Behavioral Detection Replaces IOC Whac-A-Mole
Mike Vizard talks with Nicole Beckwith of Cribl about why security teams need to move beyond indicator-of-compromise detection models built around hashes, IP addresses, domains and signatures. Beckwith explains that attackers can easily rotate low-level indicators, so SOC teams need to shift toward behavioral detection, MITRE ATT&CK-based rule chaining and richer telemetry pipelines. The conversation also explores agentic SOC use cases, AI-driven attack speed, data pipeline strategy and how security leaders can make the business case for modernizing detection engineering.
Transcript
Hey guys, thanks for the throw. We're here with Nicole Beckwith, who's the senior director of security engineering and operations for Cribl, and we're having a little chat about, well, what's wrong with the indicators of compromise approaches that we all seem to rely on? Because, well, I think that they are all dependent upon signatures, and we all know what happens with signatures.
We wind up playing a giant game of Whac-A-Mole. But Nicole's going to explain what we can do to fix all this stuff. Nicole, welcome to the show.
Thank you. Thanks for having me. I'm excited to be here, and this is such a fun topic to discuss.
Right. " Yeah, I think it's a great question, and we have been really doing detection-based alerting for about two decades now. So think about IoCs and how we utilize them within the security operations world.
So an attacker burns a hash or an IP, a domain. Victim A publishes that indicator, everybody else blocks it, and that model has really been the way that we have done business for essentially two decades. And indicators of compromise, we built our AV stacks, our IDSs, our threat intel feeds, and most of the rules within your SIEM based on those IoCs.
So, going back and talking about where IoCs really started, we have to go back to when I was born, essentially, in the 1980s, and thinking about the antivirus products that we had back then. Mm-hmm. And we were doing byte pattern matching.
So it's been a while since IoCs really came onto the scene. After that, we had Snort that came on board, and we were doing network signatures with them. And then we kind of shifted gears a little bit, and we had OpenIoC and we had STIX TAXII, and that really changed the way that we looked at how we operated within the IoC environment and within our detection environment.
So we now had this sort of schema and a transport protocol for these indicators. And because of this, that shifted the entire ecosystem, and we suddenly had this whole economic model around shared indicators. So you had ISACs that popped up.
You had paid commercial feeds that were coming on the scene. You had MISP, and now what we refer to as TIPs, or threat intel platforms, that really started becoming a thing. And then after that, indicators and IoCs became this currency that we shared among the community.
And you would trade these back and forth, either amongst each other or in these shared platforms. And for about a decade, indicators were good, and that's how we operated. It's how we wrote our detections and how we operated the basics of a SIEM.
So that promise held for that decade, but now we're having to take a step back and really rethink how we're doing this, especially since AI has come on board. So to your point, it seems to me like the adversaries have gotten a little more adept at understanding what the good guys are doing, and they're just tweaking their attack a little bit to avoid the signature, and they're getting very clever about their usage of evasion techniques. So does this model that we had around signatures still work, or is it just fundamentally broken?
It is fundamentally broken. So first, the pyramid of pain is really probably the one thing that hasn't changed throughout this entire transformation, right? We're just thinking about it differently.
So instead of talking about the bottom of that pyramid and the hashes and the IP addresses and the domain names, we're pushing further up that pyramid with the tools and the TTPs, and we really need to get to that behavioral-based detection model to be effective. So if you think about what we all like to do, which is impose cost on the adversary, it's really easy for them to burn a hash, right? It just means that you recompile something.
Burning an IP means you run a different VPS. A domain, you register another one for 10 bucks. So as you climb up that pyramid, it gets harder and harder for them to switch what they're doing, and that's really where we want them to be.
We want them to have to fight harder to get into our environment. And so most of the 2010s, we lived at the bottom of that pyramid because that's where the tools and the feeds operated. So now that we're pushing into that behavioral-based detection and AI is changing how we're operating, we're pushing to the top of that pyramid.
And for the adversaries, there are probably three major things that I think have really changed since AI has come onto the scene. The first and foremost is polymorphic and metamorphic malware. So it's really cheap to produce, it's really cheap to scale.
They can change it at a drop of a hat. And so that signature-based static detectionThe foundation layer of the IOC stack is just gone for that class of attack. So it goes out the window, and those IOCs are no longer effective for those detections.
Second is phishing infrastructure. So if you think about it, it used to be that it was really hard to craft a phishing email, and especially for non-English speaking persons. LLMs solved that for us overnight.
And we now have adversaries who can craft phishing emails at scale. They can stand up 10,000 convincing phishing sites within a weekend, and it makes it really easy for them to conduct those attacks. So, those are the first two.
Again, switching up how we see IOCs, because that really kills our detection model. The third is that bespoke tooling. So what used to require a developer on the operator's payroll can now be vibe coded in basically an afternoon or a weekend.
So, you think about custom credential dumpers or custom lateral movement utilities, exfil tools, et cetera. Again, those are degrading every single layer of that pyramid as we go down and back up that pyramid. So we essentially have a whole detection model where the bottom of the pyramid is basically just a noisy enrichment source, and that's what we have to reframe our thinking to understand.
Like IOCs aren't dead, right? They're just being demoted. So they're a piece of context that you correlate into an investigation.
It shouldn't be the thing that your alerts are firing off of now, right? If the cost of launching the attacks is dropping to near zero, how do we drive up the cost of launching them in the first place to the point where it's too painful for them to do? Or has that just become a non-starter conversation for us at this point?
Yeah, we can actually really benefit from thinking about, one, the MITRE ATT&CK framework, but shifting gears to behavioral-based detections and TTPs. So if IOCs are getting demoted, we have to then move up that pyramid of pain to those TTPs. And the reason that TTPs are so durable is because they're structural.
So they're tied to the attacker objectives, not to IOCs and artifacts. So if you think about it, an adversary who wants to get into an environment and wants credentials, they still have to read LSASS, they still have to dump SAM, they still have to abuse DC sync, or steal a Kerberos ticket, right? So there are still actions that they have to do, even if you take the IOC out of that equation.
So the binary doing can change, but the act cannot. So, this is where MITRE ATT&CK comes in. So when we think about behavioral-based detections, we think about MITRE ATT&CK as basically the whole framework that we need to utilize to move up that pyramid of pain.
And so it's basically where all of our detection engineering work needs to operate at this point. I love talking about MITRE with my team, although they might hate it, right? Because we shouldn't be thinking about we have to cover every single box in a MITRE ATT&CK framework, right?
We need to really think about how we're chaining those and how we're detecting based off of them within each individual environment. So what works for Cribl may not work for a bank. But, again, the MITRE ATT&CK framework is where those behaviors lie and where we need to shift our thinking to.
So to your point about that, change management is always hard no matter what it is. It is. So how should security teams go about making this transition?
I mean, what's involved? Yeah, that's a great question. And I really think that a lot of teams aren't prepared for this massive shift, right?
Because we've operated under this IOC framework for so long that we have to shift not only how we're ingesting alerts or indicators or changing our rules up, we have to adjust the entire operating model of a team. So, for detection engineering, instead of rule counts or a rule firing based off of an IOC, we are now rule chaining based off of behaviors, and how the threat actor is operating. So, we have to shift our way of thinking within a SOC to be able to get ahead of the adversary.
Agentic SOC, everybody likes to talk about the agentic SOC and whether AI can really effectively displace humans at this point. I would argue it can't yet. What it does do, though, is it allows us to triage the tier one, tier two stuff.
It enriches what the team is doing. And then our humans in the loop can basically focus on the larger scale things. And part of that just comes down to the behavioral nature of the thing.
If it doesn'tDo the exact same thing the exact same way every time. Kind of makes it hard for AI detect. So if the attackers are becoming more dynamic in their tactics and techniques, then I got to put some humans at the top of that food chain to understand what they're doing, right?
Yeah, that's correct. If you think about it, binaries are disposable. So when they become disposable, the only thing that you have left is behavior.
And that's a durable signal that you can operate off of. So switching to that behavioral-based detection is where the industry needs to trend. Of course, I'm sure you've heard everybody talking about Mythos and other AI models, but it seems to me that the attack surface is going to be more vulnerable as more of these vulnerabilities are disclosed.
Sometimes they're even disclosed now before there's even a patch for whatever it is. So does that change the nature of this game as well? Because it seems to be all happening at machine speed now.
It does change the game significantly for a couple different reasons. First is, again, we have to switch to that behavioral detection to be able to get ahead of this, right? Because we're operating at machine speed, we have to have machine speed to counter the attacks.
And so, if you think about agents that are triaging alerts, we should be able to get closer to the source, enrich them, form the hypothesis, pivot through the telemetry the way that a senior analyst would. So, these agents are dramatically more effective when the underlying signal is there. And that brings me to the second point, which is, it isn't effective, and we can't do what we're talking about if you don't have the telemetry there in the first place.
So AI didn't kill the IOC. Think about it as collapsing its half-life from days to minutes, and that's changing everything about where we spend our detection budget. If you don't have the telemetry to first be able to operationalize any of this, then you're not going to be effective in the first place.
Behavioral-based detection is way hungrier than IOC matching. So the amount of telemetry that we're ingesting into our pipelines is a lot greater. The Harvard Business Review, I'm sure you've seen the recent report that's been published, but it was about solving agentic AI's need for infrastructure and telemetry, right?
And in that report, I thought it was really interesting because it calls out that during the study conducted, 95% of executives believed that agentic AI was going to be critical to their business strategy within the next two years. But yet, when they dug deeper into that, those same executives stated that 75% of them lacked any plan for agentic AI. That's terrifying for me in security.
Because if you don't have a plan for it, I guarantee you aren't thinking about how to secure it, right? And from my perspective, your detection program lives or dies on the pipeline that feeds it. And so if you don't have the telemetry that's being ingested to be able to even detect off of IOCs in general, then you're definitely not going to be able to detect off of behaviors.
Now, I think cybersecurity folks will follow what you're saying, but how do you have this conversation with the business who's going to be like, "Hey, let me get this straight. " And they're going to be like, "And are you sure? " But, so how do you go down there and have a meaningful dialogue with an argument that says we need to change the way we're going to do stuff.
It's going to be more data intensive, AKA costly, but B, it'll have a better outcome, but I can't prove a negative. Yeah. So it's an interesting conversation to have, and typically, it all comes down to money and budget, right?
And if you think about your traditional SOC tech stack, you've got companies that are spending upwards of hundreds of thousands of dollars on IOC feeds and ISACs and tips and things that are foundational to the IOC detection world. So shifting your thinking and getting to the behavioral-based detections and ingesting more of that telemetry, you're going to have to make some concessions with some of your tooling, and you're going to have to shift the way that you ingest the data, the way that you're detecting on the data. And there are a lot cheaper ways to do it than the IOC feeds and the tips of the world.
And so, for me, talking to our executives and talking to leadership about how we do this, it is discussing it in a way that they understand, that isn't getting into the nuanced details. So thinking about metrics, which is what all executives in C-suite like to see. They want to see the numbers that are going to shift.
They want to see that trend over time. They want to see that instead of spending $500,000 on these five things, we're going to move it over here to start ingesting more of our telemetry and then start rule chaining or building out more of that MITRE ATT&CK-based detection framework. So that's how I've been successful so far in shifting that thinking.
All right, folks. Well, you heard it here. The game is definitely changing, and you're not going to get a million dollars to solve this issue, so you got to figure out how to repurpose what you already have.
Is that fair? That is fair. All right.
Hey, Nicole, thanks for sharing your insights. Thank you for having me. All right.
And back to you guys in the studio.