Intel Corporation (INTC) Earnings Call Transcript & Summary
October 12, 2023
Earnings Call Speaker Segments
Todd Cramer
executiveWelcome, everyone. Welcome, and thanks for joining our webinar. We hope to have a great dialogue today on not only ransomware and how it's evolved, but how AI is being used by Intel on clients to fight brand somewhere. So I'll just do a little housekeeping at the moment here. We have chat windows. So I encourage you to chat amongst your fellow participants. If you put questions into the question bar, we'll get to those probably at the end, but we may answer those as we go. And then we've set some resources here that we hope you look at that will run through at the end, some of these resources. And feel free to ask us any questions. But without further ado here, we'll let us introduce ourselves. So I'm Todd Cramer and I head up Security Ecosystem Engagement at Intel. I've been at Intel 15 years. I work on security, and I'll turn it over to my counterpart, Ram to introduce himself.
Ram Chary
executiveGood day, folks. I'm Ram Chary. I manage platform security engineering at Intel. I've been at Intel for many years. In my time at Intel, I started from a CPU microarchitecture and I worked my way up the stack on the OS and the networking areas. For the past 10 years, my focus and my team's focus has been on developing security solutions for our Intel platforms. What my team and I love is to collaborate with our partners to eventually deploy these technologies that, in the end, are helping our customers. And I look forward to our conversation today. Thanks.
Todd Cramer
executiveSuper. Let's get into the topics. So as we flow through our presentation here, we're going to talk about ransomware and it's constantly evolving. So we'll bring up some new techniques that we're seeing out in the marketplace. We'll talk about that AI-powered security at the endpoint that you may not realize is actually already in your processor for a couple of generations doing you good for your antivirus. And then we'll take a peek around the corner. Intel's got a 14th generation launch with some special capabilities in it for AI. And so we'll look across that landscape and hopefully bring out some new pieces for everybody. So I'll start here. And what you see at the top is a very high-level extracted cyber attack kill chain. You may see this out in the industry. It's been out for years, and it constantly evolves and even things like the MITRE ATT&CK framework really blow out the tactics and techniques that are used by attackers. But essentially, it's showing you the typical category or phases of flow as an attacker, as they try to infiltrate the system from initial access, how they first execute to launch on the system, how they try to persist, how they try to evade defenses from the EDR and then that lateral movement, moving to a second host, second machine, second part of the network. How are they going to exfiltrate data or achieve their objectives and then ultimately, the impact and recovery phase. And so think about this as we'll return to this feature later, I'll explain sort of the software and the hardware architecture that maps underneath this to build defense in depth. But here are the first look, let's just say, threats are accelerating. It's clear, right? We constantly hear the news, and I'll cover some of those headlines, but let's just look at a couple of the techniques that are speeding things up. Ransomware is a syndicated set of software and automated tools. There's sophisticated nation state crime brokers, small shops, and they collaborate with each other. One of the ways they do that is what's called access brokers, right? The dark web where people's credentials and other enterprise access vulnerabilities are actually shopped out there for someone to collaborate with another game, grab it and launch an attack. And so one of the facts that out there is the cost of that to launch attack, to get at this dark web is dropped all the way down to $2,800 a to get some of these credentials. And so the cost to launch these attacks has gone down, which opens up the ability to do that. And then as you get to the execution phase, you'll hear this term of fileless malware-free attacks, right? So old world attackers used to drop something on your system that was easily scalable, a signature. And so most of the antivirus tools out there, were able to uncover those easily by scanning files and looking at the disc itself. Well, that no longer works. You hear the notion of living off the land attacks, which is a broader category of techniques that they use because they know where the antivirus or the EDR, endpoint detection response are going to have problems. And so process hollowing, spinning into memory, and we'll talk more about that. Those are very difficult areas to catch these attackers. So you typically -- they are able to execute that first phase of an attack and get in. And the other part that goes with it is the stat of the tooling that are used -- penetration test tools that are used for good are turned around and used for nefarious reasons, their consoles, their ways to probe the system. So they have software that they use to probe defenses. And things like Cobalt Strike, Sliver Frameworks, Metasploit, these are way up on the use as well, 161%. But the good news is as we talk about this, there's ways we can help detect this. And then moving over to lateral movement. CrowdStrike has been tracking for years. The time it takes for an attacker to get to from one machine to that second host, 79 minutes is the average, right? That's how fast they can move and the fastest they've recorded in the last year is 7 minutes. Just imagine that for sec operations that's trying to track and respond. That means a lot of automation needs to come in play on the SecOps side of things. And then finally, that all important impact. The average cost to remediate ransomware is no small fee, $1.4 million, and you typically see some of those payments still going out and the damage and release of information happening. So we'll return to this later, but that's just a view of why -- one reason why we're seeing the acceleration on pieces here. So Ram, why don't you walk us through a little bit of the prevalence.
Ram Chary
executiveYes. Thanks, Todd. Hopefully, you're all seeing this slide that shows the big ramp in ransomware attacks in particular, right? So as we all in the start touched on, ransomware attacks have been escalating substantially. And as we know, it's hitting businesses, infrastructure. Every day there is a school or some establishment that I see in the news, right, both in the public and private sectors. Just briefly, why is this happening? I mean Todd touched on some of the top-level issues. I want to just spend a minute on a little bit more detail, right? There are a couple of, I would say, 2 major aspects to ransomware. One is the evasion techniques and Todd touched on some of those. That's common to a lot of malware, right, not just on ransomware. And then the proliferation is very unique to ransomware, right? So as we talk about malware evading detection, as Todd was saying historically, we were scanning static signatures or hashes, AV software would run it on our hard drives and essentially are looking for malware address. Malware these days, uses polymorphism, right? That can change constantly. That's what happens. And as Todd mentioned, it's most often fileless, it's sitting in memory. And they can use existing code to craft attacks, letting out the land attacks like ROP attacks, where you can kind of take existing code what they call gadgets of good code, then you kind of link them together to start an attack that it's brand new. So malware detection by -- that's kind of changed with the advent of the endpoint detection and response or EDR, right? So they use extensively behavior analysis and they're doing an extremely good job of doing that. Where you're focusing both on run time behavior as well as this new type of attacks where they are sitting in memory, right? They're not messing a hard drive. So they could look at system cost sequences, they can look for patterns that -- in the memory code and so on. And later, we will touch on some Intel technologies, which actually help -- we work very closely with our partners to make those more efficient. Now to bypass all these -- the behavior analysis from a software level, right? So malware has been using other techniques, especially in the case of ransomware, you can do process splitting, right? So rather than 1 process going in say, encrypting 100,000 files, you can have 100 processes, right? So the goal of that is to make the malware look kind of benign and trying to kind of sneak under the radar, right? And so a lot of the techniques, it's constant cat and mouse game. In some cases, we'll -- and we have techniques which are uniquely helping us to take some of these types of attacks that malware can run within a VM, right? In that scenario, the malware is completely opaque to a detector that's running in the host OS or route partition, right? So those are some of the evolutions that we've seen. Now on to the next slide, Todd.
Todd Cramer
executiveI was going to add -- I was just going to make another point here. The -- and as you see with the COVID pandemic lockdowns, right? So what you have is employees moving outside of the corporate VPN, the traditional firewall. And so that increases the importance of the endpoint itself and how you protect it. That's why you see the system of record for security moving from that firewall type of protection to an EDR, endpoint detection response, behavioral-based detections, tools to act for IT. And -- and that's where notions like Zero Trust, where you authenticate the user and you check the health of the device. That's where the EDR comes into play. They very much monitor that health of the device to enable and access for a remote worker to get to a SaaS app or a cloud app. So another reason as COVID hit, the change in most IT departments had a huge scramble to try to retool the importance of their security category software as itself. So again, EDR has raised in importance as the pandemic has hit. So as Ram said, let's look a little bit more on the techniques that we're seeing.
Ram Chary
executiveGreat point, Todd. Those are good comments about that. Just briefly on the proliferation side, right, and Todd touched on this. The key reason, I think we see the rise of ransomware proliferation of it almost every day is because of ransomware-as-a-service, right? You and I go to a site to get ransomware from one site, we can look for vulnerabilities for a specific organization from another site that Todd mentioned. You need a payload deployment tool from another one and a means of monetization from yet another place, right? So it's all packaged so beautifully that anyone can build and deploy a ransomware attack and which is what we are saying. So malware developers can track out new variants that they look different and they kind of evade the traditional detection techniques that have been using. I was just looking last night, in fact, there was a registered article on ransomware attacks. Apparently, LockBit has been very successful, and it's actually the #1 due to adoption by the ransomware-as-a-service, right? So in short, our partners are telling us that ransomware is not going away anytime soon. So that's been a big portion of our focus and our collaboration with our partners to deploy solutions to kind of try to make this whole problem a little less intense right? So anything you wanted to add Todd on that?
Todd Cramer
executiveYes. I'll just sort of touch on the last 2. So with a lot of these ransomware attacks that are automated for the attacker masses to launch that do -- that aren't as sophisticated, when you get to an enterprise in these nation states, they do what's called adaptable, human-operated ransomware. And so they're using that Cobalt Strike tooling to probe move laterally look across the enterprise assets, deploy the payloads that will ultimately be invoked to drive the ransomware. So they're surfing. And actually, I think it's Mandiant tracks to what's called the dwell time. It's up to 16 days. It means until it gets in, until you actually discover it, it can be 16 days, right? They're taking that long with a human who has eyes-on glass hands on keyboard looking across the environment. So again, back to that kill chain, getting these things very, very early and planning your fail safes if they do get through critically important, right, because they're getting in there. And then the other technique double extortion as ransomware was started, it was encrypt the data, hold the key ransom. Well, as we know, they exfiltrate that data and they have the data with a double threat of the publicly releasing the information. So they're working multiple ways. So if you find it one way, they still have the information. So that's why you see ransomware just continue and it's going to be with us for a while. It's been with us for a decade and it's just going to increase here. So this arms race in AI is what we'll talk about as we go here. New tools that adversaries use but also new AI tools that we're using to keep ransomware at bay, keep it in check, right?
Ram Chary
executiveGreat, great Todd. So if you go to the next -- yes. So this one -- first of all, let me preface this. We work with all the leading vendors right in the EDR and AV space, and they're doing a bang-up job, right? We only hear about stuff that gets through, never about what actually gets caught. That's the story of security in general. But we want to kind of focus a little bit on why this is problematic, right? There are some problems in trying to detect especially these new variants than they happen. This -- what we're showing here is a snapshot in time of a selection of zero-day ransomware attacks. Let me just focus -- it's hard for you to read. But let me just highlight what it's saying. The left one is the Darkside, there's a group Darkside and they had a ransomware, what a couple, 2.5 years ago or so which was the most famous incident was the Colonial Pipeline attack that actually happened. Now this data that we're sharing is it was tracked by VirusTotal. Right, on that, when this initial attack came out, of the 71 core engines that they attacked, that they are tracking, only about 6 out of those actually detected it out of the box, right? And the detections improved quite rapidly over the next 2 weeks with updates and so on. But one of the things, again, I was looking at it was mentioning that we just [indiscernible] yesterday from various vendor sources, Todd mentioned sometimes you have this dwell time that's pretty long, but there's also the other scenario where because detection techniques have gotten better and better with EDRs, sometimes people are -- some of these, especially these new operators who are just training together ransomware, they are in a hurry to not be detected, right? They got to make their money and move on. So sometimes a dwell time for ransom is 24 hours. It's what we're in. And in some cases, a 20% of the cases or so, it's even 5 hours, right? It used to be -- just to give you an example, you used to be 4.5 days just last year, right? So it's speeding up in one way. So given the speed at which ransomed is striking and spreading and hitting it, the traditional reactive techniques, which is what we normally use for patching, it's necessary, absolutely right, but it's not sufficient in these cases. So the question we heard from our partners, as we talked to them 2 or 3 years ago was, hey, is there a way to use hardware to help augment the software solutions that they already have to make it just that much more proactive, right? There's no 100% solution security, but it's all about, as I said, it's the cat and mouse game. And can we use our hardware techniques to get better. And that's what we are going to talk about later. In other words, basically, they're asking for a solution that can see through many of these evasion techniques that we mentioned earlier and also it's got to be something that's deployable, not very big and shouldn't be consuming too much of the CPU, right? So those are -- we'll get into some of those details as we get further on. Anything else you want to add?
Todd Cramer
executiveYes, I was going to say -- and so when you see that first curve, right, takes that week or 2 until you get more antivirus detecting that. And so one of the things that we realized in our back testing of these very variants in our lab, that what you'll find out is that hardware assist that augmentative piece that we're adding would have caught these right at day one without a tune up, right? So what I'm sort of foreshadowing is that hardware security, as we look at this, has a very unique property. Malware can't hide as it executes on the microprocessor architecture itself. So it's a great tool as we will find out, to use with machine learning so that even as your software is tuning up, you've got this unique capability right on the PC helps close the so-called zero-day gap, not in every situation, but it's a true augmented position, and we'll show you some data to show you how that's really working. Great. So just to cover the headlines, right? And so this is real, right? These aren't just statistics here, Ragnar Locker spun up a VM to dodge security. Zero-day malware variants circumventing antivirus signatures and that increased 70% on ransomware. Another one hiding in a virtual machine. LockFile using intermittent encryption. These are real techniques with real attacks that are causing dollars in losses in the industry. And at least we'll cover a couple of them I know we've got to fill this page with endless headlines, but I think you get the picture here from these. And so let's just look at -- when you talk about AI and deep learning in general, I would probably argue cybersecurity industry is at the forefront of all the industries in its use, right? It's a lot of people in security see the focus on AI in the last few months, and they're sort of chuckling because they know, they've been running this and innovating on it for a few years now. And primarily where those innovations take place is in the cloud, right? When you have an EDR, you have not only the agent that sits on every device to collect the telemetry and the data and to provide protection and response. But that -- there's a stream of that data headed to the cloud into a sense of a whole collection of AI-infused toolings, things that are using deep learning in the high-scale capacity of the cloud where you can run these deep learning algorithms to look at these indicators of attack. You have a cloud-centric console that's very easy to deploy across global deployments at a lower cost. You have AI that's able to look at and predict how an exploit will be -- vulnerability will be exploited. And now this new wave of generative AI security assistance for SecOps, right, instead of them going through screens trying to work across teams now they have this incredibly useful large language model-oriented generative AI assistant to quickly triage and look across data and put automation in place. So AI has done a wonderful job in the cloud. But -- and I'll say, trillions of events are processed every day by these security clouds and resulting in huge numbers of detection. So again, as we're just saying, not everything is Swiss cheese out there. There's a lot being caught and that's a great innovation. It will continue to be there. But then you look at the statistic that 90% of all that valuable cybersecurity data is coming right from the endpoint. And so it brings to mind, well, is there more we should be doing or can be doing with that rich super set of data that resides on your client machine. It's impractical to send it all to the cloud. So some of it goes on use, it's valuable threat data. When you send it to the cloud, the provider and ultimately, the end customer has a high cost, right? We know that running AI on the cloud is a very expensive high-in-demand cost. And then you get to privacy issues, right, sending that data from the endpoint, cross-border data issues to a cloud, that regulatory environment ever increases and you want to ensure privacy to ultimately try to just leave data where it resides on the end point. And then from a meantime to detect standpoint, latency to respond, right? All important yes, you can respond very quickly to put preventions in place with a cloud-powered security cloud but there's actually more you could do right there on the endpoint. So we'll peak into that future as we go here. So AI today, for the last few years, great innovations in the cloud, but we'll talk more about a blended approach of using the client as well. So I think we're up on our first poll here. So I invite everybody to describe your organization's experience with ransomware attack, right? Have you experienced a ransom attack that evaded your antivirus defenses? Did you have an AV EDR that actually caught an attack? Or are you not sure, but you are worried about ransomware or it's just not a concern. So let's take a look, and we'll see and comment on the results as we go here. We'll give it another, I don't know, 10 seconds, 15 seconds. Looks like there's a lot of -- not sure yet, right, which is to be expected, right? They're for sure, targeting large enterprises and SMBs, and looks like around 20% has detected it and some have evaded it, right? So I think there's still a lot of -- that's probably why you're at the webinar here, understanding what's happening out there, and we'll hope to close those answers here to give you a better picture. So thanks for doing that poll. And again, here is the final results interesting across the board. Okay. Let's continue. So here, we're going to move into the part that we have been doing for a few years of AI-powered security on the endpoint to combat ran somewhere. So we'll impact that a little bit. But at a high level here, Ram will talk about the software tool. But first, I'll just talk about our spectrum of partners. We at Intel, don't just put out the processors. That's my role in our organization is to engage different classes of software, primarily endpoint detection and response, but enterprise security browsers, no different classes that are providing protections. And as you'll find out here, what we call the Intel Threat Detection Technology enabling stack that we've worked across many partners more than you see here. They pick and choose which of these features, and we tend to see most of these vendors implement the full suite over time, right? And so we're still, as we monitor, the only solution out there that's giving this hardware assist a ransomware detection in this way on endpoint. And so it's very unique. And so Ram, why don't you tell us a little more of what we've done over 5 years to develop the software stack.
Ram Chary
executiveYes, let me -- I think we have a video coming up, which will actually go into some more visual representation of it. But here, we talked about some of these scenarios where we started out historically with the first problem we were talking about where we have polymorphic malware, memory resident malware. So we have certain techniques for ISVs, to our partners to be able to -- it's called accelerated memory scanning to be able to do a lot of those searches, which inherently are more expensive to do on the CPU, but we offloaded to the GPU. So one of the things you'll see in our solutions is, in our Intel CPU, we have a great CPU, but we also have a very good GPU, right? So, integrated graphics. And we have found that the integrated graphics is a great place to offload a lot of that parallelism that's needed for doing those memory searches. In addition, we will talk about it a little later. We have a very great source of microarchitectural data called the performance monitoring unit. And as the video show and I was going to, when I talk about the AI, how we actually use that. But at the high level, that data is very critical, along with AI that we use to be able to flag some of these new variants, right? And at the end of it, we are a detection solution, right? Our partners who we work with, they are the ones who are providing the ultimate. At the end of the day, they are doing the security and the actions that are needed. So we do the detection, they take care of whatever else they have to do to protect the organization. So we have SDKs that we provide. We have made optimizations to the drivers to make sure that -- remember, I mentioned earlier, solution is great, but if it's taking 10% of the CPU, it's still on [indiscernible], right? The bar we get from our partners is all the stuff we do has to run under like 1% or 1% to 1.5% of the CPU given in the most busy systems. So a heck of a lot of optimizations we have done of the drivers. So we provide those. We provide these SDKs to our partners, and we work with them very closely to see the deployment. At the end of the day, again, we generate signals. The remediation is still with our partners in the cloud. So -- and we'll get into more details. You'll see some of that in the video coming.
Todd Cramer
executiveYes. And you -- and just to highlight again, so when you think about what threat detection can do, think about 4 capabilities that the ISV has in front of them. That offload for memory scanning and other workloads, which is quite useful. The targeted detectors where Intel's -- you'll see packaging machine learning to get these targeted attacks. Anomalous Behavior Detection which does yet another use case that we'll talk about. And then these new use cases, entirely novel use cases of deep learning and AI on a piece of hardware. So again, these 4 features, we work with these partners to enable over time, and you can check with your account manager if you have one of these EDRs to see what they have in place or learn about the road map with Intel. So let's take a look at the video. And actually, the video, we created a virtual experience that we run at shows. So if you see us at a show of a headset get a better deeper view of this, but this will walk through the components and save us some slide where to just see the animation and action. So I'll play that now.
Ram Chary
executiveThat sounds good Todd. [Presentation]
Todd Cramer
executiveGreat, I hope that gave a broad view of it. So let's turn it over to Ram to look a little deeper into the AI that we've been doing here on client and how it works. So Ram, I think we call this our cake slice, right? So lead us through this.
Ram Chary
executiveYes. Thanks, Todd. Yes, as you saw in the video, you have -- you have this great feature in Intel CPUs, it's called the Performance Monitoring Unit or the PMU. It literally tracks -- I'm an old CPU guy, right? So it really tracks hundreds of microarchitectural events. For instance, cache misses and branch-mispredictions and so on, right? Now any software running on the CPU will leave a micro architectural fingerprint, right? That's the premise. Now this PMU has existed for a long time. It's one of the richest -- it's got a lot of capabilities because it was intended for performance tuning, right? So like any of our developers, I've used it before, I'm sure some of you have, we have a tool called VTune, there are others. Basically, you're running your software to see where is spending most of its time so we can try to optimize. Right? But we import our premises at the end of the day, malware is software, too, whether it's running in a VM or whether it's running the host OS, it's going to run. And so we have kind of reused to repurpose this PMU for detecting these fingerprints left by the malware execution, right? Now a key innovation has been to use AI because there's a lot of telemetry that's coming from the system. But AI has been a critical tool to turn all this telemetry data into some -- into a signal that our partners can do something like, right? This picture start to shows, it's a machine learning model. It's a cross section of it for ransomware. As Todd and I were saying, we call this the cake slice. It's made up of lots of dots, right, colored dots. Each colored dot in that cake slice is a different process that's running on the system. Now as you can see, both good applications and malware will trigger these events, but they do so a little differently. So our models, and I will go into more detail in the next slide, but our models are trained to only raise an alarm when the app behavior falls in that top layer, right? So if you look at this cake model, the icing is bad, right? The cake is actually -- the benign, the good stuff. So any time we see something running and in real time, we actually see the behavior top -- kind of fall on the top layer of the icing layer. But remember, we track it at the thread level, right? Or we could look at it as a VM, but we will give that signal instantly to our partners so that they can then do the remediation, right? They can do -- they can either kill the process, they can sequester the system, whatever they want to do, right, or detonate it in the cloud, they can do all those things, but we give them that early warning signal to be able to detect it. Okay. Now to talk of -- the of cake is making me hungry. Lets go to the next one. Now I think that's -- we have the machine learning. Yes. Okay. Hopefully, you can all see it, the ML slide. So let's talk a little bit more into the machine learning model because to me, this is the crux of what we are building, right? The first part is the futurization aspects. Now like I said, as an engineer, I think the Intel PMU is a beautiful component, right? This is over 500 events that we provide. Now the interesting part for us is we look at all this data for a particular type of attack. Say, ransomware in this case. And we have to curate the best PMU events for a particular type of attack, right? Meaning you have to take the 500 or 1000 events and pick the best 4 or 8. Usually, it's a handful of those. Which are very representative of a few things, right? First, it has to have data effectiveness. We're detecting the number of variants, right? There's a huge number of families, a huge number of variants. We don't want 10 different ransomware models. We just have one ransomware model, right, that for a particular platform. The second thing is it has to be portable between machines, right? We know that at the end of the day, our customers who are buying our PCs for -- like vPro PCs, you're going to have potentially multiple OEMs, multiple configurations, i5, i7s. So for us, it's got to -- this model has to work across all of those, right? Because the absence of it you'll have variations of skew specific ones and that doesn't work for us. It doesn't work for our partners. The last piece is the stability of the model over time, right? So once we build the model it's got to -- we can't -- it's not something we want to be changing on a daily basis because at the end of the day, it's less work for us to keep it more stable and more importantly, it's less work for our partners who in the end of the day have to also integrate it and kind of deployed, right? The second piece is classification. And this is a very interesting thing for me. Our training process takes in -- basically the way we train is we take all these PMU execution data from both benign usages because that's a critical part. You want to eliminate false positives. Remember that cake, cake is good. And malware. And we use supervised learning, so we basically tell the model which is which, right, this is good one, this is not good. But then the interesting part, the power of our solution and have a great mission learning team that works on it behind day in and day out, is we leverage unsupervised learning to kind of let it organically find the most unique behaviors and collections amongst these various data strains in malware right? Because that's something that's what AI is meant for. It kind of can see patterns that we as humans don't. Then the last piece, which is very important is our model at the end of the day has to be built to be small. So that it can be deployed. There is no point building a 100-megabyte model, right? It's very difficult to deployed over the air. So we built very compact models, 2 to 4 meg and often compressed it's less than a meg, right? So that's a lot of the focus is making that compact model as well, which is actually very affected. And the last piece I want to hit on is the kind of the time series part of it, right? So we design -- our models are designed, so a partner can just take it and deploy it, right? And it works for pretty much most environments. But, some partners may want to customize it, right? They may be running it continuously some of them and some of them may be using it as a step-up mechanism, right? They suspect something so they want to run our models. But either is fine. Or we have partners who may care -- who are pretty good at dealing with false positives and they want immediacy of notification. And others say, I don't care if it takes a little longer just -- I don't want any false positives. So we have all these dials. So think of this time series as a sliding window, right? We can either narrow it or broaden it. And it allows our partners for us to customize it for our partners. The sensitivity of the system for a particular implementation. So we have this basic one that works across everyone, but our partners, we work with them all the time to kind of fine-tune it for their own deployments. Anything else you want to add to that?
Todd Cramer
executiveYes, I'll add. And this has been in production on hundreds of millions of systems out there, right? And so behind Ram and his team that are developing the knobs and dials for the ISV and going through the proof of concepts and the integrations with the ISV giving real-time feedback. There's labs behind this we constantly are evolving, like back testing. And I think it's up over hundreds of strains of ransomware variants and actually, I think 300 or 400 strains on the core families, right? And so that constantly evolves. That's the type of thing that you have behind Intel with people, with Ram's team. And then the other thing is, as Ram said, every ISV is different as far as how they're going to trigger and use this in conjunction with their software-based AI in the cloud or what have you. And so over time, the sophisticated years -- we teach them how to evolve this package of machine learning on the client for themselves, right? So this is a very interactive close relationship we have with these ISVs to keep this tuned to keep it working, to keep innovating on it, right? We've been at this for 5-plus years evolving this. And so I'll talk on the next slide about the data that shows you it's working. But...
Ram Chary
executiveAnd the collaboration is very, very big. Yes, because all -- even the -- we run it on -- in our lab settings, right? But when it starts that it runs on hundreds of millions of systems all over the world. So it's running into apps that we have never seen. It really helps us fuel our models and optimize it, working with our partners. Yes, go ahead, Todd.
Todd Cramer
executiveYes, sure. Well, let's look at the data, right? Does it work, right? We know it works because we hear from our partners on these hundreds of millions of systems that it is working, that it is a detection assist that as these software vendors go through industry MITRE ATT&CK testing against each other to score, right? We hear constantly that, hey, these CPU assisted features are quite meaningful in high fidelity in them achieving those results that you see on MITRE ATT&CK test. So we had the idea of approaching SE Labs who does lots of this MITRE testing individually with the major EDRs and so we brought this technology and we said, you're the experts with the labs, you have multiple EDRs you run, you're intimately knowledgeable. You have the ransomware families. You know what's out there. So you design us -- we'll equip you the software, the sample apps, and you design a set of tests here to bring out this. And again, this is one set of test limited data, but they took the top families that you see over there that are -- have evolved out in the industry. And they ran through testing TDT with a major EDR and they said, okay, with that TDT assist, how did it do? 97% detection coverage. And then they said, well, let's turn off the EDR and just run the sample app to see this hardware assist. How is it doing? 93% right? Pretty good coverage. And so again, above this, the EDR has other AI in the cloud that often fires first, right? But it's a good backstop to know that your hardware is confirming what they're seeing in software, raising that detection capability and then all important, as you go back to the graph that Ram had earlier from VirusTotal, we know -- and that's what some of these tests designed is, they design tests for those techniques of fast movers, right, binary obfuscation, cloaking in a VM. Many of the techniques were run at these tests. And you know what we saw that we were pleasantly surprised with is those zero-day tactics that are out there, this is exactly where the hardware showed up to augment. In the cases where the EDR missed it right? So again, the coverage is -- there's overlap, but it is doing and finding in these difficult variants. That's the job it's supposed to do. And then they also deployed the same software with the EDR on our competitor, AMD, and again, there is no hardware assist that works in the same way here. And so you see the score there lower. Same software on a different device. So we're pretty proud of this technology we develop. And actually, SE Labs came out with their annual report, and they said, "Hey, that's pretty nifty." They gave us their innovative award last year in their annual report. So again, that's what we're doing this webinar. We're trying to bring an understanding of -- think about the hardware, don't just think about the software. The hardware matters in the assist that it provides. And if you want to scan that they go through all of their setup, their tests, the technical results. And you can look at that report that's published live on their site there. Again, it's sort of a hands off. We gave them the software. They ran the test, they published the report. So let's talk a little bit more how these features work together. There's not just the targeted CPU assisted ransomware. Let's bring it to speed on some other hardware features and how these are going to build defense and depth. So here, we're going to talk about -- we talked about the accelerated memory scanning. Not -- this is different from the targeted ransomware or detection, but many of our ISVs choose to use our GP offload because it's very good to go after fileless attacks. And so we're going to return to the kill chain in a minute to see where this very first feature and other memory protections that we have try to catch attacks at that first instance and another one is Intel Control Flow Enforcement Technology, works on Intel 11th Gen systems forward. It's a shutdown feature. It prevents entire classes of JOP and ROP attacks to memory, right? So now you got 2 features looking where these fileless attacks are going on Intel systems. And here, you just see a slide -- CrowdStrike actually has this implemented. Other, defender -- other vendors as well have it. And so again, you'll see the software and the hardware innovations. And so this just to preview you on that first fire feature, so to speak. And now we're going to look at on the next slide how this again, here's the kill chain. And so in the blue layer there, I gave -- we gave just a smattering of the hardware features that you get many of these are working at different layers of the stack below the OS security that's innovated and implemented by your OEM software and the BIOS controls. Some of these are what builds the chassis for virtualization-based security that Microsoft has in Windows 11 that you're toggling on. And then some of these in these boxes are the things that we've talked about in this webinar. But now you see, when you talk about a notion of defense in depth, what you're really talking about is you have multiple software features and now hardware features that work together to cover the same attack if the EDR software missed it with their AI on the cloud, guess what? The accelerated memory scanning may find that Cobalt Strike that's trying to deploy into memory. And it stopped right there. It hasn't moved. The other feature, Anomalous Behavior Detection. We haven't talked about that, but what it's doing is monitoring processes for first indications of living off the land attacks. So if they're trying to hollow out the software and that gets very hard for the EDR to detect. You've got a CPU sensor looking for that, right? So from its first entry is a fileless attack to actually infiltrating the process. You've got 2 features. And then moving forward, as it would try to spin up that gadget in a ROP attack, you've got CET working for you. So these are all the far shift left, first indicators where you want to attack it, should it get through everything on one machine, now you have the milliseconds, a CPU assisted ransomware detector that fires up and says, we're seeing this on this machine or multiple machines. So this notion of defense in depth isn't just a software thing. It's a blend of software optimized by hardware, and it builds that, right? And that's the name of the game in security. Build all the features that work together and are integrated. So anything else Ram or we'll go to our poll.
Ram Chary
executiveNo, no, I think you did it all. The thing that I -- one thing I wanted to add is many of these features like what we said with this Anomalous Behavior Detection, very powerful feature, also coming from the PMU. There's a lot of data coming from it. So a lot of the work my team does is optimizing it so that instead of taking 10% of the CPU takes 1%, right? So that for our partner, it becomes more relevant, it's easier to deploy. So a lot of that enabling that we do across the board. And that's true for a lot of the work in tell us with CET as well.
Todd Cramer
executiveOkay. Well, we've looked at the attacks. We see what Intel does today is one of the few AI in endpoint technologies. And now we're going to start to peak into the future. But before we go there, are you interested in this hardware optimizations that we talked about. High interest, some interest, no interest. I mean we're always curious. We kind of think of hardware security as the hidden feature people don't think about, right? They think about, oh, it's accelerating encryption. But now you see the hardware actually does a lot more that's integrated in the core detection of that. And that's what this webinar is about is to give you the interest. So -- well, super. I think that's what we want to see. So hopefully, Ram, there's some valuable stuff here, and we'll close it out. And in just a minute here. Great. So it looks like 84% interest and some interest. So let's unpack it more. So if we can get that up to 100%, Ram. So let's move into the next phase here. Let's look at the near future, near future, I mean, months away here, right? We have some new capabilities that we're bringing to market. And you probably have seen from Pat, our CEO at innovation, Intel Core Ultra Processors that has our XPU or different capabilities. Obviously, Intel for the CPU and many -- for some of the limited AI that our EDR partners run, they'll leverage the CPU for that, right? Our partners are very careful about trying to keep the security agents performance envelope sub-2% to not disrupt the user experience. And that's where we help them, right? We've got this GPU with hundreds of execution units. And in a corporate environment, people aren't playing games this is a useful tool. And so we're able to take our own machine learning for these targeted detectors, other workloads like memory scanning for the ISV, they call our API and TDT and they offload it to the GPU, and some of them see a 7x boost in the ability to scan that memory, right? Scan more, detect more. That's where the horsepower of the silicon comes in. And then we'll talk a little bit here about this brand-new tool, a neural processing unit, and it's ideal for sustained workloads and deep learning type of algorithms. Now we're going to get into a different class that does new things for cybersecurity and so that's just the internal on it, and we'll let Ram unpack a little bit more of how -- what we're doing with our partners on this NPU.
Ram Chary
executiveOkay. Great. Okay. So I think the -- with the NPU there are -- let me give you a little background, right? So today, a lot of this -- if you look at a particular attack that's going to happen on your system, the detection mechanism that is used by -- typically used by our partners is they try to stop a lot of those, but if they are suspicious of something they'll take that application of whatever that is and run it in the -- try to detonate it in the cloud, right? So -- and that's a very good technique to actually find out if that's malware or not. But if you take that particular use case, which is how do you actually try to find those kinds of problems, there are a lot of costs involved with that, right? You got to move all that to the cloud and just the overhead in terms of latency, that's something that you don't want to incur that cost every time. So what if you could -- you don't have to do that, right? What if you can do a lot of that initial tree processing on the PC itself. Remember, Todd said 90% of the signals are coming on the PC. So the question we are asking is, can we do some other processing on the PC itself to be able to give a higher indication or higher confidence on whether they think a particular type of application is bad or it's suspicious, right, based on a lot of the data that we are getting working with our partners. So that's one of the scenarios where we can use -- and again, I mean you're now talking about like pre-execution analysis. There's a lot of data that it's orders of magnitude more data than say what we are just getting from the CPU. So deep-learning is a very good use case for that. And we believe the NPU is a perfect place to run it with Meteor Lake coming up. But as one of the things we are finding as we talk to our partners is each of them has, as expected, that's the nice thing about the richness of the ecosystem, right? Some of them want to look at the deep learning applications for antiphishing. Some of them want to look at it from the prospective data loss prevention. And I talked about the pre-execution analysis or early execution analysis. That's one example. And basically, the goal as others can look at the new incident of attack discovery, right? So there are a lot of different techniques -- and where -- and we will go into a couple of those later, right? And our goal is to work with our [indiscernible] optimizer for our platform so that together, we have a great solution. So...
Todd Cramer
executiveWell, super. -- let's dig in. I think the...
Ram Chary
executiveLet me -- can I go on this one Todd?
Todd Cramer
executiveGo right ahead, Ram.
Ram Chary
executiveYes. Okay. So very quickly, right, when you look at this picture, let's talk about -- I look at it as 3 things, right? What problem is AI solving? What data is used to build the AI? And at the end of the day, where this AI run, right? Remember, Todd was saying the relevance of our XPUs. So in the simple use cases, right, when we are looking at early indications, the memory standing and so on. A lot of that -- at the end of the year, by the way, the current scenario is lot of that ISV deep learning is running in the cloud. But in this scenario, we are improving the signal quality, right, of the data that's actually going in. So it gives them better indications of IOAs. That's the first one. And there, as I mentioned earlier, there's a lot of intelligence scanning that's happening for memory resident software or malware and we are offloading that and that's the accelerated memory scanning Todd mentioned, CrowdStrike, a bunch of others have deployed it, we use GPU offload to be able to do that, right? Then there is -- by the way, we can run some of these on the CPU too. Our goal is always use the best XPU on the platform, right? It's not like some of these techniques will stop working. We are just trying to optimize it. Now as we get further down, right, you are now talking about what Todd was saying. You can look at Anomalous Behavior Detection value, looking at control flow attacks, or supply chain attacks sometimes where something is changing in the way the application is behaved right? And here again, we use -- so in those scenarios, think of it as an engine light notification. We tell our partner, hey, this application is behaving differently from what it's supposed to do, and they then do the remediation steps. We use a CPU, a lot of CPU telemetry as well as GPU offload. At the end of the day, the machine learning , deep learning is still happening in the cloud. Now with the next one on the right, is where we are starting to bring the machine learning or the AI to the endpoint, right? And everything that we talked about, this targeted detectors I spent a lot of time talking about the models. That's what we have today. right? And that's something that, again, multiple partners have deployed and hundreds of millions of systems. And that's -- there, the data is actually sourcing from our CPU -- the PMU that I mentioned. B, Intel of designing that machine learning models and working with our partners to deploy it, and it runs on the CPU, but we also -- when the GPU is available, we will also offload it to the GPU. And then the last one that where we are going with it is where we are actually looking at some of these new types of attacks, right, whether it's DLP or antiphishing or pre-execution. There, a lot of the data, in fact, comes from our partners. They have a huge amount of data on benign and malware behavior. We take the data, we work with them to optimize it. And again, we run it on -- in this case, we hope to run on the NPU, right? Go ahead Todd.
Todd Cramer
executiveLets do this. No, I'm just going to speed this up just to kind of close it out. I was just going to say, we at Intel, obviously, we do -- we work with lots of tools, right? There's lots of ways that developers are creating AI to run on Intel systems. So there's this close collaboration let you write as a developer, your AI and the tool of choice and have that work on the GPU. So there's lots of work involved here. And why don't we just move it to the questions here. And as we go before that, I'll remind you, the assets that we have, we have some videos from our partners on the CPU-assisted ransomware detection. We have an ABI Research report that in 7 pages really recaps what we talked about today. We have the SE Labs report linked. We have some below the OS security white paper. So again, a rich set of assets, if you want to go grab those and take them away. And then for those that have to leave at the top of the hour, you can do that. Otherwise, we'll go another couple of minutes here and start answering some questions.
Todd Cramer
executiveSo why don't I take the first one, Ram. Wondering what gets detected by TDT is that, for instance, low-level calls to encryption CPU routine. So I guess it's -- what is exactly is it doing on the microprocessor architecture with the AI? What is it leveraging from that?
Ram Chary
executiveRight. I can explain this, right, very briefly. We are looking for behavior, right? So for instance, in the case of ransomware, we are looking at the point where an encryption is actually happening. And our entire models have built to delineate good encryption, right, that a whole lot of applications do. This is from -- this is ransomware specific encryptions. And we do that very quickly because of all the data and the local processing with AI. So we are not looking at high-level calls. We are actually looking at the actual point where the execution is happening. We give the notification, as I said, at the threat level to our partners for remediation. Hope that clarifies.
Todd Cramer
executiveRam, here's another interesting one. Are there any hardware features that were introduced in silicon just for TDT. And I know your team has a close collaboration on teams driving the telemetry density, et cetera. So there's a relationship.
Ram Chary
executiveYes, it's a 2-part answer. First, in the first part, our goal is to make this platform work. I mean this technology work on as many platforms as possible on day 1, right? So we are -- and that helps our partners, right? The more percentage of systems our partners can deploy the technology better for them. And we don't want to be delaying new features at the security level things move fast. So we are not usually dependent on new silicon features are -- which inevitably sometimes require support from OS. So those are long lead items we try to avoid. To a large extent, we just use what's already there and repurpose it because then you can deploy it on already existing systems out in the field. That said, as in many of these cases as we work in the space, we kind of find optimizations that would help us be that much more efficient, say, run faster, and we influence our silicon road map. So those features will be coming in, in the future and we adapt it, right? So it's a little bit of both, but our goal is not necessarily to depend on brand new features to show up because the problem we are trying to solve are in today's systems, too. So now there are cases where the new brings a brand-new capability. So we are very actively working to try to see how we can bring even more AI very logically from [ after that ] to the PC.
Todd Cramer
executiveAll right. I'll take this one. And what is the -- with the high cost associated with ransomware remediation, remember that average $1.4 million. fees, how does Intel technology aim to mitigate? Well, you see we're on the detection and to hopefully stop it from its attack objective. But there's other vPro features, right? When you buy a vPro machine, there's vPro management and remediation that we work with RMM vendors and others and even security vendors to give that unique chipset-level remediation of vPro, right? Wake a device that's a remote worker, send a patch -- firmware patch ensure that it reliably installs. Remote Secure Erase the remote device. So there's more than just security that you get that helps with it across that attack kill chain, that's unique to vPro, right? The next one, how does the integration of AI on the client side change the response to ransomware threats when it comes to third-party integrations. I would just -- I'll start us off Ram is saying, the third-party integration of the EDR itself, sure, that's part of the core enabling of getting ransomware created. But most of these software vendors have what's called XDR capabilities, right? They are exposing the threat telemetry that they find and extending it to a rich ecosystem of the other vendors, SIM vendors, other categories of software or even run NDR by system integrators, right? So this valuable Intel threat detection events is flowing through beyond just the ER to their partners that help build the threat defense that you have here. I don't know if you have anything else to add on that Ram or?
Ram Chary
executiveNo [indiscernible]
Todd Cramer
executiveWe'll take one more question here. Well, I'll let you get it. Can you give some specifics on how TDT interacts with leading EDR partners to bolster overall security against evolving threats. I feel like we covered that, but maybe there's another point on evolution of threats and how it...
Ram Chary
executiveYes, I can briefly say, right? I think you hit a bunch of those. For instance, CET is an extremely good technology to detect a whole lot of types of attacks, right? The ROP attacks and so on. And vPro has a whole list of that. As you said, defense and depth right from the virus level we have various features that actually help that. TDT is a part of that solution. And some of the things we do in TDT today are kind of the last tip, right? If stuff escapes, we catch it. But as we said, AMS and some of the other features we do, are also useful in our partners detecting these attacks sooner. It's an incremental -- and our partners love it, right? They are deploying it. And Todd, you can take the last one, it I was wondering -- the [indiscernible] Intel work with partners and mandate the use of telemetry. The thing that we are finding is, we don't need to mandate. We don't want to mandate anything, right? Our goal is to build solutions. And if our partners see value, they will deploy it. and we work with our partners to do so. And what I'm gratified to see is the technology that we're building, our partners are really liking it. And so that -- we like that model we just show them the data and work with them to make their solutions better.
Todd Cramer
executiveWell, super. With that, I think we had a good dialogue here. I learned some new things from Ram here. And so good to have our true expert speaker with us. I hope you got something out of this. Again, if you have more questions on this technology ask your Intel account manager, here's your post-event survey. So for those left on the call, we appreciate if we hit the right level for you. Thank you.
Ram Chary
executiveThanks.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Intel Corporation transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Intel Corporation earnings transcripts and 248,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.