Aviatrix CPO Chris McHenry on Securing IT Environments Amid Rising Network Traffic Complexity
Chris McHenry, chief product officer for Aviatrix, dives into why IT environments are becoming more challenging to secure in an era where it’s more challenging than ever to identify legitimate network traffic.
Transcript
Hey guys. Thanks for the throw. We're here with Chris McHenry.
He is Chief Product Officer for aviatrix. And we're talking about well network traffic these days, especially in the cloud, it's getting hard to distinguish what's what, and I guess we need to find some way to figure out what the actual intent is, because otherwise it all looks the same. Chris, welcome to the show.
Thank you. Thank you, Mike. Good to, good to see you.
Right? Yeah, so this is something that we're super passionate about. It's, uh, it's been, it's been a really big problem.
I'm excited to talk about it. Well, describe what the problem is because theoretically, we are at least implementing all these various zero trust protocols, but if we don't have some way to understand what it is something is trying to do, it gets really hard to put a policy in front of it. Yeah, a hundred percent.
And, and I think in many cases, organizations are even a step behind that. I zero trust has been something that people have been working on for almost 20 years now, if you get back to kind of the origins of it, but obviously it's been a project on CISO's whiteboards for the last 10 years or so. And, uh, it's challenging.
It's challenging because in many cases we have no idea what things are doing on the network in the first place. Uh, not only do we not know what they're doing, but we don't necessarily have controls. And cloud really, I think in many ways has completely changed the game in terms of the way that people need to think about network security, think about how they, uh, how they look at their network traffic.
And ultimately, uh, the network is the thing that allows attackers to act in your environment. And they're getting really, really good at, uh, what they generally call living off the land, which is using the things that look normal. Uh, you know, it's, it's, uh, it's obvious, you know, if you go look at many of the breaches nowadays, a lot of them start with a stolen identity, A legitimate, legitimate stolen identity, stolen credential, right?
And so, uh, so figuring out how we can, um, how we can mitigate some of these attacks, I, I, I, I do ultimately believe that the key lies in the network. Now, one of the things that's really changed when organizations move to the cloud is that, uh, your trust boundaries fundamentally change because a lot of the services that you're using used to be inside the four walls of your data center. If you had an Oracle database as an example, it would be a physical piece of hardware that you sought on the floor that you could plug, you know, cables into.
Now you're renting a database from Snowflake, you're using APIs from OpenAI or Bedrock, or all of these different paths. Are those things that we trust? Are they east west traffic?
Are they north south traffic? Are they internet traffic? Like, what do they look like?
Right? It's, it's fundament. That pattern has fundamentally changed.
And so we need to start rethinking how we think about network security in the context of, in the context of workloads. And it's only gonna get crazier, uh, crazier with ai. Mm-hmm.
So, um, yeah, it start starts with just, you know, people didn't understand what their workloads and their applications are doing on premises. They look fundamentally different in the cloud, their behavior characteristics, the mechanisms that you use to enforce them. And that's really what we're trying to solve here at Aviatrix with our cloud native security fabric is, is rethinking the way that network security and zero trust looks for these modern cloud workloads.
To your point, I think we don't really even know what normal looks like. So how do we identify what the issues are gonna be if we can't understand what's an anomaly? Because everything kind of looks somewhat new and different to us.
So how do we start this movement or shift? Yeah, it's a great question. Uh, I think the biggest thing that I recommend for organizations is starting with understanding where the internet is.
Like what is that trust boundary look like? Because those are the places that are gonna drive the, the strongest indicators of compromise in an organization. And one of the things that happened with cloud, and going back to that complete shift in the way that traffic patterns look inside of the cloud, is that, uh, many, many, many more of your workloads and services have dependencies on the internet.
And in many cases, organizations aren't controlling that path. So, uh, as an example, if you look at the default security posture, when you deploy a workload inside of AWS, it's completely opened outbound to the internet. If you look at, uh, you still have to make some configuration to allow to access the internet, but it's completely open by default.
Same thing with Azure, although they're shutting that down at the end of September and changing the way that they do default up on internet access. Up until this point, you deploy a vm, immediate access to the internet. Why?
Because you have these interdependencies and they want you to use past services, and they were really selling to developers. But that is one of the, the key things that you see exploited by cyber criminals as well. Um, there's some amazing research, like I love my peers in this space.
Palo Alto obviously has an incredible threat research organization. There was an article that I read from unit 42 a while back talking about, you know, one of the most common techniques for data exfiltration in the cloud is that the attackers will actually spin up a VM and then they'll just start shipping the traffic out, because most customers have no control over that, that egress perimeter. So it's, uh, it that, that ends up being, you know, it's, a lot of people think about, okay, well I need segmentation.
Yes, you do. I might need micro-segmentation. Yes, you probably do.
But in the cloud, we oftentimes have a bigger problem, which is we don't have control over the basic trust boundaries like the internet. And if we can add those controls, they're much higher, stronger, they're much stronger, uh, high fidelity signals of when you might be compromised, and also a much more important position for control. So it actually gives us a pretty easy place to start.
We talk a lot about egress security with our cloud native security fabric. The reason that's the case is because it's so poor in so many organizations that we visit, and it's like first principle fundamentals understand what's going on to the internet. So, uh, it's different.
Cloud is different, and it's one of those, it's, uh, there's, there's a lot of opportunity for improvement. It also feels like whether we like it or not, the reality of the threat is that people aren't breaking in anymore. They're simply logging in, they're stealing the credentials, and we have no way of understanding what they're up to because they may look normal for months before they do something that they shouldn't be doing.
A hundred percent. And this actually, so it's an interesting question, right? Because the, um, I have this philosophy, and I've, I've said this in a number of interviews before, but I have this philosophy that there really are only three pillars of what I call runtime security.
And those are things that can actively stop an attack. It's not just about detecting it. You can detect it in many cases, you're already too late, right?
It's about how do you actively stop breaches? And there's a long time philosophy in cybersecurity around defense and depth, and I generally see that defense in depth falls across these three pillars. So the first one is identity, right?
It is, can you log in or not? And what do you have access to once you log in, like aaa, RAC, all of that stuff. Identity pillar number one, definitely compromisable, actually all three of them are compromisable.
That's why you need to events in depth. And the problem with the cloud is in many cases, that's your only layer of defense. Your management network is on the internet.
You don't have good network security. You can't deploy the other, you know, endpoints everywhere. Other two pillars.
Other two pillars are endpoint security, right? Which in the cloud, you can't deploy it everywhere. You can't deploy endpoint security on a server serverless function easily, as an example.
Um, and you definitely can't deploy it on your databases, which are as a service in many cases. And then the third pillar is network security. And if you lose effective visibility and control in the network, and you lose effective visibility and control in the endpoints, then the only layer you have is identity.
And any of those layers can be compromised at any point in time. So I, I would argue that it's really less of a problem on how do I discover anomalous behavior? Because anomalies in many cases are too late.
It's actually more how do I build defense in depth from a runtime perspective. And I think the challenge of understanding what's good and bad in the cloud oftentimes has to do with you only have one perspective. You only have the perspective on the logins, on the authentications, on the behaviors of the users.
You don't have an understanding of how they're moving laterally within the network. Don't have an understanding in many cases of what they're doing on the endpoint that you don't necessarily own. And so combining those three things together really allows us to get a much better signal on what intent is, what's normal, what's abnormal.
And that's, you know, that's, that's really the key is we, we actually see that customers are lacking the defense in depth. And it's one of the fundamental things that's challenging to determine intent and ultimately stop attackers who look like they're good because they stole a valid set of credentials. Despite all our conversations about defense in depth, are we still overly focused on the perimeter?
I almost feel like, um, we haven't moved all that far. And, you know, we check everybody coming in through the gate, but we have no idea what they're doing once they're in town. Uh, I think it's a great question, and I would argue that, um, we shouldn't even be thinking about the perimeter anymore, right?
It's, uh, you know, again, going back to the, the concept of the traffic patterns have changed. What is east west traffic? If I'm calling a database that I don't own, that somebody else owns?
Is that east west? Is that the perimeter, right? We see a lot of people using techniques in the cloud, like private endpoints.
Um, you know, the, the concept of, Hey, I'm gonna, I'm gonna ride on the AWS backbone to get to this third party service. Well, to me, that's a backdoor outta the network. Like if, like, that's the perimeter, right?
Like if the perimeter looks fundamentally different. So we need to think about, I actually think there's a blurring of, uh, of what, what that kind of traditional East west traffic and, and what, uh, perimeter traffic looks like. And we really need to be thinking about it holistically in terms of how do I protect the workloads that I own as they're communicating with other workloads that I own, and as they're communicating with workloads that I don't own.
And so, um, looking for solutions, you know, I think it's, it's, it's always important to sequence. So where are your higher, highest risk points? The perimeter is still a highest risk point.
Mm-hmm. If organizations had full control over the perimeter, then we wouldn't be talking about it anymore, but they don't. And so you definitely wanna start there.
But then lateral movement, obviously it's a critical part of the kill chain and part of the Mitre attack matrix, and that's, that's that east west movement, we need to do that as well. And if you, if you can, you can achieve those obviously sequencing from most important, um, you know, uh, those kind of critical control points. And then, and then getting more granular and more effective internally in your environment, we can make a huge impact on the cybersecurity posture of organizations.
You mentioned this in passing, but I'd like to get into it a little bit more. But we have soon all these AI agents, so let's imagine for a minute that we have, uh, for every one person there's 15 AI agents, each of them is gonna have an identity and some authorization to go do something. But do I have this right?
If they get compromised, it's not like I'm just having data stolen. It's like an entire process will be hijacked. Yeah.
So is this level of risk gonna be a lot higher? Yeah, it definitely is, right? Like if you think about the most common insertion point for attackers in an environment, you know, it's, it's kind of a, goes back and forth on whether it's vulnerability exploits or whether it is social engineering, right?
Most of the high profile attacks you hear from, like scattered spider recently, they, they start with social engineering. AI agents can be socially engineered, right? That's what prompt injection is.
And so if we think about it, your workloads, which used to be highly predictable and highly deterministic, are now vulnerable to the same vulnerability that humans are in some respects, right? With social engineering. So yes, it's a challenge.
And actually I think it makes it even more important to be very, to have a very good understanding and the ability to control what data agents have access to. Because just talking back and forth between, you know, a, a a, a customer and a client service little portal and, you know, answering questions like no big deal, right? Um, but as soon as that agent, the AI agent has access to a database or has access to even scrape things from the internet, because you could use that to send things out to the internet or has access, some of the exfiltration that we've seen with AI agents are posting code to GitHub repositories because you gave that agent access to GitHub, like that relationship, the access that the agents have to other portions of your environment.
It's the same challenge that we have with humans, right? It's when I get your credentials, what can you do? Because I socially engineered you.
Now we can social engineer agents, so we need to take it a lot more seriously because of the non-deterministic nature of the agents. So what's your best advice to folks about how to get their organization to think through all this? 'cause I think sometimes we're so busy fighting the fire that we can't think about fire prevention.
Yes. So the, I think this is an amazing question, uh, and I love your analogy around fire pre prevention, right? Mm-hmm.
Because, uh, my best advice for organizations is go back to first principles, right? We talked about AI agents, you could go buy a suite of AI security tools out there, but it's like playing whack-a-mole. Like the first principles of cybersecurity have not changed in 25 years.
There are three runtime security controls, identity network endpoint, right? And if you think about even the techniques that organizations are using to defend against agent threats, they're almost all using network, actually. They're using proxies, they're inspecting traffic, they're preventing access to systems, they're using identity as well.
Um, they're using components of those core, core, core elements. And so we obviously need to be able to enable our organizations to leverage ai. I think it's completely transformational, but you will constantly be playing whack-a-mole if you don't go look at the first principles.
And that is exactly the same as fire prevention. That's why you do proactive burns, right? It is because you don't want to be fighting fires every fire season.
And so, um, and so again, you'll never get out of playing whack-a-mole, you'll never get out of fighting fires if at some point you don't go back and focus on first principles. It's not just about taking your vitamins, it is about thinking through like, how, how do you, how do you prevent the illness? Like, it, it is, it is that, again, first principle controls.
Mm-hmm. To that point, and we talked about AI agents being a, a cause of an issue, but is there hope for the networking and the security people with the rise of AI agents that might help them bring some of the order to the chaos and adhere to those first principles 1000%? Right.
So we are, you know, we look at AI security in two ways. Uh, from a network security perspective. We look at it as how do you secure ai, so security for ai, or how do you use AI for security?
And I do think there is an immense opportunity to actually fundamentally rethink how people implement zero trust with AI agents. And I will just say stay tuned on that one. 'cause we're gonna do some cool stuff in the next couple months.
All right, folks. Well, you heard it here. One way to think about it is the more chaotic things become, the more important it is to hold onto your principles.
Hey Chris, thanks for being on the show. Yep. Thank you, Mike.
All right. And back to you guys in the studio.