Social Media & Cybersecurity – Mark Batchelor, 443ID
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Mark Bachelor. Who's CTO for 443 ID. We're talking about open source intelligence as it applies to security and what's going on in the world Mark.
Welcome the show. Thanks for having me. I appreciate it.
We've been doing some form of forensics forever in a day. Now, it mixed results, but you guys are taking a little bit more of an open source approach to this. So what's the difference in and how will the result be any different than we've seen before?
A good question, so I wouldn't say we're taking an open source view of it per se I'd say what we're really doing is we're taking what is already called open source intelligence, right? So if you were to think about what they Define as open source intelligence is basically anything that's publicly available. That's legally obtainable that you can use to do investigations on right and there have been companies that curate data like this for years and lots of organizations use that data to run investigations to figure out The Who Behind what happened in a lot of cases, right?
So you can think of social profile data you can think of IP address data data about email addresses that have been in breaches things like have I been owned and things like that, right all considered open source data if I've got enough of it I can generally or somebody you can generally the figure out who's behind it what their tracks were where they went the federal government's been doing this for years and it's it's ridiculously powerful when you have a lot of that data and so what we're doing with that data, Is I'm a long time identity security person. So I've been doing authentication and identity and access management for a long time and my co-founder and I decided to start this company because we had both seen what you can do with open source intelligence, but nobody had really applied it to the IAM space or the authentication space in real time yet. It's still kind of been in the investigative world so much, you know after the fact right.
So we decided to do is say look all this data is available. Let's curate a bunch of it some of our own let's you know, use some third-party providers and set it up in a real-time manner so that when somebody authenticates to something we can make a relatively informed decision about that person before we've even collected any data in our own platform about them, right so if I integrated my application Application I had I come with some baggage already. Right every we've all got it.
We've all been in breaches. You know, we've all do certain things with IP addresses we all exist in certain locations. So we've all got behaviors that are noted and even the lack of having behavior is a behavior right is a is it something to note?
And so what we did is we created a real-time platform to harness some of that open source intelligence data that exist out there to provide scoring back to platform so they can decide what to do. Next. Should they MFA the person should they run them through a full kyc process that type of thing based off of how risky they look so that makes sense.
Yeah. It's simplest level if I am traveling and let's say I'm in San Francisco and I have an IP address for that. There should be some activity online somewhere that correlates the fact that I am the in San Francisco such as I checked.
Somewhere and you can now capture that stuff in real time and kind of at least provide a higher degree of confidence in the fact that I am who I am. You got it and then to take it a step further what we're developing as we March forward is the ability to create a general fingerprint for somebody that says with some degree of accuracy. We'll never be a hundred percent accurate because this is all based on sort of Internet information right with some degree of accuracy.
This is likely Michael right? Because we've seen this behavior from him before we know that he generally logs in in this area from the science P. This is probably really is Michael and if it if your fingerprint changes or your behavior changes, we can determine that this probably isn't Michael you should probably ask for more stuff before you authenticate this person, right?
And what was the hard part about being able to do that in real time? Because all this data is out there and there's a bazillion apis for collecting and so what what happened what needed to happen on the back end to capture all that day, then turn it into something actionable. It's a good question.
So that's kind of the the gist of it really is that back end, right? So we had to build a pretty robust data ingestion platform, right the normalizes things and then once it's normalized sort of a caching mechanism to to make sure that we aren't constantly calling out the third party providers and things like that to get more data, but what we really were trying to set up to do with that back ends was let people create we call policies right let people create policies that tell us what level of risk their willing to take for that particular login flow or registration flow or whatever happens to be so we let them tune our policies. So the score that we give back is is valid for what their use case is right and so the hard part about all that was kind of putting together an algorithm that Normalize all that and make it.
For lack of a better term kind of dumb it down to get it down to a single score. Right? And so we wanted them to be able to influence our score which is why we've got both sides of the equation there.
We can influence scores we can also give them all the derogatories about that person. That makes sense. Yeah, and the idea is that not everything has the same level of risk and you don't really want to interrupt the customer experience too much for a low level.
Risk scenario versus something that's higher risk and today it seems like a lot of the policies we have in place are blunt instruments so I can little little more fine-grained approach. Yeah 100% So the example I always give is you know, if I'm Twitter. Died I want more users do I care if they're Bots kind of but I still want more users.
So I'd probably set up a policy that says look let more risky people in right? I don't care as much if they're on a tour exit node. I don't care if they're coming to me off of a VPN.
I don't care if they're been in a lot of breaches because I want more users. Whereas I'm a bank. I don't want those users.
Right? I want actual people that have been kyced into my platform, right? So we let them kind of decide what they want to do with it.
Right? And that was it's always been one of the things about this type of data is that you haven't been able to influence the facts or the facts, right? And so you've either been in breaches or you haven't you either recently been in a breach or you haven't but I've never been able to kind of tune it to my use case to say look.
I don't really care about the breaches, but I do care if they've been on a tornado things like that. right Who has the sophistication in these organizations to make those kinds of evaluations? I mean is it really part of say a digital transformation initiative or is it a security team?
Who's looking at this who's kind of waking up in the morning going? We need a better way of looking at this stuff in real time. Yeah, so we're relatively new in the market and we're kind of still figuring out a bit of our fit, but I'll tell you where we've kind of a couple places where we're finding some uptake.
IAM teams, so identity access management teams because they want to use our signals. to perform adaptive MFA Right, so they're rolling out multi-factor authentication for their consumer platform or even internally and one of the signals they'd like to curate is a bunch of Open Source intelligence. So they're using our scores in some cases to decide whether or not someone should MFA right?
So we've kind of latched on to some of those types of projects. We've seen some uptake in sort of the soc space. Right?
So people that are doing security audits that are running sock centers for other companies. They're using us to report against user populations. So they you know, they take their users population.
They run through our platform. They do a weekly report that says, here's all your risky users. Right and these people suddenly became risky and they weren't you probably do something about them.
Right? So we've been selling into security teams and I am teams mainly today. This is becoming a bigger challenge because frankly just more people are moving about these days.
They're working from home. They're working everywhere in between the home and the office and there isn't this real sense of consistency is to where anybody might be accessing any kind of service whether it's consumer or B2B related. Yeah.
That's one of the reasons why we started doing this. So you're familiar with user behavioral analytics, you know, there's there's a bunch of companies out there that do UVA and in general UVA had been not relegated but had been mostly focused on sort of internal activity, right? So, you know, when do you open your email?
When do you access this thing? When do you you know, what's normal for you? Right one of our premises was that on the internet, especially since everybody's remote now, what's the subset of that?
That is interesting? Right? So what IP address you normally come from what can we glean about your username or email address and your phone number?
For example, if you're doing MFA or register, right? Fed that data can we do similar things that uba does with less data and we actually think we've we're doing we're pretty successful at it at this point. I like to call it uba light.
It's it's not really UVA light but it's taking a subset of what they do to do the same thing with everybody going remote. It actually opened the aperture up for us quite a bit so that we could say well if you're in San Francisco today and tomorrow, you're in New York City, that's entirely possible, right? That's not impossible travel.
It becomes part of your attributes, right? So we come back later and we say look, is it normal for you to be in New York City? Yeah, you've been there before.
Is it normal for you to be in San Francisco? Yep, you've been there before. Is it normal if you mean Las Vegas, maybe not and so now we ask for more Authentication.
Makes sense. Yeah, is there a line here between that which is helpful and that which might be deemed creepy. I mean, do you have to kind of figure out you know, what exactly is the scenarios that you're trying to apply this in it without question.
There's a there's a line between that that's useful in that that's creepy. We're doing our best not to cross the creepy line. That's one of the reasons why we're only looking at those attributes that you would normally see right.
So email IP phone number, right? It's all readily available data. And yeah, it could be considered creepy one of the One of the things that I was always enamored with now we're not doing this but one of the things that I was always enamored with was the idea that ad tech companies could follow me all over the Internet so that they could sell me a pair of jeans, right?
Hey Mark likes jeans. He should show me show me ads for jeans right. Now.
Those companies only got to be right like five percent of the time or whatever. It is in order to for me to be happy with jeans, but the tech I always thought you could do something interesting on the security side with something similar without hat without doing tracking without, you know, playing the captain Mouse game of tracking cookies and all that kind of stuff. Right?
So that's what we're tempting to do. Here is use similar concepts for security purposes. Right and if I get it, right it's viewed as helpful and if I get it wrong, it's kind of viewed as you know, the latest version of trying to spam because of where I am, but I get the point hopefully as we go along you think the average person is gonna realize more and more about how much signals that they're generating and that people are able to track that and you know, once people understand that it becomes less creepy, right?
Yeah, it does to your point facts. The matter is everybody's generating a bunch of signals and we're tempting to curate those signals so that we can make better security decisions right and curate him in a real-time manner, right? It is where words something to go with this.
So you're absolutely right though. Everybody's gonna make more signals over time and we will only be Messier as things go forward. So what's the biggest challenge in setting all this up right now?
Biggest challenge we spent a bunch of time on that back ends the the data ingestion piece to make this thing real time had had been challenging. We finally we finally got there with it. We're very comfortable at this point with the kind of scale.
We can handle that's been challenging and The other piece that we don't know yet is sort of the regulations side of things. Right? So, you know what to California data privacy laws due to us, what does gdpr to do us we're pretty comfortable with where we are right now.
Because of what we're collecting and how we collect it, but we don't know what regulational due to us the future either. Right, so we spend a lot of time thinking about that and the way to do it right versus doing it in a creepy way, right? That's actually been quite challenging.
Into access this I just need to call an API or how do I actually feed this back into my systems single API call today? It's a get-score endpoint and you you pass us username. And/or email slash IP and we'll run it score it give you back everything we know about it and you make a decision.
It's pretty simple. Yeah, when you think is the biggest issue that people are not appreciating about this right now. I mean is it does the sea level really understand what's possible or the security teams is an education up in that level or do you think the rank and file and get this as well who understands what can be done?
so I think the security teams actually get this pretty well and they have tools for this already investigative tools for this most good security teams today that do sort of force modem for post-portums on hack attempts and that kind of thing are already using tools from vendors that pour over open source intelligence to help them figure out who try to hack up. Right? All we've done is just take that and want to put it real time into their workflows, right?
So they get it I think cisos understand it because they're already exposed to it again, but not a real-time fashion and the rank and file I think services like have I been ConEd have been valuable for the rank and file and so they can just go and find out how many breaches they've been in for example that service alone has has brought a lot of insight into wait a minute. If I just have my email out there. You can tell me exactly how many breaches I've been in that's kind of scary.
Right? So I think the regular file are starting to get it and they will Be they will use you know, our platform and others to to use adaptive MFA and various other things kyc right based on their scores, right? So I think they're starting to get there.
I don't think what we're doing is all that. New per se. I think what we're doing is in a novel way.
We've turned something that's been around for a while and it's something that's real time. All right, folks like any tool that can be used for good or ill. Hopefully are better angels will prevail.
Hey Mark. Thanks for being on the show. Yeah.
Thanks Michael. I appreciate it. All right back to you guys in the studio.