Summary is AI-generated, newsdesk-reviewed
  • RAD Security unveils AI-driven incident investigation to cut false positives in cloud security.
  • Signature-focused methods are outdated; RAD's AI aids in accurate behavioral detection.
  • New RAD features: Amazon EKS Add-on, AI Investigations, and Findings Centre enhance detection.

RAD Security has recently emerged as a finalist in the Black Hat Startup Spotlight Competition, introducing a pioneering AI-driven incident investigation tool designed for behavioral detection and response within cloud security.

Traditional security measures heavily rely on signature-based detections, which frequently overwhelm security teams with false positives. RAD Security is at the forefront of innovation by integrating AI-powered incident analysis with behavioral, signatureless detections. This advancement aims to drastically reduce false positives and alleviate the workload on security professionals.

Enhancing Detection Accuracy

CTO and Co-Founder Jimmy Mesta explained, “By definition, signatures are stateless, making investigations based on the signature-focused approach inaccurate and tedious. By adding AI-powered investigations to behavioral detection, which is already a step ahead of signature-based detection in accuracy, security teams can quickly get light years ahead in the accurate assessment of incidents.”

This combination of AI-powered incident investigations with behavioral detection methodologies significantly lowers false positives and offers security teams enhanced tools to handle various attack tactics, such as reverse shells, unauthorized data access, and Sudo CVE.

Behavioral Analysis and AI Integration

Historically, signature-based methods have gradually been replaced by behavioral strategies

While signature-based approaches can be bypassed by avoiding specific parameters, RAD's behavioral solutions reliably detect such events. Additionally, a behavioral drift event may not always be malicious, so incorporating AI investigation capabilities ensures greater diagnostic precision. AI effectively analyzes large datasets, distinguishing between benign and malicious activities, making it a vital tool for modern incident analysis.

Historically, signature-based methods have gradually been replaced by behavioral strategies in response to emerging threats, particularly in endpoint and network security markets. Currently, cloud security primarily depends on signature-based approaches, with components like Cloud Workload Protection and runtime security usually built into broader Cloud Native Application Protection Platforms (CNAPPs). RAD Security's Cloud Detection and Response solution distinguishes itself by establishing behavioral baselines to identify zero-day threats, enhanced by real-time identity and infrastructure insights to guide response actions.

Adapting to Workforce Challenges

With a growing number of detection and response tasks handled by a shrinking workforce, 22% of security professionals report recent company layoffs.

This issue is particularly acute in cloud security, where 65% of professionals experience burnout due to skill gaps. Despite these challenges, cloud native adoption progresses, with forecasts indicating that 95% of new applications will utilize cloud native workloads by 2025. Therefore, effective detection and response mechanisms for zero-day incidents like the XZ Backdoor are becoming increasingly crucial.

Signatureless Detection Features

To address these industry challenges and emerging threats, RAD Security has launched several new features:

  • Amazon EKS Add-on: Available in the AWS Marketplace for Containers, RAD Security enables the real-time provision of KSPM and runtime features directly from EKS, providing real-time Kubernetes risk insights alongside signatureless cloud detection and response.
  • Automated AI-Powered Investigation: Utilizing LLMs, RAD Security rapidly evaluates numerous behavioral detections to establish whether incidents are malicious or benign, offering real-time infrastructure and identity context.
  • Findings Centre: A user-friendly console allows for straightforward navigation of all incidents, streamlining detection and investigative processes.
  • RAD Open Source Catalog: Featuring updated version details and new open source images, this catalog enhances the standard in behavioral workload fingerprints by tracking changes over time.

Professionals interested in improving attack detection accuracy in their cloud environments can engage with the RAD Security team at the Black Hat Conference in Startup City, booth #219. Further details of RAD's innovations will be presented at the Innovators and Investors Summit, where the team is one of the four finalists in the Startup Spotlight competition.

In case you missed it

Responsible AI Adoption Starts With Governance
Responsible AI Adoption Starts With Governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence
How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organizations are increasingly discovering that the same cameras installed to pro...

Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation
Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...