API Security Reference Architecture for Zero-Trust – Richard Bird and Chase Cunningham, Traceable AI
Traceable AI, the industry’s leading API security company, today announced the release of the industry’s first API Security Reference Architecture for Zero Trust. This groundbreaking reference architecture serves as a guide for security leaders, as the industry addresses the urgency of integrating API security into zero-trust security initiatives.
Transcript
This is techstrong tv. Hey everyone. Welcome back to techstrong tv.
I've got two first time Techstrong TV guests to, uh, speak with us today. They're both with Traceable ai. Let me introduce you to Richard Bird, CSO of Traceable ai and Chase Cunningham traceable AI advisor advisor.
Richard, as he told me, is the good looking one with the guitar in the background. Well, that's what Richard said. Anyway, uh, Hey, Richard.
Welcome, welcome to Techstrong tv. Why don't you give people a little bit of, of your own Richard Bird story on, on how, how you got to be here today. Will do.
Happy to be here as well. Um, Richard Bird, chief Security Officer for traceable ai. And, uh, I'm a bit of a, um, uh, an not usual quantity in the solutions space.
Um, I spent 20 plus years in the corporate world, and, uh, I did about, uh, 16 or 17 of that in banking and financial services. And I've also been, uh, two track, uh, IT executive. I went IT operations first half of my career into, uh, c I o role.
And then, uh, and then got invited into the beginnings of organized and structured, uh, information security. Uh, went back, uh, I did 11 of my years at JP Morgan Chase. Went back to Chase, uh, joined a, uh, information security team.
And, uh, was, uh, uh, not wise enough to say no when I was asked if I would take over identity for the vast majority of the bank. Uh, so trial by fire. Uh, but I left the corporate world about 20 plus years ago, or pardon me, excuse me, about five years ago.
Uh, joined the solution side and, uh, been having a blast. I tell people I feel like Benjamin BUN button aging in reverse. Um, I got to startups, I got to startups, you know, later in life As one of the oldest people on staff.
Uh, but I'm having an absolute blast doing it. You know what? There's no time, any time is a good time, right?
There's no time like the present. So, uh, and look, I'm right there with you, man. I, well, I've been in startups now for 25, almost 30 years, but, um, welcome to the club and it's a pleasure to have you on, Richard.
Thank you. Chase, how about you? Uh, sure.
So I'm retired Navy Chief. Uh, I did my time, uh, doing work with, uh, a bunch of three letter agencies. Then I went to work for three letters.
Uh, I was a contractor for a while there. Um, I wound up going over to Forrester Research and created the Zero Trust Extended Ecosystem Framework. Uh, sure.
And then after that, I was the Chief Strategy Officer at Aircom Software. And now I'm currently the VP of Security market research at g2, uh, software. So doing a bunch of things in the space.
I've written books on Zero Trust. I've written books on other cybersecurity topics and cyber warfare, and I have my own, uh, podcast called Doctor Zero Trust, where we talk about zte, uh, weekly. Excellent man.
And of course, you know, the Forester folks did so much to not just coin the name zero trust, but to really develop and, and mature this whole concept to help develop and mature this whole concept that's been so widely, you know, adopted by, by the cybersecurity industry. And, and, you know, uh, marketplace. You know, when I look guys, when I looked at the, the title and abstract for this interview, part of me wanted to scream, right?
And I'll tell you why. I've been in cyber a long time, 25 plus years, and it's so predictable in cyber, we, we follow that Gartner hype cycle to the letter, right? We, we grab a concept and we run with it, and it gets hyped up, and it gets hyped up to the point where it, it's unrealistic what, you know, it's not going to slice bread and, and, you know, bring, uh, bring hair growing on my head again or anything like that, right?
Uh, well, maybe it will one day, I don't know. But, um, you know, and then, you know, it's that whole trial of disillusionment and then, you know, it, it gets real. So when I see a thing here with API security and zero trust, to me, these are two concepts that are, have lots of merit, are very valid, are really damn important, but have been victims of this, you know, overhype and, and, you know, overhyped expectations.
And I'm saying to myself, oh, wow, this sounds like we're putting peanut butter and jelly together here. Or, you know, peanut butter and chocolate, and did, did they really go together? How do they go together?
So let's talk a little bit, actually, before we do, I, I would be remiss. Hey, Richard, I'm gonna ask you for people who aren't familiar with traceable ai, would you mind just giving them a quick background? Absolutely.
Uh, I would, I would say, I would always start the conversation about traceable to say we're the most unfairly advantaged startup possibly in solutions history. The reason for that is the roots of the company, uh, the roots of the company are tied directly to our founders. Uh, GT Bonsal, uh, Sanjay Nagaraj, uh, gt, um, in oh seven or oh eight eight-ish, I believe started AppDynamics and, um, and, and was very, very successful, uh, you know, kind of semi legendary for his sale of AppDynamics to Cisco the day before I p o in 2017.
Now, the reason why the AppDynamics piece is so important is because there was a, there was an aha moment as, uh, the company was building application performance metrics and measures and all of the things that AppD does. Um, there's a, there's a legend, uh, that one of our, uh, distinguished engineers said, Hey, did you notice that we're throwing away all the security related information while we're focusing all the, on the, all the application performance information? I wonder if that security information is, uh, important.
And that's really be became the, the core, the kernel of, uh, the, the business proposition for traceable, which was, uh, it, all of the a p I space. The entire a p i universe is just simply code language. Um, so are you able to define and understand what an A P I is supposed to be doing?
Are you able to catalog and discover every, uh, a p i within a given, uh, e ecosystem or environment? And are you able to manage the security in a way that you reduce the risk and the exposure of those APIs, uh, for yourself as a company, but also because of the way that the world has expanded from an a p I standpoint? Now, what about your supply chain, your third party risk, your associated vendors?
All of this, uh, space now has virtualized into, uh, this layer seven, uh, this top, uh, layer referenced in, in zero trust models. And, uh, that, that virtualization now has created a space where, uh, APIs run everything. Um, I, I should, I'm an old banker, so truthfully, mainframes still run everything, but nobody wants to talk about that cuz that's not going.
We do. We, no, we do here, we do the Open Mainframe project with the Linux Foundation once a month. I spent an hour talking mainframes.
Yeah. But, um, and, and even APIs, uh, we actually, uh, had requests the other day for the use of the api, I, IBM api, I gateway, uh, uh, connect to ee, um, because even now, uh, extracting the stranded value that you haven't been able to get because of the massive amount of work to do hard integrations and hooks, um, is, is evaporating. Because APIs can do that.
I always like to say, like, you know, uh, uncle Ben and Spider-Man with great, uh, power comes great responsibility, great responsibility, right? APIs have a tremendous amount of power, uh, but they've had no security framework around them for more than a decade, uh, which is, which is problematic. So a traceable focuses attention on security monitoring, cataloging, discovery, divining, what an API is supposed to be doing.
Great thing about APIs. When they stop doing what they're supposed to be doing by design, they're probably doing something bad. And that's a really, really helpful aspect of APIs that is still complicated by the fact that there are so many of them.
Volume is our enemy, um, you know, but, uh, being able to operate at enterprise scale is another part of traceable story. Absolutely. com was, was our first property that we started, and Jodi and the, uh, AppD team were the, I think the first or second sponsors.
So I've been, you know, working with Jodi Companies, Jodi companies ever since. Um, but yeah, I, I mean, you know, I, I think the, the, and I, I've spoken to Jodi and, and, and the team. I think the biggest problem initially with API security is that people didn't even know what APIs they had.
And if you don't know what you have, how can you make sure they're secure? And, and this is a problem right? Now, take that and overlay that with sort of a zero trust philosophy.
When you, well, you don't know what APIs you have. How do you, how do you even contemplate, right? In installing sort of a zero trust architecture on your APIs that you don't know are there anyway.
Um, and, and this, this is a problem, right? This is a problem. So let, let's talk about this reference architecture then, and, and you know, what it does, what it's, what it's supposed to do, how people work with it.
Well, if I can jump in real quick, I want to set the table here, because one of the things that you've said has been the biggest problem I've experienced since I've joined Traceable and talking with the market about a p i security. And then I wanna kind of, um, you know, pitch it over to Chase for his perspectives, because this whole effort really came about because of, um, my relationship with the Zero Trust community. Uh, I joined, uh, a group of zt uh, practitioners and, uh, thinkers, um, and I was like, I was an unwashed, um, you know, sinner.
I did not believe in Zero Trust to the depth that I believe in it. Now, when I first started out, because I was an identity guy, and, and Zero Trust to me, always really, um, sounded like friction. And when you run, you know, one of the largest identity shops on the planet for one of the largest banks on the planet, friction is a bad word.
However, the, the realization that I had was, is I was absolutely totally wrong. Um, and, and part of the, you know, the idea, the development of a Zero Trust, uh, uh, a p I access, uh, framework and reference architecture is because of a big gap, um, in Zero Trust, which is reflected of the fact that Zero Trust is still evolving and maturing. But that big gap is, is that, um, I've been on stages with, you know, chase and with John Kender, Bagg and Eve Mahler and Greg Il talking about, you know, zero Trust.
And, uh, always the conversation went to, and when we get zero Trust, right, all security will move into layer seven, you know, by policy. Um, and all of a sudden the red lights went off for me when I joined Traceable, I was like, does anybody know how bad application security is? Yeah.
Because that's, that really has been the Wild West for 30 years. And so the point that you made that I really want to kind of dig into and then, you know, kick things over to Chase, is it the, the people that talk about API security being so hard because we have no idea what we have, everything's outta control, are missing a historical pattern and truth about technology. We have had multiple episodes of, I don't know what I have.
We used to, didn't we, we, I walked into data centers as a, as a senior executive and say, how many firewall rules do we have? And I would have data center operators look at me and go, Ooh, I don't have any idea. Uh, when we first started on virtualization, how many VMs do you have?
I don't know. How many web applications are your employees using? I don't know.
Right? And I think that, um, speed, velocity, volume is scary, which is causing people to go, eh, you know, there, we don't know. So obviously, you know, we don't stay a fighting chance, but in reality, we've been successful for 20 years, taking the unknown and turning it into the known.
And I think it's the unknown aspect of this unknown is the anathema of zero trust, right? And, and having unknowns isn't just not acceptable. It defeats the entire mission of achieving zero trust outcomes.
And that's, that's a, a good baton handoff, I think, to chase. Yeah, I mean, For, For me as somebody that, that was a red team person and is always looking at things from the perspective of where the weaknesses lie. Um, but that was one reason why we decided to come up with this framework was the entirety of zt and the entirety of digital architecture, in my opinion, is, is potentially a house of cards if we don't deal with the API problem.
Um, I honestly think that now the way that we've evolved architecture and infrastructure digitally is that the API is the network. I don't think that the network really is that, uh, critical in the long sort of approach that we have to overall security architecture. It moves net electrons, that's it.
We've kind of like taken network and we've mushed it into security for a long time, when in reality where we're at and where we're going is that APIs, the connections, the interaction, the burst ability, all those things that we rely on is critical to this. So to your point, Alan, we, we saw that there was a need in the market to come up with a reference architecture so that people could understand this was not just more pontification and, you know, blowing smoke into the market and saying, look, here's another thing that you can do. Um, we really focused on having a pragmatic, practical approach to this from practitioners so that folks could read through this document, understand, okay, this is what, you know, we can aspire to.
These are the, where we see areas for improvement. This is what APIs do in this context. And being able to have a formulaic approach to it.
I, I think absolutely mandatory because at the scale of APIs that we see in, in enterprises today, right? If, if you don't have something that's programmatic, you're kidding yourself, right? Don't bother.
Just really don't bother. You know, if you're a little mom and pop shop and you could count and you think you could count the APIs you're using on two hands, well, you don't know what you're talking about either, because you're probably using 10 times that amount of APIs really, in your business. But that being said, it's a lot easier to wrap your head around, but at scale, it's crazy.
Yeah. One of the first things that we start out in this document is exactly what you both hit on, was understanding the totality of APIs that you actually are connected with and leverage. And that, yep.
Sounds like a holy crap problem. How do I deal with this? But guess what?
That's what technology is for. I mean, that's literally why solutions are created. We don't, you don't manually go through on a spreadsheet and update firewall rules anymore.
You use software. Like, that's the same thing. Well, The, I remember when you did do that, but yes, you're right.
I had a lot of friends who made good money with that firewall automation stuff. Um, but, but guys, here, here's the thing though. New APIs come on board all the time in an organization, right?
We connect, we zap, we do this, we do that, right? How do you, and, and, you know, and the whole point of a ZT architecture is look, by default, by default, we are, you know, zero trust. We, we don't trust anything by default, right?
And, and so now when you get outside the security organization and you're dealing with developers and you're dealing with, you know, ops and DevOps and so forth, and people are like, man, this is, you know, this is kind of really slowing me up. We gotta move at the speed of business. How, how, how do we do that here with, is this reference architecture?
Help us speed that up? Well, I, the, there's a couple of different aspects to it. The first is, is that it's important to recognize, especially when we think about traceable coming to market, um, you know, specifically focused on APIs and their relationship to Zero Trust, really the first organization to do that, it means we're at beginning days, right?
There are some structural problems, uh, with the way that a p i management and a p i governance, which is functionally non-existent in most companies. There are some structural problems that are going to need to be sorted out, right? When we think about a zero trust, uh, a p I access overlay, um, what we're doing is we're taking that first important step of not just discovery, but the idea that if you have discovery now you can keep track of, and you can also do comparative analysis from a conformance standpoint against internally published standards for a p i development and so on and so forth, right?
Those are baby steps. Like when we think about that DevOps example that you just used, look, there's some really bad problems with APIs. The one that I harp on the most that is such a complete violation of Zero Trust, um, is the idea of implied and persistent trust, particularly at the authorization layer layer with APIs.
And, and we can't blame developers entirely for that issue, right? The fact is, is that we're still using, um, you know, a ees and symmetric, uh, symmetric encryption, uh, that was introduced by Microsoft in 2001. Um, we haven't seen much in the way of kind of key exchange innovation that's happened that creates more secure transactions.
It's basically my a p i is authenticated and I have AC access to everything. And, um, the real problem with that is, is that that's an exact copy and model of what's wrong with identity today, right? I, I authenticate once I have access to everything and many cases keep my session open, I have access to everything forever.
APIs can't continue to function that way, right? And so when we look at the Zero Trust approach to APIs, what we're saying is, is we are trying to expose, we are trying to say the quiet things out loud, that force conversations for substantial structural improvements to way, the way that APIs are used and deployed. And nowhere in that mission do we talk about, we wanna make it harder for DevOps.
That is a non-starter, right? But we do need to, uh, address the structural insecurity issues with APIs that exist today. Agreed.
Guys, unfortunately, we're, we're so far over timer ready, but I gotta get, I, we gotta leave people with something here. Um, chase, Richard, what's the best way? Readers out here say, yep, you're talking to me, man.
I, I, we need to jump on this. What's the best way to engage here? How do they get the architecture?
How do they interact with it? What, what's, what's your prescription doctor? I mean, I, I'm always glad to share anything that we, uh, work on or publish, uh, personal wise.
So folks can always contact me on, I'm pretty active on LinkedIn, but Richard knows where all the bodies are buried at Traceables, uh, system there. ai. But I think it's more important, like the point that Chase just made, like, these are, this is not, you know, frankly, this is Richard's opinion.
This is not go read a white paper, right? This takes a lot of socialization, a lot of conversations internally, a lot of peer conversations. Um, and, and that's really, you know, why I love working with Chase, why I'm so excited to have him as part of our advisory board.
Um, as well as, you know, several other, you know, key, um, resources and personalities in cybersecurity is because we do actively make ourselves available for these conversations in the market. Um, if we're not out there actively speaking about it, we're easy to reach. Um, but we, we now have what I think is a very, very good structured set of materials for people to be able to access, uh, within, uh, traceable, uh, AI's website.
Um, and then, you know, the resources like us that are available out there to have these conversations. Love it. All right.
ai, is that, is that the website? Yes, sir. Wanted to make sure we got that right.
Hey, chase and Richard, thanks for joining us today on Techstrong tv. Keep up the great work. You know what, we, we'll, maybe we'll run this back and dive in here a little.
We'll peel the onion back a few more layers next time. Happy to do it. All right.
Hey gentlemen. Thanks guys. We're gonna take a break here on Text Drunk tv.
We'll be back in a moment.