Joseph Woodwell – How Automation is the Only Choice for Security Professionals to Get in Front of the Zero-Day Challenge
The faster you respond to a zero-day, the more likely you will keep the attackers at bay. It seems simple, but we all know there are many obstacles along this path including a lack of visibility, alignment between the vulnerability and patch processes, and a resource shortage that leaves you without staff to quickly implement the many processes needed to remediate the vulnerability. One way to circumvent some of these obstacles is to automate the application of relevant patches for new vulnerabilities with specific risk.
In this session, you will learn tips for increasing zero-day response times, areas ripe for patch automation, how to save time and effort deploying patches, and gaining alignment between IT and security teams.
Transcript
Welcome to the koalas presentation securing your digital world. We are all about helping and providing our clients to with the ability to reduce risks through continuous security intelligence and automation. Now automations are really interesting word because automation can give us speed it can also freak people out because of the inherent risk that's associated with automating certain processes and procedures but we think the industries matured enough all these many years later since the founding of quality to enable automation of specific and and limited set of security tasks and functions that will give you all the advantage and all the speed necessary to overcome some of the some of the most severe cyber threats today.
So let me give you a quick example back in 2013. Tesla was under investigation because of a Model S. Vehicle of theirs caught fire after its driver ran over a piece of debris in the in the road and it punctured the battery pack of that Tesla.
Does anyone remember or know what Tesla did in response? This is super smart hours before the national highway traffic safety administration was about to launch their investigation. Tesla pushed out an update that automatically raised the cars or the vehicles ride height at highway speeds so that it would it could eliminate the possibility of such a puncture of the battery pack in the future.
The interesting thing is not only did they avoid by doing this preemptively in the kind of painful regulatory investigation, but they increase the safety and reduce risk for drivers through automation. Now, what does that have to do with qualis? Um, I'll make that point in in just a second but we've been doing this since 1999.
We've been in the cloud since 1999. And I know I was one of the first Skeptics I was using qualis in 2002 and the idea of a cloud service was kind of a scary thing that you're sending all this data into the cloud and I'll come back to that and in a little bit but we we are now in a hundred and thirty countries with over 10,000 subscription customers 1800 employees, and we're a worldwide Corporation. We've won a lot of awards.
I'm gonna skip that because nobody needs to see that but we have been recognized for what we're able to provide customers worldwide. And the upshot of that is that we're able to drive positive outcomes for our customers and some of those customers. Well, they range, you know, the gamut of manufacturing and Retail Energy food and beverage Finance some of the largest names in Industry today, and that's it's an important thing for you to Some of those customers are customers that you that you use on a daily basis in it, whether it be in the cloud or on your desktop using office automation software to write a memo or to send an email.
So we help organizations to reduce their risk, and these are the ones that we can that publicly. We can talk about so for for our perspective the key is to be able to identify assets quickly identify their vulnerabilities and then prioritize the work for you and then enable you to automate wherever possible those Corrections those remediations and and to be able to Monitor and continuous mode as well as to detect in a continuous mode any potential upside or downside risk and vulnerability and be able to respond to those quickly. So what we hear from our security at it teams that work with us is I have 13 different agents working on my hosts and I need to reduce agents.
I've got Point Solutions the data siled. We're on-prem some of these are in the cloud. It's kind of a combination.
It's very difficult to have to manage that kind of a spread not only do we have siled data collection, but we have siled analysis and Remediation multiple agents tying it up making it a little bit more complex. Plus they take up a lot of resource. And so the challenge is also too many vendors, right?
Because now I've got to manage all these different relationships all these different subscriptions or installations. It's very difficult summer it based on the asset inventory and management side. Some of them are security and there's a crossover and it's kind of confusing to to and difficult to implement certain Technologies because of that and then we haven't even addressed the skills Gap where the the IT staff for the Staff, I mean they're just overwhelmed with the demands that businesses are being you know that the Enterprise is placing on them from a skills standpoint.
And so there's a little bit of a shortage. So what all of this me means is prolonged exposure to risk because you don't even have the tools or you can't work out Corrections and remediations because of all the different tools, even though they're under the same umbrella in your on your network. It's very very challenging.
And so what we propose Is with qualysis that we provide a single platform a single agent one view. It's always on it's kind of fulfilling the promise of a phrase that I really kind of detest and I've hated it for almost 20 years now and that is a single pane of glass and you've all heard it but very few products are really able to deliver that kind of capability where you have regardless. If it's an IT environment with workstation servers virtual machines Cloud mobile containers iot ICS, whatever the case is, we have a capability to be able to see your entire environment goal post to go post with a variety of sensors that all share common code and that report into a common UI if you will the agent itself is about 15 Meg downloaded and installed.
It just takes metadata on a not a four hour schedule enables. To to upload that metadata into the cloud with us or to a maybe it's an on-prem scanner that scanner is also a type of sensor and it's just looking, you know at your at all of your devices all of your host and assets and Reporting up as well into the cloud and then we unify that view with our dashboard. So regardless if it's internet scanners looking at external facing assets or virtual scanners VMware hypervai, whatever the case may be a cloud connector that you have in AWS or in Microsoft Azure or in gcp Whatever the case is maybe it's API Communications.
We're able to unify all of that information and present a unified view of that in our dashboards that gives you asset visibility vulnerability management capabilities threat detection remediation and response as well as compliance reporting and and that's that's really a remarkable capability. To be honest with you. I think it's probably about 10 years, you know it we should have had this 10 or 15 years ago, but we do have it today and the idea is that we're able to give you visibility and respond in a very laser focus kind of way case in point.
We have a large subsidiary of GE in Houston. A customer of ours that used are threat intelligence dashboard in this security platform. We call vmdr vulnerability management detection response and in vmdr, there's a module called threat protect.
And so they in the threat protect module you get a brief blurb on the threats that are hot and relevant today and and with context about how they impact your specific environment. These guys pulled up something called proxy, log on. This was when proxy log on was really big early last year and it turns out that they saw 27 servers that were impacted by proxy log on so they didn't have to go hunting and fishing through a phone book worth a vulnerability data and the assets.
It just said you've got proxy log on Here's Where You're vulnerable. Okay, and here's information on the patch and what you need to do to remediate etc. Etc.
They printed that out went to their Microsoft admin. And or exchange server admin, I should say and then informed him. Hey, we've got these 27 servers with proxy logon and the information from the that information actually surprised the Microsoft admin.
He said well, that's really interesting because I only have 22 Exchange servers that I administer. Let me take a look at this. I'll talk to Microsoft and see what's really going on here because this is way more than what I was expecting and so he came he came back and said actually this is correct.
We do have 27. Well, how could this be? You know, he only knew about 22 servers were well the case is that at least in one instance?
For example, they had a Microsoft Exchange Server that had been allegedly decommissioned right and reprovisioned for IBM Tivoli and it turns out that whoever did the Tivoli instant implementation or installation just installed it on top of the Exchange Server never deactivated never white the server never did a you know re-imaging of it. They just installed it on top. So there there he goes this poor guy is completely unaware that there's an there's a license or an instance of exchange that's running in the clear and that and he's not updating it.
He's not keep you know monitoring it. He's not making sure that it's secure and patched on a monthly basis just running in the clear. So those are the types of things that we bring the table turns out that they actually had as time went on they had 34 instances of of Microsoft proxy log on and exchange servers in their environment when they only expected or at least Exchange Server Ed man only expected 22.
So that's the type of thing that we're we're providing reliable threat intelligence. That's High Fidelity. We have over 80 leading experts that help enable that we have platform services from, you know, roles based access controls to A machine learning and AI scalability alerts and notifications workflow really nice custom scripting capabilities that you would love and then of course dashboards and Reporting like you would like for custom custom.
Presentation of the data in your environment plus a unified platform with data normalization and indexing categorization and enrichment. What do I mean by that? I'm talking about end of life and end of support for custom software for software.
That's just traditional off the shelf stuff that's open source, we show you everything including certs that are about to expire shirts that have expired and we help you to manage those certs in an ongoing basis. So that's the type of stuff that we're bringing in unifying in this data platform as well as API and integration work with other clients. So for example, if you want to make Splunk your your single source of Truth, so to speak and feed all these data sources and logs and what have you in the Splunk we can do that as well service now is another integration and jira those are two for you know it ticketing and asset management.
So we do those as well. um We also have a really nice control center, which will support secops risk compliance management and provide you with not just it I'm sorry, not just SEC Ops, but it Ops and devops capabilities to manage containers and the whole development process so that you get clean apps released to the public release to your business units that are free of vulnerabilities any potential issues. So is this proven do we really can we really deliver on this and the answer is well, we have six billion plus active scanners deployed doing scans and audits annually $50,000 scanner appliances 75 million Cloud agents deployed and two trillion plus security events that we're collecting in real time.
So yeah, we can definitely provide the scalability in a secure way. We're fedramp medium certified today or qualified today looking. to become fed ramp high in the near future if that's a requirement of years where ISO 27,000 and one certified and as well as supported or endorsed by aicpa and for Security operation Center certification Let's see.
I want to I want to stop here and just give you an idea with vulnerability management detection and response. This is not a actually a solution bundle. I think that's the kind of lessons that it doesn't even begin to address the functionality of all of these different modules that are built into vmdr and how you can just go all over the place and seamlessly within within our suite called vmdr.
But we give you full global view of all of your assets. Whatever they may be in your environment full-blown vulnerability management detection and response patch orchestration. So when you're ready to remediate those assets because of those vulnerabilities we tell you exactly what needs to be done.
If you want to you could upgrade to patch management and that will actually enable you to patch just with the click of a button you can remediate hundreds or thousands tens of thousands of devices that may need a patch Tuesday update or something critical like blog for Shell or blog for J detection and we'll give you a real accurate calculation called true risk that's based on asset priority as well as the vulnerability priority the marriage of those two gives you true risk and and a sense of you know, what really needs to happen in your environment in order to reduce your risk exposure. I've already talked a little bit about threat protect and continuous monitoring, but we're giving you near real time. See maybe 20 years ago people with scan once Order once a month if you were really sharp and and now scissos and some organizations are have made a shift to looking at scanning on a daily basis.
That's a really difficult thing to do but with quality because of these low Footprints agents that are able to just report the Delta and send metadata into the cloud for analysis and for reporting purposes, you've got basically near real time visibility into your environment again, I mentioned certificate assessment earlier 30 60 90 views on certificate from a management standpoint. You can enroll manage shirts, you know, take your expired search and re-enroll them Cloud inventory. If you want to there are very few tools that can actually marry what you have on Prem with what you have on the cloud and give you a unified visibility to those devices and it's all the same and it looks the same but it's just cloud data.
It's just Cloud hosts so we can provide that as well. As kubeflow which will we we're a little bit out of time today to discuss but that in a nutshell is it's just a summary of what qualysis doing to enhance Automation and to make it possible so that you don't have to wait for an investigation for an event to happen and for people to get in trouble and for you to you know, come up in the news to understand what you need to do in your environment to make it to make it more secure and reduce your risk profile quality can help you on a daily basis to stay on top of that and to improve the experience both internally and externally for your customers. Thank you very much for your time, and I'm open to questions.





