Opens in a new tab
vmblog logo 2024 wht (updated)

AI Proving Grounds: Where Today’s Leaders Overcome Tomorrow’s Challenges

Share: 

ai proving grounds

By Lee Rossey, co-founder and Chief Technology Officer of SimSpace.

Imagine enlisting in a branch of the U.S. military to be told on the first day of basic training that your unit only conducts live-fire training exercises in active combat zones. No blanks or multiple integrated laser engagement systems, no secure, controlled training environments. Just live ammunition against hostile combatants in enemy territory.

Such a scenario would never happen due to the immense risk to the lives and safety of inexperienced service members in training. But while the risks may not be as deadly as purely live-fire military training, this is precisely what countless businesses at the forefront of the world’s most critical industries are doing every day by conducting AI cybersecurity testing in live production environments.

The advent of AI is often compared to previous significant technological advancements, such as the explosion of the World Wide Web in the Nineties. What makes this a flawed comparison, however, is the sheer speed at which AI is developing; even enthusiastic adoption of consumer-level Internet access and early ecommerce took much of a generation to fully reshape how people interacted and shopped online. By contrast, the rapid advancement and proliferation of AI technologies is forcing many businesses to adapt to a constantly shifting attack surface that changes in weeks, not years. This, in turn, is putting many companies in the perilous position of attempting to respond to increasingly sophisticated adversaries in a uniquely volatile threat environment to safeguard proprietary and customer data in live production systems.

This is the challenge we set out to solve by creating AI Proving Grounds.

What Are AI Proving Grounds?

AI Proving Grounds are a high-fidelity sandboxed recreation of a company’s entire tech stack and attack surface that allows businesses to stress-test their resilience to specific intrusion scenarios in a safe, controlled environment entirely separate from their actual technology infrastructure.

The primary purpose of AI Proving Grounds is to simulate business’ actual production environment as closely as possible, and run highly specific attack scenarios to identify potential weaknesses and vulnerabilities without exposing proprietary systems or sensitive data.

How do AI Proving Grounds work?

The first step in creating an AI Proving Grounds simulation is the creation of Hyper-Synthetic Data that mimics that of a client’s live production environment. This includes broad system topology, operating systems, client/server models, applications, security measures, as well as simulated network activity and telemetry from virtual users to mimic how an organization’s employees typically interact with those systems. This Hyper-Synthetic Data is then stress-tested by realistic advanced persistent threat (APT) attack scenarios to help technologists identify potential vulnerabilities in production.

The next step focuses on testing and validating agentic solutions across the attack surface. This phase enables clients to better understand the decision quality of agentic workflows, ensure that agent responses adhere to internal policies and governance structures, and provide insights into how individual agentic workflows perform.

Once this is complete, AI Proving Grounds simulations stress-test agentic workflows to ensure that deployed agents are safe and trustworthy across a range of enterprise systems, including SIEM, SOAR, EDR, identity systems, and ticketing platforms. This involves pushing these workflows to their breaking point to identify vulnerabilities prior to deployment. Just as military recruits are tested to gauge how they respond to rapidly changing conditions on the battlefield, these tests are non-deterministic to recreate the urgent, high-intensity nature of real-time intrusions and simulate such attacks as realistically as possible.

The final aspect of AI Proving Grounds focuses on the human element, including analyzing performance data to identify successes and failures, and enable partners to design comprehensive training scenarios of their own. This involves benchmarking responses to specific attack vectors to form the basis on ongoing training programs and ensuring that humans can work with agentic solutions to create robust rapid-response protocols within their organizations based on likely attack scenarios.

Creating a Culture of Resilience, Not Reactivity

As any experienced cybersecurity professional can attest, a real-time cyberattack is a true baptism of fire that can test the mettle of even the most level-headed operator. Combined with the increasingly sophisticated threats posed by large-scale AI automation, it’s also an immense risk to the operational security of millions of businesses and critical infrastructure.

We created AI Proving Grounds to enable the world’s leading enterprises to create cultures of readiness, not reactivity. Every second counts during a live intrusion, and the stakes are simply too high to rely on conventional training in production environments. As AI technologies continue to mature, the stakes will only increase. Is your organization ready?

##