Threat Detection, Kate MacLean – Lacework
Mike talks to Kate MacLean, Sr. Director of Product Marketing at Lacework about its new threat detection and alert investigation capabilities. They discussed not just the new features but also the evolution of CSPM and also the benefits of having their tool built on Snowflake, a data analytics platform.
Transcript
This is texturing TV. Hi, this is Mike Rothman. Welcome to Textron TV.
I am pleased to be here with Kate McLean from lacework. I think are you VPN product marketing or director of product marketing? Yes something product marketing.
I just gave you a promotion. Congratulations you thank you very much. Welcome to our TV Kate.
Why are you can't make the assumption that are audience is familiar with laceworks when you give us a little bit of information about the company as well as maybe a little bit of background on yourself. Sure. So as you mentioned I run the product marketing function at lacework.
I've been in cybersecurity for over a decade now at a variety of companies like RSA Cisco in and outlays for I'm so I'm happy to continue to focus on the space because it's so exciting now lacework for those that might not be, you know, very familiar with lace work. We were founded in 2015. The time and still today our least for Founders.
They really set out to change Cloud security forever with an automated and data driven approach. So we know the cloud enables organizations to build to innovate faster to grow their business, but it also creates, you know a number of challenges. Else Dynamic nature of cloud environments Cloud workloads creates a massive amount of noise and security teams in particular.
They're challenged to find the right insights Or the critical deviations in their environments, you know in the midst of all of this noise and the billions of signals that might be happening. So this challenge not unique to any specific industry every business really struggles to do it and to have the data that they need before. It's it's too late the other thing, you know teams are siled.
They work in different work streams different tools. They have different priorities and it often leads to inefficiencies when it comes to collaborating to respond investigate and resolve issues. So lacework, we take an automated data-driven approach that enables us to ingest process analyze contextualize these billions of signals related to that cloud activity helping customers to identify unusual behavior threats vulnerabilities with more efficacy and ease of use than other tools and then for investigations, we also provide A little graphs context Rich event cards were automatically correlating information across customers events that could take hours days longer to piece it all together manually.
And so we actually find that our customers are you know, significantly reducing their investigation time with us and they're actually reporting significant reductions in their their alert Farm volume as well 121 reductions even that we're weeding out kind of the informational low criticality alerts to focus on the most critical that they really need to find a way to resolve. So tell me a little bit about you know, who is the typical user of of your tool right? Because you know, when you think about Cloud right, you know, we've been able to democratize a lot of Technology infrastructure.
You have business users, you know, folks call that shadow it I hate that right because it's derogatory. The fact is folks are you know business users and business groups are starting to feel their own it organizations because they're not getting what they need at a central it, right? The cloud gave them the ability to spin up a whole mess of stuff right build out applications really support Innovation at you know, kind of our technology driven Innovation at scale that they couldn't in a velocity that they couldn't do that before right, but now that kind of starts to get a little scary for security folks, right?
You know, what are they doing? I don't have visibility over that. I'm not really sure they don't know what they're doing.
Right? I hear that a lot. They don't know what you're doing.
So are the users of lace work, you know, they tend to be you know, business oriented folks who have no idea what security is and and why they should care about this stuff is that the central life security folks that basically just say listen, give me a hook, right? You know, let me Connect into your Cloud accounts and let me make sure that I've got, you know the visibility in that in environment. So who tends to use you, right?
Yes. It's a good question. I mean, I think it varies greatly as you said also very by size of company likely industry.
So, you know, we work with some of the largest and small. Most Innovative companies out there really to secure that underlying technology so it could be you know an IT department. It could be a security department.
It could be a platform team a chief product officer. We're working with an engineer a devops. We work with a variety of folks.
But we typically find is we start with security and then we end up engaging with the extended team because really everybody has a hand in securing Cloud environments cloud workloads, or if they don't they're not preventing or addressing risks early enough, right because risks should be at risks of misconfiguration risks of vulnerability the earlier the easier you can address those the less kind of problematic it becomes later on when they become costly issues or or things that attackers can exploit when they're they're inactive and production environments. com and and you know, contain your journal and and not just our security practice, right? We talk a lot about shift left, right?
You know, how do we get closer to the code? How do we get closer to that? But it's the same kind of thing in Cloud, right?
And and one of the things that's most interesting to me is that you know in traditional on-prem infrastructure on a tax attack, right somebody's on the outside or somebody's in the inside. They're trying to do something malicious their Boston into your stuff. They're breaking your things but in Cloud, you know Miss A misconfiguration because it could trigger something that's publicly accessible and you don't have other defenses.
Right a misconfiguration can be just as damaging as an attack somebody who has no idea what they're doing and they're all a lot of them out there, right? They don't know what they're doing, right they can cause this, you know, huge issue on that front. So so the ability of giving a lot of different folks visibility over what's happening.
In the environment and really not just looking for attack and I know we're gonna talk about detection in a second, but I don't want to go there quite yet, um, you know, because misconfiguration is such a huge problem in class. It's tell me a little bit about I mean, I know that's where you guys started right? So tell me you that term democratize, right?
So we say that makes security information more accessible to teams, right? So we actually are history is deep-seated. It's kind of agent based workload protection or runtime protection.
So we've been focused on getting all of the data really that a security team wants to dig into and understand what's happening. And then over time we've expanded left as you suggested to offer more kind of low friction security because that's something else devops Builders platform teams. They want, you know to secure things they want the protection but with the least amount of friction, right because they're they're focused on building things faster platform teams keeping the lights on the infrastructure up and running and so they want things that can help them, but it is not To take something down break something slow there their flow of innovation.
I'm so we started to kind of workload protection and then we moved left to offer capabilities around compliance reporting kind of configuration management vulnerability Discovery and management in November of last year. We acquired a company soluble to offer IAC scanning. So as you said kind of Shifting last and giving developers and Builders easy ways to check in as they're building to try to prevent the downstream effects.
Of misconfiguration or vulnerabilities actually being, you know publicly facing and exploitable for attackers. Yeah. No, that's great.
And one thing Beyond another thing that I think is kind of unique and interesting about your platform before we get into the news. I promise I will get from up is I know you guys at least you were are basically built on top of snowflake right so that you know, so and and for those of you not familiar, you know snowflakes say managed data warehouse, I guess is the best way to put it it's a business Analytics tool you're pumping the security Telemetry into or all kind of contract. I guess we shouldn't just restrict it to security but you know basically pulling all of the Telemetry into snowflake building, you know, and obviously of your proprietary schemas intelligence all kinds of so, can you just give us a little bit of a sense about what you know, kind of being built on this, you know, truly Innovative and and modern data platform does as opposed to the old flat files.
I mean if you were at Network intelligence or you know are saying that witness or any of those These big flat file things that we're trying to, you know, make give us information. And now we've got, you know, kind of just such a powerful data platform underneath that. How's that, you know kind of opened up opportunities for yeah, as you said, so we're ingesting as much data as we can in every way possible with our agent or with our agent kind of scanning and scanners.
Right? So the more data we can get the more we can learn from it. So we've got dozens of models that we're using to analyze the data and we're so we're ingesting all the data we're normalizing it.
So we also work in a multi-cloudment so we know AWS Google Azure have different languages. We abstract all that information to get the data and get an understanding of what's Happening regardless of the environment you building or the multiple environments that you build in so ingesting data normalizing it and then applying, you know our models to look for deviation. So we're looking at each customer building baselines for how their environment typically operates and then looking for deviations from that typical.
That Norm so, you know our in our models actually are pretty pretty simple in what they're looking for when it comes to threats in particular they're looking for is this normal is this expected should this be happening? And if the answer is no we're gonna again alert on that critical deviation. Now, we're finding the known bad stuff too.
The the, you know, crypto Mining and the things that are tagged and have you know, Associated, you know, domains associated with crypto mining whatever that might be. We're identifying the known stuff the more importantly it's that unknown stuff that's kind of low and slow or elusive that you haven't that the world hasn't seen before or is unique to your environment and that you really have a challenging time because of all of the signals and noise. I'm so we're able to uniquely find that and then as you said all the other stuff to you, so not just, you know configuration information all of that all of the cloud trail logs the cloud audit logs where ingesting all of that and trying to get as much information there as well.
All the failed API calls the spikes in the compute all of that that could signal just Weird wacky unusual behavior that's compromised or maybe a misconfiguration a glitch or something that you want to stop. So we're trying to find any issues as early as possible by getting as much as much data normalizing it and then applying our models. That's right and and the cloud, you know gives you scalability to be able to at a much more effective cost point at gather all of that Telemetry, right?
I mean, I I can't tell me calls I've taken from you know customers that are bitching about, you know, again vendor that you know, kind of jacks you up on an ingest based, you know cost model to be named later. Right? But nobody's ever said.
Oh, I'm really happy with their pricing, you know, so Cloud I think opens up a lot of opportunities there. But back to me, you know, the anomaly detection pieces. I know the news that you came here to talk about before I took you off on a variety of detours is about a new, you know time series modeling capability that you have on the platform to supplement a lot of the Atlanta not only detection there.
So when we talk about A little bit of what you do and on the Eastern response side as well because yeah, I guess that's why you're here not to just you know kind of kids. I'm happy to Check right? So we sometimes you know replace tools that you might have suggested.
Sometimes. We also augment or complement them. So organizations will have something like a Sim tool for a variety of reasons compliance.
They need the logs. Right but organizations will oftentimes put us in front and pre-process logs. So we're seeing our customers report up to 50% reduction of ingestion costs when it comes to them because we're able to correlate a lot of that data that helps them so they don't need to use that same tool for all the things for all the querying of investigation and and identification of threats too.
So I didn't want to lose that thought I use. Yeah. But are exciting news like you said so our our improvements and detection investigations.
So we as we've been talking about data is gold right like data is so important and we're looking at using new and expanded data sets to find risks and risks earlier with our new enhancements and also enable our customers to more effectively collaborate across their teams and their tools to respond faster with our time series model. We're adding that to our existing behavioral engine and we're detecting things like crypto jacking compromised accounts earlier by using time as kind of what we're looking at the new dimension and then in terms of the investigation, we've revamped our enhanced our alerting experience. We now have a bi-directional sync with jira.
And some interactive or collaborative experience in our alerting which helps to speed kind of response makes teams just streamlined investigation and and operate smarter and faster. That's like the thirty thousand foot view of the the announcements, but I'm happy to kind of take a deeper as well and kind of go through the guts of what that means. Yes, especially the integration with your because you know, a lot of what we talked about especially something that's very important to our audience is is kind of the intersection of devops and security and I don't call this SEC Ops because that's a programmatic thing.
Right? But you know, your attends to be the tool that a lot of these devops teams use in order to track all the issues that are happening both on the day and the op side so, you know really integrating with with your you know gives the security folks. In fact the seat at the table right that they're able to you know, kind of view what's happening from, you know, kind of a defect that could impact security or you know, some type of operational challenge that could be some type of malicious activity there so that they've got one place where they're handling all those issues it was that the thinking behind that Yeah.
We actually have an existing at your integration as well, but it's not by directional but 50% Nearly 50% of our customers use our existing integration. But what it does today is If an event is flagged in our least work platform. We automatically open a ticket in jira and then an organization obviously gets that notification if they if that's their workflow tool of choice, right but then let's say they close it in jira.
That's where it's broken. It doesn't automatically sync back and that requires somebody to close it out in jira, then go back open up the laser clap platform and close it out there as well with this kind of buy direct directional configurable think we're moving that tedious process of manually updating it in both. So not only can you work within the work pool that is or the you know, the workflow management tool.
That's your choice. It automatically sends the information back to us. So you don't have to think about it again, right?
So bi-directional thank you work where you want to with the team that you're used to working with automatically sends the information back to our latest work platform. So as you said if devops is in jira automatically is gonna send that information back to the least work platform if that's where let's say you're security team is spending time. Yeah, that's that's great.
So Kate, thanks for thanks for joining us on on Tech strong TV today really appreciate the time appreciate the learn a lot more about lace work. And as well as some of the new capabilities that you'll be rolling out mid-august I guess or is this stuff, you know kind of right which asset and kind of happened at any time. So yeah the time series again is looking at anomalies based on volume spikes and volume that's already generally available actually, but the the bi-directional safe with jira is rolling out soon for sure.
Okay. That's fantastic. Appreciate the time Kate McClain senior director product marketing for lease work.
I'm Mike Rothman, and we will hand it back over. Thank you.