The volume and variety of attacks have left security teams playing catch up. Dwell times span days. Intrusions are left undetected for months. How can an organization accelerate incident detection and response to minimize potential damage and improve the defense?
Contributor
Transcript
Sanjog Aul [00:00:00]:
Welcome listeners. This is Sanjog Aul, your host and the topic for conversation is Accelerating Incident Detection And Response. So what we have seen is the volume and variety of attacks have left security teams playing catch up. There’s so much going on dwell times are spanning days, intrusions are getting undetected for many months and the organizations are trying to figure out how to tackle all of this. So what we wanted to discuss here on this topic is to see how organizations can accelerate their incident detection and response approach and processes to minimize the damage they may be causing and to improve the overall defense and to discuss it, I have with me Naresh Podila who is the Chief Information Security Officer with Pall Corporation. Hello Naresh,
Sanjog Aul [00:00:56]:
thank you for joining me.
Naresh Podila [00:00:58]:
Hey, thank you Sanjog. Thanks for having me.
Sanjog Aul [00:01:01]:
Great to have you and so the first question I have is why don’t you play like an analyst and give us in your view, the current state of incident detection and response. Where do you think enterprise security leaders are in handling it and do you think they can claim that things are going to get under control in the near term?
Naresh Podila [00:01:25]:
In most organizations that I have seen, incident detection is still heavily manual intensive, which means that it depends on the skills and expertise, the resources engaged in it on a day to day basis or in the third party who’s doing the monitoring for you. So that’s one area of concern. The second is that incident response itself has a number of handoffs. So there’s a handoff from the investigating team, the actual team that has to deal with it on the endpoint. Sometimes there is a handoff even there from one geography to another, as in from a triage unit to an endpoint support unit somewhere in the middle, information security needs to be communicated with and depending on the context of the item, all of these handoffs need to happen efficiently and that’s a lot of times the communication breaks down.
Naresh Podila [00:02:27]:
To answer your question on enterprise security leaders can claim that things are under control. I think there are definitely areas for improvement.
Sanjog Aul [00:02:36]:
So the focus that you had in your response was most around the handoffs or too many chefs or too many parties getting involved in getting things done. Is that where the quality and the predictability of how well an incident would be detected and responded to hinges on.
Naresh Podila [00:02:55]:
The responded to, hinges on that. Now the detecting part, as I said, is also heavily manual intensive. There it is, something of you are depending on the skill of a group of people to manage that effort of looking for the odd stranger and curious. Yes, there are log analysis tools and all that are available that are being leveraged but at some level, it still depends on the skills of the team.
Sanjog Aul [00:03:25]:
And so if you were to look at the different types of incidents, so is it across the board or would you say a certain type of incidents take the most energy, the most number of resources, and still they are the toughest to tackle.
Naresh Podila [00:03:45]:
In our context, I’ve found things are directly on the endpoint, especially when you’re working for a large global organization with a fairly mobile workforce, dealing with those are the most difficult. So if you get an alert for unwanted software or for malware on an endpoint, that’s where the multiple handoffs happen and that’s certainly it’s true in our case because once we get an alert like that, it goes to a triage unit. The triage unit says, okay, this endpoint is in Japan, it might be off business hours. So there’s no easy way for even if we have a 24/7 endpoint support team over there for them to reach this particular endpoint or the individual who has the endpoint. So now we have to wait until the person comes back in and is on the network. Anything to do with endpoint has greater challenges than something that’s on our steady, stable infrastructure, on prem infrastructure, even cloud infrastructure but non mobile infrastructure is a lot easier to deal with in a timely fashion.
Sanjog Aul [00:04:54]:
So while you speak about the endpoint and you mentioned that is the most time consuming, it could get the most complex. We still have the cloud, the network, the application areas. There are so many places where vulnerabilities could be found or incidents could be originating from. Are the rest of them in the same level of ease or complexity, would you say?
Naresh Podila [00:05:20]:
So in general, so if you look at vulnerabilities in the application area or on the network area, usually when you get an alert on that, you’re dealing with a certain amount of expertise in that area, because there is typically either outsourced or in house expertise that deals with that area, that when you find out something is odd, strange or curious happening in those kinds of areas, it is relatively easy because of the expertise involved, relatively easy to get somebody at least mobilized and start looking at what perhaps the incident response team is pointing to and jump into action. When you’re dealing with an endpoint and we are dealing with a user who has a laptop or desktop and the support person is trying to reach out, and they might not be in the same geography, they might not be facing each other across the table, getting that person to do something or getting access to that machine. That’s where the complexity it is logistical complexity sometimes.
Sanjog Aul [00:06:23]:
And one aspect is the, very time factor which is what you are alluding to when you’re saying how quickly can we get something done but then it also also has a component of where a person or a team which is going to try to look into. Suppose there’s something going on in the network and there may be some trigger, but when you have to be in order for you to find a solution, you have to be able to go in and figure out what’s going on. So even though person or the team has expertise, but things can be equally complex just to figure out what’s the intention of an intruder, what are they after? So that your response is not merely just try to plug the hole, but also to prevent any damage that they can cause. So to that end, would you say your weightage factor, if you will, on which type of incident is most challenging versus another, would that change the scale if you look at the very complexity on what that it is that you’re trying to solve?
Naresh Podila [00:07:26]:
Correct, so now if you’re talking about, if you’re looking at network based attacks and where you’re talking about an incident where, let’s say that there is data exfiltration happening, for example, that’s where, yes, where now you have to mobilize a team of people that might be across different functional areas, sometimes across geographies to come together and work together and solve the problem and look for where there might be issues that need to be dealt with but yes, that has its own set for challenges to deal with and to respond to incidents like that.
Sanjog Aul [00:08:04]:
So what about the security and the risk management strategies which if deployed would work well in the kind of environment that we are dealing with today, which is very dynamic, it is getting increasingly complex and things are coming from the left field which where we least expected them to come from.
Naresh Podila [00:08:29]:
So the first way that we could maybe deal with this better is think of ways in which we can automate the playbook in the sense that can we for each scenario have a playbook that prompts each actor in the chain with what the recommended actions might be given the particular scenario that we are talking with. If there is a particular type of incident and we prompt each accessor in the playbook, here are four things that you should look at, given what we are seeing or given the indicators that we are seeing in this incident or in this event or in this attack, if you like and that way, if you have a tool set that provides that kind of prompt to each actor in the chain of responding to an incident, that would certainly help in making sure that incidents are dealt with in an efficient manner, of course there are other things. Can we train our users to recognize the odd stranger serious and alert and provide an alert on the front line but that comes down to awareness but really, if we are able to automate playbook in the way that I spoke about, that would really help.
Sanjog Aul [00:09:42]:
Let’s take a quick break listeners. We’ll be right back and let’s look at the approach we take where we could outsmart the intruders and that approach could mean in terms of the process we may follow or the technologies that we deploy. Is it possible for us to even deceive them, set traps there or landmines as they try to come in so that we come to know about what they are trying to do, what is their intent, what approach they are trying to take so that it is not just about us preventing damage, but also in a way safeguard against any future attacks they may do because we will know their playbook? Is that even possible? Let’s explore that when we come back. Please stay tuned.
Sanjog Aul [00:11:40]:
Welcome back. So Naresh, when we are looking at the technologies that are available and the good news is at least there is a lot of innovation going on when it comes to security centric technologies. So have they reached a level of advancement and sophistication that not only just block the intruders but we could even outsmart them? Can we deceive them, have them fall into our trap as they try to come through and infiltrate and even learn about their intent, their playbook so we can beat them to the punch?
Naresh Podila [00:12:15]:
In our experience, yes, we do have some basic honey, frost and flakes. We use them here, we use them in other places. I’m not 100% that this is the most effective way or the technology is where at least we’ve been particularly successful in doing what you’re suggesting which is outsmart or flap intruders. I would say that depending on the kind of business that you are, if you are a B2C type business, big brand name that people recognize and where there are a lot of opportunists, I think it is much more likely that honeyford or straps of the nature that you suggest are effective. In the case of business to business businesses where you have much more fewer but more sophisticated intruders, they might not be quite as effective. So it’s, it stands a little bit. I guess another way of putting it is that the effectiveness of those kinds of things depends on the profile of the business that you’re applying to protect.
Sanjog Aul [00:13:20]:
I agree with you that everything that you’re going to deploy or the type of techniques and technologies you’re going to use will depend on the risk profiling. Agreed with you. Where do you think overall the security technology landscape is? Is it at a point where you feel we have been enabled if we choose to use them to go head on, have a face off with the intruders and beat them at their own game? Are we coming close to it if we put our mind to it?
Naresh Podila [00:13:51]:
I have not, to be honest with you, seen anything at that level of sophistication where organizations are, at least in the commercial business domain, where you’re battling or you have technologies that help you set up the battle in that way. Yes, I have seen honeypot type infrastructure in place on the network. They have been effect in certain places to a limited extent, but I’m not sure that they had the sweeping success that you are describing.
Sanjog Aul [00:14:23]:
And if there was a technology available, what would you have expected for it to have for it to be effective in achieving the end goal that I just referred to.
Naresh Podila [00:14:35]:
I think that we would have seen a lot more success in being able to protect consumer data than we see today in some the number of breaches that are out there in the marketplace every other day you feel like you’re hearing about a new incident or a new event that has happened and if these technologies and all of these businesses are motivated to the consumer data that they have and so if these technologies were as effective as we are talking about here, I think we would have seen more success coming from it.
Sanjog Aul [00:15:09]:
So that’s the outcome that you’re referring to. So in your view, because maybe the lack of knowledge about which technology is existing which could help you do it, or the very nature of the technologies that may exist today. What features and functions? Let me ask question another way. What features, functions or traits of a technology? If was available could help us do better than what we are doing today because you’re mentioning about the breaches that are happening. That means we have not been able to prevent them from coming back in again, these intruders, these infiltrators. So if we had to put a trap, for example, into like honeypot that you mentioned, would we have put one in an endpoint, application, cloud or network and what would be the most effective way of doing it? If such a technology existed?
Naresh Podila [00:16:00]:
I would say I think a network, an application server of some kind on the network, perhaps in the DMZ would be a good place to keep it. It would be relatively easily accessible and then you can see who’s getting at it and what’s happening and look at the source IPs, track things that way but that would be, I think the most effective or the best place to put the trap.
Sanjog Aul [00:16:26]:
And the reason you feel that it has not been done so is because perhaps the technologies or the solutions available or what people know are available are not seen as which could really make a dent in this problem. That’s why the investment wasn’t made.
Naresh Podila [00:16:44]:
Yes, I certainly believe that. I haven’t seen anything that promising in this area. So maybe there is a little bit of skepticism on how well the technology works.
Sanjog Aul [00:16:55]:
And that skepticism is rooted in because it is too good to be true. If there was someone claiming it, or would you say it’s because they don’t know even how to use the technology, where is this doubt? Where is this skepticism coming from?
Naresh Podila [00:17:11]:
I think it is a bit of both. Both of those reasons that you described that the technology has, of course here is a lack of conviction that technology is like this will indeed I think they would. My skepticism comes from the fact that they would probably deceive the relatively inexperienced or novice intruder, but might not deceive a more determined and professional intruder and that’s where my skepticism comes from.
Sanjog Aul [00:17:39]:
And so if, let’s say we were to go after this goal of accelerating the detection and response, would you going to go about working harder at it or would you use things like automation or would you not want to get better data which will help support the security management so that your strategies are right on? So one is to do quantitative scaling of effort, another is to get smarter about it. So of course the natural answer will be smarter but are we there yet where things which we need to get smarter about accelerating the detection and response? Do we have the wherewithal for it? Do we have the budgeting for it? Do we have the mindset for it.
Naresh Podila [00:18:32]:
So we in our business are certainly leveraging automation to sort out some of the problems I referred to earlier in the conversation, which is how do you ensure handoffs happen smoothly? So they’re basically saying certain categories of tickets we know need to go straight to desktop and support, don’t need to go through a triage unit, don’t need to go through so many handoffs. They can be directly sent off to a desktop support ticketing system where the desktop engineer can pick it up, pass on it, close it, and that should automatically close the ticket in the security event management system, for example. So we’re trying to reduce handoffs where it makes sense to reduce them. So based on categorization of tickets, this kind of automation just takes some analytical work, doesn’t really take a lot of additional investment in technology and tooling. Most organizations can do this relatively easily, which is to leverage automation where they can based on ticket categorization. So you’re not putting all tickets into one hopper and then dealing with all of them the same way, but developing different pathways for different tickets based on where they should go for the best response. The other area which is somewhat maybe aspirational is to leverage some of the capabilities of machine learning that are out there now in the marketplace to see if, to help learn, for example, for the technology to learn what normal looks like. So if they can understand, if the technology can understand what normal looks like in parts of the log, then would they be able to better detect anomalies than a fed hunter would in an incident response unit or a soc and that some of the promise of the newer technology or the newer capabilities really that are out there, that can potentially be leveraged for this purpose.
Naresh Podila [00:20:34]:
To answer your question, yes, automation on the incident response front can certainly something that we are looking at and we are using and can be leveraged I think relatively easily and the second is maybe for I have seen a little bit more aspirational, which is to use the newer capabilities that are in the marketplace to see whether we can do more in this phase.
Sanjog Aul [00:20:57]:
So one last question for you is that this is important and we want to accelerate the incident detection and response. So if you had to evangelize changes in the people, the processes and the tools to get the most out of any related investment, what would be your advice to other security leaders who may be listening to this?
Naresh Podila [00:21:23]:
So the first, I would say is simplify the process so that you’re dealing with a particular situation where the width of the organization is the most in other words. Make sure that if your attack surface is large that your response surface is large as well. Set it up so that wherever you have the greatest width of capabilities, that’s where all of that is being utilized in dealing with an incident when something happens. So that’s one to set up the process so that the strength of your organization, the width if you like, of your organization is dealing with the operational aspect of it. The second is inventory your system so that you have a good understanding of what your crown jewels, critical assets if you like, are so that you have an extra sense of ring of security, if you like, around these. So that if there is indeed an event that happens that seems to affect one of them, you are able to react with n times the speed and alacrity that you might otherwise. In other words, prioritize when dealing with incident response so that you are when some of your crown jewels or critical assets are impacted, you are dealing with them differently than you might be dealing with any other routine incident that comes your way or event that happens comes your way.
Sanjog Aul [00:22:52]:
Once again, thank you Naresh for sharing your thoughts and insights about how organizations can accelerate incident detection and response to minimize damage and improve the defense. Thank you so much.
Naresh Podila [00:23:06]:
Thank you, enjoyed it.
Sanjog Aul [00:23:09]:
And listeners, I’d like to invite you to find related conversations on our website at ciotalknetwork.com.
Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More
-
- How to Drive Effective Fraud Prevention and Detection
- Fraud Detection Through Technology
- Security and Agility – Tips for Getting the Best of Both Worlds
- Assessing Our Supply Chain Security Risks: We Are Only as Safe as Our Weakest Link
- Security in the World of Mobility, the Cloud, and Social Media
- Creating a Winning Cyberthreat/Ransomware Management Strategy
- Trick or Treat – Don’t Get Tricked by Bad Actors


