Application Vulnerability Monitoring with Contrast Security’s Jeff Williams
On Jan. 16, Contrast Security announced the release of Application Vulnerability Monitoring (AVM), a new capability of Application Detection and Response (ADR).
Transcript
This is Techstrong tv. Hey everyone, welcome back to Techstrong tv. Uh, I'm really happy to have my next guest on, uh, you know, when he, when he's not busy playing basketball, he is also the co-founder and CTO of Contrast Security.
Really smart guy though. He is, been involved in Oasp for as long as Oasp has been around. Just about, uh, he's, he's probably one of the smartest folks I know in the whole AppSec space.
My friend Jeff Williams. Hey Jeff, welcome back to Tech Drug tv. How are you?
I'm good, thanks Alan. I didn't wanna make you sound, I, I, I guess I made you sound a little old when I said you've been around. Oh, watched series.
It's true though, but it's, yeah, you know, look, if the shoe fits. Anyway, Jeff, of course, you're the co-founder and CTO of contrast security, a really a, you know, a, a pivotal figure in AppSec for folks who, before we jump into what we want to talk about today, for folks who aren't familiar with Contrast security, what would you tell 'em to make 'em smart about Contrast? Yeah, we're an application security product company and we protect some of the most critical applications in the world across the whole lifecycle.
So instead of, you know, having some tools that you use in development and some tools that you use in production, contrast covers the whole gamut. Absolutely. But you've also pioneered, right, this dynamic scanning, static scanning, what you have all of that, but you've pioneered some other kinds of scanning as well at Contrast, haven't you?
Well, our big innovation was to use runtime security techniques. So we instrument running applications and we watch them run. And the reason that's so powerful is because it's real.
When you're watching the actual code run, you get results that are accurate and it's fast and very detailed findings. It's, it's just different than if you use other tools that give you kind of theoretical findings that take a lot of triage work. Absolutely.
And Jeff, before we jump into our topic of discussion, people want to get more information about contrast security. What's the website? com.
Excellent. Alright. So Jeff, I think it was the last time you and I spoke, you guys had actually, I don't know if it was you or someone else at contrast, but you guys had announced something called a DR, correct?
That's right. Yeah. That's application detection and response.
And it's a, a relatively new category in AppSec, but very exciting. Mm-hmm. And now you're here today to tell us about sort of the next iteration, the next, the next shoe to drop on on a DR, so to speak.
Yep. Yeah, so I wanna steal your thunder. You tell us.
Thanks. A BR works in production to protect applications from being attacked. So you get, you know, complete visibility into who's attacking and what attack vectors they're using and what your attack surface looks like and, and all that.
But we realized it would be great if you could connect up the vulnerabilities to the attacks, right? So, you know, if an attacker's gonna get in, they have to find a vulnerability and exploit it. So vulnerabilities and attacks are like two sides of the same coin.
And so what we're doing is we're turning on the ability to detect a vulnerabilities in production as well as attacks. And we link 'em together so that you can see exactly what vulnerability the attacker is trying to exploit. Uh, you get all the details of it and it actually benefits both sides.
It's like a one plus one equals three. 'cause now the developers get details like, Hey, that SQL injection that you were putting on the backlog, 'cause you, you weren't gonna fix it for a while, it's being attacked in production, then you need to fix it right now. And in operations, the team can see not only that there's an attack happening, but they can see exactly how the vulnerability works.
You can rule out all those attacks that don't connect with vulnerabilities. 'cause who cares. So it's, that's like 1% of attacks actually connect to the intended vulnerability and you can focus on those and you can get all the details so you know exactly what happened.
Not just the details of the vulnerability, but even the contextual details about the route that it's on. Uh, what assets are involved, what's the blast radius. Uh, and we're doing some really cool things with risk scoring, which we can talk about if you're interested in that.
Absolutely. Before we get there though, Jeff, humor me, I'm an old security person. Hmm.
Is, is this what's old, is new again, weren't we, weren't we supposed to be doing vulnerability scanning of production systems and nodes back when I was doing security from 2001 on? Yeah, that's right. And the reason that you wanna do it in production is because production is real.
Like development test environments are not even close to reality. They don't have the data, they don't have the connections. They, they're a lot of mock stuff.
Like they're not really testing the actual thing. And so you're right, the back in those days we tested production because it was real. But there's been e evolutions in that market.
Uh, there's, there's difficulties with testing production systems because if you do like dynamic scanning or pen testing, more than likely you're gonna break that system. You're going to mess up the data. And yes, that was always the fear excess attacks all over the place.
Uh, and so it's complicated. This approach, a VM is a passive approach. It watches the application run with real user data, but it doesn't need attacks in order to detect vulnerabilities.
And so you can safely run this in production without hurting anything, without affecting performance, without really any interaction other than normal user traffic. So it's really a nice, you know, a nice use case for just install it once and then from that point on forever, you just get great vulnerability data in real time as you use a system. You know, I remember Ron Gula talking, he used to call passive vulnerability scanning PVM.
Yeah. And most, most layers of the stack is that similar, he was just listening. I'm sorry, they, you would say PVM passive vulnerability scanning and he had like listeners on the network, not heat tenable, had listeners on the network that, you know, were, were trying to, from looking at the traffic, trying to find vulnerabilities.
Exactly. And what we're doing is kind of that, but for the application layer, right? And we've seen this evolution across all the other parts of security moving from scanning and firewalling to instrumentation based approaches that, you know, run on platform and monitor the running system.
So you've got things like EDR and uh, SDR and CDR and so on, they all run directly as, you know, part of the application or part of the, the stack. This is what a BR brings to the, the application layer. And a VM is this cool extension to a DR.
It's not just protect, it's also assess and, uh, find vulnerabilities. Sure. I mean, and just, you know, you and I are talking final points here for our audience out there.
A lot of your security people, and you understand what we're saying. A lot of my app dev audience and, and cloud native and so forth, if you're not familiar with all, with all of this, right? When, when you test an app in development, let's say, while it's still in development, it's not really hooked up to that database.
So you don't know what's gonna happen when you hook a live database on back end of that app or where it's sitting in the network and, and you know, what are, and the real identity and access control management system is, is, you know, letting people in or out and so forth. So you, you know, it is, unless you set up like a true digital twin of your production system, there is no substitute for for testing. You know, you wanna call it testing or vulnerability testing, whatever for testing in production, right.
To really get the real deal. That's right. Um, you know, modern apps are composed of tons of pieces, libraries, and tons of, you know, like you might have a dozen repos that make it into part of a running app.
And there's uh, you know, the environment and the databases and the backends, the APIs and so on. And that never really all comes together any place except production. So, you know, you use a SaaS tool, you run outta one repo.
Does it really have the context to identify vulnerabilities? No. So what we're trying to do is say, Hey look, you gotta test the actual running thing.
That's why we crash test cars is you gotta test the actual thing. You can't just test all the parts and go, well, I guess it's gonna work. Exactly.
'cause funny things happen when you do that. You mentioned a risk score. So you're telling me we don't use CVSS anymore?
No. Well, here's CVSs. I said it tongue in cheek.
I just posted about CVSS. It's fine, it's good enough. Uh, it's got some warts and so on, but it's good enough.
The problem is the farther you shift left, the less context you have. And so CVSS has placeholders for all this kind of data. Like is the, the application being attacked?
Does it have critical assets, uh, you know, does it make connections to other stuff? Like all this stuff that you can't know if you're shifted way to the left. And so we use a s based system, but we're calculating the score and we're including all this, all this threat data, uh, all this data from production production context about assets and so on.
So you get a dynamic risk score. So, you know, take a SQL injection for exist, for example. Almost all the other AppSec tools will say that's critical and that's it.
But it's not a SQL injection that's not being attacked in production might not be as critical as some other things that are being attacked. And that SQL injection might not connect to a database that has anything particularly sensitive in it. Uh, it might only be accessible by an admin.
And so that SQL injection you thought was critical, it's not, it's really a low or e even lower. Uh, and so we're trying to give you an accurate risk score that takes into account production context that's gonna help you focus on that 5% of issues that really matter. And that's, that's super exciting to me.
Here's, here's one thing that I didn't know before I headed down this road about a year ago. Uh, CVSS makes assumptions about those things, and it assumes the worst case always. If they don't know that it's being attacked, then they assume it's being attacked.
And you get this. But that was done deliberately. I so look, I remember when they came out with CVSS, right?
And my friends fly the yes, but, but they, they erred on the side of of conservative, right? Because what are we gonna assume? I mean, you couldn't, you couldn't slice that baby in half without killing the baby.
So they, they went that way on purpose. Yeah, I get that. And that's, that's what I would've done, uh, until I really thought about the problems that real companies are having.
1 million AppSec vulnerabilities in their backlog that's from pony mod. And they're struggling to prioritize that stuff and fix the stuff that matters. And if everything is inflated scores, they're never gonna be able to fix the right.
Well, that is the flip side. If everything is, is super critical, nothing's super critical. Exactly.
Right. And so that there, there is that, but in the absence of context, that's, that's why the answer is in production, the context that you want, all the answers that you're looking for are there in production. And so what, what a DR and a VM are really about is flipping on the lights in production.
And you mentioned digital twin before. I'm glad you said that. 'cause what we are doing is we're, we're making a digital twin of AppSec in production and not just one app, but like your whole application estate, all your APIs, all your apps, how they connect to each other, all your assets.
We're building that, we call it the contrast graph. And that graph is where the context comes from. And all of the findings that we make are informed by the context, by the contrast graph, you know, now I can see said the blind man.
So it's not that you're doing a point in time scan like Qualys or, or, or Tenable or, or found stone back in the day used to do. Right. Pulling a name from the way back archives sheep.
Yep. But, uh, but what you guys are actually doing is in essence setting up a graph or a, a digital twin of that production system. So you don't need an actual scan to, because that does break things or potentially break things.
That's right. But you could, you could run on there and you see instantly where, where there's a problem. That's right.
Yeah. Our sensors are gathering real time telemetry from the running applications and all the telemetry feeds into, uh, you know, massive streaming data architecture that we've built that builds that graph. And then based on the graph, we can give these really contextual findings so that people can prioritize the work right, fix the right stuff and really get healthy fast.
And somewhere Marty Roche Rush and, and Ron Goler are smiling. 'cause I, you know, they had this vision back then, but I don't think we had the, we didn't have the horsepower to pull it off, right. To Well, those guys are busy, uh, you know, sipping bourbon and smoking cigars on the golf course somewhere.
There is that. Well, right near you. You live near them, right?
Yeah, yeah, yeah. They're all in your neck of the woods. Uh, that's right.
But yeah, no, I mean, look, this has been sort of a dream in, in vulnerability management for a long time, but it sounds like you, you, uh, you're living the dream, Jeff. Well, it's time for AppSec to AppSec to grow up. We can't think of like one app at a time, one scan at a time.
The strobe light visibility isn't working for anybody. So, you know, we think this is the, the right approach. And we're, and I think most importantly, we're bringing dev and ops together.
Like whenever there's an attack, you want the ops team to respond to the incident, but you also want the development team to fix the underlying problem. And you want the the there to be some coordination between those two efforts in parallel. Uh, and you want the feedback loop to be really quick.
That's, that's the vision that we're, uh, helping our customers implement. I love it. Let me ask one other business related question.
How, how is this being offered? Is it a standalone, you gotta already be a customer and if you are, does it cost extra? How, how do you package this?
No, uh, a DR is, uh, generally available for everybody. You can buy it now and, uh, we'll get you started on a path to a better AppSec program. Um, we still offer an a ST product that you can use in development.
Uh, it uses the same runtime instrumentation, but we, we believe the future is using both a DR and a VM in production to monitor real production activity. I love it. Yeah.
Hey man, keep it up. You're always innovating there, Jeff. Good for you.
I appreciate it. com. Absolutely.
Jeff, you're gonna be with us at RSA at our, uh, what we used to call it DevSecOps, but now we call it cybersecurity and AI and App Dev. Uh, Monday of RSA week. I know Contrast has Stein on to sponsor there.
We might have a panel I need to talk to you about. Nice. I'd be happy to.
Absolutely. We'll, we'll talk more on that, but man, it's always good to see what's cooking at contrast. Thanks.
There's always something cooking. Thanks. Right.
Thanks. Great to catch up. Appreciate it.
All righty. Jeff Williams, co-founder CTO of Contrast Security here talking about A VMI got that right. A VM.
Okay, we're gonna take a break on Text Drunk tv. We'll be back in a moment.