Sandy Bird, Sonrai Security | AWS re:Invent 2022
Sandy Bird, CTO and Founder of Sonrai Security, joins Alan Shimel at AWS re:Invent to discuss Sonrai Security’s release of its industry-first Insights Engine which lets developers and security teams control multi-cloud environments to limit data theft.
Transcript
This is texturong TV. Hey everyone, Welcome to our coverage from AWS reinvent 2022. We're here with some people in 55,000 other people who come into Las Vegas for this annual pilgrimage to the cloud.
We are not live on the show floor. If you couldn't tell or actually in our secluded Tech strong TV studios here at the wind Hotel. We've been doing interviews here and you'll be seeing them over the days and weeks ahead as we try to give you a flavor of why 55,000 people decided to come out here to the desert and talk cloud and security and devops and Cloud native Etc.
My guess right now is Sandy bird. Sandy is with Sun Ray. Sunray Sun Ray Sunray I practiced at 12 times Sunrise security and I am not as familiar with Sunray security.
I don't know if you folks are so we're gonna make Sandy tell us Sandy. First of all welcome and thanks for being here. Yeah, thank you.
Thank you. Let's jump into Sunray. Tell us a little of the sun Reed background.
Yeah. Look I spent my whole career in security 20 years was a co-founder of a company called q1 labs to build a Sim Technologies phenomenal, but about five years ago. I really wanted to be kind of like all feet in the future, right, you know build a company built completely without infrastructure of my own and security background.
So we started looking at everyone moving their workloads to these, you know Platformers the service providers right Amazon or gcp. What was really interesting about it was when we looked at the space people have been moving workloads to the cloud for a while at that point, but actually securing them was kind of new and there's some new patterns that were in there and so, you know, we looked at it and said look, there's a huge opportunity here to help people build better security than they ever had on-prem and if they do the right things in Cloud, they truly can do that. And so, you know summary was built on the fact that we could actually secure your data in these public Cloud Platforms in a way that was fire Superior to what you're doing on-prem.
I agree with you. I mean, look, I'm also in security 20 25 years and you know, the interesting thing is when the cloud first started happening 2005 2006. I think a lot of people were kind of Handy Penny sky falling, how am I gonna take what I do here and do it over there.
Especially with security and that was kind of the wrong approach, right? You're not just going to take your security here and do it over there. You needed to develop.
I guess the term would be Cloud native security but that's been co-opted already. So but you needed to develop security that was made for that environment. But I always felt the good news was if you did it, right?
It was a superior environment to do security in than what we were dealing with in the old, you know, cat and castle and Castle hello perimeters and all of that kind of nonsense that we grow up in. so what makes what makes it special for you guys? I think actually that castle and moat analogies and interesting one because in in these worlds, everything is one step from the internet no matter what it is.
And if you tried to use a lot of network-based controls on top of these platforms you'd fundamentally fail because there's too many ways. to basically get inside using identity and then move laterally within these environments and so We took this approach to say okay, like if somebody gets in right or they breach of vulnerability and now they have a foothold. How do they laterally move through a cloud environment?
How is that different than how they would do it on-prem. And a lot of it is through using you know, toxic combinations of permissions and things within the cloud that allow you to you know, jump from often account to account, you know, even different, you know provider to provider in some scenarios depending what the secrets are used for and so we model all that out in the graph and I love graph technology. It's phenomenal and so because of that we can see all of these great paths.
So then you say well then how do you apply security to that? Well, if you actually understand all of the controls and how the cloud is deployed and you can understand all the lateral movement and you start at your most important parts, right? Where's the critical data the crown jewels and you have all those paths now, you can actually understand where you start to prioritize fixing the issues in your Cloud.
Yeah. Maybe it's a vulnerability on the edge that pops an endpoint that allows you to laterally move in. But actually it may be the fact that you have a it will use AWS examples today because we're reinvent right?
So maybe you have a role configured in an Ops account somewhere. Is that somehow get Access to an organizational account in AWS and then from there can own the world. It can do anything that it wants.
Maybe that's your highest risk because that one jump Point allows, you know, possibly tens of thousands of identities to get access to everything in destroy your whole infrastructure. And so we model all that out. And because of that we can tell people where those soft points are within their environment.
The other thing that's really interesting though is the identity is actually kind of the firewall of the old days in the cloud. And so if you look at the AWS controls or the other Cloud providers easy peers similar, they're identity controls that can block a lot of these toxic things that allow this lateral movement and so we can break those chains using a lot of these potentials for you know, scps and Amazon allow us to basically stop some of the nefarious activity and so it is different and it's you know, if it's done properly you can end up in a much better spot, you know, you can use the strong account isolation that Amazon has, you know, told everybody they should do we still walk into the odd customer we laugh, you know, they have one flat Network across all the AWS environments. Why did you do that?
But you know again they learn as they go right oftentimes after paying the party. Yes, but you know, it's interesting right? I've always for the last couple years.
I came to the realization at some point that I am was kind of the killer app for Security it is, right. but you know one of the themes that this year's reinvent is it's not just it's not your mom's AWS anymore. It's not just IAS, you know in from infrastructure service.
Yeah, we're talking next gen and I hate to use the word neck gen or Cloud 20 or 30 with that nonsense. But certainly we're seeing an evolution of what's available and how we do things on the cloud now as it relates to IAM. What I'm personally seeing is a division a cleaving of I from a right we we manage identity.
But it's not necessarily joint at the hip with with Access Control. We can manage identity here and access here and it gives you a lot more. It makes now we're playing 3D chess instead of checkers.
Yeah, and I think there's I think actually to your point. There's actually another layer on top of it because you have to take an extrapolate the human identity from the machine identities. And so there's almost four pillars to this I A&M there's Ina for people and then there's Ina for the machines and this is kind of actually one of the biggest differences we see and again it's as people move to the cloud.
Sometimes they're not even this way. They'll say things. Oh I've got I've got this solved, you know, we use single sign on into roles and that controls everything.
You're like, I'm pretty sure you're Lambda function that you wrote doesn't do that. So, how do you certify that identity? Is it actually and this is the thing, you know, we've been doing this for five years now and what we've learned is that people identities highly unpredictable.
We knew that anyway, right? So when you try to build like least privilege roles for them, you can take some stuff away, but you got to leave them some amount of stuff so they can log into the console and browse around as long as it's not in a fairies permissions. It's okay with machine identities.
You've got about two weeks of traffic. You can lock those things solid because you know every single thing they do. There's weird idiosyncrasies in the IM model where sometimes you got to understand some certain things to know how to do that.
But the reality is you can give beautiful least privilege roles to machine identities very quickly in the cloud. Yeah, and they don't complain they don't call insect. They don't that's amazing you but let's talk specifically how you guys do that though.
Yeah, right. So we have this great graph, right? So we understand all of the possible ways that you can get to all of these identities and we take any of the actual identity.
We'll call them statements that you put in a resource policy or in a an policy and we understand how those blow up into the 40,000 permissions across all the cloud providers because there's lots of those We then take in all of the audit data from that from all those points and we can see which ones of those paths are lit up. So they're used and then we can see which permissions within them are used. And then of course there's some stuff that AWS doesn't log so it's just not there.
So we have these mappings of here permissions that are logged and here are permissions that are not logged and so from that we can build kind of I always call it three levels of policy for any given identity. We can say look you configured it with star. You're not supposed to be using star for everything, you know, so we can just take away the services that they don't use and actually take it from maybe 200 Services down to five that's actually substantially less privilege is not least privileged but it's less privilege you had before probably much safer because if you weren't using sagemaker, you don't need to create sagemaker precise you URLs which are another hole to the internet but in another scenario, we could say look you want to go a little deeper than this.
Let's look at what you're using that are privilege commands things that are creating something deleting something updating something. And let's actually take only those ones that you use that are in those. We'll call them mutations.
We leave those but all the other mutations we take away and just leave you with read-only style permissions for that and that's a pretty good lease privilege role. Actually. It's it's really kind of constraints down to just what's needed.
And then there's the we could use the word zero trust everyone loves to throw I really heard anyway privilege. Yeah. Are trying before we end up every slope?
Okay. Yeah, when you get to that bottom layer, if you really and this you would really only use for machine workloads. Right and you would say look only give them every single permission they give them because the machine workloads are never gonna log into the console and browse around it's only gonna do the things it does and so you have kind of those three levels of policies on everyone but if I could ask all the people in AWS to do one thing just delete the ones you don't use at all.
It's the simplest there you seem customer this week before thousand. It was that within one account 4,000 World crazy number of roles in an accountant 4,000 unused like we should get rid of those, you know, maybe so we'll just have everything against it. Yeah.
Let me ask you questions and I want you to look into this camera. people watching this Who's your customer here give them? Let them self-identify.
Yeah, look we our product is best fit for companies that are moving their workloads to the cloud. They have many teams generally speaking more than 10 different disparate teams. Sometimes 50 sometimes 100 teams building applications on the cloud.
at the center of that organization, there's some sort of Cloud Center of Excellence Cloud Ops Team Cloud security team that's trying to manage that cloud infrastructure securely and set some guardrails. But they need to be able to measure all of those teams with the same set of rules and regulations and governance that you would use. So that's that's awesome.
If you're kind of fit to that customer, you're perfect fit for summary. So from a Side, absolutely. I think every organization though who's moving workloads to clouds.
Test of face this issue as well. They do they do we always I always use the example of our own company though can tell you wherever piece of sensitive data we have it in the cloud. I can tell you where you know, every human can get access to that.
I know that because I know the team right and it's one team building one app when you have 50 teams doing that. It's out of control and you need something with very strong governance built into it for that and it's also the inertia right because you know, it's a Time timeline as the timeline moves forward you build up more and more of this you want to call that that's a good word for for sure for people want to get more information website. com anymore.
That's some old school thing people. com. Absolutely.
All right, Sandy. Thanks for stopping up giving us the load down here. I hope you enjoy the rest of the week at AWS reinvented.
Right. We are here at AWS re-event at techstrung. A studio in the wind we're gonna be back in a little bit with our next guest.
