Yuval Shchory – Beyond Unification: How CNAP Should Reduce Cloud Security Risk
By now, every security team understands that unification is the first step to securing their workloads in the cloud. Unification can’t be the end goal though, because cloud security teams are still struggling with alert fatigue, friction with DevOps and manually trying to prioritize where their attention and remediation is required. In this talk, we will examine how to reduce cloud security risk and eliminate existing complexity in the cloud, by using smarter unification tools that can help security professionals reduce risk in the cloud and DevOps teams to remain empowered and agile.
Transcript
Hello and welcome to this session. When where we are going to discuss how cnap platform actually not just be a unified platform that deals with everything but instead truly help you to reduce your Cloud security risk, my name is evolve and I'm the head of global product management for everything Cloud security with checkpoint. when we look at Where we are today, most of cnap platforms that you see really focus on just providing a lot of information.
A lot of this information is on prioritized. Some of it is actually unattendable. And when we look at this, we understand that we have to transition into a situation where we reduce the attack service.
We need to eliminate the rest and do it based on business priorities allow focusing allow security teams to focus on risk reduction and not just on alert reduction. With the cloud everything is times hundred when we look at the amount of people involved. It's no longer just the infrastructure people or the system people making decisions.
You have developers. You have devops Engineers making micro decisions every day that has an impact on the the cloud infrastructure the cloud environment the applications deployed and actually the risk that that you see coming from these system or impacting these systems. The number of assets is is giant not only it's no longer in a data center where you can actually physically touch the server.
It's all virtualized. It's in multiple Cloud environments. Some of these Cloud environments are actually with multiple cloud service providers or csps.
You might have some of your application in AWS some of it and Azure some of it in in Google Cloud some of it in in Ali And how do you manage all those crown jewels where you actually don't know where they where they are. Also the types of applications that we need to protect differs some of the systems are internal systems that might take the downtime. Some of them are actually really crown jewels your cash flow generation machine that have to be up all the time and you can't take them down.
Even if you have a security risk, you need to work it out around it at the same time the pace at which changes a core with the transition to cicd and everything is is really fast. So sometimes, you know about a change after it happened and we see a lot of security people actually complaining or being frustrated by the fact that they don't get enough time to secure the applications but instead a developer or devops team leader comes on on a Thursday and says, hey we're ready to go online production on Monday secure this At the end of the day, your organization risk is also 100x stats exactly why we truly believe that we have to change the way that we deal with things. Unification alone of the cnap platform doesn't fully solve the problem.
You see a growing number of alerts that leads to and attended security issues. You see manual configurations being made sometimes by people that if not all the time that do not have strong security understanding of the entire environment eventually leads to Mis configurations. It needs to excessive permissions.
We also see as we discuss the minute ago it constant form of development cycles that push changes into your production system introducing you vulnerabilities introducing new malware. It's someone forgot a piece of secret within the within the code as we saw in the last two years. We saw an uprise in the amount of Secrets being exposed.
We want to make sure that these are not leaked end of the day for us security people those Diamonds are complex and a lot of time I hear from Security Professionals. That they have lack of visibility something. They don't even have understanding of how those applications actually work with all those different cogwheels.
You have virtual machines and you have containers and you have serverless functions that that kind of Connect into your system and you don't have as a security professional you don't have the disability around everything that you have leading to security gaps that are unattended because again, you just can't find them. First thing that we have to do when we talk about enabling cnap platforms to be better for what we need from them is introducing a lot more machine learning and AI into those a gaps that we have ai turns data into actionable insights instead of saying okay. I have 100 alerts that I need to take care of.
Maybe all of these 100 alerts could actually be aggregated into a single alert that is actionable and is insightful and we'll talk about how do we do it in a couple of minutes the more data we push into the system. The more accurate. The machine is the more information the the AI engine the machine learning algorithm will receive the more specific to your environment the insights and the actions you can you can receive for Last but not least when we look at real time production environment.
Sometimes we see systems with close to 100,000 high-end critical alerts received on a daily basis. It doesn't really matter if the organization is going to stop everything that it does and just focus on reducing the number of alerts. People are gonna oversee issues.
They might not be able to connect issues together understand. Hey, it actually not just this other and that alert but instead these two alerts together combine actually has a higher risk factor that I need to attend to first if we allowed the machine to really learn and provided feedback which regards so yes, this really makes sense. We can do two things.
The machine will get better at prioritizing events for hours statistic environment. And at the same time, we're not gonna have those overseeing alerts and we're going to reduce up to a point where we completely remove human error across the environment. So, how do we do it with Cloud Garden?
How do we actually use AI in order to weaponize CNET? We look at everything that we have posture information Kim information threat intelligence. Whatever we have on container protection API security network security everything that we have right?
We can pull into the machine learning algorithm from that. We're actually bringing Out Security insights, so it could be vulnerability that has a specific impact on your system misconfigurations that have specific impact on how you are using the the environment anomalies in terms of How It's administrators are connecting to machines how users connect to machines and how traffic is being directed and routed within the within the system. For example, if you see an IP address from a country that you've never seen Accessing your system and it's sucking terabytes of information every minute.
Maybe this is an anomaly that you have to attend to and this is something that will actually be expressed as a higher risk to your system. But again, not just that combined with other alerts coming from all the insightful information to the machine Learning System could generate Eventually, what we do is we take all those contextual inputs and additional contextual inputs such as the topology. Do you have you know active protection in your system, whatever active Services you have and then we actually calculate what attack surface you have with different attack paths you might have in your system and calculate a risk for each and every one of these attacks and the combination of the risk value is actually the attack surface risk overall last but not least we're bringing in business inputs in order to prioritize remediation what business input is is so critical because again, you might have a lab system vulnerable and at the same time you have a production Cash Cow, if you want vulnerable and you want to take care of your business for organization cash generating application prior to something which is completely disconnected from the internet because It is an internal system.
I'm not saying that you shouldn't but definitely you would want to attend it to it after you dealing with your number one business prioritization business priority system. So how do we actually build a risk first? The attack surface is actually a super set of the real Attack paths.
If someone could attack your system using multiple jump boards within your your system. We're actually taking these impact that's in combining them together to a Supercenter and this is your complete a tax service each attack that is assigned a resource. I explained earlier and then each asset within the attack that is giving an Asset Risk.
It is actually what level of risk this specific asset in first in first of all, the the attack patterns last but not least. It's not just it doesn't end with just telling you. Listen.
This is how risky it is or this is your complete a tax surface. Now the question is how do you remediate this and we have to remember that no one has enough security operator operation teams or resources or people within their operation teams in order to remediate everything. So this is why we're pointing the term minimal effective those which actually says listen you can deal with this problem with you know, through three different manners or three different ways and we suggest that you do this because this is the simplest fastest way to resolve the risk.
So for example, if you have a vulnerability in the system, yes, you might you know update the entire operating system, but still you might be able to just up. Made a package or maybe if this service is not top priority from a business perspective first close it and then upgrade it. So you have you know, you have the ability to protect it without impacting the entire system around it.
Now let's look at the actual services that cloud guard provides through the unified scene app. It already is but also the AI enablement capabilities that we're we're constantly adding in order to eliminate risk for our customers. From code to Cloud everything that we do is automated Cloud native.
We're providing a unified platform across whatever application you have whatever types of workloads you have be it virtual machines be it containers or serverless functions. And at the end of the day, we use everything in order to manage risks to maintain the posture and prevent threats. It's not enough just to provide you data.
You need to be able to prevent threats through your scene app platform. Last but not least scale. As we discussed when I started this presentation speed and scale is an important thing is an important factor when you look at your system and you have to make sure that your system supports the speed and scale that your organizational needs posts.
So when we look at everything that you have today when we talk to CIS and cios, they usually care about the web interfaces the top of the diagram here. This is for them like, you know, is is the Chariot at the top of everything in sometimes I wouldn't say they don't care but they don't remember what virtual machines they have how many containers they have what makes everything for them? It's all work clothes.
It's all services that deliver to the to the same type of different Cog wheels that make the application below it you have the infrastructure, right and everything here is managed through a cicd pipeline and everything here actually has posture management capabilities through Cloud guard and threat intelligence that kind of sits side and says, okay everything. Let's say is configured in a in the right way. Everything is upsetic from our configuration perspective, but I still want to look at the I still want to try and hunt for things that opposed risk due to anomalies.
And what we're adding to this is as I explained earlier is a way to effectively manage the risk a way to look at all the alerts combine them through machine learning. Look at your permission sets the entitlements that you have and ensure that they are also provided in a manner that makes sense and last but not least do it in a way that doesn't introduces new compute or actually new costs. To the application organizations when I talk about application organization.
We need to remember depending on how your organization is being run some idea organizations actually charge back the business the different business units in terms of You know, this is this is the cost of your compute some of these business units say I do not want you to install additional agents on my virtual machines on my containers on on my service functions because these actually pulls more complexity. I need more more open funds to pay for those agents and the CPU resources or the Computer Resources over all day. They consume and when we decided to go the Ageless workload direction, we actually do it in a way that doesn't introduce new costs to these business unit and by doing so removes the the friction between the developers the devops and the secops organization.
So let's now Dove a little bit deeper into each of these capabilities. First as I said, we have too many alerts and the amount of alerts actually creates a situation where we have alert fatigue we have resource rate. We don't have enough people which leads eventually to unattended risks.
The amount of alerts coming from multiple security tools is just unmanageable. And we're trying to solve it through what we're referred to as ERM effective risk management. We talked about how attacks are assigned risk score how remediation uses the eye in order to read them recommend the minimal effective deals and eventually be very actionable what you see here is actually all clickable.
So for example, if you want to look at high risk assets that are perimeter access perimeter assets are our assets that have access from the Internet or 2D internet. Everything here is kind of you know built in a funnel way. So you could really hone in on what matters you could look at different high risk assets.
You can look at. Okay, what do I have remediations for when it comes to high risk asset, etc. Etc in this is the dashboard that you should be focused on when you're looking at cnap system.
It's not just tell me what what problems I have. But instead tell me. Much risks I have in how do I reduce them?
Next is Kim when we talk about Kim and we look at how customers would like to go. They would really like to move towards. Is there a more zero trust or zero trust alike permission model?
However, the permissions usually in Cloud environments are still configured in a manual manner. Not only their configured through a manual manner but instead the person that actually says this is the permissions I need is the developers or the devops engineer and sometimes these people not because they're they're they're bad just because they do not have the information not not always the eater understand the security implication of a specific permission or sometimes they're concerned about impact to impact to production system as they introducing changes. So a lot of times we hear the sentence don't produce the permissions because I don't know if it's going to continue working in in the next version of something like this with Kim does and this is an inherent part of our see now offering it actually allows you to build a zero trust identity model provide you A visual visibility into into your entitlement as they are configured in the system, but then look at how entitlements are being used.
when we look at the configured permissions And the S use permission model we can actually model the Delta and say this is the provision model that you need and this is a constant learning machine learning process. The constantly looks at what's configured what is needed and the Delta? So even if an application changes and now requires more permissions easily, you can learn this new set of permissions and introduce to policy change in order to support the the new permission set required last but not least you do want to get alerts when anomalies are being found when something is being used not in the way that it is, usually you so for example, if the user accesses a resources that they never have in in a manner that they never have say that that someone always connected through a web interface, but now they're connecting to a different system or a different resource through SSH or something similar you might want to see if this has Act on your risk and if it does have an impact on your wrist, you would like to reduce it by eliminating the extra permissions provided when we do this.
Actually we can get as close as possible to a zero trust model. Last but last but not least agent list workload posture. The when we look at what happens between virtual within virtual machines today again, there's a lot of lack of disability.
A lot of security operations teams don't really know what trends into inside of these systems. When we look at traditional cspn assistance, the only give you kind of an external view of what you have within within the virtual machine. So how the VM is configured from a cloud service provider perspective.
providing visibility into the virtual machine itself or whatever workload type you have allows you to understand what malware is running what vulnerabilities you might have what pieces of secret information was left out to leak within the code and then ask these to be remediated upgraded removed, etc, etc, all of this because this is Ageless is done without the change to the workload without impact on performance. What we're actually doing is we're constantly looking at near real time snapshots of running the ends. Thus scanning a non-production system without impact on performance itself.
Last but not least we talked a lot about you know, the challenges that we have from a from a code perspective checkpoint acquired spectral couple of months ago with the thought that as developers create new code as they create new applications and as they move faster. They actually create new security gaps. They actually create new secrets that might be leaked again.
If you heard in the news about so many situations where someone just forgot to remove their GitHub. GitHub access keys from code or maybe submitted something that that has external access information within the code. We want to make sure that this is being reduced which is exactly why we quite spectral and we're working on integrating it as we speak into Cloud guard to provide a single capability a single platform that provides both the secops theme visibility, but also the developers spectral is all around developers First Security enabling them to automate automate secret protection to eliminate whatever blind spots they have from a public.
Like how does my application look from a public perspective and also enforce whatever policies you might have throughout the entire software development life cycle. Eventually, we need to remember that when developers and devops teams actually ask security operations team to secure their ready to be production assistants. It's they need to work day being the security teams.
They need to work very fast to get from zero to 60 60 being, you know, fully automated fully secured system. But if we actually can secure it as developers build the code as they build the application. I'm not saying that they will provide a 100% secure application at the end of the day because they're gonna be things that needs to be done surrounding the system, but maybe it's not gonna be 100.
Maybe it's going to be 90% Maybe it's gonna be 80% So yeah the issues that the security teams really need to be focused on when they're ready to go production are going to be very very much reduced and eventually it's going to prevent them from being choked. Everything here again looks at things from to to directions what you can actually see here is a deep dive on the on the right side into you know, what? What specific issues you have from a development perspective again?
Remember spectral is a developer first a security capability and and company that really focused on how to enable the development team leading to a situation where they could really understand what happens within each piece of code that they have on the system and at the same time provide the same disability to secops to ensure that when things are being built ready for production. Everything is composetic from whatever the security story The developers and the devops team could do. So what are we doing with within our CNET unified platform everybody into space talk about the importance of a unified synop platforms.
But look at what we're doing and I'll just summarize to make sure that secops team become the Hero of the Day first and foremost. We focus on risks that matter with ERM effective risk management. We actually allow teams to not just attend to alerts but instead attend to risks reduce risk and by doing so eliminate and reduce the attack surface overall.
Um as we do it, we also focus on achieving zero crust. We talk about the Kim capability that actually allows Environments to become really tight from a security permissions and entitlement perspective. We talked about spectral and the ability through spectral to truly protect applications throughout the entire life cycle of software development and not just when they are ready in last but not least we talked about ageless workload protection that provides the Deep visibility that you need into those different workload Cog Wheels, but in the same time removes, the the friction between Secaucus developers and devops in do it in an Roi and almost effortless optimized manner in order to ensure that on one hand you have visibility on the other you don't need to spend so much Opex to deploy agents Etc.
so To ensure if we all got the right points. Let me just repeat you want to make sure that your CNET environment provides you A View From a risk perspective. You want to receive the div visibility into whatever cogwheels that you have within the cloud you want to be able to establish zero trust models also within your Cloud applications and you want to remediate fast you want to remediate fast in order to move to the next thing that needs to To that needs to be taken care of.
And with that if there are any questions, I'll be more than happy if you reach out to me my details are in the webinar. Information and thank you very much for spending the time with me and listening. Thank you.
Have a great day.





