We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Zero Trust Cyber Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Zero Trust Cyber Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For theCUBE + NYSE Wired: Zero Trust Cyber Series
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for theCUBE + NYSE Wired: Zero Trust Cyber Series.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Zero Trust Cyber Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Zero Trust Cyber Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to theCUBE + NYSE Wired: Zero Trust Cyber Series
Please sign in with LinkedIn to continue to theCUBE + NYSE Wired: Zero Trust Cyber Series. Signing in with LinkedIn ensures a professional environment.
Corelight, a company led by CEO Brian Dye, aims to provide network visibility and ground truth on attacker movements. They have reached milestones such as passing $100 million in ARR and serving major tech firms, banks, and national labs. The open source-based model focuses on stable network protocol data for detection, with proprietary logic for protection against evasion. Partnerships with security brands like Microsoft, CrowdStrike, and Google leverage Corelight's data for threat detection and containment. AI, specifically large language models, enhance da...Read more
exploreKeep Exploring
What type of customers does Corelight serve and what recent milestone has the company achieved?add
What are the benefits of being an open source based company in the context of providing ground truth to disrupt advanced attacks?add
What are some examples of security brands that partner with companies providing ground truth network security solutions?add
What are the challenges that security teams face when trying to analyze historical data in order to identify threats to critical infrastructure?add
What is the importance of providing data and detections to help find advanced techniques like "living off the land" for cybersecurity purposes, particularly in light of the rising prevalence of such techniques over the next 12 months?add
>> Hello everyone. Welcome back to theCUBE. I'm John Furrier here at the NYSC, theCUBE Studios East. We got our studio in Palo Alto, California. We got Silicon Valley and Wall Street connected in an open system. It's a network now being connected to the NYSC Wired network. Brian Bauman here at the NYSC is putting that together, theCUBE contributing a key part of that here with our super studios. We got Brian Dye here, the CEO of Corelight, CUBE alumni. We just saw each other at the Google MY Security Conference. Great to see you again. Thanks for coming back on theCUBE. What do you think? Not too shabby here at the NYSC.
Brian Dye
>> Brian, fantastic digs. Great to see you again and great to see that we've covered the two Brian minimum for any meeting, just between the two of us. >> I'm John. Brian Bauman is the NYSC.
Brian Dye
>> Ah, got it. Good point. Good point.>> Okay, cool. Well, what do you think about the NYSC?
Brian Dye
>> I think the show floor is fantastic, and I think what they're doing as an exchange is really interesting. I think we were just talking outside, I think there's going to be a lot of activity in this floor happening over the next 12 to 24 months. I think the pipeline's going to pick up.>> So good to see you again. We were just chatting about Corelight at MY's Threat Detection. Give a quick... For the folks who didn't see that, interview is on YouTube if you want to check it out. It was an in-depth conversation around what's going on in security industry. Give a quick set the table, what do you guys do?
Brian Dye
>> Really we try to give defenders ground truth of what's happening on their network. So we let them understand what attackers are doing, how they're moving when they bypass the perimeter defenses. And as you might imagine, that's a pretty rich topic today, especially with some of the recent sys advisories. So really, really relevant in the Volt Typhoon and Salt Typhoon world.>> What are some of the company milestones that you can share with you guys now in terms of accomplishments? What are some of the key momentum points with Corelight right now?
Brian Dye
>> Yeah, I think probably the biggest thing, really macro level, passing through a hundred million of ARR, fully funded is a company we actually announced what is hopefully our last money in from an investment perspective at RSA this past year, and just really privileged to be serving the class of customers that we are. So if you look at two of the five biggest tech firms in the world, about half of the top 10 banks in the world, a decent chunk of the, I think eight of the top 10 national labs. Those are all Corelight customers. So it's really a privileged asset class to be able to serve.>> And what's the secret sauce for Corelight? Why are they working with you guys? Share the value proposition.
Brian Dye
>> I think it's really two things. One, just this ability to give folks ground truth to go find and disrupt those advanced attacks. And two, the fact that we're actually an open source based company. And it's not open source for the sake of open source. It's the fact that the project we're on is this beautiful flywheel, right? Because you think about security, what is the data you need to go find and disrupt those advanced attacks? Well, it turns out that that's a moving target, right? New attack finds a new technique. Try something new. You need new data to go find it. So that flywheel has been happening in the open source community for 30 years. because the open source tech is used by the web scale tech giants, the biggest DHS agencies, the Mandiant IR team, the CrowdStrike IR team. Most of the folks you'd call to get yourself out of trouble, they're the ones that have been kind of driving this tech for the last nearly 30 years.>> On the open source side as well.
Brian Dye
>> Yep. On the open source side as well.>> Talk about the role of open source because it's come up a lot as a key linchpin. We've seen the success, I don't know what generation we're on, fourth, fifth, sixth. Open source, when I was in college, it wasn't even like now it's mainstream. In security in particular, everyone has access to the open source, including the bad guys. So talk about the value that the community has done with open source to beat the adversaries. Because those guys are winning, but now we're starting to see the scale tip almost coming back for the protectors.
Brian Dye
>> Yeah. The key is, where does open source work and where does it not, right? Open source works when you've got a stable foundation to build on top of. So if you look at what the open source tech's doing really well, it's giving folks ground truth of what's happening on the networks. And it turns out the network protocols don't change very fast. So that's a very stable foundation to build off of. And it doesn't matter whether the attacker knows that you have it. The fact that the data and the evidence is there is the power. Look at where open source is not a good idea. Detection logic, right? If you open source your detection logic, then the attacker will find a loophole in that or some way to evade that detection. So that's really the kind of split that we see happening. And the big piece on the open source as well is that we've got the ability to have folks continue to evolve and contribute to that so we can be tweaking and evolving which parts of the network you really need insight into. Those two things have been the most powerful parts.>> Talk about the core light revenue model, because obviously open source is a big part of it. Do you guys make money on those pieces? Where's your value add and how does that open source continue to rise?
Brian Dye
>> Yeah. So number one, a big part of the mission for the company is to actually continue to be the economic engine supporting the open source. So we're very committed to maintaining that open model. And there has been a lot of movement in open source licensing over the last few years. We're very committed to the open source business model, and to the open source community, I should say, is a better way. And then where we add value is a couple things. Number one, we make things super easy to deploy, right? If you're trying to deploy at gigabits per second, terabits per second, that's a very hard thing to make work on your own. We make it super easy. Number two, we take a bunch of the things that have to be proprietary, like the detection logic. So whether it's supervised and unsupervised machine learning, behavioral detections, rule-based detections, there's a bunch of detection content that needs to be proprietary, otherwise you're creating a vulnerability by handing that out to the attackers. That's the second big thing. And then third is, we drive a bunch of workflow automation, so delivering via SaaS form factor, adding all the genAI stuff. And I want to come back if we have time to this intersection of open source and AI. That is super interesting. >> Yeah, we'll get to that next.
Brian Dye
>> Yeah, there's a lot going on there. But there's a bunch of workflow automation that we can build in that again, is not native to the open source project. So we can really... We found this nice balance of being able to support the open source community, continue to drive the project forward, but still creating a productive business model. So that synergy really kicks in.>> Before we get into the AI relationship, we definitely want to unpack that. That's a key decision. I'm really glad you explained that because you also mentioned earlier that you have a lot of these other companies using the open source. So talk about the partnerships that you guys have because you guys have a nice balance between how to produce revenue while maintaining the purity of open source in a good way for everybody. And since everyone's using it, the more eyes on things, the better, it's my view. More eyes, keep the lights on. You don't want darkness in the shadows in there for the bad guys. Talk about the partnership you guys have. I know you had a partnership we announced on theCUBE with Mandiant and with Google.
Brian Dye
>> Yeah, with Google and Mandiant.>> Talk about some of the ecosystem partnerships or partners for you.
Brian Dye
>> Yeah, the big one for us is this idea of ground truth on the network. Being able to find those advanced attackers, things like the Volt Typhoon specific techniques or Salt Typhoon as an adversary, the ones you didn't know about to be able to look back in time for three, four months, nine months, 12 months, find out what's going on. It turns up everyone needs that, right? It's complimentary to everything that's going on. So we really partner with basically every security brand name you can think of. So whether it's Microsoft, CrowdStrike, Google, Palo, Splunk, and Cisco and a whole host more, everyone who's doing security analytics in any material way, they love working with us because the data we provide is, it's not just detection of the attacker, it's the context. You can look at the whole kill chain, connect the dots across that kill chain, confirm containment, confirm remediation. So if you make a SIM or anything that looks like a sim, then the evidence that we provide is incredibly helpful. And so that's the pretty broad brush. And by the way, that's not just the SIM providers, but put in the cloud service providers too. So if you've got Amazon, Google being both the kind of Chronicle side and the GCP side, it gets pretty rich, just because of the foundational value that they .>> And there's a lot of data in there. And again, we talked about things like dwell time in our last interview at Mandiant and other threat intelligence tactics. I love the kill chain analogy, I think that's super relevant. Talk about AI, because I think you mentioned data, okay, analytics is powered by data. Data drives truth, more data, more truth, more context, context. Windows tokens got a pattern emerging here. The connection between generative AI and data. Take us through and unpack that relationship and how that relates to some things you're working on.
Brian Dye
>> Yeah, credit you for connecting all those dots. By the way, I think that there's two big themes here. One is you can't AI anything without data. So you throw all the genAI MLs you want against nothing and you're going to get nothing, especially a cyber sense, right? You've got to be able to feed it something intelligent to ask it a question about. And it turns out that the evidence we provide is incredibly relevant to that, right? And by the way, it's not just the genAI side of AI, but that also applies to supervised unsupervised machine learning, all the other parts of the broader kind of AI bubble. So that's a big one. The really fun one, though, is the second half of this, which we did not see coming in any ways. Remember, what was it, almost two years ago now when GPT3.5 hit the wire and it became super popular and everybody started using it. That happened in mid-Feb 2023, if I've got my memory right. We were in an advisory board meeting with our own customers about three weeks after that. And we were talking about supervised and unsupervised ML and false positive rates and accuracy and all that good stuff. And one of our customers, chief security architect at a financial firm here in the city stopped us and said, "I thought you guys should know that my analysts are using GPT 3.5 to investigate DNS exfiltration using Corelight today. And that struck me as interesting. I thought you guys want to know that." That completely stopped... We didn't stop the meeting. We completely changed the course of that meeting and talked about AI for the entire rest of the time. Because what happened if you're open source->> Oh, before you go forward, so what did that mean when he said that that meant that they were using Corelight data, grounding it with chatGPT?
Brian Dye
>> They were literally->> Or were they doing... Take us through it then we'll come back to that. Hold that thought on this side. Stay with the unpacking of why that statement was so impactful.
Brian Dye
>> Yeah, she in this case actually, but what her team was doing is they were taking Corelight's evidence, pointing the machine learning model or the general model, GPT 3.5 in this case, and then saying, how would I go investigate distributed DNS exfiltration using this data? And then they were actually having it automatically draft queries and Splunk to mine against the evidence that Corelight provides. So they were literally doing their jobs faster using the data and GPT 3.5 literally three weeks after that went public, before we had done a thing.>> Yeah. And that's like, now you're probably light bulb went off. "Wow. Product feature. Let's go. Take us through the next progression."
Brian Dye
>> Yeah,>> The meeting changed. What happened next?
Brian Dye
>> Oh, well, what we realized was, "How on earth did this happen? We hadn't done anything, right? This is mana from heaven," right? It turns up if you're an open source based company, these large language models are all trained on the public internet. Of course. They understand the evidence, they understand the alert syntax. So all the things that a bunch of companies had to do in terms of tuning and rag and all this other stuff, we got for free. So all we had to do was to go take and do prompt engineering. So there's a reason that we were nine months ahead of everybody else in the category to actually put GenAI features in. And the really nice thing is just like the open source relationship where our customers aren't single threaded on what we do, they can take advantage of the community. They're not single threaded on what we do with GenAI. They can take, whether it's OpenAI's models, the Microsoft implementation of that, Google's Gemini models, Meta's Llama models->> Anthropic.
Brian Dye
>> Anthropic. Claude, Anthropic. This works on all of them. So you don't have to be single-threaded with what we think is a good idea. You can take those models, build out your own workflows independent of what we do. It's really have your cake and eat it too kind of moment.>> And this highlights, in my opinion... Thanks for explaining that, by the way. I think this highlights two things. One, power of open source, two power of data hoarding. I call it data hoarding.
Brian Dye
>> Oh, a hundred percent.>> So you have data and been collecting it for a rainy day, it's the rainy day. It's a sunny day, I should say. Whatever a good day, a thousand flowers are blooming in this case. No one's single, single-threaded anymore. It's customized. The personalization, this is where AI shines is the personalization. So, thank you. Open source. Thank you, LLMs, for using open source. And then two, the impact of the velocity of the innovation on the customers are innovating on your behalf
Brian Dye
>> And it's fascinating to watch what they're doing. Let me give you two different examples. So what we embed in our own products we call guided triage, right? The ability to see all the data you need to investigate an alert and then get automated guidance from the LLM on, "Can you translate this alert into English? Can you tell me what I should do next to investigate this alert? Can you help me prioritize this alert?" That's a bunch of really practical value for an analyst on day one. That's what we embed. Our customers have taken that and run with it further. So we have a big university system that we work with that is already pre-GPT, automating 98% of their alert response, which is fantastic, by the way. Really incredible. What they're doing with the last 2% is they have a waterfall of three different AI models that are enriching evidence and helping automate that analyst investigation that they're doing at the whole SOC layer, not just at the network layer. So again, have your cake and eat it too. And it's really impressive to see, especially the forward leaning organizations, how quickly they're picking this up and what they're doing with it.>> Yeah. A great use case, great examples, great illustration of where we are now. Next question is you're starting to see token sizes. You're starting to see the frenzy of developer community, which we've been reporting on SiliconANGLE for over two years, but over the past year, just absolute stampede, frenzy, the appetite, whatever you want to say. The developers in open source right now are just dying to get their hands on building stuff. So as the infrastructure players get better, faster, better price performance, we're starting to see that, Amazon announced some great stuff. We just had Grok in here earlier. There's going to be a tipping point very shortly where the floodgates will open. Developers will start rolling in all from open source. Islam is already getting better. The proprietary models, some are saying can't keep up. What's your vision of when that tipping point comes where it's unleashing creativity, development. Because open source will win. No doubt in my mind. I'm sure you agree. You're not going to debate that.
Brian Dye
>> Well, yeah.>> We're both the same religion on that point, but this is real. Share your thoughts on this and you commentary add to that or let's talk about it because I think this is going to be a moment in time that we're going to point to and say, when that tipping point happens, new brands will emerge, entrepreneurial ventures will be stood up on top of this, innovation inside the enterprise, inside the large-scale critical infrastructure providers. Everything will just be rocking.
Brian Dye
>> So what I would say, first if I could really pinpoint the answer to that, we shouldn't be talking right now, we should be trading on the floor and making a ton of money together. So let's call that what it is.>> This is high-frequency insights, by the way, better than high-frequency trading at this point.
Brian Dye
>> Exactly. >> But we will riff on, it's like horses and hand grenades. Close enough wins.
Brian Dye
>> Totally, totally. >> This year, next year. But I think it's close. It feels close.
Brian Dye
>> Oh, I think it's already happened, we just haven't seen it at all yet.>> Okay.
Brian Dye
>> Right? If I look at what's happening... And let's take the spread. We talked about that university system that's already deployed this in Rage. If you look at take another very large bank here in the New York area, they've already got a SWAT team that's literally going around to their individual cyber functions and saying, "Hey, what can we automate? How can we be your central supporting SWAT team?" So what I think is really happening is that the energy around the LLMs is so intense that it's actually being used in most organizations outside of cyber. First we talked to the CEO of one very large financial, Canadian financial that said, "Hey, look, if I could help my sales team be 15% better, that's worth north of a billion dollars to me on the bottom line." So it's a very rational thing to say, "If I've got a certain amount of resources that I can put against genAI and these large language models, I'm going to not put them in risk reduction first. I'm going to put them at revenue generation or cost savings."
So I think there's a tremendous amount happening there. So the security teams in many cases are kind of fighting to get access for resources that are being prioritized elsewhere within the company. So that's one macro thing that's happening. Those teams that are getting the permission to do that are, I think, ramping very aggressively on the learning curve. And the only thing I think that's even slowing people down a little bit, and I use that in air quotes, is the large language models themselves are iterating capabilities so fast that how much tuning do you want to do on a model when you're kind of waiting for what Claude and Gemini and OpenAI are going to do in six months? "I want to protect my investment, protect my automation. I don't want to be overly committed." Imagine if you tripled down on the 3.5 model, and then 4.0 came out and then Strawberry came out. You'd be like, "Oh, wait, I'm missing the wave here." So I think there's such a steep innovation curve here that folks are kind of, they don't want to over-invest. That's the only thing holding people back.>> And I think that's a great point. One of the things that's come up in a lot of our conversations here on theCUBE here and also into the valley is the versioning of things, like a product. And remember back in the '80s and '90s, backwards compatibility was a huge deal. This is going to be a big part. This is again why I think open source will be the winner because you need to have that code base and slash knowledge about what your double down or triple down on so that you can roll it forward and yeah, you might have to make some modifications. This is one of the things that it's holding Nvidia back is that they've got to make software changes to all their libraries on every rev of their chips. It's a public secret, but here in Wall Street, they're trading stock at Nvidia. They don't know this. That's a major moat killer potentially. I bring that up only because we talked about it last night on the panel at the Wired event upstairs, but this is real. This whole backwards compatibility has to get nailed down. What's your thoughts on that? What's your reaction to that?
Brian Dye
>> I think you're right. And it ties into the pace of innovation, how much you're worried about sunk cost investment. If I do something that becomes irrelevant, not irrelevant, because I think there's a decent backwards compatibility, but you don't want to miss taking advantage of the next gen of capabilities from the large language models. So let's take a practical example. So you've got a lot of attention coming around the Volt Typhoon tactics that are hitting critical infrastructure. CISA came out with... It's actually a joint advisory on December 3rd from CISA, the FBI and the NSA, which is pretty rare with a lot of hardening guidelines. So now you're asking yourselves, "How do I look inside my infrastructure to find out what happened three, six, nine, 12 months ago?" This is a great application for AI because you're trying to sort through a whole bunch of data, get to the prioritization, figure out what to go do. Do you want to be thinking about that problem or do you want to be thinking about how well can I fine-tune this model when I know that there's going to be a new model coming in six months, right? I think that's the juggle the security teams are having.>> Well, great conversation. Give a quick plug for what you guys are working on right now at Corelight. What are some of the key things you're looking for from a customer standpoint? Anyone watching as a prospect or people in the open source community, hiring, what are your needs? Give a plug for the company.
Brian Dye
>> No, look, really appreciate it. A lot of what we're focused on right now are things like this recent CISA advisory. How do we give folks the data and the detections to look back in time to find these really advanced techniques to find living off the land in particular? That is the, I think if you're going to ask me a security prediction for the next 12 months, we've seen this rise is going to become so shockingly prevalent. And unfortunately, it is the type of technique that bypasses, EDR bypasses a bunch of your traditional defenses. It's one of the compelling reasons why you need Corelight. So that's, number one, a big area where we're focusing.>> And hiring? You guys looking to hire?
Brian Dye
>> Hiring in a very big way. I think we have... I'd have to double check on the website, but we're expecting to hire north of 100 people over the next 12 months. So I don't care what job function you're in, we're looking for you. There's a ton of opportunity there.>> You got math background, you like machine learning, you like solving problems.
Brian Dye
>> Well, it's not just that, honestly. So yes, the research labs team, the engineering team, but customer support, finance and GNA, marketing, product management, literally every function of the company is continuing to grow as we grow, on behalf of our customers. That's a huge one.>> Nice.
Brian Dye
>> And we're always looking for folks that want to go support and engage with their open source communities. I was actually just talking to a podcaster yesterday who was actually about to host a CTF in the Southeast, and he had no... We had made the connection before the two of us sat down together. So it's such a... The broader cyber talent shortage is absolutely still real. So anything we can all do as an industry to help folks get into the business, it's an unqualified positive.>> And I appreciate what you guys do. If you're watching this and you're interested in cybersecurity, open source, get on it immediately. Number two, you don't need to have the experience. You can level up pretty quickly if you're a problem solver and you like to get stuff done fast and you can handle the pace of play. Pace of play is pretty fast in cyber.
Brian Dye
>> You do not need a CS degree. That's the biggest misunderstanding people have. Yeah.>> I always say, I've seen anthropologists be great at cybersecurity and mathematicians, again, all coming down the pike super-fast. Brian, thanks for coming on theCUBE, appreciate it. Good seeing you here in our new studio.
Brian Dye
>> John, likewise.>> In Wall Street, I'm John Furrier. We're at the Silicon Valley, Palo Alto and Wall Street here at the NYSE, bringing you all the media coverage here. I'm John Furrier. Thanks for watching.