Anna Belak, Sysdig | Black Hat USA 2023
The Sysdig Threat Research Team recently published a cloud threat report which proved what we all know – attacks in the cloud happen fast. But we didn’t realize how fast. From cloud automation as a weapon to software supply chain vulnerabilities, the annual report exposes shocking statistics on the evolving tactics of attackers lurking within the clouds. Is a 90% secure software supply chain secure enough to rely upon? How are threat actors leveraging automation in 2023? How many minutes does an attacker take on average to launch a targeted cloud attack after uncovering credentials? (Hint: not many) Anna Belak joins us to dig into it all.
Sysdig recently published it global cloud threat report. Some key findings:
1. It’s 10 minutes from attack to damage in the cloud
2. 10% of high-risk vulnerabilities are undetectable until they move to production – you need threat detection, prevention is not enough
3. Attackers have gotten really good at the cloud and automation has only made them better. Scarleteel 2.0 is a great example of an attack we could walk through.
Transcript
This is Textron tv. Hey everyone. Welcome back to our techron TV coverage.
Live at Black Hat here in the desert in Las Vegas. And it's hot like a desert. I, I don't know how many of you have been to Vegas lately, but walking yesterday, the wind was so warm.
I don't know if you had a chance to walk outside. I felt a little like Lawrence of Arabia or something. I was looking for the sand to hit me.
But anyway, the good news is once you get into the air conditioning here at Mandalay Bay and they, the throngs of people are at Black Hat. I don't, I haven't seen an official count yet, but it looks as big as it ever was. You know, it's certainly back, I don't know if you know this woman, if you've watched Tech Drunk tv, she's been on Oh, at least a half a dozen or more times.
It's Annabell. She is the, well, she runs the cybersecurity research team over at sis Sig. And for those who don't know, you know, SIG has a pretty steady, steady stream of reports that come out.
A lot of different topics, a lot of great research and reporting coming outta there. Anyway, Anna, welcome so much in person in the flesh here in Las Vegas. It's Very cool to actually meet you in person.
It's very nice to have you here with us. Um, you know what, before we jump into the latest report and talk about blackout, let's talk about Anna. We've done this on, on Zoom, but now we're gonna embarrass you in person.
Excellent. Give him a little bit of your background, if you don't mind. My background is unusual as, I guess it's true of all cyber people.
None of us are very Confederate. Yes. We're, Yeah.
Um, I started out as a scientist. I did a PhD in computational physics. Wow.
Yeah. Um, into challenging problems. I guess that's my affliction.
Mm-hmm. Uh, but I get bored easily. And physics is very like a long term proposition.
Like you have to commit to it for life. Yes. I did not have that in me.
Mm-hmm. So I quit actually after the PhD and I said, I'm gonna find the best job in the world, whatever it takes. Uh, and applied to hundreds of jobs.
Uh, one of them was with Gartner and I was a hundred percent convinced they would never hire me 'cause I had nothing about it. I was like a physicist. And they hired me to work on docker containers and Kubernetes and like emerging technologies.
Really? Yeah. Because they were looking for folks that were smart and could figure something out that was brand new.
Right. And No one really knew it anyway. Yeah.
Like There crazy, no one knew it. There's not like, you know, 40 years of baggage. Right.
That's 30 years of docker experience Yeah. In the last Two. So yeah.
So that's what I did. And I spent six years there working on, um, those systems and then security of those systems, and then eventually made my way into the real world where we try to build security tools for, um, the new world. Absolutely.
You know, as crazy as it sounds, your profile in terms of what you were looking for, what you like and what interests you is very common in the cyberspace. The cyberspace used to, you know, I've been in cyber 25 plus years myself. It used to be a lot of people who used to like to break things just to see if they can be broken and then put 'em back together better.
Right. And, and also a lot of a d d jumping around, you know, shiny trinkets syndrome. So you're not, you are with your people.
I am with my people. You, you have found your tribe, as they say. I've embraced my people.
Yes. Uhhuh. And, and then of course you left Gartner came to SIG where you're heading up as, as I mentioned, the cybersecurity research team there.
And they, you know, for those who don't know, SIG is a, is a leader in, in what's called Cloud native security. But it, it's cloud native today is so big and so broad. They're a leader in cybersecurity today because so much of what we do is involving cloud native.
But their research division in particular has done some amazing work. Before we get into the latest report, if you don't mind, Anna, share a little bit bigger picture right. About the research team and some of the stuff and work you're working on.
Sure. Yeah. So this team is doing the thing that everyone hopes the vendor will do.
And they're keeping track of what the bad guys are up to so that we can build a tool that can help you define more effectively. Mm-hmm. They have tons of approaches.
They have a really impressive collection of folks there. So like X government X, you know, you name it. Mm-hmm.
Uh, and uh, what their mission is to design, essentially design a research system. So it's a lot of honeypots. Um, they work on real live data as well.
Like if something happens to a customer, we're there to check it out. Mm-hmm. Uh, and then to summarize that into really what you should be looking for and what you should do.
So if you're a customer of SIG or if you're just a, um, business that has some kind of cloud security tooling in place, what are you even looking for? Like, how do you know when the bad guys are there? Yeah.
And you know, this, this of course is, is a big problem because unfortunately, almost the nature of the beast is we don't find out until afterwards when, when it's hit the fan. Yep. But we are making, we are getting better though.
I, you know, I've tried really hard recently when I'm talking about cybersecurity breaches happen. It happens to the best of us, but we shouldn't lose sight of the fact that we have made a lot of progress. Things are better than they were and they continually get better.
Some of it because of the work that your team is doing and, and cystic in general. But overall, I mean, as an industry, we, we, we are doing, I think, better anyway. You guys have a new report that you're touting a little bit out here at at the show.
Why don't you tell us about it? Yeah, it's very fun. So this is our second one.
Mm-hmm. Uh, we did our first one last year and there are some themes that we've kinda followed through and there's some new stuff. Uh, the newest, most exciting thing is probably the time element.
So, you know, we know cloud is fast. It gets you provisioned fast to do something new and cool. Uh, we also speculated that the attacks in cloud would be fast for the same reason.
And now we have hard data to prove that. So we did a huge study, uh, setting up a bunch of different systems to see what the attackers would go after and how that would look. And so we measured specifically, um, impact on verticals.
Like would they go after telco, finance, healthcare, what have you. Um, by the way, telco number one, finance number two, not, Not a surprise I guess, but, but now look confirmed in cloud by this is purely cloud, it's not. Yeah, I understand.
Uh, and then the speed at which these things happen. So once they find you, uh, which is quite easy, 'cause public APIs, exposed assets, et cetera, uh, it takes them 10 minutes to start hurting email. Oh my God.
10 minutes. Really? Which, Uh, and that's an average, right?
So in some cases it's like seconds. If it's like a minor or a malware, they just boom. Like it's there.
Um, if it's a more sophisticated kind of somewhat manual attack, it'll be longer. But the early stages of the attacks are super fast. 'cause it's so highly automated.
They're like, have all these scripts. They're doing all this reconnaissance and discovery. Just run it, find something juicy, send the WhatsApp message to the bad, like, you know, whoever the attacker.
And then they come in and they grab the credential and off they go. Um, and then the second element that's like the fast. Okay, it's fast.
Um, what's maybe even more impactful is that it's quite sophisticated. So these guys know cloud, right? Oh yeah.
And I kind of joke, but not joke. Their full-time job is breaking cloud. Um, and our full-time job is trying to stop doing them.
We do. Well, no. Like we have a business to run.
Well, I sell security tools. Right? But like, you are a media guy, somebody else's, you know, someone I don't retail don't Time.
Right. Know the security thing is, uh, So it's the nature of, of the whole thing. It's cat and mouse.
Yeah. The cat is, well Always one step behind the mouse. The mouse is fast.
Eventually we get the mouse, but it's, there's more, more m well, The mouse moves on to more. Yeah. Yeah.
So Yeah. Lemme ask you a quick question on that though. So, so, uh, tech and finance no meet, what was the telco and finance?
Telco and finance were number one and two. Yeah. How big a drop off was it to three and four?
Um, it's pretty, I think so tel I might be wrong. Telco was 30 something percent. Finance was 20 something.
It's like 34, 27, something like that. Next one was I think 15. Oh yeah.
So it was significant. And Then, so what's interesting, uh, and I, I wish I could remember what the third one was, but I don't. So I, telco finance, we were not surprised.
We were actually surprised. Healthcare may be the third one. So healthcare was low.
Really, healthcare was only 5%. Wow. That surprises Me.
And then defense was low Really. And so we kind of thought there would be more interest in attacking those kinds of orgs. 'cause healthcare is a huge target for ransomware.
Sure. Is. Um, defense has always got delicious things to look for.
Mm-hmm. Um, so we have a suspicion that the cloud attackers Do have a different priority set. Yeah.
They either don't believe they can get into those systems because they either don't have anything valuable in cloud or maybe they think it's better defended. Um, whereas finance and telco are like really wide targets for just fraud. Right.
So much fraud. Yeah. Quick, Quick, quick.
Um, and again, let's just do the anatomy of this. So a lot of these attacks are set on auto, right? They're discovering public ips discovering, you know, infrastructure.
Then they run an automated attack, uh, schema. And then if it, if it returns anything, that's when it kicks off a WhatsApp or whatever to a live person who says, Hey, I got a live one here for you. Yep.
And this is when they do their thing from that point on. You know what amazes me? I said earlier, I've been doing this 25 years.
We always had the gut that hackers are basically lazy. They go for the lowest hanging fruit. It's a kind to walking down the hallway here at the Mandalay Bay and, and twisting knobs, you know, doorknobs.
And if they find one open, easy pickens, if it's too much of a hassle to pick the lock, they'll move on to the next one. And that's what it seems to be here in 10 minutes. I'm making a decision.
I'm in, I'm out, or I'm onto the next one. Yeah. I think that's hasn't changed.
That's still true. Um, it's, the signals are a little different now. We see, for example, that the most prevalent attack is crypto mining.
Right? Yeah. What free money is free money.
Right. But, And it's also, Well, so the, the angle there is people go and look at that and they say, oh, well crypto mining, what, what else? It's just crypto Mining.
Who cares? Shut it down. Forget it.
But It's not murder, But it's testing the doorknob. Right? Like if I'm an attacker, I plant a miner, it's not getting shut down very quickly.
I'm getting a signal that this company is not paying attention. And then I go for something else. 'cause I'm like, okay, they're either not very secure or they're not very attentive to their tools.
So maybe I can find more. Yeah. If I plant a minor, it's auto shut down.
I'm like, okay, I'm not touching that. Not worth my time. Right.
So there is that. I I think there's that. I think there's also a hierarchy of criminals.
I, I think the crypto, right? Well, they're sophisticated. I think the crypto miner does crypto mining, but when he's had is full of that, he's like, you know what, this is an easy mark.
I could sell that up the food chain Yep. To the ransomware guy. Or Hey, this, this is a potential, uh, nation state or one of these guys that I want to sell it to.
And they, and I think they do. I think they sell the access Out. Absolutely.
Absolutely. Yeah. So it's, it's insidious.
10 minutes. My god. So what do we do to protect ourselves Can cry softly to our pillow.
We don't, we just hope that the, the lion doesn't eat this zebra today. Yeah. No, I mean, in some sense it's the same as always, right?
Defense in depth, you need multiple controls, blah, blah, blah. Um, I think we have to be honest with ourselves mm-hmm. About the reality of cloud, right?
So if we have all these romantic dreams of, oh, it's so fast, so scalable, so wonderful. Um, that all works in favor of the other side too, right? Uh, but we are enabled now to be much more secure, right?
Yes. We can build much more resilient systems. We can redeploy systems much more quickly.
Yes. If there's an issue. So if we're leveraging all those tools, we are gonna be much better positioned than we were on premise.
So I think there's a lot of hope. Like it's not all doom and gloom. No, No.
As as I, you know what, that's why I prefaced it because sometimes when we talk about this stuff, we, we tend to focus on the negative. Yeah. The fact is it's not all doom and gloom.
We, there are things we could do. There are things we're doing better. Immutable infrastructure is a beautiful thing that allows us to do that.
I'm A big fan. Yes, yes. Um, interesting stuff.
What else is in the report that's of maybe of interest to our audience? So one other one that's interesting. So this builds up on last year's work.
Mm-hmm. So last year we went through docker hub and we looked for malicious images. Uh, one cool thing we we saw last year was that you could find DDoS agents in the images.
And they were actually used, um, in the conflict between Russia and Ukraine. So you could be anybody like not knowing anything about Docker or Ukraine or anything. And you could just download this thing and become part of a botnet.
Right? Right. You are part of the Yeah.
The zombie nation, which is Wild. Right. So, uh, this year we did deeper analysis on malicious images in Docker hub to see if it was easy enough to tell when they were malicious.
Because right now there's this big shift left, you know, paradigm. So we're all scanning, scanning, scanning everything before we deploy, which is great. You want to do that?
Absolutely. But what we found was 10% of those mal that known malicious, so definitely bad stuff, were not detectable with any kind of static analysis. Yeah.
So you had to run the image and analyze it in runtime before you could see the malicious behavior. Well look, one could say 90% was detectable. Yeah, yeah.
It's the other 10% that'll kill you. But, um, Well just have runtime and out. So something like, 'cause people believe that, oh, if you fix it all on the left side, we're good forever.
Obviously that's not true. Doesn't happen Like That. This is like a quantitative metric that says 10% of time.
You're just, Let me ask you another question. 'cause I don't want to give Docker hub necessarily a bad name. I don't think Dr.
Hub It's helpful fault. No, well, well I'm not gonna go that far either, but I don't think Doc Docker hub is necessarily any worse than any of the other repos. No, no.
And we scanned a bunch of repos. We just did the deep analysis on Docker hub. Right.
Um, yeah, there is nasty stuff in, you name it, they're all over like GitHub all over it. There's lots of nasty stuff. So, you know, I've been, I've been talking to a couple of the repo vendors.
Yeah. 'cause and maybe I'm naive, but my take is you need to have a, a guard at the door before anyone downloads stuff from you. You should some of the responsibility, Mr.
Repo owner or Ms. Repo owner is on you to clean your act up. Because I come to you as sort of a trusted resource and you're not, or be up and say, don't trust anything from me.
Well, yeah. Um, yeah, that is a challenge. I, I agree with you that they bear some responsibility.
I'm also a little empath empathetic to them because they've been under a lot of attacks lately. Um, Yes, they Have. So our team has found It's a hard job.
Um, well there were lots of attacks that caused them to tighten some of their controls actually over the past couple years. And then our team has found attacks against them that we called free jacking. So it's when Yes, they grabbed their freemium accounts and just like abused them for money.
I think we I interviewed you on That. Yeah, you probably did. Yep.
So it, they're having a, a bad day. 'cause clearly like this technology moves forward. We're doing all these, you know, repositories, scanning, rapid deployment artifacts, et cetera.
And then of course the attackers come in and they're like, oh look, a delicious new attacks. So yeah. Cat, cat, mouse, cat, cat, Mouse.
But this, it is cat and mouse. But this is also, you know, one of the things about the whole cloud model was yes, you could put more resources. A cloud provider or a repo owner could put more resources in protecting their mother load, but it's nevertheless a mother load that makes it more attractive.
It's like a big piece of cheese for those mice. Right. And I, I think ultimately some of the responsibility has to reside with them the same way you look at what we did with the Apple App Store and the Google Play Play Store, right.
We've, they, they have a responsibility to make sure that the apps, we think they do anyway, that the apps in there are, are are, you know, vulnerability free or you know, act, not act. And when they do come out that they were vulnerable apps in there, we point the finger at Google and at Apple. So anyway, it happens.
And uh, for people who want to go get more information on, on this particular report and stay abreast of the rest of the great stuff you guys do, where, where can they go? com. It is definitely on the website and reach out to us.
Uh, we're around. I'm always happy to chat. Anna, It's been a pleasure meeting you here in person for the first time.
I'll see you on the Zoom next time probably. But until then, keep up the great work. You guys.
Really All kidding aside, you know, and you guys do great. Great work. Awesome.
So Awesome. Thank you for having us. Thank You.
Annabella head of, uh, she runs the cybersecurity research team over at assisting. Until then, this Alan Shimmel for Techstrong. And we'll be right back.





