Rad Security — RSA Conference 2024 Innovation Sandbox

RSA Conference 2024 · Innovation Sandbox

Overview

This talk, presented by Brooke Motta, Co-founder and CEO of Rad Security, introduces a novel approach to cloud-native security: behavioral cloud-native detection and response. Given the rapid migration of applications to cloud-native platforms—projected to encompass 95% of all applications by 2025—and the alarming statistic that 90% of security teams reported a breach in their container and Kubernetes environments in 2023, the need for more effective security solutions is paramount. Motta highlights the critical shortcomings of traditional signature-based security, which proves inadequate against the escalating threat of zero-day vulnerabilities and sophisticated attacks, citing the recent XZ backdoor as a prime example of a threat signature-based systems would miss until it's "far too late."

Watch on YouTube

Visual summary for Rad Security — RSA Conference 2024 Innovation Sandbox
Visual summary for Rad Security — RSA Conference 2024 Innovation Sandbox

Key moments

  1. 0:00 Introduction: Cloud native security challenges
  2. 0:25 The critical flaw of signature-based detection
  3. 0:40 Rad Security's unique behavioral detection platform
  4. 1:00 Automated response actions and LLM-powered classification
  5. 1:10 Key benefits: Detect insiders, shift left, novel attacks
  6. 1:20 Impressive business growth, retention, and customer base
  7. 1:35 Founders' deep expertise in security and business
  8. 1:50 Concluding message: Peace of mind and runtime protection

Behavioral Cloud-Native Detection and Response: Shifting Runtime Protection Left

Speakers: Brooke Motta, Co-founder and CEO, Rad Security

Conference: RSAC 2024

YouTube: https://www.youtube.com/watch?v=2UiVrjZRNWA

Overview

This talk, presented by Brooke Motta, Co-founder and CEO of Rad Security, introduces a novel approach to cloud-native security: behavioral cloud-native detection and response. Given the rapid migration of applications to cloud-native platforms—projected to encompass 95% of all applications by 2025—and the alarming statistic that 90% of security teams reported a breach in their container and Kubernetes environments in 2023, the need for more effective security solutions is paramount. Motta highlights the critical shortcomings of traditional signature-based security, which proves inadequate against the escalating threat of zero-day vulnerabilities and sophisticated attacks, citing the recent XZ backdoor as a prime example of a threat signature-based systems would miss until it's "far too late."

Rad Security's platform aims to revolutionize runtime protection by "shifting it left," moving beyond reactive threat detection to proactive environmental fingerprinting. Instead of maintaining an ever-growing database of known attack patterns, the platform establishes a verifiable baseline of known good behavior within an organization's unique cloud environment. Any deviation from this established norm is immediately flagged as suspicious, enabling the real-time identification of novel attacks, malicious insider activity, and vulnerabilities without relying on pre-existing signatures. This approach not only promises enhanced security but also addresses prevalent industry challenges such as reduced security budgets, the complexity of new cloud-native environments, and the high rate of burnout among security professionals by streamlining detection and response with the aid of Large Language Models (LLMs) for alert classification.

Background

▶ Watch: Introduction: Cloud native security challenges (0:00)

The landscape of modern application development is overwhelmingly defined by cloud-native architectures, characterized by containers, Kubernetes, and microservices. This paradigm shift, while offering unparalleled agility and scalability, simultaneously introduces a new frontier of security challenges. As Brooke Motta underscores, 95% of applications are anticipated to be built on cloud-native platforms by 2025, yet the security posture of these environments remains precarious, with 90% of security teams reporting a breach in their container and Kubernetes setups in 2023 alone. This alarming statistic points to a fundamental inadequacy in current security strategies designed for this dynamic and distributed ecosystem.

The core problem, as identified by Rad Security, lies in the industry's pervasive reliance on signature-based detection. This traditional security model operates by identifying known malicious patterns, or signatures, in network traffic, file systems, and process behaviors. While effective against previously identified threats, it is inherently reactive. For every widely reported zero-day vulnerability, such as the recent XZ backdoor vulnerability, countless others go undetected for extended periods because no signature exists until the exploit is discovered, analyzed, and a defensive pattern is developed. By the time a signature is created and deployed, an attacker may have already achieved their objectives, rendering the protection "far too late." This reactive stance is further exacerbated by the rapid pace of innovation in cloud-native environments, where new services, configurations, and interactions emerge constantly, creating an expanding attack surface that signature databases struggle to keep pace with.

Beyond the technical limitations, the human element of security is also under immense strain. Security teams are grappling with reduced budgets, forcing them to do more with less. They face the daunting task of securing entirely new, complex cloud-native environments, often lacking specialized tools or expertise. This environment of high stakes, constant vigilance, and an ever-growing volume of alerts contributes significantly to employee burnout among security professionals, which Motta highlights as being at an all-time high. The existing security paradigm not only fails to provide adequate protection but also places an unsustainable burden on the very teams tasked with safeguarding digital assets. The imperative, therefore, is to move beyond reactive, signature-dependent security to a proactive model that can establish a verifiable baseline of an environment's intended state before an attack, thereby "shifting runtime protection left" in the security lifecycle.

Key Findings

▶ Watch: Rad Security's unique behavioral detection platform (0:40)

Rad Security's core contribution is its innovative behavioral cloud-native detection and response platform, which fundamentally redefines how organizations protect their dynamic cloud environments. The platform's primary value proposition centers on its ability to proactively fingerprint each unique cloud environment. Unlike traditional security tools that hunt for indicators of compromise (IOCs) or known malicious signatures, Rad Security focuses on understanding and establishing a baseline of known good behavior. This paradigm shift means the platform does not need to maintain an exhaustive database of millions of potential attack vectors or generate a signature for every conceivable threat. Instead, it operates on a principle of anomaly detection: any activity that deviates from the established baseline of normal, expected behavior is immediately flagged as suspicious.

This behavioral approach yields several critical findings and capabilities:

  • Proactive Zero-Day Protection: By monitoring for deviations from normal behavior rather than relying on signatures, Rad Security can identify novel attacks and zero-day vulnerabilities in real-time, long before a signature for them might exist. This directly addresses the critical weakness exposed by incidents like the XZ backdoor.
  • Malicious Insider Detection: The platform's ability to discern anomalous behavior makes it highly effective at detecting malicious insiders. Since an insider's actions, even if authorized, might deviate from their usual patterns or established "good behavior" for their role, the system can flag potentially harmful activities that might otherwise bypass traditional access controls.
  • Enhanced Shift-Left Security: Rad Security helps organizations hone their shift-left programs by integrating runtime protection capabilities earlier into the security lifecycle. By establishing a behavioral baseline from the outset, it allows security teams to build and maintain secure cloud-native environments proactively, rather than reactively patching vulnerabilities after deployment.
  • Automated Response Actions: Beyond mere detection, the platform offers concrete response actions. Upon identifying suspicious activity, security teams can quarantine, label, or terminate the offending action directly through the platform. This capability significantly reduces the Mean Time To Respond (MTTR) and mitigates potential damage.
  • LLM-Powered Detection Classification: To combat alert fatigue and improve the efficiency of Security Operations Center (SOC) teams, Rad Security leverages Large Language Models (LLMs) to classify detections. This intelligent classification helps prioritize alerts, reduce false positives, and provide richer context to analysts, thereby saving invaluable SOC team time and alleviating burnout.
  • Strong Market Validation: The platform has demonstrated significant commercial success and market acceptance, evidenced by its 3X year-over-year growth, an impressive 219% net retention, and 0% churn. This strong performance indicates a compelling value proposition that resonates with diverse organizations.
  • Broad Industry Adoption: Rad Security is already integrated into the tech stacks of leading companies across various critical sectors, including gaming companies, financial services organizations, insurance companies, and SAS B2B companies. This wide adoption underscores its versatility and effectiveness in securing complex cloud-native environments across different industry verticals.

These findings collectively point to a paradigm shift in cloud-native security, moving from a reactive, signature-dependent model to a proactive, behavioral-driven approach that offers superior protection against evolving threats while simultaneously improving operational efficiency for security teams.

Technical Deep Dive

▶ Watch: Key benefits: Detect insiders, shift left, novel attacks (1:10)

Rad Security's technical innovation lies in its implementation of behavioral anomaly detection specifically tailored for cloud-native environments, which are characterized by dynamic workloads, ephemeral resources, and complex inter-service communication within containers and Kubernetes clusters. The core mechanism is to "proactively fingerprints your unique environment" to establish a verifiable baseline of known good behavior.

At a foundational level, this fingerprinting process involves continuously observing and learning the intricate patterns of activity within an organization's cloud-native stack. This likely encompasses a broad range of telemetry, including:

  • Process Execution: Monitoring which processes are initiated, by whom, with what arguments, and their parent-child relationships within containers. Legitimate applications exhibit predictable process trees.
  • File System Access: Tracking read, write, and execute operations on critical files and directories. Anomalies might include a web server attempting to write to /etc/passwd or a database container accessing unexpected configuration files.
  • Network Communications: Observing ingress and egress network connections, including source/destination IPs, ports, protocols, and data volumes. Deviations could involve a container initiating connections to external malicious IPs or unexpected internal service-to-service communication.
  • Kubernetes API Calls: In Kubernetes environments, the platform would monitor API interactions. This includes kubectl commands, API server requests, changes to deployments, services, pods, and namespaces. An attacker compromising a pod might attempt to escalate privileges by manipulating Kubernetes resources, which would represent a clear behavioral anomaly.
  • System Calls (Syscalls): At a lower level, monitoring syscalls provides granular insight into how processes interact with the operating system kernel. Unusual sequences or types of syscalls can indicate malicious activity, such as privilege escalation or data exfiltration attempts.

By collecting and analyzing this rich tapestry of data, Rad Security constructs a comprehensive model of what constitutes "normal" operation for each specific container, pod, service, and the overall Kubernetes cluster. This baseline is not static; it continuously adapts and evolves as the environment legitimately changes (e.g., new deployments, scaling events, software updates).

The detection logic then operates by continuously comparing real-time activity against this established behavioral baseline. "Anything that deviates from that behavior is flagged as suspicious." This is the essence of anomaly detection. For instance, if a container that typically only serves web traffic suddenly attempts to initiate an outbound SSH connection or execute a shell script it has never run before, this deviation would trigger an alert. The system doesn't need a signature for "outbound SSH from web server container equals bad"; it simply recognizes that this is not the web server's known good behavior. This makes it particularly potent against polymorphic malware, fileless attacks, and novel exploits like the XZ backdoor, which might bypass traditional antivirus or intrusion detection systems (IDS) that rely on static signatures.

The platform's response actions—quarantine, label, or terminate—are critical for mitigating threats in real-time. These actions imply deep integration with the underlying cloud orchestration layer (e.g., Kubernetes API) and potentially cloud provider APIs. For example:

  • Quarantine: Isolate a compromised container or pod by modifying network policies or moving it to a restricted namespace, preventing further lateral movement or data exfiltration.
  • Label: Tagging a resource (e.g., a pod) as suspicious for further investigation or automated policy enforcement by other security tools.
  • Terminate: Automatically shut down and restart a compromised container or pod, effectively neutralizing an active threat by reverting to a known good state or preventing further malicious execution. This is particularly powerful in ephemeral cloud-native environments where resources can be quickly replaced.

Furthermore, the integration of Large Language Models (LLMs) to classify detections represents a significant advancement in operational efficiency. Instead of raw alerts, SOC analysts receive enriched, prioritized, and context-aware notifications. The LLMs can process alert data, correlate it with other environmental factors, and provide a human-readable summary of the potential threat, its impact, and recommended remediation steps. This capability drastically reduces the cognitive load on analysts, minimizes false positives, and accelerates the investigation and response process, directly addressing the issue of security professional burnout.

In essence, Rad Security's technical approach leverages sophisticated behavioral analytics and machine learning, applied to the unique characteristics of cloud-native environments, to provide a proactive, adaptive, and automated security posture that moves significantly beyond the limitations of traditional signature-based defenses. By understanding "known good" rather than chasing "known bad," it offers a more resilient defense against the rapidly evolving threat landscape.

Demo / Proof of Concept

▶ Watch: Impressive business growth, retention, and customer base (1:20)

The talk provided by Brooke Motta at the RSA Conference 2024 Innovation Sandbox was a high-level pitch designed to introduce Rad Security's capabilities and vision. Due to the format and time constraints of an Innovation Sandbox presentation, the transcript does not include any specific details regarding a live demonstration or a technical proof of concept for the platform. The focus was on articulating the problem, the solution's core principles, and its market impact.

Defensive Implications

▶ Watch: Concluding message: Peace of mind and runtime protection (1:50)

Rad Security's behavioral cloud-native detection and response platform offers profound defensive implications, fundamentally altering how organizations approach security in their modern application ecosystems. By shifting the focus from reactive signature-based detection to proactive behavioral baselining, it empowers defenders with capabilities crucial for navigating the complexities of cloud-native threats.

  1. Proactive Zero-Day Protection: The most significant implication is the ability to defend against zero-day vulnerabilities and novel attacks without prior knowledge or signatures. As demonstrated by the XZ backdoor incident, relying solely on signatures leaves organizations vulnerable until a threat is publicly disclosed and a patch or detection rule is developed. Rad Security's approach means that any anomalous behavior, even from a previously unknown exploit, would be flagged because it deviates from the established norm of "known good." This significantly reduces the window of opportunity for attackers exploiting unpatched vulnerabilities.
  1. Enhanced Insider Threat Detection: Traditional security often struggles with insider threats because malicious actions might be performed by authorized users, making them difficult to distinguish from legitimate activity. By continuously monitoring and baselining individual and service-level behaviors, Rad Security can detect deviations in established patterns that signify potential insider threats, whether accidental misconfigurations or deliberate malicious actions. An authorized user accessing unusual resources or executing commands outside their typical scope would trigger an alert.
  1. Improved Cloud-Native Security Posture: The platform is purpose-built for the unique characteristics of containers and Kubernetes. This means it understands the intricacies of pod lifecycles, service meshes, Kubernetes API interactions, and container isolation. Defenders gain visibility and control tailored to these environments, where traditional endpoint security or network intrusion detection systems often fall short. It helps in enforcing the principle of least privilege by ensuring that components only perform actions consistent with their defined roles.
  1. Accelerated Incident Response and Reduced MTTR: The platform's automated response actions (quarantine, label, terminate) are critical for mitigating active threats rapidly. Instead of manual intervention, which can be slow and error-prone, these automated responses can contain a breach in seconds, significantly reducing the Mean Time To Respond (MTTR). This minimizes the potential damage, data loss, and operational disruption caused by a security incident.
  1. Reduced Alert Fatigue and SOC Burden: The integration of LLMs for detection classification is a game-changer for Security Operations Centers. SOC analysts are often overwhelmed by a deluge of alerts, many of which are false positives or low-priority. By using LLMs to enrich, prioritize, and contextualize alerts, Rad Security enables analysts to focus on genuine, high-fidelity threats. This not only improves efficiency but also directly addresses the problem of security professional burnout, allowing teams to be more effective with existing resources.
  1. "Shift Left" for Runtime Protection: While "shift left" is often associated with static analysis and security in the CI/CD pipeline, Rad Security extends this concept to runtime. By establishing a verifiable baseline before an attack occurs, it injects a proactive security mindset into the operational phase. This means security is considered an inherent part of the environment's design and operation, rather than an afterthought, leading to more resilient and inherently secure cloud-native deployments.
  1. Cost Efficiency and Optimized Resource Allocation: In an era of reduced security budgets, Rad Security's approach offers significant cost efficiencies. By preventing costly breaches, reducing manual investigation time, and optimizing the effectiveness of SOC teams, it allows organizations to maximize the impact of their security investments. The ability to automatically respond to threats also reduces the need for extensive manual intervention, freeing up highly skilled personnel for more strategic security initiatives.

In summary, Rad Security provides defenders with a powerful, intelligent, and automated solution that moves beyond the limitations of legacy security models. It offers a path to achieving true peace of mind in securing cloud-native environments, enabling organizations to innovate rapidly without compromising their security posture.

Key Takeaways

  • Shift from Reactive to Proactive: Traditional signature-based security is "far too late" for zero-day vulnerabilities like the XZ backdoor; a proactive, behavioral approach is essential for cloud-native protection.
  • Behavioral Baseline for Cloud-Native: Rad Security establishes a unique "fingerprint" of known good behavior for each environment, flagging any deviations as suspicious rather than relying on an exhaustive list of known attacks.
  • Real-time Novel Attack Detection: This behavioral anomaly detection enables the identification of novel attacks, zero-days, and malicious insider threats in real-time, without requiring pre-existing signatures.
  • Automated Response and LLM-Powered Classification: The platform offers immediate response actions—quarantine, label, or terminate—and leverages LLMs to classify detections, significantly reducing SOC team workload and improving response efficiency.
  • Addressing Industry Challenges: Rad Security tackles critical issues such as reduced security budgets, the complexity of cloud-native environments, and high security professional burnout by providing efficient, automated, and intelligent security.
  • Proven Market Traction: With 3X year-over-year growth, 219% net retention, and 0% churn, the platform demonstrates strong market validation and adoption across leading companies in various sectors.

About the Speaker(s)

Brooke Motta is the Co-founder and CEO of Rad Security. She brings a wealth of experience in revenue growth and business strategy, having served as a three-time Chief Revenue Officer (CRO) at prominent cybersecurity companies such as Bugcrowd and Rapid7. Beyond her professional achievements, Brooke is also an active mentor for the Executive Women's Forum (EWF), a coach for Girls on the Run, and a mom, embodying a blend of leadership in technology and community engagement.

The talk also referenced Jimmy Mesta, Rad Security's co-founder, highlighting his significant contributions to cloud-native security. Jimmy is recognized as the author of the OWASP Top 10 for Kubernetes and is a former security leader and thought leader in the cloud-native security space, underscoring the deep technical expertise underpinning Rad Security's offerings.

All talks from RSA Conference 2024