CrowdStrike’s Ajit Sancheti on Swivel Chair Syndrome
Ajit Sancheti, general manager for next-generation security information event management (SIEM) at Crowdstrike, explains why swivel chair syndrome that adversely impacts the effectiveness of cybersecurity teams is finally coming to an end.
Transcript
Hey guys. Thanks for the throw. We're here with Jit Sancheti, who runs the Falcon Next Gen Sim platform over at CrowdStrike.
And we're gonna be talking about, well, whiplash. Turns out that cybersecurity analysts have been in these swivel chairs for so long, and as they move from screen to screen, you know, it's, it's a danger because you know, your head starts to hurt after a while. And it looks like, though, finally we're gonna do something about all that agent welcome to show.
Hey, Mike. Good morning. Good day.
Nice to see you. Um, how is the SIM evolving? 'cause I think that the whole security analyst experience has always been, well, less joyous, shall we say.
I mean, by the time I sort through all the different screens and things that I am trying to prevent, there's just a high level of stress because every minute that goes by, I, at least in my mind, um, more damage is being inflicted. So how can we kind of just make that job better? Uh, it's a good question, right?
So you have, you have to understand where the current sims came from. Primarily they were log management systems. They did a good job of it.
Then we started to deal with things like apps. If you remember, you know, I date myself when I say that in 2005, then you started to figure out, okay, how can I use the SIM to identify these apps? I know it's hard to do, it takes time, but they, they were doing their job quite well.
But what has happened over time, as you look at the evolution of the modern attack vectors, what attackers have done is they've started to leverage all the other technologies that we need to do beyond the endpoint to, uh, to identify threats. So what I mean by that is SaaS technologies, cloud applications, identity platforms, compromise credentials, things like that. Attackers have started to figure out, okay, how do I get into an enterprise beyond just doing something like malware and getting onto the endpoint?
Now, as they started to do that, the challenge for enterprises became the, the security operations team became pretty apparent. Now, you had to go beyond the endpoint. You had to bring in all these other data sources.
Bringing in these other data sources meant that the, the, the, the, the SIM platform that you were using had to match the speed and the accuracy that you needed to respond to these threats. Because in addition to the fact that you're bringing in more data, which we'll talk about in a minute, it, you know, has its own challenges. The attackers themselves are moving faster.
In fact, you know, if you look at the CrowdStrike, uh, latest threat report, it's down to almost two minutes when before they've been able to get into an enterprise, and it's even less time once they get into the enterprise and they start to move laterally. So now we're talking about minutes and seconds, and we cannot respond in hours and days, which means that you, if you look at the SIM itself, you're bringing in more and more data. Well, that's the, what we call a CrowdStrike.
The data paradox has two different dimensions to it. One is the cost dimension. As you bring more and more data, it's non-linear, the cost that the same vendors charge you.
The second is the performance. You start to lose more and more of the performance, the more data you bring in. So what you're doing is you're starting to make these choices, financial and performance decisions, and you're not bringing all the data you need to bring when you don't bring in all the data you need to bring.
Well, now you have to start to figure out, okay, can I do the first level of triage on the SIM platform? Then the swivel, you know, chair syndrome. Let me move to my endpoint platform.
Let me move to my identity platform. Let me move to these other platforms to go and do more and more of the detailed analysis I need to do. So the SIM has evolved, but the nature of the threats has evolved a lot faster, and which is what we're trying to solve with what we call, you know, with what you need to build in the next generation sim.
What does that look like exactly? Is it truly one screen, or is it just my ability to navigate from screen to screen within the, and save context is just better? I mean, how fundamentally different is my experience gonna be?
Yeah. So you want to be on one screen, and you're gonna do as much as you possible to get on one screen. The way you do that is you start to think about, okay, when I have a threat, what's the first place I go to?
You see, usually the endpoint, all your telemetry that you get from the endpoint, that's where you normally go to. And if, and as you know, CrowdStrike started with the EDR, you know, the endpoint security. And so a lot of the telemetry that you're looking for when you're looking for threats comes from the platform.
So if you can make your endpoint platform, and you can build all the capabilities on top of it to make it your sim, by bringing in all the third party data, bringing in the signals that you need, bringing in, uh, the ability to respond to threats automatically on those third party platforms, you will spend most of your time in one screen. It's gonna be very rare for you to say, now I need to go from the sim. I need to go back and look at the other platforms to see how to respond to the threat.
So you, you start out with the endpoint, you bring in third party data, you do the normalization on top of it, you build, uh, the machine learning models on top of it, ai, all of that on top of it. So not only can you detect and prioritize your threats, you can also respond faster. So all on one screen, To your point about the data, have we reached a point where we really can't process this stuff without the help of ai, uh, because we do need to respond in near real time and it's just become a, a challenge that's more than a human's gonna be able to handle on their own?
Yeah, it is a human limit, right? We're starting to hit the point where you're bringing in, in some customers for CrowdStrike, we're bringing in petabytes of data. Who's gonna have the time to process that much data?
And really you're looking for the signal from the noise. To do that, to do that, you need to have really good models that will help you identify the threats. But you're not just looking for identifying these threats when they happen, but you're, you're also looking to see how you can be predictive about these threats that might happen.
So what that means is trying to understand attack paths, trying to understand navigation, how the attacker would go through your network. Where are your weak spots? What's your exposure?
So it's, it's, you have to be very careful that it's not always, the sim is not always just responding. We have to think of the paradigm where the sim is. The next generation SIM is also helping you predict so that you know where the response needs to take place.
What is your rule book? What is your workflow? How are, how are you as an organization going to attack a threat that you see?
So yeah, it's, it's very much a, yep, we need to build models, but we had to be very careful that we only think, we don't think only about response models. We also think about how we can start to predict these things as they happen. Are we also gonna start to see a wave of consolidation of tools?
Because if I look back over the past decade, we got a little tool happy, and now we have a tool for just about everything. But then I gotta stitch all those tools together and support that and maintain that. So have we reached some point now where basically the weight of the tools is just too much?
Yeah, the it, it shows up in multiple different ways. Uh, if you look at, uh, the number of, uh, uh, tools at the endpoint, we went from so many different agents sitting on an endpoint. When you talk to an enterprise, more often than not, the first thing they say is, I need to consolidate the number of agents I have in my endpoint.
And, and for us as a, as a crowd tech, as a company, we've always spoken about the single agent and the single agent that does everything that you needed to do, depending on the kind of, uh, attacks you're trying to, or the threats you're trying to identify and respond to. So that's one place where the consolidation has been very, very apparent. People are saying, you know, I need to do more with the agent that I have on my endpoint.
'cause ultimately, security is helping the employees do their job. The more agents you put on there, the more your performance suffers. The more complications you bring into your network, the more management you have to do.
So that's one place. The other is on the man on the management of the response side. So if you, if you think about it, if you had to go to different platforms to respond to a threat, all of that is time.
And if the attacker is moving at the speed of minutes and seconds, you can't go to different platforms so that the consolidation is also happening at the management layer. It, you know, insecurity waxes a wanes, right? We go through the place where we say we need one platform, then we go to the time we say, well, we need best of breed.
But ultimately, a lot of the platforms that are coming out now are pretty much doing what the customer and the enterprise needs for its, uh, security needs. So you will see more and more of this consolidation. We don't think it's more, it's, it's required because we started that way, but it's gonna be something that you'll see with other vendors also.
Mm-Hmm. It also seems like we're trying to give the analysts more time or allow organizations to invest more in analysts by automating more of the security operations side of this and maybe integrating that more with the IT operations in general. Because I feel like, uh, a large amount of effort has gone into maintaining the security platforms versus actually fighting the fight.
Yeah, yeah. Such, such a, such an important point, right? Because the, our goal should be to, for, to make the analyst work on the high value activities.
But so much of what we've done until now is just make them do the mundane day to day. You know, you don't figure this out. Triage this, so much of this can be automated.
If you automated, then they work on the high value, uh, activities that make them interested. You also have the question of turnover, right? When you make people do boring jobs, they don't want to be in that job.
So the more you do to make it, make it so that they're working on high value and, and working on the harder problems, the more likely you are to retain your talent. And that's gonna be one, one part of it. The other is all of our systems are interconnected.
So as you said it, I sometimes we can't even tell the difference between whether this is a problem that's gonna be solved by it, it's a problem that's gonna be solved by the security team. Because as you know, an integrated part of a, of a, of a, of a next generation similar at least, is the security orchestration and response. And when, when you're responding, you're not just responding on security platforms, you may be responding on an IT platform.
So now the two teams have to work together very closely. So more and more the the lines are gonna start getting blurred because our, our job is to stop the breach. Our job is not to say, Hey, this is a security problem.
This is an IT problem. So the teams will start to spend more time together. We still have this, despite the rise of ai, this ongoing skills shortage issue.
Um, when to what degree are people relying on external expertise versus their own internal expertise? And, um, I know early on a lot of people were wiggy about relying on external expertise, but have we gotten to some sort of maybe happy medium There? There is a happy medium, but, uh, but I also think that with the newer solutions, what you're doing is you're expanding the number of enterprises that can do it themselves.
But I'll give you an example, right? When, when we started the next gen sim, uh, when you started, uh, offering the next generation sim to our customers, what surprised us was the number of even the smaller organizations that said, man, I can do this ourselves. Before we would be intimidated when somebody said, look at, you know, we need to get a sim, and we would say, we just don't have the manpower.
But now with the approach that we're starting to see with next Generation Sim, being able to bring all the data in one place, that's number one. And then building all these, uh, tools and models, it's making it possible for the smaller organization also to think about having a security posture that's almost as mature as one that has a lot more resources. But I will say that there are many organizations that would rather outsource some of this so that you can have external expertise, best of class, you know, a lot more expertise to help them out.
I don't think it's gonna be either or. Very often people are augmenting with external resources. So we talked about the fact that more of this is happening in real time, and that implies more stress.
And we've already seen that there's a lot of burnout in this whole cybersecurity space. So how do we kinda mitigate the burnout factor if we're need to respond in more real time and there's just more angst in the environment. Yeah.
So what do, you will see, again, what you will see in the, in the, in all the new sims, uh, you know, what we call the next generation sims is going to be a lot more automated response. One of the fears of responses in the past was the, the signals are so noisy. If you respond, you're going to do something with, you know, maybe a false positive.
Now as your detection accuracy goes up, what happens is you can be more confident in your response. Not only can you be more confident in the way you automate your response, you can also be very granular. So you can be, you can get down to the identity, you can get down to the end point.
You can start to respond in a way that if you did take action, it's very, very restricted and targeted. So that's gonna help a lot as you start to think about how, how do I make my employees not, uh, get burned out, automate your responses. Build, get the models to start, become self-learning.
As the models become more learning, they start to take care of a lot of the issues. And again, it takes your employees and start working on the high value items and the activities. And so you, you get less burnout people.
It's not hard work that people worry, right? People worry about the very repetitive nature of doing the same thing over and over again. So if you get them to solve other problems, they're gonna be interested.
Is it gonna be simpler to roll back something as well in that age of automation? 'cause there's one way I could put it, it's one thing to be wrong. It's another thing to be wrong at scale.
So how do I kind of maintain some level of governance and control that in the event that something doesn't quite go the way I hoped? Yeah. So you'll start to build models.
So what, what one of the things that will happens with these models is they start, you start to build more and more confidence in the model itself, in the way it responds because it's learning. So I look at responses as a gray scale. You have the, you know, the allow every time to the deny every time.
And then there's multifactor, reauthenticate reset. You have a whole set of responses in the, on the gray scale. As you start to build more and more confidence in your models, you can start to get more and more, you know, uh, move more to the right of that scale so that you can start to take actions, which is going to be more important than just, you know, figure, uh, figuring out, okay, I got this problem, I'm always gonna block it.
It's not gonna work. And as the machine, as the models also learn your behavior and things changing, they can also decide, you know, how right or how wrong they were, and they start to back off in the way they respond to a threat. So you're gonna get both.
You're gonna get better and you'll move to the right, or you'll start to get less confident as the, as as the model say, okay, we made this was not right. You start to roll back. Because that's, again, it goes back to the point that there's so much data coming in and it's very hard for a human to process, but if you can get the accuracy up, you can get more and more definitive in the way you respond to threats.
Mm-Hmm. Um, as this kinda continues to evolve, um, do you think that, um, we need to rethink how we invest in cybersecurity? And I'm asking the question because about every three or four years, somebody stands up and says, we're investing in cybersecurity and it costs too much.
And yet it's not like the bad guys are always gonna keep doing the same thing. So do we need to kinda realize that this is an ongoing game of proverbial cat and mouse and, um, every time we do something, the opposition respond and vice versa, and it kind of just, we need to think through what our strategy is and what the cost of doing that is in a more realistic fashion? Yeah.
Now the, the, the way I think about it is this is a dynamic threat. There's nothing static about security challenges, right? So if it's a, if it's a dynamic threat, you need to think about the platform choices that you make that can scale somewhat, be somewhat futureproof, right?
Not everything is very, very future proof, but at least it can be somewhat future proof that that means that the platforms that you choose will be, you know, you can pick one platform and say, this is the basis of all the security I do, but it also plays well with others. It plays nice with others, meaning other new technologies that come in, I can leverage it, I can bring it to the same platform and I can work, work with it to solve a security threat. So you're not always making big, you know, let me lift, you know, lift and shift, bring in a new platform.
Again, the niche of my threat changed. I'm gonna change that again. So it's a, it's a cost of doing business because we are trying to protect our business, but you can also make the choices, right, in that you don't have to keep making huge changes.
It's incremental over time that adjusts to the nature of the evolving threat. You know, the threats have changed, right? You look at malware was, was a big deal until about four or five years ago.
Now it's credential compromise, four or five threats as some identity compromise, uh, component to it. So attackers are changing. Your platform has to evolve, but as it evolves, you have to make sure that you don't have to go back and rebuild everything that you did in the last few years.
All right, folks, you heard it here. Cybersecurity is evolving one more time and it's something that we need to constantly be vigilant about and therefore make those investments. And a lot of times people will ask questions of like, are we winning or losing this battle?
And the answer is yes, on, on both counts. It just depends on what day of the week it is. Hey, agent, thanks for being on the show.
Thanks Mike. Thanks for having me on. Alright, and back to you guys in the studio.