Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

4/19/2018
09:00 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Microsoft CISO Talks Threat Intel, 'Data Inclusion'

Dark Reading caught up with Microsoft's Bret Arsenault to discuss intelligence, identity, and the need to leverage more diverse datasets.

RSA CONFERENCE 2018 – San Francisco – The need to simplify security drove Microsoft to break its strategy into three distinct parts: platform, intelligence, and partnerships. It was the importance of data that CISO Bret Arsenault focused on during an interview with Dark Reading this week at the RSA Conference. 

"Intelligence, in general, is a big differentiator in how we think about security now, versus what we could do five years ago or ten years ago," Arsenault said. While Microsoft is securing everything in its Windows platform by default establishing partnerships in the public and private sector, it's the company's massive, diverse data store that's shaping its strategy.

The effectiveness of artificial intelligence and machine learning, two of the biggest buzzwords circling the security industry (along with blockchain), heavily rely on data, Arsenault said. Threat intelligence became core to Microsoft's plans fifteen months ago, following a $1 billion investment to integrate security across its products and services.

Throughout 2016, those funds went toward projects such as doubling the number of security execs and launching the Microsoft Enterprise Cybersecurity Group (ECG) and Cyber Defense Operations Center (CDOC). By the end of the year, Arsenault said, Microsoft had seen a shift away from the "spray and pray" approach to security and toward better detection and response, fueled by threat intelligence. The need for data has only intensified.

"What I know about artificial intelligence and machine learning is the accuracy of those things is very highly correlated to the amount of the data you have," he explained. However, while the size of the dataset certainly matters - Microsoft's data repositories more than double each year, he noted - even more important is the information's quality.

Data Diversity vs. Inclusion

"A diverse workforce creates better products," said Arsenault. "Diversity of data is equally, if not more important than the amount of data."

Some companies mostly handle a single data type; he pointed to telecom companies, which primarily handle network traffic, as an example. Microsoft, with a large and varied portfolio of products and services, collects network data, device data, and identity data, Arsenault noted. The company has data on the one billion machines it updates each month. It gathers cloud data, which is pulled from Azure business services and varies across industries.

Yet it's not enough to only be diverse, Arsenault pointed out. Having a rich set of data means little without inclusion, or putting it to practical use. "Diversity is interesting, but inclusion has created a whole new priority," he added. Businesses often place more emphasis on diversity of data than inclusion.

Looking ahead, Arsenault touched on an idea that was top of mind for many security pros during RSA: the rise of cloud and disbanding of the traditional perimeter. As we operate in a client-to-cloud world, the idea of the network as a control point has eviscerated in its effectiveness, he explained. Now the most effective control point is users' identities.

"You have to go really hardcore at the device piece, because the network is dissolving," he said. One of Arsenault's priorities is to eliminate passwords within Microsoft, where in the past year 66% of users log into Windows Hello for Business with biometrics or PIN. Employees are encouraged to shift away from passwords, which they are only required to change once a year.

Related Content:

Interop ITX 2018

Join Dark Reading LIVE for an intensive Security Pro Summit at Interop IT X and learn from the industry’s most knowledgeable IT security experts. Check out the agenda here.Register with Promo Code DR200 and save $200.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/20/2018 | 8:44:02 AM
Discovery vs Inclusion
Discovery and Diversification are helpful when trying to shape intelligence but similar to unreviewed logs lack of inclusion into practical process limits their effectiveness. The transition from non-inclusion with D&D to inclusion can be described as the transition from satisfying a compliance check-box to more of a security best practice approach.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/20/2018 | 8:41:15 AM
Passwords
Glad to hear MS is trying to shift away from passwords. They are inherently insecure and without a password policy driving complexity and password expiration they become eternally instantiated.
Stop Defending Everything
Kevin Kurzawa, Senior Information Security Auditor,  2/12/2020
Small Business Security: 5 Tips on How and Where to Start
Mike Puglia, Chief Strategy Officer at Kaseya,  2/13/2020
5 Common Errors That Allow Attackers to Go Undetected
Matt Middleton-Leal, General Manager and Chief Security Strategist, Netwrix,  2/12/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-20477
PUBLISHED: 2020-02-19
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.
CVE-2019-20478
PUBLISHED: 2020-02-19
In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other words, this issue affects developers who are unaware of the need to use methods such as safe_load in these use cases.
CVE-2011-2054
PUBLISHED: 2020-02-19
A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper in...
CVE-2015-0749
PUBLISHED: 2020-02-19
A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the affected software. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker ...
CVE-2015-9543
PUBLISHED: 2020-02-19
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is rel...