RSA Conference 2023: Unity + Basics = Security

AI Basics


Happy beginning of May. This year he returned from the RSA conference.The greats and the good gathered in San Francisco for four days of informative keynotes, sessions, presentations, hallway conversations, and behind-the-scenes meetings. Now that this whirlwind of activity has passed, it’s time to reflect on the key takeaways from what we’ve seen, heard, and speculated.

Each year at major cybersecurity industry events, themes seem to emerge almost organically through talk tracks, booths, and product announcements. Last year was Zero Trust. This year it was artificial intelligence (AI).

AI as an accelerator

The topic of AI (and all its forms) permeated presentations and conversations at RSAC 2023. However, if this is anything to say, it’s just the direction of travel.

AI has infiltrated cybersecurity for over a decade. It is already used in areas such as spam detection, website classification, AIOps, exploit detection, and malware detection.Just to name a few. Until now, most of these integrations have been done internally. Working with vendors integrating AI capabilities, mostly in the form of machine learning (ML) Build into core product functionality without exposing it directly to users. The Large Language Model (LLM) and ChatGPT revolution looks set to change that, but we are still at the beginning of that change.

The “5 Most Dangerous New Attack Techniques” session moderated by SANS Institute President Ed Skoudis is always popular, and this year was no exception.what was The remarkable thing about this year was the noveltyor lack thereofAn overview of the techniques described and the basic nature of recommended responses and mitigations.

Panelists discussed malicious code injection into CI/CD pipelines, supply chain attacks, malvertising, and search engine optimization (SEO).—aTried and tested techniques that have become more prominent due to the amount of threat actors using them. Unsurprisingly, ChatGPT was mentioned in the session, but primarily as a technology that could streamline and turbocharge existing techniques such as social engineering, phishing, and ransomware.

Us Against the Machine

As I walked through the Moscone North and South floors, I didn’t see any groundbreaking innovations or product announcements. This year, the emphasis seemed to be on iterative improvements and integrations. There was a palpable sense that the security vendor community was finally starting to come together. Perhaps part of it was driven by the theme of this year’s conference, ‘Stronger Together’.But much of it has proven beyond slideware through increased integration and cooperation between vendors.

It’s heartening to see our industry act on the essential truth that our biggest competitors as security vendors are not each other. it is the attacker. Only by complementing and enhancing each other’s services throughout the cybersecurity stack can security practitioners be more effective at beating the real competition.

Here are my impressions of RSA Conference 2023: fast. ⅤWorking with Endor promises to significantly accelerate and enhance information security.

If you want to ride the pinnacle instead of being dragged down by the wave, revisit the basics of information security. There is no single vendor. There is no silver bullet to provide cybersecurity, sell zero trust, or fill your belly with threat intelligenceWhatever those increasingly unclear terms mean. To get the most out of all that cybersecurity has to offer and prepare for the threat landscape for years to come, it all starts with creating a baseline. Know and find evil ”.

Moving forward from RSAC 2023

Security starts with visibility. CISOs should look to their suppliers of choice for better feature integration, better information sharing, adherence to industry standards, and industry partnerships that offer something beyond logos on slide decks.

The security stack needs to be able to reliably identify it. every day devices on the networkIt’s not just where you can deploy agents. You need real-time visibility into communication flows, contextual enrichment, and rich historical data.It helps to “know better”. A defense-in-depth model doesn’t have to be a single vendor. The potential loss of critical functionality in the event of an incident or replacement is very real. And the burden of integration should not fall on the practitioner. You already have enough burdens.

Security then continues in a collaborative ecosystem— ones that automate detection and triage and oil the wheels of incident response. defense against tProven and effective threat vectors for supply chain attacks include adjusting security architecture and deploying threat intelligence across traditional IT infrastructure, DevOps, cloud, and poorly defended environments such as OT and IoT. need to share. All of this should be reinforced with an integrated training program.Prepare your workforce for tomorrow’s attack and arm your workforce for today’s attack.

It’s a tall order, but the lesson from RSA Conference 2023 is that it’s not unattainable. We will definitely grow stronger together.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *