Go back

#18 ITDR - A promising domain or just another fad

23m 11s

#18 ITDR - A promising domain or just another fad

In this episode of the Identity Navigator, host Rohit discusses the growing significance of identity as the main attack vector in cybersecurity and the rise of Identity Threat Detection and Response (ITDR). ITDR represents a convergence of Identity and Access Management (IAM) and Security Operations Centers (SOC), aimed at proactively detecting, investigating, and mitigating identity-based threats through monitoring anomalies such as unusual login patterns or privilege escalations. The landscape is rapidly evolving with strategic moves by major players like Cisco and Microsoft, though the definition of ITDR remains fluid, leading to diverse vendor interpretations. Rohit emphasizes that identity attacks are especially perilous because attackers exploit legitimate credentials, making detection challenging. He outlines key functions of ITDR systems, including threat detection, investigation, and response, and highlights maturity factors like accurate identity inventories and automated remediation. Listeners are advised to focus on capabilities rather than product names when evaluating solutions and to consider controls like identity deception (e.g., honey accounts) for enhanced security. The episode concludes with a preview of future discussions on specific ITDR tools and an invitation for audience feedback.

Transcription

3084 Words, 17903 Characters

English
Hello and welcome to another episode of the Identity Navigator. This is your host Rohit. Thank you for the great feedback on the last episode which was about continuous access evaluation. Check it out if you haven't done it. We now have a community of listeners from over 40 countries. Thank you all so much. Please keep the emails and LinkedIn messages coming and let me know if you would like to hear more about any specific topic. Which brings me to today's topic which a lot of you have requested in the past few months and I personally have been very interested about it as well. As more and more cyber attacks roots back to identity and identity compromise, we are and will see more of a few things. The first is identity becoming the primary attack vector and taking a center stage in cyber security teams. We have already seen this happening. Identity is now the number one attack vector in most of the cyber attacks. And the number two things that you would see more of is emergence of the new IM domains and tools. Some of these domains and tools, they are absolutely going to change the way we manage and think about digital identities and access control. But then you have also got your opportunists. Those just trying to catch a ride on the IM gravy train. They see the dollar sign and things. Why not slap an IM label on our product and see what happens in the realm of identity and access management. We are all familiar with domains like identity governance, consumer identity, access management, privileged access management, so on and so forth. However, there is a new domain emerging that is gaining significant traction among major players in the identity industry. Identity threat detection and response are commonly called as ITDR. ITDR is poised to become a major force, offering innovative ways to detect and respond to identity related threats. As this domain continues to evolve, it holds immense potential to reshape how we approach identity security. And we also need to look into is it truly a new concept or is it a fad or is it only being spun around by the opportunists? Because the word DR is very sellable. As soon as you identify a threat surface, create a DR product like XDR, EDR and so many other DRs exist today. Now detection and response or DR isn't some security secret source. I would argue that by definition it is a reactive approach. There is an inherent complexity with identity do. If we were discussing endpoints, servers, networks or firewalls, this could be shut down. But you cannot just shut down an identity. You cannot just run a scanner on it. It is very different from physical things that we have traditionally guarded and therein lies the complexity of it. So I would say with identity security, you are not guarding the vulnerabilities. You are not guarding the gaps. You are guarding the front door of your organization and this is a front door that cannot be closed. This is a door that has to be big enough for your guest, friends and family to come in. And this is the same door that attackers are now utilizing as well. You know how in those heist movies, the bad guys sometimes use fancy disguises to blend in with the crowd? Well identity based attacks are kind of like that but ways sneak here. Imagine a high security art museum. Now instead of trying to break in through a window or disable the alarm system, our cyber thief does something much more clever. They don't just dress up as security guard. They somehow convince a real guard to hand over their uniform, badge and access code. Now our thief isn't just walking around in a costume. They have got all the real credentials. They can scroll, right past every checkpoint, open any door and even chat with other staff without raising suspicion. They are not trying to fool the cameras or dodge the senses. They are using the system exactly as it's meant to be used but for all the wrong reasons. Now because everything they are doing looks totally legit from the outside, nobody is going to raise an eyebrow. They are not breaking the rules. They are playing by them but with a totally different end game in mind. This is what makes these identity based attacks so dangerous. The bad guys aren't just pretending to be one of the good guys. They are manipulating the whole system to make it look like they are the good guys. It is not about wearing a convincing mask. It's about changing the face underneath. Thus we need dedicated approach to solve this problem and ITDR products or domains is trying to do it. We are witnessing a significant shift in the industry with major players making strategic moves to solidify their positions in this emerging space. Cisco for instance has recently acquired ORD, a move that is sent to Ballster, their extended detection and response capabilities. Similarly Delinear has brought authorized into their fold in answering their ability to detect and mitigate identity based threads across cloud environments. But it's not just about acquisitions, industry giants like Beyond Trust, Crowd Strike and Sentinel One are investing heavily in developing their own ITDR technologies. The soft always affords to be reckoned with is leveraging its existing products, integrating intra with Defender XTR to create a comprehensive ITDR solution. But there is one small problem. Like Zero Trust, no one really sure of what ITDR is. As this space is still taking shape. We are seeing multiple players entering the market, each bringing their own interpretation of what ITDR truly encompasses. But this diversity is good because this diversity is driving innovation and pushing the boundaries of identity security. As the ITDR landscape continues to evolve, it is clear that this is more than just a passing trend. It is becoming a crucial component of modern cybersecurity strategies addressing the growing challenge of identity based threads in our increasingly cloud centric world. A lot of these companies don't even use the word ITDR in their product names. So if and hopefully when you are looking into ITDR solutions, keep in mind that you might need to look beyond just the product name. You will have to focus on the capabilities and how they align with your organization's needs for identity protection. It's about the function and not just the label. So if you are looking at the vendor telling you why do you need ITDR, you might have to do extensive research. You want to be clear on what do you want ITDR to be in your company and then start looking for those solutions. Because as we discussed, every vendor is coming with their own set of implementations for this space. So when I realized how fluid this space is and how many unknowns there are, I had to phone a friend and I reached out to Mike new shounder who is one of the words leading expert on ITDR. Mike as great as he is, hooked me up with some excellent insights that allowed me to more be more thorough in my research and I cannot help or cannot thank him enough for setting me up with all of his research and his point of view that really made my arguments more convincing. Interestingly, Mike has proposed the name identity defense in depth which in short could read as IDID or you could also read it as I did which has a nice ring to it. I don't think it has caught up yet but there is a void in industry today. I think in the very near future, ITDR would be renamed to something which more and more of identity teams would associate with. Now ITDR is a subject. essentially bridging two previously distinct domains in cyber security. Identity and access management and security operations centers are SOC. Historically, these two areas operated in relative isolation. I am focused on managing digital identities and access rights while the SOC's concentrated on detecting and responding to security threats. Now with ITDR, we are seeing a convergence of these disciplines. This convergence isn't just a minor shift. It is a significant evaluation or evolution in how we approach cyber security. Act its core ITDR aims to protect against attack that compromises user identities. Personally for me and I am oversimplifying it a little, ITDR is a use case but it is here to stay. It might go through a few iterations. It might go through the change in a nomenclature. It might have increased or decreased in scope but this use case or the underlying thought process behind it is here to stay. So the foundational things and ITDR system should be able to do what are those. Let's look into those a little bit. Number one, threat detection which means monitoring identity related activities to detect anomalies or suspicious behaviors. That may indicate a potential threat such as unusual login patterns, revealage escalations or unauthorized access attempts. Number two, what it should be able to do is investigation of detected anomalies to determine their nature and potential impact. This involves analyzing logstata, user behavior and any other relevant information to understand the scope and intent of the threat. Number three is based on these anomalies taking appropriate action to neutralize the threat and prevent further compromise. This may include blocking access, revoking compromise credentials or implementing additional security measures to protect the affected identities. So it could be simply thought of as cybersecurity aimed at identity, right? Cyber security aimed to protect a broad range of IT assets and infrastructure. ITDR hones in on the specific challenges of securing identities and access management systems. Irrespective of what you think it is, it is pretty evident that this is an important space. You may not even call it ITDR. You may not even consider it an IAMs or you could consider that it was always present as cybersecurity control and thus there is nothing new. But just based upon the recent increase in identity based attacks and I don't want to quote some random statistics, you would have to think about and implement these controls to enhance your organization's security posture. So it has always been there, but because of the recent attacks, it is now at the forefront and the attackers are asking you to be more implicit or explicit about how you are going to be dealing with the challenge lies in the scope of the problem, right? Identities exist everywhere in our digital ecosystem and the contextual knowledge needed like a service account may not have MFA, but a user account must. This is where the challenge is. It's about the context or the depth where you are going in and this is the challenge with multiple vendors as well, right? We spoke about the three basic things that every ITDR system should have, things like thread detection investigation of detected anomalies and then response based upon those anomalies, right? In thread detection, we spoke about potential threads like unusual log in patterns, privilege, escalation and some of the other things. Now the maturity of your system to identify more of these potential threads. Can you look at, can you identify man in the middle attack? Can you identify a session hijacking? Can you identify impossible travels? Can you identify behavioral differences? Can you identify golden ticker attacks and just goes on and on? So maturity of the thread detection is really a challenge for the vendors and for you as a buyer, what or how mature do you want the thread detection to be? Because you like it or not, you will never have everything unless you are going to be paying $100 million for the simple solution, right? You will have to pick and choose based upon your risk appetite, but for defining that risk appetite, you will first have to define for yourself what is the threat that you are trying to mitigate, right? And then we will get about, okay, so these are the threads that we want to mitigate, how is the tool detecting the anomalies and how is the tool responding on those anomalies? Do you want an automated response or do you want the response to be manual? What type of workflows do you want behind it? These are all implementation details and business problems to solve, but thread detection should that scoping should be number one in your list when you are looking into the space or domain. So if ITDR had a maturity scale, it will depend on a few things. I will tell you 10 of those. Number one is no vendor in the world can come and solve it if you do not know how accurate your identity and access inventory is, right? So in the majority scale, the number one criteria is accuracy of your identity and access inventory. Now remember, identities are both human and non-human and non-human just doesn't means your service accounts. This also means your API keys, your certificates, your job tokens and access is both direct and indirect. It could be indirect access like group membership, which we all assume, but then policy inheritance that we all could think of, but then also think about assumed rules in the cloud, which is completely different from how roll-based access control works on premise. So you would have to look into both human and non-human identities and both direct and indirect access and that would be the number one criteria for your ITDR maturity. Number two is how clean is your inventory and do you know the risk associated with the clean most up to date? And number three on the maturity scale would be familiarity with historical attack paths known weaknesses and understanding of evolving threat vectors. And this would really depend on the product. This is something that you should expect from the product. What is their familiarity with historical attack paths? What is in scope for them? Do they understand the weaknesses and how do they cater to the evolving threat vectors? So some of the historical attack paths like we discussed, golden ticket and also silver ticket. Pass the hash, password spring, man in the middle, credential harvesting, credential compromise detection inside a threat detection. So ask this question about what is the scope of their detection. And this would be one of the things that would count towards your ITDR maturity. The four things that would count against your maturity scale is effectiveness of reactive controls like log analysis. And don't think of this about the silos. Think of it, the control should be smart enough to look at two different and innocent events and sniff a problem. So association is one thing. But looking at two distinct and different innocent events and still I trying to and still being able to sniff a problem with relative high success rate is what would count towards the reactiveness of your reactive control. Number five on this scale is effectiveness of detective controls like creation of baseline identity security posture and anomaly detection. And this is really for us to decide or define. Number six is pairing these two reactive and detective controls together. Number seven on the maturity scale is what are the ways how you conduct threat hunting on identity. Number eight is integration with your seam and so and other systems so that you can have multi plane coverage. So multi plane coverage and the maturity of that would count towards the maturity of your ITDR number nine is organizational effectiveness between sought and I am teams. Those standard operating procedures and handoff that exists and last but not the least a key factor in refining or determining your maturity scale for ITDR is automated remediation capabilities. Because by definition it has the word response in it and how automated your remediation or response is that would define the maturity of your ITDR. There is another interesting concept here called as identity deception, deception. It is conceptually similar to honeypots used in networking. Both involve creating decoy elements designed to attract and engage potential attackers. So, they consist things like honey accounts. These are fake user accounts created within identity store like Active Directory. They are designed to attract attackers. When an unauthorized user attempts to access these accounts, it triggers alerts and allows security teams to respond quickly. And honey tokens which are deceptive credential profiles, pleased in identity cache on endpoints. This serve as early warning signals when access by unauthorized users helping to identify potential breaches before they escalate. So, this is not a new concept. Think of it as honeypots used in networking. But these identity deception is not to fool or deceive your ITDR system. This is a control that should, ideally, should exist in the ITDR systems and these identities should be known to your ITDR system. This is not a way of checking with which ITDR tool is most effective. This is a way of catching an attacker earlier in their journey. Some of the leaders we spoke about in this space are beyond trust. Crowdstrike, I have falcon identity, plate protection, delineas, optimized platform and Microsoft with their enter ID and HDR implementations. Now, next time we will talk about beyond trust and their identity security insights tool. We will see what it does in the next episode and see how they stack up to everything that we discussed today. Also, the platform that I used to record, the podcast has now been made redundant. So, I am trying this episode on a new platform. So, you might hear a new intro and outro music. In any case, thank you for listening. Please keep sending me those emails and LinkedIn messages. It really helps me to keep this going and invest that time. I can always be reached out via LinkedIn or you can email me at [email protected]. Thank you all. I am really looking forward to your responses on the ITDR. What do you think about it? What resonated with you the most and what would you like to have heard most? Until next time, this is Rohit, your identity navigator.

Podcast Summary

Key Points:

  1. Identity is now the primary attack vector in cybersecurity, leading to the emergence of Identity Threat Detection and Response (ITDR) as a critical domain.
  2. ITDR bridges Identity and Access Management (IAM) and Security Operations Centers (SOC), focusing on detecting, investigating, and responding to identity-based threats through monitoring anomalies like unusual logins or privilege escalations.
  3. The ITDR landscape is evolving with major acquisitions and investments, but definitions vary; maturity depends on factors like accurate identity inventory, threat detection scope, and automated remediation capabilities.
  4. Identity-based attacks are particularly dangerous because attackers use legitimate credentials to bypass security, akin to a thief using a real guard's uniform to infiltrate a museum.
  5. Organizations evaluating ITDR should focus on functionality over labels, assess vendor capabilities against their specific needs, and consider controls like identity deception (e.g., honey accounts) for early threat detection.

Summary:

In this episode of the Identity Navigator, host Rohit discusses the growing significance of identity as the main attack vector in cybersecurity and the rise of Identity Threat Detection and Response (ITDR). ITDR represents a convergence of Identity and Access Management (IAM) and Security Operations Centers (SOC), aimed at proactively detecting, investigating, and mitigating identity-based threats through monitoring anomalies such as unusual login patterns or privilege escalations. The landscape is rapidly evolving with strategic moves by major players like Cisco and Microsoft, though the definition of ITDR remains fluid, leading to diverse vendor interpretations.

Rohit emphasizes that identity attacks are especially perilous because attackers exploit legitimate credentials, making detection challenging. He outlines key functions of ITDR systems, including threat detection, investigation, and response, and highlights maturity factors like accurate identity inventories and automated remediation. Listeners are advised to focus on capabilities rather than product names when evaluating solutions and to consider controls like identity deception (e.g., honey accounts) for enhanced security. The episode concludes with a preview of future discussions on specific ITDR tools and an invitation for audience feedback.

FAQs

ITDR is a cybersecurity domain focused on detecting and responding to identity-related threats, bridging identity management and security operations to protect against attacks that compromise user identities.

Identity is now the number one attack vector because attackers increasingly compromise legitimate credentials to bypass security measures, making it a central focus for cybersecurity teams.

An ITDR system should monitor for identity anomalies, investigate detected threats, and respond with actions like blocking access or revoking credentials to neutralize risks.

ITDR maturity relies on accurate and clean inventories of both human and non-human identities, including direct and indirect access, to effectively detect and respond to threats.

Identity deception uses decoy elements like honey accounts and tokens to attract attackers, serving as an early warning control within ITDR systems to identify breaches sooner.

Companies like Cisco, Microsoft, and CrowdStrike are investing in ITDR through acquisitions, product integrations, and developing their own technologies to address identity-based threats.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.