{"id":38538,"date":"2019-06-19T09:11:23","date_gmt":"2019-06-19T08:11:23","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=38538"},"modified":"2019-06-19T09:12:03","modified_gmt":"2019-06-19T08:12:03","slug":"darktrace-expert-on-the-risks-of-collaboration-on-the-cloud-and-the-role-of-ai","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2019\/06\/19\/darktrace-expert-on-the-risks-of-collaboration-on-the-cloud-and-the-role-of-ai\/","title":{"rendered":"Darktrace expert on the risks of collaboration in the cloud and the role of AI"},"content":{"rendered":"<p><em>Justin Fier, Director of Threat Intelligence and Analytics, Darktrace, discusses the major vulnerabilities seen in Software as a Service today and looks at real life examples of attacks where AI cyberdefences have been able to prevent a breach.<\/em><\/p>\n<p>It\u2019s no secret that collaboration is the bedrock of business. In fact, a <a href=\"https:\/\/www.forbes.com\/sites\/adigaskell\/2017\/06\/22\/new-study-finds-that-collaboration-drives-workplace-performance\/#29d6cb5d3d02\">Stanford University study<\/a> demonstrated that merely priming employees to act in a collaborative fashion \u2013 without changing their environment or workflow \u2013 makes them more engaged, more persistent, more successful and less fatigued.<\/p>\n<p>To digitally optimise this biologically ingrained capacity for teamwork, businesses the world over have adopted Software-as-a-Service (SaaS) applications that facilitate the sharing of information between multiple users.<\/p>\n<p>Run via centralised, cloud-hosted data centres rather than on local hardware, such applications offer financial and technical benefits to companies of all sizes, from storage savings to reliable connectivity to support speed. Yet it is their collaborative nature that has positioned SaaS software at the heart of the modern enterprise.<\/p>\n<p>At the same time, the interactivity of cloud services renders them an attractive target for advanced cybercriminals, who can often leverage a single user\u2019s SaaS credentials to compromise dozens of other accounts.<\/p>\n<p>And while leading SaaS vendors conform to high security standards, the cyberdefences they employ nonetheless have a common weakness: human error on the customer end.<\/p>\n<p>By launching sophisticated attacks, today\u2019s threat actors are increasingly gaining access to cloud services through the front door, necessitating a fundamentally different security approach that can detect when credentialed users behave \u2013 ever so slightly \u2013 out of character.<\/p>\n<p><strong>Sensitive file access <\/strong><\/p>\n<p>Among the key challenges of SaaS security is balancing the convenience of open access to information with the imperative of protecting privileged assets.<\/p>\n<p>Indeed, with hundreds or even thousands of employees sharing a welter of files and databases at all times, safeguarding SaaS applications against insider threat is extraordinarily difficult with traditional security tools, which use fixed rules and signatures to catch only known, external cyberattacks.<\/p>\n<p>Rather, detecting when credentialed users enter parts of these applications where they don\u2019t belong requires AI security systems that understand their typical online behaviour well enough to spot subtle anomalies. And as employees\u2019 responsibilities and privileges inevitably change, such systems must be able to adapt while \u2018on the job\u2019.<\/p>\n<p>The necessity of this AI-driven approach to cyberdefence recently came to light when a serious threat was detected by AI on the network of a European bank.<\/p>\n<p>After stealing credentials or otherwise gaining access to a SaaS service, the cybercriminals frequently ran scripts to identify files containing keywords like \u2018password\u2019 to find files that stored unencrypted passwords.<\/p>\n<p>As they had already breached the network, the attackers could have reasonably expected to be in the clear \u2013 having already successfully bypassed any conventional security controls.<\/p>\n<p>However, while these attackers would likely have exploited the cleartext passwords to escalate their privileges and further infiltrate the organisation, Artificial Intelligence was able to flag the activity as anomalous for the bank\u2019s particular network because it breached the following model: \u2018SaaS\/Unusual SaaS Sensitive File Access\u2019.<\/p>\n<p>Ultimately, the AI\u2019s nuanced and evolving understanding of what constitutes \u2018unusual\u2019 behaviour for each of the bank\u2019s users and devices proved critical, given that the suspicious file access may well have been benign in other circumstances.<\/p>\n<p><strong>Social engineering<\/strong><\/p>\n<p>Perhaps the most difficult cloud-based attacks to counter are those that rely on social engineering, since they involve deceiving employees into handing over their credentials and other lucrative information voluntarily.<\/p>\n<p>In these cases, AI anomaly detection is the optimal security strategy, as thwarting a social engineering threat before it\u2019s too late means protecting employees from their own mistakes.<\/p>\n<p>In 2018, a device on the network of a UK property development company that had attempted to connect to a rare external domain was detected, just two seconds after landing on office365.com.<\/p>\n<p>The domain had a suspicious name and offered HTTP connections to a form containing sensitive data transmitted in plain text, which would be vulnerable to a man-in-the-middle (MITM) attack.<\/p>\n<p>Further investigation indicated that an employee at the property development company had been tricked by a shortened URL in a phishing email to visit the suspicious domain.<\/p>\n<p>Despite the user actively clicking on the URL to visit the page, Artificial Intelligence flagged the event as threatening due to the rarity of the destination domain in comparison to the company\u2019s normal network activity.<\/p>\n<p>AI has consistently demonstrated this ability to provide a safety net for human error \u2013 flagging anomalous connections and rare domains regardless of how well they may be disguised to the unsuspecting user.<\/p>\n<p>From social engineering attacks to insider threats to stolen credentials, the risks inherent to SaaS are largely user-dependent.<\/p>\n<p>As a consequence, any security tool up to the task of defending SaaS applications must understand how these users work, evolve and collaborate.<\/p>\n<p>Indeed, it is precisely the sought-after interconnectedness and collaborative nature of SaaS platforms which makes the potential reward for attackers so great, as a single breach could allow them to compromise an entire company.<\/p>\n<p>Yet the efficiencies promised by SaaS need not come at the cost of security, since the latest AI cyberdefences shine a light on even the most nebulous traffic in the cloud.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Justin Fier, Director of Threat Intelligence and Analytics, Darktrace, discusses the major vulnerabilities seen in Software as a Service today and looks at real life examples of attacks where AI cyberdefences have been able to prevent a breach. It\u2019s no secret that collaboration is the bedrock of business. In fact, a Stanford University study demonstrated [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":38543,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,13],"tags":[3211,3355,22,3106,9487,9488,9489,9490,217],"class_list":["post-38538","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-top-stories","tag-ai","tag-artificial-intelligence","tag-cloud","tag-cybercriminals","tag-cyberdefences","tag-darktrace","tag-director-of-threat-intelligence-and-analytics","tag-justin-fier","tag-saas"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/38538","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=38538"}],"version-history":[{"count":2,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/38538\/revisions"}],"predecessor-version":[{"id":38542,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/38538\/revisions\/38542"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/38543"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=38538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=38538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=38538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}