Defending Against Cross-Domain Cyberattacks with Cristian Rodriguez
Cristian Rodriguez, field CTO for the Americas at CrowdStrike, discusses how organizations can better protect themselves from cross-domain cyberattacks. This includes how organizations can adopt a unified cybersecurity approach, the latest research on the emergence of cross-domain cyberattacks, and why these attacks are easily mistaken for normal user behavior.
Transcript
This is Textron tv. Hey guys, thanks for the throwaway here with Christian Rodriguez, who is field CTO for the Americas for CrowdStrike, and we're talking about cross domain attacks and the signal and the noise, and it's just getting harder to figure out exactly what's going on in the land of cybersecurity. Christian, welcome to show.
Oh, thanks for having me, Michael. I think everybody is kind of, sort of struggling with the same thing. We are picking up all kinds of signals through our systems, but we don't know how to make any sense of it so that we can respond in time before the attack actually hits us.
Um, I think AI has helped us a little bit in that in the future going forward, but what's your assessment of what is our maturity in cybersecurity these days and what are people getting right and what do they need to work on? Yeah, I think, um, great question. Um, I think one of the issues is, you know, companies invest in a lot of, uh, different tools and each of these different tools have, you know, disparate sets of data that they bring to the attention of defenders.
And, you know, you know, more data doesn't necessarily mean easy. More data means more data. And to your point, you can really get lost in that, uh, especially when you are, you know, experiencing this UI whiplash of hopping from screen to screen, uh, trying to make sense of it all and trying to tie it together.
And I think as, um, as adversaries become a lot more sophisticated in their, in their approach to, uh, targeting their respective victims, um, they are adopting, you know, a multitude of ways and approaches to get into these environments versus, you know, kind of the olden days of, you know, I have all my assets behind a firewall, and I can kind of focus on a very specific set of my environment to, to, to, to get visibility. I think, you know, the, the approach of an adversary kind of targeting so many systems, um, you know, becomes, makes it very difficult for defenders to start to understand how to prioritize what events look at. Um, and, and, and, and because of that, because these attacks are so multifaceted and defenders have to invest in so many different technologies, it becomes a bit of a challenge to get your arms around, you know, what data you should start to prioritize looking at, or even just tying that data into a narrative that helps you understand the motivation and the trade craft of, of these adversaries.
And that trade craft seems to be evolving because, um, for lack of a better analogy, I feel like it used to be more smash and grab, and now they're kinda breaking into systems and staying around for a long time and seeing how everything works before you know they're there. In theory, they shouldn't be giving off signals that it makes it possible for us to detect that. But, um, what's the challenge?
The challenge is these adversaries are, are are logging in, uh, with legitimate credentials, right? And they're emulating the behavior of like an administrator or a normal user. We, we have plenty of reports and evidence of, uh, of adversaries simply, you know, using a, an account of, of, of a, of a user or an admin where they log onto a system and they, they start to use tools that are inherent to the operating system to kind of mask their efforts, right?
And that's kind of hard to, you know, the, the days of using just malware, um, I don't wanna say they're gone, but they're a little less prevalent, right? Where an adversary logging in with a legitimate account or a legitimate identity can start to move laterally in a, in a way that, um, is a lot harder to, to capture if you're not looking for very specific types, types of, of of trade craft and activity. Do you think the bad guys are kind of, I don't wanna say they're laughing at us, but maybe they're slightly bemused because we spend all this time trying to defend against these sophisticated attacks and they're basically like, guys, you left the key under the doormat and I just got all the credentials and away we went.
Yeah, I mean, I don't know if they're necessarily laughing, but I know that they are, are walking through, uh, their victims' environments a lot more, uh, unhindered versus, you know, the efforts in the past that were, um, initiated with like malware for example, right? I think that's, you know, again, malware isn't going away, but it's just not being seen as an entry point. As much as we've seen in the past, we've had, um, you know, evidence of a major increase in the amount of access brokers, for example, selling legitimate credentials in these underground forums that, again, to your point, make it very easy for these adversaries to kind of simply just walk in through the front door, um, without being questioned or, or challenged, right.
Or circumventing ways to be challenged. And then there are, you know, plenty of brute force attacks that adversaries have been using to, again, gain access to these credentials and these identities so that they don't have to drop malware and, and, and bring awareness to their, to their presence. And so yeah, you're, you're absolutely right.
I think they, these adversaries are, are just becoming a lot more effective at using identities to, as this kind of compromise point or this initiation point in order to, in order to further their attacks for, you know, motivations that can lead anywhere to, you know, from or start with exfiltration of data or, uh, even more destructive based attacks. And we reached some point where maybe we realize that we cannot succeed without some help from AI in this space. I kind of feel like we went from a high degree of skepticism of AI to suddenly, I don't wanna do this job without it.
Yeah. I mean, I think AI can be a, a bit of a double-edged sword, right? I think AI is there to act as, um, almost an assistance.
I, I would say that AI can help you get to answers faster. You know, what we're really talking about, everything you're describing kind of leads to this velocity issue where if the adversary's logging in with legitimate credentials, and once they're on a system, they're very pervasive and they're moving laterally, and their breakout time, for example, is increasing. We, we published a report, uh, this year that highlighted, uh, an average 62 minute breakout time, basically representing the amount of time it takes from, for an adversary to move la laterally from the actual initial point of compromise or system being compromised.
And so I think AI helps with that timing, right? In, in terms of understanding things like anomalies in the way that users authenticate to different systems or the resources that we're, they're requesting once, once they have authenticated successfully. I think AI isn't meant to necessarily be this mental prosthesis, right?
Where you become solely dependent on it to get your answers. I think it can help streamline answers and responses and workflows in an effort to get your arms around, you know, known tradecraft and known behavior, um, creating automated ways to respond to it and helping you threat hunt, um, a lot more, um, efficiently. Uh, but, you know, AI I think is just another, another tool in, in your toolbox of, of, of, you know, capabilities that you want to implement into your threat hunting program and your remediation strategy to help reduce your mean time to detect your mean time to remediate, um, and at the end of the day, stop an attack from happening.
So how have we gotten to the point where now we're measuring, uh, uh, responses in seconds? 'cause time is of the essence, and maybe if I think back to threat hunting a few years ago will be by comparison feel like a leisurely sport. Yeah, I don't know.
It's, yeah, a Leisure sport, I think a bit of a stressful one too, That, um, Yeah, I think, I think what we're seeing is, um, when you're in threat hunting historically, you've had these three major approaches, right? You, you're looking for, uh, outliers, you're using atomic indicators, and then you're, you're almost creating this kind of like hypothesis statement that you're chasing of, you know, if I'm a bad guy, what would I need to do in order to gain access to the system, stay persistent, and then kind of run through that entire, you know, kill chain, if you will. Um, and I think AI can absolutely help with that.
Um, you know, with respect to how do I start to identify outliers in my environment, if I start to understanding application behavior better, that will help me understand anomalies in the way that the application behaves moving forward, if there's something that an adversary is taking advantage of, or if I'm seeing authentications and I'm trying to get acclimated with the way that my users authenticate in my environments, and all of a sudden this user that is authenticating to the system from Jacksonville, Florida, you know, suddenly seconds later tries to authenticate to that same resource, another resource from like Oxford, uh, for example, like that should ultimately be driven by some additional, you know, intelligence to say that's not right. There's, there's no way that this user can travel that quickly, or there's no way that this user who's accessing or requesting access to a resource after they successfully authenticated if they were making a, a, a requesting a resource that they historically haven't, or they're trying to do something within that resource that seems anomalous. I can actually start overlaying AI to help me make a better decision on the likelihood of that attack activity being, being malicious, right?
But more importantly, I can even start to tie this story together to say that I've seen this authentication, I've seen that this user is coming from a resource like an endpoint, and maybe they're requesting access to a server, and now they're on that server now getting data ready and maybe that server's in the cloud, and there's certain misconfigurations around that. I think that entire ability to take all of these, like these four disparate, you know, data sources, right? And, and, and resources that are providing data and events, if I can take that telemetry from all of them and start to apply logic and AI across that so that in terms of patterns and baselining and even outlier identification, I can use AI to help me make a better and faster decision on what is normal, what is suspicious, and what is truly malicious by my mapping that back into trade craft that I've observed historically and then evolving trade craft that we're, we're actively observing.
So Do you think it's becoming more stressful to be in cybersecurity or less? And I asked the question because the more is it's in real time and the less is, it seems like I got better tools to discover all this stuff, so maybe I got a finding chance. Yeah, I mean, I mean, I think, I think stressful is a bit subjective, right?
Depending on the industry that you're in, you know, like we, even within cyber, um, I think that, um, you know, the adversaries aren't slowing down. I mean, we, we've seen, uh, I think AI can help take a lot of the rudimentary things that we've been kind of, um, tightly wound about as defenders. And so even if we're talking about, um, even if we're talking about kind of basic threat hunting capabilities and, and skill sets that we need, I think that AI is absolutely going to help augment those efforts and, and, and simplify some of those efforts so that we aren't having to deal with a certain mundane and very routine tasks.
I think we can handle a lot of that back to ai. Um, I think when we start to really dig into what does evolving trade craft look like, what, what am I dealing with? If there's a nation state in my environment that is very well resourced and has the, the abilities and the capabilities and the skill sets to live in environ my environment or take advantage of certain protocols that historically we haven't seen exploited or to, um, you know, leverage supply chain attacks in an effort to gain access to not only my environment, but like my business partner's environments, I think AI is going to help us, again, get rid of some of the very rudimentary tasks so that we can start to focus and, and even leverage AI to augment our efforts to hunt within those more complex types of, of, of campaigns.
And so I don't know if that's necessarily something that reduces stress. I think it, I think if anything, it creates a heightened awareness. I don't think there's a concept of sitting back and resting on our laurels hoping that AI is gonna be the, the, the final answer.
Uh, you know, the bad guys get smart, right? And there's a human behind that keyboard and humans are very persistent and, you know, and, and I, and, and AI is also helping the bad guys at the end of the day, right? Ai, AI is being leveraged for very nefarious purposes as well.
And I think that it, it, if it's gonna make a defender's life easier, it's also gonna make the bad guy's life easier. I heard somebody kind of describes cybersecurity once as it's kind of like being in the army long periods of boredom punctuated by SHEEO terror. Um, and I'm asking this question because I'm wondering if it can reduce the burnout rate that we see in cybersecurity.
And one of the challenges we talk all the time about how there's not enough experts out there and not enough people in the field, but part of the problem too is the folks in the field burn out. Yeah. They burn out because, um, you know, the bad guy just has to be right one time, right?
And the defender has to be right all the time in terms of, you know, protecting the organizations that they're responsible for, and that, that could be, um, if you're under resourced and understaffed, that can be a lot, right? And I think, um, I think as a community, uh, there are plenty of services out there that can help, um, bring together, you know, kind of this community immunity perspective into like, what's, what else is happening out there? I don't think it's necessarily something that defenders should be, should feel that they're alone.
Uh, you know, and, and it's not a job that should necessarily be isolating. I think this is a, this is a job that basically should bring, you know, regardless of who you work for, if you're defending against nation state actors and ECR actors that, you know, have major implications with respect to the damage of, of their attacks being successful, I think there are, there's so much opportunity that we have as a cyber community to come together and, and not only share intelligence, but uh, share experiences, right? And, um, you know, and ai, it can absolutely be even kind of a focal point for a lot of that, uh, you know, that kind of, kind of bringing that community together because there could even be ways where one organization is leveraging AI in a creative way that, you know, maybe organization A leverages it, leverages it really well and, and organization B doesn't.
And if they start sharing some of those use cases, I think that actually takes a little bit of that stress off of that, that burnt out defender to say, oh, I never thought about using AI in this capacity, for example. Um, and, and, and I think there, there's the opportunity to, for talking about the, the, the, the, the, the people aspect of working in cyber. Yeah, I think there's plenty of opportunity for collaboration, right?
And that includes sharing experiences, you know, sharing how they're using AI creatively, um, and then sharing, you know, um, you know, even just challenges, right? On, you know, resource constraints. Because I think, you know, the, the more that folks talk about some of these issues, the more I think that you'll start to see better collaboration even across the vendor side.
So ultimately, what's your best advice to folks when they're trying to deal with this massive amount of data? It's near real time response, and the, the game has certainly changed. So what are I gonna do to stay relevant?
Yeah, I think, I think, um, I mean we're, we're always big proponents for people process and technology and, you know, intelligence kind of sitting at the heart of that paradigm. But I think when we start to, to look at this picture of, okay, you know, as earlier described, we have all of these different data sources that are disparate, and we have this UI whiplash experience of hopping from screen to screen, and we have, you know, no real way of under even understanding how to prioritize things like patching, right? I think the first goal is to, to start to look at, um, what are my data sources that help me dictate, uh, what a true positive is when I'm doing my response and when I'm doing my triage and my threat hunting.
And if I can start to get a better understanding in the handle of out of the, the 50 or the 25 different data sources that I'm taking into a log aggregation tool, for example, if I can take like the top six, right, and start to, to, to hone them into what helps me get to identifying a true positive the fastest, right? So they can start building workflows and using AI to help me dictate what my response, uh, action plan is, how to threat, how cross that data, how to actually correlate the fact that someone logging in from, you know, or using an, an authentication or using credentials on one system, uh, is also, also has this ripple effect across cloud services and maybe, you know, on premise systems or virtual systems, you know, aggregating that data in a place where I can quickly scope out what is relevant across those like, you know, six or seven data sources. I think that is actually a really quick way to start getting a, a little more sleep, because now you have, you know, a, a lot more, um, high fidelity signals, right?
We talked about, you used the term signals earlier, the high fidelity signals going into a tool set that can correlate all that information very, very quickly so that I understand that an endpoint impacted by this identity, this identity also access these cloud resources. These cloud resources also have these misconfigurations, these misconfigurations lead to these vulnerabilities. That is a story that helps me as a defender understand very quickly, like where I need to start my threat hunting, where when I can end it, and ultimately what is a true positive.
But if I'm now chasing 20 different data sources and trying to build a correlation manually, or even adding AI to that, the 20 data sources, that's still 20 different data sources that I need to, to parse through and understand contextually if they're relevant, when at the end of the day understanding, you know, what an adversary's trade craft is, how that maps to something like a framework like miter, for example. Then applying controls around that in a way that doesn't require me hopping from screen to screen to screen. I think that, you know, if we're talking about how do we reduce stress and how do we start to leverage a DI and how do we start to simplify, you know, getting our arms around this very datas disparate problem that a lot of enterprises have.
I think it's going into a technology or a platform or a framework that allows you to take those very high fidelity data sources and, and contextually have workflows and actions that you can build around it as quickly as possible. All right, I think Christian has come up with a new KPI here for security. It all comes down to how well you sleep.
So maybe we'll measure those, we'll measure those pleasant dreams and see how it goes from there. Christian, thanks for being on the show. Thanks for having me.
All right. And back to you guys in the studio.