Keen to check for 'abnormal' user behaviours? Microsoft talks insider risk, AWS imports and compliance at infosec shindig RSA

Before you remove the mote from thy hacker's eye, remove the beam from the eyes of your, er, Teams


RSA As IBM's crew cancels their hotel rooms, Microsoft's infosec staffers are still set to attend the decades-old RSA conference and pulled the covers off a raft of security releases and previews for the event today.

The clocks strike 13 as Insider Risk Management is released

We spoke to Microsoft 365 Senior Director, Alym Rayani, about compliance and insider risk at last year's Ignite event.

Four months on, and the company has decided the product is ready for prime-time with the release to general availability of Microsoft Insider Risk Management and Communication Compliance. For Microsoft 365, naturally.

The gimlet glare of Insider Risk Management will use the likes of Graph to gaze over Office, Windows and Azure, as well as casting an eye over non-MS services such as SAP SuccessFactors and Workday via connectors. File activity, "communications sentiment" and "abnormal" user behaviours will be detected by the vaguely creepy service and passed onto HR (or whoever the workflow reckons is most appropriate.)

The data will include a timeline to show trends, context and history for the identified user. By default, the display names are anonymised.

As with all these things, the devil is in the detail and to get the most out of the new Orwellian Monitoring Insider Risk Management tools companies will have to ponder their processes – just slapping on some software and expecting it to do a bandaid on secret seepage isn't going to fly. It is, however, relatively easy to get started on the platform; there are no pesky agents to install nor audit events to configure. There are also three new policy templates: "Departing employee data theft", "Data leaks" and the exciting "Offensive language in email."

The "machine learning" used to spot naughty words has found its way into the Communication Compliance functionality too, which was also made Generally Available. Monitoring corporate communications such as Teams Messages or Bloomberg chats, as well as email, the system will keep an ear out for offensive language and threats and trigger workflows accordingly.

We can think of at least one corporate that could probably have benefited from such a thing. Alas, that particular aircraft has long since left the runway before the departure gate could be closed.

Microsoft Loves Linux (Security)

As well as widening the preview of Microsoft Threat Protection, a system aimed at a more automated response to threats, the gang has also extended the cross-platform support for Microsoft Defender Advanced Threat Protection (ATP) to include a whole bunch of Linux distributions.

Teased at last year's Ignite (skip to around the 14-minute mark for the full "sneak peek" experience), RHEL 7+, CentOS Linux 7+, Ubuntu 16 LTS, or higher LTS, SLES 12+, Debian 9+, and Oracle EL 7 all get some loving from Microsoft's AV boffins. Users can expect a full command line experience as well as AV, while basic alerts and machine information will show up in the Defender Security Center.

The functionality remains in preview for the time being and will be joined by additional security capabilities for iOS and Android devices.

Azure Sentinel: Give us your tired, your poor, your AWS CloudTrail logs

Having nudged Azure Sentinel into the light at last year's RSA event Microsoft is giving its security information event management (SIEM) platform a buffing with some new toys.

First up are connectors for the likes of Forcepoint and Squadra as well as one for Azure Security Center for IoT. The latter is particularly interesting since it means IoT data workloads from Azure IoT Hub-managed deployments can be shovelled into Azure Sentinel. The information will allow those who have bought into the Microsoft worldview to have a decent chance of spotting threats in a converged network.

As well as adding resources (via GitHub, of course) Microsoft is will also not be charging customers for importing AWS CloudTrail logs from 24 February 2020 to 30 June 2020. AWS CloudTrail allows users of Amazon's cloud to track their AWS account. With customers using multiple clouds, Microsoft's hope is that its SIEM platform will become a one-stop shop for security monitoring. And if Madam decides that Madam prefers her cloud to be Azure, well, we doubt the Redmond gnomes would demur.

Azure activity logs, Office 365 audit logs and Microsoft 365 security alerts can already be ingested for free. ®

Broader topics


Other stories you might like

  • It's 2022 and there are still malware-laden PDFs in emails exploiting bugs from 2017
    Crafty file names, encrypted malicious code, Office flaws – ah, it's like the Before Times

    HP's cybersecurity folks have uncovered an email campaign that ticks all the boxes: messages with a PDF attached that embeds a Word document that upon opening infects the victim's Windows PC with malware by exploiting a four-year-old code-execution vulnerability in Microsoft Office.

    Booby-trapping a PDF with a malicious Word document goes against the norm of the past 10 years, according to the HP Wolf Security researchers. For a decade, miscreants have preferred Office file formats, such as Word and Excel, to deliver malicious code rather than PDFs, as users are more used to getting and opening .docx and .xlsx files. About 45 percent of malware stopped by HP's threat intelligence team in the first quarter of the year leveraged Office formats.

    "The reasons are clear: users are familiar with these file types, the applications used to open them are ubiquitous, and they are suited to social engineering lures," Patrick Schläpfer, malware analyst at HP, explained in a write-up, adding that in this latest campaign, "the malware arrived in a PDF document – a format attackers less commonly use to infect PCs."

    Continue reading
  • New audio server Pipewire coming to next version of Ubuntu
    What does that mean? Better latency and a replacement for PulseAudio

    The next release of Ubuntu, version 22.10 and codenamed Kinetic Kudu, will switch audio servers to the relatively new PipeWire.

    Don't panic. As J M Barrie said: "All of this has happened before, and it will all happen again." Fedora switched to PipeWire in version 34, over a year ago now. Users who aren't pro-level creators or editors of sound and music on Ubuntu may not notice the planned change.

    Currently, most editions of Ubuntu use the PulseAudio server, which it adopted in version 8.04 Hardy Heron, the company's second LTS release. (The Ubuntu Studio edition uses JACK instead.) Fedora 8 also switched to PulseAudio. Before PulseAudio became the standard, many distros used ESD, the Enlightened Sound Daemon, which came out of the Enlightenment project, best known for its desktop.

    Continue reading
  • VMware claims 'bare-metal' performance on virtualized GPUs
    Is... is that why Broadcom wants to buy it?

    The future of high-performance computing will be virtualized, VMware's Uday Kurkure has told The Register.

    Kurkure, the lead engineer for VMware's performance engineering team, has spent the past five years working on ways to virtualize machine-learning workloads running on accelerators. Earlier this month his team reported "near or better than bare-metal performance" for Bidirectional Encoder Representations from Transformers (BERT) and Mask R-CNN — two popular machine-learning workloads — running on virtualized GPUs (vGPU) connected using Nvidia's NVLink interconnect.

    NVLink enables compute and memory resources to be shared across up to four GPUs over a high-bandwidth mesh fabric operating at 6.25GB/s per lane compared to PCIe 4.0's 2.5GB/s. The interconnect enabled Kurkure's team to pool 160GB of GPU memory from the Dell PowerEdge system's four 40GB Nvidia A100 SXM GPUs.

    Continue reading
  • Nvidia promises annual updates across CPU, GPU, and DPU lines
    Arm one year, x86 the next, and always faster than a certain chip shop that still can't ship even one standalone GPU

    Computex Nvidia's push deeper into enterprise computing will see its practice of introducing a new GPU architecture every two years brought to its CPUs and data processing units (DPUs, aka SmartNICs).

    Speaking on the company's pre-recorded keynote released to coincide with the Computex exhibition in Taiwan this week, senior vice president for hardware engineering Brian Kelleher spoke of the company's "reputation for unmatched execution on silicon." That's language that needs to be considered in the context of Intel, an Nvidia rival, again delaying a planned entry to the discrete GPU market.

    "We will extend our execution excellence and give each of our chip architectures a two-year rhythm," Kelleher added.

    Continue reading
  • Amazon puts 'creepy' AI cameras in UK delivery vans
    Big Bezos is watching you

    Amazon is reportedly installing AI-powered cameras in delivery vans to keep tabs on its drivers in the UK.

    The technology was first deployed, with numerous errors that reportedly denied drivers' bonuses after malfunctions, in the US. Last year, the internet giant produced a corporate video detailing how the cameras monitor drivers' driving behavior for safety reasons. The same system is now apparently being rolled out to vehicles in the UK. 

    Multiple camera lenses are placed under the front mirror. One is directed at the person behind the wheel, one is facing the road, and two are located on either side to provide a wider view. The cameras are monitored by software built by Netradyne, a computer-vision startup focused on driver safety. This code uses machine-learning algorithms to figure out what's going on in and around the vehicle.

    Continue reading

Biting the hand that feeds IT © 1998–2022