Alexa Raad is chief operating officer of Farsight Security, based nin San Mateo, California. Farsight Security is a provider of real-time nactionable Internet threat intelligence solutions.
nnnnIn this exclusive interview, Raad discusses methods of curbing ncybercrime by tracking bad actors through the trails they leave in the ndomain name system. She also offers some encouraging advice to women andn girls interested in breaking into the cybersecurity field.
nnnnFarsight Security COO Alexa Raad
nnnnAlexa Raad
nnnnChief Operating Officer
nnnnFarsight Security
nnnnTechNewsWorld: What is Farsight Security’s mission?
nnnnAlexa Raad: We believe that everyone is entitled to a safer Internet,n and so everything we do starts out with that mission in mind. What we ndo is provide Internet defenders with very valuable data that they can nuse to get some context around nefarious acts.
nnnnAs an example, if you think about Internet threats like phishing and nbotnets and malware — all of those start with a DNS — a domain name nsystem. And so every kind of nefarious act leaves footprints and nfingerprints in the DNS. That’s something that cannot be faked. We nprovide information that is contextual.
nnnnAspose Ad
nnnnTo give an example, a lot of the new domain names that are registeredn are typically registered with bad intent, meaning criminals are going nto use them to commit some sort of act, like phishing attacks, etc. Whenn a domain name is registered, it’s fine, but when traffic starts going nto those sites, it becomes much more dangerous.
nnnnWhen people start actually going to a phishing site, it raises the nthreat level. We have a global sensor network that picks up these nresolutions. We collect this data, but without any npersonally-identifiable information, which is important.
nnnnThat information allows people to see what’s actually got some ntraction, and we also add additional information for guilt by nassociation. If a phishing site is actually hosted where there are lots nof other bad actors or bad sites, that provides you with some context. nYou start to follow that and get a better picture of that attack than nyou would otherwise.
nnnnWe provide real-time and historical information, and both are ncontextual. The real-time data is important, because you have to fight nthese battles in near real time. The historical information is importantn because you want to know if this was the first time we ever saw this nURL or domain name. A lot of these patterns repeat themselves. It is nunlikely that a site was bad six months ago and all of a sudden it’s nreformed. Having that contextual information is important.
nnnnTNW: Why do you have a passion for cybersecurity? Why do you think it’s an important and vital field?
nnnnRaad: I believe in the mission of cybersecurity. I want to leave our nkids with a safer Internet. The Internet is such a utility — we all relyn on it, and we have to have some modicum of expectation that the nInternet is safe.
nnnnThe DNS is a fabric that’s equalizing. Regardless of where you are onn the Internet, you have a voice. We’re learning that if Internet is not ntaken care of, there will be unintended consequences.
nnnnTNW: What are some of the key cybersecurity issues today? What are some prevalent or common problems that we face?
nnnnRaad: There’s an increasing number of attacks with the Internet of nthings. The number of Internet-enabled devices is increasing, and all ofn these connected devices provide vectors for cybersecurity attacks. The nrace is on for cheaper devices, but the race isn’t necessarily on to ncreate more secure devices.
nnnnTNW: What advice would you give to girls and women wanting to get into the cybersecurity field?
nnnnRaad: It’s the ideal field for women. To be really good in ncybersecurity, you have to have an inquisitive mind, be a nproblem-solver, and see things holistically.
nnnnFor a problem that’s complex, you need to think holistically, you ncan’t compartmentalize. You have to think, how would a criminal look at nyour DNS architecture? Women tend to think holistically, and if you do, nyou will excel in this field.
nnnnThe other piece of advice I would give is that you have got to be nyour own champion. Don’t wait for anyone to propose something to you or nto give you the promotion that you deserve. You have to speak up. You nhave to be your own advocate, and you have to lay out the business case.
nnnnIf you want to be promoted, for instance, you have to say, this is nwhat I’ve done, this is what I’ve accomplished, this is what I can do nmore of, and this is why it’s in your own best interest to promote me. nThere is an imbalance in the number of women in power, and it’s also at nthe executive level. Very few women are CEOs or in the c-suite or on then board, and there is a lot that women can offer and do.
nnnnWhether it’s because companies recognize the need to hire more women nor they have a policy to do so, the opportunities for women are there. nThe security industry is growing. There aren’t enough people to fill then jobs available, and a lot of them are high-paying, with good benefits. nYou just need to be your own champion.
nnnnTNW: What new cyberthreats are emerging, and how can businesses prepare themselves to face them?
nnnnRaad: You see a lot of ransomware. Just a few weeks ago I was at my ndentist, and he told me that he had just been the victim of a ransomwaren attack, and he ended up paying it. You wouldn’t have thought he would nbe the victim of an attack like that, but someone in his organization nhad clicked on a link, and all of his patient records were frozen until nhe paid the ransom.
nnnnYou will see more of this because it pays well, and it targets peoplen who aren’t well-versed in security hygiene. We’ll see more and more of nthe security issues and attacks that come because of insecure devices nlike wearables and Internet-connected devices.
nnnnThere isn’t an incentive for manufacturers to create more security. nThe economic incentive is more toward creating devices that are cheaper nand more affordable than more security, but it really has to be both. Itn requires both better engineering and better policy
n