Thales Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/thales/ Breaking news about the market for products, systems and services for the U.S. intelligence community Sun, 01 Feb 2026 22:24:21 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg Thales Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/thales/ 32 32 59882712 Security at the Enterprise Edge: Top Five Concerns https://intelligencecommunitynews.com/ic-insiders-security-at-the-enterprise-edge-top-five-concerns/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-security-at-the-enterprise-edge-top-five-concerns Sun, 01 Feb 2026 22:23:27 +0000 https://intelligencecommunitynews.com/?p=43755 From IC Insider Thales Trusted Cyber Technologies By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies As digital transformation continues...

The post Security at the Enterprise Edge: Top Five Concerns appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

As digital transformation continues driving change in federal agencies’ operating environments, the need for edge-level data protection has never been greater. Cloud and edge environments are essentially becoming micro data centers, taking on many of the IT core infrastructure characteristics formerly reserved for large HQ facilities. Bolstered by renewed interest in the  Modernizing Government Technology Reform Act, there has been a rise in core-level IT capabilities at the network edge government-wide.

This interest, however, introduces some challenges for extending core-level security to edge environments. For example, solutions for these edge environments may be constrained by specific, size, weight and power demands, and may require more elaborate data protection technology.

When developing an ecosystem to protect data at the edge, it’s important to consider several key principles, namely size constraints, the threat of hostile access, managing cryptographic keys, controlling access, protecting mission-critical data in transit, and complying with regulatory requirements.

Right-sizing edge solutions to defend data access

The government’s size, weight and power (SWaP) requirements for equipment in tactical areas are very specific. That, along with the extreme conditions in the physical environment at the network edge, creates demands on both durability and compactness in edge security solutions.

Add to these demands the need for data security in the event of equipment being taken by  other parties during conflict and you begin to understand the scope and complexity of edge network technological capabilities.

Edge equipment must come with a cryptographic erase solution that protects encrypted data. In fact, the military generally follows NIST policies for the destruction of physical media after a sanitation process. This process typically requires overwriting drives multiple times to ensure data is properly erased.

To simplify this process somewhat, data encryption keys can be erased or destroyed, obviating the need to sanitize the storage drive itself. The data itself remains encrypted and inaccessible, no matter who might control the physical equipment.

These simpler types of protective measures are essential for edge products because users at the edge may not have as much experience with data security measures as their counterparts in headquarters data centers. Default configurations must be secure and easy to understand.

Also, keep in mind that edge systems are also susceptible to connectivity issues. Consequently, such systems must be able to store and secure data locally, sending new or updated data  back to the core or the cloud after the connection is restored. As an added concern, multiple connected units must be configurable at the enterprise level.

The importance of centralized key management

We wrote earlier about the usefulness of data encryption keys in limiting data access. Such keys are particularly important at the edge, where an organization’s IT security teams may need to manage multiple cryptographic keys and a variety of encryption solutions.

Unfortunately, native key management solutions are not typically interoperable. As a result,  system administrators often store cryptographic keys in the same location as encrypted data – which does not follow best practices for key management and  practically invites exploitation.

The answer here is to ensure centralized key management. By doing so, an organization has secure storage and backup of encryption keys. Access control policies are defined. Encryption tasks can be separated from key management tasks. The entire key lifecycle is more properly addressed – from key creation, rotation, backup and destruction. In edge environments, where keys can be susceptible to compromise, this approach is indispensable.

When deciding on appropriate cryptographic products, it’s important to look for solutions with hardware security modules (HSMs) as removable tokens. HSMs act as the root of trust for encryption solutions. These removeable tokens can be ideal in edge environments, because detachable tokens keep essential data safe, even in the most remote or hazardous locations. Without the root of trust, encryption keys remain secure on the edge device and are not accessible without the HSM token.

Control access with multi-factor authentication

With apps, services, and data in the cloud, accessed through devices at the edge, everyone becomes an outsider. That creates a genuine need to establish and enforce identity and access security policy safeguards for assets in the cloud, on-premises, and at the edge.

New threats and risks are heightened as operational requirements change, demanding a simple but scalable solution for authentication. Multi-factor authentication, therefore, is the most secure way to limit access to data and applications, particularly at the edge.

With multi-factor authentication at the edge, organizations can be assured of better access control across multiple environments. This is true no matter which devices are used, and whether data is maintained locally, on-premises, or in the cloud.

Protecting data in transit

The demand on high-speed wide-area networks has been pushed with cloud migration of data, global collaboration, and bandwidth requirements at the edge.

Huge amounts of data are traversing the network and consequently under constant threat. It is essential to encrypt everywhere – both data in motion and at rest.

Data in transit is best protected by network encryptors which allow people, organizations and locations to securely share information. Network encryptors protect data, video, voice, and metadata from eavesdropping, surveillance, and overt and covert interception which is critical at the edge.

Vendor agnostic interoperability is critically important for these solutions, to make it easier on network architecture and IT professionals. Also important is the flexibility to adapt to changing security and network requirements.

Security compliance policies and regulations

Compliance with security requirements is a critical part of minimizing vulnerability at the edge, where susceptibility to attack is considerably greater. To ensure compliance, enterprise-level security policies must be applied across all architecture, including the edge.

Organizations need to look for solutions that carry certifications from multiple organizations, including FIPS 140; the Commercial Solutions for Classified program, and the Committee on National Security Systems Memo #063-2017. The Department of Defense’s Information Network Approved Product List, which had been a repository for such solutions, was sunset in December 2025. Cybersecurity requirements are in the process of transitioning to the DISA RME Vendor Security Technical Implementation Guides (STIG) program.

The challenge of building an IT infrastructure with hardened security that extends to the very edge can seem daunting. By considering these five aspects, it will become significantly easier to develop a system that appropriately controls access and protects data at rest and in transit – from the core to the cloud to the edge.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

 

The post Security at the Enterprise Edge: Top Five Concerns appeared first on Intelligence Community News.

]]>
43755
Understanding Data Security Posture Management: Five Questions to Get You on Your Way https://intelligencecommunitynews.com/ic-insiders-understanding-data-security-posture-management/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-understanding-data-security-posture-management Mon, 03 Nov 2025 15:08:16 +0000 https://intelligencecommunitynews.com/?p=43089 From IC Insider Thales Trusted Cyber Technologies By: Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies Data Security Posture Management...

The post Understanding Data Security Posture Management: Five Questions to Get You on Your Way appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By: Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

Data Security Posture Management (DSPM) is emerging as a better way to get visibility into where your sensitive data is located, who has access to it, how it has been used and how stored data and applications are secured. It’s a shift from perimeter-based defenses to data-centric approaches, and it’s important to understand because, in today’s hybrid multi-cloud environments, and with quantum computing just around the corner, dynamically managing data security postures is essential.

In the article that follows, we’ll take a deeper dive into what DSPM is, and what you need to know to implement this strategy effectively.

DPSM and today’s security challenges

In general, DPSM refers to tools and practices organizations can use to protect sensitive data across their infrastructure. These tools identify vulnerabilities, generate alerts, and provide remediation guidance to address data security risks. When integrated into other security systems, DSPM helps organizations maintain a strong data security posture and meet regulatory requirements.

There are several challenges and risks that have emerged in recent years that make DPSM strategies essential for any organization:

Poor visibility into data security across the information lifecycle. Accurately identifying and classifying data is harder than ever as data now spreads across clouds, data lakes, and on-premises systems. Understanding the location and interaction of structured and unstructured data is, of course, essential. But today, data can be easily moved and shared. When users share data without proper security measures in place, that sensitive information may end up in unknown or external locations, which makes it more vulnerable to data exfiltration attacks.

Credential sprawl. Cloud computing has led to organizations storing sensitive data online. Because of the adoption of cloud services, containers, and DevOps; keys and secrets are now scattered across platforms, repositories, and codebases. This in turn increases the attack surface, and exposes your data to problems arising from mismanaged credentials. In fact, according to the 2024 Verizon Data Breach Investigation Report, 80% of data breaches involved stolen credentials. Securing sensitive credentials and preventing unauthorized access are one direct benefit of implementing a DSPM strategy.

The AI threat to credential security. In a report from Sapios research and Deep Instinct, a significant uptick in attacks over the past year was traced back by survey respondents to bad actors using generative AI. With AI, attacks like phishing are more convincing, scalable, and harder to detect, which increases the risk of credentials being compromised. Multi-factor authentication is not enough to counter this threat; it must be supplemented with behavioral monitoring, such as tracking unusual access times, login locations, and unexpected data downloads. An effective DSPM strategy can help safeguard organizational data across all environments.

Post-Quantum Cryptography risk. As many news reports indicate, it’s only a matter of a decade or less before quantum computing breaks asymmetric algorithms like RSA and ECC, exposing sensitive data. The damage this could cause may not be apparent for years. The 2025 Thales Data Threat Report shows “Harvest now, decrypt later” attacks are the leading interest in post-quantum computing. Cybercriminals are collecting encrypted data today to decrypt when a Cryptographically Relevant Quantum Computer (CRQC) exists. Organizations’ need to prepare now by adopting the National Institute of Standards and Technology (NIST) FIPS post-quantum cryptography standard  algorithms (ML-KEM, ML-DSA and SLH-DSA) and embracing crypto agility.

Difficulty detecting insider threats. Insider threats, including leaks and sabotage, are becoming increasingly sophisticated and challenging to detect. Traditional perimeter security is insufficient to prevent breaches. What’s really required is effective risk management through robust monitoring.

The growing importance of data governance. Global data protection regulations impose severe penalties for non-compliance. US Federal Government guidelines for achieving Zero Trust maturity models by 2026 contain requirements for data governance. This makes it more important than ever to recognize behavioral changes and identify threats before they compromise sensitive data. DSPM as a security strategy can help address emerging vulnerabilities and attack vectors.

To implement a comprehensive and successful DSPM strategy, you will need to have answers to these five questions. Let’s look at each one.

DPSM Question One: Where is my sensitive data?

Many organizations don’t fully understand where their sensitive data is. In the 2025 Thales Data Threat Report, 24% of respondents indicated that they had little or no confidence in identifying where their data is stored. This creates security risks that can create opportunities for attackers – often through hidden vulnerabilities or misconfigured databases you may not even know exist.

To secure sensitive data, you have to know its specific location. That applies to both structured data (from databases and spreadsheets, for example) and unstructured data (like emails, documents, and multimedia files).

Unfortunately, data types are often spread across various storage environments, including on-premises servers and multiple cloud platforms (like AWS, Azure, or Google Cloud). What’s more, data within an organization is often moved, processed, and accessed by various applications and users. This dispersal of sensitive data across locations complicates comprehensive tracking and management without advanced monitoring tools.

Data protection regulations (GDPR,  HIPAA, Zero Trust etc.) require detailed knowledge of where specific types of data are stored. Consequently, it is critical to leverage data discovery and classification to automatically discover all data stores in your data estate – from structured to unstructured – across on-premises, cloud, multi-cloud, and hybrid environments.

Automated discovery and classification is the only way to routinely and consistently discover and classify new or modified data stores.

DPSM Question Two: Who has access to my sensitive data?

Controlling and monitoring who has access to sensitive data is essential for preventing unauthorized use and potential data breaches. Many organizations, however, lack the comprehensive tools required for full visibility and oversight of data access. Without a way to aggregate and analyze access to data across various systems and platforms, it’s hard to know who has access to sensitive information.

Many modern enterprises employ complex and layered access structures, including role-based access control (RBAC), attribute-based access control (ABAC), and other models. These intricate systems make it difficult to understand exactly who has access to what data and under which conditions.

Additionally, in large organizations, different departments or divisions often manage their own IT resources independently. This can lead to inconsistent access controls and policies. Decentralization makes it harder to track data access throughout the organization.

Scanning your data store locations for granted user rights and displaying various details regarding user rights is critical to understanding your data posture by mapping users and privileges to database objects across all databases.

DPSM Question Three: How well are credentials protected?

It’s important to have safeguards over metadata and credentials – such as encryption keys and secrets – that can unlock encrypted data to make it readable and usable. This includes using cryptography that supports protecting data today and tomorrow, because cryptographically relevant quantum computers will only accelerate malicious decryption techniques.

The problem in protecting credentials is that many organizations rely on multiple cloud providers to house data, so that key creation, management, and rotation processes may vary across CSPs. With an ever-increasing number of encryption solutions, it’s difficult to manage policies protection levels – to say nothing of escalating costs.

The best way through this maze is to transition into a centralized encryption key management system. Centralizing keys and secrets management for key life-cycle  generation, storage, rotation, backup, recovery, revocation, and termination effectively delivers separation of duties. This ensures that the same person creating and managing the keys cannot access protected data.

Limiting access to sensitive data to only those who need it for their work can reduce the risk of insider threats and external attacks. And monitoring who has access to data can help in auditing and tracking usage patterns, which can be vital for security and operational efficiency.

DSPM Question Four: How has my sensitive data been used?

Tracking how data is accessed and used over time is vital for security and compliance. This includes understanding the context of data access and modifications, and detecting unusual patterns that could indicate a security threat.

Effective data usage tracking requires advanced monitoring and logging tools that provide detailed and accurate records of all data interactions. Many enterprises lack these tools or do not have them fully integrated across all systems. This can lead to gaps in data usage visibility.

Complicating matters is that enterprises employ on-premises systems, multiple cloud platforms, and a variety of end-user devices. Each of these environments can process and store data differently, which makes it challenging to track exactly how data is accessed and used across the entire organization.

Understanding specifically how data is used makes it easier to detect anomalies, because unusual access patterns or unexpected data modifications can be early indicators of a data breach. Then, by optimizing data access controls, organizations can better match actual business needs and security requirements.

With the digital economy driving exponential data growth, organizations must have data-centric compliance and security solutions to reduce risks of non-compliance and breaches. That includes comprehensive logs of data usage, which are not only crucial for audits, but can be invaluable during forensic investigations after a security incident.

DSPM Question Five: What is the security posture of our data stores?

Assessing the security posture of data stores involves evaluating the effectiveness of implemented security measures, identifying vulnerabilities, and understanding the impact of potential threats. This knowledge can help strengthen defenses, enabling proactive improvements to data security and aiding in the prevention of breaches.

Therefore, it’s important to manage security resources effectively. By knowing where security is weakest, organizations can allocate resources more effectively to where they are most needed.

Regular assessments of your security posture ensure that defenses keep up with evolving threats and changing business practices.

Effective posture management requires the latest regularly updated vulnerability definitions, leveraged through scans to assess resources, search for vulnerabilities and determine risk. By scanning databases with predefined vulnerability tests, organizations can be aware of databases susceptible to the latest threats.

These scans, using CVSS, assign a risk score to the vulnerabilities discovered in your network and data. CVSS is “an open framework for communicating the characteristics and impact of IT vulnerabilities.” It is maintained by NIST as part of the Security Content Automation Protocol (SCAP) framework. Scoring vulnerabilities using CVSS provides an accurate model for measuring the risk inherent in discovered vulnerabilities and prioritizing them for mitigation.

Beyond scanning, it’s also important to employ monitoring across the data management lifecycle. Monitoring delivers real-time information, such as system events, alerts, violations, blocked sources and more. Monitoring events, alerts, and violations is a multi-faceted pursuit. Depending on your specific implementation, there may be several types of users with varying roles and associated security policies. You will need to fine-tune for yourselves how events are interpreted to determine if an alert is a false positive, an attack, or something else.

These are the important things to know about DSPM, and the state of your data, to establish a strategy that will gain you greater visibility into where your sensitive data is located, who has access to it, how it has been used and how stored data and applications are secured.

Quantum computing is becoming more of a reality every day, and multi-cloud environments are only complicating matters further still, so perimeter-based defenses are no longer enough. Dynamically managing your data security postures – ideally from a single platform – is essential to keeping data secure today and into the foreseeable future.

Keeping Your Data Safe with a Single Platform for DPSM

Across all businesses, public sector and private industry, data is an organization’s most valuable resource, driving economies of scale. As more businesses and even federal agencies are adopting AI, more data than ever before will be generated, leading to more data depositories, more data blind spots and more potential to leave data exposed and vulnerable to bad actors.

To protect this data, every security professional knows that they need an effective way to identify sensitive data and to keep it secure for their organization’s own sake and for compliance with local and international cybersecurity guidelines.

This can lead to a complicated and scattershot collection of solutions and tools. There are, however, some vendors that can support your Data Security Posture Management (DPSM) efforts with a single platform to help you understand the state of your data.

To take one example, CipherTrust DSPM automates the discovery and classification of both structured and unstructured data. This platform is applicable across a wide range of data stores, including on-premises, cloud, multicloud, and hybrid-cloud environments.

If you are ready to look for an all-in-one data platform for DPSM, here are the feature and benefits you need to look for from a solution vendor:

Scanning and Identifying Data: Make sure your DSPM platform can systematically scan data environments—whether on-premises or in the cloud—to discover data repositories. This must include databases, big data platforms, cloud storage, and file systems.

Classifying Data: After data repositories are discovered, a DSPM platform must be able to classify data based on its type and sensitivity. This automated classification helps organizations to understand the data they hold, and to prioritize their security accordingly.

Understand User Access: To identify excessive, inappropriate, or unused privileges, an effective DSPM platform must provide user rights management, monitoring data access, and activities of privileged users. It must also give security and IT teams full visibility into how data is accessed, used, and moved around the organization.

A comprehensive data protection strategy is crucial for DSPM. That means establishing a solid foundation for data protection through encryption and effective credential management.

Platforms like CipherTrust DSPM identify sensitive data and protect it with industry-leading technologies. The right platform ensures the security of your credentials and metadata, preventing unauthorized access by users and applications, and reinforcing your overall data security and compliance framework.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Understanding Data Security Posture Management: Five Questions to Get You on Your Way appeared first on Intelligence Community News.

]]>
43089
AI Security Risks and the Coming Quantum Threat https://intelligencecommunitynews.com/ic-insiders-ai-security-risks-and-the-coming-quantum-threat/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-ai-security-risks-and-the-coming-quantum-threat Wed, 09 Jul 2025 13:35:08 +0000 https://intelligencecommunitynews.com/?p=42136 From IC Insider Thales Trusted Cyber Technologies By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies Artificial intelligence (AI) is...

The post AI Security Risks and the Coming Quantum Threat appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

Artificial intelligence (AI) is rapidly transforming our world, from the way we work to the way we interact with machines. As AI becomes more sophisticated, so too do the potential security risks.

Although AI and quantum computing can enable better security, they also threaten security at the same time. These converging technologies independently pose an existential risk to cybersecurity, and both have significant security ramifications.

Let’s look at some of the critical issues at the intersection of AI, quantum and security. In this article, we’ll make sense of the language surrounding quantum computing and AI. We’ll also look at the malicious use of AI, and outline a strategy for guarding AI systems and the coming quantum computing threat.

 Detangling quantum computing

 Security experts typically group quantum computing into four areas:

Quantum computing. Utilizing quantum computers to do complex computations that can’t be achieved by classical computing platform.

 Quantum Key Distribution (QKD). This is a distinct technology from quantum computing. It uses the inherent physics in quantum mechanics to securely distribute cryptographic keys across different endpoints.

Quantum Random Number Generation (QRNG). This refers to leveraging the physics of quantum not for computational efforts, but to generate randomness to derive random numbers through quantum entanglements of measuring how photons react to sensors.

Post-Quantum Cryptography (PQC). This refers to the concerns of how a cryptographically relevant quantum computer might break classic cryptography as we know it today.

All of this language provides context when we consider how AI is creating a higher-risk security environment for organizations.

Malicious uses of AI

There are several ways in which AI can be used maliciously by bad actors:

Deepfakes and Disinformation. Deepfakes involve creating fake audio or video content that convincingly impersonates real individuals. Deepfakes are difficult to detect and stop, which makes them a potent threat.

Disinformation campaigns. Use of deep fake content can discredit public figures by spreading false information, influence public opinion through deceptive content, and extort funds by impersonating someone’s loved ones over video calls.

Social engineering. AI can be used to create persuasive messages that can deceive individuals into revealing sensitive information or taking harmful actions. Cybercriminals leverage social engineering to exploit human psychology, which can lead to unwitting security breaches.

Hacking and cyberattacks. Malicious actors can use AI to automate attacks on computer systems, networks, and critical infrastructure. AI techniques like fuzzing and neural networks can enable the creation of sophisticated computer viruses.

The language of AI security attacks

How can AI security be attacked by rogue actors? There are several typical common means of exploiting vulnerabilities.

Poisoning attacks. During the training phase of an AI implementation, attackers inject malicious data into the training set. These small, nearly imperceptible changes to the model input can lead to wildly different expected output that is incorrect, inconsistent, or erratic.

Transfer attacks. These types of incursions exploit the transferability property of machine learning models, potentially using a successful attack on one AI system against another, similar AI system. Transfer attacks can even target black-box models, where the attacker has no knowledge of the model’s architecture or parameters.

Prompt injection attacks. Here, attackers create input prompts to mislead the model. Such attacks are specifically designed to exploit vulnerabilities and produce harmful responses.

Backdoor attacks on AI models. Malicious actors can insert backdoors during the training of AI large language models. These hidden patterns allow them to trigger specific behaviors in the model when certain conditions are met.

Non-traditional threats to AI models

AI can create a range of cybersecurity threats that cannot be addressed by traditional countermeasures.

Data poisoning. Data poisoning involves adversaries intentionally introducing false or misleading information into the training dataset. This can be achieved through various methods. Inaccurate information or false data can be added to skew model outputs. Existing data can be altered to mislead the model. And in some cases, critical information can be deleted, which can cause the model to function incorrectly.

Backdoor insertion. This refers to a type of attack where an adversary covertly manipulates an AI model during its training phase, embedding a hidden vulnerability known as a “backdoor.” This backdoor allows the attacker to control the model’s behavior under specific conditions, typically triggered by certain inputs. When the AI model encounters this trigger during its operation, it can lead to harmful or unintended outcomes. For example, an AI model used in healthcare could misdiagnose a condition when presented with a specific input.

Backdoor attacks can remain undetected during normal operation, so that the model appears to function correctly for benign inputs. This can make it challenging to identify the compromised behavior until the trigger is activated.

Training data extraction. In this case, specific data points used to train a machine learning model can be retrieved, enabling an attacker to access sensitive or proprietary information that the model was trained on. The implications of training data extraction include potential privacy violations, especially if the training data contains personally identifiable information (PII) or confidential business data.

Membership Inference. These attacks are characterized by an adversary attempting to determine whether a particular data point was included in the training dataset of a machine learning model. This is particularly concerning in scenarios where the training data contains sensitive information.

Adversarial/evasion attack. In adversarial attacks, an adversary deliberately manipulates the input data to mislead the model into making incorrect predictions or classifications. The goal is to cause the model to misclassify the adversarial example while keeping it perceptually similar to the original input. Adversarial examples generated for one model can often be transferred to fool other models, even if they have different architectures or were trained on different datasets.

Model theft. Also known as model extraction, this is a cybersecurity threat where an adversary aims to replicate or duplicate a machine learning model without having direct access to its internal parameters or training data. This is typically accomplished by querying the model through its public interface, such as an API, and analyzing the outputs based on various inputs.

Prompt injection. This type of attack targets machine learning models, particularly large language models (LLMs) that use prompts for instruction-following. In a prompt injection attack, an adversary injects malicious instructions into the prompt, disguising them as legitimate inputs. This allows the attacker to manipulate the model’s behavior, causing it to ignore its original instructions or perform unintended actions.

High-risk vulnerabilities to quantum attacks on cryptography

What would happen when a cryptographically relevant quantum computer can break Public Key Infrastructure (PKI) cryptography? In a word, disaster. All internet-based encryption is done with PKI cryptography.

When bad actors are able to break PKI, it will be much easier to forge signatures and impersonate entities utilizing those credentials. This can put the integrity of any contract that is digitally signed at risk.

It would be difficult if not impossible to trust any updates to systems that aren’t quantum resistant. And the risk doesn’t even have to be immediate. With “harvest now, decrypt later” tactics, an adversary can collect transmitted encrypted data for later decryption, so even the most sensitive long-lived data can be put at risk. That’s why agencies like NSA are pushing CNSA 2.0 requirements at such an accelerated pace, when compared to older transitions of different versions of cryptography.

Securing AI models and data with quantum resistant security

So, how do we protect this AI technology from the coming threat posed by quantum computing?

AI models are broken into three different parts: The inputs to the model, the model itself, and the outputs to the model.

There are unique threats to those models, and it is critical to treat them in kind and make sure you are protecting across to all three of those areas. It is about altering the model to give inaccurate results that will affect decision making, it isn’t like the quantum threat of “harvest now, decrypt later” which is about data theft.

It all comes back to data and the importance of protecting the data. You need to protect the data at rest, in transit and in use. You must ensure that the data you are using to train the model is classified appropriately and protected. The data must be encrypted to ensure that only those with proper access can retrieve the information.

While data is in transit, make sure to monitor all transactions on the network, to detect any malicious actors that might be trying to gain access to any of this data. Also, make sure that the data is encrypted when it is moving across the network.

Do not forget the impact of quantum computing on encryption. You must ensure that your encryption solutions—whether for data at rest or in transit—are crypto-agile meaning that they support both today’s classic algorithms and the PQC algorithms designed to be quantum resistant. This will protect your AI data from quantum attacks.

The cryptographic keys used to encrypt and decrypt data are the keys to the kingdom. If these keys are compromised, malicious actors can decrypt your data. Key management enables central management and protection of cryptographic keys across different use cases. It also provides the ability to backup and archive key material, for on-premise, cloud, and hybrid deployments.  Key management solutions must utilize post quantum cryptography to protect against the quantum threat.

When data is in use, you must have access to behavioral analytics tools. If you are the administrator of the AI model systems, you must understand how that data is being utilized in real-time. You must also leverage strong authentication to ensure that access is properly controlled.

Data discovery and classification allows you to search structured and unstructured repositories for sensitive data and provides tools for understanding your risk level.

Encryption and tokenization can support a large number of use cases (for example, the file system level, the database or column level, application embedded libraries, API gateways, etc.).

Strategy for securing AI systems against the quantum threat

The tools mentioned above are just that – tools. What’s necessary is to develop a strategy for how those tools fall into your overall plans for securing your AI systems.

Here are a range of best practices that form a solid strategy to protect AI against the coming quantum threat.

Protect data within AI systems. Encrypt sensitive data at rest and during transmission.

Use crypto agile solutions that offer both classic and PQC algorithms and offer secure key management practices.

Use access control and authentication. Implement access controls to restrict data access based on roles and permissions. Use authentication mechanisms (for example, OAuth, API keys) to verify user identities.

Minimize data collection. Collect only necessary data for model training and inference. Avoid storing excessive or irrelevant information.

Anonymize and pseudonymize. Anonymize personally identifiable information (PII) to prevent direct identification. Use pseudonyms (fake names) for individuals in datasets.

Use audit trails and logging. Maintain audit logs to track data access, modifications, and system activities. Logs help detect unauthorized access or suspicious behavior.

Secure APIs and endpoints. Protect APIs and endpoints used for data exchange. Use HTTPS and validate input data to prevent injection attacks.

Mask and tokenize data. Make data (credit card data, for example) anonymous, so that hackers don’t know who or what the information is about. Importantly, you must prevent that data from being used when you are training any AI models.

Secure model training and deployment. Protect training data from unauthorized access, and use federated learning to train models without sharing raw data. Ensure that AI models are deployed in a secure environment, and limit access to model APIs and endpoints.

Conduct regular security assessments. Perform penetration testing and vulnerability assessments on a routine basis. This will enable you to identify and address security gaps.

We’re seeing AI technology and systems extending into all aspects of computing, and the rapid approach of cryptographically relevant quantum computing can make these systems susceptible to hacking from bad actors who themselves are using AI to make their dirty work easier.

Create a proactive strategy that safeguards against the malicious use of AI (and eventually quantum computing). In that way, your organization can make the best use of the technology without falling victim to its dangerous downsides.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

The post AI Security Risks and the Coming Quantum Threat appeared first on Intelligence Community News.

]]>
42136
Meeting the Insider Cybersecurity Threat Head-On: A Primer https://intelligencecommunitynews.com/ic-insiders-meeting-the-insider-cybersecurity-threat-head-on-a-primer/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-meeting-the-insider-cybersecurity-threat-head-on-a-primer Mon, 05 May 2025 13:18:33 +0000 https://intelligencecommunitynews.com/?p=41634 From IC Insider Thales Trusted Cyber Technologies By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies One of the main...

The post Meeting the Insider Cybersecurity Threat Head-On: A Primer appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

One of the main cybersecurity challenges on the radar of experts in 2025 is insider threat. Federal IT professionals not only need to be aware of this threat, but to take active measures to minimize its potential damage.

A blog posted to the Cloud Security Alliance by a Microsoft security specialist listed insider threats among the top ten cybersecurity threats to watch out for in 2025. And according to the 2025 Ponemon Cost of Insider Threats Global Report, insider threat risks this year could cost organizations an average of $17.4 million. The cost of incident containment and response has been increasing, even though the average time to contain the threat has actually decreased.

There are a variety of strategies already being promoted to protect against insider threats. As far back as 2021, in a commissioned report from Forrester Research, common strategies include implementing database activity monitoring, improving incident detection, investigation and response capabilities, using AI for threat intelligence and breach investigation, and improving identity and access management tools and policies.

The Cloud Security Alliance blog mentioned earlier also notes that organizations looking for ways to address this threat “should implement strict access controls, conduct regular audits, and foster a culture of security awareness. The blog also states that “Behavioral analytics tools can also help identify unusual activities that may indicate insider threats”.

Of course, there is much more to an insider risk mitigation strategy than can be summed up in two short sentences. In this commentary, we’ll take a closer look at the problem of insider threats to cybersecurity, and provide a deeper dive into ways to minimize the risk from insider threats.

Insider threats defined

Simply put, an insider threat is a security risk that comes from an internal source of the targeted organization. It may involve a current or former employee (or business associate) who misuses access to sensitive information or privileged accounts within the organization’s network.

Unfortunately, traditional security measures focus primarily on external threats; they are not always capable of identifying threats coming from inside the organization.

There are several types of insider threats:

Malicious insider. This is a person who intentionally abuses legitimate credentials – most commonly to steal information for financial or personal gain. As an example, a malicious insider might be a person with a grudge against a former employer, or an opportunistic employee who sells secret information to a competitor. These people may have an advantage over other attackers: They are familiar with the organization’s security policies and procedures, as well as its vulnerabilities.

Careless insider. Typically, this person unknowingly exposes the system to outside threats. Unfortunately, this is the most common type of insider threat. Inadequate cyber hygiene training can result in mistakes, such as leaving a device exposed or becoming the unwitting victim to an email phishing scam. An employee with no intention of harming the organization may click on an insecure link, thereby infecting the system with malware.

A mole. Is an imposter – technically an outsider – who has gained insider access to a privileged network. It may be someone from outside the organization posing as an employee or partner.

While not necessarily the most common across every organization, malicious insiders can cause some of the greatest damage. It is important, therefore, to understand some of the key indicators of such threats.

How can an organization know that it has been exposed to a malicious insider threat? Certainly, it can be indicated by anomalous activity at the network level. Similarly, if an employee seems to be dissatisfied or holds a grudge, that also can be a sign. Unfortunately, even an employee that is enthusiastically taking on additional responsibilities could mean the potential for foul play.

Some threat indications are easier to track than others are, and they fall generally under the category of unusual behavior. For example, activity at unusual times, such as signing in to the network at 3:00 am, should throw up a red flag. Unusual volumes of traffic, or transferring large amounts of data across the network, can also be a cause for concern, as can unusual types of activity such as accessing resources not typically associated with an employee’s responsibilities.

Best practices to minimize insider threat

There are several strategies an organization can employ to reduce the risk of insider threats.

Protect critical assets. By critical assets, we mean systems, technology, facilities, and people. However, a critical asset can also refer to Intellectual property, including customer data for vendors, proprietary software, schematics, and internal manufacturing processes.

It is important to have a comprehensive understanding of what the organization considers a critical asset. What kind of critical assets does the organization have? Can the assets be prioritized? What is the current state of each asset?

Define, document and defend policies. Organizational policies must be clearly defined and documented in order to enforce them and prevent misunderstandings. Every employee in the organization must be familiar with security procedures and should understand their rights in relation to intellectual property (IP). This is cyber hygiene best practice and it ensures that privileged content is not shared improperly.

Increase visibility. Make use of solutions that can track employee actions and correlate information from multiple data sources. Deception technology, for example, might be useful in luring a malicious insider or imposters and gaining visibility into what they are doing.

Make the right kind of culture changes. Once again, this ties back to good cyber hygiene. Security is a combination of knowledge, attitudes and beliefs. To ensure employees are not being negligent, and to address the root causes of malicious behavior, it is essential that all employees are properly educated in security issues – and that they have what they need to improve their overall satisfaction.

Insider threat detection: Machine learning and other solutions

Insider threats can be more difficult to identify or prevent than outside attacks. What’s more, they often can circumvent or avoid traditional security solutions that focus on external threats, like firewalls and intrusion detection systems. If an attacker can get past an authorized login, conventional security measures may not identify any unusual behavior. Malicious insiders also can avoid detection if they are familiar with the organization’s existing security measures.

That means protecting critical assets must rely on more than a single solution. An insider threat detection strategy must be diversified. One way to do that effectively is to combine several tools, so that insider behavior can not only be monitored but also filtered through a large number of alerts to eliminate false positives.

Machine Learning (ML) applications can help analyze data streams and prioritize the most relevant alerts. Digital forensics and analytics tools, like User and Event Behavior Analytics (UEBA), help detect, analyze, and alert a security team to any potential insider threats. User behavior analytics can establish a baseline for normal data access activity, while database activity monitoring can help identify policy violations.

Insider threat risks are not going away, and in fact may become increasingly pervasive and costly in the years to come. Understanding the types of insider threats and taking proactive measures now will be essential in mitigating the consequences of this cybersecurity challenge.

What to Look for in Insider Threat Solutions

User behavior analysis is the basis of protection from insider threats. Unfortunately, that by itself is not enough. The cybersecurity industry has introduced many providers that offer a range of solutions to monitor how users move through the network, as well as protecting assets on a data level. Therefore, no matter what a malicious insider accesses, the organization remains in control.

Data security solutions must be able to protect data on premises, in the cloud and in hybrid environments. These types of solutions also give security and IT teams full visibility into how the data is being accessed, used, and moved around the organization.

Here are some of the features any organization should look for to ensure they have a comprehensive solution with multiple layers of protection:

  • Database firewall: To block SQL injection and other threats, while evaluating for known vulnerabilities.
  • User rights management: To monitor data access and activities of privileged users, identifying excessive, inappropriate, and unused privileges.
  • Data masking and encryption: To make sensitive data useless to bad actors, even if they are somehow able to access it.
  • Data loss prevention (DLP): To inspect data in motion, at rest on servers, in cloud storage, or on endpoint devices.
  • User behavior analytics: To set baselines for data access behavior, employing machine learning to detect and alert on abnormal and potentially risky activity.
  • Data discovery and data classification: To reveal the location, volume, and context of data on-premises and in the cloud.
  • Database activity monitoring: To monitor relational databases, data warehouses, big data and mainframes, generating real-time alerts on policy violations.
  • Alert prioritization: To look across all security events and prioritize the most significant ones. AI and machine learning technology are particularly helpful in this case.

 

Make sure your solution provider offers these types of features, and be prepared before the next insider threat comes calling.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

The post Meeting the Insider Cybersecurity Threat Head-On: A Primer appeared first on Intelligence Community News.

]]>
41634
Tiami Networks and Thales Defense and Security to partner https://intelligencecommunitynews.com/tiami-networks-and-thales-defense-and-security-to-partner/?utm_source=rss&utm_medium=rss&utm_campaign=tiami-networks-and-thales-defense-and-security-to-partner Tue, 22 Apr 2025 13:06:30 +0000 https://intelligencecommunitynews.com/?p=41525 On April 17, Tiami Networks and Thales Defense & Security, Inc. (TDSI) announced the signing of a Memorandum of Understanding...

The post Tiami Networks and Thales Defense and Security to partner appeared first on Intelligence Community News.

]]>
On April 17, Tiami Networks and Thales Defense & Security, Inc. (TDSI) announced the signing of a Memorandum of Understanding (MoU) to commence a strategic partnership. This collaboration marks a major step forward in the future of 5G-integrated sensing and defense technology.

By combining Tiami’s PolyEdge Multifunction Sensor software, which uses AI to passively sense and interpret the wireless environment, with TDSI’s deep expertise in tactical networking, radar, and mission-critical defense systems, the two companies aim to co-develop next-generation situational awareness capabilities. These joint solutions will target a range of applications across U.S. Department of Defense programs, government operations, and commercial markets where secure, real-time sensing and decision-making are paramount.

“This partnership with TDSI represents a powerful alignment of our advanced sensing capabilities with their world-class defense systems,” said Amitav Mukherjee, CEO of Tiami Networks. “Together, we’re shaping the future of multi-domain awareness by fusing FutureG RF sensing with robust, field-proven communications technologies.”

Through this relationship, the companies will explore integration pathways between Tiami’s edge-AI and 5G/Wi-Fi-based sensing platform and Thales’ secure tactical communications architecture. Potential use cases include force protection, perimeter security, airspace awareness, and urban surveillance – all leveraging ambient wireless signals for reduced signature and jamming-resistant sensing.

“TDSI is excited to work alongside Tiami Networks to explore and operationalize multifunction sensing capability that complements today’s defense systems,” stated Paul Mehney, vice president of strategy, Thales Defense adn Security, Inc. “Partnerships with tech firms such as Tiami Networks allows for rapid and agile innovation in the defense sector.”

Source: Tiami Networks

If you enjoyed this article, please consider becoming a paid subscriber. Your support helps keep our site ad-free.

The post Tiami Networks and Thales Defense and Security to partner appeared first on Intelligence Community News.

]]>
41525
Protecting Data in Large Language Models: How to Get Started https://intelligencecommunitynews.com/ic-insiders-protecting-data-in-large-language-models-how-to-get-started/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-protecting-data-in-large-language-models-how-to-get-started Mon, 03 Feb 2025 15:18:51 +0000 https://intelligencecommunitynews.com/?p=40877 From IC Insider Thales Trusted Cyber Technologies By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies As artificial intelligence and...

The post Protecting Data in Large Language Models: How to Get Started appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

As artificial intelligence and machine learning continue to extend into all aspects of the enterprise, there is a growing need to protect sensitive private data in Large Language Models (LLMs). This is true not only for data at rest and in transit, but also during computational execution.

The primary emphasis in protecting LLMs is the backend framework, which stores all data queried by users to the LLM, along with user credentials, logs, metadata, and more. Any prompt or  response that is used and stored can contain sensitive data that requires protection.

To understand how LLM data protection works in two separate but closely related use cases, we should begin by breaking down the components of a typical LLM framework.

Understanding LLM Frameworks, RAG and RAGDB

A key component in using any LLM is its LLM framework or runtime. An LLM framework is a platform or tool focused on simplifying the deployment and use of LLMs. The goal is to provide a user-friendly interface and infrastructure for the integration of advanced AI capabilities into various applications.

Key features to look for in an LLM framework typically include ease of use, scalability and integration. The framework should simplify the interaction with LLMs through intuitive interfaces or APIs. It should also ensure that the platform can handle large-scale deployments and heavy computational load while supporting a range of models and customization options for different use cases. And it should do all this with seamless integration to existing tools and workflows, which will  enhance productivity and efficiency.

Two main aspects of LLMs are Retrieval-Augmented Generation (RAG) and the RAG Database (RAGDB).

Retrieval-augmented generation (RAG) is an AI technique combining information retrieval systems with large language models (LLMs). RAG improves the accuracy and relevance of LLM output by providing access to authoritative knowledge bases.

This approach works by retrieving data relevant to a user’s query, then providing the retrieved data as context for the LLM, which uses the data to generate a response.

There are numerous benefits to this approach in terms of accuracy, relevance, cost-effectiveness and control. RAG provides access to the most current and reliable facts, which are most relevant to a user’s query. This translates to cost-effectiveness because RAG improves LLM output without retraining the model, while giving users control over the data from which responses are generated.

RAGDB (Retrieval-Augmented Generation with Databases) is an extension of the RAG framework, integrating structured databases into the retrieval-augmented generation process. This approach improves the production of accurate and contextually relevant text by utilizing structured and often more precise information from databases.

RAGDB employs structured retrieval – that is, in addition to unstructured text, RAGDB retrieves data from structured databases. This involves querying relational databases, knowledge graphs, or other structured data sources to find specific information.

Figure 1, below, depicts a typical architecture for custom-built LLMs:

Here, the RAGDB (with the files) is an optional component, depending how the RAG capabilities are being used. The knowledge base, in the form of files and documents, is retrieved by the RAGDB.

The web framework – specifically the backend of the web framework – refers to the software structure and tools for developing the interface and logic that users interact with. These are open platforms or libraries for operating large language models (LLMs) in production.

A web framework usually handles communication between all the components. Depending on the specific framework, the backend framework (within the web framework) might also function as a separate, independent component dedicated solely to interacting with all other components, including the web framework itself.

The LLM runtime will also communicate via its APIs with the backend framework. The user will interact with the front-end framework where the UI will display the conversation (between the user and the LLMs).

Security Considerations

Ensuring data safety in LLM use cases with RAGDB requires careful security considerations. While RAG enhances query understanding and information retrieval, it also poses challenges for maintaining data privacy and security. Enhanced querying runs the risks of exposing sensitive data if it is not properly secured. Better information retrieval capabilities demand robust access controls and encryption to prevent unintended data access.

By addressing these risks and implementing the proposed solution, organizations can effectively fortify their data protection strategies and mitigate the risks associated with LLM use cases, thereby ensuring the confidentiality and integrity of sensitive information.

As noted at the outset of this commentary, securing data in LLMs has two use cases: Data protection at rest and in transit, and data protection at rest, in transit and in execution. Here are key factors to consider for each.

Data protection at rest and in transit: The need for data-centric security platforms

Data protection at rest and in transit requires a data-centric security platform to reduce risk across your organization and to decrease the number of resources required to maintain strong data security. A security platform like that described here integrates centralized data security and management core functions, such as key management, data discovery and classification, data protection and granular access controls.

By centralizing and simplifying data security, this type of platform provides efficient, integrated and fast data protection, centrally managed by the customer. This helps accelerate the time to compliance and safe cloud migrations of sensitive data.

IT teams generally favor data-centric solutions that secure data moving from networks to applications and the cloud. When perimeter network controls and endpoint security measures fail, data-centric solutions enable organizations to remain compliant with evolving privacy regulations and the demand to support a tremendous number of remote employees. Such platforms can be deployed on premises, in cloud or hybrid environments.

A data-centric security platform requires a central management component to simplify key lifecycle management tasks for all encryption keys. This should include management of secure key generation, backup/restore, clustering, deactivation, deletion, and access to partner integrations that support a variety of use cases (data discovery, data-at-rest encryption, enterprise key management, cloud key management, etc.).

Such central management should support access control to keys and policies, robust auditing, and reporting, in both physical and virtual form factors.

Protection of data at rest, in transit, and during execution: The need for end-to-end protection

Protection of data at rest, in transit and in use is a cloud infrastructure issue requiring end-to-end data security. This type of protection scenario should be centrally managed across a variety of cloud service providers.

As a concept, end-to-end protection is based on the principle of separation of duties. The customer remains in control of their own data protection for cloud deployments, and defines the profile of the cloud hardware/software stack where workloads will be computed. This approach enhances trust in cloud deployments by holding each stakeholder responsible for their respective roles and reduces the ability for a malicious actor to access code and data at rest, in transit and while being executed.

With this approach, customers can migrate existing workloads with sensitive data or create new workloads needing zero trust, confidential computing, and confidential AI to broaden data security, attestation and set the right authorizations.

With end-to-end data protection, multiple parties can securely collaborate on various use cases, such as Confidential AI datasets and models as needed while preserving privacy, confidentiality, and compliance with privacy regulations.

Protecting data at rest, in transit and in use also extends to the concepts of Confidential Virtual Machines (CVMs), third party attestation Service, and root of trust during CPU and GPU Inference.

CVMs are designed to ensure the confidentiality and integrity of data and applications while they are in use. This is particularly important in cloud computing environments where multiple tenants might share the same physical hardware.

Traditionally, data has been protected at rest and in transit, but with confidential computing technologies, this protection is extended to data in use. Confidential VMs use hardware-based encryption to protect the data in memory. Even if an attacker gains access to the physical server, they cannot read the data stored in the VM’s memory.

CVMs also ensure that the code running in the VM has not been tampered with, by verifying the integrity of the software stack, including the operating system and applications. By ensuring data confidentiality and integrity, CVMs help organizations comply with regulatory requirements for data protection.

It’s important to know the difference in the root of trust for a CPU and a GPU when used in an end-to-end solution, because there are particular hardware dependencies in each case. For example, if CPUs are used for the LLM inference, then the CPU inference runs within the confidential VM and thus it is within the root of trust a hardware-based trusted execution environment.  If GPUs are used for the LLM inference, then the GPU inference runs within the runtime memory of the GPU, which is not part of that chain of trust, and requires its own attestation and verification.

Conclusion

In today’s data-driven landscape, safeguarding sensitive information in LLM use cases is vitally important.

Whether your organization is leveraging the advanced capabilities of Retrieval-Augmented Generation (RAG) or not, in addition to state-of-the-art data protection, you need a robust data-centric solution framework to protect private data in different scenarios as needed by the use case.

The threat posed to data privacy and security in LLMs demands enhanced protection for query understanding, information retrieval, and contextual responses. By implementing stringent data protection strategies, such as robust access controls and transparent encryption, organizations can mitigate the risks associated with LLM use cases.

Ultimately, end-to-end data protection may be the best solution for data protection at rest, in transit and during execution, guaranteeing the confidentiality and integrity of sensitive information. This will strengthen an organization’s data protection strategies in our current era of exponential data growth.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

The post Protecting Data in Large Language Models: How to Get Started appeared first on Intelligence Community News.

]]>
40877
NIST’s Quantum Standards: The Time for Upgrades Is NOW https://intelligencecommunitynews.com/ic-insiders-nists-quantum-standards-the-time-for-upgrades-is-now/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-nists-quantum-standards-the-time-for-upgrades-is-now Mon, 04 Nov 2024 13:08:07 +0000 https://intelligencecommunitynews.com/?p=40157 From IC Insider Thales Trusted Cyber Technologies By Bill Becker, CTO, Thales Trusted Cyber Technologies After years of research, development,...

The post NIST’s Quantum Standards: The Time for Upgrades Is NOW appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Bill Becker, CTO, Thales Trusted Cyber Technologies

After years of research, development, testing, and collaboration, in August NIST released its first set of Post Quantum Cryptography (PQC) standards. Now’s the time for federal agencies – and vendors supplying equipment to the public sector – to start planning IT infrastructure upgrades that make use of these PQC standards in their crypto-agile firmware or software.

For  vendors and suppliers, NIST’s announcement means that technology providers, standards organizations, and industry groups have to get to work fixing whatever issues may have been standing in the way of large-scale releases and deployment of interoperable PQC implementations.

It’s simple. You can’t wait until the hackers have quantum tools before you start working on a plan to protect against them. Agencies and industry alike need to start now to transition to the new world of post-quantum cryptography.

A quick overview on the new NIST standards

There are two important encryption functions at the heart of NIST’s new PQC standards:

  • General encryption. This function protects information across a public network
  • Digital signatures. This applies in particular to identity authentication.

 

For a bit of history, after a 6 year competition to select the next generation of quantum-resistant cryptographic algorithms, in 2022 NIST selected four algorithms from the original 69 eligible algorithms submitted. Then in 2023, NIST announced draft standards for three of the four selected algorithms:  CRYSTALS Kyber, CRYSTALS Dilithium, and SPHINCS+. The fourth draft standard, based on FALCON, is planned for late 2024. More recently, in August 2024, NIST released the first three finalized post-quantum Federal Information Processing Standards (FIPS) encryption standards: FIPS 203, FIPS 204, and FIPS 205.

Here’s a flyover look at each of the standards:

  • FIPS 203. This standard is based on CRYSTALS-Kyber algorithm. The new name is the somewhat awkward but more specifically descriptive Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM). Intended to be the main general encryption standard, ML-KEM has the benefit of faster operation. It also has smaller encryption keys that can be exchanged relatively easily between two parties.
  • FIPS 204. This standard is based on the CRYSTALS-Dilithium algorithm, and is now known as Module-Lattice-Based Digital Signature Algorithm (ML-DSA). This standard is intended to be the primary standard for protecting digital signatures.
  • FIPS 205, which is also intended for digital signatures, makes use of the SPHINCS+ algorithm. In this iteration, it is known as Stateless Hash-Based Digital Signature Algorithm (SLH-DSA). Based on a different mathematical approach than ML-DSA, this standard is supposed to be used as a backup method in case any vulnerabilities are exposed in ML-DSA.

 

And the name changes are going to keep coming. When the FIPS 206 standard (which is built around the FALCON algorithm) is released, the new name for the algorithm will be “FFT (fast-Fourier transform) over NTRU-Lattice-Based Digital Signature Algorithm” or FN-DSA. That’s a mouthful, we know, but NIST wins back points for accuracy.

Continuing their mission to offer a robust suite of post-quantum encryption standards, in September 2022 NIST launched an Additional Digital Signatures project which called for additional general purpose signature schemes. In October 2024 NIST announced they have selected 14 candidates to advance to the second round of the Additional Digital Signature process.

Evaluating and implementing PQC migration

The NIST National Cybersecurity Center of Excellence (NCCoE) has been working with industry collaborators and other federal agencies to make it easier to understand the challenges associated with the migration to PQC. So far, the project has drafted guidance for crypto discovery, interoperability, and performance testing.

Now, in practical terms, the onus for change is actually on the vendor and supplier community. If they haven’t already done so, vendors have to start implementing crypto-agility across their product lines. That means putting serious effort into implementing product architectures that can accept in-field firmware updates that introduce the new NIST PQC algorithms and corresponding protocols in all of their products.

This is particularly true for providers of Hardware Security Modules (HSMs) which are often used as the root of trust for our cryptographic systems. Some vendors implemented PQC before the PQC FIPS standards were released to provide agencies a preview of how a PQC enabled system will operate within an existing FIPS 140 certified cryptographic module.   This helped agencies conduct initial testing and makes for a relatively quick and easy transition to quantum-safe encryption solutions when PQC standards compliant firmware upgrades are made available.

Late in 2023 in a publication focused on the public sector vendor community, we said the race was on to “quantum-proof” encryption in the federal sector. Government has not been stingy with reminders, guidance and compliance milestones to agencies – everything from the May 2022 White House National Security Memo on Quantum, to the Office of Management and Budget’s OMB M-23-02 roadmap for agency post quantum cryptography migration. And most recently OMB M-24-14 instructed agencies to “Prepare for the Post-Quantum Future” by ensuring that they are sufficiently resourced transition to post-quantum cryptography.

As was described in the previous policies, the first step on the road to PQC migration starts with crypto discovery. Agencies should start using automated crypto inventory tools to know specifically where and how cryptography is being used in their organizations.

With NIST’s published standards, there’s really nothing more standing in the way of planning for this migration. Quantum computing is farther along than we may realize, and we have to start safeguarding our networks and our data against cybersecurity threats from bad actors. Because make no mistake: They will certainly use the quantum technology to their own bad ends.

Three steps to post-quantum strategy

With this background, and the understanding of the very real threats that can be posed by  hackers armed with post-quantum technology, it is absolutely essential to develop a strategy for cryptography in a post-quantum world. Fortunately, you can get started by remembering three simple steps:

  1. Know Your Risks. Harvesting and early attacks are a real threat to long-term data. IT managers and other network professionals need to understand how their organizations use possibly vulnerable cryptography, the expiration date of their encrypted data, and the crypto-agility maturity of their IT infrastructure. The best way to do this is to inventory cryptographic technologies and prioritize high risk systems. There are tools available that can automate crypto discovery and inventory.
  2. Focus on crypto-agility. Crypto-agility is not only about the quantum threat; it’s about being able to face the reality that all algorithms will absolutely fail over time. Many systems today make it difficult to rotate keys, to choose different sizes/parameters, and to change mechanisms or key algorithms. These are all required for protocols to be versioned, negotiated and not to fail when presented with unknown options. They are essential for crypto-agility, and it’s important to work with providers with solutions that embrace those needs.
  3. Start Today. In fact, if you don’t start today, you’ll be racing to meet the threat tomorrow. Organizations have to begin designing a quantum-resistant architecture today, if they hope to protect themselves against the emerging quantum threat. IT infrastructure equipment is often deployed for years or decades without hardware replacement. Consequently, in the post-quantum world, it’s important to make sure currently deployed hardware was developed with crypto-agility principles in mind, and to receive software or firmware updates now that post-quantum crypto algorithms and protocols are being standardized. It is also important to check with equipment providers to see what beta or technology preview firmware they have available for testing in non-production systems that implements pre-standardized quantum-resistant cryptographic algorithms. Setting up a PQC test environment is a good idea. This will enable organizations to start testing new technology without impacting production environments.

Let’s not sugar-coat things. Quantum computers will break today’s public key cryptography. So, now what?

Even though large-scale quantum computing is several years away from being a practical reality, federal government observers and experts are already worried about the cybersecurity implications. The sooner an organization can start working toward quantum cybersecurity, the better it can handle incoming threats from when bad actors with quantum hacking in their bag of dirty tricks.

One company’s role in the PQC transition

Thales Trusted Cyber Technologies (TCT) has been actively involved in industry and government’s PQC transition from the earliest days of standard-setting.

Since 2021, Thales TCT’s Luna T-Series Network and PCIe hardware security modules (HSMs) FIPS 140 certification has included the onboard, user-configurable quantum entropy source. Thales TCT also participated as one of the earliest members of NIST’s National Cybersecurity Center of Excellence’s “Migration to Post-Quantum Cryptography Project.” In that capacity, the company contributed the T-Series HSM and associated interoperability testing to ensure that PQC implementations could be supported across the industry.

Thales is also a member of the Post-Quantum Cryptography Alliance, the steward organization for the development and maintenance of open-source PQC libraries. Perhaps most importantly, Thales TCT and the National Security Agency (NSA) have signed a Cooperative Research and Development Agreement (CRADA) for evaluating the NIST-selected PQC algorithms when operating on an HSM.

The CRADA results will be used by Thales TCT to accelerate PQC algorithm deployment, and to assist the government and other HSM users in getting a handle on the value of using PQC-enabled HSMs to mitigate the quantum threat. Thales is also a contributing member of the OASIS PCKS#11 Technical Committee, which is instrumental in defining interoperable specifications for cryptographic modules.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

The post NIST’s Quantum Standards: The Time for Upgrades Is NOW appeared first on Intelligence Community News.

]]>
40157
Artificial Intelligence at the Crossroads: The Need for Security https://intelligencecommunitynews.com/ic-insiders-artificial-intelligence-at-the-crossroads-the-need-for-security/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-artificial-intelligence-at-the-crossroads-the-need-for-security Mon, 08 Jul 2024 14:19:31 +0000 https://intelligencecommunitynews.com/?p=39170 From IC Insider Thales Trusted Cyber Technologies By Bill Becker, CTO, Thales Trusted Cyber Technologies The rapid acceptance of artificial intelligence...

The post Artificial Intelligence at the Crossroads: The Need for Security appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Bill Becker, CTO, Thales Trusted Cyber Technologies

The rapid acceptance of artificial intelligence (AI) across a range of applications in both the public and private sectors carries with it the promise of unprecedented speed and operational efficiency. That same speed of adoption, however, begs the question of whether today’s AI has incorporated adequate security.

There is substance behind that question – which is why in 2023 the industry analyst group Gartner placed a number of AI technologies in its Hype Cycle report, with generative AI at the top of its Peak of Inflated Expectations.

This dubious distinction should not be surprising to any of us. You can’t read or watch the news without the topic of AI coming up as one of the greatest innovations for human achievement in modern memory. And yet, for the very reason that AI has the potential to do great things, it is also one of the most significant potential causes for harm if used for malicious purposes. We must be clear that with the advent of AI, demands on security have never been greater than they are at this moment.

It is the potential threat to security posed by AI that prompted the Senate Cybersecurity Caucus this past May to introduce the Secure Artificial Intelligence Act of 2024. The legislation is intended to “improve information sharing between the federal government and private companies by updating cybersecurity reporting systems to better incorporate AI systems.” Additionally, the Act would create a “voluntary database to record AI-related cybersecurity incidents including so-called ‘near miss’ events.”

To fully prepare for the transformational possibilities of AI, we must enter into this new age with our eyes wide open, understanding that there are security considerations to address when implementing AI. These considerations fall broadly into three categories:

  • Security of AI – How secure AI is from interference from bad actors,
  • Security for AI – Essential practices to address AI’s security concerns, and
  • Security from AI – Positive contributions to cybersecurity that come from or are enhanced by AI.

 

In this article, we’ll take a clear-eyed look at each of these aspects of AI security. Before we do that, however, let’s understand the potential malicious uses of AI.

Malicious Use of AI

As with practically every technological innovation before it, AI can be used – and in fact is being used – by bad actors with malicious intent such as criminals, terrorists, and hostile nation-states.

These bad actors deploy a surprisingly wide range of tactics made easier through AI to disrupt operations in both public and private sector. To name just a few current and potential abuses of this technology:

Deepfakes and Disinformation. For the uninitiated, deepfakes involve creating fake audio or video content that convincingly impersonates real individuals. This manipulated media can then be used to discredit public figures by spreading false information, or to influence public opinion through deceptive content.

In many instances, they can be used to extort funds by impersonating someone’s loved ones over video calls. Deepfakes by their very nature can be hard to detect and stop, making them among the most serious potential threats.

Misuse of Military Robots. Adversaries could exploit AI-powered military robots for malicious purposes. These robots might be reprogrammed to cause harm or disrupt security systems.

Autonomous Weapon Systems. Rogue states or non-state actors might deploy AI-enhanced lethal drones or other autonomous weapons. These systems could potentially be operated without human intervention, posing a grave threat to global security.

Social Engineering. AI can be used to craft persuasive messages that deceive individuals into revealing sensitive information or taking harmful actions. Cybercriminals already leverage social engineering to exploit human psychology; the added capabilities unlocked by AI make this type of malicious activity particularly concerning.

Hacking and Cyberattacks. Malicious actors can use AI to automate attacks on computer systems, networks, and critical infrastructure. Techniques like fuzzing and neural networks enable the creation of sophisticated computer viruses.

Membership Inference Attacks. AI models can be reverse-engineered to infer membership in specific datasets. Attackers could exploit this capability to reveal sensitive information about individuals.

Security of AI: Common Attack Vectors

The other side of the coin of malicious uses of AI described above is the equally troubling potential that a user’s own AI implementations can be manipulated or subverted in adversarial attacks. There is a significant challenge to preventing machine learning models from being deceived and having their vulnerabilities exploited without the knowledge of network administrators.

Some common adversarial attack techniques include the following:

Poisoning Attacks. In the testing or deployment phase of machine learning, models are susceptible to evasion attacks. Attackers may inject malicious data into the training set, with small, imperceptible perturbations added to the input. This manipulation of input data may deceive the model into misclassifying data and producing incorrect output. The model learns incorrect patterns and may therefore potentially make wrong decisions.

Transfer Attacks. These attacks exploit the transferability property of machine learning models. An adversarial example crafted for one model can also fool other models with similar architectures. Transfer attacks can even target black-box models, where the attacker has no knowledge of the model’s architecture or parameters.

Prompt Injection Attacks. In this example, attackers craft input prompts to mislead the model. These prompts are specifically designed to exploit vulnerabilities and produce harmful responses.

Backdoor Attacks on AI Models. Malicious actors in this instance insert backdoors during training. These hidden patterns allow them to trigger specific behaviors in the model when certain conditions are met.

We’ve seen some of the inherent potential security problems of AI. In the next section, let’s take a slightly deeper dive into best practices to address security for AI.

Security for AI: What to Do

Whether it is personal identity information, corporate intellectual property, or even computer network information, there is a vast amount of sensitive data utilized by AI systems that needs to be protected before, during, and after use. Uses of that data can include training of large language models, input data, or the output of an AI solution, among others.

It’s absolutely essential to protect data in AI systems to maintain privacy, security, and ethical standards. Here are some essential practices:

Access Control and Authentication. Implement access controls to restrict data access based on roles and permissions. Use authentication mechanisms (for example, OAuth or API keys) to verify user identities.

Anonymization and Pseudonymization. Anonymize personally identifiable information (PII) to prevent direct identification. Use pseudonyms (fake names) for individuals in datasets.

Audit Trails and Logging. Maintain audit logs to track data access, modifications, and system activities. Logs help detect unauthorized access or suspicious behavior.

Data Encryption. Encrypt sensitive data at rest and during transmission.

Use strong encryption algorithms and secure key management practices.

Data Minimization. Collect only necessary data for model training and inference.

Avoid storing excessive or irrelevant information.

Data Masking and Tokenization. Mask sensitive data such as credit card or Social Security numbers with placeholders. Use tokens to represent sensitive information.

Regular Security Assessments. Conduct penetration testing and vulnerability assessments. Identify and address security gaps.

Secure APIs and Endpoints. Protect APIs and endpoints used for data exchange.

Use HTTPS and validate input data to prevent injection attacks.

Secure Model Deployment. Ensure that AI models are deployed in a secure environment. Limit access to model APIs and endpoints.

Secure Model Training. Protect training data from unauthorized access. Use federated learning to train models without sharing raw data.

Security from AI – How AI Helps Security

So far, we’ve spent a lot of time discussing the threats and potential harm related to AI, now let’s consider the good side of AI. How is AI being used to enhance cybersecurity? Here are ten examples of how AI is being used in the field of cybersecurity:

Intrusion Detection and Prevention. AI can identify unusual activity on a network and alert security personnel to potential threats. It helps detect unauthorized access attempts or suspicious behavior.

Cyber Threat Intelligence. AI analyzes data from various sources, including social media and the dark web, to identify emerging threats. It provides valuable intelligence to businesses, helping them stay ahead of cybercriminals.

Phishing Protection. AI analyzes emails and detects patterns indicative of phishing attempts. By identifying malicious links or suspicious content, it helps prevent successful phishing attacks.

Vulnerability Management. AI scans software and systems to identify vulnerabilities. It prioritizes which vulnerabilities need immediate attention based on their potential impact, allowing organizations to focus on critical issues.

Network Security. AI monitors network traffic and identifies unusual patterns that may indicate an attack, such as denial-of-service (DoS) attacks or unauthorized access attempts.

Password Security. AI helps users choose stronger passwords by identifying weak ones. Strengthening password security reduces the risk of unauthorized access.

User Behavior Analytics. AI monitors user behavior and identifies patterns that may indicate security risks. For example, it can detect unusual login locations or abnormal data access.

Threat Detection and Prevention. AI algorithms continuously analyze data to detect potential threats. Whether it’s malware, ransomware, or other malicious activities, AI helps prevent security breaches.

Vulnerability Assessment. AI assesses the security posture of systems, applications, and networks. It identifies vulnerabilities and recommends remediation steps.

Password Management. AI assists in managing passwords securely. It can suggest password changes, enforce password policies, and detect compromised credentials.

All of these examples demonstrate how AI enhances cybersecurity by automating tasks, improving threat detection, and enhancing overall security posture.

The introduction of artificial intelligence and machine learning touches nearly every aspect of our everyday IT experience – from enhanced user interaction to operational speeds that are orders of magnitude beyond our current capabilities. The significance of these advancements is comparable to creation of computer networking itself.

To go confidently into these new, virtually uncharted areas, we must temper our enthusiasm for AI with an awareness of what bad actors are planning or actually doing now to use this technology to their own nefarious ends. The need for incorporating comprehensive security measures with AI, including securing data in motion and at rest, has never been greater.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

 

The post Artificial Intelligence at the Crossroads: The Need for Security appeared first on Intelligence Community News.

]]>
39170
Web Application Firewalls: The Top 10 Security Challenges and How to Meet Them https://intelligencecommunitynews.com/ic-insiders-web-application-firewalls-the-top-10-security-challenges-and-how-to-meet-them/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-web-application-firewalls-the-top-10-security-challenges-and-how-to-meet-them Mon, 06 May 2024 13:51:15 +0000 https://intelligencecommunitynews.com/?p=38612 From IC Insider Thales Trusted Cyber Technologies By Bill Becker, CTO, Thales Trusted Cyber Technologies Web applications are the entry point...

The post Web Application Firewalls: The Top 10 Security Challenges and How to Meet Them appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Bill Becker, CTO, Thales Trusted Cyber Technologies

Web applications are the entry point to an organization’s data, which makes them a prime target for hackers. From attacks that have shut down corporate and government sites, to Distributed Denial of Service (DDoS) in the financial markets, to web breaches that leak consumer and corporate data, cybersecurity incursions are almost constantly in the news. That doesn’t even include the unreported breaches and small-scale online fraud. Unfortunately a hacker’s arsenal of tools – technical web attacks, business logic attacks, and fraud – are generally unprotected by traditional network security systems.

Hacker forums show that favorite methods of cybercrime include tactics like SQL injection and cross-site scripting (XSS). In a report from the Ponemon Institute, nearly two-thirds of organizations experienced one or more SQL injection attacks that evaded their firewall over a single year, with detection requiring an average of nearly 140 days.

And, hackers aren’t stopping at traditional web attacks. Business logic (custom rules or algorithms governing how a user interface operates and interacts with a database) attacks and fraud are also becoming increasingly popular techniques. Hackers exploit business logic flaws to scrape websites for intellectual property, and perform repeated brute force attacks or use wildcards in search fields to shut down applications. Typical application scanners can’t detect business logic flaws and secure development processes may not mitigate them.

Web application firewalls, therefore, can be an organization’s first line of defense to protect applications against threats like technical web attacks, business logic attacks, and online fraud. Unlike traditional network security solutions, web application firewalls understand web usage and validate input to stop dangerous attacks like SQL injection, XSS, and directory traversal. They block scanners and virtually patch vulnerabilities. And they rapidly evolve to prevent new attacks and keep critical applications safe.

Unfortunately, not all firewalls are created equal. Organizations must carefully evaluate the security, management, and deployment capabilities of these firewall products, to minimize threats from back actors.

Let’s look at the top 10 challenges addressed by web application firewall and the features any such solution should provide to mitigate those challenges.

Understanding web applications

Advanced, custom web attacks are on the rise among organizations of all sizes and complexity. With JavaScript and SQL, hackers can create almost unlimited SQL injection and XSS attacks. While signatures can help detect web attacks, they must either be written broadly (resulting in false positives) or they must define the exact syntax of the attack (resulting in false negatives). Hackers can use encoding, comments, and obfuscation to outwit traditional security solutions.

To stop attacks, a web application firewall must understand the protected application, including URLs, parameters, and cookies. Understanding the protected application and validating input helps stop attacks like SQL injection, parameter tampering, and cookie poisoning.

Since organizations frequently update applications, a web application firewall also needs to automatically learn application changes without manual intervention. This makes it easier to manage a web application firewall while providing the highest levels of protection.

Staying ahead of hackers

Hackers are constantly creating new attack tools, developing new ways to recruit volunteers, or honing existing techniques. What’s more, fraud malware developers have architected self-mutating files to evade virus signature detection. Keeping up with the latest application threats—including vulnerability exploits, malicious users, and fraud schemes—is an enormous challenge for application security solutions.

Consequently, a web application firewall must have up-to-date protection. It should leverage live attack, reputation, and fraud data from around the world to identify both attacks and attackers. Security signatures, policies, reputation data, and fraud intelligence should be updated automatically without human intervention.

It is also important to look at the research organization that is producing security content. Is it focused on web application security? Is it equipped to defeat the latest application attacks? If not, it’s time to consider another solution.

Thwarting evasion techniques

Organizations need to block web attacks without blocking legitimate traffic. How do you tell the difference between a cybercriminal and a web user that accidentally submitted special characters in a form field? The answer is through advanced analytics and correlation.

A web application firewall must include an analytics engine that can examine multiple attack indicators to block attacks without false positives. This analytics engine must be able to evaluate factors such as attack keywords, special characters, protocol violations, and known attack strings simultaneously. It should identify violations and then perform additional analysis using risk scoring and regular expressions to differentiate between malicious requests and unusual, but harmless traffic.

The firewall also must correlate requests over time to detect repetitive attacks, such as brute force login or Distributed Denial of Service (DDoS). A flexible and intelligent correlation engine will enable a web application firewall to stop sophisticated hackers without blocking legitimate users.

Preventing automated attacks and bots

Cybercriminals now have access to off-the-shelf toolkits like the Havij SQL injection tool to extract sensitive data. Because of the growth in automated attacks, stopping malicious users is now as important as stopping malicious requests. But correctly identifying the bad guys requires multiple defenses.

Your web application firewall should have real-time reputation intelligence to identify and block malicious traffic before an attack can happen. It should also be able to recognize bots— the automated clients behind most automated attacks.

To reduce network level DDoS attacks, a web application firewall should also include integral support for a high-capacity, cloud-based DDoS protection service.

Recognizing malicious sources

In most cases, malicious web visitors that try to steal data, commit fraud, or take down websites aren’t even human. They are bots that continuously attack one site after another. On the other hand, human hackers are more sophisticated than bots; they use anonymous proxies or Tor networks to hide their identity. Unfortunately, organizations can’t identify malicious users until the damage is done.

A web application firewall must recognize known malicious sources and sites. Because hackers often use anonymizing services, the firewall should detect access from anonymous proxies and Tor networks. It also should recognize users referred from a phishing site. Ideally, the firewall also should be able to restrict access by location, which helps eliminate unwanted traffic and can thwart DDoS attacks from a specific country.

Because web application firewalls can be effective at detecting web-based threats, they should also be able to collect and share information about attacks and attack sources. Intelligence-based solutions are the future of application security.

Patching vulnerabilities virtually

By some estimates, more than 83% of scanned sites have at least one vulnerability. At the same time, fixing discovered vulnerabilities can take 59 days on average, during which time your applications remain exposed to attack. Besides the cost and the time required to fix vulnerabilities, organizations must consider additional hurdles like vulnerabilities in legacy applications and in packaged applications.

A web application firewall must prevent attempts to exploit application vulnerabilities. Defenses such as input validation, HTTP protocol validation, and attack signatures must be able to block most vulnerability exploits out-of-the-box. At the same time, however, organizations need granular control to ensure strict security measures are applied to known application vulnerabilities. Your firewall should integrate with application scanners and build custom policies to virtually patch vulnerabilities discovered in this way.

Stopping malware

Cybercriminals are using their success with online banks to branch out into other applications like ecommerce and bill payment. How do they carry out malware-based fraud? First, they infect machines with malware such as the Zeus or SpyEye Trojans. Then, when infected users log into a targeted web applications such as online banking sites, the malware modifies web pages, performs unauthorized transactions, or steals login credentials

Because web application firewalls sit between web users and applications, they must be able to analyze end user attributes and web traffic patterns to identify malware infection and block malware-infected devices. They must also perform a number of actions, such as monitoring the user for a specified period of time, generating an alert, or integrating with a fraud management solution to open an investigation case. And, they have to do it all without requiring changes to the protected web application.

Eliminating payment and account origination fraud

How can organizations protect their applications against fraudulent users quickly, without expensive and protracted application development projects?

Your web application firewall must be able to integrate with cloud-based fraud security solutions, to analyze a range of user and transaction attributes, including browser irregularities, known fraudulent devices, and suspicious payment information. The web application firewall should correlate fraud risk data with web attack and user information to accurately identify and stop fraud.

Supporting both on-premise and cloud deployment

Application architectures are as diverse and rapidly evolving as application threats. Consequently, a web application firewall must provide flexible deployment and configuration options.

Because many organizations have moved their application infrastructure to the cloud, web application firewalls support virtual appliance solutions for private clouds and cloud-based security services to protect hosted web applications.

Organizations hosting applications on-premise have specific needs of their own. Many require a high performance solution that won’t change existing applications or network devices. Others may need a firewall that can modify content, sign cookies, rewrite HTML. Still others may need non-inline deployment, so IT security teams can ease into inline deployment over time.

When evaluating web application firewalls, it’s important to look for solutions that will support both on-premises and cloud requirements for the foreseeable future.

Automating and scaling operations

Web application attacks can be complicated. Stopping those attacks shouldn’t be. Security administrators should be able to create custom security policies without learning a scripting language. Organizations must be able to centrally manage application security policies and monitor events at a global level. They also need detailed security alerts and customizable reports for monitoring and forensics.

Your web application firewall must have point-and-click security policies. Simple, flexible policy configuration makes initial configuration easier, and simplifies the process for administrators to review security policies.

Besides custom policies, web application firewalls must support centralized management, to help synchronize policies and application profiles across all of their web application firewalls, no matter where those devices may be located.

Conclusion

Web applications drive organizations more today than at any other time in history. Unfortunately, a whole industrialized economy has emerged for hackers, with automated tools to steal data, disable websites and commit online fraud. Network security products like firewalls and intrusion prevention systems are typically not enough to stop these growing risks.

Protecting your assets and improving security means having a web application firewall that fully meets your organization’s specific requirements. Your odds of falling victim to today’s growing range of cyber-attacks are greatly improved when your web application firewall supports the essential capabilities described here.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Web Application Firewalls: The Top 10 Security Challenges and How to Meet Them appeared first on Intelligence Community News.

]]>
38612
Thales acquires Imperva https://intelligencecommunitynews.com/thales-acquires-imperva/?utm_source=rss&utm_medium=rss&utm_campaign=thales-acquires-imperva Mon, 04 Dec 2023 13:55:37 +0000 https://intelligencecommunitynews.com/?p=37271 On December 4, French firm Thales announced that it has completed the acquisition of Imperva, earlier than expected (previously foreseen...

The post Thales acquires Imperva appeared first on Intelligence Community News.

]]>
On December 4, French firm Thales announced that it has completed the acquisition of Imperva, earlier than expected (previously foreseen at the beginning of 2024). This is a key milestone for Thales, creating a global leader in cybersecurity, with more than 5,800 cybersecurity experts across 68 countries and €2.4bn in cybersecurity revenue expected in 2024, including civil and defense activities, with double-digit growth expected thereafter.

This transaction will generate significant value creation for Thales’ shareholders in line with the targets communicated in July 2023, when announcing the acquisition. In addition, the profile of Thales’ Digital Identity and Security (DIS) activity will be significantly enhanced with new financial targets by 2027 (2024-2027 organic sales growth of +6 to +7% and 2027 EBIT margin at 16.5%).

Patrice Caine, chairman and chief executive officer of Thales, said, “The acquisition of the U.S. company Imperva is an important day for Thales, as it marks a new step in the expansion of our global cybersecurity capabilities for enterprises and governments around the world. We are very excited to welcome the Imperva teams to Thales. The combination of our entities’ values and our joint commitment to a future of trust will create significant synergies, business opportunities and major market innovations. With ever-increasing cyber threats against business and government digital infrastructure, Thales is now uniquely positioned to help customers protect the heart of their digital ecosystem: applications, data and identities.”

Together, Thales and Imperva will help customers address cybersecurity challenges that have increased rapidly in frequency, severity, and complexity, with the most comprehensive solutions for the broadest range of application, data security, and identity use cases. These three market segments combined are forecasted to grow significantly in the coming years. With the addition of Imperva, Thales’ expanded cybersecurity portfolio now offers a highly complementary combination of solutions to help customers secure applications, data and identities across their entire digital ecosystem, the company said.

This is Thales’ ninth acquisition in the digital security area over the last nine years, and the second largest in the group’s history after Gemalto, world leader in digital security. After the completed acquisitions of Tesserent, the leading player in cybersecurity in Australia, S21sec & Excellium, two major players in cybersecurity consulting, integration and managed services in Europe, and OneWelcome, a European leader in Customer Identity and Access Management, the integration of Imperva within Thales will position the group’s cybersecurity business as one of the top five global leaders in cybersecurity.

Source: Thales

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Thales acquires Imperva appeared first on Intelligence Community News.

]]>
37271