Cyber Security Dispatch

Cyber Security Dispatch

By Andy Anderson & CSD StaffBusinessTechnologyBusiness NewsTech News
Download on the App Store

Cyber Security Dispatch episodes

  • A Postcard From the Future - An Interview with Dr. Ron Ross

    Key Points From This Episode:


    •    Dr. Ross’ job specifics and NIST’s role in cyber security.

    •    The current climate of cyber danger and how this relates to the internet of things.

    •    Cyber resiliency as compared with the idea of cyber security.

    •    Counter measures and tactics that typify cyber resiliency.

    •    The characteristics of diversity and homogeneity in security systems.

    •    The idea of deception as a tactic in defense.

    •    Dynamism and reconfiguration in the ongoing battle against adversaries. 

    •    Minimizing the time that a cyber criminal has to operate within a system.

    •    Utilizing virtualization and shielding in the framework.

    •    Accelerating dissemination of the information available on cyber security

    •    And much more!

     

    Links Mentioned in Today’s Episode:

    Dr. Ron Ross — https://www.nist.gov/people/ronald-s-ross


    NIST — https://www.nist.gov/

    NIST Cyber Resiliency Framework — https://www.nist.gov/cyberframework

    Dr. Ron Ross on Twitter — https://twitter.com/ronrossecure

    Cambridge Analytica — https://cambridgeanalytica.org/

    59 min
  • The Nightmare of IOT Vulnerabilities - An Interview with Stefano Zanero & Roberto Clapis

    On today’s episode we host a conversation with Roberto Clapis and Stefano Zanero from Secure Network in Milan. We tackle the issue of IOT device security and try to break down just where companies and users are at with this issue currently. We get a background to Stefano and Roberto’s work and their interest in security as well as little peak inside their presentation from The Black Hat Convention. One of the main takeaways from the discussion is the idea of communication between security and other sectors, something that our guests suggest would greatly improve the strength of security. Listen in to hear what they have to say!

    28 min
  • Air Gaps Are Like Unicorns - An Interview With Galina Antova
    Air Gaps Are Like Unicorns
    An Interview with Galina Antova

    Introduction:

    Welcome to another edition of cyber security dispatch. This is your host Andy Anderson. In this episode, Air Gaps Are Like Unicorns, we talk with Galina Antova. One of the co-founders of Claroty, a fast growing security startup in the world of industrial control systems. She shares her experience working to protect these critical systems and the journey that led her to found Claroty.

    Transcript:

    Andy Anderson: Everybody sort of ends up in cyber security in kind of a unique way. Like I don't think there is a single kid who grows up being like, "I want to be a cyber security expert." What was your path into this biz?

    Galina Antova:  You're absolutely right, it was kind of like by accident to me. I started my career with IBM. So  just the whole software development, security topic was fascinating. When I came across the industrial domain, it was basically the intersection of  the stuff that runs the world and cyber security. And so I just became fascinated by that topic. And this is how I ended up just getting into it more and more, and eventually co-founding Claroty.

    AA: So Claroty has sort of established itself as sort of a thought leader and sort of a category creator in this industrial control systems and SCADA systems. For somebody who is as immersed in that world, what's sort of happening there for people who, if they haven't been reading all of the hacker news?

    GA:  Well I think that what happened over the last few years really allowed for the industry to become a real market opportunity. The thing that is not new and that is not easy to change is the security posture of those industrial control system environments. So, in the office environment, we're used to kind of changing our laptops every couple of years. You can't really do that in the industrial control system environment.

    The lifecycle of those machines is 35, sometimes 40 years, and so we can't just rip and replace. So, you've got to work with existing infrastructure that, when that infrastructure was designed, security wasn't really an key requirement. That hasn't changed and that's kind of like the one of the sources of the problem.

    What has changed rapidly over the last few years is actually how interconnected those systems are. When the first POCs were designed, they weren't actually meant to be connected to non-control networks. So the fact that we've got everything on networks now means that everything is interconnected so therefore, no “air gaps.” So you've got to find a way of actually monitoring that environment.

    The third thing that has also changed significantly in the last couple of years, is that in terms of the threat landscape, first of all, I think a lot of folks have realized that those networks are critical; they are more valuable. Downtime can cost millions and an attack can damage expensive equipment or harm people.  Once an attacker actually gets into the OT networks, from there on, they don't really need to exploit new or know vulnerabilities to cause damage. They can simply send legitimate commands, just leveraging the existing infrastructure and the existing commands to make changes to the process that can be catastrophic.

    So the threat landscape, together with “insecure by design” industrial control systems, is what is actually creating the opportunity.

    AA: Yeah, the sort of ability to really to cause physical harm is literally -

    GA:  Exactly. The impact is completely different than that in the IT domain.

    AA: Yeah, and to sort of looking at the backdrop against the security, which you're looking to improve, obviously if you've been in this space you've heard of Stuxnet; maybe you heard about kind of what was happening in Saudi Arabia, where things were happening with Saudi Aramco; maybe some of the other stuff that happened with WannaCry. For someone who is just coming to this space, how do you see this increase of threat level, particularly like the involvement ... Attribution is always hard but potentially nation states fall apart.

    GA:  No, I'm not going to talk about attribution, because nowadays it is almost impossible to do. There are so many sophisticated ways in which you can do a false flag, so I'll leave that for other hosts to discuss. But really at the core of the issue is the fact that those networks are really, really, really valuable. Valuable in many different ways. Valuable because they could be used to cause physical damage; valuable because in many cases they actually hold some of the IP of those companies, for example the way a chemical company produces things.

    So from that perspective, people will be people. I mean bad people will have interest in attacking industrial networks. Now it doesn't necessarily have to be a nation-state. There is “weaponized” malware available in the wild, so think of terrorists, think of all kinds of crazy people with agendas. I think what was proven over the last few years, starting with Stuxnet, is that it is possible to manipulate those networks. For many of those large companies, that had been the wake-up call, that industrial control systems could actually be manipulated so that it broke the process or equipment or could harm people.

    AA: And when you think about essentially the security that you're layering on to their systems, is it in many cases just sort of a mirroring of what has happened on the more traditional IT systems? Like are you essentially just taking those models and those processes and those tools and essentially adapting them to the other side?

    GA:  We're trying to do the complete opposite. And this goes against probably every kind of common sense advice that you would hear in the cyber security industry. But basically there is about a 10 year gap in the cyber security posture of IT networks and industrial networks. And so if we repeat the same cycle, it's not going to get us anywhere. What we try to do with our technology is get to the end result, not necessarily by applying the same security controls, because many of those security controls will not be relevant.

    For example, something as simple and in many cases useless as anti-virus, is not even something that you can deploy on a controller because of the warranty issue. That's a real-time machine.

    I don't need anti-virus on the controllers and I don't need some of the other measures that do not give me what I'm looking for, and are destructive to the network. So, what we've done is our approach is a completely passive data acquisition approach. We read the networks so we're transparent. That also means that the attackers cannot see us on the network. But because of the ability in which we understand those networks, and the protocols that are running those networks, we're basically able to detect the very first steps the attackers make. In cyber terms, we are able to detect attackers at the earliest stages of the “kill chain” so that we can stop them before they progress.

    It's a different way of approaching the problem.

    AA: Very cool. And essentially then, who ever is managing your system for a company is then able to, once they've been alerted that there may be an issue, do you guys get involved in sort of remediation or understanding what to do?  What's that next step?

    GA:  Yeah, first of all for industrial control system networks, the ability to be able to see that something wrong is going on, it's a huge impact. Because right now the security teams are going into those networks completely blind. And if you look at any of the sophisticated attacks, I mean attackers were on those networks months, so that initial detection is kind of extremely key.

    In terms of the remediation, it depends on what level of the network. So if something is detected at the really lower levels of the network, where the controllers actually operate the physical process, no one should automatically block traffic from an automatic technology prospective. That needs to be handled in a more manual way, otherwise you can break the operational process or cause a real safety issue.

    If we see something from a higher level of the network, from the IT domain, then yes, absolutely. We actually integrate our technology with other security technologies that are able to then take action, based on that information and intelligence.

    AA: Very cool. As you think about some of the systems that you're getting involved with, they really are literally critical infrastructure. It’s power plants and those sorts of things. How in that landscape, what do you see in terms of the interaction between both technology providers like yourself, industry, as well as sort of the government sector as well? Is there collaboration that's happening or is it really very silo separate?

    GA:  Well there is some collaboration but it's really hard to rely on the government or rely on a standard body, to kind of tell you what to do. I have a lot of respect for, and actually we're workingwith a lot of advisors centered around standard bodies. But standards creation and implementation take a long time and threat actors change tactics very quickly. And so we are creating a completely new paradigm of how to actually address the threat now.

    When it comes to governments involvement with standards, I think that a lot of the large companies have just taken that into their own hands, because the government can really interfere with some of those attacks. And as you mentioned, early attribution is really hard.

    AA: Yeah. Sort of switching gears, in terms of some of those major industrial players, I saw that you guy had some big partnerships recently. Schneider Electric.

    GA:  Schneider Electric, and also Rockwell Automation. Yeah.

    AA: Walk me through kind of like that process and what that was like and what that's sort of been able -

    GA:  It's a very long process because they go through a lot of checks now. But it's a great working relationship with all in industrial control system vendors that we're working with. First of all, I think that for us, it’s great to get the validation from them, that our technology works as intended and that it's not disrupting the industrial processes their customers are running, which is huge.

    And secondly, they also leverage our technology to go to market, because in a real-world scenario, whether you're and oil gas company or a large manufacturer, you don't just have one industrial control system, it’s better if you have all of them. And so our technology cuts across all of them, and so all of those partners can actually take this as a component and plug us into whatever cybersecurity offering they may have.

    AA: I mean it's a related question, but as you think about getting installed in major systems, large corporates, you potentially begin to become a threat back to yourself, right, if you have access? So how do you handle those concerns?

    GA:  Good question.

    So one of the things that I mentioned is with our passive technology, we are actually completely out of band on the industrial network. So we don't exist to the attacker. The attacker would not see us as an IP on the network, etc. We're in stealth, so to speak in the network itself.

    Now of course we go through the regular and kind of rigorous security testing in our own lab and have third parties audit our own technology. But the biggest thing is we're actually passive, we sit on a SPAN port, not inside the OT network and not installed on the systems within the network. So we don’t provide an attack vector for bad guys.

    AA: So you're outside.

    GA:  Yeah.

    AA: Great. We've been covering a lot of stuff. Anything you want to go over specifically to talk about? Is there anything that you're like, "I've been waiting to sort of tell people about?"

    GA:  No.

    AA: Okay. Maybe in general sort of the IoT space, we've all seen the graph, like the number of devices and then it looks like a good investment return, right? Hockey stick. How do you think about that? Does that scare you? Does that excite you? Like there is just going to be everybody buying our stuff. From your perspective, how do you think about sort of a more connected world?

    GA:  Good question and actually I do want to say something now. It's actually a great thing that you guys are covering industrial cyber security. It’s been kind of like such an isolated domain, so to speak, that even amongst the overall cyber security industry it has been kind of isolated. So part of what we're trying to do is bring it into  mainstream cyber security so that folks talk about it. For example, at the last DEFCON we did a workshop on ICS together with some of the partners.We’re educating the overall cyber security industry.

    Now that kind of translates into your question about IoT. So IoT is everything. People can think of it as the networks that are running in nuclear power plants and then the intelligence in my toaster. So it's not really the same; there is a huge difference between what IoT is.

    AA: Hopefully a different, more sophisticated system.

    GA:  The way I think about it is that you cannot stop it. The interconnectivity is a good thing if you can actually leverage the power that that gives you. But you can't stop it, right? So the initial push back against security technologies in the ICS domain, was because we're just going to air gap them. Well, it's not practically possible and it's kind of the same thing with the IoT-- you are deploying sensors everywhere in your plant and leveraging that data for all sorts of things.

    So I would say, for me, it's very exciting, because when everything is connected and everything is talking to each other, you can do so much more in terms of orchestration in how things flow. That being said, the more we think about security as a priority, and we bake it into the process, the better we'll be off. So it's a fact, you can't really change it.

    AA: I mean gosh, having not been involved in industrial control systems to the level that you have, I sort of read about them from afar. But gosh, I didn't realize that the lifecycle was really 35-40 years, that long.

    Are you seeing now that maybe the treat, the understanding of the potential threats is increasing -- at least vendors and people who are involved are starting to think about building systems?

    GA:  Oh they started that a long time ago. A few years ago, all of the ICS vendors already started being much more open about their vulnerabilities and how they cover them. But again you’ve got to think through the timeline of that, right? So okay, you're getting really serious about improving your security postures, so you started the design of your next controller. That design phase itself, in most cases, is a five year process. And then you launch it on the market and that doesn't mean that the large multinationals are going to go and rip and replace the billions of dollars of infrastructure that they have invested. It might be another 15 years before they actually have to operate.

    So that being said, just last week I just came from  probably one of the best, certainly the most technical, ICS cyber security conference in the industry,  S4X18 in Miami. And what we saw there was Schneider Electric talking openly about the recent incident on the Triconic safety system, which was just absolutely admirable. The fact that they're so transparent about that, engaging with the community is something that would not have happened 7-8 years ago.

    So the fact that we're seeing vendors not just increase proactively their security, but being very open with the industry is a huge, huge step forward.

    AA: Yeah, it is. A sea change in a community when there are problems that everyone has quietly known exists, suddenly -

    GA: You might as well be upfront about it and show and tell the community what you're doing about it and how you're solving it.

    AA: Yeah, sunshine cures a lot of ills for sure.

    The session that you're in, you've made one of the best quotes I've ever heard, which was that, "Air gaps are like unicorns; lots of people talk about them, but we're not sure that we've ever actually seen one."

    GA:  Especially in industrial control systems.

    AA: Oh, that's hilarious.

    So in general and part of the reason that this publication exists is, a lot of people talk about the problems, like what's wrong. And it's easy as a community whenever anybody's system goes down, pretty quickly that person get tarred and feathered. So we always try and talk about the positive, an actual focus on solutions. So what's working and who is doing a good job? Who is admirable right now? Whether that's yourself or partners or companies that you work with. You do not need to name names.

    GA:  Actually, I'll take it from a different perspective. I think that one of the biggest changes that kind of enabled our industry to even exist is the fact that board-level members started paying attention and actually understanding what does it mean if they don't have cyber security for the industrial networks. So seeing that awareness at the board level, and then the board members asking the CEO, and then the CIO, to actually do something about it, creates the budget, which means that now we can actually solve the problem.

    No problem is unsolvable, you just have to have kind of like a focus on it. I think that most of the large Fortune 500 companies that have industrial networks, and the vast majority of them do, even if it's not things that we think about. I mean this building has HVAC, and elevators and lighting; all of that is ICS, right?

    So I think that the boards have done a really good job of asking the right questions. I think that specifically after Wannacry and NotPetya, when the security teams realized that, even though they're not targeted, some of that stuff can get into the shop floor. I think that was a huge wake-up call. And so we've seen quite a lot of interest after that. I think the security teams are also doing a good job of just asking practically, what they can do better in their networks.

    AA: Some sort of quiet, stunning headlines after that, in terms of like what Maersk is saying they potentially lost.

    GA:  And that was just the tip of the iceberg. That was just really a very small fraction of what actually happened behind the scene.

    AA: We're really curious what happens, kind of post GDP on, because I think maybe some changes before that, but just in terms of the disclosure requirements and timing. We just see a flood of more information come out because they're worried about otherwise getting huge [inaudible 00:18:43].

    This has been great, just to sort of switch gears for a little bit. For people in the industry, what are you reading? What are you following? How do you kind of stay up?

    GA: Good question. Every once in a while I try to read stuff that's not related to cyber security. Which you know, I kind of have to remind myself, because I think what kind of the time that we live in right now is so fascinating, and there is so much that could be done, that it just kind of keeps me up to date.

    I actually talk to people. I'm privileged to have access to a lot of the smartest folks in cyber security, both on the technical side as well as the issues that they are facing; it’s just a tremendous challenges. What I tell a lot of my clients is that I never want to have their jobs because they have to be good all of the time and attackers just need to be good once an a while.

    But I also work with some of the smartest folks that come from an offensive cyber background. And so a lot of exciting things on just how we think about technology and what we can do with technology. I try to talk to people, because otherwise there is just too much hype in the media, no offense but, right? There is just a lot of hype, especially when it comes to critical infrastructure and those control systems, because the general public does not understand it that well, and usually we see headlines of like the world's exploding or the US grid is going to come down, or something like that.

    AA: If it bleeds, it leads, right?

    GA:  Exactly.

    AA: Cool. Yeah.  I mean that's most of what I wanted to cover. I mean thank you.

    GA:  Wait well thank you for getting into that topic of international cyber security. Like I said, we need more education, not just for the general public, even for the folks that understand cyber in general really well. That's kind of a new domain.

    AA: If people wanted to kind of check out any of your stuff, or see sort of what you're doing, where would you have them go?

    GA:  I think I’ve got most of the things that I write on Linkedin so probably they can check my page

    AA: Thank you so much.

     

     

    22 min
  • Focusing on What Matters an Interview with Justin Berman CISO of Zenefits

    Key Points From This Episode:
    Justin’s studies, consulting work and path to his current role at Zenefits.
    Calculating risk return for defense and attack and how Justin approaches this.
    Why better general security at other companies benefits everyone.
    Justin’s approach to defending against advanced persistent threats.
    Why security needs to talk more about the less sexy sides of their work.
    The hottest new strategies and technologies according to Justin.
    The role and appropriate time for automation within a security protocol.
    Zenefits' ambition for their security and how far this extends.
    The role of CISOs in the conversation about security within a company.
    Cultural change at companies and how this leads to sustainable security.
    The difficulty in hiring currently within the security sector.
    And much more!
    Links Mentioned in Today’s Episode:
    Justin Berman Website — http://www.justinbermanphotography.com/
    Justin Berman on Linkedin — https://www.linkedin.com/in/jmberman
    Justin Berman on Twitter — https://twitter.com/justinmberman?lang=en
    Zenefits — https://www.zenefits.com/
    FS ISAC — https://www.fsisac.com/
    Phantom — https://www.phantom.us/
    Equifax — https://techcrunch.com/tag/equifax-hack/

    35 min
  • Deception as A Strategy An Interview with Rick Moy from Acalvio
     
     
    Deception as A Strategy
    An Interview with Rick Moy from Acalvio

    Well Rick, thanks for joining us. Just introduce yourself.

    My name is Rick Moy. I'm the chief marketing officer at a company called Acalvio Technologies. We are a Deception 2.0 company. We are creating a distributed deception platform that brings automated deceptions at scale and authenticity to organizations of any size. The goals is to make it easy to manage, deploy, and implement deception strategies in the network in order to do a better job of detecting attackers who have gotten past the prevention that is deployed on the perimeter and on the endpoints.

     Yeah. Such a great background and experience and fit for some of the conversations that we've been having. We're seeing the realization in the market that static systems aren't secure, they're just not. If an attacker can see what you're doing, they're going to be able to penetrate it.

    I know you guys have been around a while. Walk through where Deception and changes have happened. What that history looks like.

    Yeah. Well, so first of all, to set the context like I talked about in my talk this morning, deception has been around for a long time. It exists in nature. You have the Venus Flytrap, the angler fish, you think of those fun things. So, nature's got them. We've used deception in warfare, kinetically, so military use smokescreens, false retreats, fake units, right, during D-Day, we created some inflatable tanks to fool the Germans.

    In cyber, it really started around 1989 with the German attacker who was breaking into Lawrence Livermore. A guy named Cliff Stoll is one of the first documented deception campaigns, where he actually created fake systems, fake files, and even fake departments logically in the company, and a fake secretary who he gave an account on the system in order to mislead the attacker. So, deception is part of our world, whether we realize it or not.

    Attackers use deception against us in phishing campaigns, in malware, polymorphic malware. We use deception to sinkhole botnets. We use it to gather threat intelligence externally. The field of honeypots, which most people think about, has been around for 20 years, and that's great. A lot of open source, community level projects. It solves a certain problem, but the change we've noticed over the last few years is that making those enterprise ready, right. What does that mean? No one has time to manage another platform. It takes time to figure out well what kind of campaign do I want to run. There's some manual effort required.

    The new phase of deception, we call Deception 2.0 has a couple key principals. It's got to be manageable. It's got to be automated. It's got to be authentic. It's got to interoperate with your existing infrastructure fabric. All those things have to be true. That's really only become viable within the last 12, 18 months I would say. There's a lot of Deception offerings that I call more point products. They solve a specific part of the problem, but they aren't as fluid and dynamic as the modern enterprise would like. Keep in mind, developers have been talking about Devops for five years or so now, so that's really become part of the mantra within the CIOs organization. We've gotta be Agile. We've got to adapt to a digital transformation, that's still ongoing.

    Yeah. You brought up so many good things there. I think that pain point that you talk about where you're already seeing 10,000 threats a day, maybe a million incidents a day, and if you were going to create another system where you're going to create even more incidents. You already are overwhelmed. The idea of how do I handle more when I'm already drinking from the fire hose. How do you guys, both your own technology but what do you see in the market in terms of that filtering, that understanding what is noise on the network and what is the really high-risk elements.

    That's perfect, right. It's true. There's organizations I've worked with that get millions of alerts a day. That's exactly the problem with the prevention or traditional detection type of technology. Where deception comes in is really a great blessing for the organizations. It's a totally different philosophy.

    With prevention you're trying to find the bad guy hiding in the crowd. With deception, you've set out fake assets, decoys that will attract them. By definition, anyone whose interacting with that decoy is not following business process. If they're an employee, they're not following the business process. If they're an attacker, they're looking for some data to either steal or ransom back to you.

    “Deception 2.0 has a couple key principals. It’s got to be manageable. It’s got to be automated. It’s got to be authentic. It’s got to interoperate with your existing infrastructure fabric. ”
    — Rick Moy

    The definition of deception is it gives you high-fidelity alerts, so a very small number of them because, in general, they don't occur very often. They're designed specifically to detect lateral movement. Someone who has gotten a foothold on a workstation or a server inside an organization is now trying to pivot and find some of that important treasure to, again, steal or ransom back to you. By doing that, trying to figure out what machines are next to me, what services are in the environment, how do I connect to them ... all those activities could potentially reveal their existence if they connect to them. That's where we come in. Deception's a great compliment to a very noisy existing infrastructure that most organizations already have set up. These two things can be complimentary and used together.

    Yeah. When you think about when you're creating a network and, essentially, trying to replicate something that looks like your existing environment and putting assets there. How do you do that in a way that's efficient, easy, and that also is believable to an attacker. In many cases, sadly, a lot of organizations don't even know what their network looks like and what's on it. How do you stand one up that's an image of it, a copy of it, that's real ... at least real enough to an attacker?

    That's a great question. That's exactly one of the shortcomings of the previous generations of honeypot technologies. Modern approaches will allow admins and organizations to use gold images.

    You can take systems that are actually deployed, dirty images. We call them gold, but a lot of them call them their copper or pewter or their fairly tarnished. They're not necessarily a precious thing. That's exactly what you want. You want to replicate and mimic the actual systems in your environment. If it's too clean, it's going to be suspicious. If it's too locked down, it's probably not going to be a good lure for an attacker. It needs to have the same kinds of flaws that your other systems have.

    Not to get too technical because we have an audience that spans the range from security professionals to individuals who are tangentially involved, but can you dig in a little bit to one layer deeper in terms of how you do that? Is that done through virtual machines? What's the way you deploy a network?

    To be honest, there are some that are out of the box that are just standard. There's a whole matrix of different types of deceptions you can deploy. Out of the box, you would get some basic things like SMB file shares, certain Windows operating versions, Windows 7, Windows 8, and Windows 10, Server 2012, etc. Those generally we provide. Others can be virtualized or containerized. We call it in our lingo, "service reflection."  The process of wrapping an image that's already in production and then mimicking its existence on different VLANs. We have technology that really simplifies that. It's all about making it easy for an organization to roll out a deception campaign.

    So you're deploying stuff both on prem as well as in the cloud? How is the deployment typically?

    “There’s a certain investigative, James Bond nature to it ... what’s going on, who’s inside the castle walls, what information do I have, how can we lay some traps to have that person reveal themselves. ”
    — Rick Moy

    Acalvio is a cloud first company. Everything we design is meant for organizations who are going to be moving to the cloud or deploying from the cloud. That same engineering discipline allows us to deploy cloud-ready apps on premises in a very efficient DevOps manner. We've done the design for the hard stuff first, but are also deployable on prem.

    Where are things going? What's new? What do you think people should be really excited and trying out in this phase? What's cutting edge in deception right now?

    Cutting edge, I'd have to say it's probably the boring part of just making it operational. A couple of years ago, cutting edge was putting up a lone honeypot on the outside of your network and getting external threat intelligence. Well, that's something that a lot of people know. If you put something on the outside of your network, within about 5 minutes, you're going to start getting attacked, right?

    What's really critically important to the organization, as well as kind of fun I think and so maybe this is the definition of cutting edge, is finding the bad guys who are already inside your network. There's a certain investigative, James Bond nature to it ... what's going on, who's inside the castle walls, what information do I have, how can we lay some traps to have that person reveal themselves. You get into this detective mode, and you start to think well what tools do I have to do that. There really isn't anything more exciting in my mind than the deception arsenal of tools that you have.

    The honeypot is your actual server, you can put services out there that maybe just like a FTP service, which was used, for example, in the Sony hack. File sharing ... you can put fake spreadsheets out there. You can have false, misleading data in database servers that would, if that data was ever used in public you would know that you had been breached. There's really creative ways that you can think about marking content that if it's touched or used somewhere else will be an indicator. It really forces you, as the security guy, to think a little more holistically about what business are we in. Are we in healthcare ... is it patient records? Are we financial services ... is it bank account information? Are we a R & D shop designing semiconductors, so then it may be IP around a particular laser etching technology or layout of a microprocessor. I would want to have different strategies around each of those. That's what's interesting, and frankly invigorating, for a security person who maybe last week their top priority was applying a patch or responding to some malware on Jane's computer. Now he gets to think more strategically about the business and the threats that it faces. It's something that's typically reserved for the C-level suite, but in reality it's the people who are hands-on that have to implement that.

     I think it's a great opportunity from many perspectives.

    Sounds very cool. As people are thinking about adding deception to their strategies, what would you say is the best way to climb the curve, to educate themselves? Are there some resources out there? Are there some books they should check out? What sort of way to get involved there?

    Actually it's a great question. It's almost a setup. We actually have a couple of books that we've written.

    Cool.

    You can go on Amazon. There's a couple historical books you can look at. The Cuckoo's Egg is one. Kevin Mitnick has written a book about deception.

    We have two free books. One's a Dummies book, Deception for Dummies. It's a very short read. It's actually quite entertaining.

    You don't have to be a dummy. It does a really good job of explaining it. Then we have an advanced field guide for the advanced practitioner whose had more experience with some honeypot technologies.

    Awesome. Thanks for taking the time. This is your opportunity if you've got a soap box ... what would you like the community to know if you had 30 seconds, a minute, to say, "Gosh, you know you really need to be thinking about this."

     I would encourage the community to recognize that deception is all around us. We use it every day, and it's used against us every day, whether it's in advertising, social relationships, and in cyber it's used. Let’s use deception to change the dynamics.  The attackers are using automation and forcing us to do manual review of the problems they've created. Deception is the only platform that allows us to lie back to the attacker and change that dynamic and make them do some work.

    From that perspective, when you look at the technologies at your disposal ... huge points for that. When you also consider that it's lower cost to deploy than a number of other technologies and more effective and lower noise, there's a lot of reasons to look at it. I'd encourage people to have an open mind and to read up on what Gartner says is the number three of the top technologies for the next year.

    Yeah. Awesome. This is great. Thanks so much.

    Thanks for the time.

     

     

    16 min
  • What The Future Of The Internet Looks Like and How We Can Secure It Humanely - An Interview with Andrea Little Limbago, Chief Social Scientist at Endgame
    Key Points From This Episode:

    Andrea's journey from academia to cyber security.
    Why cyber security is also a retention challenge.
    How companies can protect their employees from burnout.
    What happened to the utopian idea of the internet?
    State sovereignty and the balkanize internet or splinter net.
    The implications of China’s new social credit system.
    Learn more about GDPR and the control over your own data.
    Does Russia’s internet look different to the rest of the internet?
    The effects of the crypto currency movement on cyber security.
    Learn more about the Russia-China authoritarian model.
    Will GDPR be successful in helping democracies move forward?
    Discover what Endgame does and how it operates on a daily basis.
    Find out what it’s like being a woman in cyber security today.
    Fake news and cyber hacks and their effect on the political climate.
    And much more!

    27 min
  • The Current State Of Protecting Industrial Systems and Safeguarding Civilization Today-An Interview with Joe Slowik, Adversary Hunter at Dragos

    Key Points From This Episode:

     

    •    Learn more about Joe Slowik and his non-traditional CS Background.

    •    Joe gives his overview of the current thought around industrial controls.

    •    Find out how we defend industrial control systems today.

    •    How can attacks be actualized to impact an ICS environment?

    •    Script locking and reevaluating credential storage and credential use.

    •    Adopting a strategic perspective and designing network defense.

    •    Discover more about the Perdue model and what this means for defense.

    •    Tackling the misconception that the attacker only needs to get it right once.

    •    Who are getting industrial control systems right and what to aspire to.

    •    Why we need to develop a more analytical approach to threat behavior.

    •    How to empower individuals to respond and react to threats as they arise.

    •    Learn more about the Dragos company motto of safeguarding civilization.

    •    And much more!

    28 min
  • Uncle Sam is Learning New Tricks - An Interview with Steve Orrin, CTO of Intel Federal
    Uncle Sam is Learning New Tricks
    An interview with Steve Orrin CTO of Intel Federal
    Full Transcript of the Interview

    In this interview, we talk with Steve Orrin, CTO of Intel Federal and take a deep dive into how government agencies are speeding up and changing their process for adopting new technology

    Well, Steve just introduce yourself, your name, where you’re from, company, those sort of things.

    Sure. I’m Steve Orrin. I’m the Federal Chief Technologist for Intel Corporation. I drive our strategy, direction and technologies working with the government, as well as helping the government work with Intel.

    Awesome. Everybody seems to have ended up in the world of security in a unique way. What was your path into this space?

    I started out as a research biologist going all the way back and was going to do something in that field. Then had an interesting idea back in ’95 and did my first security startup, before going to med school. The rest is as they say history.

    Med school, I trust never really happened.

    Never happened. I did about four security startups throughout the 90s and early 2000s. Then one of them got acquired by Intel, which is how I ended up here back in 2005. It’s interesting, the two benefits of having not come from a classic CS or EE background is I don’t assume that things work in a certain way, because I wasn’t taught that that is the way it has to be.

    In many cases, it also has helped being able to translate what we’re doing in cyber security and security in general to audiences that don’t have that background. Working on within healthcare organizations or on HIPAA and understanding how the security technologies help, I can speak their language. Now with things like the genetics research and AI being applied to it, being able to translate – be the translation function, having some of that background has really helped be able to communicate to multiple domains.

    Yeah. I bet that biology background is the interplay of complicated systems

    Absolutely. We’ve seen examples of where they – computer systems are being compared to biological systems. Now in the current world, Neuromorphic computing and brain neuroscience has brought it back to the fore. We’re seeing modeling chips after brain activity, so it comes back to haunt you on a regular basis.

    We certainly steal the terminology viruses and malware and all these sorts of things, right? That’s interesting. One of the things that – I’ve seen you talk about is that you’re thinking about defining the problems that some of the organizations that you work with and those tend to be – your focus is really government and particularly the federal government, and bridging that gap between the problems that they have and the new technology that’s either out there, or potentially coming down the pike. How does that process work?

    Well, I think it’s part of how we’ve approached the industry for a long time is the problem solving. Really, what it starts with is listening. Spending time with the customers, spending time with the various agencies and the ecosystem that supports them to understand what they’re trying to do, some of the challenges they’re facing, some of the areas both today, the problems they’re facing, or also where they want to go.

    In the government space especially, they design things well in advance of actually building them. Getting a feel for what they’re actually trying to achieve and talking to multiple customers. What’s happening in one agency maybe slightly different than another, but you can find those common themes.

    Then understanding the breadth of the technologies both from security obviously, but also from just the – whether be compute capabilities, networking, data analytics and artificial intelligence, and piecing together and saying, “You know what? If I bought something from over here and used this system here in this way, we can actually solve not only the problem that this one agency is having, but the commonality that we’re seeing across multiple agencies.”

    Really, the nice thing about the working with the government, a lot of times they’re a vanguard for the broader industry. A challenge that the government sees today with a drone, or with a compute system is something that the banks, healthcare, industrial are going to see, or are already seeing, but don’t necessarily know that they have the problem yet.

    “In the government space especially, they design things well in advance of actually building them. Getting a feel for what they’re actually trying to achieve and talking to multiple customers. What’s happening in one agency maybe slightly different than another, but you can find those common themes.”
    — Steve Orrin

    We can use those requirements and bring them to the broader commercial space. That’s been the step around that for a long time. One of the big changes that we’re also seeing is the government are willing to take commercial systems. As opposed to being – everything has to be special for the government. You’re looking more at how do we take what’s already working and scaling in commercial, or even consumer use cases. Take 80% of that and do the federalization for the last 20% to harden it, or to make it work in that mission context.

    As we’re seeing there’s a two-way street now that we haven’t seen for a long time. Adapting technologies that are more readily available and quicker time to deployment, but also helping to drive the commercial to get better security, get better performance.

    Yeah. Particularly in security, I mean it seems like the flow of individuals and ideas is also between government, academia and private industry is more fluid compared to other spheres. There is a lot of the funding might be coming from different portions and the people working in them.

    We’re seeing a lot more of the – whether you call it government industry collaboration, government industry academic collaborations of funding going through universities to commercial entities. We’re seeing that both on the engagement on ideas, but also on the actual funding of projects. I think a lot of these is because of the recognition that good ideas can come from anywhere and it doesn’t need to be a 20-year program to get us to something usable.

    Yeah. I mean, we’ve encountered certainly you’ve seen the wish list come out of an agency, “Okay, we’re looking for potential solutions here.” How is that? Who is going to realize that and where that might come from, from academia or academia morphs into private industry, those sorts of things?

    We’re seeing a lot more of private industry sort of separate into two buckets. The big companies like Intel and Microsoft and Amazon and others have a focus on federal and engaging with the commercial capabilities. But also bringing in the smaller companies. There’s a lot more vehicles or contracts available for small companies to get involved. There is organizations like DIUX and others that are specifically tasked with go find those innovative companies and help bring them into the DOD.

    Then there are really companies, a couple of them in the valley that provide training courses. How can your startup learn how to work with the government? We’re seeing a lot more of the investment, because we can’t wait for some lab to come up with the next big thing. From the government’s perspective, they have needs today. They want to be able to do what Silicon Valley does, what New York is doing for the business, the high-speed transaction processing is needed as well. You’re seeing a lot more openness to engage. I think we’re seeing them from both sides.

    One of the areas I think that I know you’ve spoken about in the past is – it’s tied in with those issues is the movement to the cloud and sort of whether you’re putting resources, or data out there and how that process looks. For someone who is not as deeply meshed in that space, walk through some of the challenges, as well as sort of opportunities there.

    The cloud presented some very interesting challenges for the government. Most people think, well of course the security problem. Yes, that was a huge problem on how do we secure the cloud? How do you get apply the security controls for data protection, for system, the regulations around the stakes and so forth. How do you deploy to an environment we don’t control, you don’t own it?

    Some of the early stages were hosted private clouds. That’s still important part of the puzzle, but I think part of what changed with things like FEDRamp and others to help make it easy for Cloud providers to provide that. The biggest challenge especially in the early days wasn’t the technology and wasn’t the security. It as the contractual capability.

    Typically you buy a thing. I want to buy a phone. You can’t buy a cloud. Idea of a subscription model, or buying services was not something that – then being able to deploy it through the process. Also when the government wants to buy something, it’s not just why I purchase this. There is an accreditation process and there is authority to operate. Those are documentations, certifications and test that have to be done. If I did it once for one agency and then I was going to go sell my product or widget to another, start over from scratch. I can use the documents, but I have to go through that process again. That doesn’t work in a cloud model.

    In Federal now we provide a framework for the security controls, but also for the contractual mechanisms to enable the adoption of services. That was a key of change that help the governments start to adopt. It also gave the com providers the means to figure out how they could take their cloud and make it a GovCloud, or Azure for government on these other things.

    “In Federal now we provide a framework for the security controls, but also for the contractual mechanisms to enable the adoption of services. That was a key of change that help the governments start to adopt.”
    — Steve Orrin

    That worked for the civilian. It worked really well and we’re seeing a lot of adoption by civilian agencies into the cloud and state local of course. But then you start looking at things like DOD, which have a higher level of security requirement and the separation and segmentation requirements. That required a little bit different engineering on the cloud provider side. I think the opportunity with making up that we’ve seen the GovCloud, we’ve seen the Amazon C2S and other implementations that where the cloud providers have done that extra mile and area going through it to get the classifications and clearances they need.

    It’s been a two-way street on that. There’s still some fundamental challenges. You have this notion of I want to be able to protect my data independent of we’re living. I need to be able to apply my security controls into an environment that I no longer control. Even in the hosted, you still could go point to there’s that data center and that data center I have my people sitting there and operating on it. When you have shared services, we have figuring out how do I still get that level of security control and visibility with a fundamental challenge.

    This is why things I worked on for a number of years is being able to use that physical hardware capabilities and be able to implement that into the virtual and cloud domain as we bridge that gap to give you this ability, give you – their term, or uses that to station to the environment before you deliver your workload, or your data.

    That was another key change that once that got adopted enable people to be more comfortable with these models. We won’t see DOD throwing everything into a public cloud. That is what happened. The notion of a hybrid cloud and the thing able to have data in a specific community clouds and things is definitely happening already and will continue to do so.

    The next challenge will be as they look to that next stack, so PAS, SAS, function as a service presents unique challenges that they have to be worked through. Because again, even in a infrastructure I still have a thing that I can fill my software load as a gold disk I can put out there. This is my database. I know where it is. When you distribute that across multiple services, across multiple systems, again it’s another area of how do I then wrap that with the self-controls.

    A related question and I’m curious, because this isn’t an area that we’ve had as many conversations about and thinking about is – an agency, if your fed ramp or more on the DOD side has vetted the environment of one of the major cloud providers, right? AWS, or Azure or whatnot, do you then have the opportunity for some of the smaller startups to piggyback on that work that’s already taken place?

    Hey, I have my SAS solution. It normally runs in an AWS environment. Can I then deploy it? You federal agency are comfortable with that. Can I then create essentially a private deployment, the spoke deployment of that in that environment, then I don’t have to go through all the hoops and whatnot?

    I can give you really two good examples. One is when we worked with IBM Federal with IBM Softlayer –

    Working with theCloud provider and then being able to build and bring in to companies like Hytrust that provides access control and policy control and data encryption. Being able to have that one in that environment is part of a service that can be provided to the tenants, to the government customers.

    In that case, it was picking very specific set of ecosystem vendors and building them in is part of that offering. Then you see others, we see this in Amazon and Google and others of where – if the application from that SAS provider passes the appropriate security, because they still need to have the security control in your system, then there is an easy migration path to go from the public cloud, assuming you have a government agency that’s going to sponsor it, or you meet the certain level of bare-minimum requirements.

    We’re seeing – I don’t think it advertises the Amazon marketplace for GovCloud, but there’s an Amazon marketplace for GovCloud, as well as for Google and others, where ecosystem environments that have done the security controls and have gone through that certification process can now run on that infrastructure and provide their services to government customers as well. It comes from both directions, either a ecosystem and I want to get into the GovCloud, or wants to have their product run for government. They go through the heavy-lift. Or you see an agency and say, “I need this product.” And they Work with them to help get them there.

    Yeah. Then you know the checklist of what you need to do just becomes a lot shorter. There’s still a checklist, but it’s not a 100, it’s 10.

    Exactly. The other thing is you can ride on top of the fact that you’re running on the FedRamp clouds. You don’t have to go into a re-inspection. You can leverage that certification and then authority to operate.

    Yeah, very cool. In talking through this and you touched upon it a little bit, thinking about bridging the digital security and the physical security. How are those two worlds coming together and maybe trying to improve each other?

    There are a couple of really good examples of this. One is around root of trust and being able to measure and then attest to the measurements. That’s being able to use the physical hardware in an environment to securely boot the system and to then attest to that secure boot and wrap that up in a quote as we call it, that then can be used by the virtualization infrastructure by the Cloud management&  policy infrastructure and set to go to look and say, “Before I provision this workload to that particular server, or to that group or cluster of servers, I can attest to the security state, boot it in hardware and verify that prior to provisioning.”

    Or I’m going to encrypt something to an environment. I can verify that the key is protected in a hardware TPM and only will be decryptable on that system that it has security.  That’s a really good example of how those, from just being able to bridge the gap between physical and virtual.

    Another great example and this comes up a lot in the current regulations is sovereignty and geo-location. A data physically sits within a country, within a region. If you have certain regulations, whether it be some of your European Union regulation –

    GDPR.

    Or in the case of FISMA that it has to be based in the US, as well as other safe harbor things, you need to know not only is that system secure, but is in the location that it’s supposed to be for me to be able to do that work.

    Being able to get location tags embedded into a system and attestable, being able to hook up to some of those other systems, or the physical and then be able to communicate them across the digital as part of that attestation, so I know it’s a secure server, in Virginia in the Chantilly data center. Then be able to use that as a policy just like you would when you would say, “I want to only provision the systems that can handle this throughput and this capacity and have this memory.” You can now have these attributes of is the system reporting itself to be still secure? Is it in the correct geo-location, or is in the correct cluster for my policy and use that as just part of the migration or provisioning policies?

    We’re seeing that as again another linkage of the digital and virtual world. Where this gets more interesting is when you get out of the big data center side of cloud, you start looking at the tactical cloud and deployed clouds. There you’re looking at not only can I know that this cloud is secure in a rack sitting in some location in a closet, but also has anything changed on it that has been accessed? Be able to get that evidence from not just the actual software and the boot of that software, but from all the access points and all the touch points on that system. Is the firmware secure? Has it been upgraded? Again, it’s all part of the attestation to the physical and virtual state of a given system.

    Tied in there also encryption thinking about where is it encrypted? Is it encrypted in transit? Is it encrypted in rest? What are those?

    Does it have the capabilities to support the at rest, in-transit and now in use? Are the keys that are supporting that protected and verifiable?

    I know public – private key exchange is near and dear to your heart.

    Indeed.

    Awesome. Yeah, I think it’s interesting. A lot of the things that you have touched upon, kind of that understanding at the station of where the loads are, the servers are, the encryption piece, as well as control over the data, all of those factors or things we’re talking about every day. We spend a lot of time thinking about moving target defense and how – can you change your sort of network profile and make the attack service look different and change for an adversary? You couldn’t do that without a number of things that you talk about, understanding where things are, what is there, can we attest to them and then also are things encrypted?

    I think those technologies and being able to attest to the security state, physical location and the operational configuration are going to be essential for scaling those software-defined perimeter and dynamic defensive measures approaches. One of the key challenges is that it does thwart certain reconnaissance and attack vectors, but if you can’t manage something at scale then it doesn’t do you any good either.

    Be able to build in that I can make these changes and have a dynamic environment, but from a management from the good guy side of the gap, I can get that visibility, I can attest that this was the system and the configuration is what I deploy, even though that the port maybe changing, the IP, the services that where they’re hosted can be dynamic in moving around from a management perspective and security management perspective, I can get that visibility.

    It’s going to be how you then you’re going to get comfortable to scale that and operate that across multiple nodes. I think those two are going to work hand-in-hand. I see a lot of promise in this dynamic digital perimeter, especially it’s the idea of what it is you’re protecting has changed. It’s not longer, well I’ve got this big enterprise and I want to keep a hard shell on the outside, and then we talked about also there’s things coming through so I’m going to push it with defense in depth.

    Well, even defense in depth is really something that’s falling apart now when you have microservices and SAS, where it’s no longer even your perimeter to defend. Being able to have – not just have a dynamic or soft environment, but have a perimeter that moves with the application and with the data inside and out is ultimately how we’re going to try to solve some of the security challenges with the integrated and incorporated services.

    Yeah, and moves with the teams too, right?

    Exactly.

    That we often are talking with people and thinking about segmentation. It’s usually they’ve got three categories; untrusted, trusted and super trusted. Beyond that actually implementing things becomes really, really challenging.

    I think that the shift that we should be looking at is moving away from the walls of – again, it’s a hard change, but from people to networks to data-driven. At the end of the day, that’s what the attacker is after and that’s what’s important to the company is the access to and use of that data. The controls we deploy should be dependent on the data. The data should have those classifications, and then it’s just a mapping of the firewall, the network and the system to map to the data and we often call this data use controls. I think if we take a data centric approach, that will help us deal with this more dynamic environment, because data will live wherever it is and data wants to be free.

    Right. Are you starting to see that happen in practice? Are you starting to see either organizations and – in this business, you never name names, right? Or projects where they’re starting to really hone in on where is the data going and how are we protecting it, that sort of focus?

    We are definitely examining obviously things like GDPR and then past ones regulations as well – require people to really understand their data, understand what’s important, what’s PII, what’s the IP that I want to protect. At the same time, looking in the military and the government, we have things like classification levels.

    It’s always been there and I think the current state of the development of the architectures is really driving that we need to get better at how we manage the data life cycle. I think one of the things that will also help exacerbate that will be analytics, where the data – it’s a good thing. I know my data. I know I can create it there. What about the aggregate of that data, or the inferencing I got from that data?

    That really starts to stretch, “Well, I need to have better controls in metadata around that that I can then protect its access points.” At the same time, be able to get you access to the inference or to the aggregate without getting access to the data. I think those things are really getting people thinking differently.

    I think there’s a lot of good work that’s been done. I think we’re starting to see organizations get smart about how they do data use protections, controls and access. The answer isn’t just encrypt everything. That is part of it, but it’s also about how you encrypt it, where you encrypt it and how you decrypt it.

    I think it’s that full life cycle. It’s really the thing that’s going to help change. We are seeing a lot of folks in government and in the industry look hard and fast at how they’re working with data. Because of these, things like cloud, we have shared infrastructures and information sharing and shared analytics are really driving them, “Now we have to put with the better model.” Are looking at solutions, whether they’re coming from the enterprise side, or on ERM approaches, or looking more at the IoT space and looking at things that can be embedded and drive around. We’re seeing a lot of activity in that space.

    Yeah. I mean, I’m curious. We were having a lot of conversations and everyone is certainly talking about GDPR and trying to understand how it’s implemented. Curious in your experience is the – some of the conversations have basically people are thinking GDPR will in some ways become a worldwide standard, right? Because if you’re going to have to comply with what’s happening there, it’s crazy to maintain potentially other standards. Is that the thinking you’re hearing certainly from your conversations with our government, or whatnot?

    There are folks that would love to see one standard to rule them all.  Just have one thing to deal with. I don’t think that’s reality. I think that what we’ll end up seeing is multiple interations and alternates, either existing data centers will adopt GDPR-like facets, for each country, with major countries coming up with their own flavor of it. Organizations, like they did when PCI and HIPAA and all the other things came out a number of years ago are going to have to manage and deal with that across them.

    “I think one thing to keep in mind is that compliance does not equal security. Even if we had just one standard and we had a good standard, it means that we can document what we did and report it to an auditor. It still doesn’t mean that your security prevents you from being attacked, or that you’ve protected the data. It means that you adhere to a set of requirements that came about via consensus.”
    — Steve Orrin

    I think one thing to keep in mind is that compliance does not equal security. Even if we had just one standard and we had a good standard, it means that we can document what we did and report it to an auditor. It still doesn’t mean that your security prevents you from being attacked, or that you’ve protected the data. It means that you adhere to a set of requirements that came about via consensus.

    I think that GDPR is going to drive security. It’s going to drive a lot of product sales for a lot of companies. I think if we use that as an opportunity to go back and look at our data, because again GDPR is really about the data. If we go back and use that as an opportunity, so how would we –independent of the GDPR, we’re going to have to protect our data better. It gives us that opportunity to take another look.

    As far as one standard – because it’s the EU and there’s a lot of companies are multi-national, I think a lot of organizations are going to have to adopt it. I think what you’ll find is that it’s a subset of a broader set of regulations. There’s going to be – this for now, there’s going to be multiple regulations and then just when we get to figure that out there will be a new one that we’ll have to come find to in the future.

    Progress recedes like a horizon mind. I’ve been peppering you with questions. You’ve got a soapbox, what do you want to talk about? What are you thinking about wish the community was more aware of these days?

    I think there are two things that are keeping me engaged and excited – I think one is around how do we secure this artificial intelligence, machine learning environments, and understanding the complexity of that full lifecycle? I think that’s an exciting area that we’ve only just started to understand the different aspects of protecting the training, the inferencing, the analytics and cognitive side and then the actuation or visualization and understanding that those are different systems with different parties involved.

    Some of them we have more control over than others. Some of the system capabilities, what you have in a data center on training side, what you have in a camera that’s doing the inferencing are very different. I think there’s a lot of exciting work that needs to be done on how do we secure the AI. The fact that these are starting to make real decisions, and I don’t think we have good visibility into what went into training it, to recognizes a person,  a truck, tree and how then the feed affected that outcome.

    That is one of the things that are near and dear to me is how we start securing that. I think another key area is looking at the overall – the way that systems are actually getting deployed and we’re seeing very complex backend data center, cloud services. All them talking to the very edge and understanding how we get the best, the right security at the right place. I know it sounds like a little bit of hygiene, which it is. The idea that your laptops and the data center are the only thing you have to care about, that should be a gone notion.

    You have to worry about the entire enterprise includes the devices, the sensors, the components that are all connecting either directly or indirectly into your network, or that you’re relying upon for mission critical systems. The complexity there and the challenge of what I can do on my laptop with fully capable and what I can do in a phone, which is somewhat capable and what I can do in a smart meter are very different things. I need to do it the right amount of security good enough, but that’s still a pretext.

    I think that’s an area where every single – a lot of interest of what is the right approach. Do I make the smart meter, the most secure thing on the planet? Do I put a gateway in place. Do I aggregate the security? How do we get those – the evidence and the controls deployed around that complex organization? I think if you see the theme there, I like complex systems.

    Yeah. All right. I mean, we had some scary conversations about IoT devices earlier today and what’s there and what’s broken is – yeah, and as you think they’re all in the same network, right? It’s great if you secure the things that you’re more aware of, more thinking about, but you can’t even patch, let alone have visibility in some of those devices. It’s really a challenge.

    Exactly. It’s like, what do you do when you’re being DDoS’d by your refrigerator, right?

    We’ve all seen the Silicon Valley like incredible things. Steve, this has been great. Thank you so much for sitting down with us. This is really such a – covered so much ground and different things. We’d love to have you back anytime.

    Absolutely. Thank you.

    Awesome. Thanks so much.

    27 min
  • What We Didn't Predict, Can Still Hurt Us, An Interview with Internet Hall of Famer Paul Vixie
    What We Didn't Predict, Can Still Hurt Us
    An Interview with Paul Vixie CEO of Farsight Security

    Well, thanks for coming on. It's fun to ... I mean, you're literally a legend, right? It's a hall of famer. Not everybody can say they're a hall of famer.

    Hall of fame thing, plus three dollars will get you a cup of coffee at Starbucks.

    But you have a pretty interesting story in terms of an education background, from dropping out of high school to getting your PhD. For those who are listeners who haven't heard that story, I'd love to hear it again.

    Well, so high school for me started in, I don't know, '78 or so, and computers at that time were bigger, more expensive, slower, and less plentiful than they are now. So, in order to get access to one, you had to go to where they were and work out some kind of a deal with whoever owned that computer, usually lab tutor. I did that instead of homework, and was a really horrible student. Anyway, in 1980, my counselor told me that I was going to be a junior again for the upcoming school year, and I decided that the trend was not to my liking. The way I was earning a living at the time was not computers, I was earning a living pumping gas. I'd always envisioned myself graduating  to someday being a tow truck driver, but I thought, "Alright, before I go check that out, I gotta see if this computer this is able to pay." It turns out, being a computer guy paid a lot better than driving a tow truck, so I did that.

    Years later, I did start a PhD program at Keio University in Japan, and it took seven or eight years for me to get that done. At the same time, we were having new babies, I was starting companies. I had a lot of other stuff going on. Then the year after that, I was inducted into the Internet Hall of Fame, largely because of all  I did that made my PhD take so long.

    Well, when you finally got it, it seems like it went pretty well.

    It's a funny path, and not one that I could repeat or that I'd recommend, but it's mine.

    Yeah. It sounds like you've sort of navigated that practitioner to academic sort of leading research kind of world in a really interesting way. Having sat in a number of your talks, it seems like you're always having conversations at a global level, right? Sort of trying to push the community to do things. How did that happen? How did you get pulled to that part of the space?

    Wow. All my life I  wake up angry about something. If you do that, and you do it pretty much at scale, which is to say every day, eventually you start to want to know not so much why I'm angry about this, but where did this come from? Does it have any ancestors in common to the thing  pissing me off yesterday? What that'll lead you to if you follow it, and I didn't have a choice, is to realize that the thing we live on is round, and no solution that is only going to help one part of that round thing is going to last long enough, or be sustainable, or make any real difference in human history.

    As a result, I am one of the 10% of Americans who has a passport. I have traveled, I've seen how other people live, I've seen that not everything we do is the best way it can be done, and I have tried to apply some hierarchy to the  things to be pissed off about, and there's just no way to do that without a global view.

    What you're saying is you're pissed off at a global scale?

    Yeah. Pretty much.

    Yeah, I mean, you know, it's interesting I think. The internet come out of this sort of community of people who knew each other, and seems like it ... It was before I was born, so you'll tell me, probably, but there was sort of a collaborative spirit. It was a small community, and then this thing grew to a scale that I think maybe few of the people who originally came up with it ever could imagine. But all the sort of unintended consequences, sort of unanticipated issues that have arisen across that spectrum, and that initial everyone is here in this together community spirit, maybe some of the later people don't quite have that same communal ethos.

    “ Even the people who did do well financially, you know, started companies that later went public or sold for a lot of money, the thing they were passionate about was changing the way communication worked, and making a lot of money was just a really beneficial side effect, as opposed to being the point in and of itself.”
    — Paul Vixie

    I agree that a lot of the latecomers right now are sort of concerned about trying to cash in on something before whatever it is collapses. That's very extractive thinking, and that was not prevalent in the early days. Even the people who did do well financially, you know, started companies that later went public or sold for a lot of money, the thing they were passionate about was changing the way communication worked, and making a lot of money was just a really beneficial side effect, as opposed to being the point in and of itself.

    Now, for those of you born later, it's maybe hard for you to understand that within the generation of people  working on this kind of thing in the 80s, some of those were quite junior. I, for example. When I came to work at the Digital Equipment Corporation Western Research Lab in 1988, I was 25. I had always been a very big fish in whatever small pond I was in, and so I thought very highly of myself. I went to work in this lab that had 30 scientists, you know, PhD people, and I was very much the junior man on that totem pole, as low as you could go.I learned a great deal about what a real pond looks like, instead of the small pond I'd been swimming in up until then.

    Even a few years ago, I was on a panel at a Hackers conference with Marshall Kirk McKusick and Eric Allman, who are two people from the BSD community. The organizers were probably born about when you were, so they think of all of us as BSD people. What I had to point out to the audience is, you know, when I came into this, Sendmail was already a thing, it was already a global presence in the world.I learned a lot about what I know about programming and C by reading Eric's source code and asking him questions, which he was kind enough to answer. And Kirk had written the Fast File System, and that was also as universal at the time. It was in every Sun computer  made in the first decade, and all the BSD systems. Again, I learned what I know about file systems by studying his work that was five to ten years before my time.

    Yes, at this point, a lot of people are going to lump us together. I always remember coming into this late and really feeling like I had missed the boat, and had to do a lot of work to prove to these people that I was useful. I think there was a lot  that  went on then that is not necessarily going on now, simply because there are millions of people doing it instead of dozens.

    Yeah. Yeah, the scale of the community just makes it really hard for it to feel maybe like a community sometimes, right?

    Yeah.

    But, you know, I was bouncing around the internet and came across a LinkedIn article that you had written about that mentorship process, and you had your six questions, right? For those people who hadn't seen that, talk to me about that kind of piece, and how you think about kind of the mentor mentee relationship and whatnot, because it was, at least for me, really interesting.

    That article was a little bit scary for me because it was written for management people, not technical people I don't have a lot to say to new technologists, other than to tell them, "Well, don't do this, because that worked poorly for me." So, the idea that I would have something innovative to say in a non-technical way felt like a bit of a phase change..

    A lot of times you have people whose interests are theoretically alignable who can't get it done. They end up spending a whole bunch of time circling and misdirecting and just kind of not making progress, either for themselves or whatever organization they're in. So I crafted those six questions. The idea is to really invite somebody to speak plainly and to speak the truth and to create a safe environment for them to say something that maybe has been on their mind.     It's not too different from what a lot of married couples learn to do, which is, you know, "Hey, honey. How have I been pissing you off? What is it that you have just given up talking to me about because I was never able to listen?" If we all try that, we'll probably hear something, and that's interesting because it means not so much that you have to dig for it, but that there are some things that you have to dig for    If they have a list of things that they hate, and you are willing to give on every one of those points, you could create a lot of marital harmony if you would just talk about it, as opposed to sort of running through our lives with our hair on fire, as we do. So, that's what those questions were designed to do,  to open a lane of communication to people who really should be talking and should be listening but, for whatever reason, aren't.

    Yeah. I mean, that seems like at least a theme that I've heard in a number of your talks, this sort of, how do we get a community to align themselves around something that's maybe not directly in their own self-interest, sort of a tragedy of the commons problem at cosmic, global scale.

    Yes.

    Yeah, I mean, where ... Excuse this analogy, but every time I hear you I can't sort of help but think of Don Quixote, right? You seem like you keep tilting at windmills, right?

    I do. I do, and I sometimes think of that as character flaw, but sometimes the windmill moves a bit.

    Yeah. It's always this industry, so much to talk about the problems and what's broken, right? But maybe not enough attention of what has worked and what is working. Where have you seen maybe a windmill lean or shift just a little bit?

    Well, I'm going to answer a slightly different question, which is, what works and what doesn't? I've started a couple of non-profit companies, couple of for-profit companies, some of them have done okay, some of them have been terrible failures. Generally speaking, the time that I launched the anti-spam industry with a company called MAPS, Mail Abuse Prevention System, and some technology called the RBL, which is used pretty much by everybody now. No one who listens to this webcast will ever receive mail that was not, in some way, subject to RBL lookups. If I had been a little bit more foresighted about it, I could  have patented that and I'd be the road reflector family. But I didn't, right? I was trying to solve a problem, not make money.

    But the problem I was trying to solve was to make spam harder to send, more expensive, less successful, and in that sense, I was building a wall. You may have noticed that you're still getting spam.It's my belief that without the RBL and without the industry that I inspired, you'd be getting more spam. It's possible that if you and everybody else was getting more spam, you'd do something about it. You'd get angry about it, and if we had angry people, torch bearing mobs, as it were, then maybe the problem could be finally solved. So, it may be by building the walls I built when I built them, all I did was to contain the problem.. So, I may have had the opposite impact on history that I planned to.

    Now, in other cases, for example, starting the Internet Systems Consortium, which is the non-profit that Bind comes from, or starting the Palo Alto Internet Exchange, which was the first neutral commercial internet exchange. It was the first place that ISPs could come in this country and connect to each other in a neutral house where nobody was getting a circuit revenues from anybody. It was really groundbreaking. Nobody realized how important that would be. We hired the people who later left in disgust and funded Equinix, which has become the big player in that. But in the case of those two companies, I was not building walls, I was building roads. I wasn't making certain things harder, I was making, instead, certain things easier, and the impact of those has been far greater. My lesson, out of all that, is you should build roads, not walls.

    That's such a interesting way of approaching a problem. Yeah.

    Well, it's interesting, but it's also terrifying, because I actually had to do all of that. It feels now that I could spend a few hours with a pad of paper or a white board and work that out theoretically, and maybe there are people who can, but no, I actually have to go through the whole thing before I will learn the lesson.

    Is it, I mean, even at the scale of a community that's millions, billions, right? Billions using it, millions working in it, is it still in many cases handfuls of people who are really kind of moving the needle, or ... When change happens, who's doing it, right? More than the practical, kind of. What's the community and what's that look like when it happens?

    “He had a vision of a Unix-like operating system that would be a fairly open license that you wouldn’t have to pay AT&T for and that the community could take the biggest single hand in shaping its future. ”
    — Paul Vixie

    I think the easiest case study for success in making a difference would be Linus Torvalds. He had a vision of a Unix-like operating system that would be a fairly open license that you wouldn't have to pay AT&T for and that the community could take the biggest single hand in shaping its future. I'm certain that a lot of people laughed when they heard what he wanted to do, but I think you've got at least two versions of Linux running on your body right now, and everybody listening to this, likewise. That's how prominent it's become. That's what a big deal it is.

    Again, he was not building walls. He was building roads. He wanted to make certain things possible, and he's won that game. There are other examples where it took a lot of money, maybe, to get something done, and certainly Linux has a lot of money invested in it, but it's being invested by companies who accepted the code base, they accepted the culture, they accepted the license, they hired people from the Linux community to be their executives There are other cases where somebody has said, "I want to have a success like that, but I don't want to do it in a crowd sourced sort of community integrated way. What I want to do is just write a lot of checks and end up owning stuff." You know, maybe that is better than nothing, but look at a couple of the highly commercial versions of Linux, and they've got nothing compared to the market share that Red Hat has, having both a commercial and non-commercial version.

    I look at Google as an interesting example. Of course, Alta Vista was really the first search engine of that kind, and that was part of Digital, but Digital Equipment Corporation was completely insane when it came to networking. They didn't understand what they had, so they kind of wrecked Alta Vista. Anyway, Google could not have come about if Linux hadn't come first, because they had to be able to hack on the bare metal and figure out how they were going to do things differently enough that no commercial provider would ever have given them enough access, or whatever. But they didn't have to start by building their own operating system. They could sort of join a community already in progress, and in fact, they've already put huge contributions into that community. They've paid back much more than they benefited. I think that's a better approach, is to figure out a way, and this goes back to what I was saying earlier about alignment of interests. A lot of the people that you compete with are potential fellow travelers, if you're creative.

    Yeah. Yeah, and standing on the shoulders of giants, right? You know, and hopefully helping someone else up with you, right? From a historical perspective, I think it's ... Just to change directions ... Interesting sort of the, at least some of the explosive growth of the internet took place kind of in the early 90s and through the 2000s, right? When you sort of had a quieting of the Cold War. The interests from a geopolitical standpoint were maybe in a different place than they are right now. I've heard some people have begun to sort of think about that cyber warfare is becoming essentially another stage of the Cold War, with China and Russia sort of rising as powers and trying to battle with the US for global supremacy. When you think about that, do you get worried about ... When you think of a community that's working together, and how does that ... When you start to have competing factions at that level, what's your sort of ... I realize that's very much out of left field, but ...

    I used to think I could change human nature, and I've given up on that. What that means is that any macro historical pattern will reissue. You're going to see old ideas applied to new technology inevitably. If you take a look at not just the United States' recent election, but recent elections in Germany, Ukraine, and what not, it's no longer really possible to trust democracy, because crowds of people can be misinformed through social media, and made to either abandon or adopt positions that are not the ones that they would come to if they were allowed to think peacefully on their own. In that way, the Internet has turned pretty much the whole of the human population into a potentially torch bearing mob, and we don't think clearly. We did that. We, the people who built whatever small piece of the Internet each of us built, made that possible, and we didn't have a plan for how we were going to keep this bad side effect from occurring.

    Now, you mentioned the 90s, and I think there's a point that often gets missed because the Clinton family and the Clinton Foundation often takes credit for how great the economy was during their eight years in office. What I want to point out is that in 1993, the National Science Foundation decided to release the Internet. They were no longer going to fund it, they were going to do what was called the Commercialization and Privatization Effort, and it was in full swing by '94, and it was over by '96. I think that is why the 90s was a period of boom growth.

    Because we were getting a lot more efficiencies, we were getting a lot more potential relationships, we were virtualizing a lot of things. That was the good part. The bad part is, when I was a kid growing up in San Francisco, you'd read in the newspapers every month or so, some senior citizen had got mugged on social security day, you know, because they got their check, they walk to the bank, and people wait outside the bank. Hey, you're a senior citizen on social security day, I'll bet snatching that purse is going to be profitable for me. So, those people were at those risks.

    Now those people are not at the risk because it's much easier to steal that same money through a malware infection and a keylogger or a botnet one nickel at a time, or whatever you're going to, and you can do it from the privacy of your parent's basement, or wherever it is that you live  to launch those attacks You don't have to be in the same country. You're not on the scene, you're not at risk of tripping or being chased by a good Samaritan, recognized. There's no risk, and the attack surface is effectively infinite. And we did that. We the people who did our small part to make the Internet possible did all of that without a plan for what the heck we were going to do now.

    It seems like you're a student of unintended consequences.

    Yes, I am.

    How about now? What are you most ... What windmills are you tilting at, and what are you most concerned about?

    The natural forces of the human economy and history and human nature are going to mean that this Internet of things deal is going to make all of us even less safe. We will have less privacy. We will have less certainty that the transactions that we are conducting are actual with the counter-party we thought they were, and we're going to put all of this type of electronics into cars and start to have a lot of self-driving cars without having really learned the lesson that all software has bugs. Or at least all software ever written has had bugs. We don't know if maybe some day there will be some that doesn't. But trend line indicates that all software will always have bugs, and that we just don't know what those bugs are at the moment we ship it. That means we're going to kill people with bugs.

    When I've talked to people in the self-driving car industry, they say, "Well, right now we're killing people without software. It's humans driving the cars, and humans are incompetent." So when I ask the question, "So, your value proposition here is that you're going to kill fewer people in new ways." And they said, "Well, yeah," because they see the fewer, and I see the new ways. It's like, I am a pedestrian, and all the cars around me are going to have your bugs in them. I am a test subject in your laboratory, and my consent was not sought. Yet, that's how human history progresses. That's what I'm worried about, is this unintended consequences thing is bad by itself, it's worse when you square it, and it's even worse when you cube it, and we're going to cube it.

    It sounds like you need to recruit more ... Now, you've been mentoring on the small scale, and probably on the large scale. For those people who are listening to this, reading this, what's the ... Where would you recommend that they go? How would you sort of direct them to follow a path somewhat like yours, and work for the good, at least in some measure?

    Well, there isn't so much a path, but there is an attitude. Now, 100 years ago most American families knew where their food was coming from. Even if they weren't growing it themselves, they understood the process that they were outsourcing, and so they knew what was in their food. Now, that's gone away. We have outsourced all of that. Our food is brought to us and we don't really have any more than a fuzzy concept that we got from a movie some time or a story we heard about how that animal was raised and slaughtered or what had to get sprayed on that crop or how much diesel fuel went into bringing it to our table. That is where we go wrong. I'm not saying that we should all continue to grow our own food, but we should continue to investigate where it comes from so that we can be making informed choices about what we do.

    If I could get people to investigate what they do and what they're benefiting, and make a decision about what future they would like to aim for, that would be huge. But at the moment, people hear what they want to hear, and they believe what they want to hear, and other people are very good at figuring out what that's going to be and delivering those messages. And a lot of us, sadly, just lap it up and do not think about the way that we are participating in really our own destruction or our own imprisonment.

    Yeah. The silent majority, right? Sadly, for good or for evil, right?

    People who cannot be bothered to understand what's going on but still vote.

    Yeah. Well, this was great. Really fun. Thank you. Appreciate it.

    Thanks.

    Before we end, here's your soap box. Anything you want to talk about, mention, get people involved in? The floor is yours. Feel free to pitch whatever you've got or want to.

    Okay. So, it's a two-parter. You cannot make a digital system, like a computer or a network, safer by making it more complicated. What that means is that, let's say you have a network of some kind and you add some new thing, maybe it's a firewall or some other security related technology. That's got software in it, and all software has bugs, and so there are some risks. You need to have some kind of an inventory about what you have and what versions you're running so that if a bug is found, you know that you need an update. That means that the point at which you write a check or flip out your credit card and get a new thing is not the end of your investment, it's the beginning your investment. If you don't, then the bad guys, who understand your technology a lot better than you do, because that's how their incentives are aligned, are going to take you for a ride. I think security and complexity don't go hand in hand. If you want both, you have to work really hard.

    That, I think, is a good lead in to understanding why I'm doing the company I'm doing, Farsight Security. A lot of folks in the security buy side just can't be bothered. They don't have time.They have budget, they want to write a check to be safe. I don't think that's actually possible. I don't think you could do that, so I don't tell people that that's what we do. What I tell them instead is a bit of a tough love story. You have to understand what the threats are. You have to understand what your threat surface looks like, and then when something happens, you have to have enough clues inside your corporate DNA to be able to do an investigation. So, I sell tools and data feeds that facilitate that kind of understanding, that kind of investigation., and I am often criticized by a current customer, or sometimes by a prospect, who says, effectively, "Paul, you're trying to sell me a shovel, and I want to buy a hole." My point is that you probably can't solve your problem by buying holes, and I'm not good at lying to you and telling you that you can.

    Yeah. You don't know where to put it. Where do you want me to dig it, right? I have to ask you that every day.

    I think that investing in your understanding and in your ability to make enlightened followup actions after an attack, or even before an attack, is the best thing you can do. The people who invest that way might spend more up front, but they certainly save more on the back side.

    Yeah. This is awesome. Anything else? Where can people find you if they want to follow up? We can throw links and stuff in the ...

    Well, I am, of course, Paul Vixie on LinkedIn, Twitter, and Google, and Facebook. The company is FarsightSecurity.com.

    And I am always excited to hear from people, to answer questions, to get involved in arguments about the best way forward. Yeah, pretty much if somebody wants to choose the road less traveled, they should be reaching out to us.

    Paul, this is great. Thank you so much.

    Thank you.

    Great to sit down, literally with a legend.

     

    31 min

About Cyber Security Dispatch

From the publisher's feed

Cyber Security Dispatch brings you to the front lines of cyber security. In our podcast we interview leading experts and practitioners who are fighting attacks, securing systems, and exploring the…