RAD Security has launched a pioneering behavioural detection and response solution specifically designed for cloud native environments. This announcement coincided with CEO Brooke Motta’s presentation at the RSA Conference Innovation Sandbox in San Francisco.
Traditional signature and anomaly-based detection methods have proven ineffective against attacks like the recent XZ Backdoor. RAD's new platform introduces a unique approach by establishing behavioural baselines through workload fingerprints, enabling real-time attack detection. This innovation also integrates real-time infrastructure and identity context to prioritise responses effectively.
Moving beyond signature-based detection
Jimmy Mesta, CTO and Co-Founder of RAD Security, articulated the growing challenge as cloud native environments expand. "Security teams can no longer rely on signature-based detection that only works after the attack, or false promises from AI and machine learning models based on insufficient samples of cloud attacks. Security teams need to respond to cloud native attacks as they happen, with clear prioritisation across workloads, infrastructure, and identity," explained Mesta.
The prevalence of container usage in production is notable, with 70% of teams utilising them, and experts estimate that by 2025, 95% of new applications will adopt cloud native workloads. A survey reveals that 90% of teams using containers and Kubernetes encountered an incident in the previous year, with 95% of IT decision-makers acknowledging the detrimental impact of the cloud security skills gap.
Understanding cloud native behaviour
The XZ Backdoor software supply chain attack highlighted the deficiencies of current detection systems
The XZ Backdoor software supply chain attack highlighted the deficiencies of current detection systems.
Existing methods identified threat signatures only after delays, and anomaly detection often missed attacker techniques exploiting normal processes. To counter such zero-day attacks, a pre-emptive behavioural profile of the environment is essential. RAD's behavioural fingerprints rely on the principle that most cloud native workloads maintain a consistent set of core behaviours. Deviations from these norms indicate potential threats.
Enhanced workload visibility
RAD's platform leverages ITDR and KSPM capabilities, providing essential context to reduce noise and enhance the understanding of detection impacts. This approach contrasts with CSPM and CNAPP vendors, who leave teams unaware of dynamic changes across cloud native identity, infrastructure, and workloads.
RAD's launch builds on the prior release of its open-source fingerprint standard and Cloud Native Identity Threat Detection & Response (ITDR). Over a dozen firms have incorporated RAD to create environmental fingerprints, witnessing a threefold increase in ARR last year, alongside a 219% net retention rate. The growth of cloud native technological priorities is further evidenced by a 60% growth in customer contract value, with nearly half of the new ARR stemming from existing customer expansions.
New features and innovations
Additionally, AI and LLM-driven analysis classifies drift events into known attack types
The latest release includes several advancements: RAD can now create behavioural workload fingerprints and detect changes for both custom and open-source containers at runtime. A newly configured eBPF sensor offers enhanced flexibility, requiring minimal permissions and a smaller footprint. It also enables customers to take various response actions such as pod termination, labelling, or quarantining.
Additionally, AI and LLM-driven analysis classifies drift events into known attack types, improving incident categorisation. An integrated workflow manager allows automated response setups, facilitating actions like notifying teams, adjusting settings through AWS API, or initiating Terraform runs.
For those interested in learning more about RAD's cloud native behavioural threat detection and response capabilities, visit their innovation showcase at the RSAC Innovation Sandbox competition or contact them to start developing unique behavioural fingerprints.
RAD Security releases the industry’s first behavioural detection and response solution for cloud native environments, as CEO Brooke Motta takes the stage in San Francisco for the RSA Conference Innovation Sandbox.
To-date, signature and anomaly-based methods are late and ineffective against cloud native attacks like the recent XZ Backdoor. RAD’s detection and response platform is the first to baseline behaviour through workload fingerprints, detecting cloud native attacks as they happen, while tying in real-time infrastructure and identity context for response prioritisation.
Identity context for response prioritisation
“As the footprint of cloud native environments continues growing, security teams can no longer rely on signature-based detection that only works after the attack, or false promises from AI and machine learning models based on insufficient samples of cloud attacks. Security teams need to respond to cloud native attacks as they happen, with clear prioritisation across workloads, infrastructure and identity,” explains CTO and Co-Founder, Jimmy Mesta.
Today, 70% of teams are using containers in production, and analysts predict that, by 2025, 95% of new applications will be built using cloud native workloads. A recent survey shows that 90% of teams using containers and Kubernetes had an incident in the last year, and a full 95% of IT decision makers feel their team has been negatively impacted by the cloud security skills gap.
Consistent set of core processes
In the weeks following the zero day XZ Backdoor software supply chain attack, cloud native IDS approaches resulted in signatures days and weeks following the attack, and anomaly detection approaches were blind to the set of attackers’ techniques that relied on normal processes. To detect the XZ Backdoor and other zero day attacks, a behavioural profile of the environment would have been required before the attack took place.
RAD’s behavioural fingerprints are based on the fact that the majority of cloud native workloads exhibit a consistent set of core processes, programs and files at runtime. Any drift from this core set of behaviours is suspicious.
Cloud native technologies
RAD fingerprints get critical context from its ITDR and KSPM capabilities to help reduce noise and allow teams to understand the true impact of detections, compared to CSPM and CNAPP vendors that leave teams blind to the real-time changes between cloud native identity, infrastructure, and workloads.
The launch of the detection and response platform follows the release of the open source fingerprint standard and Cloud Native Identity Threat Detection & Response (ITDR). Over a dozen companies are using RAD to create fingerprints in their environment, and in the last year alone, RAD Security has seen ARR has grown by 3 times, with a 219% net retention rate and new logos from highly regulated and digitally mature industries such as insurance, banking and media. At the same time, the current and growing importance of cloud native technologies in the security team’s priorities is reflected in 60% growth of customer contract value, with nearly half of new ARR coming from expansion of current customers.
LLM-driven analysis
New features in this release include:
- Fingerprints and drift for unique containers: RAD can now create cloud native behavioural workload fingerprints and detect drift for custom containers (versus just open source) at runtime
- eBPF sensor: RAD is releasing a newly re-configured, custom eBPF sensor to get around the inflexibility and instability inherent in legacy agents. RAD’s agent requires the fewest and most precise permissions, has more flexibility for correlation of data across the environment, and a smaller footprint
- Response actions: Customers can terminate pods, label pods, and quarantine pods (e.g. prevent network egress from pods) in response to drift detection
- AI/LLM Categorisation of Drift Events: Drift events are classified into different attacks (if known), based on LLM-driven analysis
- Workflow manager: Set up automated workflows to choose how to respond to detections from RAD, whether that's to notify to one or more channels, label a pod to enable security teams to further investigate, kill a pod, or quarantine, open a pull request, run Terraform, call an AWS API to change a setting, and more
Learn more about behavioural cloud native threat detection and response, meet them in the innovation showcase at the RSAC Innovation Sandbox competition, or reach out to get started creating unique behavioural fingerprints today!