Lightning Talk: Detection Engineering with AI & Deception

SANS Institute · Beginner ·🔐 Cybersecurity ·2mo ago

Key Takeaways

Introduces detection engineering with AI and deception techniques for accelerated defense

Full Transcript

For 5,000 years of warfare, the old fortress mentality of building higher walls and taller walls has clearly failed. But as my science students know, and I know there's some some of them here in the room, when it comes to cyber defense, I'm a big fan of Wim Stoelhorst's time-based security model and equation. Is anybody familiar with that? Time-based security? Some of you? Okay, at least those of you who took my class. Time-based security says two things. First, prevention only buys you time. Time to the what? To detect and respond, just like in the real world. And also that if it takes longer to detect and respond to a threat than the time that prevention buys you, well, the system's insecure, right? It's ineffective. But what happens when AI enters the equation? What if prevention time drops to absolute zero? Does the math still hold true? Is this still valid? When AI offensive tools can throw like thousands of exploits per minute, per second, discovering all these many vulnerabilities, and there is no prevention, or so it feels, what are we going to do? Are we just like hopelessly waiting to lose as cyber defenders, or is there any hope for us? Well, think about it. Most people are very, I would say, obsessed with zero days. It's all about the zero days, the exploits, but is that what it really is? I mean, we have seen it this morning. Many of the speakers have talked about the attack chains, all the many steps that the offensive agents have to take, including getting into the environment, stealing credentials, moving laterally, getting to achieve the objectives. Now, thinking in along those lines is the core of the philosophy that I call think red out blue, which is essentially thinking as an attacker to become a better defender. Think about the offense. What characterizes these offensive tools? It's speed. But is speed making the tools smarter? Or is it making more fragile? And is this fragility something that we as defenders can we exploit it? Can we play our home field advantage as cyber defenders? If so, how do we do that? The author Jonathan Swift centuries ago said, "Falsehood flies." You know how it follows, right? The truth comes limping after it. Now, these offensive tools, they're just like flying at machine speed, like throwing attacks as if they were lies, right? Going really, really fast. But we as cyber defenders, we don't have to just come limping after them. We could actually flip the script. How so? I'm going to quote something that Bruce Schneier said this morning. He said, "The AI agents are gullible." What does that mean? They have been trained to follow patterns, patterns that they have learned, right? During the training. They have also been trained to inherently trust environmental signals. That is their fragility. So, can we fight lies with lies? Think about it. A human attacker, for example, that is on the network and sees this password.txt file that just looks too good to be true in a share sitting on a share folder. Is he going to touch it or not? That's human intuition. What is the AI agent going to do that has been trained for rapid compromise? Can we fight lies with lies? Yes. So, today we're announcing the CPO. This is an agentic network deception tool that illustrates the concept of how to use tripwires, red herrings, and deception to fight lies with lies. How does this work? Well, the CPO broadcasts like thousands of lies on the network by requesting fake host names. Baking Windows discovery common Windows discovery queries asking for host names that do not exist on the network. Now, if somebody answers that request, what do we know? It's a poisoner. There's no false positive. There's no false negative with any of that. One single breadcrumb can derail the attack chain. But there's more. Think about OODA loops, observe, orient, decide, act. That during the attack OODA loop, the CPU can crunch the observe time with these fake props, but it can also now through the agentic workflow take over the decide and the act by taking rapid response and completing the defender feedback loop in a fast matter in a fast manner. For example, one of the things that he can do is to do credential seeding. Seeding or injecting fake credentials into the attacker system to again derailing this type of attack. Think about what this does with time-based security. It shortens detection and reaction time while extending prevention time. Today we're releasing the CPU, but we're gaining it for defenders. We're releasing it in a different way. See, 10 years ago I was in a stage like this at the Sans Threat Hunting Summit presenting my project called Rastreador. It was a project that I shared with the community for free, open source it. To help defenders to hunt for threats at scale. But times have changed. And today these crawlers are just like crawling for the uh for uh defensive tools and give up GitHub projects, open source projects to train these models for offensive tradecraft. Why would we share our defensive playbooks with the adversaries? Would any professional sports team share their playbook with the opponent the day before a game? No. So today you can download the CPU or actually request access to the CPU for cyber defenders. We're protecting it uh, in this in this way. And remember, the clock is ticking, literally as well. But time can still be in your favor. >> [applause]

Original Description

Vibe Detection Engineering: Accelerating Defense with Compound AI & Deception 🎙️ Ismael Valenzuela, Author & Senior Instructor, SANS 📍 Presented at SANS AI Cybersecurity Summit 2026 Detection engineering is evolving with the use of compound AI and deception techniques to accelerate defense. By combining adversary-informed approaches with automated workflows, teams can shorten detection cycles and improve response at scale. This talk explores how integrating AI-driven detection with deception strategies helps validate signals and keep pace with attacker behavior. Explore upcoming SANS Summits to continue learning from leading voices in cybersecurity: https://go.sans.org/summits
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Related Reads

Up next
How To Delete Your Data From The Internet | Privacy Bee Review & Tutorial 2026
Tutorial Stack
Watch →