Akamai’s State of the Internet Report with Roger Barranco
Akamai’s latest “State of the Internet” report provides actionable insights from security experts who battle cyberthreats every day to arm defenders and CISOs alike with the real-world strategies needed to safeguard systems in today’s increasingly complex digital landscape. Roger Barranco, vice president, global security operations, discusses the top takeaways for CISOs navigating this rapidly changing cyberlandscape as well as the latest malware research from Akamai’s threat research team.
Transcript
This is Techstrong tv. Hey everyone. You know, one of the nice things about doing what I do at Techstrong and Techstrong TV is, you know, I've had the chance to be in this industry, whether it's through Techron or some of the companies I've worked with are co-founded for a really long time.
And along the way I've had the opportunity and the pleasure of meeting some real gentlemen, some really fine people, whether they're men, women, what have you. Uh, this next guest is, is one of those people. He is my friend, Roger Barranco.
Roger. Roger. And I know each other probably 10 years or more, uh, maybe more thinking back.
And, uh, then all that time as I, as I say, he's been one of the fine people you meet in the, in this, in the industry, in the cyber world, currently Vice president, global security operations with Akamai. And he's, he's probably been at Akamai now, was 10, 12 years. He'll, I'll ask him.
Let me introduce you to Roger. Hey, Roger, Barranco. How are you, man?
It's great to have you on Again, Alan, it's so good to see you again, buddy. You know, I, I, it's, It's been too long. It has been.
I I remember walking through data centers with you and saying, this is the cloud, right? Essentially, uh, when it was, you know, what, 15 plus years ago, even, uh, when that was, uh, in its comparative infancy, right. And system around It.
Yes, it was, it was private cloud and it was just, you know, you were running things in VMware, multi-tenant VMware. That was, that was basically it. That Roger, how long are you at Akamai now?
It's gotta be 12 years. No. Yeah.
You know, if you include the acquisition of Prolexic from, uh, my, uh, it's a little over 12 years. That's 'cause I, of course, we knew Prolexic. I remember Akamai buying it.
For those who don't know, Prolexic at the time of their acquisition by Akamai was probably the preeminent DDoS protection pool and company in the world. And, and Akamai bought them. And they've been thwarting some of the biggest DDoS attacks X ever since.
Um, now of course, Roger, you moved above and beyond that, as I said, global, uh, security operations vp, you know, Roger. But give people a sense of, I mean, you've had a distinguished career given an idea of, of where you've been and now you got here. Yeah, sure.
You know, um, for anybody on here that's looking at security, wow, it's still cutting edge. Uh, how do you differentiate yourself if you're looking for a job and a career? It's clearly security.
It's always changing. It's always exciting. Uh, it's invigorating to think, Hey, you know, we're, we're protecting the world's most critical infrastructure from nation state actors from, you know, really well equipped, uh, cyber criminals, uh, across the board.
So, you know, if you're into an environment that's always changing and interesting, uh, this is it. So, Roger, I'm gonna ask you to do a little Akamai kind of setting the, the field a bit. A lot of people out here think of Akamai and I, I think they fall in two camps.
Some people say, oh, Akamai, they're a security company. Right? Probably the minority of people, though I think most people still think of Akamai, and it's part of their original mission, if you will, which was, you know, current commonly CDN content delivery network.
They, and of course, and, and, and I don't wanna ppo CDNs, right? Right. In a world where latency counts, and if we can get you to the edge next to where you're gonna access, if we can get information and, you know, content to the edge where you're gonna access it quicker, that's a huge plus.
And that's a very, very important mission. But Akamai is so much more than a CDN security is, but one of of many things that Akamai delivers today. How would you describe Akamai?
So, you're right. The, the CDN is the foundation from which many of our solutions sit on top of it, which makes it very powerful because of the size and capacity of the platform and how close we are to the actual end user that needs those services. So, mixed in with security, you get great performance.
It's really rare to have those two things together in the same package. Right? So, but you're absolutely right.
Um, the fact that the foundation is CDN, the reality is that well over 50% of Akamai's revenue is security. And it's security across a plethora of products. From API to bot management to DDoS, like you mentioned before, clearly waf, uh, it, it, it's extremely deep and broad, uh, which is sometimes one of the challenges, right?
It's to think of, well, what are all the different situations and challenges that we can help with? But layering it in with the right tool for the job Is, is key to it. And that, you know, not to be flippant, but as you get older, you learn it's all about having the right tool for the job, right?
It really is. It makes life a lot easier all around. Um, so we, we've laid out sort of the Akamai story.
Roger, you guys recently came out with a defender's guide, right? Right. Give a, and, and over the years we've featured Akamai security research and you know, our friend Martin McKay for many years was writing the, uh, Akamai reports.
Martin, of course, has moved on stuff now, but, uh, what's this defender's guide? Is it the latest incarnation of this? Tell us about it.
I I really like the evolution of the Defender's Guide. So we used to call it the Sodi, the state of the Internet. It was a wonderful document that contained a lot of metrics in what we're seeing, and we do see the bulk of the world's internet traffic that's clean.
Uh, so we're well positioned to talk to these data points from our findings quite literally along the way. But the, um, so DS evolved to the Defender's Guide because we said, Hey, we wanna make this more actionable. We, it just doesn't, you know, we don't wanna just contribute to the standard, you know, a lot of people or do the fear, uncertainty, doubt type discussions.
That's not who we are. We really wanna say, this is what we're seeing and this is how you can help yourself. And if you go to the Akamai website, it's, it's very prominent on there.
Uh, you can download that guide and it will talk to what we're seeing prominently from a cyber concern perspective and look quite literally what you can do to protect yourself along the way. Okay. Um, so give us, I mean, Roger highlights high, you know, we only have 15 minutes and we've probably used seven of them already, Uhhuh.
Sure. But, you know, armed people here, what, what, what are the kinds of things they should be really digging into? One thing that I see all the time is that it, and it's example by the fact that the number one attack source is very consistently the us.
So the attacker, the bad actors might be in Eastern Europe or somewhere in Asia or wherever that happens to be. Why is that? Because the Americas are typically behind on patching.
It's just that simple. So just doing the basics, like patching is incredibly important. And I know it's really tempting to have deep discussions about Redtail, which is, you know, a malware that goes in and it takes over an infrastructure to, in a very intelligent way, um, participate in crypto mining, right?
But the reality is, if you have a really good zero trust microsegmentation environment in place, you're gonna be protected. Uh, if in a very significant way. If you have strong API protections in place, aside from WAF protections, very different security protocol, you're gonna be in much better place to pull those items together.
So what have we seen out there? You know, it's pretty stunning to me that d believe it or not, Alan, I don't know if this is gonna surprise you or not. DNS attacks still make up 60% of DDoS Not, not surprised at all.
Yeah. 9999% of the time. Right.
I always leave a little sliver there, because there's always that super smart navy state Actor something right Out there. But, you know, I I, it's funny, the interview I did before you, Roger, was with a company that specializes, they're all former special spec ops people, Uhhuh digital, and they specialize in protecting high net worth individuals, celebrities, et cetera. And we were ta having this discussion.
Some things never change in security. And one of those things is, is that unfortunately people don't get religion until after the calamity happens. Right?
Then all of a sudden they're looking for miracles, or they're looking for solutions and DDoS protection. Today's a perfect example. You know, until, until you've been a victim, you just think it's fine being the zebra in the herd.
They're never gonna pick on me. And then one day that lion grab grabs you and it's like, oh, I should have done this. Right?
Right. And I don't know, I mean, maybe guides like this telling people sharing real world incidents, I don't know what it'll take for people to say, Hey, we've gotta be proactive about, because you're right. A DNS based DDoS attack today is, you know, that's like getting hit with a, with not even a bow and arrow, maybe a cross bow, right?
It's, it's could be lethal to your business, but there's really no reason in today's world that you should be susceptible to that, You know, the solutions are very inexpensive. First of all. It's not like you need some massive infrastructure on that.
There are some great people out there that, you know, can help with that solution. Um, it, it, it, like I said, it's just, there's no excuse for it. And to, Alan, to your point, goes back to patching a little bit, is that to be a good internet citizen is critical because those are DNS servers that are being com not compromised, but taken advantage of.
And that can be modified, you can change your settings, but very specifically, uh, you know, on the DDoS front where you're going, we just had a lot of customers from the, uh, Australia New Zealand region, get absolutely hammered because of a political support statement they made, uh, related to the Israeli Palestinian, um, conflict. And there were a lot of, uh, entities that were knocked over and absolutely crushed. And to your point, they, unfortunately, several of them, uh, for lack of a better description, had to learn the hard way.
And they could come to us and say, help us out, because this very fine product that they had in place with very strong AI and ML and, you know, language models and everything, did a good job on 99%. That 1% that it didn't do such a great job on it had no solution for. So if I give advice to anybody, it's gonna be, hey, you know, challenge your vendors and make sure that they have that human overlay that's absolutely critical for that consultative engagement to handle that 1%.
Because in today's world where it's much less brick and mortar wow is 1% is crushing the bottom Line. It's all it takes. It's all it takes.
You know, you mentioned the magic word there with ai. I mean, you know, when I look at AI from a security point of view, it truly is a double-edged sort. Absolutely.
There's so many things we can do with AI that can make us better security pros that can raise our level of security posture, make us better protected. But at the same time, you know, it's the old story. The bad guys are not dummies and they use it too, and they're using it to be more effective to, to have better attacks, you know, find more attack surface.
Any advice on that, Roger? Yeah. You know, so two things.
You're absolutely right because we see it all the time that the rate at which attacks shift when you put a mitigation in place is stunning. Which is why the soc, the security operations team, has had to evolve and add people like data scientists and threat researchers directly into the security operations team. 'cause you don't have the time to escalate to engineering to see about background investigations anymore when you're protecting a customer.
But the AI is making it, uh, very interesting. But I will tell you, Alan, at the end of the day, it's rare to find a truly novel, traditional attack. It's always some variance of a line injection or a SQL injection or an API attack.
If you put the basics in place to protect you, you will be in really good shape. And very quickly, every customer we have that spends a lot of time with us during peace time, when it does move to wartime and they're under attack, it ends up being a really good situation for them. 5 terabit attack and here's all the detail on it, and they didn't even know they were attacked.
That's perfect. That only happens because we're testing with them and working with them during peace time to prepare for that bad day. Agreed.
Agreed. Roger, we're about out of time, but for people who maybe want to grab the guys and, and, you know, get into it, what, what would, what's your best advice? I know it's a long URL, we're not going to give it to you.
Yeah. 'cause no one's writing it down. But how, what's the best way to navigate to it?
com, it'll be prominent on the homepage. Just click on it and it'll gl guide Them through. It's really easy to access it.
And a wealth of actionable information. It always is. It's been one of the best reports on the internet for years and years.
Man. Roger, next time you come up here, we'll do this in person in the studio, please. I'd like that very much.
We're we're 15 minutes from feno. Yeah. Awesome.
All righty, man. Roger Barranco, VP Global Security Operations, Akamai Technologies here on Techron tv. We'll be back with more in just a minute.
Stay tuned.