The Capital One breach proved we must rethink cloud security
theglobeandmail.com
theglobeandmail.com
So perimeters are antiquated. Yet, in this case, a perimeter was not adequately enforced and was thus breached.
> For one, AI tools need not delineate and secure the cloud’s intrinsically nebulous perimeter.
Antiquated and nebulous!
> Rather, the latest such tools take an inside-out approach: analyzing what goes on inside a given cloud environment in real time to keep pace with ever-evolving users and architectures. As the environment changes, in other words, so, too, does the AI’s understanding of normalcy.
So we're replacing the "nebulous" perimiter with the notion of normalcy?
> Indeed, the risks inherent to IaaS and SaaS are highly user-dependent – the same activity associated with, say, a subtle insider attack when carried out by one employee might well be benign when done by another.
I assume he means "a thing that looks like a subtle insider attack".
This is always a red flag: the author is describing a scenario where AI is supposed to detect things that anomalous data. That's always struck me as the Hollywood vision of AI, where the computer is a magic oracle finding something that isn't right for reasons the designer never specified.
There are absolutely mathematical tests that can detect unnatural distributions of data[1] but they rely on a clear definition of what is natural.
I think we definitely have a problem with manually derived security rules. And most likely AI techniques could help designing a system to explain what our security rules and configurations are actually doing. Especially as configuration can be very dynamic as you have those rules being defined on the fly by code written in any number of languages.
But all of this still relies on very concrete notions like a perimeter because that's the math and the math hasn't changed.