Cloud

6/5/2017
04:35 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Oracle Brings Machine Learning to its CASB Service

Machine learning is a next step for cloud systems, as Oracle integrates new capabilities into its CASB offering to discern and leverage user behavior.

Oracle and other companies are integrating new technologies into their cloud access security broker (CASB) offerings to ratchet up security.

Database giant Oracle today announced that it has integrated machine learning, artificial intelligence, and contextual awareness in its CASB service. The idea is to address the growth of security incidents targeting privileged and end-user credentials.

Cloud vendors are competing to address two important issues, says Andy Smith, senior director of product development for Oracle's security portfolio. They are trying to figure out how to bring their products to the cloud, and how to develop the tech to secure their own clouds.

CASB providers are under pressure to create new technologies for better cloud management. These systems sit between cloud service customers and cloud providers to consolidate the enforcement of security policies.

In the past, mostly large businesses demanded CASB systems. "The larger you are, the more complex you are, you have hundreds of cloud services," says Cloud Security Alliance CEO Jim Reavis.

However, as more information and key data assets are moved off-premise, small- and medium-sized businesses are looking into CASB adoption for greater visibility into their organizations.

Oracle's new approach uses supervised and unsupervised machine learning for advanced threat detection. The system detects and stores user actions and compares them with established patterns to determine abnormal activity on each cloud service.

The user behavior analytics (UBA) engine sets historical baselines for each user and service (Box, Office 365, etc.). When it finds behavior derives from the norm, it launches incident response options such as incident management systems and automated remediation.

Unsupervised machine learning compares users' behavior with their previous actions to determine risk. "It creates its own normal" by using algorithms to verify whether activity is anomalistic, says Smith. This "normal" continuously changes based on data it receives.

Supervised machine learning is more customizable: Administrators can specify personal attributes or CRM activity they want to analyze, and create a correlation to look for actions that are against policy. The system had always integrated unsupervised machine learning, but now users can identify what they want to look for, he says.

Say an employee has been put on notice and the business is worried about data theft, for example, he says. Admins can monitor correlations between when someone is put on notice and whether they attempt to steal data before they leave the company.

"They can use it for any kind of risky behavior and apply it to any types of threats," says Smith. "The main one we always think about is compromised accounts," or those that people are concerned about because of phishing or credential theft."

To better monitor risk, the company is bringing what it calls adaptive access to its Identity-Based Security Operations Center (SOC). This new approach to access control will use machine learning to combat fraud across cloud applications by analyzing each login attempt and data on location, device, and time of day.

"The concept of adaptive access isn't new," says Smith. "Doing it where it's built into the cloud service and integrated into other risk services -- that's what's new."

Oracle's CASB is introducing security monitoring and threat detection for several applications, including its own Oracle Human Capital Management (HCM) Cloud, Oracle Enterprise Resource Planning (ERP) Cloud, and Oracle Customer Experience (CX) Cloud Suite. This is in addition to tools like Slack, Office 365, Box, Google G-Suite, AWS, ServiceNow, GitHub, and Rackspace.

Smith emphasizes the importance of ensuring the CASB integrates with the rest of the security fabric. For him, the key is making sure the system covers SaaS, PaaS, and IaaS so the business isn't using multiple CASB systems to get full security coverage.

Related Content:

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada, July 22-27, 2017. Click for information on the conference schedule and to register.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-7907
PUBLISHED: 2018-09-26
Some Huawei products Agassi-L09 AGS-L09C100B257CUSTC100D001, AGS-L09C170B253CUSTC170D001, AGS-L09C199B251CUSTC199D001, AGS-L09C229B003CUSTC229D001, Agassi-W09 AGS-W09C100B257CUSTC100D001, AGS-W09C128B252CUSTC128D001, AGS-W09C170B252CUSTC170D001, AGS-W09C229B251CUSTC229D001, AGS-W09C331B003CUSTC331D0...
CVE-2018-3972
PUBLISHED: 2018-09-26
An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as used in Monero 'Lithium Luna' (v0.12.2.0-master-ffab6700) and other cryptocurrencies. A specially crafted network packet can cause a logic flaw, resulting in code execution. An attac...
CVE-2018-17538
PUBLISHED: 2018-09-26
Axon (formerly TASER International) Evidence Sync 3.15.89 is vulnerable to process injection.
CVE-2018-11763
PUBLISHED: 2018-09-25
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
CVE-2018-14634
PUBLISHED: 2018-09-25
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerabl...