RAD Security has introduced a groundbreaking behavioral detection and response solution tailored for cloud native environments. This announcement was made as CEO Brooke Motta addressed the RSA Conference Innovation Sandbox in San Francisco.
Unlike traditional signature and anomaly-based methods, which often fall short in countering cloud native threats such as the recent XZ Backdoor attack, RAD’s platform establishes baseline behavior through workload fingerprints. By doing so, it identifies attacks in real-time while integrating comprehensive infrastructure and identity context to enhance response prioritization.
Emphasis on Identity Context in Security
Jimmy Mesta, CTO and Co-Founder of RAD Security, highlighted the limitations of relying solely on signature-based detections or incomplete AI and machine learning models. He emphasized the need for real-time responses to cloud native attacks with distinct prioritizations spanning workloads, infrastructure, and identity. As cloud native environments expand, traditional methods increasingly prove inadequate.
95% of IT decision-makers acknowledged the adverse impact of a cloud security skills gap
Currently, 70% of security teams are leveraging containers in production, and it is projected that by 2025, 95% of new applications will utilize cloud native workloads. A recent survey revealed that 90% of container-using teams, particularly those employing Kubernetes, experienced security incidents over the past year. Furthermore, 95% of IT decision-makers acknowledged the adverse impact of a cloud security skills gap.
Challenges in Detecting Zero Day Attacks
The XZ Backdoor software supply chain attack underscored the inefficiency of contemporary detection methods, as signatures and anomaly detection took days to weeks to address the threat.
Successful recognition of such zero day attacks necessitates a pre-existing behavioral profile of the environment. RAD’s innovative approach constructs behavioral fingerprints based on the observation that most cloud native workloads maintain a stable set of processes. Deviations from these behaviors are automatically flagged as potential threats.
Enhanced Context with ITDR and KSPM
RAD Security is witnessing a surge in demand, with annual recurring revenue tripling
RAD Security’s fingerprints are supported by comprehensive context from its Identity Threat Detection & Response (ITDR) and Kubernetes Security Posture Management (KSPM) capabilities, offering a clearer understanding of detection impacts.
This is in contrast to competing CSPM and CNAPP vendors, who often leave organizations without real-time insights into changes across cloud native identities, infrastructures, and workloads. The recent launch of RAD’s detection platform follows the introduction of its open-source fingerprint standard and ITDR solutions.
RAD’s Growing Influence and Innovation
RAD Security is witnessing a surge in demand, with annual recurring revenue tripling and a 219% net retention rate. Businesses from sectors such as insurance, banking, and media are adopting RAD's solutions, reflecting a 60% growth in customer contract value, primarily through existing client expansions.
The company’s latest updates include the ability to create behavioral fingerprints for custom containers at runtime and detect any behavior drift. New features include a custom eBPF sensor enhancing data correlation and a range of response actions, like pod termination and quarantine, driven by LLM analysis. Moreover, a workflow manager allows automated responses to detections, from pod labeling to executing AWS API calls.
Those interested in exploring the latest in behavioral threat detection and response can meet RAD Security representatives at the RSAC Innovation Sandbox competition or reach out directly to begin developing unique behavioral fingerprints.
RAD Security releases the industry’s first behavioral detection and response solution for cloud native environments, as CEO Brooke Motta takes the stage in San Francisco for the RSA Conference Innovation Sandbox.
To-date, signature and anomaly-based methods are late and ineffective against cloud native attacks like the recent XZ Backdoor. RAD’s detection and response platform is the first to baseline behavior through workload fingerprints, detecting cloud native attacks as they happen, while tying in real-time infrastructure and identity context for response prioritisation.
Identity context for response prioritisation
“As the footprint of cloud native environments continues growing, security teams can no longer rely on signature-based detection that only works after the attack, or false promises from AI and machine learning models based on insufficient samples of cloud attacks. Security teams need to respond to cloud native attacks as they happen, with clear prioritisation across workloads, infrastructure and identity,” explains CTO and Co-Founder, Jimmy Mesta.
Today, 70% of teams are using containers in production, and analysts predict that, by 2025, 95% of new applications will be built using cloud native workloads. A recent survey shows that 90% of teams using containers and Kubernetes had an incident in the last year, and a full 95% of IT decision makers feel their team has been negatively impacted by the cloud security skills gap.
Consistent set of core processes
In the weeks following the zero day XZ Backdoor software supply chain attack, cloud native IDS approaches resulted in signatures days and weeks following the attack, and anomaly detection approaches were blind to the set of attackers’ techniques that relied on normal processes. To detect the XZ Backdoor and other zero day attacks, a behavioral profile of the environment would have been required before the attack took place.
RAD’s behavioral fingerprints are based on the fact that the majority of cloud native workloads exhibit a consistent set of core processes, programs and files at runtime. Any drift from this core set of behaviours is suspicious.
Cloud native technologies
RAD fingerprints get critical context from its ITDR and KSPM capabilities to help reduce noise and allow teams to understand the true impact of detections, compared to CSPM and CNAPP vendors that leave teams blind to the real-time changes between cloud native identity, infrastructure, and workloads.
The launch of the detection and response platform follows the release of the open source fingerprint standard and Cloud Native Identity Threat Detection & Response (ITDR). Over a dozen companies are using RAD to create fingerprints in their environment, and in the last year alone, RAD Security has seen ARR has grown by 3 times, with a 219% net retention rate and new logos from highly regulated and digitally mature industries such as insurance, banking and media. At the same time, the current and growing importance of cloud native technologies in the security team’s priorities is reflected in 60% growth of customer contract value, with nearly half of new ARR coming from expansion of current customers.
LLM-driven analysis
New features in this release include:
- Fingerprints and drift for unique containers: RAD can now create cloud native behavioral workload fingerprints and detect drift for custom containers (versus just open source) at runtime
- eBPF sensor: RAD is releasing a newly re-configured, custom eBPF sensor to get around the inflexibility and instability inherent in legacy agents. RAD’s agent requires the fewest and most precise permissions, has more flexibility for correlation of data across the environment, and a smaller footprint
- Response actions: Customers can terminate pods, label pods, and quarantine pods (e.g. prevent network egress from pods) in response to drift detection
- AI/LLM Categorisation of Drift Events: Drift events are classified into different attacks (if known), based on LLM-driven analysis
- Workflow manager: Set up automated workflows to choose how to respond to detections from RAD, whether that's to notify to one or more channels, label a pod to enable security teams to further investigate, kill a pod, or quarantine, open a pull request, run Terraform, call an AWS API to change a setting, and more
Learn more about behavioral cloud native threat detection and response, meet them in the innovation showcase at the RSAC Innovation Sandbox competition, or reach out to get started creating unique behavioral fingerprints today!