RAD Security has recently emerged as a finalist in the Black Hat Startup Spotlight Competition, introducing a pioneering AI-driven incident investigation tool designed for behavioral detection and response within cloud security.
Traditional security measures heavily rely on signature-based detections, which frequently overwhelm security teams with false positives. RAD Security is at the forefront of innovation by integrating AI-powered incident analysis with behavioral, signatureless detections. This advancement aims to drastically reduce false positives and alleviate the workload on security professionals.
Enhancing Detection Accuracy
CTO and Co-Founder Jimmy Mesta explained, “By definition, signatures are stateless, making investigations based on the signature-focused approach inaccurate and tedious. By adding AI-powered investigations to behavioral detection, which is already a step ahead of signature-based detection in accuracy, security teams can quickly get light years ahead in the accurate assessment of incidents.”
This combination of AI-powered incident investigations with behavioral detection methodologies significantly lowers false positives and offers security teams enhanced tools to handle various attack tactics, such as reverse shells, unauthorized data access, and Sudo CVE.
Behavioral Analysis and AI Integration
Historically, signature-based methods have gradually been replaced by behavioral strategies
While signature-based approaches can be bypassed by avoiding specific parameters, RAD's behavioral solutions reliably detect such events. Additionally, a behavioral drift event may not always be malicious, so incorporating AI investigation capabilities ensures greater diagnostic precision. AI effectively analyzes large datasets, distinguishing between benign and malicious activities, making it a vital tool for modern incident analysis.
Historically, signature-based methods have gradually been replaced by behavioral strategies in response to emerging threats, particularly in endpoint and network security markets. Currently, cloud security primarily depends on signature-based approaches, with components like Cloud Workload Protection and runtime security usually built into broader Cloud Native Application Protection Platforms (CNAPPs). RAD Security's Cloud Detection and Response solution distinguishes itself by establishing behavioral baselines to identify zero-day threats, enhanced by real-time identity and infrastructure insights to guide response actions.
Adapting to Workforce Challenges
With a growing number of detection and response tasks handled by a shrinking workforce, 22% of security professionals report recent company layoffs.
This issue is particularly acute in cloud security, where 65% of professionals experience burnout due to skill gaps. Despite these challenges, cloud native adoption progresses, with forecasts indicating that 95% of new applications will utilize cloud native workloads by 2025. Therefore, effective detection and response mechanisms for zero-day incidents like the XZ Backdoor are becoming increasingly crucial.
Signatureless Detection Features
To address these industry challenges and emerging threats, RAD Security has launched several new features:
- Amazon EKS Add-on: Available in the AWS Marketplace for Containers, RAD Security enables the real-time provision of KSPM and runtime features directly from EKS, providing real-time Kubernetes risk insights alongside signatureless cloud detection and response.
- Automated AI-Powered Investigation: Utilizing LLMs, RAD Security rapidly evaluates numerous behavioral detections to establish whether incidents are malicious or benign, offering real-time infrastructure and identity context.
- Findings Centre: A user-friendly console allows for straightforward navigation of all incidents, streamlining detection and investigative processes.
- RAD Open Source Catalog: Featuring updated version details and new open source images, this catalog enhances the standard in behavioral workload fingerprints by tracking changes over time.
Professionals interested in improving attack detection accuracy in their cloud environments can engage with the RAD Security team at the Black Hat Conference in Startup City, booth #219. Further details of RAD's innovations will be presented at the Innovators and Investors Summit, where the team is one of the four finalists in the Startup Spotlight competition.
RAD Security takes the stage as a finalist in the Black Hat Startup Spotlight Competition, it unveils the first-ever AI-powered incident investigation capability for behavioral detection and response. Today, cloud security is based almost exclusively on signature-based detections, which are notorious for burdening security teams with false positives.
RAD Security is the first to combine AI-powered incident investigation with behavioral, signature-less detections, to significantly reduce false positives and provide much-needed relief for overburdened security teams.
Signature-focused approach
“By definition, signatures are stateless, making investigations based on the signature-focused approach inaccurate and tedious,” says CTO and Co-Founder Jimmy Mesta. “By adding AI-powered investigations to behavioral detection, which is already a step ahead of signature-based detection in accuracy, security teams can quickly get light years ahead in the accurate assessment of incidents.”
RAD’s behavioral approach and AI-powered investigations result in the lowering of false positives on their own; but by putting these two capabilities together, RAD enables security teams to achieve a multiplier effect. The enhanced accuracy of behavioral methods versus signature-based methods is easily demonstrated using multiple examples of attack tactics like reverse shells, access to sensitive data, and a Sudo CVE.
Behavioral drift event
In these examples, while signatures can be easily bypassed by avoiding the exact parameters, they are detected by RAD’s behavioral solution. By the same token, a behavioral drift event is not always a malicious event, so the addition of the AI investigation capability ensures additional accuracy. AI is particularly suited for looking across large sets of data and quick contextualisation, making it a natural investigation tool and engine to analyze benign versus malicious drift.
Throughout the history of cyber security, and most famously in the endpoint and network security markets, signatures have eventually been replaced by behavioral methods in response to an evolving threat landscape. Today, the cloud security category is nearly entirely composed of signature-based approaches with runtime security and Cloud Workload Protection (CWPP) that are standalone or part of a broader Cloud Native Application Protection Platform (CNAPP).
Cloud native environments
In sharp contrast to signature-based CNAPPs, or posture-focused Cloud Security Posture Management (CSPM), RAD Security’s Cloud Detection and Response (CDR) solution creates behavioral baselines of unique good behavior to detect zero day attacks, enriching detections with real-time identity and infrastructure context that inform response actions.
More and more, detection and response is being accomplished by fewer and fewer dedicated people, with 22% of security professionals reporting recent layoffs at their company. The workforce reductions are an even more acute pain in cloud security, with 65% of cybersecurity and infosecurity professionals claiming burnout due to skill gaps. Even though a full 95% of IT decision makers feel their team has been negatively impacted by the cloud security skills gap, cloud native adoption continues, and analysts predict that, by 2025, 95% of new applications will be built using cloud native workloads. Zero days like the XZ Backdoor are now a regular occurrence, making detection and response in cloud native environments more important than ever.
Signatureless cloud detection
RAD Security has introduced multiple new features to help security teams adopt new innovation that will help them address these alarming trends and emerging threats:
- Amazon EKS Add-on: RAD Security is now available as an Amazon EKS Add-on in the AWS Marketplace for Containers. This means customers can now provision the real-time KSPM and runtime features of the RAD platform directly from EKS, for real-time visibility into their Kubernetes risk as well as signatureless cloud detection and response.
- Automated AI-Powered Investigation: RAD Security uses LLMs to quickly analyze multiple behavioral detections and determine whether an incident is malicious or benign, including real-time infrastructure and identity context.
- Findings Centre: All incidents are now available in an easy to navigate console, making detection and investigation easier and quicker.
- RAD Open Source Catalog: New version details and new open source images have now been added to the RAD Catalog, detailing the changes in behavioral fingerprints over time and bolstering the behavioral workload fingerprint standard.
Schedule a meeting with the RAD Security team at the Black Hat Conference this week to discuss improving detection accuracy for attacks in your cloud environments. The team will be exhibiting at booth #219 in Startup City, and at 4:45PM EST they will be presenting at the Innovators and Investors Summit as one of the four finalists in the Startup Spotlight competition.