Amazon’s latest security offerings, announced at its re:Invent conference, cover everything from advanced biometrics to new tools for defeating runtime and cloud threats, including identity and access management (IAM) capabilities. Credit: ThomasAFink / Shutterstock The latest security announcements from Amazon aim to address a wide range of security issues for businesses, including an all-in-one hand-scanning biometric system and new capabilities for its Detective security visualization tool and GuardDuty continuous monitoring solution. Amazon One Enterprise is the most novel of the company’s announcements, which were made this week at its AWS re:Invent event in Las Vegas. One Enterprise is a palm-based identity tool for both physical and digital security — users can authenticate using a handprint, instead of carrying an access fob for building access, or using a PIN to access software resources. The idea, according to the company, is to reduce overhead from the management of standard enterprise authentication methods and eliminate many of their associated vulnerabilities. Keycards and the like can be lost or stolen, and must often be verified by other means, while PINs and passwords must be regularly changed and have the ability to be reset when forgotten. According to Amazon, the use of vein and palm imagery for matching is more accurate than even double iris scanning. “The new service’s palm-recognition technology uses advanced artificial intelligence and machine learning to create a palm signature that is associated with identification credentials like a badge, employee ID, or PIN,” the company said in a press release. Elsewhere in the security stack, Amazon added identity and access management (IAM) support for its Detective security visualization tool. This means that users can now search through user IDs and roles for indicators of compromise automatically, the company said. Moreover, a new generative AI feature can generate natural-language summaries for investigations in Detective, which Amazon said should make it easier and faster to synthesize information from the company’s numerous security platforms. Finally, the company announced that its GuardDuty intelligent threat detection product now has the ability to detect runtime security issues in ECS clusters, whether they’re running on the AWS Fargate serverless computing platform or in EC2. Runtime security is a particularly important consideration for containerized environments, and Amazon said that the newest version of GuardDuty looks for discrete events (file access, process execution, and similar) that can indicate a runtime threat. Amazon One Enterprise is currently available only as a preview version in the US, with beta customers including door manufacturer Boon Edam, IHG Hotels and Resorts, among others. The new capabilities in Detective are available for AWS customers as of now, although the gen-AI-powered group summaries tool is only available in the US, Asia Pacific and Europe as yet. ECS Runtime Monitoring in GuardDuty is also available immediately, priced on a per vCPU, per hour basis. Related content opinion 5 best practices for running a successful threat-informed defense in cybersecurity The concept is well understood but putting it to work is much harder. Leading organizations provide some guidance on how to best implement this robust defensive strategy. By Jon Oltsik 29 Aug 2024 6 mins CSO and CISO Threat and Vulnerability Management Endpoint Protection feature Is the vulnerability disclosure process glitched? How CISOs are being left in the dark Better communication and collaboration between researchers and vendors and improved bug reporting mechanisms could help address confusing and sometimes wholly suppressed bug reports. By Cynthia Brumfield 26 Aug 2024 10 mins CSO and CISO Threat and Vulnerability Management Data and Information Security news WordPress users not on Windows urged to update due to critical LiteSpeed Cache flaw Updating to version 6.4 or higher will prevent exploitation of the vulnerability that allows attacker to gain admin access. By Lynn Greiner 23 Aug 2024 3 mins Threat and Vulnerability Management Identity and Access Management Vulnerabilities news Black Hat: Latest news and insights The Black Hat series of international cybersecurity conferences brings together top IT security pros, researchers, and thought leaders to discuss the latest cyber techniques, vulnerabilities, threats, and more. Here’s the latest to know. By CSO Staff 08 Aug 2024 4 mins Advanced Persistent Threats Windows Security Threat and Vulnerability Management PODCASTS VIDEOS RESOURCES EVENTS SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe