Managed Detection and Response with Generative AI – Tom Corn, Ontinue
Tom Corn, chief product officer for Ontinue, explains how the provider of a managed detection and response (MDR) service is with the help of Microsoft taking advantage of generative AI to make its security operations team more efficient.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Tom Corners Chief product officer for on continue. And we're talking about AI cybersecurity managed Services of all kinds of new types in the world is changing as we know it Tom. Welcome the show.
Thank you. Mike. Good to be here.
Thank you for having me. Every day we wake up somebody's talking about how this cyber security sky is about the fall because the bad guys are gonna get access to AI but turns out that the good guys are gonna get access to AI as well. So you guys are at the Forefront of this.
How are you guys using AI to kind of give your teams in advantage? And how does that benefit your customers at the end of the day? I think what we're finding is there's a whole variety of use cases for AI that have emerged that are Beyond just I certainly we've seen classification for example, identifying malware and an anomaly detection and I think has been already seen and we've been leveraging that we are we're a firm that really specializes on leveraging the Microsoft Technology stack Microsoft is obviously done a lot of work in here, but we're starting to see AI permeate a lot more use cases across security scoring scoring system and user Behavior ranking how We rank the criticality of vulnerability so that we can focus our efforts on the right places summarization.
How do we quickly glean out of a lot of information about a particular new threat actor or particularly threat the Salient points. So that's where we started to see large language models like gpt3 for example support. You know, I think we've started to see new models.
We've been leveraging things like chatbots and things like gpt3 to break the old model of we have a bunch of pre-canned reports for you to look at instead. You just ask the question will compile the answer to that. automation is another area that we've been starting to apply this to both wholesale automation of Investigation triage and response so that it can be fast consistent but also sort of Automation in the form of augmented intelligence.
How do we automate parts of the process for tier three analysts? So that they're not doing a lot of manual efforts on on things. So all of these have The started to permeate, you know, we we invested quite heavily in this we actually made an acquisition of a company called scuba a few years ago out of Zurich and burns switzerlands Switzerland by for those of you don't know actually has a realist strong Center for research in this area predominantly by ETA really one of the major universities there.
This was a group of data science phds, and we've been putting them to use on a pretty novel set of use cases. They've been modeling Defenders. supposed to attackers and really looking at what is how do they get the information treat the information the processes they go through we've been using that to identify.
Where are the bottlenecks. Where are the things that take too much time? What are the things that are done repeatedly and what's the difference between how the best analysts treat those on if use cases and we've been using that to drive an enormous amount of Automation in the system just to get much faster speed much more consistency and ultimately so that we're investing our dollars more on threat hunting and tier three analyst as opposed to more of the basic stuff and we've got a lot of success automating a lot of these pieces and speed is everything and security.
Do you think that we have found ourselves in something of an arms race when it comes to Ai and cybersecurity and that organizations will rely more on external service providers to get that capability because it doesn't seem feasible for the average organization that kind of build and maintain an AI model. Well, I think there's actually maybe a few points to your your question. Right one part is certainly AI is something that the attackers have access to as well, although candidly AI is still not writing great malware yet.
Um, but I'm sure that's on the horizon and there are more use cases for it too. I think we've seen the democratization of AI so a lot more people are using it and the challenge is going to become not just using things like gpt3 but how do you tune and chain it? So the the new Battlefield is going to be actually bringing people who are from data science backgrounds to really leverage that and tune models for particular use cases particular verticals, even for a customer or that's where the real big value is going to be.
Um, I guess the question of the arms race. I actually think some of the bigger problems will face is what will happen with regulation. You know to build these AI models means you need to aggregate a lot of information across customers across regions if that's not done carefully if that's not done an anonymized position.
What does that open up in terms of privacy laws across countries. And then also just again the democratization of these tools I think will end up in the beginning everyone will seemingly be the same but really as I saying earlier really how you tune AI to really get the right consistent set of results and how you have explainable ai models. So you're not just doing this blind and not knowing what it comes up with crazy answers is gonna become increasingly important.
I think that those kinds of issues are going to be the things we have to tackle in the coming. You know a couple of years and coming a few years much more than an arms race against attackers. Is there relationship between cybersecurity service providers and internal it and cybersecurity teams changing as we go along seems to me it used to be more of Outsourcing kind of relationship and maybe now we're getting a point where it's more about co-managing this together.
And you know, we're starting to get rid of a lot of that historic tension. Yeah, you know it's a good point. I think there's really two things there one is security as a team sport.
You don't solve this with? You your detection and response team needs to be able to collaborate with the broader security team and this and the IT team so much of security is operationalized by it security doesn't patch security doesn't configure even when you're implementing compensating controls that's often a broader it organization. And the reality to security is it's often boils down to making decisions accurate and fast and collaborating across these groups so that Is changing so that as you there's a hugely compelling reason to Outsource.
Because there's a shortage of talent you really need to bring an experts 24 hours a day seven days a week and that just is not your The Core Business of most organizations. but the ability to collaborate effectively with those groups is going to become really key. Number one and two it's going to be just as important that those groups understand the customers environment as that they do as it is that they understand the discipline of security because the thing that will stop an outsourcer from adding real value in response in it actually triaging and and prioritizing is their lack of understanding of the customers' environment architecture operational constraints.
So those two things for us, that's really meant right really doing two things one building a team of we call them cyber advisors basically sock Engineers that are assigned to a customer to build and maintain An environmental on a model of the customers environment their their structural context and also their operational constraints and our teams are using that model and maintaining that model to make decisions so that we're knowledgeable to burn environment. Otherwise, you can't make the right decisions on the second front this collaboration piece. We've taken I think a really radical departure here are our view was just the world doesn't need another Management console.
The world doesn't need another portal. And if what this really is is about real-time live collaboration. We decided to build our whole interface into Microsoft teams in our case.
Our customers. We're experts on Microsoft. Our customers are all using Microsoft Technology.
I'm on other stuff too, but they're used teams. They use Defender. They use sentinel those type of pieces.
To them teams is their operating system for the business. It's their nerve center. That's where they're communicating every day.
That's where they're sitting every day. So rather than taking them to a portal we went and built everything into them. If you're getting an alert for a critical we show up as a team.
We're an extension of their team and as in essence when something is notifying them it's an Adaptive card showing up in their interface. If if they need to connect with us, they're hitting and engage button in teams and that connects them by chat or video or voice to our Defenders anywhere in the world. If if they're asking questions, they have dashboards and channels, but they also have the ability to just ask a question and plain English in teams and a chatbot sort of helps connect them to the right information.
It's a very different model and you know, I when I think back over the last several years where we've had this whole discussion about security getting built in most of that discussion was about getting rid of agents and boxes and may starting to embed that in the infrastructure. I think this next leave is really this theme. How does the management of security get built in to the collaboration infrastructure that companies have I think that's going to make a real difference and certainly it's been A real game changer for us and to your initial question Mike it is made us.
Become far more an extension of people's teams. The van sort of a black box on the side and you know, the proof is in the pudding. It's it's allowed us to have much faster decisions and execution.
In the moment collaborating these teams. Does that become the means by which we ship security both left and right we hear a lot about bringing development teams and getting them more involved. We hear more about it operations teams are taking more responsibility for the security operations side and part of the issue is the historically those are a lot of manual handoffs.
So is that whole thing gonna become smoother because I have some Foundation layer like yours. I I think it is because what it says is there are different people who understand have different relevant context for major security decisions to your point. Mike.
Some of those are the application developers themselves if we're having anomalous behavior on a critical application. You know a great source to validate something would be the team working on that application if we're seeing, you know scenario we deal with a lot you have impossible travel scenarios right on a user. Well, maybe the best way to quickly do that is to show an Adaptive card to get the response directly from the user themselves this you were seeing this, you know, that gives us authoritative context on the ground in real time, and they're already is a system that abstracts the organizational structure and gives direct access to It's these type of systems like Microsoft teams like slack Etc and building it into that really starts to take advantage.
Of that so that we have the context directly from the sources the experts on these pieces. So yeah, I think that is one of the big ingredients of left and right. I hadn't thought of it that way but I think it's a really interesting way of looking at it.
So what do you think is the biggest challenge organizations run into as they kind of come to that thought process around how to meld these different constituencies together. You know, what is it? Is it a technical challenge or is it more a cultural issue?
I I think the thing that is probably stopping them is not initially a technical challenge. I think once they See through to the right way of doing it then it becomes a question of right do we have the right technical components to do it? Although ironically, I would say.
Most of them maybe don't realize they actually have it right in front of them. It's a question of how do they operationalize it? I think that's probably the best statement of our industry in general which is We don't lack for tools.
We don't lack for technology but we lack is the expertise on and the process to how we should operationalize that effectively. So I I you know, I I do find it interesting this in our engagements and it varies of course, but very often we find ourselves bringing together teams it and security as an example and in some cases to your point Mike even the application teams. In ways that is very profound and that never happened before.
I'm not sure I can answer why that doesn't happen before maybe these have been considered different disciplines and candidly each they may each they may each have preconceptions that the other group is more. a blocker to the things that they're doing but at the end of the day, I think we're all trying to achieve a common good which is we need to be able to conduct business and connect people and connect people to data and applications in a reliable and Safe Way and security should be away for us to move fast. Just like, you know, you know, the old cliche breaks are on a car to enable you go fast not to enable you to go slow and it security really should be that it should be ways that we can much more effectively manage risk so we can connect people so we can enable these kinds of transactions so we can enable this kind of work and I think the digital transformation that's going on right now.
Is a tremendous opportunity to take advantage of some of these new platforms and if we don't it will be I think the greatest missed opportunity in our industry. We don't take advantage of this for us. It's really been I think obviously we've had a very particular area of focus in our view was There is such a large constituency of companies that are leveraging Microsoft in our case for a lot of this digital transformation and it's such a large base that our view, you know most.
Managed detection and response Services tend to go horizontal and they abstract. I don't care what tool you have. We'll just support it.
We decided to go deep on a particular Tech stack with Microsoft, but I think it is allowed us to explore some of these areas that aren't just how do we support the you know, the AV engine or just the EDR component but instead think more holistically about things like the collaboration system things like how do you you know, yeah things like collaboration reporting, you know logic apps adaptive cards. It allowed us to explore a bunch of technologies that one would normally consider as Security Technologies, but it's we're trying to think of this from what's the job to be done here and the job to be done isn't just the detection engine. It's the workflow.
It's the collaboration. It's the localization. Of the service to the unique operational constraints of this customer.
So I think it's a really interesting. Time I think there are more dramatic changes going on and Security today than I have in my 22 years in security have ever seen and I think we're really all collectively starting to work on some problems that really matter, which is really my opinion. How does security truly get operationalized?
All right, folks, I might argue that the patron saint for cybersecurity should be Benjamin Franklin who once said if we don't hang out together, we will surely hang separately. Um, thanks for being on the show. Thank you.
Thanks for having me. All right back to you.