--- title: "Zoe Braiterman — AI, ML, AppSec, and a dose of data protection" url: https://appsecpodcast.com/zoe-braiterman-ai-ml-appsec-and-a-dose-of-data-protection/ date: 2019-07-01 duration_seconds: 1563 guests: ["Zoe Braiterman"] topics: ["AI and LLM Security"] audio: https://www.buzzsprout.com/1730684/episodes/8122640-zoe-braiterman-ai-ml-appsec-and-a-dose-of-data-protection.mp3 transcript: true --- # Zoe Braiterman — AI, ML, AppSec, and a dose of data protection *July 1, 2019 · 26 min* with [Zoe Braiterman](https://appsecpodcast.com/guests/zoe-braiterman/) on [AI and LLM Security](https://appsecpodcast.com/topics/ai-security/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122640-zoe-braiterman-ai-ml-appsec-and-a-dose-of-data-protection.mp3) ## Show notes Artificial intelligence can help analyze security data, but the systems using it also need protection themselves. Zoe Braiterman brings a background in data science, organizational thinking, and OWASP community work to an early conversation about that two-way relationship. Chris and Robert ask how artificial intelligence and machine learning differ, where automation is already appearing, and what pattern recognition might contribute to application security. The discussion moves from familiar examples such as fraud detection toward the data, models, and processes behind automated decisions. Zoe emphasizes the human role in understanding those systems and protecting the information they use. This archive episode captures exploratory thinking about AI and AppSec while encouraging practitioners to keep asking questions and learning together. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Zoe Braiterman: → [Zoe Braiterman on LinkedIn](https://www.linkedin.com/in/zoebraiterman) Mentioned in this episode: → [OWASP Women in AppSec — project repository](https://github.com/OWASP/WIA) Chapters: 00:00 AI, machine learning, and AppSec with Zoe Braiterman 02:03 Zoe’s path through data science into security 03:31 Community work with OWASP Women in AppSec 04:30 Distinguishing AI and machine learning 06:25 What autonomy means for a process 07:19 Examples of AI applications 10:18 Fraud detection and learning from data 14:25 Possible uses of AI in application security 16:19 Smarter tools and penetration testing 18:39 Pattern recognition in security data 21:08 Protecting the data and processes behind AI 23:45 Learning resources and closing advice ## Transcript *3,639 words · assemblyai* **0:00 Chris Romeo:** Zoe Braiterman is an innovation intelligence strategist focused on both machine and human, and also the OWASP Women in AppSec chair. We explore the intersection of application security with artificial intelligence and machine learning, and we end up discussing data protection along the way. Zoe approaches AppSec from a different angle, and her perspective gets us thinking about the importance of AppSec in the future of autonomous everything. I want to take a moment to introduce you to Security Journey. At Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term sustainable security culture amongst all their developers. Our approach is to provide security education that is conversational, quick, hands-on, and fun. We don't do lectures. Instead, we let the experts talk about what's important. The modules are quick, 10 to 20 minutes in length. We believe in hands-on experiments, builder and breaker style, that allow developers to put what they learned into action. And lastly, fun. Training doesn't have to be boring. We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo. The Application Security Podcast. Here we go. Hey folks, welcome back to the Application Security Podcast. This is Chris Romeo, one of the co-hosts here of the podcast, and I'm also the CEO of Security Journey and another co-host is right here with me. Hey, Robert, what's up? **1:58 Robert Hurlbut:** Hey, Chris. Yeah, this is Robert Hurlbut, Threat Modeling Architect. Glad to be here today. **2:03 Chris Romeo:** Awesome. Well, we are joined today by Zoe Braiterman, and Zoe is here to talk with us specifically about artificial intelligence and machine learning, but I'm sure we're gonna talk about a lot of different things in the world of AppSec. So Zoe, with everybody who comes on the AppSec Podcast here, we always ask, what is your security origin story? If there was a comic book about Zoe and her career into security, what does that episode number 1 of that comic book look like? **2:37 Zoe Braiterman:** Well, so I tried to enter the field of data science through New York City meetup scenes and projects and teams, etc. But I realized that every project I tried to start working on, I would be asking way too many questions beforehand, and I learned that that's a big important part of AppSec. So that's where I decided to then get into AppSec. **3:04 Chris Romeo:** So where'd you go? So you didn't study computer science, or did you study— you didn't study security or anything in university then? **3:12 Zoe Braiterman:** No, I studied business, but I actually saw a lot of very nice relevance, you know, from managerial economics to AppSec in terms of studying the structures of communication and the different contexts and organizational processes. **3:31 Chris Romeo:** And you're involved with something that, uh, all of us— it's hard not to love in the world of AppSec, and that is OWASP. What's your involvement in the world of OWASP? **3:44 Zoe Braiterman:** Oh, um, so I'm a member of the Brooklyn chapter, and I also chair the Women in AppSec committee, building in diversity into the wonderful community that we have globally. **3:57 Chris Romeo:** We've talked to some of the other folks we've had. Vandana's been on the show before and Jesse. And so you work with— all 3 of you work together to promote the Women in AppSec for OWASP? **4:08 Zoe Braiterman:** Yes, along with Catherine and Geeta and Laura Donna on the officer's side and a bunch of other committee members and participants who contribute regularly, and we actually have 2 women starting a London chapter next week, which is wonderful. **4:30 Chris Romeo:** Very cool. So I guess the topic that we wanted to discuss today was artificial intelligence and machine learning and what is the application to application security. for these 2 very transformative types of things that are happening in the industry right now. And so, as I was telling you before we started here, I don't know a whole lot about artificial intelligence and machine learning. I probably know enough to be dangerous, which is true about a lot of different topics. I think Robert knows quite a bit more about this than I do. So, maybe before we start, let's get a definition. When we say artificial intelligence, and then we say machine learning. Give us some, the definitions of those things kind of from your perspective. And 'cause I feel like a lot of people get these 2 things confused. They think they're, it's like threat and risk. They think it's the same thing. So what is artificial intelligence and what's machine learning? **5:24 Zoe Braiterman:** So artificial intelligence, you know, implies autonomy and yeah, just autonomous processes. And machine learning is, You know, training a specific model to continue to, you know, recognize, classify, etc., some, you know, some type of data and be able to act accordingly. **5:51 Chris Romeo:** So where does the Terminator fit in? The Terminator fits into which category here from that? **5:57 Zoe Braiterman:** I actually haven't seen that film. **5:59 Chris Romeo:** You haven't seen it? Okay. **6:00 Zoe Braiterman:** I guess that's on my to-do list now. **6:01 Chris Romeo:** Yeah, it's like the first— I don't know, Robert, was that the first time artificial intelligence ever made its way into the The big screen in Hollywood? **6:08 Robert Hurlbut:** Uh, maybe HAL, actually, way back when. **6:11 Chris Romeo:** Oh, see, now you're— yeah, you're going way back. **6:13 Robert Hurlbut:** But I'm— I didn't actually see it when it first came out. It was probably— I was alive, but, uh— **6:19 Chris Romeo:** Because you were far too young is what you're saying there. **6:22 Robert Hurlbut:** Yes, yes. But, uh, but that's one example of that. **6:25 Chris Romeo:** Yeah, HAL from 2001, and then Terminator from the artificial intelligence side. So, okay, so, so Zoe, you said so autonomous process from artificial intelligence is, is kind of what we need to think about. So when we say autonomous process, that truly means it can operate on its own? **6:42 Zoe Braiterman:** I guess at least for a specific application or for a specific type of process, you know, initiated with, you know, the input output units and depending on the model of the, the neural net, et cetera. Some of them have input/output and forget gates, for example. It's of course mysticized a bunch when you see the robots on, I guess, one of those, likely Terminator, as you mentioned, although as I mentioned, I haven't seen it. **7:19 Chris Romeo:** So what are some examples then of how AI is being applied today, just in general? Maybe not even in the world of security, but just in general, where are people trying to use AI today? **7:31 Zoe Braiterman:** Computer vision, various models, whether it be recognition of certain features or also feature learning generatively to generate new, you know, data types or data structures, whether it be an image or, or some sort of sequential data for predictive analytics, stock prices, market trends, etc. Natural language processing, NLP, is big, you know, including sentiment analysis. So it's not specifically natural language syntax. **8:11 Chris Romeo:** Yeah, and so I think one of the, one of the big examples that I always see thrown out when we talk about artificial intelligence is this idea of the self-driving car. And even the self-driving truck that's pulling the heavy load filled with stuff that's being shipped from the West Coast to the East Coast or whatever. And so, when I think about the threat model that goes into this whole idea of self-driving cars, I mean, it makes me not want to leave my house, but at least they're not as much of a kind of reality at this point. But it seems like that's where we're going. **8:45 Zoe Braiterman:** Yeah. **8:46 Chris Romeo:** Seems like there's just, when we talk about the threat landscape that's brought about by artificial intelligence, it seems like we're opening ourselves up to a whole lot of new risk in the future. Zoe, what do you think about that? **8:57 Zoe Braiterman:** Oh, definitely. Because, you know, it keeps training one input-output or, you know, one step at a time. And I'll give a concrete example. One inaccurate label and that can be influenced by adversaries, for example, then goes on to the next input and output layer. And so from there, they have a bunch of different controls moving forward. And it's similar to threat modeling and risk trees. But also every step that's scary and mystical in the news, take that, apply every AppSec concept, and then keep it continuously connected. With all the IoT devices and industrial IoT, IIoT, and smart cities and everything in an increasingly connected and complex world. What else can go wrong, I guess? **10:09 Chris Romeo:** Yeah, seems like the sky's the limit for what can actually go wrong here when we're talking about these new tech, this new tech. **10:15 Zoe Braiterman:** Yes. **10:18 Chris Romeo:** So what about machine learning then? Tell me this is actually a real thing. That this is when I think of machine learning, this is what I think of. So when I travel the world or the greater, I don't know, East Coast of the United States, And I get to a hotel and I give them my card and they swipe my card and they say, I'm sorry, your card's been denied. And all of a sudden I get a text message from my bank that says, hey, are you really in such and such a location? Because you didn't tell us if you were. Is that an example of machine learning? **10:50 Zoe Braiterman:** Well, it could be, you know, definitely some involved. Like for example, assuming it actually was your bank, then they probably could have had ways of implying such data that's not always accurate, but based on statistical models, but then also predictively inference toward the next input. So that's one of the differences of, I guess, typical statistical modeling to machine learning modeling, which can be, again, applied to unseen, not yet seen inputs to generate such assumptions. And because it's based on a lot of complex big data to keep up with competitors, et cetera, in this world, so then something can go wrong, as with any kind of statistical model, which is far beyond you know, like a computer architecture or computer science, that it at the end of the day, it is a projection. **12:02 Chris Romeo:** That's on the machine learning side. **12:04 Zoe Braiterman:** Right. So again, even assuming that it was your bank, because there's always the possibility, you know, phishing, etc., or any sort of social engineering. **12:15 Chris Romeo:** I'm just taking out that as a— certainly, I recognize that as a risk. But I'm, I'm taking that out of out of play and saying, hey, if we can say for sure it is actually the bank, then yeah. I mean, is that an example? Is the bank systems actually kind of applying this idea of machine learning? Like, are they going to remember in the future when I go to that same location because the dataset got smarter? I don't know if smarter is the right word, but got better as a result of them tracking my existing visit there. **12:46 Zoe Braiterman:** Yeah. **12:47 Chris Romeo:** And is that machine learning if it does— if the system does get— makes a better decision about whether I'm actually there based on past data? **12:55 Zoe Braiterman:** Oh, past data as well as inferences from, for example, combined preferences for consumers. So really getting those behavioral economics models, for example, and aggregating them using take, you know, your connected devices as well as, you know, all those models combined. And, you know, it's obviously not all open source when it comes to the big players. **13:26 Robert Hurlbut:** Yeah. **13:28 Zoe Braiterman:** But, you know, some combination of that is likely behind it, which also could make it wrong sometimes. So not necessarily always an adversary per se, although I wouldn't exactly I wouldn't say that the corporations who are removing some of our privacy rights are necessarily unadversarial, but— **13:55 Chris Romeo:** Yeah, I guess it depends on what side you fall on there. But yeah, there's definitely some privacy constraints just through legitimate companies that we do business with as well that We wouldn't list them as an adversary per se, but when you think about how they use our data, it's like, hmm, maybe this is an adversarial relationship I'm in. **14:17 Zoe Braiterman:** I mean, the adversarial is, it's a spectrum, you know, it's non-binary. It just depends on the context. **14:25 Chris Romeo:** It's true. That is true. So, when we think about artificial intelligence, machine learning, and AppSec and how these 2 things kind of relate. What are the uses of artificial intelligence? Starting— let's start with there. What do you see as kind of the ways artificial intelligence could be used in the field of AppSec? **14:47 Zoe Braiterman:** For example, how a pen tester has to get into the minds of a non-ethical hacker and do the same, similar processes and try to put themselves in those shoes. So kind of, you know, again, first of all, you know, trying to imagine and, you know, put into threat modeling, for example, and I'm sure, Robert, you can speak more on this, but try to, you know, get that kind of insight into the threat model, but also in terms of what the adversary might be doing, but also try to generate your own models first. So kind of, who can get there first, let's try to get there first, similar to the idea of offensive security. Creating models to just generally do that and then apply some game theory, for example, generative adversarial networks where it's essentially generation of opponents and trying to beat each other out at a zero-sum game, but try to apply similar models on our side as well to, you know, to get there first. And I imagine on the defensive side might be on the radar at some point to really be able to automate that more and more in various ways and scale it out to various frameworks and architectures. **16:19 Chris Romeo:** So, when we think about artificial intelligence from the pen testing perspective, is it the case where we'll eventually get software, we'll create software that's better at finding vulnerabilities as a result of the fact that the software itself can apply some type of autonomous decision-making and data collection process and and develop new mechanisms, or is that— it almost seems like science fiction-y to me, like this is a movie, it's, you know, like a movie where there's a large robot coming back from the future to try and extinguish humanity or something. But I think that movie's already been made. But what I mean, so, so like, what, what kind of— what do you see as the, the kind of use case for this? Is it, is it the pen tester being able to just have smarter software? **17:12 Zoe Braiterman:** So I guess all sides of the development team have— having smarter software, one should hope. And also, I guess, bringing in data science and maybe, maybe, you know, there's future for specific, you know, type of AppSec training specifically for the data scientists. **17:38 Chris Romeo:** Yeah. **17:38 Zoe Braiterman:** whose job it is to essentially scale everything out and create these models and try to make sure that everyone's on the same page of that similarly and maybe a little bit separately from the rest of the development team where the security trainer comes in or— Yeah. I mean, in terms of that side as well and, you know, the— the human element side, there might also be new opportunities and new needs seen for that. But yeah, so in terms of the methodologies itself, trying to make them, you know, account for more, more future threats and also, also on the defensive side and the scaling side. trying to, you know, maybe new opportunities for external tools and vendors, etc. **18:39 Chris Romeo:** So then does machine learning, does that make for something different as far as, you know, are there different potential use cases for machine learning in AppSec? **18:50 Zoe Braiterman:** I mean, a lot of machine learning techniques in terms of just, you know, automating processes are essentially machine learning, but it just in terms of how much is scaling out, and I can't speak for any other AppSec team and what, you know, what they do necessarily, but yeah, just I guess continuing to scale it out using, you know, from various angles. **19:14 Robert Hurlbut:** Well, I think about, you know, some ways I've seen it used just in industry, how, you know, we talked about, I think you talked about advertising or marketing and, and how they figure out our buying patterns. And so some of the most interesting articles I've read in security in relation to machine learning is just gathering all that data about attacks and trying to understand how they actually work. And then how do you find the patterns? And then how do you look for the patterns in new attacks and try to determine what's an attack and what's not? And so I think that's really, really interesting. I mean, certainly one of the things I've found, and Zoe, you can talk about this, is I think that we are here where we are because of the fact we have better machines, faster processing. We have tons and tons and tons of data now that we have to wade through, but we have machines that can do it and memory and resources and so on. And so that's how we are here, and I think it'll get better. But also, we're just gonna see it happen more and more. We're gonna be using it more and more. I don't think there's hardly an industry that it's not touching now. And certainly, I think we can benefit from that in security with some of the things that we were— I just mentioned there about finding attacks and trying to get ahead of the game, if you will. **20:39 Zoe Braiterman:** Oh, definitely. And yeah, making sense of specific potential attacks and, you know, the specific modeling and the specific— yeah, I mean, all of the details and then trying to make them more and more specific and then more and more kind of different ways to play with the components within those models, definitely. **21:08 Chris Romeo:** Yeah, so you mentioned kind of, I guess, a different perspective than I was even thinking about we first started the conversation, I was thinking about AI and machine learning kind of from the perspective of how does the AppSec team use, you know, how could you potentially use these technologies to do AppSec better or make AppSec easier? And you actually made reference to the fact that data sciences teams need AppSec to be built in. So almost the other side of the coin from what I'm thinking about. And That is just the importance of AppSec best practices and all the things of OWASP being boiled into these new artificial intelligence machine learning products and things that are being done in different industries that need for that solid set of best practices to make sure that when we have self-driving cars, we can have some amount of assurance that they are in fact not remote control vehicles. They are, you know, they, they have solid security architecture that's gone into them. **22:12 Zoe Braiterman:** Oh, definitely. Yeah. And make sure that, you know, at each, I guess, phase of the automated processes that, you know, proper controls are taken at each of them and trying to track throughout the entire training of the models and all of that. And also for various services that implement them within different organizations. **22:48 Chris Romeo:** Zoe, where could folks find you if they want to kind of continue this conversation about AI, machine learning, AppSec? OWASP WIA, Women in AppSec. Where's the best place for them to find you and continue the conversation? **23:09 Zoe Braiterman:** I suggest starting with Twitter. So it's Z. Braiterman, Z.B.R.A.I.T.E.R.M.A.N. And yeah, so on Twitter I reference chair of OWASP WIA, but I also go by security and human and machine intelligence strategist because I really believe in the human element and the collaboration behind all of this as we continue to progress. So, yes. So, @ZBrainerman on Twitter. **23:45 Chris Romeo:** I just thought of one other thing I'm curious about. Are there any kind of references or resources, things that you kind of have as go-to resources for AI and ML that you'd point out, want to kind of draw attention to for our audience? **23:58 Zoe Braiterman:** I follow a combination of academic references and open source references. And I guess colleagues doing various applications of ML in industry as well. And also being able, looking at different frameworks that are out there and getting into the specifics specifics about what types of data they use and what types of models and, you know, the applications and trying to see really, I guess, dig deeper, you know, into the underlying components that could be used for various parts of AppSec. **24:43 Chris Romeo:** So I guess any last words for our audience about this topic? **24:49 Zoe Braiterman:** Be very, very conscious as a user and Just keep learning within the community and everything on the professional side. And yes, be secure. It's even more important now. **25:06 Chris Romeo:** That is definitely true. Well, Zoe, thank you for taking the time to speak with us today, and we look forward to continuing the conversation on Twitter and wherever the conversation goes. Hope to catch you soon at an OWASP event, maybe even OWASP in Washington, D.C. And so once again, thanks for being here. **25:27 Zoe Braiterman:** Definitely. And thank you both. **25:29 Chris Romeo:** Thanks for listening to the Application Security Podcast. Our intro music is 8-Bit Kung Fu by Born and TJ, and our outro music is Southern Delight by Stefan Kartenberg. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com. **25:51 Robert Hurlbut:** application-security-podcast. **25:51 Chris Romeo:** You can also find Chris on Twitter @edgeroute and Robert @roberthurlbunt. Remember, security is a journey, not a destination. --- Source: https://appsecpodcast.com/zoe-braiterman-ai-ml-appsec-and-a-dose-of-data-protection/