API Security and Visibility – Chuck Herrin, Wib
API security is one of the biggest challenges facing CIOs/CISOs today. Traditional API security solutions have so far been siloed and fragmented, leaving CIOs/CISOs with a choice of multiple pain points and patchworked solutions. Wib is launching on Nov. 8 the only solution to provide complete visibility across the entire API landscape, from code to production, helping give software developers, cyber defenders and CIOs/CISOs full control of the complete API domain.
Transcript
This is Textron TV. Hey, welcome back to Tech strong TV. I've got another a guest actually a new company that recently came out of stealth and David talked to you about today.
I want to introduce you to Chuck Herron Chuck is the I believe CTO of a company called Web he's gonna tell us all about it and about his background. Hey Chuck. Welcome to Tech strong TV.
Thanks Alan. Thanks for having me. It's great to be here.
All right our pleasure to have you on we love hearing about new companies and You know what's going on in the market? So Chuck before we jump into web though. Maybe we should do a bit of the Chuck story, right?
He was your background. Sure. Sure.
I'll try to keep it relatively brief, but but comprehensive at the same time. So I like you Alan. I've been in security space for a long time over 20 years.
And so while this company is Young. I am not we are going back to a couple of decades. So I made my start in in the cyber security space working with very large banks in the Southeast and sort of penetration testing team and then sort of the bottom fell out if you remember about 20 years ago when sarby's Oxley became the law of the land in 2002 then so I moved from pentesting to defending went to the blue team and I was the ciso in financial services companies here in the US and Bermuda some Global firms.
For about 18 years and and then left there to become a builder. So I was an attacker for for a while. And then I was a Defender for a long while so attacking was more fun.
Defending is more profitable and now and now I'm a builder so taking taking that, you know, 20 years of Battle Scars and bringing it into the, you know been into the building space and that's what we're doing it with is we're we're gelling all of our experience around attacking and defending and putting it into what I think is is I almost hesitate to call it the next big thing because it's the current big thing but a lot of folks aren't yet aware of it, which is API security and then the attack surface changes that come around digital transformation projects and the proliferation of apis and microservices that use them. So it's a really fun space. It's a really fun time to build.
Absolutely. We'll look I will tell you with our audience API security is no strange term we've done I think three virtual events. I care for a full day conferences on API Security in the last eight or nine months.
and You know that I even last year at the RSA conference in San Francisco besides half our team catching covid there. We put on the devsecops event every year at RSA and and part of our agenda there when we weren't talking software supply chain. And that's bomb.
We were talking API SEC as well. So I agree with you. I I think this is the Brave New Frontier.
It's kind of what's next in apps that kids, you know laughs and that kind of that generation of Technology kind of Fades out and it's be it's quite frankly because you know, we live in an API economy everything today kind of talks to each other and plugs in. You know it it's it's ubiquitous. And that's the way that software is eating the world apis are eating software.
I mean, no doubt. It's it's dramatically increasing. Well, it's all tied into this right?
So what I did is about nine 10 years ago Chuck. I I discovered what we call today devops. And I thought to myself what a great thing.
This is for security, right? You know, that was all that mattered to me. Well, this is gonna be great for security.
But the fact of the matter is is as we sit here today. The way we do software has fundamentally changed right? It's not some bespoke kind of every app is a bespoke thing that you know a team of developers sat and crafted from scratch.
Software today is more of an assembly line project right Supply chains and stuff like that and components that work together. And how do they work together? Right they they talk to each other they communicate as we move to a multi.
multi-threaded type of application platform and and you know kubernetes and the whole Cloud native thing. There's like two levels of apis. There's apis right apps.
that talk to other apps via API or you know talk is a bad word, but you get the just right share and then there's The intra-app the interior, excuse me, the inter app right parts of an app. Different containers what have you that actually communicate with each other? And that might be of a bigger world.
Then then the outside app to app kind of come, you know communication. So yeah, it's it's huge. Yeah for sure.
To be fair. There are some players, you know some I don't know if they're still unicorns in today's macro world, but you know, they raised the ton of money. I'd heart very high valuations.
What makes whip different? So I think that what makes live different is we are building on the lessons that the first players to Market taught us. And so I'll never speak ill of our competitors.
I think we're all working on on hard problems to solve. This is a non-trivial problem to solve and the Common Thread between really the the first players in the market. And and web is we we all are starting from position of expertise with attacking apis, right?
So the the offense is informing the defense. What are the actual vulnerabilities? What how are they being exploited and these things shift over time quarter over quarter.
We you know, continually watch the the evolution of vulnerabilities as well as attacks in the wild and I think that what the first movers in the space that are really good job of was defining the problem the core problem of rules-based defenses. Cannot understand or defend against logic-based attacks. And and the the way that they decided to address that and the lens that they put towards it was one of production traffic which is a valuable lens and it's the lens that that we at web use as well.
So seeing what's actually coming across the wire whether it's at a an API Gateway or a load balancer, whatever's coming across the wire requests responses. It gives you a lot of information that you didn't have before as a Defender to understand sort of the the threat modeling methodology. So you and I both been around a long time familiar with threat modeling it, you know, you need to know your assets actors interfaces and actions who's doing what to what via what the the challenge with that singular approach though.
Is that it's a limited approach. So imagine that you're going out onto the front porch. You hear something go bump in the night or if you live where I live here coyotes, you go out on the front porch with a flashlight and you can see more than you can see yesterday, which is a good thing.
But what we at web learned is that singular lens is important, but it's not sufficient. To really understand what's happening from all the way exposing your code via business lot. You're excuse me business lodging via code all the way to the outside world.
You need to augment that traffic visibility with visibility into the code as well as simulated tests and attacks. There's really very little you can do to assess a pi security and a static manner in the code. So you need to simulate a tax and really exercise the apis to understand how the attacks are going to change across multiple endpoints and so forth and so on and by putting those three lenses together into our Central what we call our Fusion engine, it gives us Telemetry in an up-to-date inventory to really give us close to a hundred and you know, a hundred percent coverage 360 degrees of coverage into the API ecosystem as you can as you can have the problem with with the singular lens whether it's just code or just traffic Is it is very rise for false positives and it blind spots and and just finding all of the apis in an ecosystem is a challenge in and of itself.
And so that that's really the differentiator where we we talk to a lot of the folks that you know worked and designed and engineered those first Solutions. And we asked if you could do do it differently, what would you do? If you do it over again do it differently, what would you do differently and they said we would have a broader a broader lens a broader approach and I I take that to my personal experience as the ciso in financial services and Banking and insurance and fintech, you know when I built this fintech in Dallas.
Before we ever opened a single bank account or wrote a single insurance policy. We add hundreds of apis and thousands of endpoints and I couldn't see what I was expecting to see and that's the piece that I think a lot of Defenders are missing is they don't even know necessarily what they can't see and and apis aren't just about transfer of data that's you know, obviously a critical, you know piece of it, but it's also about invocation of function. And and so, you know one panel I was recently on with the CTO of an analyst firm that I really like.
He asked the group. How many apis does your storage platform expose how many of those are documented and how many of those are your monitoring? And if you're in an industry, like medical, you know and and ransomware is a key something that you're worried about but you're not monitoring the interfaces into your storage platforms.
You're probably missing a pretty material part of your attack surface, and and that's what we're trying to to solve for and just looking at at production traffic only tells you what's active. It doesn't tell you what's exposed. It only tells you what's active and it only tells you what's active where you know to look and so by putting more lenses to it.
We're instead of the the flashlight. We're trying to bring up the sunlight that that's the overall goal is all I want to see is a Defender is everything. Yeah, no, I I get it.
Look I I think fundamentally that's been job one. With the API security tools, actually you kind of you can't defend what you don't know is there. and and the fact of the matter is most organizations.
I don't think have a real handle. On what apis they got running it, they don't internally and to external sources and it's worth. Well as you get more apis proliferating it's going to get worse, right?
Yeah. Now I I do agree with you. Also Chuck, you know, look, it's a Time Time Warner story in Tech, right?
The first generation sort of does the missionary work of defining a problem and then you know the next gen folks. learn from those experiences and and you know craft Newer better Solutions, right? It's kind of the way the world early gets the worm but the second mouse gets to cheese big guys.
They say you you hit it on that. So whip just launched. I think it was November 8th something like that earlier this month, right?
I don't know. I was there funding announced with the launch or you know, that's about kind of the company if you will. Yes.
So we we just closed a funding around led by disruptive Technologies here in the states and we are using that to fund product development as well as expansion into the Americas and the Amia most of our current customer base is in the Amia region. So really with our R&D and and you know research and development teams based in Tel Aviv. And so we're expanding the North American operations looking to have about 70% of our Revenue out of the the Americas by 2024 and really keeping our heads down on product development.
So there's really two aspects of what web is bringing to market. The first is the software platform, but the second is a penetration testing practice and while my guys are world-class attackers that can do full scope penetration testing. They're really really good at apis and this is an area that a lot of pen testing firms lack and it's an area that for example, the new PCI standards version 4 that we're just released just here.
Yes, right. So the new pen testing requirements require specifically testing of apis and gaps and business logic that's not been API testing for PCI isn't new exactly but specifically testing for business logic attacks. That's not something that normally happens and there's no way to to automate that with your network vulnerability scann.
And so what we're what we're setting out to do sort of, you know at the beginning of a relationship with with a customer is give them the the inventory and the documentation that they need to then do their own API testing or we can help them with API testing but essentially automate the boring stuff and fill that foundational Gap that they miss with with the manual you're asking developers to document things and a lot of times the developers. They don't even know what we find these these apis that they don't know where they came from or was somebody that maybe it's a company that grew via acquisition. They don't know what they don't know and so having a discovery engine to go out there and tell them what they actually have and then generate the documentation for them.
And then also tell them the risk associated with it is really important to triage. What do we need to work on next right rather than spamming your Dev teams with hundreds of jira tickets without context we help them to organize. This is a thoughtful and logical approach to getting your API security under control so you can catch up and keep up and and that foundational part at the bottom the inventory and the documentation and then the thoughtful testing regime really is a great place to start.
Absolutely, I get it. Hey Chuck. We're about at a time.
Yeah. Web website. How do people go get more info very simple.
com. We have case study information. If you want to secure a demo we were happy to talk with you figure out the approach that makes sense for your organization.
Every API is a snowflake and every company is doing it differently and we have a lot of experience not only with sort of the standard sort of software installs and you run it but as well as as managed service and consultative agreements to your earlier comments Alan about devops a lot of times we find ourselves as a bridge internally talking between security teams and infrastructure teams and development teams to sort of bring teams together in our platform is designed in such a way that it doesn't Force develops, but it's available to support devops. com would be happy to you know, be happy to you know, however we can. Fantastic.
Hey Chuck. Best of luck with web keep us posted and we'll talk to you soon. Sounds good.
Gosh, I'm here. All right, we're gonna take a break on Tech strung TV. We'll be right back.