Summary is AI-generated, newsdesk-reviewed
  • RAD pioneers behavioural detection for cloud native environments at RSA Conference Innovation Sandbox.
  • Signature-based methods fail against cloud native attacks; RAD uses workload fingerprints instead.
  • 95% of new apps to be cloud native by 2025, increasing need for advanced security.

RAD Security has launched a pioneering behavioural detection and response solution specifically designed for cloud native environments. This announcement coincided with CEO Brooke Motta’s presentation at the RSA Conference Innovation Sandbox in San Francisco.

Traditional signature and anomaly-based detection methods have proven ineffective against attacks like the recent XZ Backdoor. RAD's new platform introduces a unique approach by establishing behavioural baselines through workload fingerprints, enabling real-time attack detection. This innovation also integrates real-time infrastructure and identity context to prioritise responses effectively.

Moving beyond signature-based detection

Jimmy Mesta, CTO and Co-Founder of RAD Security, articulated the growing challenge as cloud native environments expand. "Security teams can no longer rely on signature-based detection that only works after the attack, or false promises from AI and machine learning models based on insufficient samples of cloud attacks. Security teams need to respond to cloud native attacks as they happen, with clear prioritisation across workloads, infrastructure, and identity," explained Mesta.

The prevalence of container usage in production is notable, with 70% of teams utilising them, and experts estimate that by 2025, 95% of new applications will adopt cloud native workloads. A survey reveals that 90% of teams using containers and Kubernetes encountered an incident in the previous year, with 95% of IT decision-makers acknowledging the detrimental impact of the cloud security skills gap.

Understanding cloud native behaviour

The XZ Backdoor software supply chain attack highlighted the deficiencies of current detection systems

The XZ Backdoor software supply chain attack highlighted the deficiencies of current detection systems. 

Existing methods identified threat signatures only after delays, and anomaly detection often missed attacker techniques exploiting normal processes. To counter such zero-day attacks, a pre-emptive behavioural profile of the environment is essential. RAD's behavioural fingerprints rely on the principle that most cloud native workloads maintain a consistent set of core behaviours. Deviations from these norms indicate potential threats.

Enhanced workload visibility

RAD's platform leverages ITDR and KSPM capabilities, providing essential context to reduce noise and enhance the understanding of detection impacts. This approach contrasts with CSPM and CNAPP vendors, who leave teams unaware of dynamic changes across cloud native identity, infrastructure, and workloads.

RAD's launch builds on the prior release of its open-source fingerprint standard and Cloud Native Identity Threat Detection & Response (ITDR). Over a dozen firms have incorporated RAD to create environmental fingerprints, witnessing a threefold increase in ARR last year, alongside a 219% net retention rate. The growth of cloud native technological priorities is further evidenced by a 60% growth in customer contract value, with nearly half of the new ARR stemming from existing customer expansions.

New features and innovations

Additionally, AI and LLM-driven analysis classifies drift events into known attack types

The latest release includes several advancements: RAD can now create behavioural workload fingerprints and detect changes for both custom and open-source containers at runtime. A newly configured eBPF sensor offers enhanced flexibility, requiring minimal permissions and a smaller footprint. It also enables customers to take various response actions such as pod termination, labelling, or quarantining. 

Additionally, AI and LLM-driven analysis classifies drift events into known attack types, improving incident categorisation. An integrated workflow manager allows automated response setups, facilitating actions like notifying teams, adjusting settings through AWS API, or initiating Terraform runs.

For those interested in learning more about RAD's cloud native behavioural threat detection and response capabilities, visit their innovation showcase at the RSAC Innovation Sandbox competition or contact them to start developing unique behavioural fingerprints.

In case you missed it

Hikvision solution boosts Muçum flood preparedness
Hikvision solution boosts Muçum flood preparedness

When Brazil’s Taquari River threatens to overflow, the Municipality of Muçum no longer waits and watches—it knows. Using Hikvision’s water-level detection...

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...