Detection at Scale cover image

Detection at Scale

Latest episodes

undefined
May 14, 2024 • 28min

The Duckbill Group’s Corey Quinn on What Billing Data Can Tell Us About AWS Security

In a recent episode of the Detection at Scale podcast recorded at the RSA conference, Jack chats with Corey Quinn, Chief Cloud Economist at The Duckbill Group, an AWS cost-management agency. They talked about the intersection of security and billing in the context of AWS environments, highlighting the significance of observability through billing data to enhance security measures.  Corey also discussed key offenders in AWS services for security and highlighted the challenges companies face in determining optimal investments in security services. Throughout our discussion, Corey offers valuable takeaways on navigating the evolving landscape of AWS security practices and optimizing billing strategies for enhanced cloud security. Topics discussed: The importance of observability via billing data to bolster AWS security measures and optimize investments in security services. How to identify key security offenders in AWS services to enhance cloud security practices and mitigate potential breaches. The challenges in determining optimal security investments within AWS environments. Detecting potential breaches through AWS billing insights and the significance of understanding billing intricacies for security enhancements. The impact of billing data on identifying security vulnerabilities and navigating the AWS security landscape with enhanced strategies. The role of services like Route 53 in bolstering security measures and considerations for AWS spending on security services.  Resources Mentioned:  Corey Quinn on LinkedIn The Duckbill Group website 
undefined
May 7, 2024 • 41min

LinkedIn’s Jeff Bollinger on the Role of Human Intuition in Addressing Security Challenges

In this episode, Jack Naglieri speaks to Jeff Bollinger, Director of Incident Response and Detection Engineering at LinkedIn, who shares valuable insights on his journey in security, key technological shifts he's witnessed, and his approach to threat intelligence, incident response, and monitoring.  Jeff highlights the importance of contextual understanding in security operations and emphasized the critical role of human intuition, adaptability, and creativity in addressing security challenges. He also discussed the need for a balanced team with diverse skill sets and his views on the evolving role of AI in security operations. Topics discussed: Technological shifts in the field of incident response and detection engineering, from the Y2K era to the present. The nuances of monitoring behaviors and moving towards higher-level monitoring: it’s useful but imperfect because humans can be unpredictable. Automation in security operations and how human analysts are still important and relevant because they have intuition that AI does not. Incorporating threat intelligence effectively in security programs: knowing what your scale is and what threats correspond to it. Building effective incident response programs and key considerations in security operations. 
undefined
Apr 23, 2024 • 36min

Josh Liburdi on Brex's Innovative Approach to Data Quality in SecOps

In this episode, Jack Naglieri speaks to Josh Liburdi, Staff Security Engineer at Brex. Josh explains the process of developing their new security data pipeline toolkit, Substation and how it has been working. He also discusses the importance of quality data, highlighting the impact of data transformation.  Josh also shares his insights on the value of human analysis in SecOps and modern incident response strategies, from handling alerts to understanding program gaps.  Topics discussed: The development process of Substation, a security data pipeline toolkit to enhance log collection and data quality for threat detection The importance of quality data in security operations and how sometimes it is helpful to collect it even if you don’t analyze it right away. The data transformation process and its impact on threat detection, as well as how it’s made the team at Brex more efficient. Enhancing the ability to write better rules after implementing Substation. Josh's advice for security practitioners: it’s ok to seek help and “soft skills” are important. 
undefined
Apr 9, 2024 • 30min

SAP's Matthew Valites on Why He Is a Proponent of Detection as Code

Matthew Valites, Director of Threat Detection & Operational Strategy at SAP, discusses the best threat detection approaches, using detection as code, and the role of GenAI in the future security landscape. He also shares actionable lessons from his book, 'Crafting the Infosec Playbook'.
undefined
Feb 27, 2024 • 29min

Meta's Justin Anderson on How to Understand, Identify, and Execute Your Detection Strategy

Meta's Justin Anderson discusses how they built a detection platform treating it like software code, gauging risk using TTPs, and taking a shift-left approach. They emphasize the need for strong engineering and investigation skills, AI limitations in detection, and advice for building a security program.
undefined
Jan 23, 2024 • 35min

Sony's Charles Anderson on How to Manage Detections and Risk Across a Global Company

On this week's episode of the Detection at Scale podcast, Jack talks with Charles Anderson, Director, Global SOC at Sony. They discuss better approaches to risk-based alerting that leverage metadata, how they fine tune detections across a global organization, and what factors to use when determining thresholds. They also talk about how to use Time to Detect to improve your strategies, how LLMs can help with baseline detection, and why it's key to not lose sight of risk in pursuit of threat. Topics discussed: A better way to approach risk-based alerting by leveraging metadata to connect the dots. Which factors to consider when determining your thresholds for alerting. How Sony is using machine learning and why applying a single model to the entire organization doesn't work. Why organizations are targets of opportunity and accidental exposure more than they are of planned attack. The process Sony's SOC uses to fine tune their detections and how it has to be different across the globe. How to use Time to Detect to tell the story of what you're covering and what you're missing. Advice to other security professionals that includes not losing sight of risk in pursuit of threat.
undefined
Jan 9, 2024 • 40min

Remitly’s Jason Craig on Building Better Strategies for Identity, Logging, and Threat Modeling

On this week's episode of the Detection at Scale podcast, Jack talks with Jason Craig, Director - Threat Detection & Response at Remitly. They discuss the common TTPs of threat actors and how organizations can better protect against them by adopting hardware-backed authentication, a risk-based approach to logging, and building their threat modeling. They also talk about why organizations should move away from cellular MFA, the need for more behavioral profiling, and advice for security professionals. Topics discussed: The common TTPs of threat actors and conglomerates like Lapsus$ and what organizations need to know to protect themselves against them. Why enterprises should rely on hardware-backed authentication rather than SMS MFA on cellular. How to take a better approach to identity management by using hardware-backed authentication and behavioral profiling that eliminates background noise. Why threat modeling begins with knowing what you do as an organization and what you have that's valuable to an attacker. How to take a risk-based approach to understanding which user data or sensitive information to protect first. Why an accurate asset inventory is a precursor to detection and response. Advice to security professionals and organizations on "knowing thyself" and codifying adversary tracking.
undefined
Dec 19, 2023 • 30min

AppOmni’s Drew Gatchell on Creating Better Detection for SaaS Platforms

On this week's episode of the Detection at Scale podcast, Jack talks with Drew Gatchell, Director, Detection Engineering at AppOmni. They discuss how to overcome the challenges to detection on SaaS platforms and how they're building strategies upon alerting and detection frameworks. They also talk about how generative AI can help with normalizing inputs, the benefits of data lakes for D&R, and why it's key to have a measurable plan for detection. Topics discussed: How AppOmni is tackling the challenges of detection in SaaS platforms and auto-logs, especially when it comes to varied latency. What frameworks Drew is working with and how he's building upon them for better detection. How signal creation starts with a hypothesis that can be turned into a plan, and why it's important to include signal redundancy. What techniques AppOmni takes to address security in real time. How they're using AI to normalize their inputs and create additional content on top of the detection rules. The benefits of data lakes and how they're a tremendous asset to D&R. Advice for security leaders on having a measurable plan for detection, why detection should be layered, and the need to continuously validate your capabilities.
undefined
Dec 12, 2023 • 22min

Block’s Emanueal Mulatu on Reducing Burnout, Fostering Engagement, and Increasing Productivity in Security

On this week's episode of the Detection at Scale podcast, Jack talks with Emanueal Mulatu, Senior Engineering Manager - Detection & Response at Block. Together, they discuss what success means in security, the most rewarding things about security, and how to address and prevent one of the biggest challenges today: burnout. They also talk about ways to increase productivity through automation, the potential for AI and large language models, and why creating a great workplace starts with a healthy work-life balance. Topics discussed: The most rewarding things about security — like the relationships and trust you build — and the biggest challenges facing security today. The value of building relationships across departments as well as with your customers. How to recognize the root causes of burnout and address it through meaningful initiatives like fitness or reading challenges. Why having a culture of writing can help with problem solving and collaboration. Why automation is the biggest initiative that's increasing productivity and morale, and the opportunities that AI and LLMs will bring. Advice for security leaders on how to build better workplaces focused on psychological safety and continuous learning. How to define security success, especially through the eyes of the C suite.
undefined
Nov 28, 2023 • 46min

Google Cloud’s Anton Chuvakin on Decoupled SIEMs and the Future of Data Platforms and Security

On this week's episode of the Detection at Scale podcast, Jack talks with Dr. Anton Chuvakin, Senior Security Staff at the Office of the CISO at Google Cloud. They dig deeper into the conversation taking place online around decoupled SIEMs, which both Jack and Anton wrote about. They discuss what a decoupled SIEM is, the evolution of data platforms and security capabilities, if decoupled SIEMs will work broadly with current customer demands, and if having backend data lakes is the best solution for fast, real-time querying. Topics discussed: What is a decoupled SIEM, and why the broader discussion around whether security data lakes will replace SIEMs prompted Anton's Medium post. How this conversation is being driven by the fact that we’re coming to the "end of the runway" on previous storage choices. The arguments around why decoupling may not work broadly, simply because customers want integrated SIEMs. The evolution of data storage platforms and how successful past attempts at integrating security capabilities were. Why there's not a straightforward solution to storage — and why it's a challenge that's taking years to solve. Why having a data lake on the backend is the best solution to fast querying and real-time detection. A discussion around OCSF and the benefits of log normalization.  Resources Mention:  “Decoupled SIEM: Brilliant or Stupid?” by Anton Chuvakin “The Transition from Monolithic SIEMs to Data Lakes for Security Monitoring” by Jack Naglieri

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode