PREVENTING THE THREATS OF TOMORROW AND BEYOND Jonathan Kaftzan VP Product marketing & innovation
Is Prevention Possible? 2 Private and confidential
FROM PREVENTION TO DETECTION…AND BACK Prevention An Antivir virus us: Polymor orphic ic veness ess Signatures- Code based ectiven Antivir An virus us: Encr crypte ted Payload ads Static re Effect Heuristics Mach achin ine e Learni ning ng Met etam amor orphi hic c Static Analysis Code, Filel eles ess Deep Lear arnin ning g Anti-Sandb An andbox ox alware Static & Dynamic Techni nique ues, s, Sandboxin oxing Anti-malwa Exploit oits Analysis Solut utio ions ns Detection An New At Attack ck Behavior vioral al An Analysi sis, s, “needle in a vecto ve tors s & surface aces An Anti-Expl xploi oits ts Detect ection ion & haystack” new Resp sponse onse atta tack ck ve vecto tors s and Threat Hunting surface aces 1990 2000 2010 2015 To date Private and confidential
FROM HUMAN BRAIN TO DEEP LEARNING Artificial Intelligence Machine learning Deep learning 1950 1980 2010 4 Private and confidential
Healthcare Diagnosis WHEN SCIENCE FICTION BECOMES REALITY Personal recommendations Virtual assistants Face recognition Deep learning is the area of artificial intelligence where the real magic is happening right now.
THE BIGGEST IMPROVEMENT IN ARTI TIFICI FICIAL AL INTE TELL LLIG IGENCE ENCE Deep learning has accomplished groundbreaking success in every field it has been applied 20 % - 30 % 20 % - 30 % 10 % - 20 % improvement in improvement in improvement in face recognition voice recognition text analysis AND NOW, DEEP LEARNING IS ALSO TRANSFORMING CYBERSECURITY 6 Private and confidential
DEEP LEARNING, DEEP IMPACT
TRAINING THE BRAIN
DETECTION OF THE UNKNOWN BECOMES AN INSTINCT
DEEP LEARNING Vs. MACHINE LEARNING: NO FEATURE ENGINEERING 0.5 Machine learning 1.8 -6.4 2.3 . . . N Machine learning Raw data Manual feature Vector of features Engineering Deep learning Raw data Deep learning Private and confidential
DEEP LEARNING Vs. MACHINE LEARNING: NO FEATURE ENGINEERING Machine learning Only 2.5%-5% Feature engineering of available data Linear model Limited files type covered (PE) Domain expert Deep learning 100% Of available Non-linear model: Zero time to Autonomous, raw data Context & support intuitive & Automated correlation any new file types between data Private and confidential
DEEP LEARNING Vs. MACHINE LEARNING: NO FEATURE ENGINEERING Machine learning False positives Accuracy with unknown 50-70% 1-2% Deep learning Accuracy with unknown False positives >98% <0.001% Private and confidential
NON-LINEAR VS LINEAR CORRELATION AP API I Dll ll Preve event t access ess to hooki oking g injection regi gistry try key by drive vers rs Malw lware e keylog loggers ers Malw lware e spyware re Malw lware e AP APT 13 Private and confidential
NON-LINEAR VS LINEAR CORRELATION API AP I Dll ll Preve event t access ess to Mach chine e Lear earning: g: Deep ep Lear earning: g: hooki oking g injection regi gistry try key by Linear ear corr rrel elati tions Non-li linea ear r drive vers rs Mach chine e le learni rning corr rrel elati tions Malw lware e keylog loggers ers Malw lware e spyware re Malw lware e AP APT 14 Private and confidential
NON-LINEAR VS LINEAR CORRELATION AP API I Dll ll Preve event t access ess to Linear ear Non-li linea ear r hooki oking g injection regi gistry try key by corr rrel elati tions corr rrel elati tions drive vers rs (Mach chine e le learn rning) g) (Deep ep Lear earning) g) Malw lware e keylog loggers ers Malw lware e spyware re Malw lware e AP APT An Antivi virus s softw tware 15 Private and confidential
EFFECT OF MORE NEURONS LAYERS 3 hidden neuron layers 6 hidden neurons layers 20 hidden neurons layers Malicious Benign • The more layers, the better the accuracy • But…accuracy is limited and also runtime performance will be affected 16 Private and confidential
THE DEEP LEARNING PROCESS FROM TRAINING TO PREDICTION 24 hours Deep Instinct neural network Third party public sources Lightweight agent: Darknet <150MB, <1% CPU Home Made Malware Run on any CPU Only two updates a year Mutated Malware Data sample: hundreds of millions of malicious and benign files Supervised & unsupervised Nvidia GPUs training Private and confidential
THE DEEP LEARNING PROCESS FROM TRAINING TO PREDICTION Milliseconds *.ppt *.exe *.pdf Malicious No Tradeoffs: *.dll *macro Highest *.dll *. macho detection rates, *.doc *.RTF lowest false *.exe Benign *. APK positive *.doc *.ppt *. SWF Connectionless protection Autonomous on-device prevention Private and confidential
DEEP LEARNING BY
WHAT IS THE SOLUTION? Deep Instinct Neural Network Real-time Prevention Technology: >99% detection, <0.001% false positive Proprietary Deep Learning Framework Management Console Any Device, OS and network (1-2 updates a year, 150MB , <1% CPU) Deployment, Brain & Policy Update Zero Risk : No need to rip and replace D-Clients Management console : On prem or cloud PC Server Mobile Tablet Laptop Workstation Private and confidential
REALTIME PREVENTION by Deep Instinct Time to prevent Time to Time to Remediate Investigate & Contain 20 ms 50 ms <1 minute By D-Brain By Deep Classification “… so much of the success of EDR-like features and investigation capabilities relies heavily on the skills and experience of the security administrators using the product day-to-day . ” Private and confidential
WE DO NOT We do NOT use We do NOT require Signature Connectivity Sandboxing (for detection) Frequent updates Traditional machine learning Wait for execution of attack Experts for features Skilled & expensive SOC team engineering 22 Private and confidential
THE VALUE OF THE DEEP INSTINCT PREDICTION MODEL Spora Ransomware Created 10 Months earlier D-Client v1.9 D-Client v1.9 Discovered Release day and Prevented Spora is first First by the Deep reported as a upload to Instinct client new ransomware VirusTotal on a production family endpoint 45 days (at least) 37 days April 2016 Jan 10th 2017 Feb 16th 2017 Feb 24th 2017 23 Private and confidential
MYLOBOT: A NEW HIGHLY SOPHISTICATED NEVER- SEEN-BEFORE BOTNET First detected and prevented on a live customer environment on May 2018 Highly sophisticated botnet incorporates different malicious techniques Malware vs. Malware 24 Private and confidential
MYLOBOT: A NEW HIGHLY SOPHISTICATED NEVER- SEEN-BEFORE BOTNET First detected and prevented on a live Real-time prevention customer environment on May 2018 by deep learning cybersecurity Highly sophisticated botnet incorporates vs different malicious techniques Malware vs. Malware One month of extensive cyber expert analysis 25 Private and confidential
Com ome e Vis isit it Us s at O t Our r Bo Boot oth #5 #552 Take ke th the e Test st / Answe swer r Cor orre rectly ctly / Wi Win a Pr Priz ize Private and confidential
Thank you jonathank@deepinstinct.com | www.linkedin.com/in/jkaftzan Private and confidential
- Founded in 2015 - THE FIRST COMPANY TO APPLY DEEP LEARNING TO CYBERSECURITY THREAT PREVENTION INTELLECTUAL STRATEGIC HIGHLY EXPERIENCE PLATFORM PROPERTY INVESTORS TEAM First-see seen, , Unkn known own Unique prop opri riet etary ry deep ep 90 full time employees le learn rning g framework for Zero ro-da days, s, AP APTs, s, Deep learning scientists , cybersecurity Ransomw somware e comprised of PhDs, MSCs, Protected with 3 Cybersecurity veterans - Ex IDF registered patents & 3 and Israel intelligence Service trademarks 28 Private and confidential
DEEP INSTINCT ’ S MULTI LAYERED PROTECTION POST EXECUTION PRE-EXECUTION ON-EXECUTION Prevent Detection & Response Deep static analysis Deep behavioral analysis Automatic analysis PE | Ransomware | PDF | Office | Macro | Code injection | Enhanced Ransomware | Malware classification | Attack timeline (process chain) | Offline sandboxing Fonts | TIFF | RTF | SWF | Mach-O | JAR Metasploit's shellcodes *Virus – file infectors | *Worms | File reputation (D-cloud) *Keyloggers | *Credentials dumping | *Banking Remediation trojans | *Spyware Script control Whitelist/blacklist – Hash, Certificate, Folder | Import of list of indicators | File quarantine and restore | File delete | Terminate running process | Isolate device network Private and confidential * Roadmap
Recommend
More recommend