Hello, and welcome to this videocast in which we'll look at how cyber defenders can cut mean time-to-resolution, MTTR, to nearly zero. I'm Warwick Ashford, a Senior Analyst at KuppingerCole Analysts, and I'm joined by Prakash Sinha, Senior Director and Technology Evangelist at Radware. I'm always fascinated by that title. What exactly does a technology evangelist do, Prakash?
Hey, thank you, Warwick. So, as a technology evangelist, my job is to storytell.
So, I have a background in engineering and also product management. So, I work very closely with product teams as well as engineering teams.
So, product teams have use cases and engineering teams have sprints. And so, my job is to actually translate the innovations that they come up with, like strategic, and basically convert that into a strategic value for our customers.
So, it's storytelling, but with some use cases and some substance. And I help security leaders see what's possible and guide them towards a transformation initiative that they have in play.
Well, I guess we'll have the opportunity to see a technology evangelist in action today, as we talk about important challenges facing security operations that make it imperative to drive the mean time-to-resolution down to as near to zero as possible. Not only are we seeing attacks increase in frequency, size, and complexity across all attack vectors, but I think you'll agree that most importantly, we are seeing that the rate of innovation in attacks is increasing. And the most likely driver of that is AI.
And I saw that Capital Technology University near Washington in the US is estimating that 40% of cyber attacks are now being driven by AI. Prakash, from what you're seeing, how are attackers using AI and what does that mean for SOCKS today?
So, it's a very, very good question. And I like that stat. I hadn't heard it before, but we absolutely see, we measure this in our own data centers. We have almost 15 terabits of capacity in the cloud, and we measure this on a day-to-day basis. And what we see is an increasing use of AI by the attackers. And the reason is there are many tools. If you go to GitHub, for example, there are lots of AI-powered or AI-assisted DDoS frameworks. There's Captcha browsers, there's WebExploit kits.
So, all of these are available for free. And then you can rent some of these also by the hour from Eastern Europe.
So, it makes it very, very easy for low-skill threat actors to launch very, very sophisticated attacks. And in fact, there is a tool on GitHub, mhddos, I believe, 54 different vectors that you can exploit without really knowing about exactly what they are, right?
So, the implication for a security operations center is very, very big. In terms of, they rely on traditional defenses like signature-based detection don't apply anymore. And it takes a long time to create those signatures, right?
So, the time to react is very small. That's the biggest challenge here.
So, I guess that's what we're talking about today. But in light of the fact that an increasing proportion of cyberattacks are being driven by AI, and that AI is lowering the barriers to entry, as you said, it's just much easier for people to get in without actually knowing what they're doing. I'd say this means that never before has it been as important as it is now to resolve threats quickly, as you say. The concept of near zero NTTR sounds quite ambitious.
So, how realistic is that precaution for the average SOC? And sort of what does it take to get there?
Oh, that's a very good point. So, it is ambitious, of course. A near zero mean time to resolution is, it is ambitious, but it is achievable.
There is, you know, if you're a CISO, you have to go through a certain, you know, steps in order to get there. Now, near zero doesn't mean that there is zero incident. It just means that you are minimizing the time that it takes to detect to a resolution, right?
So, that the threats don't have a lot of time to do damage. So, in order to get there, there are three key areas that you need to focus on.
One is, can you detect in real time, right? So, that's where AI algorithms that can recognize evolving attack patterns, not just from one use case or one customer, but across a wide variety of customers.
So, that's the real-time detection. The other is automated remediation that kicks in close to detection, right?
So, it doesn't mean that you let AI actually do and, you know, around haywire and change how you operate. But what it means is, get an assistance from chat or something like that, where you can feed in the detection and it'll tell you how to remediate it, right?
And then, of course, the other area, because you have to report some of these breaches, is smart forensics and guidance, right? So, this is where AI definitely can assist.
In fact, we've seen, we have our own tool called AI SOC Expert, and we've seen some organizations actually reduce that mean time to resolution for incidents almost 20x, which by automating some of these incident resolution and reducing the mundane tasks that an analyst has to take, right? So, that's where it is ambitious, but, you know, automation is a stepwise process, and there are processes in place today that you need to morph with AI assist. Let me put it that way, right?
So, you've mentioned the speed, but I think in the context of the SOC, perhaps for me anyway, the most significant outcome of cyber attackers using AI is that it's being used to automate attacks so that they can deliver higher volumes of unique and adaptive attacks. So, there seems to be some consensus around the idea that if attackers are using AI and automation, defenders absolutely have to do the same.
So, how does AI automation help reduce the burden on SOC analysts, especially with the ongoing talent shortage in cyber security? That's a very big challenge, especially security expertise is lacking, and a lot of skilled hires, right?
So, yes, we can teach them. It takes a long time to actually come up to speed. The SOC landscape itself is evolving very rapidly. And like you mentioned, right, multiple attack vectors, there is dynamism in the environment, a lot of customers moving from on-prem to cloud.
So, a lot of changes in play, and then the domain expertise is also changing, right? The existing network or security operations that were used to a certain way of doing things, maybe doesn't apply in the cloud, right? Or maybe it's different in the cloud.
So, you have to get used to that. And of course, with these attack vectors, there's a lot of data that's coming in.
So, there is a skill shortage. So, AI can help here, fight AI with AI, as we say.
So, automate some of the repetitive tasks, right? Tasks that free your analysts to focus on high priority items, breaches, things like that, or proactively looking at things or using AI to assist it. The root cause analysis, something has happened. How do you analyze it and narrow the time? Because there are so many events that are taking place, and everything is coming up to SOC. What should you actually see?
So, can you build a storyboard around it? And then recommendations of how should you resolve it, right? It's not just detect, you have to analyze it, and then you have to make some recommendations.
So, do you have to change up security policy? Those are the areas where human analysts can help, but can be assisted by AI.
So, that's, I mean, because of lack of security expertise and lack of skillset. And of course, very difficult to find these people, very expensive too, right? Putting it all together, we are not trying to replace any human analysts, right? But increasing and enhancing their ability to act quickly. That's where I believe that AI can assist.
Yeah, no, I absolutely agree with you. But I think working with AI is just kind of like a whole new world for most people.
So, with AI now recommending real-time mitigation steps, how do organizations maintain accountability and trust in those automated decisions? So, automation is a step-wide process.
You can't, I mean, you can't really... I wouldn't recommend AI just, you know, go and change policy, right? The changes need to be transparent and explainable and governed, right?
So, because if you've seen some of the recommendations, especially for EU AI Act or NIST and all of these, they recommend that you log these policies, right? So, our approach and our recommendation is to use AI-assisted actions, right? The SOC analyst always sees what's being recommended, why? And if you look at even PCI, PCI actually says, you have to be able to look at these actions and explain what changed, right?
So, those are the PCI 4.0 recommendations, if you look at that. So, we're not doing like fully automated responses yet. It will happen eventually. Identicate AI is on the way, but accountability is maintained through very clear audit logs and well-defined decision paths. And human oversight is very, very key here.
So, it's, you know, you are using AI for assistance, like a co-pilot that we use in Microsoft Office, right? So, you have co-pilot and co-pilot can actually tell you a lot of things about all your documents. This is very similar.
So, now, just to kind of pivot away from that a bit is, if a CISO or a security team is just starting their AI transformation journey, you said, you know, you focused on transformation, what are the first few practical steps that you'd recommend? So, CISOs, so they are on the hook, right? Because they are responsible for it.
And also, if a breach happens, they have to answer within 72 hours, at least for the, for US, right? It's probably about the same time in other, in Europe, as well, right?
So, first is, look at your SOC and security operation center capabilities. There are the delays. You have a process in place. What can be automated out of that, right?
So, basically, the thing is, what is mundane? Things that can be easily automated.
So, that's the first step. You have to look at your process and see where to start, right?
So, then, then you can augment that. I wouldn't recommend full automation yet. We're not there yet.
So, start with AI assistance, right? So, for example, if you have policies, and you have input that is coming in from some detection, right?
So, how do you merge those together? And how do you let something like an AI assist or a co-pilot merge them together and give some recommendations to your analysts, right?
So, that's the step two, which is engaging, removing the mundane part, looking at your processes, and then putting them together so that your analyst can actually make a recommendation. And change policies if needed. You can use AI assist to even change policies, right? But not let it do on its own. The third is apply these to very, very high profile and high ROI use cases.
So, because, you know, money matters, right? Since you only have so much budget.
So, things like where these attacks are taking place, look at some of the AI tools that are used for attacks. MHDDoS, there are many, right?
So, look at some of those. What are they targeting?
So, they usually go for some critical information, PII data. They go for financial information. They go for some proprietary information.
So, bot protection is very key. Incident response, if something is happening, do you have like a cloud security posture management? Can you put a storyboard together for how the attack is taking place? Those are some of the things, especially for these high ROI and priority use cases. And then of course, you have to align people, process and technology. Like I always say, AI works best if it's used to assist in existing workforces. You can't just change everything lock, stock and barrel. Okay.
So, now the time has gone quickly. And so, just to wrap up, I mean, there are a couple of things that you've covered. You've covered a great deal actually, and that's great. But finally, I wanted to know what success looks like for a SOC that's fully embraced intelligent automation and AI.
So, I mean, if I were to say your SOC is fully embracing automation and AI, I would say you would have a near zero mean time to resolution for most of the common attack types. These are attacks that are things like PCI-DSS or NIST-2, those kinds of compliance stuff. Those are prescriptive. Those you can automate very quickly. Or denial of service attacks, even though they are under SSL, right?
So, these are WebDDoS type of attacks where it's a denial of service, but under SSL. And so, you have to decrypt and then look at information.
So, you should have a near zero MTTR for those. You should focus on strategic work or your analysts should focus on strategic work.
ROI, I mentioned, right? So, operational efficiency, if you have very lean team, but the teams are very, very aware of how to use the AI tools or AI systems. That's the goal, okay?
And then, of course, the posture management is very key. You have to know what's important to you in terms of use cases. And can you storyboard a breach in play, okay?
So, that's can you connect things together in terms of your workflow and processes and automation that your SOC looks at this in almost near real time, okay? So, that I think is a force multiplier for SOCs that where AI can assist.
Okay, great. In closing, from what you've said, I'd say that it's a good idea to set achieving near to zero MTTR as a goal because that'll ensure a shift to a proactive approach to cybersecurity using AI and automation to ensure that threats are recognized and addressed before they can do harm, which I think is a point that you made earlier. I think it's highly likely that AI-driven automation will become a key differentiator for security teams and will become a standard component of modern security operations. And finally, I think that while AI is powerful, it is just a technology.
So, its effectiveness really depends on how it's implemented. And AI must be supported by well-defined use cases, behavioral changes, and process adjustments. And as you said, I couldn't agree more. As ever in cybersecurity, people, process, and technology need to be aligned and work together.
So, your closing thoughts, Prakesh. So, I'm a very big fan of Stephen Covey.
So, begin with an end in mind. So, near zero MTTR in this technical context is not just a technical goal. It's actually a mindset, right?
So, AI is not a silver bullet. It's just an enabler. The best outcome would be when your people, the process, and the technology come together and they use some of these assistance, right? The AI is an assistance.
The goal, right? We had a goal in achieving a near MTTR, a near zero MTTR in mind. And I think that's something that will lead to success. Great stuff.
Well, thanks Prakesh for joining us today and sharing your insights on the benefits of reaching near zero MTTR and how to achieve it. And thanks to you, our audience, for watching. We hope that you found it useful.
Thank you, Warmic. Appreciate it.