23
@bubblewire Arkose Labs Scandi Why am I here? Who am I?

Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

@bubblewire Arkose Labs

Scandi

Why am I here?

Who am I?

Page 2: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

SubjectMatter

Expertise

DataAnalytics

Product engineering

heuristicsWAF

signalsML

SIEMinsights BUILDING

SECURITYPRODUCTS

ACCURATE,ACTIONABLE & SCALABLE SOLUTIONS

Page 3: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

SubjectMatter

Expertise

DataAnalytics

Product engineering

heuristicsWAF

signalsML

SIEMinsights

TRADITIONALDEFENSIVEPRODUCTS

Page 4: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

SubjectMatter

Expertise

DataAnalytics

Product engineering

heuristicsWAF

signalsML

SIEMinsights

SWEET SPOT

FOR ACCURATE,ACTIONABLE & SCALABLE SOLUTIONS

Page 5: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

HOW DO WE

SCALEENABLING AUTOMATION AND MACHINELEARNING WHILST AVOIDING COMMON PITFALLS

Page 6: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

INTERMEDIATEATTACK SURFACE

SEPARATED ENVIRONMENT USED TO TEST AND VALIDATE SUSPECT USAGE, ACTION ORBEHAVIOR

Page 7: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

WHERE WE SEE SOMEADJACENTCONCEPTS

INTERACTIVE HONEYPOTS, LAYER 7 IDS,ANTI-FRAUD,SPAM, BOT & ATO SOLUTIONS

Page 8: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

TO RETAIN ACCESS USERS MUST

COMPLETE TASKS AND TESTS AND PERFORM AS EXPECTED

Page 9: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

ESCALATEDVALIDATION

& WHAT WE LEARN FROM HONEYPOTS

Page 10: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

BENEFITS OF INTERMEDIATEATTACK SURFACE

MOVE TARGET FROM YOUR ASSETS, WASTE ATTACKERS TIMEAND EXHAUST RESOURCESVALIDATE USERS

Page 11: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

BUT WHAT IF IT COULD LEARN?

Page 12: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

MACHINELEARNING

DIFFERENT ALGORITHMS FOR DIFFERENT SITUATIONS WITH DIFFERENT REQUIREMENTS

Page 13: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

ENSAMBLEALGORITHMS

META ALGORITHMS THAT COMBINE SEVERAL ML MODELS FOR IMPROVED PERFORMANCE

Page 14: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

APPLYINGMACHINELEARNINGIN SECURITY

SHOW US THINGS WE DON’T KNOW

DO THINGS WE DO KNOW FASTER OR MORE EFFICIENT

(AT SCALE)

ANOMALYDETECTIONMALWARECLASSIFICATION

NETWORKFILTERINGBEHAVIORALANALYTICSMARKETING

LACK OF TRUSTNO EXPERTISEABSTRACT IDEAOVER RELIANCEON “SCIENCE”TRAINING DATANOT DEFINED PROBLEM

Page 15: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

ISSUES INMACHINELEARNINGIN SECURITY

SECURITY EXPERTS ARE NOT RARELY DATA SCIENTISTS

DATA SCIENTISTS ARE NOT RARELY

SECURITY EXPERTS

ANOMALYDETECTIONMALWARECLASSIFICATION

NETWORKFILTERINGBEHAVIORALANALYTICSMARKETING

LACK OF TRUSTNO EXPERTISEABSTRACT IDEAOVER RELIANCEON “SCIENCE”TRAINING DATANOT DEFINED PROBLEM

Page 16: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

PERCEPTIONMORE DATA

BETTER PERFORMANCE

MANY BELIEVE THAT FEEDING MORE DATA TO THE MODEL ALWAYS YIELD BETTER RESULTS

Page 17: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

REALITYSIZE DOESN’T REALLY MATTER

WHAT MATTERS MORE IS A CLEARLY DEFINED PROBLEM STATEMENT

Page 18: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

REDUCING

SCOPEDEFININGEXPECTEDBEHAVIOR FOR BETTER

RESULTS

Page 19: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

What about continuous reinforcement? → the beauty of

webapp security and user interaction

INTERACTIVEREINFORCEMENT

UTILIZING USER INTERACTION AS CONTINUOUS REINFORCEMENT FOR MODELS & HEURISTICS

Page 20: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

LOCALMODEL CORRECTION

BE SELECTIVE ABOUT WHATTO REINFORCE

Page 21: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

GLOBALNETWORKEFFECT

SIMILARITY IN ATTACKS ACROSS MANY TARGETS PROVIDE GLOBAL PERSPECTIVE

Page 22: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

CONCLUSION

Page 23: Who am I? › USA-19 › Thursday › us-19-Westelius-Attack-S… · analytics product engineering heuristics waf signals ml siem insights sweet spot for accurate, actionable & scalable

@bubblewire

arkoselabs.com

Let’s connect!

THANK YOU

IM BUILDING PRODUCTS AT

COME SEE OUR BOOTH #860