Kevin Mandia. [Photo: Kevin Mandia LinkedIn page]

"AI-based attacks find logic gaps, not code flaws."

Kevin Mandia (케빈 맨디아), founder of Mandiant, which was acquired by Google, and CEO of AI security startup Armadin, recently said this in an appearance on venture capital firm Andreessen Horowitz's (a16z) YouTube channel.

AI attackers, he said, target gaps in workflow design rather than coding errors in applications developed by companies. Unlike humans, they also try every possible path to the end.

Armadin provides automated security agents that can counter AI-based attacks. It focuses on helping white hats gain an edge over black hats. Armadin's co-founders include Travis Lanham (트래비스 란햄), a former Google Cloud security engineer, Evan Pena (에반 페냐), a former Mandiant executive, and David Slater (데이비드 슬레이터), an engineer on Google's security operations team.

Armadin in March raised $189.9 million in seed and Series A funding led by Accel. GV, Kleiner Perkins, Menlo Ventures, 8VC, Ballistic Ventures and In-Q-Tel, an incubator under the U.S. Central Intelligence Agency (CIA), also participated.

Mandia also shared Armadin's results so far. "Since January this year, we have found more than 90 zero-days at customer sites. They were all systems in operation," he said. "They are not small companies. They are Fortune 500 companies," he added.

He also described what happens after discovery. "We usually call the CISO within 48 hours and say, 'We found a remote code execution (RCE) vulnerability in the DMZ (a publicly exposed network segment),” he said. "In most cases we go from there into the internal network, and the customer agrees with our assessment," he said.

"Companies that receive the call immediately go into emergency response as if a real hacking incident has occurred," he said. "This is not a penetration test. It is like a real attacker breaking in," he added.

Mandia cited the way the AI model is trained as the key to results. "We post-trained every model with real red team operators and people who can write exploits themselves," he said.

Armadin, he said, attacks under the same conditions as an external hacker without receiving any internal company information such as source code or login credentials. Mandia also shared his view of reactions around Anthropic's AI model "Mythos." "When Mythos came out, everyone was amazed that it could scan source code and find thousands of vulnerabilities. That is noise," he said. He meant that what matters is whether a system can actually be breached, not the numbers.

Keyword

#Mandiant #Armadin #Andreessen Horowitz #Accel #In-Q-Tel
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.