.
28:47 And this single op the attacker generated 17,000 lines of C2 implant etc code just for this operation. That's essentially proof that evasion and the assumption that artifacts are going to stay the same just isn't there. And if we extrapolate this a little bit more, if we calculate the trajectory, we can see from groups like the UK is SI, which does a sort of testing of frontier models against their ability to conduct 32step autonomous breach operations.
29:20 We're getting to 9.8 steps out of that 32 at 10 million tokens. And that's up 59% just this year alone. So our trajectory is autonomous operations will just be part of the course. And again I would not make any assumptions about any models doing this. We can inject this at any place. So scarcity will not come from restriction. So I told you at the beginning I'm probably the only optimist in the room. How can I be optimistic after all that?
29:49 Well, a couple reasons. First is this is not magic. This is productivity. The attackers are much more agile. They go asymmetric to defenders. They've done that since time immemoriam. And so they move first on AI because you have policies, restrictions, auditing, compliance, and token costs that slow you down. But defenders have the exact same advantage. But let me tell you where we don't want to go. We don't want to go van for patch. We don't want to go exploit for detection, evasion for detection. Hand-to-hand combat with attackers will cause us to lose in defense.
30:26 We will be asymmetric. We don't want to do that. What we want to do is retrain the physics here. We want to figure out where we can use this production advantage to actually turn the tables. And I think we can do this. We can use the same productivity advantage but invest in durability. We can shift left and make more secure software that'll limit vulnerabilities. We can move away from handtohand detection. Detection is still great. It's just it's necessary but not sufficient. We can move to more prevention mechanisms and we can use secure by construction and even formal methods to get deterministic safety. If we could do that along a realistic timeline, then we can turn the tables and drive this problem towards attackers. And I really believe that.
31:14 And let me show you why. First is secure by design and construction are really coming into their own. There are more tools than ever to use safe system level languages. Formal verification is almost tailorade for AI. It gives AI and Oracle to write software that is provably safe against the set of properties that you need. Perfect for boundaries. And prevention is getting much simpler because using tool sets like infrastructure as code, you can actually reason about the safety of your infrastructure and do things to fix it at less cost with less people.
31:49 All of these things would drive based on the data durable change in attacker economics and turn the tables. So let's talk about secure by construction. You've all heard this, but I want to put this in front of your face as you see that vulnerability curve. About 70% of vulnerabilities that are patched today, at least by the major vendors, are memory safety issues. Safer languages like Rust and Golane eliminate those. And we have strong evidence of this.
32:17 Google has done an amazing job of proving this in Android. In 2019, 76% of the vulnerabilities they patch in this operating system used by billions of people from cars to phones and everything in between, 76% were me safety issues. In 2025, it's less than 20%. And that's because they wrote five million lines of Rust code, which based on their own analysis has a thousand times less defects. And they haven't shipped a single memory safety issue in that code. That's amazing. And Azure has done something similar in the containment boundary. rewrote the hypervisor in open source in Rust and it's now scaling past 1.5 million virtual machines without an incident. So if the world's most popular mobile operating system and a very popular hypervisor can do this, why isn't everyone doing it? Well, traditionally it's expensive. You need experts who know how to do this. You need to learn new languages. All sorts of reasons. You need to convert old code bases. But AI is changing this, right? There's a project from Microsoft research called Rust Assistant. It showed that it could take 74% of the failures, compilation failures in Rust code and fix them automatically without user intervention, passing tests improving. Similarly, for existing C code bases in a variant of C called safe C or check C rather, that's pretty similar to some of the things that you'll see from clang and Apple. They were able to infer memory safety contracts in this codebase and they generated 86% of those code contracts that'll check for what are called spatial safety vulnerabilities or buffer overflows. This is productivity driving memory safety driven from AI. It doesn't look the same as generating automatic vulnerabilities, but it is absolutely critical.
34:15 The real frontier though is doing this automatically and there's great work happening here. Sila is a really good example, great paper from sort of Google, Microsoft on taking SIMP, which is a library in Windows that does most of the core encryption, TLS, you name it, and converting it automatically to safe Rust. They were able to take a Shaw 3 method, which is a few thousand lines of code, convert it automatically to Rust, and then run tests. All the tests pass and the performance was within 1%.
34:44 Rustler is a more sophisticated project. I can do this with dependency graphs context and what it does is generate Rust and then work through those error checking until you have valid code that passed tests. And it's not just Microsoft or Google doing this. DARPA, who you could argue really showed us first where the agentic vulnerability discovery was happening, actually has a project called tractor where they're sponsoring and giving out data sets for automatic conversion. If we can land this as a community, we can really drive security forward. But with memory safe, are are we safe? Are we done when we do all this? Unfortunately, no, we're not safe.
35:27 Memory safety does not mean security. You still have logical issues. You have authentication issues. You have crypto issues. You have lots of issues. Most of the issues today are memory safety, but they won't stay that way forever. And Anthropic has done some really interesting work here. They released a blog post and a paper recently about using Claude to do an analysis of a postquantum encryption algorithm for digital signatures called Hawk where they were able to to find a cryptographic attack which is traditionally the most scarce I would say of security expertise is people who can do cryp analysis and they were able to do that with Claude. They also were able to show that they could do some attacks against AES128 that drove around an 800 times increase in attacks against that in terms of performance. And then they also had a great bug in wolf SSL around forgery.
36:19 These are traditionally I would say top tier in terms of scarcity or complexity to reason about. And what we're showing is that AI can find not just memory safety issues but logical flaws. So if memory safety removes bug classes, we need something that's going to guarantee safety prophecy properties, guarantee the logic. Can AI help us with that? Formal methods have a really rich legacy in computer science. You know, started in the 60s, we had model checking in the abstract form which essentially creates a you know mathematical representation of the logic in your program and then does abstract reasoning on that. Symbolic checking took that further further compressed state space and actually allows you to compute whether or not a given code base violates a property. If that property is violated in this mathematical proof, you get a reproduction which is really awesome. And as a result, we've seen high-risk safety platforms start to adopt this. The reason it hasn't gone mainstream is writing the specifications is hard, takes a lot of expertise.
37:24 Writing the proofs is even harder. And then you have state space explosion for complicated programs. And then finally, you have to maintain this. Nobody wants to maintain anything. So the key question is, can AI make it scale? And from my standpoint, formal methods are having a moment similar to reinforcement learning had with AI. Reinforcement learning has become absolutely critical to modern AI. Even though it was invented back in the 60s and 70s, formal methods is perfect. It gives AI generated code in Oracle for correctness both from security but performance reliability. It's almost tailorade in my opinion. So what do we need to do to get there?
38:06 Well, we need to be able to specify what must never happen. That can come from things like specifications e etc. You then need to create a model of that specification, a checker that validates those models and proofs and you need to be able to supply the verdict. There are awesome tools out there like CBMC forc that Amazon and AWS have used for checking of lib C their crypto libraries etc. But you still requires a lot of maintenance and effort to get the good results from this.
38:37 But we're seeing both Apple and Microsoft doing a ton of work around this. Both Apple and Microsoft have taken their core crypto libraries and done formal verification and both of them through formal verification have found really interesting crypto issues. in Apple they found an error in MLDDSA with Microsoft. We recently found in protochem which is a key encapsulation algorithm for PQC a single ship that was wrong. passed all the tests, passed fuzzers, passed human review, only formful verification found it. And this is not just for crypto. AWS is doing this at scale with Cedar for their arbback policies, which is amazing.
39:21 So the key question, at least in my mind, is how can we if we think formal methods is going to be really helpful, how do we scale it? And again, we're seeing really interesting research here. Anias is able to take code bases like rust or even specifications and convert them into what are called lean proofs. So, lean is a functional language for describing proofs around code for formal verification and Microsoft demonstrated on real code and simcript that in a single week mostly driven by agents we could generate 30,000 lines of lean code that formally verified AES GCM and that means it's free of logical issues. It's free of cryptographic issues at least as the proofs stand and it's free of memory safety. So we come out of this having mathematical grounding in the soundness and reliability of that crypto. If we could have that for all of the boundaries I talked about previously, we'd be in a different game with respect to AI.
40:26 Now how can this apply to sort of the the questions duour? So I extrapolated a little bit from the public information around this open AI escape, right? and the hugging face incident. And what OpenAI did, at least from my assessment, is they did all of the right things. They had essentially a isolated strong boundary around their model evaluation. They gave one proxy out which was necessary to get to packages. And unfortunately, that was enough for a capable model to find what looks like nine different vulnerabilities, all forms of logical vulnerabilities on the fly. What that tells us is you can follow the best practice out there, the best boundaries, but if you can't guarantee your code is free from logical issues, which is a tall order today, you're simply not going to be able to guarantee safety. This is a call to action. If that package system was formally verified and with the right proofs, we might be talking about something different.
41:27 So Dave, you've talked a big game about how we can change and prevent things, but what happens when we can't find all the bugs and we can't find them all, right? Everything I'm talking about here is taking 20, 30, 40 years of software debt and converting it to memory safe and formalized software. What do we do in the meantime? Well, today most infrastructure cloud onrem is owned without exploits. most of its configuration issues and unfortunately very little of that infrastructure can be reasoned about by agents because very little of it has been converted into infrastructure or code or other persisted policies that can be checked through a number of scalable mechanisms with AI but we know that prevention is key we cannot get into a hand-to-hand combat detection we will lose so we need to be able to reduce attack surface improve the security posture and configuration and ultimately shift less in the infrastructure side. The less that reaches production, the less that's reachable in production and that means less for the attackers to go after.
42:36 And we know that agents can reason about infrastructure holistically when they're in the right format. So creating graphs or ontologies of all the assets and network flows in your organization can allow them to do things like create locality or understand centrality of the biggest risks out there and focus remediation on that. So for example, you could compute a identity style attack graph and then use that to figure out which accounts are are overprivileged. You can do the same thing for posture, right? Which which devices or infrastructure pieces in your organization have the biggest attack surface? And you can allow agents to validate that. On top of that, once you've computed a graph, edges become more obvious. So if you've computed a graph of normalized authentication across your organization and all of a sudden you have a connection from accounting to the DC, one that creates a point of analysis that agents can operate on that. Two, agents can scale out and do more proactive hunting than you ever could do with humans. So in the end, we believe agents can drive meaningful productivity here. And we have good examples of that.
43:53 a check off an analysis of using agents for check off which checks against various IA mechanisms have showed us that 78% of the findings in that check off can actually be resolved by agents. So attackers have changed the economics of what we're doing today but as defenders we can choose to change the physics and I want to leave you with three things that you can do today. One is you can focus on your highest risk surfaces and make those secure by design. It doesn't have to just be memory safety. It can also apply to web.
44:27 Number two, you can figure out what your most critical boundaries are and start to use agents to work on formal verification for those. There are many open source tools that are capable of doing that now and you can start to prepare yourself. And then finally, you can start to use infrastructure as code and graph computation to build an agent army that can help with prevention. If we invest in this, we change the physics, we change the economics, and we lead the pack. Thank you.
45:02 Right on. Great energy. Hey. Okay, everyone. That was fantastic. It was everything I'd hoped it to be. I I want to give you a couple of housekeeping notes, then we move on to the rest of Black Hat. in this room at 10:30 will be the next session and all of the main briefings talks will start upstairs at 10:15. tomorrow's keynote will be here again where Yan Shisho Shiovali who was also the team captain for Shellfish is going to talk on vulnerability research in the Agentic era.
45:43 Then tonight 6:30 there's a special premiere of Midnight in the War Room. It's happening. It's a movie screening. It's happening in Oceanides A which is on level two. All right. Well, thank you for coming to the keynote. It's been fantastic welcoming in everyone for day two and I look forward to seeing you tomorrow. Thank you.
Summary
- Black Hat USA encourages attendees to engage deeply with the community, fostering connections and discussions beyond the main stage.
- The conference features themes such as AI threats, cyber conflict, and resilience engineering, reflecting the political nature of cybersecurity.
- Jeff Moss, founder of Black Hat, highlights the importance of scholarship programs to bring new talent into the cybersecurity field.
- The rapid increase in vulnerabilities and exploits, particularly driven by AI advancements, poses significant challenges for cybersecurity.
- The discussion emphasizes the need for a shift from reactive detection to proactive prevention strategies in cybersecurity practices.
- AI's role in automating vulnerability discovery and exploit generation is reshaping the threat landscape, necessitating new defense mechanisms.
- The importance of secure software development practices, including memory safety and formal verification, is underscored as essential for future resilience.
- The conference aims to prepare the cybersecurity community for a future where threats are more abundant and sophisticated, advocating for collaboration and innovation in defense strategies.
Questions Answered
What is the significance of the Black Hat conference?
The Black Hat conference serves as a platform for cybersecurity professionals to engage deeply with research, share ideas, and challenge each other on pressing security issues.
How does community support impact cybersecurity professionals during times of change?
In times of rapid change and uncertainty, cybersecurity professionals rely on their community for support and direction, emphasizing the importance of in-person connections.
What are the implications of exploiting known vulnerabilities?
Many security strategies are based on the assumption that vulnerabilities are scarce and can be quickly patched, but this approach carries significant risks if exploits become more commoditized.
How are autonomous operations changing the landscape of cyber attacks?
Autonomous operations are making cyber attacks easier and more efficient, challenging the assumption that such operations are difficult for attackers.
Can AI enhance the scalability of formal methods in cybersecurity?
AI has the potential to make formal methods more scalable, which could improve the correctness and reliability of software in terms of security and performance.