In a significant development in the cyber security sector, RAD Security has introduced the industry's pioneering AI-powered incident investigation capability, designed to enhance behavioural detection and response. This innovation promises to address the prevalent issue of false positives that burden security teams relying on traditional signature-based methods.
The new offering from RAD Security combines AI-driven investigation with behavioural, signature-free detection techniques, aiming to alleviate the workload of overstressed security personnel. According to CTO and Co-Founder Jimmy Mesta, "By definition, signatures are stateless, making investigations based on the signature-focused approach inaccurate and tedious." He emphasized the advantage of AI-powered investigations, which advance the accuracy of behavioural detection, enabling much quicker and precise incident assessments.
AI and behavioural techniques in action
RAD's approach merges behavioural drift analysis with AI for comprehensive incident investigations. This combination mitigates false positives by correctly interpreting potential threats, such as reverse shells and unapproved data access, which might otherwise bypass standard signature detection. Through this strategic unification, RAD's solution provides enhanced analysis of both malicious and benign anomalies.
RAD's approach merges behavioural drift analysis with AI for comprehensive incident investigations
The shift from signature-based to behavioural security strategies is not a new trend; it's been gaining ground across various domains of cyber security. Despite the dominance of signature-based methods in cloud environments, RAD Security's behavioural-based Cloud Detection and Response (CDR) solution aims to offer real-time insights into zero-day threats by contextualizing detection through identity and infrastructure data.
Adapting to the changing workforce landscape
The industry faces challenges like workforce reductions and skill shortages, with 22% of security professionals experiencing layoffs and 65% reporting burnout. Despite these pressures, cloud-native operations are expected to dominate by 2025, necessitating robust detection systems to combat the rising occurrence of zero-day vulnerabilities in cloud environments.
Recent innovations from RAD Security
- Amazon EKS Add-on: RAD Security is now available as an Amazon EKS Add-on in the AWS Marketplace, allowing customers to leverage real-time Kubernetes risk management and signatureless detection.
- Automated AI Investigation: Utilising large language models (LLMs), RAD rapidly assesses behavioural detections for real-time incident evaluation.
- Findings Centre: This feature provides a user-friendly interface for streamlined detection and investigation processes.
- RAD Open Source Catalogue: Includes updated behavioural fingerprints and new open-source image details to enhance standards.
RAD Security is actively engaging with the community at the Black Hat Conference, showcasing its advancements in booth #219 at Startup City. The team will also present their innovations as finalists in the Startup Spotlight competition at the Innovators and Investors Summit.
RAD Security takes the stage as a finalist in the Black Hat Startup Spotlight Competition, it unveils the first-ever AI-powered incident investigation capability for behavioural detection and response. Today, cloud security is based almost exclusively on signature-based detections, which are notorious for burdening security teams with false positives.
RAD Security is the first to combine AI-powered incident investigation with behavioural, signature-less detections, to significantly reduce false positives and provide much-needed relief for overburdened security teams.
Signature-focused approach
“By definition, signatures are stateless, making investigations based on the signature-focused approach inaccurate and tedious,” says CTO and Co-Founder Jimmy Mesta. “By adding AI-powered investigations to behavioural detection, which is already a step ahead of signature-based detection in accuracy, security teams can quickly get light years ahead in the accurate assessment of incidents.”
RAD’s behavioural approach and AI-powered investigations result in the lowering of false positives on their own; but by putting these two capabilities together, RAD enables security teams to achieve a multiplier effect. The enhanced accuracy of behavioural methods versus signature-based methods is easily demonstrated using multiple examples of attack tactics like reverse shells, access to sensitive data, and a Sudo CVE.
Behavioural drift event
In these examples, while signatures can be easily bypassed by avoiding the exact parameters, they are detected by RAD’s behavioural solution. By the same token, a behavioural drift event is not always a malicious event, so the addition of the AI investigation capability ensures additional accuracy. AI is particularly suited for looking across large sets of data and quick contextualisation, making it a natural investigation tool and engine to analyse benign versus malicious drift.
Throughout the history of cyber security, and most famously in the endpoint and network security markets, signatures have eventually been replaced by behavioural methods in response to an evolving threat landscape. Today, the cloud security category is nearly entirely composed of signature-based approaches with runtime security and Cloud Workload Protection (CWPP) that are standalone or part of a broader Cloud Native Application Protection Platform (CNAPP).
Cloud native environments
In sharp contrast to signature-based CNAPPs, or posture-focused Cloud Security Posture Management (CSPM), RAD Security’s Cloud Detection and Response (CDR) solution creates behavioural baselines of unique good behaviour to detect zero day attacks, enriching detections with real-time identity and infrastructure context that inform response actions.
More and more, detection and response is being accomplished by fewer and fewer dedicated people, with 22% of security professionals reporting recent layoffs at their company. The workforce reductions are an even more acute pain in cloud security, with 65% of cybersecurity and infosecurity professionals claiming burnout due to skill gaps. Even though a full 95% of IT decision makers feel their team has been negatively impacted by the cloud security skills gap, cloud native adoption continues, and analysts predict that, by 2025, 95% of new applications will be built using cloud native workloads. Zero days like the XZ Backdoor are now a regular occurrence, making detection and response in cloud native environments more important than ever.
Signatureless cloud detection
RAD Security has introduced multiple new features to help security teams adopt new innovation that will help them address these alarming trends and emerging threats:
- Amazon EKS Add-on: RAD Security is now available as an Amazon EKS Add-on in the AWS Marketplace for Containers. This means customers can now provision the real-time KSPM and runtime features of the RAD platform directly from EKS, for real-time visibility into their Kubernetes risk as well as signatureless cloud detection and response.
- Automated AI-Powered Investigation: RAD Security uses LLMs to quickly analyse multiple behavioral detections and determine whether an incident is malicious or benign, including real-time infrastructure and identity context.
- Findings Centre: All incidents are now available in an easy to navigate console, making detection and investigation easier and quicker.
- RAD Open Source Catalogue: New version details and new open source images have now been added to the RAD Catalogue, detailing the changes in behavioural fingerprints over time and bolstering the behavioural workload fingerprint standard.
Schedule a meeting with the RAD Security team at the Black Hat Conference this week to discuss improving detection accuracy for attacks in your cloud environments. The team will be exhibiting at booth #219 in Startup City, and at 4:45PM EST they will be presenting at the Innovators and Investors Summit as one of the four finalists in the Startup Spotlight competition.