Safeguarding Expanding Attack Surfaces with BeyondID’s Neeraj Methi
Neeraj Methi, vice president of solutions for BeyondID, explains how artificial intelligence (AI) will be used to enable cybersecurity teams to better protect rapidly expanding attack surfaces.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We are here with Niraj Mei, who is vice president of Solutions for Beyond id, and we're talking about how AI is gonna be used for the good guys, and hopefully maybe we can figure out what's going on with our attack surfaces and how the bad guys are infiltrating our systems in seven days or less.
Niraj, welcome to the show. Uh, thank you Mike. I'm super excited to be here with you talking about how we can help our customers prevent, you know, breaches in seven days.
We All talk about what the bad guys are doing, but it's important to remember that the good guys can do things as well. And AI kind of cuts both ways, especially with machine learning algorithms. What is it that we should be able to expect from machine learning in the modern age and, you know, how is it changing the way we need to think about cyber security?
Yeah, I, I think what we have to see is we have to run faster than the bad guys, right? They have the same tools as we, we have the same tools. What we need to do is proactively looking at what is AI telling us and make some human sense out of it.
So for example, you know, if somebody is doing MFA spraying, you know, what do we do about it? You gotta have proactive steps taken up. If you see that, uh, you know, signals coming from ai, what steps are you going to take as a human?
You can automate some of it, some of those things can be elevated, and then you can take some manual steps. That's where I think we need to focus on. Assuming that the bad actors are already working inside your organization, what are you doing with it?
Is your AI able to identify the patterns which are not normal? A lot of times what bad actors are also doing, they're acting as if they are you, you know, kind of being in your, in your environment for months so that you can't even detect them. But guess what?
Humans have the intelligence. If you see some irregularities and some things which are not common, and then obviously all the time kind of monitoring any very specific changes. For example, you know, if you have admin accounts which are being changed or updated or reset or kind of used in a way which is not normal, that's a signal you gotta look out for.
So I give an analogy to my customers, like, think about, you know, your house. You have protected your house from outside, you have locks, you got alarms and all that stuff, but a window could be left open by, you know, your child, or you left a door open, you know, you know, or some, some hole somewhere and somebody gets in. What are you doing inside your house?
Monitoring every room and every place? What is happening? Not much, right?
But if you start doing that, AI can help you. Hey, I see this odd object. It's really not supposed to be here.
It's moving around. Now. If you see that, what actions could you take?
You could probably elevate the security as, Hey, by the way, I see something wrong. I need a human to be kind of, you know, interjected in this thing and look at it. Or maybe if I cannot bring in a human right, I'm just gonna, you know, protect that area to just to be consolidated there.
This person cannot move anywhere outside this room until I figured it out. What's really happening? So you're containing the, you know, threat.
Beyond that rule, I feel like the battle is more in real time these days. I think historically we kind of thought there'd be malware somewhere and we'd have time to hunt it down before it got activated, but at the moment it seems like everything is instantaneous. And by the time I discover the threat, it's probably been activated.
So how is that changing the way we need to think about how we respond? So basically, as, as your AI is gonna help you see some threat even might be, you know, false positive, you can start elevating some of the, uh, authentication. For example, elevate the, the request to re-authenticate yourself, elevate the request to kind of identify yourself with something else.
Because these bad actors are also able to authenticate from username password as, as we know is already stolen. Just think about they already have the SMS phone factor they already have. So what are you gonna do next?
Right? So you gotta start thinking about what are the next levels I need to take, which is harder for them to, to, to get into. And then you have, you know, security talks about layer security.
You know, you breach one layer, you breach the second layer, you breach the third layer. How many layers can they really breach? It gets harder and harder and bad actors at some point is gonna give out, this is too hard.
So we need to make it harder for the bad actors to get through your, uh, systems. And that's layer security we gotta think about and automating it. To your point, yes, how many humans can be looking at it?
So when an AI detects something, you automatically elevate something from the end user perspective to authenticate them, authorize themselves, or tell them again who they are. We talk a lot about zero trust these days. It seems to me it's almost gonna be impossible to implement that without relying more on the machines to help us.
Well, you, that's why you gotta think from an identity perspective. So at beyond Id, we believe you gotta lead a zero trust than identity as the first choice. Because identity is the thread between your devices, your network, your application, your workloads, and also your data.
Because those, you know, traditional walls are gone now, right? We all are working from anywhere, everywhere. You have partners coming to your organization, you're working with so many different organizations which are not in your four walls.
And the application used are also not in your four walls, the SaaS application I'm talking about, right? So what is that primary thing which you have, which you can attach yourself to protect that is identity. So you have to start with identity and think about zero trust from an identity perspective and monitor your identity very, very closely to protect yourself.
What is the challenge with getting to that mindset? 'cause it seems like on the face of it, that identity would be the first thing that we would do, but of course, historically we've done other things and created castles and moats. But when you talk to organizations about making a transition to a more identity focused approach to security, what's the challenges?
Oh, a lot of challenges. If you think about it, it could be the single point of failure. If you don't protect it, well now you have, you know, everybody inside your organization if that's being breached.
So you have to think about, uh, you know, identity as like, how are you securing it? Because if you think about it, I see software, uh, you know, lifecycle happening because you, Michael could be coming from organization, which I trust if your organization is breached, but I trusted you, guess what? I'm, I'm breach now, right?
And I'm working with many different organizations. So that trust, which which is being built using federated identity needs to be really, really rethought. And you have to kind of continuously re-authenticate, reauthorized people.
You cannot just accept one authorized person and then give them access. A continuous monitoring and authentication is a must. Now, Do I buy this or is this more of a strategy?
'cause I'm scratching my head a little bit going, is there someplace I can go down the proverbial shopping aisle to find the zero trust section? Or do I have to like stitch together six or seven technologies to make all this work? You, you have to stitch it together.
It's not like a one point solution. You buy it and you'll be protected. It is a continuous thing because now the world we live in is integration.
Everything is integrated with everybody else. And to provide that integration, again, what I'm saying is you gotta use identity as a stitching thing between all these different applications, systems, organization you're working with and then using the total secure experience you gotta create. Because if you think about it, you cannot use security to, you know, avoid the experience, uh, customers or users are expecting.
So yes, it is a strategy which you have to continuously monitor and adapt to. And it starts with identity, is what I'm suggesting. So for example, you know, how do you register your users to start with?
How do you authenticate your users to start with? Once the user is in inside, how are you continuously authorizing them to what they're accessing? How are you monitoring your admin account?
Account? How are you monitoring your partner account? What are they able to do?
How are you defining the policies which are giving you the least privileges to what you need to do? All those things are strategies which you need to continuously adapt and change. And misconfiguration is another biggest, uh, threat.
We see the talent is not there. I mean, the security talent we think can do all those things is not there. So you need to bring the experts who can continuously help you deliver on security strategy, which we're talking about here.
As part of that in mind, gonna essentially eliminate the username, password combo as, and I'm shifting to something else. And what does that something else look like? Well, something else is passwordless as we have been probably hearing, you know, username, password.
I said, just assume that's been lost. Somebody already has it. So you gotta go to, you know, 5 0 2 standards where you're doing pass keys, passwordless, attaching your authentication to your devices, you know, to who you are, you know, from your, you know, biometrics where you're coming from.
So a lot of those, you know, vectors need to be considered to authenticate you as a user where there's no password required. Do I do that wholesale or am I gonna do that one application at a time? Do I start with my new applications or can I go back in and update all my legacy AppSec?
It seems like a heavy lift. So if you already have an identity management system and it can support it, you start there. And then per application, you gotta have policies too.
It is not like, hey, once you have, you know, passwordless authentication done, it applies the same way across your environment. So for example, if you're going to your finance application, you wanna make sure you have a higher assurance level. You know, yes, you're gonna bring me in as a password authentication, but if I'm gonna go, let's say make a wire transfer, or maybe I'm gonna look at a financial report, I'm gonna elevate your authentication, maybe ask for another factor.
Maybe your biometric, maybe an identity proofing, maybe you know, two other factors which I need to look at. Maybe where are you looking coming from? Are you coming from a computer which is, uh, attached to, to you as an individual from the company organization?
So yes, you start with the first, uh, you know, layer of protection and then every application you're going to, you need to make sure what kind of assurance level you need and elevate that as as you go through it and continuously do it. Keep the session small. The other thing we have seen is customers have kept their session too long and session is hijacked and then then other bad actors are able to use that.
It also seems like the bad guys are getting a little craftier and they're learning how to live off the land, as they say, which means that they're stealing credentials and then acting like a normal user for weeks and months on end, and then it's harder to detect. So, um, how do we kind of know what's normal versus abnormal? Exactly.
That, that's what we have seen in recent attacks. Uh, Mike, what we need to do is, is as much as they want to act as who you are, but they're leaving trails, right? I mean, when I say that, so I'll give you an example.
You know, when a bad actor is like, yeah, they're gonna start acting as you for like a month, and then they're gonna start doing things which you normally don't do. For example, they're gonna create another account. They're gonna, you know, start changing things if you're, if they gotten as an admin, you know, add another IDP or they're gonna start assigning new users which have more permissions and these kind of behaviors, which we can detect.
And what you can do is as you detect any of those behaviors, you gotta elevate the assurance level so that they cannot just do it. 'cause what happens today is if you're an admin, you are in, we have trusted you, now you can do anything. So what we are saying is do not even trust admin, access people to do what they do, monitor them, protect them.
And if, if you really need to do something dynamically, as you said, because the business is dynamic agile, you don't wanna slow it down, maybe give a temporary access for a very short time before somebody else can really intervene and say like, okay, I see it, I trust it and I'm gonna let it go through. How do we get to this new world? Because a lot of folks are, shall we say, budget challenge.
So how do I get to this whole new kind of approach when I have all these legacy systems in place that in a lot of instances I'm still paying for, but, um, is there some way to justify the ROI on this transition? Or is it just the cost of doing business is getting higher? Absolutely.
I mean, uh, you know, uh, you have to have ROI because somebody's gonna write a check. So what, what we suggest to our organization is, hey, if, so for example, let's say if you have X number of application, which are protected and y or not, once you have X plus Y protected, this is your, uh, reduced security risk. That's one from a risk perspective.
Second thing is that the optimization, the automation, which is gonna reduce your operational cost. Third, is if it is a customer application, the more users you can sign up to grow your business. If you're a consumer land, you need to protect because if you're in the newspaper or your, uh, your brand is, is deteriorated by that, uh, breach, you're gonna lose a lot of business.
So those are the metrics we go for, but we make it very simple for our customers to kind of measure those metrics so that they see the OROI to talking about a legacy application. Mike, you're talking about you absolutely need to modernize them. When I say modernize, you don't have to change the whole application, but you can change the security layer on them so that they can, uh, you know, start supporting modern standards.
How do I have this conversation with the business? 'cause it seems like from their perspective, we've invested in a lot of security tools over the years and we told 'em they'd be more secure and they have a certain amount of confidence in that. And now we're coming around and saying, Hey, guess what?
We gotta upgrade this whole thing again. And maybe they look at that with a little certain amount of John to die. Well, in a lot of cases, we are not asking them to upgrade those security tools they have.
What we are suggesting is how are you making sure these, all these tools are talking to each other and helping you be more secure, right? So how do you enhance your existing investment in technology? How do you bring them together where they're, we can look at all those things which are happening and kind of pushing the policies, the configuration which they needs to be doing.
'cause a lot of time I said it's misconfiguration, it is not being done in a best practices way. Some door or some window is left open again, humans are humans. We are prone to errors.
So that's what we need to do, leveraging existing technology and putting them together in a strategic way which can protect them further. All right, so ultimately, what's your best advice to folks about how to get from where they're today to where they need to be tomorrow? First, just assume the bad actor is already inside.
Ask yourself, do you have, uh, ways to detect it? If you detect it? Do you have ways to respond them quickly if you know that, and then can you mitigate that risk as fast as possible?
If you can answer those questions easily, quickly, then you're good. If not, ask for some expert helps. All right, folks, you heard it here.
The bad guys are changing their tactics and techniques. They're not massive changes. They're a little more subtle most of the time.
But as the wise man once said, you can't defend what you can't see. So if you don't know what's going on, you kinda lost already. Niraj, thanks for being on the show.
Thank you, Mike. All right, back to you guys in the studio.