Threat Intelligence

4/19/2018
09:00 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Microsoft CISO Talks Threat Intel, 'Data Inclusion'

Dark Reading caught up with Microsoft's Bret Arsenault to discuss intelligence, identity, and the need to leverage more diverse datasets.

RSA CONFERENCE 2018 – San Francisco – The need to simplify security drove Microsoft to break its strategy into three distinct parts: platform, intelligence, and partnerships. It was the importance of data that CISO Bret Arsenault focused on during an interview with Dark Reading this week at the RSA Conference. 

"Intelligence, in general, is a big differentiator in how we think about security now, versus what we could do five years ago or ten years ago," Arsenault said. While Microsoft is securing everything in its Windows platform by default establishing partnerships in the public and private sector, it's the company's massive, diverse data store that's shaping its strategy.

The effectiveness of artificial intelligence and machine learning, two of the biggest buzzwords circling the security industry (along with blockchain), heavily rely on data, Arsenault said. Threat intelligence became core to Microsoft's plans fifteen months ago, following a $1 billion investment to integrate security across its products and services.

Throughout 2016, those funds went toward projects such as doubling the number of security execs and launching the Microsoft Enterprise Cybersecurity Group (ECG) and Cyber Defense Operations Center (CDOC). By the end of the year, Arsenault said, Microsoft had seen a shift away from the "spray and pray" approach to security and toward better detection and response, fueled by threat intelligence. The need for data has only intensified.

"What I know about artificial intelligence and machine learning is the accuracy of those things is very highly correlated to the amount of the data you have," he explained. However, while the size of the dataset certainly matters - Microsoft's data repositories more than double each year, he noted - even more important is the information's quality.

Data Diversity vs. Inclusion

"A diverse workforce creates better products," said Arsenault. "Diversity of data is equally, if not more important than the amount of data."

Some companies mostly handle a single data type; he pointed to telecom companies, which primarily handle network traffic, as an example. Microsoft, with a large and varied portfolio of products and services, collects network data, device data, and identity data, Arsenault noted. The company has data on the one billion machines it updates each month. It gathers cloud data, which is pulled from Azure business services and varies across industries.

Yet it's not enough to only be diverse, Arsenault pointed out. Having a rich set of data means little without inclusion, or putting it to practical use. "Diversity is interesting, but inclusion has created a whole new priority," he added. Businesses often place more emphasis on diversity of data than inclusion.

Looking ahead, Arsenault touched on an idea that was top of mind for many security pros during RSA: the rise of cloud and disbanding of the traditional perimeter. As we operate in a client-to-cloud world, the idea of the network as a control point has eviscerated in its effectiveness, he explained. Now the most effective control point is users' identities.

"You have to go really hardcore at the device piece, because the network is dissolving," he said. One of Arsenault's priorities is to eliminate passwords within Microsoft, where in the past year 66% of users log into Windows Hello for Business with biometrics or PIN. Employees are encouraged to shift away from passwords, which they are only required to change once a year.

Related Content:

Interop ITX 2018

Join Dark Reading LIVE for an intensive Security Pro Summit at Interop IT X and learn from the industry’s most knowledgeable IT security experts. Check out the agenda here.Register with Promo Code DR200 and save $200.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/20/2018 | 8:44:02 AM
Discovery vs Inclusion
Discovery and Diversification are helpful when trying to shape intelligence but similar to unreviewed logs lack of inclusion into practical process limits their effectiveness. The transition from non-inclusion with D&D to inclusion can be described as the transition from satisfying a compliance check-box to more of a security best practice approach.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/20/2018 | 8:41:15 AM
Passwords
Glad to hear MS is trying to shift away from passwords. They are inherently insecure and without a password policy driving complexity and password expiration they become eternally instantiated.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19019
PUBLISHED: 2019-01-22
A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
CVE-2019-6260
PUBLISHED: 2019-01-22
The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which allow arbitrary read and write access to the BMC's physical address space from the host (or from the network in unusual cases where the BMC console u...
CVE-2018-19011
PUBLISHED: 2019-01-22
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the application.
CVE-2018-19013
PUBLISHED: 2019-01-22
An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file.
CVE-2018-19017
PUBLISHED: 2019-01-22
Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior). When processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privil...