Back
Dave Palmer
Cofounder, Darktrace

A New Era of Cyber Threats - The Shift to Self Learning, Self Defending Networks, Dave Palmer

🎥 Dec 09, 2019 📺 Cyber News Group Podcast ⏱ 12m 👁 6 views
... think Gartner now said the autonomous response is the way forward I think for a lot of people in cybersecurity industry everyone ...
Watch on YouTube

About Dave Palmer

Dave Palmer, cofounder and director of technology at Darktrace, has spoken extensively about the use of artificial intelligence in cybersecurity. He has stated that Darktrace's approach involves using AI to detect cyberattacks that have already penetrated an organization's defenses, rather than solely focusing on preventing intrusions. Palmer has described the technology as an "immune system" that learns normal patterns of behavior within a network and can surgically interrupt unusual activity, such as ransomware encryption, while preserving business continuity. He has also discussed the growing complexity of defending hybrid networks that include cloud, SaaS, and IoT environments, and has argued that automation and AI are necessary because the scale of modern digital businesses has surpassed human comprehension. Palmer has warned that AI will increasingly be used by criminals to automate and scale their operations, citing examples such as AI-generated spear-phishing emails and self-spreading worms that treat network propagation like a game of chess. He has noted that criminal organizations are already offering hacking tools with money-back guarantees and call centers, and has predicted that AI will make attacks more damaging once inside a network. In a separate talk on physical surveillance, Palmer demonstrated a passive Wi-Fi and Bluetooth detection system built with a Raspberry Pi, designed to help individuals determine if they are being followed. He emphasized that the tool is meant to assist people in potentially dangerous situations, and discussed how unique Wi-Fi network names and probe requests can be used for device identification even when MAC addresses are randomized.

Source: AI-verified profile updated from Dave Palmer's recent appearances. Browse all interviews →

Transcript (1 segments)
D
Dave Palmer0:05
Thank you. Well, thank you for coming. Today I'm going to talk a little bit about the history of the company and where we come from, what we're trying to achieve, as well as talking about the concept of self-learning, self-defending networks and some of the trends that we're starting to see at Darktrace. Just a little bit of history about the company: we were founded in 2013 by mathematicians from the University of Cambridge. It's grown pretty fast, and just a few of the awards that we have won are a testament to the technology that is coming out of our R&D facilities. Just looking at the existing threat landscape, as I'm sure a lot of you know, this is changing quite dramatically. It's not the case of just having on-premise networks anymore. We have a lot more hybrid networks, we have cloud, we have software as a service, we have IoT, and the complexity of those networks makes it very difficult to defend. Also, you have to rely on a lot of products to get full coverage. Coupled with the fact that you're having a rise year-on year, as everyone knows, in the volume of potential threats and attacks, this is where Darktrace has taken a fundamentally different approach. We don't rely on rules and signatures to determine what is bad within a network. We are looking for unusual behaviors in the network. That's the fundamental difference at Darktrace, so that we can understand how we can deal with new and novel threats. This brings us on to our cyber AI platform. This effectively consists of the Enterprise Immune System, which is our core monitoring tool, and that is giving you full coverage across your SaaS, email, IoT, and network. So it covers the entire of your digital estate, as well as our autonomous response capabilities in email and network, in cloud, SaaS, and IoT, to give you that full coverage. Effectively, our AI deploys into the core of the network, and what it's trying to do is understand what is normal and what is abnormal. Very simplistically, say a person who's working in the finance team came in at 9:00 in the morning, they checked their emails, browsed the web, pulled down certain files. But then something very strange was happening in the background. Say they downloaded something executable, and something happened in the background of the device, and there was some beaconing out, speaking out to some command and control structure, or there's some port scanning or IP scanning, or there's some lateral movement. Darktrace's mathematics would then pick this up as very unusual for this particular device, and that is how we pick up new and novel threats rather than relying on rules and signatures to determine what is bad within the network. We also have the autonomous response capabilities, and this is really important. We've been talking about this for three years, and I think Gartner now said autonomous response is the way forward. For a lot of people in the cybersecurity industry, everyone knows there is a skills shortage, and it's very difficult to hire, retain, and keep highly qualified people. So this is where we really believe is the future: autonomous response, automating as much as possible in the process. This is what we call Antigena. To talk a little bit about how we apply this in the network, we're taking very specific actions within the network to ensure that device is going back to its normal behavior, blocking the unusual connections that are happening in the network, but critically still allowing access to, for example, a domain controller so that device can still go about its usual pattern of life. The important thing about this is that it has to be targeted to ensure business continuity. It also allows time for humans to catch up. I think everyone last year was thinking ransomware was almost dead, and it certainly had a resurgence this year. So this is where it's very critical to have that autonomous rapid response to allow human teams to catch up and deal with the problems. I want to talk about some of the things that we see every day. We have this interesting screen around all our offices around the world which highlights some of the finds of the week, shown to employees to show what our technology is doing. We see anything from cryptocurrency mining to IoT hacks. A very interesting case in Kazakhstan where there was a malicious actor at a manufacturing plant. To get access to this manufacturing plant, a very sensitive industry, they had a fingerprint scanner, and the criminals had actually uploaded their own fingerprints to the system so they could gain physical access to the building. I think this is actually the first time a criminal voluntarily uploaded their own fingerprints. That was probably one of our most talked about. Also in the US, we had an employee who had a Tesla car connecting into the corporate Wi-Fi and was using the Tesla car to exfiltrate data. I was at a client yesterday, a financial research company, and they had one of their employees at the weekend bit mining from their device using a lot of the company's resources. So we find some really interesting hacks and threats, which is fascinating. We're also starting to see AI-based attacks coming in because it's so easy. You can go on the dark web, buy a ransomware kit for 20 to 200 dollars, find malware kits, and now we're even starting to see AI-based threats. There's one which is trying to understand, in a phishing attack, which methods, which wording gets the biggest results, which understanding of email traffic understands the right approach to get into that network, and they'll use that to apply it to other networks. So the emergence of AI-based threats is quite alarming and quite interesting. We had our conference in Barcelona, and some of our R&D were giving a few insights. I'm not sure how much I can talk about that, but they were talking about how they train the Darktrace AI. They effectively have a defensive AI and an offensive AI, and they pit them together. Obviously, the defensive software we sell and our clients use is that defensive AI, and then they have an offensive AI which they're pitting against each other to try to improve the quality of them. Apparently, the offensive AI they have developed in the Darktrace labs is pretty dangerous, and they've obviously had to pull it back. It just gives you the scale of once an AI starts learning a system from malicious attempts, how dangerous it could possibly be. The only way to defend against it is using AI. I know it's a bit of a buzzword in the industry, but applying AI techniques in the real world is also very difficult because every single company is different, every network is different, the resources and manpower vary. Some people have 50-man SOC teams, some smaller companies might have a one-man IT team. So using AI is an effective way of leveling the playing field slightly. Just looking into some of the attacks that we are seeing resurging, one is certainly ransomware, especially in the US this year. It's still highly profitable. Again, it's so easy to download ransomware kits from the dark web, but also now you can hire people to be more specific with the campaigns to specifically target certain industries rather than just firing it out there. It's becoming more targeted and more dangerous. The noisy attacks are not hard to find, but what about the slow and low type of attack, especially ones like the British Airways attack which was in the network for about 270 days? This was malware which was fairly quiet for a long time. Just an example: you might have malware in the network which is quiet for a couple of weeks, but then wakes up and connects to its command and control, says 'Hey, I'm here, what's my next instruction?' and then goes back to sleep for another couple of weeks. Wakes up, does something else, might start to scan a few other devices, understand which areas it can talk to, 'Oh, that's an area I can potentially target,' go back to sleep again, then waking up and starting to try to brute force entry into an area of the network. These slow and low type attacks are very difficult to pick up in a network, especially in a noisy network. So the reliance on AI is so important to correlate all these weak indicators together to build up a stronger picture of what's happening within the network. Also, we see a lot of our clients on that digital transformation migrating to the cloud. The cloud has much greater resource, and what we found interesting at Darktrace is that malicious actors are using the benefits of the cloud to their own advantage, mainly in the form of bit mining because they can use a lot higher resource. So we've seen a lot of bit mining resulting in a lot of clients' clouds, which has been a really interesting development that I don't think we probably saw about a year ago. To conclude, AI is absolutely paramount to dealing with cybersecurity, especially given the human resource limitations. So it's incredibly important to use AI in cybersecurity. And that is it. We also have a stand, so if you want to find out a little bit more, come and chat to us.