Andre Rall, Uptycs | AWS re:Invent 2022
Andre Rall, Director of Cloud Security at Uptycs, joins Alan Shimel at AWS re:Invent to talk about the Uptycs platform that allows a user to get visibility into their assets and assess risks to remediate security breaches. They also talk about Uptyc’s Secret Menu promotion.
Transcript
This is texturong TV. Hey, everyone. Welcome back to our continuing coverage of AWS re:invent 2022 out here in Las Vegas.
We're at our studio to extract TV studio here at the win. We set up the suite and didn't doing a bunch of interviews all week meeting some great people want to introduce you to our next guest today and his name is Andre roll. And he is with uptick.
Actually only since about April you had said right on. Yes, that's correct. Yeah.
Anyway, welcome welcome. Thanks for having me. Rather than me trying to read from some biography.
Why don't you share with our audience a little bit about your your personal Journey? Yeah. Thank you.
So like you mentioned, you know, I've been at uptex for several months right now. Prior to Optics as with AWS for over five years and I was overseeing their account take over division. So a lot of folks don't know this but AWA says a division that focuses on legitimate accounts being compromised or breached so I ran their team and you know, some of the learnings we found there were just immense which we'll get into a little bit but so spend five is at AWS prior to that as at Rackspace for seven years.
Oh, really? Yep. So, you know, so got a lot of knowledge and experience within Enterprise companies and my backgrounds always been within Cloud security cyber security network security.
So it's been a interesting Journey just to see how this has evolved over the last couple of years, right? We didn't even call it cyber security. Yeah, that works security or infosec.
Yeah anyway. You know that's interesting about the account takeover term. If you don't mind, I want to spend them just a moment on that and that is you know in talking off camera.
a lot of organizations They don't take action till you contact them and say hey, my account's been taken over. My coinbase account was Packed my Facebook or whatever and I'm not blaming any of them. But you know, it's very it's generally a reactive.
Yes situation where a customer says. Oh my goodness, you know, I've got bad bad stuff going on. From what you mentioned the the Amazon model is a little bit more proactive.
Yeah. Yeah, exactly. So.
At Amazon AWS. We had a a very skillful technical team a lot of machine learning. We would look for anomalies in the data.
And we would actually proactively notify customers and we're necessary. We would actually proactively mitigate or terminate any resources that were spun up by these thread actors nine out of 10 times. They were spinning up resources to mind cryptocurrency.
Sure. So yeah. We're well, it's not even get into where the crypto Market encourage these are today, but that's interesting that it was a much more of a proactive mlb-based take action.
Type of service you want to realize it's not everyone out here me and be familiar with uptick so they know AWS. Yeah, we're here but what about upticks? How would you describe kind of uptick's Mission to to our audience?
Yeah. We you know, we're a a unified platform. So if you think about security You know, you have developed a laptops.
You have containers kubernetes you have cloud. We offer a platform that allows you to gain visibility into all of those Solutions a single user interface that you can go in and get visibility into assets and most importantly we give you a risk assessment and will allow you to remediate you know, or so we find that customers find security technology. It's complex.
And the reason they come to us is because they want to make as less complex and they need our help so, you know to sum it up we're a cnap and XTR platform that money many customers can use to kind of help manage their risk in the environments. Absolutely and look our audiences is technical. They know xdr.
Yeah, right detection and response tend to detection and response and so the you know, The initials don't get them too, too out of way. But let's talk a little bit about Secrets menu. They're not spend a lot of time, but it's something you know upticks is working in.
Yeah, sure. Yeah, absolutely. So we're running a campaign right now.
You can get all of our Solutions everything. I mentioned endpoint detection kubernetes containers Cloud, you know cspm cim CDR For one dollar really one dollar. So Christmas, all you have to do is sign up by December 31st, and you can enroll a minimum of 100 assets or maximum of 1,000 assets.
Cloud or on-prem 2 well and you get to use a full product suite for for those assets and with that comes Enterprise supports love it. So it's it's a pretty pretty good deal pretty good deal. So look, I I don't want to you know, hey, it's crazy Yeti and sign up now, but for a dollar you got a month folks.
You can check it out. You know what I find interesting though when they look at the uptick story. Like many companies today.
Look we're all focused on cloud and Cloud security. There's 55,000 people here, right? So it's all about the cloud.
But today's world of security and you you've been at security a long time, too. We've broken down the silos about endpoint security Cloud security network security. I am all the It used to be much more rigid that generally someone doing like look from where I came from.
We had host space security. Right endpoint security network security and kind of never the twain shall meet. But today if you don't have sort of a comprehensive.
Security offering like uptext does here you you can't really be good just in the cloud you need. That endpoint sort of view of things and and see what's going on here to help make you better hear about and vice versa. Yeah, absolutely.
And one of the biggest challenges Caesars of having right now is security tool sprawl, you know, and there was a statistic that I think the average security team is using anywhere between 30 and 40 different tools. You know, imagine the security team and the security manager having to be successful with multiple. Tools multiple user interfaces becomes a nightmare.
So that's why I think upticks is uniquely positioned. We have a single tool that you can go across that threat landscape. Like I said from developer laptop to Cloud to on-prem.
Yeah, and you know, we're there to help you make sense and manage your risk, you know, the it's the complexity issue Security's heart. Yeah. I don't care whether it's Cloud security endpoint Security's heart.
So we it's always been that way unfortunately. It's harder when you have this. Sprawl as you called it, right and you get to manage.
It's probably your how many how many endpoint detection and response tools? Do I need and it's hard. So I want to spend the rest of our time though talking a little bit about kind of the lessons you learned to Amazon or the count takeovers and so forth.
I'm bringing it into what you're doing it up ticks, right? How do you build on that knowledge to make an upticks offering or an upticks better? Yeah, you don't mind.
No, absolutely. One of the biggest lessons I learned at AWS was Cloud security to your point is so it's very complex. Even the Enterprise customers that we had that we engaged with who's accounts were breached.
They were at a loss at times of what to do. So. Simplifying cloud in the security of cloud is one of the biggest lessons I've learned.
The other one is how threat access think. You know AWS for example is made up of bunch of apis connecting all the services. That's really what it is.
When thread actors are in an environments, they're hitting certain apis to achieve a desired outcome. We got to know. Threat actor Behavior almost like a fingerprint a pattern and really understand how they think through it.
So thinking like a threat actor, but also how do you simplify Cloud security for customers or my two biggest takeaways? Let's go to Optics now. So at Optics one of the solutions that I've developed is called Cloud detection and response.
Okay going to a thread actor. They have a design outcome. They need to for example, escalate privileges.
We have mapped out the sequence of apis that thread actors are calling and we're displaying it in a way that is very simple to customers to say. Hey, someone has escalated privileges in your environment. Here are the exact apis that they called and by the way, here are the links to the API documentation, and we're going to give you metadata.
As a long-term credential was used was an I enroll that was used. Where was a source IP. Has that Source.
I be seen been seen in your accounts in the last 90 days as a user agent been seen in your account. So we're trying to help security teams identify identify and get to a point of action very much a lot quicker and most importantly we're giving remediation. So here's what you need to do, Mr.
Customer Mrs. Customer to go in and remediate this because a lot of people don't know how to do the remediation. Yep.
So your floor I've seen in the security world for as long as I've been in it and I I wonder where it went up to get to this. So when I first started a company back in 2001 called still secure. You know a lot of the world was using snort for IDs that yes you remember right and the idea was intrusion detection system and at the time checkpoint, you know checkpoint was able to I forget what it's called opsec or whatever where they you could like insert a rule into in the fly into a check point firewall to block something based upon what you saw, of course, by the time you were able to do that.
The attacker was in out back home eating lunch and spending your money, right? But but nevertheless it was the beginning of some sort of automated remediation or automated blocking so we had this great idea. Hey, we're gonna build Blocking in we're gonna go from IDs to IPS intrusion prevention and the world is going to love it because we're actually being more proactive.
We're blocking them as it's happening, but we really weren't blocking on some other story. But anyway, I was so surprised by the market. It took literally almost 10 years.
for the market to come around to the idea of at least the most basic kinds of Code Red kind of worms. Why can't I just block those automatically? Why do I need a human?
Why do I have to make my case? Why do I have to show you the evidence? And then say maybe you should do this.
This is what you should do. When do you think we go to the point where we have enough Trust? In ml have enough trust in an upticks offering here where hey we're gonna block this until you tell us not until you tell us to unblock it and you tell us to unfix it because where that certain that this is a an attack.
Yeah, you know, the whole automatic remediation automatic blocking it's a very sensitive subject because I know There are false positives and I think for us, you know, we want to get to that stage and you know, there's certain customers on our endpoints that we automatically do that kubernetes. We do it right? Oh you do.
Yep uncertain certain actions and certain rules we can take that. I think for customers to get comfortable with that and confident and confident with that. They need to trust the tool.
They need to trust that our alerting and detection is there's high confidence in what we're servicing. But again, you could have a developer have a bad day and accidentally do something. They're triggers a role right and now they're blocked and potentially bringing down a production system.
So I think it's it's you know, it's a it's a very slippery slope. Yeah, but you know, we can do it today if customers allow us, you know, going back to some of our offering like CDR, we're going to offer automated remediation one click go and revert this policy go and revoke the session from this I am role. So we're gonna give customers that option if they want to do that.
I I love and I think that's where we're heading. I think what it is is a period And I think the like everything else in Internet time the time frames crunch. There's a period of I need to be confident right man.
You're sending me, you know, you sent me 10 alerts in the last three months and every single one was right on right? I trust you when I get an alert now, I know there's a very high degree of probability that that yeah is what's going on. How are you because I mean, this is a rolled out.
You know this thread actor kind of ideas is rolled out with upticks already or it's something yes. It's rolled out. It's rolled out.
How are what kind of response you're hearing from people like who were watching this they love it because what we're doing with CDR is we're opening a window into half straight access think you know, I've spoken to a lot of security Engineers security Executives and they can tell you how to secure an environments. But as soon as you say, how do you exfiltrate data? How do you escalate privileges?
They came from a high-level explainer. But say no give me the exact sequence of apis you would call to do this. And they struggle so that's what we're doing is we're showing them the thread act to behavior.
In how to achieve that desired outcome. Not only are we opening that window. We're also educating them now now the security team can say, oh this is how you escalate privileges in a cloud environment.
This is how you can exfiltrate data. Oh, I did not know that right. So we're helping educate them so that in the future when they go and design or evolve their Cloud security strategy.
They can take that into account and and understand how great access think. I love it. Let me ask you another if you don't mind.
Yeah. What's the drag time from the time you like kind of say hey this wait a second. This is fitting this pattern.
This looks like a threat actor. To alert to being able to take action. Less than a minute really.
Yep. Oh, that's fantastic. So we ingest for example AWS cloudtrail AWS config VPC flow logs.
So as soon as that generates and gets sent to us, we're already learning detecting off of that. So you you recognize it almost like on almost every time. Yeah almost instantly obviously, you know, we're at the mercy of AWS and how quick they can generate it and then we're using you know, you leave them and now you're bad now thing.
Yeah, I love lyrics they're great. But but yeah, it's almost here you need the info to exactly and just one thing I keep talking about AWS. You're not gonna buy swords in but we're multi-cloud AWS you as you can do all that everything.
I mentioned across all the different clouds. And we could get it offer a dollar for a dollar. There we go.
What a great promo. That is hey. I want to thank you Andre for coming up and sharing with us.
You know, I I think you're also what the most important thing if anyone is gonna take something out of this is to be successful insecurity. You got to kind of think like a bad guy once in a while like a threat actor. You got to understand what their motivations are.
You got to understand what they're techniques are and you have to understand your own infrastructure. And you know, what are the roads and paths they take in there. In order for you to to be successful against them, right?
We can't we've passed the time in security where we could sit back. And and wait for the bad news. Yeah, fingers crossed.
No one no one breaches me. Yeah. Yeah strategy.
It's not it's not a winning strategy. It's just not Creed. I want to mention one other thing up ticks because I'm looking at his jacket.
It's upty CS. Yep, right? com up six calm and then the promotion is upticks secret menu calm.
I love it. All righty. Thank you so much.
Thanks for having me. This is not a problem. com.
Hey listen till the end of the year end of the year a dollar for the it isn't no brainer guys go do that. Learn to think like a threat actor we're out. We'll be back in a little bit a moment here with some more AWS reinvent.
