Jul 28, 2017 · 17m · a16z

Giovanni Vigna

Giovanni Vigna · 15m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

At the Andreessen Horowitz Academic Roundtable, Computer Science Professor and Lastline CTO Giovanni Vigna presents "Innovate to Protect," detailing the evolutionary arms race between evasive malware and enterprise defenses. He demonstrates how full-system emulation and continuous heuristic innovation are essential to countering active human adversaries.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 0.0 Guest teaching 5.0 Guest disagreement 0.4 The host pushing back 0.0
05100:0010:000:31–3:14 · The host as informed peer 0/10 Speaker Profile: UCSB, Lastline, and Shellphish Giovanni introduces his academic background at UCSB, his startup Lastline, and his CTF team Shellphish winning DARPA Cyber Challenge funding. The segment is a solo monologue presentation with no host participation.3:14–7:26 · The host as informed peer 0/10 Cybercrime Evolution and Targeted Attacks Giovanni outlines the evolution of cybercrime from mass remote attacks to targeted social engineering, sharing an anecdote about stealing a Russian botnet. The segment contains no host interaction.7:26–11:39 · The host as informed peer 0/10 The Cybersecurity Arms Race: From Antivirus to Sandboxes Giovanni details the arms race between detection and evasion, explaining how malware detects sandboxes via specific user profiles like Andy and drawing parallels to Volkswagen emissions cheating. No host interaction takes place.11:39–14:06 · The host as informed peer 0/10 Innovation Metrics and Antivirus Detection Latency Giovanni discusses creating costly economic asymmetries for attackers and presents empirical VirusTotal findings showing a two-week signature generation delay. The segment is entirely presenter-driven.14:06–17:11 · The host as informed peer 0/10 Full-System Emulation and Instruction-Level Visibility Giovanni explains full-system emulation for instruction-level visibility and connects security limits to the computer science Halting Problem. The presentation concludes without host intervention.0:31–3:14 · Guest teaching 3/10 Speaker Profile: UCSB, Lastline, and Shellphish Giovanni introduces his academic background at UCSB, his startup Lastline, and his CTF team Shellphish winning DARPA Cyber Challenge funding. The segment is a solo monologue presentation with no host participation.3:14–7:26 · Guest teaching 5/10 Cybercrime Evolution and Targeted Attacks Giovanni outlines the evolution of cybercrime from mass remote attacks to targeted social engineering, sharing an anecdote about stealing a Russian botnet. The segment contains no host interaction.7:26–11:39 · Guest teaching 6/10 The Cybersecurity Arms Race: From Antivirus to Sandboxes Giovanni details the arms race between detection and evasion, explaining how malware detects sandboxes via specific user profiles like Andy and drawing parallels to Volkswagen emissions cheating. No host interaction takes place.11:39–14:06 · Guest teaching 5/10 Innovation Metrics and Antivirus Detection Latency Giovanni discusses creating costly economic asymmetries for attackers and presents empirical VirusTotal findings showing a two-week signature generation delay. The segment is entirely presenter-driven.14:06–17:11 · Guest teaching 6/10 Full-System Emulation and Instruction-Level Visibility Giovanni explains full-system emulation for instruction-level visibility and connects security limits to the computer science Halting Problem. The presentation concludes without host intervention.0:31–3:14 · Guest disagreement 0/10 Speaker Profile: UCSB, Lastline, and Shellphish Giovanni introduces his academic background at UCSB, his startup Lastline, and his CTF team Shellphish winning DARPA Cyber Challenge funding. The segment is a solo monologue presentation with no host participation.3:14–7:26 · Guest disagreement 1/10 Cybercrime Evolution and Targeted Attacks Giovanni outlines the evolution of cybercrime from mass remote attacks to targeted social engineering, sharing an anecdote about stealing a Russian botnet. The segment contains no host interaction.7:26–11:39 · Guest disagreement 1/10 The Cybersecurity Arms Race: From Antivirus to Sandboxes Giovanni details the arms race between detection and evasion, explaining how malware detects sandboxes via specific user profiles like Andy and drawing parallels to Volkswagen emissions cheating. No host interaction takes place.11:39–14:06 · Guest disagreement 0/10 Innovation Metrics and Antivirus Detection Latency Giovanni discusses creating costly economic asymmetries for attackers and presents empirical VirusTotal findings showing a two-week signature generation delay. The segment is entirely presenter-driven.14:06–17:11 · Guest disagreement 0/10 Full-System Emulation and Instruction-Level Visibility Giovanni explains full-system emulation for instruction-level visibility and connects security limits to the computer science Halting Problem. The presentation concludes without host intervention.0:31–3:14 · The host pushing back 0/10 Speaker Profile: UCSB, Lastline, and Shellphish Giovanni introduces his academic background at UCSB, his startup Lastline, and his CTF team Shellphish winning DARPA Cyber Challenge funding. The segment is a solo monologue presentation with no host participation.3:14–7:26 · The host pushing back 0/10 Cybercrime Evolution and Targeted Attacks Giovanni outlines the evolution of cybercrime from mass remote attacks to targeted social engineering, sharing an anecdote about stealing a Russian botnet. The segment contains no host interaction.7:26–11:39 · The host pushing back 0/10 The Cybersecurity Arms Race: From Antivirus to Sandboxes Giovanni details the arms race between detection and evasion, explaining how malware detects sandboxes via specific user profiles like Andy and drawing parallels to Volkswagen emissions cheating. No host interaction takes place.11:39–14:06 · The host pushing back 0/10 Innovation Metrics and Antivirus Detection Latency Giovanni discusses creating costly economic asymmetries for attackers and presents empirical VirusTotal findings showing a two-week signature generation delay. The segment is entirely presenter-driven.14:06–17:11 · The host pushing back 0/10 Full-System Emulation and Instruction-Level Visibility Giovanni explains full-system emulation for instruction-level visibility and connects security limits to the computer science Halting Problem. The presentation concludes without host intervention.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 9:15 Volkswagen Evasion Analogy

Giovanni playfully lampoons Volkswagen for deploying malware-style sandbox evasion techniques to pass emissions tests, sarcastically citing German integrity.

Hardest push from the host ▶ 8:00 Pushback on Static Analysis Efficiency

Giovanni rejects the industry assumption that static analysis and conventional sandboxes remain adequate, explaining how rapidly polymorphic threats bypass them.

Biggest teaching moment ▶ 14:15 Full-System Emulation vs Sandbox Blindspots

Giovanni educates the audience on why standard sandboxes miss non-privileged memory loops between API calls and how full-system instruction emulation resolves this gap.

The host holds their own ▶ 16:40 Computer Science Theoretical Bounds

Giovanni demonstrates technical depth by linking practical malware detection bounds directly to fundamental computer science theory regarding the Halting Problem.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Speaker Profile: UCSB, Lastline, and Shellphish 0300 Giovanni introduces his academic background at UCSB, his startup Lastline, and his CTF team Shellphish winning DARPA Cyber Challenge funding. The segment is a solo monologue presentation with no host participation.
Cybercrime Evolution and Targeted Attacks 0510 Giovanni outlines the evolution of cybercrime from mass remote attacks to targeted social engineering, sharing an anecdote about stealing a Russian botnet. The segment contains no host interaction.
The Cybersecurity Arms Race: From Antivirus to Sandboxes 0610 Giovanni details the arms race between detection and evasion, explaining how malware detects sandboxes via specific user profiles like Andy and drawing parallels to Volkswagen emissions cheating. No host interaction takes place.
Innovation Metrics and Antivirus Detection Latency 0500 Giovanni discusses creating costly economic asymmetries for attackers and presents empirical VirusTotal findings showing a two-week signature generation delay. The segment is entirely presenter-driven.
Full-System Emulation and Instruction-Level Visibility 0600 Giovanni explains full-system emulation for instruction-level visibility and connects security limits to the computer science Halting Problem. The presentation concludes without host intervention.

Statements from this episode (4)

Assertion Supported
Giovanni Vigna's research team hijacked a Russian botnet to write a paper
“We even captured once an entire botnet. We stole it from the Russian cybercrime gang, and we ran it for a while to understand what information we would collect, and then we wrote a paper on it, because that's what we do.”
Giovanni Vigna Jul 28, 2017 ▶ 3:47
Disclosure
Lastline processes 750,000 malware samples per day, requiring accelerated analysis
“You cannot execute a thousand, a hundred, or in our case, 750,000 samples a day, ah, for an hour, because the computing power would be enormous and incredibly expensive, so you have to speed it up.”
Giovanni Vigna Jul 28, 2017 ▶ 10:08
Assertion Not checkable as stated
Giovanni Vigna's study found no antivirus consistently detects day-one malware
“Actually, there was, in a year that we did the study, there was never one single antivirus that was able always to get the sample the first day.”
Giovanni Vigna Jul 28, 2017 ▶ 13:34
Assertion Supported
Giovanni Vigna says perfect malware detection is mathematically impossible
“So it's impossible really to understand what a program does. So we will always only have heuristics and never the final algorithm that is able to tell this is a good program and this is a bad program.”
Giovanni Vigna Jul 28, 2017 ▶ 16:45
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.