Blog

Cloud

Keep the car running: Why AAA Washington turned to Autonomous Response

Standard-BlogbildStandard-BlogbildStandard-BlogbildStandard-BlogbildStandard-BlogbildStandard-Blogbild
02
Februar 2022
02
Februar 2022
This blog explains why AAA Washington’s security team chose Darktrace’s Self-Learning AI over a traditional SOC, and how they expanded its coverage to endpoints and the cloud.

AAA Washington kennt man hauptsächlich als Pannenservice, das Unternehmen ist aber auch in anderen Bereichen wie Versicherungen und Reisen tätig. Aus Sicherheitsperspektive haben wir zwei Prioritäten: Wir wollen richtig vorbereitet sind, um komplexe und weit verbreitete Bedrohungen wie Ransomware abzuwehren, und wir möchten die sensiblen Daten unserer Mitarbeiter und Mitglieder schützen.

Vor rund zwei Jahren waren wir an einem Scheideweg und mussten eine Entscheidung treffen. Unser Informationssicherheitsteam wusste, dass wir Lücken in der Echtzeitüberwachung hatten, insbesondere bei der 24/7-Response. Wir hatten zwar Tools und überprüften auch die Protokolle, aber es gab kein 24/7-Monitoring. Wenn also ein Angriff um 3 Uhr morgens stattgefunden hätte, hätten wir sicherlich nicht sofort Maßnahmen zur Eindämmung der Bedrohung ergreifen können.

Wir hatten also zwei Optionen. Das war unser Matrix-Moment, die Wahl zwischen der roten und der blauen Pille. Entweder waren wir bereit, eine lebensverändernde Wahrheit anzunehmen, oder wir würden den traditionelleren Weg einschlagen.

Für uns war die blaue Pille – und das, was uns viele damals empfahlen – die Beauftragung eines externen, rund um die Uhr arbeitenden Security Operations Center. Wir wussten, dass dies unser Problem lösen würde, aber auch mit vielen Nachteilen verbunden wäre, vor allem im Hinblick auf den Zeitaufwand: Man muss ein Service-Level-Agreement (SLA) vereinbaren, SNMP-Traps einrichten und Protokolle an das SOC übermitteln, das dann erst einmal all diese Protokolle durchforsten muss. Und dann muss sich das SOC neben AAA Washington ja auch um Hunderte anderer Kunden kümmern. Man muss eine Beziehung zu dem SOC-Mitarbeiter aufbauen, der aber anfangs die Nuancen der betreffenden Umgebung oder die Geschäftslogik nicht kennt …

Die Skepsis war daher verständlicherweise recht groß.

Und dann gab es da noch diese rote Pille. Für uns war das Darktrace mit seiner KI-Technologie, die sich eigenständig ein Bild von unserer Umgebung machen könnte und autonom auf sich entwickelnde Angriffe reagieren würde. Keine steile Lernkurve, kein ständiger Wartungsaufwand.

Wir mussten es einfach versuchen und testeten die Lösung zunächst in einer lokalen Konfiguration statt mit der Cloud. Das funktionierte reibungslos – wir bekamen die Box, schlossen sie an und schon waren wir startklar. Wenn uns das Produkt nicht gefallen hätte, hätten wir einfach den Stecker gezogen und es wieder zurückgeschickt.

Darktrace lieferte uns sofort neue Einblicke und schon in der ersten Woche erhielten wir den Warnhinweis, dass jede Nacht 1 GB Daten von unserer Backup-Appliance an ein Rechenzentrum an der Ostküste übertragen wurden. Wir dachten, wir wüssten, was in unserem digitalen Ökosystem vor sich geht, aber im Grunde hatten wir keine Ahnung. Darktrace lieferte uns genau die Erkenntnisse, die uns fehlten, und das zeigte uns, dass wir auf dem richtigen Weg waren.

Autonome Reaktion

Also volle Punktzahl bei Transparenz und Erkennung von Anomalien, aber was ist mit der Response-Funktionalität, wegen der wir überhaupt erst auf Darktrace gekommen waren? Wir waren gespannt, welche Maßnahmen Antigena empfehlen würde und wie präzise und tiefgreifend sie sein würden.

Da wir bei AAA Washington naturgemäß vorsichtig sind, richteten wir Antigena im Human Confirmation Mode ein. Das heißt, ein Mensch musste für die vorgeschlagenen Maßnahmen vorher grünes Licht geben. Es dauerte etwa zwei Wochen, bis sich die Technologie ein Bild von den Nuancen unserer digitalen Umgebung gemacht hatte, und schon nach kurzer Zeit konnten wir uns davon überzeugen, dass ihre Maßnahmen extrem präzise waren und sich nur minimal auf den regulären Betrieb auswirkten.

Antigena ergriff nie drastische Maßnahmen wie die Isolierung eines Geräts, sondern stoppte einfach nur die schädliche Aktivität. Die Technologie hat uns bei einigen der großen Angriffe, wie z. B. den SUNBURST-Attacken und zuletzt der Log4Shell-Sicherheitslücke, optimal geschützt.

Umstellung auf eine hybride Cloud-Strategie

In den zwei Jahren nach der Implementierung von Darktrace nahmen wir – wie viele andere auch – erhebliche Veränderungen an unserer digitalen Infrastruktur vor, darunter die Migration in die Cloud. Ich fragte mich, ob die Transparenz und der Schutz durch Darktrace darunter leiden würden.

Das war aber kein Problem, weil Darktrace spezielle SaaS-Module für Microsoft 365 und andere Systeme anbietet. Die Technologie deckt schädliche Aktivitäten in unserer gesamten Microsoft 365 Produktsuite auf.

Wir werden zum Beispiel über ungewöhnliche E-Mail-Weiterleitungsregeln informiert, die auf eine Kontoübernahme hindeuten. Bei anderen Tools muss man erst sechs- bis achtmal klicken, bevor man diese Informationen findet. Und auch wenn die Informationen vorhanden sind, ist der Zugriff darauf komplex und wenig intuitiv. Darktrace ist in dieser Hinsicht so etwas wie der Heilige Gral, weil es alle wichtigen Einblicke in einem Sicherheitstool bündelt. Dank dieser zentralen, ganzheitlichen Sicht reduziert sich der Zeitaufwand für die Auswertung und somit für die Response.

Selbstlernende KI auf den Endgeräten

Als es zu der massiven Verlagerung der Arbeit ins Homeoffice kam, schützte Darktrace auch hier unsere Endgeräte durch Transparenz und Autonomous Response. Mit Netzwerkschutz allein würden Bedrohungen wie Ransomware schlichtweg unbemerkt bleiben. Dass solche Bedrohungen erkannt werden, bevor sie sich ausbreiten und weitere Geräte infizieren, war für uns entscheidend.

Damit stellte Darktrace wieder einmal seine Anpassungsfähigkeit unter Beweis – ein weiterer Grund, warum ich von einer langfristigem Zusammenarbeit mit Darktrace überzeugt bin: Jedes Mal, wenn ich denke, es könnte vielleicht auch ohne Darktrace gehen, werde ich von den aktuellen Entwicklungen eines Besseren belehrt.

Immer sicher unterwegs

Darktrace ermöglicht uns genau das, was wir uns gewünscht haben, nämlich eine 24/7-Response. Aber das ist längst alles: Die Technologie zeigt uns immer wieder, dass sie sich an Veränderungen unserer digitalen Infrastruktur anpassen kann, mit dem Unternehmen wächst und unsere Mitarbeiter jederzeit und überall schützt.

Darktrace liefert uns mit dem Threat Visualizer alle wichtigen Informationen in einer zentralen Ansicht. Mit der App erhalte ich Benachrichtigungen über Warnmeldungen mit hoher Priorität und die eigenständigen Maßnahmen von Darktrace, egal wo ich gerade bin. Und wenn es wirklich ernst wird, ist immer jemand da, der mir schnell hilft und sagt, was ich wissen muss.

Dass ich vor vielen Monaten die rote Pille gewählt habe, war eine der besten Entscheidungen, die ich als IT-Sicherheitsexperte getroffen habe. Egal welche Herausforderungen uns erwarten, ich bin zuversichtlich, dass wir sie mit Darktrace meistern werden.

Weitere Berichte unserer Kunden

EINBLICKE IN DAS SOC-Team
Darktrace Cyber-Analysten sind erstklassige Experten für Threat Intelligence, Threat Hunting und Incident Response. Sie bieten Tausenden von Darktrace Kunden auf der ganzen Welt rund um die Uhr SOC-Support. Einblicke in das SOC-Team wird ausschließlich von diesen Experten verfasst und bietet Analysen von Cyber-Vorfällen und Bedrohungstrends, die auf praktischen Erfahrungen in diesem Bereich basieren.
AUTOR
ÜBER DEN AUTOR
Ron Nichols
Senior Information Security Analyst bei AAA Washington (Gastautor)
Book a 1-1 meeting with one of our experts
share this article
ANWENDUNGSFÄLLE
Keine Artikel gefunden.
PRODUKT-SPOTLIGHT
Keine Artikel gefunden.
COre-Abdeckung
Keine Artikel gefunden.

More in this series

Keine Artikel gefunden.

Blog

E-Mail

Looking Beyond Secure Email Gateways with the Latest Innovations to Darktrace/Email

Standard-BlogbildStandard-Blogbild
09
Apr 2024

Organizations Should Demand More from their Email Security

In response to a more intricate threat landscape, organizations should view email security as a critical component of their defense-in-depth strategy, rather than defending the inbox alone with a traditional Secure Email Gateway (SEG). Organizations need more than a traditional gateway – that doubles, instead of replaces, the capabilities provided by native security vendor – and require an equally granular degree of analysis across all messaging, including inbound, outbound, and lateral mail, plus Teams messages.  

Darktrace/Email is the industry’s most advanced cloud email security, powered by Self-Learning AI. It combines AI techniques to exceed the accuracy and efficiency of leading security solutions, and is the only security built to elevate, not duplicate, native email security.  

With its largest update ever, Darktrace/Email introduces the following innovations, finally allowing security teams to look beyond secure email gateways with autonomous AI:

  • AI-augmented data loss prevention to stop the entire spectrum of outbound mail threats
  • an easy way to deploy DMARC quickly with AI
  • major enhancements to streamline SOC workflows and increase the detection of sophisticated phishing links
  • expansion of Darktrace’s leading AI prevention to lateral mail, account compromise and Microsoft Teams

What’s New with Darktrace/Email  

Data Loss Prevention  

Block the entire spectrum of outbound mail threats with advanced data loss prevention that builds on tags in native email to stop unknown, accidental, and malicious data loss

Darktrace understands normal at individual user, group and organization level with a proven AI that detects abnormal user behavior and dynamic content changes. Using this understanding, Darktrace/Email actions outbound emails to stop unknown, accidental and malicious data loss.  

Traditional DLP solutions only take into account classified data, which relies on the manual input of labelling each data piece, or creating rules to catch pattern matches that try to stop data of certain types leaving the organization. But in today’s world of constantly changing data, regular expression and fingerprinting detection are no longer enough.

  • Human error – Because it understands normal for every user, Darktrace/Email can recognize cases of misdirected emails. Even if the data is correctly labelled or insensitive, Darktrace recognizes when the context in which it is being sent could be a case of data loss and warns the user.  
  • Unclassified data – Whereas traditional DLP solutions can only take action on classified data, Darktrace analyzes the range of data that is either pending labels or can’t be labeled with typical capabilities due to its understanding of the content and context of every email.  
  • Insider threat – If a malicious actor has compromised an account, data exfiltration may still be attempted on encrypted, intellectual property, or other forms of unlabelled data to avoid detection. Darktrace analyses user behaviour to catch cases of unusual data exfiltration from individual accounts.

And classification efforts already in place aren’t wasted – Darktrace/Email extends Microsoft Purview policies and sensitivity labels to avoid duplicate workflows for the security team, combining the best of both approaches to ensure organizations maintain control and visibility over their data.

End User and Security Workflows

Achieve more than 60% improvement in the quality of end-user phishing reports and detection of sophisticated malicious weblinks1

Darktrace/Email improves end-user reporting from the ground up to save security team resource. Employees will always be on the front line of email security – while other solutions assume that end-user reporting is automatically of poor quality, Darktrace prioritizes improving users’ security awareness to increase the quality of end-user reporting from day one.  

Users are empowered to assess and report suspicious activity with contextual banners and Cyber AI Analyst generated narratives for potentially suspicious emails, resulting in 60% fewer benign emails reported.  

Out of the higher-quality emails that end up being reported, the next step is to reduce the amount of emails that reach the SOC. Darktrace/Email’s Mailbox Security Assistant automates their triage with secondary analysis combining additional behavioral signals – using x20 more metrics than previously – with advanced link analysis to detect 70% more sophisticated malicious phishing links.2 This directly alleviates the burden of manual triage for security analysts.

For the emails that are received by the SOC, Darktrace/Email uses automation to reduce time spent investigating per incident. With live inbox view, security teams gain access to a centralized platform that combines intuitive search capabilities, Cyber AI Analyst reports, and mobile application access. Analysts can take remediation actions from within Darktrace/Email, eliminating console hopping and accelerating incident response.

Darktrace takes a user-focused and business-centric approach to email security, in contrast to the attack-centric rules and signatures approach of secure email gateways

Microsoft Teams

Detect threats within your Teams environment such as account compromise, phishing, malware and data loss

Around 83% of Fortune 500 companies rely on Microsoft Office products and services, particularly Teams and SharePoint.3

Darktrace now leverages the same behavioral AI techniques for Microsoft customers across 365 and Teams, allowing organizations to detect threats and signals of account compromise within their Teams environment including social engineering, malware and data loss.  

The primary use case for Microsoft Teams protection is as a potential entry vector. While messaging has traditionally been internal only, as organizations open up it is becoming an entry vector which needs to be treated with the same level of caution as email. That’s why we’re bringing our proven AI approach to Microsoft Teams, that understands the user behind the message.  

Anomalous messaging behavior is also a highly relevant indicator of whether a user has been compromised. Unlike other solutions that analyze Microsoft Teams content which focus on payloads, Darktrace goes beyond basic link and sandbox analysis and looks at actual user behavior from both a content and context perspective. This linguistic understanding isn’t bound by the requirement to match a signature to a malicious payload, rather it looks at the context in which the message has been delivered. From this analysis, Darktrace can spot the early symptoms of account compromise such as early-stage social engineering before a payload is delivered.

Lateral Mail Analysis

Detect and respond to internal mailflow with multi-layered AI to prevent account takeover, lateral phishing and data leaks

The industry’s most robust account takeover protection now prevents lateral mail account compromise. Darktrace has always looked at internal mail to inform inbound and outbound decisions, but will now elevate suspicious lateral mail behaviour using the same AI techniques for inbound, outbound and Teams analysis.

Darktrace integrates signals from across the entire mailflow and communication patterns to determine symptoms of account compromise, now including lateral mailflow

Unlike other solutions which only analyze payloads, Darktrace analyzes a whole range of signals to catch lateral movement before a payload is delivered. Contributing yet another layer to the AI behavioral profile for each user, security teams can now use signals from lateral mail to spot the early symptoms of account takeover and take autonomous actions to prevent further compromise.

DMARC

Gain in-depth visibility and control of 3rd parties using your domain with an industry-first AI-assisted DMARC

Darktrace has created the easiest path to brand protection and compliance with the new Darktrace/DMARC. This new capability continuously stops spoofing and phishing from the enterprise domain, while automatically enhancing email security and reducing the attack surface.

Darktrace/DMARC helps to upskill businesses by providing step by step guidance and automated record suggestions provide a clear, efficient road to enforcement. It allows organizations to quickly achieve compliance with requirements from Google, Yahoo, and others, to ensure that their emails are reaching mailboxes.  

Meanwhile, Darktrace/DMARC helps to reduce the overall attack surface by providing visibility over shadow-IT and third-party vendors sending on behalf of an organization’s brand, while informing recipients when emails from their domains are sent from un-authenticated DMARC source.

Darktrace/DMARC integrates with the wider Darktrace product platform, sharing insights to help further secure your business across Email Attack Path and Attack Surface management.

Schlussfolgerung

To learn more about the new innovations to Darktrace/Email download the solution brief here.

All of the new updates to Darktrace/Email sit within the new Darktrace ActiveAI Security Platform, creating a feedback loop between email security and the rest of the digital estate for better protection. Click to read more about the Darktrace ActiveAI Security Platform or to hear about the latest innovations to Darktrace/OT, the most comprehensive prevention, detection, and response solution purpose built for critical infrastructures.  

Learn about the intersection of cyber and AI by downloading the State of AI Cyber Security 2024 report to discover global findings that may surprise you, insights from security leaders, and recommendations for addressing today’s top challenges that you may face, too.

References

[1] Internal Darktrace Research

[2] Internal Darktrace Research

[3] Essential Microsoft Office Statistics in 2024

Continue reading
About the author
Carlos Gray
Product Manager

Blog

Keine Artikel gefunden.

Managing Risk Beyond CVE Scores With the Latest Innovations to Darktrace/OT

Standard-BlogbildStandard-Blogbild
09
Apr 2024

Identifying Cyber Risk in Industrial Organizations

Compromised OT devices in ICS and SCADA environments pose significant physical risks, even endangering lives. However, identifying CVEs in the multitude of complex OT devices is labor-intensive and time-consuming, draining valuable resources.

Even after identifying a vulnerability, implementing a patch presents its own challenges limited maintenance windows and the need for uninterrupted operations strain IT and OT teams often leading organizations to prioritize availability over security leading vulnerabilities remaining unresolved for over 5 years on average. (1)

Darktrace’s New Innovation

Darktrace is an industry leader in cybersecurity with 10+ years of experience securing OT environments where we take a fundamentally different approach using Self-Learning AI to enhance threat detection and response.

Continuing to combat the expanding threat landscape, Darktrace is excited to announce new capabilities that enable a contextualized and proactive approach to managing cyber risk at industrial organizations.

Today we launch an innovation to our OT Cybersecurity solution, Darktrace/OT, that will add a layer of proactivity, enabling a comprehensive approach to risk management. This industry leading innovation for Darktrace/OT moves beyond CVE scores to redefine vulnerability management for critical infrastructure, tackling the full breadth of risks not limited by traditional controls.  

Darktrace/OT is the only OT security solution with comprehensive Risk Management which includes:

  • Contextualized risk analysis unique to your organization
  • The most realistic evaluation and prioritization of OT risk
  • Effectively mitigate risk across your OT infrastructure, with and without patching.
  • The only OT security solution that evaluates your defenses against Advanced Persistent Threat (APT) Groups.

The most comprehensive prevention, detection, and response solution purpose built for Critical Infrastructures

Darktrace’s Self-Learning AI technology is a cutting-edge innovation that implements real time prevention, detection, response, and recovery for operational technologies and enables a fundamental shift from the traditional approach to cyber defense by learning a ‘pattern of life’ for every network, device, and user.  

Rather than relying on knowledge of past attacks, AI technology learns what is ‘normal’ for its environment, discovering previously unknown threats by detecting subtle shifts in behavior. Through identifying these unexpected anomalies, security teams can investigate novel attacks, discover blind spots, have live time visibility across all their physical and digital assets, and reduce time to detect, respond to, and triage security events.  

  • Achieve greater visibility of OT and IT devices across all levels of the Purdue Model.
  • The industry's only OT security to scale threat detection and response, with a 92% time saving from triage to recovery.  
  • The only OT focused security solution to provide bespoke Risk Management.

To learn more about how Darktrace/OT approaches unique use cases for industrial organizations visit the Darktrace/OT Webpage or join us LIVE at a city near you.

Read more below to discover how new innovations to Darktrace/OT are bringing a new, contextualized approach to Risk Management for Industrial organizations.

For more information on the entire Darktrace/OT Solution read our solution brief here.

Darktrace/OT and New Risk Management

Risk Identification

Leveraging the visibility of Darktrace/OT which identifies individual systems throughout the Purdue Model and the relationship between them, Darktrace/OT identifies high-risk CVEs and presents potential attack routes that go beyond techniques requiring a known exploit, such as misuse of legitimate services. Each attack path will have a mathematical evaluation of difficulty and impact from initial access to the high value objectives.  

Together this gives comprehensive coverage over your real and potential risks from both an attacker and known vulnerability perspectives. OT attack paths as seen here even leverage insights between the industrial and corporate communications to reveal ways threat actors may take advantage of IT-OT convergence. This revelation of imperceptible risks fills gaps in traditional risk analysis like remote access and insider threats.

Figure 1: Darktrace/OT visualizing the most critical attack paths at an organization
Figure 1: Darktrace/OT visualizing the most critical attack paths at an organization
Figure 2: A specific Attack Path identified by Darktrace/OT

Risk Prioritization

Darktrace/OT prioritizes remediations and mitigations based on difficulty and damage to your unique organization, using the established Attack Paths.

We ascertain the priorities that apply to your organization beyond pure theoretical damage answering questions like:

  • How difficult is a particular vulnerability to exploit considering the steps an attacker would require to reach it?
  • And, how significant would the impact be if it was exploited within this particular network?

This expanded approach to risk prioritization has a much more comprehensive evaluation of your organization's unique risk than has ever been possible before. Traditional approaches of ranking only known vulnerabilities with isolated scores using CVSS and exploitability metrics, often leaves gaps in IT-OT risks and is blind to legitimate service exploitation.

Figure 3: Darktrace/OT leverages its contextual understand of the organization’s network to prioritize remediation that will have the positive impact on the risk score

Darktrace provides mitigation strategies associated with each identified risk and the relevant impact it has on your overall risk posture, across all MITRE ATT&CK techniques.

What sets Darktrace apart is our ability to contextualize these mitigations within the broader business. When patching vulnerabilities directly isn’t possible, Darktrace identifies alternative actions that harden attack paths leading to critical assets. Hardening the surrounding attack path increases the difficulty and therefore reduces the likelihood and impact of a breach.

That means unpatched vulnerabilities and vulnerable devices aren’t left unprotected. This also has an added bonus, those hardening techniques work for all devices in that network segment, so apply one change, secure many.

Figure 4: Darktrace prioritizes mitigation reducing accessibility of vulnerability and the overall risk score when patches aren’t available

Communicate Board Level Risk with APT Threat Mapping

Darktrace/OT bridges theory and practice as the only security solution that maps MITRE techniques, frequently used by APT Groups, onto AI-assessed critical Attack Paths. This unique solution provides unparalleled insights including sector and location intelligence, possible operating platforms, common techniques, exploited CVEs, and the number of potential devices affected in your environment, supporting holistic risk assessment and proactive defense measures.

Ultimately, this becomes a power dashboard to communicate board level risk, using both metric based evidence and industry standard threat mapping.

Schlussfolgerung

Darktrace/OT is part of the Darktrace ActiveAI Security Platform a native, holistic, AI-driven platform built on over ten years of AI research. It helps security teams shift to more a productive mode, finding the known and the unknown attacks and transforming the SOC with the various Darktrace products to drive efficiency gains. It does this across the whole incident lifecycle to lower risk, reduce time spent on active incidents, and drive return on investment.

Discover more about Darktrace's ever-strengthening platform with the upcoming changes coming to our Darktrace/Email product and other launch day blogs.

Join Darktrace LIVE half-day event to understand the reality versus the hype surrounding AI and how to achieve cyber resilience.

Learn about the intersection of cyber and AI by downloading the State of AI Cyber Security 2024 report to discover global findings that may surprise you, insights from security leaders, and recommendations for addressing today’s top challenges that you may face, too.  

References

1. https://research-information.bris.ac.uk/ws/portalfiles/portal/313646831/Catch_Me_if_You_Can.pdf

Continue reading
About the author
Mitchell Bezzina
VP, Product and Solutions Marketing
Our ai. Your data.

Elevate your cyber defenses with Darktrace AI

Starten Sie Ihren kostenlosen Test
Darktrace AI protecting a business from cyber threats.