Advancing SASE and Addressing AI-Based Threats with Etay Maor at Black Hat 2024
Etay Maor, chief security strategist at Cato Networks and founding member of Cato CTRL, discusses his role and the importance of the Cato CTRL (Cyberthreats Research Lab), which focuses on threat intelligence and network security. He explains the innovations at Cato Networks, particularly in Secure Access Service Edge (SASE) and the company’s rapid growth. Maor also highlights the findings of the Q2 2024 Cato Threat Report, emphasizing ongoing security challenges, such as the prevalence of outdated vulnerabilities and the rise of AI-based threats in corporate networks.
Transcript
This is Techron tv. Hey everybody. We're having a lot of fun here at Black Hat talking about security, network security, a little bit of everything.
I have the great pleasure of being joined by Ike Mayor, excuse me, uh, from Cato Networks. You are Chief Security Strategy Officer. Am I close?
Yeah. Chief security strategist and the, uh, founding member of Cato. Control Of Cato Control.
Tell us what Cato Control is. It's a founding member of that Control stands for Cyber Threats Research Lab. It's the threat intelligence arm within, uh, Cato.
We do security research based on human intelligence, uh, network and enterprise security. Those are the people who get no sleep to make sure we can sleep. Right, Right.
I think no sleep is his definition. Good definition. Great.
Well, uh, folks don't know, uh, about Cato Networks. Tell us a little bit about Cato Networks. Sure.
So, uh, Cato was founded in 2015 by Shlomo Kramer, uh, founder of Checkpoint and Imperva. Um, and actually defined SS e Secure Access Service Edge before Gartner defined it. Before it was SS e Ss e before it was ss e, uh, which is the convergence of, uh, networking and security into one cloud platform.
Um, very proud to say that now we're also recognized in the Gartner MQ for single vendor SSE. So we're a leader in that space as well. Uh, over 2,500, uh, customers worldwide just surpassed 200 million in a RR company is growing and getting a lot of attention.
Doing well. That's fantastic. Yeah.
Well, a lot of stuff we could talk about. Um, I know you have a report coming out soon. You wanna tell us a little bit about that?
Sure. So we are just releasing the Q2 2024 Cato Threat Report. Um, it's a detailed report about different threats that we're seeing.
Um, if I'd have to highlight three things that kind of stand out for me, uh, number one is we discuss Intel Broker was a very prevalent threat actor in the breached, uh, forums, selling a lot of, selling a lot of credentials for very high profile companies. So we did a very detailed brief on this threat actor. Uh, number two is the Amazon brand constantly being used in cyber squatting.
So actually it's 66% of the cybersquatting attacks that we're seeing involve the Amazon brand. Interesting. That's a lot.
I didn't realize it was that high. It is super high. Uh, you know, you sometimes see these peaks when events happen.
We can theorize that this maybe has to do with, uh, prime Day. So the criminals were trying to capitalize on that event and sending out phishing and malware attacks through impersonating Amazon. And, uh, the third thing is actually the usage of different vulnerabilities that attackers are using.
You know, I'm a security researcher. You say zero day. I won't shut up for half an hour now.
I'll just talk, I'll get permission to say it before I Say it, but, uh, looks like the cybercriminals are actually using very old attacks. Log four J is still number one. There's all kinds of web vulnerabilities.
Things that are five, six, even 10 years old are being exploited, which kind of tells us, you know, the state of patching and vulnerability out there. Yeah. We're just having a conversation with one of our colleagues yesterday talking about how much log per j is still out there unpatched Three years now, right?
It's, yeah, you would, and and, and I think for folks who are not in security or not in software, don't, sometimes they just don't get updated. But it's also the whole supply chain of how deep that log four J is and whose stuff is it in. So it's not necessarily easy just to say go patch it.
It might be, I need to contact my vendor here. They've gotta contact somebody else before you get a patch rolled out. Yeah.
You know, it's, it's very easy for it. Tie the security guard, Hey, just patch log four J But like you said, sometimes you don't even know that you have it because it's nested within some software. It's a library within some software and yeah, the CISO's job is getting harder and harder.
Um, mm-Hmm. All the time. Talk a little bit about how do people best use your threat report?
'cause it's good to know, kind of stay up on, on top of what's happening. You know, some things maybe a CISO in their organization should take some action upon and change a procedure or inform people about a certain kind of phishing. Other things are really kind of more insider, you know, inside baseball, if you will, of what's happening in security.
How do people best use that report? So, the way that I think about the report when we generate it, uh, I have this acronym in my head that threat intelligence is an art, art standing for actionable, reliable, and timely. And if I don't hit these three criteria, it's not gonna be in the report.
So it's things that people can take action on. Having said actionable, you know, the information is related to a whole quarter going back. So I also look at it as three layers deep.
I look at it strategically, operationally, and tactically. What do I mean? I want to tell the CSO or the reader, whoever that is, what is happening in the world, and then what is happening in your industry.
And then also my what is happening to you might happen to you directly. And so all the information there is stuff that you can take and incorporate both in strategy and policy, but also take and immediately implement, you know, solutions or, or, uh, uh, defensive and, uh, um, detection capabilities within your, uh, security stack. Mm-Hmm.
I, I'm really curious, given your place in the world, KTO Networks place and being early and sassy before it was sassy, you, a lot of, a lot has happened since 2015. Um, you think about much more adoption of cloud native and microservices and Kubernetes. It was around then, but, you know, we're, we're at a different stage of, of adoption then.
I think a lot more companies have hybrid cloud now. Mm-Hmm. Because of acquisitions or needing to be in different clouds, you could just go down the list of, you know, what's changed.
And of course, SD WAN and SS e on top or, or on the edge, you know, if you will, to get access to that. What, what do you see as the biggest change you, you've adapted to or maybe taken advantage of? So I, I think you hit it, uh, exactly with digital transformation, uh, came the move to the cloud.
Uh, one thing that kind of bothered me throughout the time, and this is where Cato comes into play, is that we continuously adopted point solutions for different threats. So, you know, you'd have, and I come from a vendor, you know, I, we are a vendor, but you, you'd have vendors saying, oh, you have a virus problem, malware problem. We have a solution for that.
You have a DLP problem, we have a solution. You need a c we have a solution for that. And I visit a lot of security centers and you see people sitting in front of, you know, eight screens.
Now, it might be cool for like a Hollywood movie Mm-Hmm. But that analyst is crying there, maybe even at night later because they're working on trying to correlate so much information, like I said, from different hybrid environments and so on. It's becoming hard.
And I think it also contributes to the turnaround rate that we see in cybersecurity as well. And, you know, sometimes I get asked, what is the biggest threat that you see? And people think I'm gonna say, okay, oh, it's ransomware or a piece of malware.
The biggest threat that we see is the organization's own security complexity. You see this because attacks are still getting through. You see it through bad management of security systems.
You know, misconfigurations missing all kinds of things, missing, alert, alert, fatigue. All these things contribute. The turnaround rate that we were talking about before.
All these things contribute to being actually the problem. And that's, that's where we're coming in. That's what we're, we're trying to solve It.
It's kinda like thinking, I remember, I remember a time in my career where we could say, this is what the network looks like, that it's at a state. Right. Kind of steady state.
Unless I changed it or one of the engineers changed it, you knew what it was. Today. It's so big, it's so complex.
There's so many parts to it. It really, in, in and of itself is never at a steady state. It's an under constant threat of both threat and change that's happening.
Even if it's not inside your, you know, where you'd determine your network is, it's a service provider, whatever else it might be. So you kind of have to, it's like a rolling truck that you're trying to change the tires on. Right?
Right. Keep track of security. Never been, has never been like a checklist.
Oh, I've done this. I'm good. I can rest you, you always had to be on your feet, but you're right, it changed.
One of the major things that also contributed to this was, uh, COVID VD, and all of a sudden remote work that's coming in and gone are the days of the CISO coming to the office, and I have my perimeter, it's protected. We're happy in it. Mm-Hmm.
Now you have third parties, suppliers, and you have people working from home. You have cloud applications that your organization has to use, but you don't control their security. You're inheriting their security.
Right. And so, yeah, it, it, it is constantly changing and constantly we need to, to adapt to all the different, you know, the attack surfaces is constantly growing. I'll give you one example for, uh, uh, from what we're seeing in enterprises, there's a huge growth in the usage now of AI based tools.
And I'm all for it. Uh, I, I love using these different tools, but again, do you really know what is happening on your network? Because what we are seeing is all of a sudden we see all these consumer facing AI applications being used on corporate networks.
Mm-Hmm. If two years ago you would've asked me, what do I see? I would tell you, Hey, why is TikTok number 23 out of 1500 applications?
I see number 23 in usage on corporate networks. Mm-Hmm. Before even asking the question of is it safe or not?
Do you even know that that is happening? Mm-Hmm. Now we're seeing the same thing with ai.
And that brings all kinds of problem, privacy issues, regulatory issues, data leakage, security. And, and it's Not to speak of productivity, but that's an That Yeah. Without even talking about that, of course, you also have also have the flip side, uh, to it.
Uh, what happens when the AI that you're using is taken over by the attacker and can be used against you? You know, all kinds of tools that are supposed to help you. All of a sudden, the attacker can use them as well if they have control over your, one of your systems.
I'm really curious of your perspective on this. I'm, I'm gonna bring up CrowdStrike not to talk about them, but, you know, there's a lot of lessons to be learned from that. And I was talking, I've talked with several people on my position is if the only organization that improves out out of that, you know, that if the situation is CrowdStrike, then we've lost a huge opportunity for all of us to learn from it.
What do you, what, what has that done, that incident, very large incident. What has that done in your te in terms of your thinking, whether it's how you deploy software or your operational procedures? Of course, testing is an obvious one, but it's, you know, you have a, you have a different level of trust, right?
Yeah. That you're, 'cause you're providing such an important kind of internal component inside, inside it, not everyone sees. And you have to be really careful about what you distribute and how you make changes to that.
Definitely. First of all, I think CrowdStrike George and the team, their commendable job, they got into a situation that, you know, other companies can get into. And they, they had a lot of work and they went to it.
Um, I think what we need to take from this is, uh, gradually of deployment, right? That's something that we do internally as well. You know, how do we deploy software?
We actually had a a, a blog about it that we described. You know, that if something breaks in what we do, it's never for everything all at once. At the same time, we test a lot of the stuff on our own, uh, systems.
And of course every deployment and development is gradual. So I agree with you. I think the lesson learned for any organization out there, especially ones like, like us as well, which are the infrastructure, you know, the companies rely on us, is how do we deploy gradually and how do we go through, uh, the rigorous testing in order to ensure that events like this don't happen.
Interesting. It also makes me think of the devices themselves. In this case we're talking about Windows machines could be anything.
But the fact that you can get into a state that the only way to recover is to go physically touch the device. 4 million windows devices. I don't know exactly what it is, but yeah.
People climbing up in a cabinet in the airport, you know, to, to get to whatever computer to reset it. Are there things we need to think about as we, as people develop the infrastructure itself to make it so we can recover from a, let's say, a, that downstate, not, not totally bricked, but it's something where it's not gonna fully boot it up and be operational. Yeah.
I, I think this is, I think top of mind for CISOs. And now of course boards are gonna be discussing this as well. Uh, I, I put the, this event and, you know, it's almost like a once in a decade event.
Something this big, uh, uh, has ha has happened. Not in the cybersecurity category. For me, it's more the business continuity, disaster recovery side.
Yeah. Resiliency. Right?
Definitely. I like, some people ask me, what do you think about the, the, the cybersecurity incident? I was like, you know, for me it's closer to an earthquake that takes out an infrastructure than it is to a cybersecurity attack.
It happened on a, to a cybersecurity product, but it can happen to anything that has infrastructure. And so I think, yeah, organizations need to think, the vendors need to think about the gradual deployment and how they assist their customers. Organizations need to think about their business continuity, disaster recovery and Yeah.
You know, almost, almost similar. I know, I didn't want to quote it to cybersecurity, to ransomware attacks where you might have to go physically and do manual backup and manual recovery. We have to think about these processes and it's, you know, it, it's good that now this is something that is in the minds of organizations and perhaps played out and think how you do it and prepare for it.
Just like we do cybersecurity, incident response, business continuity, and disaster recovery. There's no, this can't happen to me or this will never happen. I had flashbacks fearing of, can I find that RS 2 32 cable to get into my Cisco routers if I had to.
Right. Yeah. Uh, interesting times.
What, what's your takeaway from what's happening in Black Hat where you kind of see the thing just, people talk about CrowdStrike, my view of it is people are kind of being delicate about it, not trying to bash them. 'cause we all realize it could happen Yep. To ourselves.
But then there are people, you know, very seriously impacted. Aside from CrowdStrike, what else are you kind of taking away, picking up? So first of all, I'm, I'm really glad to be here 'cause it's an opportunity to meet everybody.
You know, it's def con blackhead and RSA where everybody's really coming together. Mm. So it's opportunity to meet other researchers and talk to them face to face about what they're saying and how they're coping with things.
I'm really happy about the level of discussions and openness that we're getting to we're maybe we're not as, as good, so to speak, as the cyber criminals who are very open to speak about things. Um, but I'm happy we have these, these opportunities in terms of what people are talking about. I see a lot more discussions today around, uh, platforms and, uh, you, you, you talked about cloud before, so, uh, platforms, some organizations might call it platformization, but we're talking about like cloud native, uh, solutions.
Um, SASS e solutions. Like, like Cato, you talk, you hear talks about, you know, the wiz the other companies of the world that are doing pure, uh, uh, cloud. So I'm, I'm, I'm really happy to hear these types of discussions.
Obviously everybody's talking about ai, you can't escape it. Um, but I think it's a more, you know what, it's, it's, it's a better discussion that I heard from a year or two ago where it was super hyped now, where people are actually talking, okay, what are your models doing? How is it actually helping it aside from the AI hype Yeah.
Everybody's using LLMs and, you know, different machine learning. Let, let's get to, to what is really happening there. So I think the discussions have gone a level up in terms of sophistication going beyond the buzzwords.
Yeah. It seems that, uh, phase one was chat bots, right? And yeah, gen gen, uh, generative ai, a lot of discussions I've heard about how do we take all this data that we've got that's emitted by devices, software security, all that kind of thing, and use it in some more aggregated way to help, you know, kinda leave that cognitive load that the security engineers in, in the op center, you know, are struggling with or, or maybe, you know, identify new patterns that are happening, more ATPs kind of, uh, that are happening over time.
But there's a lot of interest in how AI can leverage a lot of that data too. Yeah. It's, and, and we're already doing the, um, so I mentioned the, the Q2 24 threat report.
Um, we did an analysis of one point 36 trillion network flows. Now, as much as I love my job, I won't be able to sit them through all this data. It Had to take some time though.
Yeah, yeah. Probably a couple of decades probably. So, yeah, we use, so we use supervised and unsupervised machine learning to find exactly that, the patterns.
And it's really, it's like so cool to see this as a researcher stuff that I couldn't dream of 10 years ago. Mm. Um, you know, just pop up in front of my, my eyes because it can identify the patterns within huge clusters of data, really something that I couldn't do before.
Or maybe I would try to sign it with all kinds of static, you know, signatures and try. Now I have systems that are able to say, Hey Ty, you see that event and that event and that event by themselves. They may be benign, but they have it so close to each other and from these machines, you should really look into that.
So we have something called, uh, Sam Suspicious Activity Monitoring. So now the system is alerting me about something that it says, I'm not gonna stop it, but it's suspicious enough for you to look into it. And that is exactly, that is actually almost 10 years of AI training in play.
That now that the algorithms know what they're talking about, we've already tested them, we've gave them back our feedback, and yeah. Now we're using AI to sift through the data. I mean, I, through even, even LLMs, it's really cool that you can take a report and say, take this report and just give you the Mitra t tactics out of it.
You know, it's, they're not mentioned there. Just tell me what they are. Saves me so much time as a researcher.
It's, it's, it's really cool tools. Yeah. We seem be gone from chat bots to kind of integrate that into our tools.
Right. That natural language to query data or help to find this, help me recraft what I'm trying to put together. You talked about, um, machine learning seems another advantage we have is 'cause of the cloud, frankly, we've kept so much data for so much longer, you know, vlogs and things.
So you can go back and look at a trillion flows, right? Yeah. It's, and by the way, and that applies exactly what we talked about before, for example, patching and how to make sure that things, uh, don't break.
We can take all the data and say, okay, now let's take all the network, uh, data that we have and let's apply the patch that we're planning to pa to apply. Would it break anything? We have all the data so we know what's going to happen.
So it, it helps in security, but it also helps in vulnerability management and identifying attacks and stopping attacks. So yeah, that we have a lot of different opportunities. Threat actors are looking into those things as well.
They're not quite there yet. It's an awkward thing for me to say. We're ahead of them by utilizing in AI utilization, you have to Say that quietly Because usually, you know, they're early adapters.
Mm-Hmm. They, they always take the technology and try to use 'em as, uh, as early as possible. They're kind of like staying away from other, like they're, it's not that they're not using it, they're using it for very specific things.
I think the industry has really went hard on, on using ai. And you're gonna see we are already seeing some very interesting results. I'm slightly concerned what happens when AI hits the consumer side and we, you know, let our AI based assistant, Hey, here's all the emails.
Here's my calendar, here's everything I know, set up all the meetings. What happens when those things get targeted by in threat actors? I'm, I'm, I'm not looking forward to that.
I hope I won't have Concentration. Yeah. Yes.
Exactly. What's, what's your thoughts on open source? A lot of security discussions around open source and also in developers.
I, you know, a lot of conversations I've had here is how much, how big of an attack vector developers are. 'cause that's an easy way to download this, this image, and suddenly you've got something rotate or something added to a developer workstation makes it into your code or whatever it might be. We didn't think about developers, the attack surface.
Um, we didn't, unfortunately, some nation states did, and we saw this with the XZ vulnerability. Perfect example. Yeah.
Right. Open source project. Um, I'm, I'm a huge for point of open source, but I think that gives us, uh, a very good case study to think about.
I think that specific incident also shows when an adversary has the time and is willing to stay there for several years before deploying attack. And frankly, we were very lucky that researcher from Microsoft, I forgot his name, but full credit to him that noticed, uh, the attack otherwise, I'm not sure how we would've identified. Mm-Hmm.
So, yeah. Uh, back to your question, I'm a huge proponent at open source, but even for me, that is and kind of opened my eyes, like, wow, they stayed there for like two, three years before they ran the attack. We need to keep our eyes open.
I immediately started thinking of spy novels of sleeper cells. I mean, essentially someone infiltrated that, and either that was their intention in the beginning or somewhere along the line they got, you know, converted to to be an attacker. And once they had that bit to commit, Yeah.
But been going back to your original point and then, but, and they had the developers as the, that's gonna be my entry. It's not gonna be the vulnerability or the social engineering of an employee. It's gonna be through the development cycle.
Mm-Hmm. And if we keep talking about, you know, incorporating security earlier and shifting left, and it, it kind of raises the alarms on those areas. Those, It makes me think also too, kind of going back a little little bit to the CrowdStrike outage, the critical infrastructure and the vulnerability of that, if there's something substantial that does hit it and, and brings that down, uh, I imagine in the w if you look at it from a network perspective, you've got a different thinking about critical infrastructure.
How do you look at that? I really hope that critical infrastructure remains as a deterrent. Weapons very similar to, um, nuclear, uh, capabilities.
Because once one side starts to use it, it's, it's not gonna end well. And I'm not gonna kid myself, I'm pretty sure our adversaries have access to critical infrastructure here as we do probably to theirs. And we already saw some of the implications of such an attack, you know, not Petya hitting, uh, Ukraine, uh, power grids going down.
Um, I hope we don't see a lot of that. But yeah, this is, this is definitely an area that is, is vulnerable. And again, I think CSA and other organizations are doing a great job.
Uh, but I really hope we don't get to see that it remains as a deterrent weapon and not something that somebody's using. This what scares me too, because it's one of those we've thought what would happen, but we didn't think anybody would ever go that far with it. But once, once somebody has nothing to lose Right.
And they're, they're willing to go after it, then you've opened Pandora's Box Or mistakes, you know, collateral from different events. We've seen attacks on certain nuclear facilities where something happened and, and some of that hit as, uh, a collateral in different places. Uh, A PLC that was attacked somewhere in the Middle East was also, Hey, it was also used in Germany in elevators.
And all of a sudden those get targeted and going back to your novels and stuff like that, then you think about like the ice nine kind of thing. One thing that may lead to, to the other, um, and again, we, we've already seen bits of it. We've seen in the last 18 months, we've seen hospitals in some cases go to manual work.
Uh, you know, writing down on charts, having to, for force to move patients from one hospital to the other. If this happens on a large scale, it's, um, it's not something that will, I, I hope to See keep pen and paper ha handy just in case. Right.
Um, last que I'll question. We could talk forever. I'm not sure we're talking to you a lot.
Um, but what's the next thing you're working on? What's kind of, you know, how researchers target, you know, innovators are always thinking about that next challenge or problem or thing they want to dig into. What's, what's intriguing you?
Yeah. So, um, in terms of, uh, security, security research and my eyes are always at what are the criminals doing and what are they, what are they preparing? To be honest, I haven't seen anything super innovative by threat actors in terms of the attacks that they run.
It's more on how they evade detection. It's really interesting to see the different tools that they have implemented to evade multiple security point products. Um, the fact that we lack, uh, visibility today, the complete life cycle, um, because of point solutions gives them those gaps.
Mm-Hmm. Um, one area that I already saw them start targeting, going back to our AI discussion, sorry, that we have to constantly go back to that, but Can't help it. But it's, it's a real cool, cool example of how they're thinking as well.
Um, so, you know, historically speaking, when you talk about malware analysis, when you analyze malware, when I, when I want to analyze malware static or dynamic analysis, dynamic analysis, I infect a virtual machine and gonna see what the malware does. Static analysis is looking at the code and saying, Hey, is it doing something bad? And you have all kinds of services like virus total today, right?
That you can upload a file and it'll do the static analysis for you and tell you is it malicious or not? We've already seen, and I think virus total went public with this on Twitter as well. Pieces of malware code that include code injections built into them to escape analysis by AI tools.
Mm-Hmm. So you see in the code, it's trying to persuade the ai, it's saying, oh, I, I, this code actually produces puppies. Puppies are wonderful creatures.
So this code is not malicious. Mm-Hmm. And you see that in the analysis and it says, this file is not malicious because it creates puppies.
I'm like, okay, here, here we are, back to the cat and mouse game of what am I doing and what are you doing to overcome it? So I think we need to pay attention to that. I think we're gonna see a little bit more of, of those types of attacks, which are trying to almost calling it like a geo jitsu, right?
You're using ai, I'm gonna use your own AI against you and I'm gonna train it. Evasion techniques against ai. Right.
Exactly. Interesting. You know, I did have one other question before we finish.
Sure. Uh, what type of bass do you play? Oh, I, I hope my wife doesn't see this because Well never tell because It's basses, right?
Mm-Hmm. Um, I play, I really enjoy playing dingo, uh, fan frats. Uh, of course I have a precision like every bass player has.
And, um, music man is the one that I grew up with actually love. That's Ding Ray. Yeah.
I play a Tobias and also a Precision P Bass. So pre Gibson Tobias stuff. We go Yes.
Pre Gibson. We Have to meet then with a couple of bases in Jam. Yeah.
It's, it's, it's my baby. That's awesome. All right.
It's very nice to talk with you. Thanks for joining us and I hope you come back again. Same here.
Thank you for having me. Great. So this is what happens at these, uh, security conferences and, uh, when folks get together and you never know where it's gonna go, it's always a lot of fun.
So thanks for, uh, being part of this conversation. Thank you.
