Erkang Zhang, Jupiter One | AWS re:Invent 2022
Erkang Zhang, CEO of Jupiter One, joins Mike Rothman at AWS re:Invent to talk about the ever-increasing complexity in companies and how this complexity is making everything an attack surface. They also talk about how data connects within a company, and how to understand what data is important.
Transcript
This is texturong TV. Hi, this is Mike Rothman general manager of tech strong research. I hear from the reinvent.
2022 conference Tech strong TV studio at the Wynn Hotel. We're doing a bunch of interviews here around the show and I am very pleased to be joined by ercong Jung the CEO of Jupiter one. I got that right?
Yeah. Yeah. All right.
I got that right. So so her Cog, welcome. Welcome to Texas what thank you.
Yeah. I'm excited but just show going I mean actually, you know before we jump into that why don't you give us a sense of both your background a little bit sure as the company because I know you guys are doing some really cool stuff. Yeah.
That sounds good. Yeah, so so it's been a really exciting fun Journey for for the past two and a half three years. So I I've been a security practitioner for all my career for the past 20 something years was a former see so at a software company and before that was at well downloading Investments head of saw her security and IBM security before that, right or may have heard of those.
Yeah. Yeah, maybe and Cisco and yeah another small one out there. Yeah, no small ones and and had a little bit of a startup experience in My early career which actually didn't work out was a good learning right but I've always wanted to you know, do I have bit of that kind of build our mindset on entrepreneur mindset.
I wanted to do something of my own and and what's also interesting is, you know over the past 20 something years, and I've had a lot of my own pain points in cybersecurity and it kind of really bothers me when when you look at the industry that things are just not working. You know and if you compare to other Industries, let's just say maybe it's medicine. Right?
So I was at a healthcare software before so it was fresh fresh in my mind. So, you know, people are generally healthier and they live longer right? So that means over time if you look at the history of men and things are working but cybersecurity that that's not a case.
You know British are more. There's more of those and attackers is you know, and so why is it why is it that we have so many people here and you know so much good stuff happening in terms of products and vendors and why is this not still not working? So I think you know that really, you know triggered me to leaning to what is the fundamentals that we're not doing right and the fundamentals are just we don't know and understand ourselves very much.
So I try to ask myself these four five questions, right? So one is what do I have? And out of the things I have what's important?
and for those that are important Does it have a problem and if it has a problem who can fix it? And then over time am I getting better? So these five fundamental questions because the environment is so complex.
It's very hard to answer a scale. So that's why I created Jupiter one and the past couple years has been exciting. Yeah now I bet so the rough category is attack surface management or you yeah different category.
Yeah, you want to talk service, right? So in Garner's terms, right? It's a cyber asset attack service management, but I like to thinking more just general simple terms, right?
It's acid visibility asset management or next Generation cmdb, you know focus on relationships and contextual analysis. Yeah. Well, let's talk about that a little bit because as we've seen over the last couple of years, you know things have gotten I don't know I'd say what more complex maybe oh, yeah a little bit right, you know, so now not only do we have all the data that you know on a bunch of different devices.
We've got mobile devices. We've got tablets. We've got other, you know, kind of devices and then we have all these Cloud platforms right clouds can be fast.
They can be, you know, kind of platform services like your date of birth and your snowflakes and you got construction service and we're here at the AWS reinvent show. So everybody's all you know hot and bothered about all the cool stuff that AWS is doing yeah here and there. So how do you really kind of get your arms around all this stuff that's out there.
So that folks can you know really get a sense of what their attack service really looks like that's a great question. Right? So first let's think about what attack service really means right or what asset really means and you know when people think about it, usually it's well it acid or device or virtual machine or workload.
Right? So, you know something that has an IP address that you can reach right, but it's actually a lot more than that like think about companies as a digital company, right? So every company is a digital company nowadays then what is digital?
Is almost everything and anything is digital. So from from workloads to devices to users and identities and access control and access policies and code repositories application SAS products and then endpoint and so on so forth so all of those things Are assets all of those things can be attacked surface. Right and anything that has any value to the business?
Can be attacked and what sort of interesting is. We got to look at the tax service. Not just at surface level right?
You have to look at attack path true because all those things are connected. If they're not connected to the operations of a company then what why bother why do you even have it? Right.
So it's we have to look at this in a way. That is it is not a siled. I'm only going to look at Cloud.
I'm gonna look at code. I'm gonna look at M Points by themselves. They only gives go so far if you look at those by themselves.
Yep, so you're second question was curious to me, right because you know, and that's obviously is it important right or how important is it? Yeah, and how do you gauge that right? I mean in my experience and I've been doing security, you know, probably for as long as you have maybe a lot more gray hair right maybe a little bit longer on that front, but it's always been you know, as somebody what's important to them and they go yeah my stuff right?
So when you take it step back and you don't know Lord shall environment, you know Fidelity in the light, you know, I mean, how do you get a real sense about what is truly important to the company from an asset standpoint? Because yeah, the guy everybody you know, they're gonna say yeah, my stuff is the most important stuff. Yeah.
Yeah. This is a great question is very hard. Your answer and there's a lot of business contacts that has to be applied.
So some of those are you know, technological Concepts or you know attributes that you have to understand some of those are truly kind of business attributes that you have to understand about the assets now because of this complexity, right? So some of Jupiter ones customers have thousands and tens of thousands of cloud environments AWS accounts and within each one of those and thousands and tens of thousands of assets and resources. So combine right there are millions of them.
So if you say that everything is important then nothing it's important. That's right, right, so you cannot You can have a million people looking at a million things. Constantly and they all change over time and all the time.
So to Define what's important? Well, first of all, you have to you know, have some business attribute Associated, right? So perhaps the value perhaps is the impact, you know, perhaps is for example an application and you know, how many users depend on it?
How many customers depend on you? Right? So these are attributes that you can enrich on to the asset itself.
Now there are other ways that you can that contribute to to what a critical asset means. If you have an application deployed to production. Then that application and the infrastructure supporting an application could be important.
If you have a user with access to customer data, then of course the data is important and that user also becomes critical. Yeah, right, so What we can see is it is not a a single definition that defines what's important is more about connecting the dots and understand the relationships and the context to derive on what's important. Now do you guys walk the customer through you know kind of that process?
Is it something that you do with you know some big brain in the sky? You know ml type thing that finds all these relationships. It says yeah what I think that's important tell me that it's not important right and then, you know get the customer, you know, 90% of the way they're 60% of the way.
Yeah, so so it does require some user input but by and large it's automated by Jupiter one building a graph model based on all the discovery of the assets. Right? So we we are an agent this platform that uses apis and read only credentials to discover those assets and as part of the aggregation and discovering all of those assets.
we build out the connections build out this kind of Google map type of thing, right or All of the connectiveness of how one and one thing connects to another into another right and by doing that we use a set of definitions and traversals which then the customers can tweak and update based on their own to identify the relationships and context and that context is drives not only the definition of criticality but or so definitions of what could be wrong and you know, what might be a noise or you know, and and who my be the owner and so and so forth now, that's cool. Yeah, and that's really a lot of the automation that goes into it. Yeah, that's always been you know again whether we're talking about DLP back in the day, right?
You know, yeah, how do you categorize a class by data and keep it you know, that's right up to date and current. Yeah, and now that we're talking about, you know, again millions of assets for typical large Enterprise. Yeah again, how do you just you know, kind of get a sense of what's important?
What's important? So let's kind of dig in a little bit on the whole. Okay.
Yeah, and you know, you know what sort of tricky about this is. Every organization's definition of critical assets are slightly different. Yeah, right and even if it's just a little bit different than what that means is oftentimes a vendor solution, then doesn't work right because it's just not their definition right of what critical is and that's a lot of times where some of these kind of DLP products, you know, it gets hard to implement right because it's hard for that police to their problems made that that's right.
So I think the the the beauty of how we've done it right is really we give you the out of the box, you know easy to get started type of experience, but on top of that it's a true platform that is data driven, you used to data and you use your own queries and your own Tag Games to customize the entire experience. Of the platform including not just the reporting but the visualization and the alerting and all of those are fully data driven. And I think that's the part that that really people are missing.
Right? So something that can truly tailor to the unique nature of their business, right? And and I think when you kind of Really can't take a step back and and look at kind of the evolution of how we used to.
Do, you know bone management, right or just bone scanning right and Discovery from you know, hey, what are you gonna do? Well, I'm gonna you know, just kind of try to find all the IP addresses maybe yeah passive monitoring or anything like that and we really didn't have a lot of the analytical horsepower engine that we have now in order to do a lot of that analytics. So yeah, it's one of these things that again whether it's your company or other, you know competitors in the you know, Tax Service management space a lot of this has been enabled by you know, kind of a lot of the cool technical stuff again, especially a lot of the stuff that we see here at AWS, right?
You know, I mean, you have a date you guys have a date we do not you don't right now and and because why would you you were probably started five six years ago? Yeah, you know, nobody gets up this morning and says gosh I really should build a data center today, right? I mean, that's right coming, you know you why we treat will and you know what AWS is a pretty good job about managing things.
Yeah, right and and storing a whole mess of data. Like so these platforms really enabling very Innovative and cool new security Tech right for guys doing this for a long time. You know, you're you're if you would have said to me, you know, 15 years ago Mike, you know, hey, you know, you're gonna be able to aggregate all of your, you know, kind of yeah that's in you know one place and do you know kind of cool analytics to really find patterns of things that you didn't even know to look for I would have said please get out of my office because I've got work to do right and it just wasn't a thing.
You're right. Yeah timing is everything right? And the maturity of the industry is also what drives you this point and and frankly, you know, 15 20 years ago.
There's just not this level of complexity. Yeah, that's right and is it was manageable and today without this we started by you know, thanks haven't gotten better. So wasn't like we started out things were great.
And that now they suck right, you know, that's right. Yeah, he's just gonna worse over time. But yeah, but that's why that's why we do this, right?
So new technologies like like you're wanting to this because You know, it's funny. I just I wrote something on Security Boulevard last week and it was kind of like my little Ode to you know, Thanksgiving and everybody, you know says oh we gotta be thankful for this and and you know, my statement was thanks for nothing, right because again, it's that same thing whereas, you know, we wake up every morning as a security person or like yeah, we feel like we're further from the shore. It's like man, I work hard yesterday.
I wrote a lot yesterday and I look and I'm like further from the shore, right? That's right. That's right.
That's yeah security, you know, which yeah, you know kind of problematic when you're security person. Exactly. Well, you mentioned a couple of things I want to talk about those a little bit.
Right? So one is vulnerability management and and two is, you know, security people and maybe talents and skills. Right?
So, you know vulnerability management is an interesting thing and you know, I think you would argue that that any proactive security is vulnerability management, right? So we have all of these terms that we call himself, you know cspn. Yeah ESPN ESPN SSP and what not right at the end of the day Are those vulnerabilities bindings misconfigurations should be?
A form of vulnerability, right and I think and again it boils down to the way that you look at vulnerabilities. Are you looking at findings or are you looking at assets? Or attack surface, right which one matters the most why would you I would argue why would you care about a findings?
If you don't know what your assets and a tax service are that's right. Right. So one of our customers Robinhood actually transformed their vulnerability Management program into a asset-centric view rather than a finding Centric view, right because at the end of the day any vulnerability whether it's a scanner finding or misconfiguration, Is all about yeah, does it have a problem, you know your assets, you know, what's important and then does a problem.
Right and then the last part is also tricky then is how do you find the owner? Right? So that's that's right, but great question, right?
So so, you know again here at AWS one of the things that you know, you can do fairly easily is tag all these assets right? So that's you find in your environment or your customers environments. That tagging is largely adopted.
Is it for ownership? Is it for you? Yeah organization.
Yeah it is it for operational. Is it for criticality, right? Oh a lot of stuff right do from from attacking standpoint?
Yeah, I found right again. I'm doing this, you know 12 13 years and in the cloud at this point most folks have no idea what it is like tagging right and they can do it, but they don't do it and and a lot of cases. Yeah.
Well, there's blind as they were you know from yeah they want. Yeah, I I think that's and unfortunate reality. And I think this is what contributes to a lot of the Garbage and garbage out situation right when you when you do data analytics, right?
So we highly recommend customers do tagging. Right? So tagging can be how you classify data and Hiking can be who are the owners or you know, tagging can be organization units or projects or applications right in systems and there's multiple ways of tagging it now.
This goes back to two interesting parts, right? So one is tagging is inconsistent. Right.
So nobody I I would I can guarantee you a hundred percent of all companies. Nobody has done a complete tagging of their resources. It just it just doesn't exist.
You know, there are people who might be doing nothing versus slightly better or maybe close to company, but nobody is complete in their tagging. So now then this goes to where a graph model like J1. Can do more inference based on partial tagging right?
Because if you if you come in and say I got nothing nothing is tagged right then we're kind of out of luck. Yeah, right. But if you if you have just a little bit of starting point, then we can walk the Traverse of the graph to to understand tagging from from the hierarchy and the you know, the the parent child relationship and so on right so kind of infer what the right pack should be at whatever levels and that's how we also Define a Ownership, right?
So let me give it an example. Right? So if I have a production workload that is not hacked.
And you say who is the owner? Now what we can do is we say well, let's let's walk two path, right? So pass one is What is the service that workload belongs to does the service has a known?
If the service doesn't have an owner, what is the owner of the AWS account? Yeah. And you better be tagging at least at the account level, right?
So who the account owner is, right. The account has a contact email, right? So so this way we can at least determine what is the closest so that's one path.
The second part is How is this provisioned because usually it's infrastructure as code right is it cloud formation is a terraform which code Repository? Created this resource. Then does the co-repo have have an owner?
Right, if the code repo doesn't have does not have an owner then who are the latest pull requests who created latest. Well, somebody has to create this pull request to make those changes and that's associated with some GitHub user or some developer. Right?
So we we can just by walking the graph infer the closest owner to that resource. Yeah. So that's that's the the nature of what J1 provides at other platform cannot right?
And and that's what I and and again as we you know. One I think that's a great, you know kind of overview of you know, kind of some of the challenges and how you've addressed some of the challenges of historically figuring out what's happening. I don't want to neglect the fact that we are at AWS.
I know you guys are now yes. Yeah, we yeah, we are in AWS partner as we're making some announcements on how we are doubling down on that partnership, right? So it'll be as is part of Jupiter ones to Stellar partner program as well.
And you know, we have join go to market. Right? So J1 is on AWS Marketplace and worrying their startup program.
So there's some of those details we will be sharing the news today or tomorrow. Okay? Yeah sounds great.
That sounds great. Um, how do folks get in touch with Jupiter one if they want to, you know, check out what you guys can offer on that a tax service management standpoint. com and Jupiter and oh and ye, okay good.
All right, we're gonna thank you for your time and appearing with us here text on TV at AWS reinvent conference. Great to chat. Yeah.
Thank you Mike. Yeah. Yeah.
It's been fun. Yeah. Up.
Thanks everybody. We'll be back with another interview shortly.
