API Security and Management in 2024 with Cloudflare’s Grant Bourzikas
Cloudflare’s 2024 API Security and Management Report unveils how APIs are being leveraged by businesses more than ever (57% of all internet traffic) — ultimately opening the door to more online threats than seen before. Cloudflare’s Q4 DDoS Trends Report dives into the ways threat actors deployed and attempted to wreak havoc through DDoS campaigns in Q4 2023, including the largest DDoS attack ever seen in the history of the internet.
Transcript
This is Textron tv. Hey, everyone. Welcome back here to Techstrong tv.
Our next guest is Grant Bki. Grant is the Chief Security Officer, CSO at CloudFlare. You know, and for those who don't know, many of you probably know CloudFlare, you may not, you may or may not know how much security, you know, CloudFlare.
CloudFlare is actually involved. And we're gonna get into that. We're also gonna talk about two reports that CloudFlare recently put out around some analysis and stuff that I think you're gonna find really interesting.
But first, let's meet Grant. Grant. Welcome to Tech Drunk tv, and thanks for joining us today.
Thanks, Alan's wonderful to be here. Pleasure to have you. So, grant, you know, let, before we jump into all the other stuff, let's hear more about Grant, right?
Your Chief Security Officer at CloudFlare. How long have you been there? What have you done?
Yeah, so I've been at Cloud for about nine months, a little over nine months. I, I joined. Um, so I think it's a very special place and we can talk about that.
Um, but for me, you know, I've been at CISO for 20 years. I've spent time in some of the largest global banks in the world. Probably the most innovative bank in the world.
Um, sometimes in trading. I spent time as a CISO for Nuclear Power Generation. Um, and then I also spent, um, about three years with McAfee at the height of McAfee, um, where I ran the labs organization as well.
So, you know, I, I started in the late nineties doing cybersecurity or that time, you know, just security with a bunch of, you know, geeky people. You and Me both. Yeah.
We didn't call it cyber then. It was info. Yeah.
It was cool. We didn't even call it cyber then. We just called it, you know, those guys in the dark room, you know, doing Mm-Hmm.
Report scanning. Um, but I think right, it's, it's the only thing I've really done in my career. Um, I've been fascinated with it and, and you know, 20 foot, you know, been a, so 20 years, been, been doing this almost 30.
So, um, it's pretty, pretty amazing journey for me. Absolutely. You know, it's far, I've actually been in, in security myself since the late nineties.
So it's, um, it's been an interesting ride back then, you know, there weren't people who went to school to be security people, right? They, people who were in security were mostly network people who got kind of drafted in, or people who liked to break things and then put it back together so they weren't so easy to break. Right.
That was kind of your typical security people. Y yeah, you're right. Like I was thinking about the old pin testing we did.
It was on routers, right? Ports open. Yeah.
That right? Like it was old school stuff and, you know, come, come, you know, look, as I look at 2024 and I always think I'm still young. Um, and, and then I'm like, Yeah, you and me both actually.
Yeah, I'm Not, I've gotten a little older as this time, but, Well, well, you see these kids coming outta school and they're like, you know, they've taken a, they've got a cybersecurity area of concentration and all of these things. But, you know, the funny thing, and it, and it's not for this show. We'll have you on another time, we could talk about it.
The common thing I hear from all these, and I call 'em kids, you know, from all these recent graduates, let's say, is how do I get started in this business? Right? They got all this education supposedly and all this training they got in school, and they have a hard time getting started in our business.
Mm-Hmm. It, it's a, it's a very good point. I'm actually part of the World Economic Forum on this, you know, how do you build cybersecurity, you know, skills?
And I think it's, how do you do it? You know, it, it's, uh, it's, it's probably worth a longer conversation. But my undergrad's an accounting.
I'm a CPA, I just finished my master's in artificial intelligence, so I'm not trained. And so I always tell people, pick up a book and read it. And so, you know, I think when I looked at, you know, going back in the days, I, I don't have the hardcore engineering, you know, outside of the AI machine learning stuff that I've done.
It was read a book and I always, the advice I always give people was an old boss of mine said, grant, do you still carry those books around? Um, now back in the old, you know, early two thousands when there were, you know, bookstores that you'd go to every week and I went to a bookstore, read a book, and then went back the next weekend and bought another one. And so, you know, I, that's my advice for people.
Go pick a book now. It's a lot easier with, with everything online, with medium and some of the great access to websites that are there, you know, do that. But I always, I always get a little frustrated.
'cause it's like, take your own career in your hand and learn things. Learn operating systems, learn networks, learn, you know, pin testing and, and teach yourself and find what, find what's curious and you'll, you'll get there. So that's my, my answer.
I, I agree with you and thank you for that advice. I mean, similar, I went to law school, man. I, I didn't do any engineering coding or stuff.
Totally self-taught in tech because I, computers were my hobby and, and that was my love, right? And whatever. But, um, it's great advice for those out there.
And I, I, you couldn't get better advice in my opinion. Grant, our audience is familiar with CloudFlare. CloudFlare, what is it about 20% of the internet traffic these days is over CloudFlare or something like that, right?
Yeah. So we, you know, I, I think I always, because a lot of people don't know, and I think even as I was going through the interview process, I, there was things I didn't know, right? And now that I'm here, it's, it's interesting.
And so I always think we're, you know, the connected cloud. So what does that mean? We operate in 325 cities across the world, um, a hundred countries.
And to your point, the cool numbers are over 20% of the internet, closer to 25% of the internet comes through CloudFlare. We stop 170 billion attacks a day. So I would make an argument, it's the largest, um, you know, from a, from an attacks surface, we're, we're core to it.
Um, and we sit in the edges near city. So we don't have big core data centers. All of our platform, all of our software runs within a local pop.
And so I always think we spec our own hardware, we build our own hardware. We, we built our own w version of Linux, and every piece of software runs on every server. So anywhere we operate, you can do anything within the network.
And I think it makes us super powerful from a security standpoint. And so I think a lot of people think of us as an old CDN, which is where the origination is, but we have a full suite of, of internet security products that we'll talk today about APIs, WAFs DDoS, you know, we have a whole full set of zero trust solutions. We have a whole MPLS replacement with, um, our WAN products.
And then something that I am super excited is we even have a capability on the edge for, um, we call it workers, that you can deploy websites, you can run artificial intelligence. And we think it's the inference from an AI model standpoint, that's the future where you can run your models closest to users. So, you know, I think when we look at it, it's a very interesting portfolio.
And a lot of people just think, Hey, we just do CDN, and there's a whole lot of interesting things we do. Agreed. I agree with you, man.
And, and I'm glad you really brought that out. I mean, look, full disclosure, we're, we're a CloudFlare customer, right? Our, our network, our infrastructure runs with CloudFlare, and it, it's primarily for DDoS and security.
And as well, look, it also improves your, your load times and your, you know, your accessibility to people. But more and more it's about the security for us. And, um, you know, there's a lot of people who like to do stupid things, especially when you have a security set like Security Boulevard, uh, you know, there's always people taking shots at it.
But anyway, they, you know, it's yeoman's work. It's good work. And, and I'm glad you're on board there and it sounds like you're the right guy for that, for this role.
And, uh, you know, I think a lot of people count on CloudFlare to make it happen for us. So, good stuff. Let's, let's dive in a little bit.
You guys recently came out with two new, uh, not two new one is new for sure. Reports the inaugural API security and management report. And then we also have a, a DDoS trends report, which you, you guys kind of update, I think quarterly, but let's dive into this new one first, right?
API, security and management. API management is, you know, it, it was kind of like a runaway train there for a while, but I think people are starting to realize now, you know, pull the brakes and, and figure out we gotta manage this stuff. Yeah, I agree.
You know, I think the one thing that I, that I always think is interesting about the report, even going back to where the internet started and we talked about, you know, just routers and switches back in the old day to websites, you know, 57% of all internet traffic is coming through APIs. And so, you know, I think that's one that's interesting. And so, as you know, as a CISO and security people, like your, your threats are just changing, right?
So everybody kind of went into DDoS earlier, you should have good DDoS protection. You talk about that here, a few, you know, to web application firewalls. And that was core to infrastructure.
And so now this API, right? Spectrum is another technology and another avenue, and it's even, you know, more pervasive, um, than what we've seen on websites. So, you know, I think it's, as we look at this, right, it's something people should be paying attention to is the APIs.
They're, they're easier, they're, they're, you know, easier for the businesses to connect business to business. Um, we're seeing websites based off it, you know, mobile apps within APIs. And so the world's headed there.
And from a security standpoint, you know, it should be something people are paying very close attention to. Uh, absolutely. Absolutely.
Um, I mean, that's reason enough to do this kind of annual report, right? 57% of traffic over APIs is the kind of key takeaway there. Um, what, what did the report show this year?
Any, you know what, I always like to ask people what, what were the key takeaways? What was the big surprise for you? Yeah, I think you, you, you see the large industries targeted crypto, um, which I think is interesting.
You're also seeing a lot of API traffic in Africa and Asia. And so I, you know, I think that was something I, you know, I, I looked at four or five times, like, why Africa? Why Asia?
I think, you know, even some of the stuff that we're doing, um, the World Economic Forum that some of these emerging countries are kind of skipping from websites into APIs. And so we're seeing a lot of traffic, um, from that standpoint. So, um, but I think, you know, the heavy targeted, you know, websites with APIs that we're seeing iot, we saw a lot of taxis, you know, kind of the legal services and, you know, gaming.
And so, you know, it's, it's one that you're starting to see a shift in where traffic is originating from an API standpoint and the traditional kind of brick and mortar sites into how do we kind of interact with, um, you know, different industries that can really leverage APIs. And I, I, I think that's one that, that's big. Um, the only one that we did see, and it was something I was reading this morning, you know, m dm, so, you know, why are, why are, you know, you know, some of these APIs may not be protected and we're actually seeing a targeted increase on your mobile device platform.
You know, though they have access to APIs internally. And so we're starting to see a little bit MDM attacks focused on internal APIs that they can get data. So, you know, a lot of the MDMs, right, that have access, right?
You grab your phone and they have access to those devices, maybe they're not protected as much 'cause they're not sitting on the internet. Um, and so we're seeing it there. And then the other one that I think is super interesting is like, people don't, you know, people don't know where their APIs are, right?
This is, this is, you know, if anybody on this call is like, Hey, I know where all my assets are, we're kind of fooling ourself. But I think this is one that, you know, everybody focuses on asset management, but exposing APIs, um, out on the internet and not protecting 'em is super dangerous 'cause, right? It's, it's the old thing that we, you know, 10, 15 years ago and we had websites just basic input validation or, um, you know, you know, being able to pull back data, um, that you're not supposed to.
And I think these are all mechanisms. It's a new platform, different technologies, different developers that, that are there. And we're seeing that threat pose significant impact organizations.
Absolutely. You know, I spoke to another of an API security vendor, that's all they do about a report they had. And, and this is going back maybe last year.
Um, you can't defend what you don't know is there. And, and the fact of the matter is, I think most organizations do not have a handle on exactly what APIs they have, which ones are, are running, you know, which ones are active, which ones are dormant, which ones have been closed, which ones have been locked down. You know, until you kind of map that out and, and have your head wrapped around that, how can you even formulate a plan to secure them?
I mean, you know, it's just chicken and egg caught before the horse kind of stuff. Yeah. And you know, I think the other one that poses this one, and this is one I always think about, um, you know, having spent time in basically two of the largest banks in the world the last five years, you know, you, there's a lot of technology, right?
And so we often try to solve a problem with technology and you know, it makes the, you know, we buy more tech, right? So we buy more APIs, we buy more wa, we buy more DDoS. And then, you know, you end up, you know, in a situation where I, I joined an organization a few years ago and I had six web application firewalls, right?
And then you start to think, well, how do I manage this? Right? Like, it's too much, right?
Just too many things. And then you add APIs to this. And so, you know, you're already behind kind of the technology curve.
Um, because like, I don't have enough people, right? I don't have enough budget. And so, you know, even at the, the global bank I worked in, I had a, you know, a billion dollar budget, 1500 people that worked for me.
And the, the number one and number two complaints where I don't have enough people, I don't have enough, you know, dollars. And, you know, it was an interest, you know, as I think you go through this, it makes API security hard 'cause it's just yet another thing to do. And I'm gonna buy another vendor and I'm gonna end up with 50 vendors.
And how do I manage this with a team of 30 people, right? And not everybody, you know, there's a super interesting thing that, um, was rolled out on, on the World Economic Forum was about the, in inequality of organizations in cyber talent, right? So, you know, the larger organizations can pay more, right?
The big banks can pay more. Um, CloudFlare has, you know, I think we've had over a million applicants to our, our jobs last year. So we get qualified people, there's inequality and you know, people wanna work for CloudFlare.
And so I can take the best people in the world, I can develop the best people in the world. And so, but it's harder for organizations that don't have the money, don't have the resources to support it. And, and you know, it's something we don't talk about a lot, but how do you defend your organization when you have 50 tools and 30 people?
And, and that's just managing engineering. That's not controls, that's not board, that's not regulators. And so, you know, it's not even helping the business.
And so I always think this is an interesting thing 'cause you know, that every CISO I talk to is I need more people. I need more money. How can you help me get huge new attack vector, right?
Um, and well, I need, I, I need more money and more people to manage my API security and, and something breaks, right? And I think in this world, you know, and, and have been in this seat for 20 years, it, it is tough, right? So how do you think about simplification and, and how do you actually get the most out of, out of, uh, out of your security posture and budget?
You know, this is why I sit on this side of the camera now, right? I, I, one of the companies I founded, uh, still secure 2001 outta Boulder. And by about 2008, you know, we, we sold 60% of our business was DOD, right?
So we did a lot of DOD agency kinda work. And then, you know, we sold a lot to global banks and, and, you know, large enterprise and I, I came to the conclusion as we tried to make a push into the mid-market, who are we kidding? These people do not, they wanna be secure, obviously, but they don't have the resources.
Not only do they don't have the resources, as you said in Security Town, there's the haves and haves nots. You know, you, they just don't have a, a snowballs chance, you know where Right. Because they don't, they they don't.
And, and so I, I went to the board and said, we should be coming MSSP, right? We, we should just focus on delivering the security capabilities that most organizations are lacking and will never have. Yeah.
You could be one of the biggest banks in the world and have a billion dollar budget. God bless you. You know, you know what they say about the Fortune 500, right?
There's only 500 of them. What do you do about the rest? And, and look, this has been a, this has been a big issue in security for a long time, man.
Yep. Agreed. Agreed.
And I think that's, it's, uh, something to pay very close attention to. And you know, the other one that I think, and you know, I, I go back, I worked at Scott Trade who I was one of the early people in s got trade and mm-Hmm. And I always thought, you know, back then, this was 2005.
Um, you know, the, when I think about technology, just the internet technology was fascinating. And one of the things when I think about DDoS and multiple vendors and API and web application firewalls and they all are present, is like the path it takes to get there. And where my route traffic from, you know, our customer to our website.
And like, there's this great chart of like, well, if I have an API vendor sends, you know, copy my traffic over here and I, you know, I, I scrubbed my DDoS traffic with this vendor and then, you know, I, I have web application firewalls and like, well I gotta outsource that. And now like latency becomes problem. And so we're not even facing, you know, we're not even facing, uh, uh, like we're facing latency problems 'cause it's slow 'cause we're trying to do things and you know, these technologies and so Right.
This inequality and understanding. And so we're seeing a big shift into this is one of our beliefs, especially with what API is. We have API service, we have a waf like add it, right, add it to the portfolio, simplify it, and, and go through it, you know, put the DDoS in, right?
And, and one of, one of the super interesting things in DDoS is they know if you have a DDoS service, they can trace route. Sure, they can see where your traffic goes. We know that they're testing it.
And typically when they test it against us, they, they don't attack that website. But they're also gonna check you for DNS DDoS, they're gonna check you for layer three, layer four, layer seven, and if you don't have it, they'll exploit it. And I think, you know, even in the DDoS report we saw is we're seeing more network level DDoS.
'cause everybody's pivoted on layer seven application DDoS, you know, the traditional HTTP get. Sure. Um, and so you're, you're seeing people exploit things and it's like, just make this simple and add things and protect it because it becomes too hard with, you know, this.
And I think we talked, I talked to many CISOs and it's like, it's just too hard to manage the infrastructure. It it is. And, and you know, even in DTAs you mentioned the, you know, pivoting from sort of app level DDoS to, to network level DDoS and we're seeing ransomware as DDoS or DDoS is ransomware now.
And, you know, all kinds of just craziness. Unfortunately, grant, we're, we're probably running outta time here, but for people who want to get more information on both of these reports as well as, you know, CloudFlare security capabilities and services, where, where can we send them? com.
You can get both the API report, you know, the API security report. It's a really good one. com.
You know, they're great. Um, they're great resources. They're good reading, they're good material to talk to the board about.
Um, that was something I used to do, you know, look at and 57% of traffic is, is API, we don't have anything, right? Or, Hey, we're seeing 117% increase in DDoS traffic, we should probably do something. So those are things I think are very good.
They're good points. You know, all a lot of vendors do it, but I, I think you can kind of triangulate and say, DDoS is up, APIs are up, should protect yourself. Absolutely, man.
Grant, good luck over at class. I know you're there nine months, but it's still just nine months. So good luck and I hope, I hope to, uh, talk to you again soon about what you guys are doing and, uh, keep up the great work, man.
Yeah, you a lot of people depend on you guys. Thanks Alan. Thanks.
You know, everybody for watching this. And yeah, if you ever want me to come back, just let me know. We're, we're always happy to have you.
Be careful what you asked for. Um, grant Bki, uh, chief Security Officer Cloud for here on Textron tv. We're gonna take a break.
We'll be back in a minute.