Spies + Math == Darktrace at London Disrupt 2016

15.6K views
•
December 5, 2016
by
TechCrunch
YouTube video player
Spies + Math == Darktrace at London Disrupt 2016

TL;DR

Darktrace detects cyberattacks by learning what a network's normal 'pattern of life' looks like, then flagging any deviation in real time, rather than pre-defining known threats. Founded by Cambridge mathematicians alongside former GCHQ and MI5 experts, its 'Enterprise Immune System' assumes breach is inevitable and finds something unwanted in 80% of trial deployments.

Transcript

[Applause] okay as uh we're we're off and running and uh we're going to bring up our next guest because I went over so please welcome to the stage poppy Gustafson from dark trace and our moderator Natasha Lomas cyber security firm dark Trace is one of the UK's most exciting and fast growing startups and perhaps also one of the most mysterious poppy... Read More

Key Insights

  • Darktrace's core approach differs from traditional cybersecurity: instead of defining what a known threat looks like from outside, it models what a network's own normal internal behavior looks like and flags deviations that could signal an attack.
  • The company originated from Cambridge mathematicians using machine learning to teach a computer a 'sense of self,' who then joined former government intelligence experts from GCHQ and MI5 who saw the math could apply to cybersecurity.
  • The math and machine learning research came first, and the intelligence-agency experts subsequently recognized it could be applied to the problem of cyber defense, making cybersecurity a timely fit for the technology.
  • The intelligence-agency founders contributed a deep understanding of the problem's scale, recognizing attacks were becoming inevitable while businesses still focused on securing boundaries against decade-old vulnerabilities.
  • Darktrace's product, the Enterprise Immune System, is modeled on the human immune system: it maintains an innate sense of self at the network level, monitoring the normal pattern of life for every device and flagging changes in real time.
  • Darktrace operates on an 'assume breach' philosophy: if an insider wants to get on your network they will, so the system focuses on catching the slow, low, quiet behaviors of an intruder traversing the network.
  • Boundary protections like firewalls and perimeter defense remain necessary network hygiene; Darktrace positions itself as a complementary layer that catches threats which get past those defenses.
  • In roughly 80% of proof-of-value demonstrations, Darktrace finds something a customer does not want to see, even at companies confident their existing antivirus leaves nothing to discover, partly because networks are growing so quickly.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What does Darktrace do and how is it different from traditional cybersecurity?

Darktrace takes a fundamentally different approach from traditional cybersecurity. Rather than defining what a known threat looks like and looking outward to predefine attacks, it learns what your own internal network normally looks like. By knowing that normal pattern of life on a day-to-day basis, it can identify when behavior changes, which could be a symptom of an attack, and it flags that change in real time.

Q: Who founded Darktrace and what is its intelligence background?

Darktrace started from a group of mathematicians at the University of Cambridge trying to use machine learning to teach a computer a sense of self. They joined with former experts from government intelligence agencies such as GCHQ and MI5 who believed the mathematics could be applied to cybersecurity. Named co-founders include Poppy Gustafsson, Jack Stockdale, Nick Trim, and Dave Palmer, with Invoke Capital as the main initial investor.

Q: What is the Enterprise Immune System and how does it work?

The Enterprise Immune System is Darktrace's product, modeled on the human immune system. Just as the human immune system has an innate sense of self that lets it identify others, even viruses or bacteria it has never seen before, Darktrace sits at the network level and monitors the normal pattern of life for each and every device on your network. If that pattern changes, it flags the change to you in real time.

Q: Did the math research or the intelligence expertise come first at Darktrace?

The math and machine learning came first. According to Poppy Gustafsson, it was first the mathematics and machine learning focused on teaching a computer to understand itself, and then the former experts from government intelligence agencies recognized this math could be applied to the problem of cybersecurity. Machine learning can be applied to any number of industries, and this happened to be the right time for cybersecurity, which helped the product take off.

Q: Is Darktrace affiliated with government intelligence agencies?

No. Although Darktrace was created with help from people who came from intelligence agencies, the company is completely independent and not attached to any particular government intelligence agency. It works with a wide range of private and public sector clients. It does support public sector organizations, including work across the UK and abroad helping them protect their own internal networks, but it is not affiliated with any agency.

Q: What can Darktrace's technology miss or not catch?

Darktrace emphasizes that good boundary protections remain part of good network hygiene, so firewalls and perimeter defenses are still needed. The company operates on an assume-breach philosophy: if an insider wants to get on your network, they will get on your network. Once inside, an intruder's behaviors and attack vectors tend to be slow and low, gently traversing the network to see what they can access, and those quiet behaviors are what Darktrace picks up.

Q: What is an example of a creative hack Darktrace has discovered?

At a luxury goods manufacturer that used biometric fingerprint scanners to secure warehouse entrances, Darktrace noticed one scanner had been left more exposed to the internet than it should. Someone had gained network access and downloaded all employee fingerprints, which were unencrypted, then re-uploaded a whole load of new fingerprints, presumably including their own, to gain warehouse access, changing the integrity of the company's data.

Q: How often does Darktrace find threats during a trial deployment?

As part of its business model, Darktrace goes into a customer environment and runs a proof of value to demonstrate the software. Even when clients insist their antivirus leaves nothing to find, Darktrace discovers something the customer does not want to see in 80% of the time it runs these proof-of-value trials. This makes it a significant eye-opening moment, partly because networks today are growing so quickly.

Summary

In this video, Poppy Gustafson from Darktrace discusses how the idea for Darktrace started from a group of mathematicians at the University of Cambridge who were using machine learning to teach a computer to have a sense of self. They partnered with experts from government intelligence agencies to apply this mathematics to the problem of cybersecurity. Darktrace takes a different approach to cybersecurity by focusing on understanding the normal pattern of life in a network and identifying changes in behavior that could be a symptom of an attack. Darktrace's security approach is based on machine learning and models the network's normal pattern of life for each device, flagging any changes in real-time.

Q: Is Darktrace affiliated with intelligence agencies?

No, Darktrace is an independent company and works with a wide range of private and public sector organizations. While they do support the public sector, they are not attached to any intelligence agency.

Q: How is Darktrace's security approach different from other solutions on the market?

Darktrace's security approach is based on machine learning, specifically modeling the normal pattern of life for a network. This is similar to the human immune system, where the system can identify changes and adapt its defense. Darktrace's Enterprise immune system sits at a network level, monitoring the behavior of each device. If any behavior changes, it flags it in real-time.

Q: Can Darktrace's technology catch everything or are there limitations?

Darktrace's technology is highly adaptable and can catch a wide range of attacks. However, it's important to note that having good perimeter defenses and network hygiene is still important. While Darktrace can identify subtle and slow attacks, boundary protection is still necessary as attackers can still breach a network.

Q: Who are the co-founders of Darktrace?

The co-founders of Darktrace include mathematicians, experts from government intelligence agencies, and members of the management team from Invoke Capital, their main initial investor.

Q: Is Darktrace's security approach applicable to all industries?

Yes, Darktrace works with organizations across various sectors, with a slight bias towards financial institutions. They also cover sectors like law firms, retail, manufacturing, healthcare, and critical infrastructure companies. Darktrace's technology is adaptable and can be applied to different verticals.

Q: Is terrorism a concern for Darktrace's customers in critical infrastructure industries?

Yes, maintaining the integrity of data and operational functionality is crucial for critical infrastructure companies. The potential future threat of "trust attacks," where attackers manipulate data to influence strategic decisions, is a concern for these companies. Darktrace helps protect critical infrastructure by identifying anomalies and changes in behavior.

Q: Can Darktrace automate the mitigation of attacks as well?

Yes, Darktrace has developed a product called "Antigena" that can take action based on identified threats. For example, in the case of a ransomware attack, Antigena can slow down or switch off the connection associated with the attack. This automation is not meant to replace security teams but to provide them with faster reaction times.

Q: Could the entire security function be automated in the future?

While self-healing and fully automated security functions could be a possibility in the future, there is still a hesitation in fully relinquishing control to machines. Darktrace believes in supporting security teams and providing them with information and initial steps to prevent damage. Human involvement in taking action based on identified threats is still crucial.

Q: Have there been any AI-led attacks using Darktrace's technology?

Darktrace has not encountered any AI-led attacks yet. The current focus is on mitigating existing risks, such as ransomware. However, the use of artificial intelligence by attackers to increase the intelligence of attacks is a potential future concern.

Q: How did Mike Lynch get involved with Darktrace?

Mike Lynch, with a PhD in mathematics, incubated Darktrace through Invoke Capital. He brought together the meeting of minds and commercially supported the idea of applying mathematics to cybersecurity. Darktrace has also received additional investments strategically, allowing them to expand into new markets.

Q: Are there plans for an IPO?

There are no immediate plans for an IPO. Darktrace's focus is on growing the business and meeting the high demands for their Enterprise immune system.

Summary & Key Takeaways

  • Darktrace began as a group of Cambridge mathematicians using machine learning to teach a computer a sense of self, who partnered with former GCHQ and MI5 intelligence experts convinced the math could solve cybersecurity. The math came first; the spies recognized its application. Co-founders include Poppy Gustafsson, Jack Stockdale, Nick Trim, and Dave Palmer, with Invoke Capital as the initial investor.

  • Unlike traditional security that defines threats from the outside, Darktrace models a network's own normal pattern of life and flags deviations. Its Enterprise Immune System, inspired by the human immune system, maintains an innate sense of self, monitors every device on the network, and identifies unusual behavior, such as an intruder moving slowly and quietly, in real time.

  • Darktrace operates on an assume-breach philosophy while still recommending firewalls and perimeter defenses. In one case, exposed biometric fingerprint scanners at a luxury goods maker let an attacker download and re-upload employee fingerprints. In roughly 80% of proof-of-value trials the company finds something unwanted, making deployments eye-opening for confident customers.


Read in Other Languages (beta)

Share This Summary 📚

Summarize YouTube Videos and Get Video Transcripts with 1-Click

Download browser extensions on:

Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator

Explore More Summaries from TechCrunch 📚

Summarize YouTube Videos and Get Video Transcripts with 1-Click

Download browser extensions on:

Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator