{"id":3699,"date":"2024-05-22T12:00:00","date_gmt":"2024-05-22T17:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/trends-at-2024-rsa-startup-competition"},"modified":"2024-05-22T12:00:00","modified_gmt":"2024-05-22T17:00:00","slug":"trends-at-the-2024-rsa-startup-competition","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/22\/trends-at-the-2024-rsa-startup-competition\/","title":{"rendered":"Trends at the 2024 RSA Startup Competition"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt9cca590d6c130b0d\/664cf52e3c4605f2ce5c419d\/Innovation_Aleksia_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/trends-at-the-2024-rsa-startup-competition.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/trends-at-the-2024-rsa-startup-competition.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Artificial intelligence (AI) security, automation&#8217;s nonhuman identity problem, and the reinvention of detection and response (DR) were emerging trends at the RSA Conference 2024&#8217;s top startup competition, Innovation Sandbox.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/reality-defender-wins-rsac-innovation-sandbox\" rel=\"noopener\">Reality Defender took the crown<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;for deepfake detection. In the space of a month, its CEO and co-founder Ben Colman <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.nbcnews.com\/tech\/misinformation\/senate-hearing-deepfake-experts-tackles-elections-sexual-abuse-rcna148109\" rel=\"noopener\">testified before the&nbsp;US Senate<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;and the company wowed the Innovation Sandbox judging panel with its expertise in detecting deepfakes. Promoting the threat deepfakes pose to global democracy in this election year, investors also saw commercial opportunities in protecting bank voice authentication and corporate brand reputation.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At the moment, building machine learning (ML) models from scratch is not that common. With powerful new foundational models coming out each week, today&#8217;s startups typically tout flexible architectures to reuse models. Startups then add value by tuning foundational models, training them on private data, or quantizing them into smaller performative versions.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In this regard, Reality Defender&#8217;s bespoke AI stands out. Its constellation of ensemble models detect deepfakes and understand indicators of aliveness, such as heartbeats and blushing.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"New Data Security Emerges for the AI Era\">New Data Security Emerges for the AI Era<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Organizations are repositories of knowledge, secrets, and technologies that they hope can be leveraged with artificial intelligence. Yet it&#8217;s a scary process exposing different AI models to select data from enterprise wikis, repositories, and databases.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Everyone seemed sensitive about calling Harmonic Security &#8220;DLP for AI,&#8221; but it didn&#8217;t bother Harmonic. It knows that data loss prevention for AI is the Holy Grail in 2024. Harmonic Security deploys endpoint large language models (LLMs) that the company says don&#8217;t need to train against your private data and can coach user behaviors at the point of data loss.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Finalist Antimatter provides engineers in DevOps with application programming interfaces (APIs) that enable safe access to internal training data. With Antimatter&#8217;s control plane, SecOps can impose global data access levels on DevOps.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">AI data security is important, but chief information security officers (CISOs) need to know what data they have before tackling AI policies. BedRock is working on answering these age-old questions: What data do you have, where is it, and who&#8217;s accessing it? BedRock reduces data into a smaller vector space before classifying with LLMs. Claiming AI reasoning capability instead of rules, it groups data with trust boundaries.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Reimagining Detection and Response\">Reimagining Detection and Response<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/rethinking-how-you-work-with-detection-response-metrics\" rel=\"noopener\">Detection and&nbsp;response<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">&nbsp;<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">is different from preventative security technologies, such as posture management. DR guides human investigators through the advanced attacks that got thorough, a labor-intensive process that GenAI threatens to revolutionize. In addition to DR automation, the industry needs platforms that span multicloud telemetry.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">DropZone&#8217;s LLM-enabled product looks like a post-SOAR automation architecture.&nbsp;It doesn\u2019t require building sequential playbooks or writing code, and it doesn&#8217;t need manual intervention.&nbsp;DropZone requires an hour of training against your past 100 cases, then can automate response for low-priority alerts typically handled by imprecise tier 1 analysts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For each alert, DropZone&#8217;s LLMs iteratively pull context from integrations with security operations center products and build investigation summaries. Alert summaries are readable in minutes and include recommendations and artifact evidence to reduce hallucinations<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">RAD Security detects increasingly sophisticated malware in Kubernetes and is kind of a next-gen convergence of behavioral AppSec and container detection and response.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">RAD Security uses a &#8220;declarative model&#8221; defining drift from the norm. It promises to be a powerful approach in Kubernetes because DevOps heavily reuses open source code. RAD Security claims that container states mostly converge on its catalog of top 50 images, with only a long tail of container variance beyond.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">RAD&#8217;s drift artifacts are what you&#8217;d expect from eBPF telemetry: process trees, file access, events, and container information. Yet when drift artifacts are fed into LLMs, multiple alerts suddenly collapse into broader attack stories.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">True multicloud detection and response is much broader than malware detection. Unlike old XDR, the cloud&#8217;s unit of focus is more identity-based. Most cloud attacks happen through authenticated APIs or stolen credentials.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Mitiga helps SecOps graduate into full multicloud investigations. First, providing visibility scores to ensure enough telemetry is collected into its data lake, Mitiga&#8217;s timeline of events spans cloud, identity solutions, and SaaS applications.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">VulnCheck ruminated on the monthlong process of disclosure to CVE assignment and to final storage in the National Vulnerability Database. By the time CVEs make it to scanners and patching, exploit kits have already proliferated on GitHub. VulnCheck speeds up the process with rapid and prioritized vulnerability intelligence and millions of contextual records.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Securing Automation's Identity\">Securing Automation&#8217;s Identity<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A few companies like Okta and Microsoft have mostly solved user identities in cloud hybrid environments. Yet automation and service accounts are producing a much larger set of identities.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With automation often falling under the chief technology officer or chief information officer, it&#8217;s tough for CISO organizations to govern nonhuman identities. Thus, these final two startups share the approach of spanning from SecOps into the engineers of DevOps.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Aembit is a workload identity and access management platform securing nonhuman identities across clouds, SaaS services, and third-party APIs. Aembit reduces the pain of managing long-lived secrets.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">P0 Security is a universal platform for authentication, authorization, and governance of both humans and nonhumans. P0 automates short-lived access to things like SSH or S3, and special access for admins or data editors. P0 Security manages tokens and bulk deprovisioning through the gatekeepers in DevOps.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Startups are rapidly adjusting to both the world of AI adversaries and data vulnerabilities in organizational AI initiatives. They know AI&#8217;s novel use will soon reinvent&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">all<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;security product categories. Nobody can predict how this will play out, but Innovation Sandbox provides the best glimpse into this future.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/trends-at-2024-rsa-startup-competition\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY Artificial intelligence (AI) security, automation&#8217;s nonhuman identity problem, and<\/p>\n","protected":false},"author":12,"featured_media":3700,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3699","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/trends-at-the-2024-rsa-startup-competition.jpg?fit=1808%2C1031&ssl=1",1808,1031,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/trends-at-the-2024-rsa-startup-competition.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/trends-at-the-2024-rsa-startup-competition.jpg?fit=300%2C171&ssl=1",300,171,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/trends-at-the-2024-rsa-startup-competition.jpg?fit=640%2C365&ssl=1",640,365,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/trends-at-the-2024-rsa-startup-competition.jpg?fit=640%2C365&ssl=1",640,365,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/trends-at-the-2024-rsa-startup-competition.jpg?fit=1536%2C876&ssl=1",1536,876,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/trends-at-the-2024-rsa-startup-competition.jpg?fit=1808%2C1031&ssl=1",1808,1031,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/trends-at-the-2024-rsa-startup-competition.jpg?fit=1024%2C584&ssl=1",1024,584,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/trends-at-the-2024-rsa-startup-competition.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/trends-at-the-2024-rsa-startup-competition.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/trends-at-the-2024-rsa-startup-competition.jpg?fit=1808%2C1031&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3699","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3699"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3699\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3700"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3699"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3699"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3699"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}