Cloud-Native and Data Security – Ravi Ithal, Normalyze
Normalyze CTO and co-founder Ravi Ithal shares data security challenges in the cloud and how cloud-native containers, microservices and cloud use cases are causal factors to the widespread increase and proliferation of data.
Transcript
This is texturung TV. But the great pleasure be joined by Robbie ital Robbie is CTO and co-founder with normal ice Volcan Rodger good to be talking with you. Good to be here Mitch.
You were talking about a number of my favorite subjects will get to that in just a moment. But once you introduce yourself, that's a little bit about you and also about normalize. Yeah, so, my name is Ravi.
I thought co-founder and CTO at normalize. I've been an engineer pretty much my dad career all the way starting in the early 2000s have seen multiple evolutions of you know move to the cloud. I assess and so on also was a co-founder at netscope, which is a handing a lot of data security and SAS and prior to that.
I was a founding engineer at Paul Walter networks, which is a great household name for a network appliances in the the on-preboard very much so very much. So so tell us a little bit about normalizing what normalize does At normalized we are trying to solve the problem of explosion of data and all the problems that it's it's causing. There are a bunch of trends that are happening in the way applications are being built a few years ago.
It used to be all monolids with one single data store. Now the same application is being built with 10 different micro services that 10 different data stores that cause an explosion in data stores amount of data is exploring. The number of changes to data is exploding and along with that comes feature velocity, which is good but also potential for data security issues, which has been real hard for Security Professionals normalizes trying to help bridge that Gap that we have seen in the market by producing a product that helps Security Professionals get an understanding of all the data stores classify the data and it's understand risks around the data.
Excellent. Yeah, it's the changes in the architecture the way we create applications also in just the location of data right from our proliferating from to the edge and all the way out to iot devices or serverless or one Cloud multiple clouds plus what we have on imprem. So it seems like we're excluding vertically and horizontally absolutely so it and it all like it makes sense.
If you go back to the history of like how things evolved even like if you go back like just 10 15 years ago applications for developed and built and deployed on Prime with data stores our service that had to be manually provision. So there is only so much speed at which data stores and data could get created then came the cloud which gave the elasticity so devops like, you know developers could could go and provision these data stores and servers in the cloud, but they were still kind of following the same method as how you would do. How It Go but how you would go about in an on-prem world, right so you go to the console create something hit create and wait for it to like, you know image itself then it's ready and it off to the developer developer deploy something it's still like, you know, it's the server side in the cloud but still the process is still on premi right then then something magical happened with the cloud native World which is you know, which is obviously there were a few things like Docker that were the the early pionees of like how do you package applications and you know make them deploy easily then came the container orchestration systems like ECS and so on which ended up really enabling developers to move fast So that that created this culture of building applications using microservices which enables teams to go as fast as they can and when they're going as fast as they can they want to create and maintain their own data stores.
So they keep their own data stores. Every microservice has its own data stores and microservices talk to you so they're using apis, right? So now suddenly security like there are two pieces of information that security has to handle.
What is the data that you're keeping wait, you know, is that sensitive is that really something that needs to be protected which used to be in one place, but now it's in ten places, right? So that is the the one explosion that cannot be dealt with manually. The second one is obviously like, you know, what are you sharing who has access to it and based on who has access to it?
What are the risks associated with those and so on right? So these these two like, you know somehow You know, but we see this all the time when it moves fast security kind of falls behind security has to catch up and that is the gap that is that that is creating the need for this product that we're that we're building at this point. Going from exponential to factorial it it's increased.
You know, it's everything gets smaller there becomes a lot more of them. Right? So one big monolith application now we have and Son maybe hundreds maybe thousands of microservices in you know, good microservices design is autonomy, right Independence and autonomy.
So it's not dependent upon running and other other than through, you know API calls and things like that. And of course we can replicate those across so it may be multiple instances of it. Thank you.
Another Trend that is coming in is, you know, especially something that picked up in the last five six years is infrastructure as code and so by building your entire deployment environments as code and there are obviously multiple Advantage you can replicate them. You can create a brand new environment you throw away the old one creating new one and so on for testing or pen testing or quality testing what not at Time it's also very easy, like since provisioning a server. You don't need to lift and shift the server and rack it up somewhere.
It's just copy paste a code line of code. And then you have another server, right? So that is creating a lot of explosion as well not always that's not always bad replicating and duplicating data and so on but it's since it's so easy people are finding applications that can benefit our use cases that can benefit from such ease of use which is creating a headache for data Security Professionals.
Fantastic, you know, I've mentioned a few folks when I was at kukan in Detroit North America. And what their two trains that I picked up on that sort of bubble up to the surface even more than they've been talked about before one was developer productivity driven largely by the economy. The other was data and data management data security data, it's Liberation.
I remember the days of you know to get to the data yet go to the DBA and through the access controls and whoever the data owner was in the business all those kind of single points right into your to your what you're describing now about the cloud native world is that's open wide up really and and I'm not sure who the data owners anymore, but certainly there's a proliferation of data everywhere. That's right. That's right.
I don't know if you hired about how you know, I mean, I don't want to say cloud native is the root of all evil but like, you know, it's it's enabling speeds to such an extent that we see the repercussions in many cases and especially security and think about like, you know, go back a few years. If you want to scale out one of your applications, you had to stand up a server, of course, like, you know, the provisioning aspect is still there, but somehow everything is manual. So it almost feels like I'm kind of getting nostalgic like if you go back to that era like you really know like, you know, you can actually the security guy can go and watch over and devops guy and then make sure he does the does a good job and then security job is done right?
Of course, it was never that way. There's always like, you know some other surface that you the leave open, but today what's happening is like, you know, the cloud native technologies have enabled such huge scale at such ease that any problem whatever surface was left open is being exponential like in a magnified, right? So let's say you had a small configuration mistake and one of your servers that would show in your detection systems would point that out and then we'll show up and then the security person had probably a whole day.
To go and fix it and then go home knowing that like that thing is patched. But today what's happening is those things are getting out of scale and average workload in the cloud is, you know, it runs in order of minutes not our Sur days, but in order of minutes, so things can come up go down. and then you want to scale you won't have like, you know if each Container has one issue and you scale it out 100 containers in front of a load balancer you have 100 issues now to fix right?
So any detection mechanism automatically is also detecting, you know, in order to order some attitude higher number of issues. So the moment let's say something like a log4j. Well, everybody comes out.
You don't have one or two machines you want to fix you have a thousand machines you want to fix right or if you have like, you know, an infusitious code rule that gives access to a certain role instead of that access being, you know, let's say it's an excessive permission instead of that being excessive permission in the case of a single server. Now, you have scaled it out to a thousand containers. So you have a thousand Access Control issues, right?
So so what is so in effect what's happening is cloud native is scaling the positives as well as the negatives is not that big but still. Cleaned out right and then what happens to the security folks they have to go look at all these. issues out of these thousand issues of access in Thousand issues of unity What should I prioritize that's where data really comes in the picture because ultimately the security any companies in full set team is protecting the company's data more than anything else, right?
So when you put data at the center of your security strategy, how do you prioritize the rest of your work in order to you know serve that objective? That's where dsps also coming to picture that that's how we are trying to build our product as well put data at the center of your security strategy and then derive all your subsequent decisions about what the prioritize what to fix and so on with respect to what's at stake in terms of data, right? So if you use Normalized product.
For example, you will see a list of all your data stores monetary value. So like let's say you have like a thousand issues 10 of them correspond to data store that is worth a million dollars another 900 correspond to another data store that is worth $10,000. You clearly have your priority, right?
So that's the that's the Target that we're going after and that I think is also something that we are seeing more and more people adopting as early adopters because it gives in the priority and consolidation and going to New Year in the new economy. And I think that's gonna help a lot both on the economic side as well as you know efficiency side. Well, as you were getting nostalgic there at the beginning I started thinking about I thought maybe you're gonna grab a US keyboard and I would get my console switcher together.
We could go work on some servers. But anyway as long, you know, you know, I'm curious your thoughts on this because Um, you know, in addition to kind of seeing data bubble back up to the surface as a Hot Topic people are talking about application security also kind of gone that way at least for security teams. Now, it's not just protocols and boundaries and protecting things in access controls.
It's getting into the more the insides of what's happening within applications. What's happening within data where it's stored as well. So since seeing these two things seem to be moving what maybe not necessarily the same speed but in parallel with security teams getting more into software architecture and API security and things like that and understanding more broadly data security crossed all the locations and uses that may have That's absolutely right.
So in fact like, you know on a weekly basis at least two or three calls, we get asked, you know, I want I have some understanding of my data but I cannot connect it to my application like who is using it. Right? And why why you know why this application needs this piece of data one classic example without bringing names I'll give you is There was a like, you know, very well-known company.
They were using they were collecting phone numbers of users and keeping it in a data store. That's a microservice by itself. And that phone number was used only to send one-time passwords and the reset your password use it as a second factor and so on right so that was great.
Like, you know, everything is fine. Now the security team or the compliance team that's not really understand if they don't understand what this information is being collected for they cannot prevent abuse of that data, right and it did happen that company they started using those phone numbers to Target ads shown on that platform and imagine like, you know, somebody finds out about it like how much and how much fine like it ran in the hundreds of millions of dollars by a European agency. So finally they fixed it but you know the root of the question is this right?
Yeah. They were in the crosshairs of like, you know many Reg. Three bodies so somehow somebody found out think about how many other places this is happening and only waiting to blow up and you become famous, right?
You know many people can pass it off as a good prompt to have from a business side, but truly to do a good security job. He need to build it when you're young when the company's Young and the product is Young even like, you know, even if you are like, you know, a few tens of millions of dollars you need to like. Reconfigure all your applications and security deposition and so on so that regulatory mistakes like this will not cause a huge burden to you several years in the future, right?
So that's that's part of security governance risk and compliance and people are recognizing that like, you know, many many of our customers are actually getting to that as well. So top short of all of that is Data is important understanding applications important but also which data is being used by what application inside your environment is also becoming very very important. Is your people struggle with do we have time for that we have time to do security you have time to build that in and the analog I always use is.
You don't have airbags to a vehicle after it rolls off. The assembly line. It's designed into the product.
It has to safety is designed into the product very much. Like, you know security data protection data security also is your so let's talk a little bit about people that are maybe starting on their Journey around Cloud native and beginning to do some of the first applications is in Cloud native architectures. How would you recommend people how do you build in data security into your process and into your design with your teams doing Cloud native?
Yeah, so that's a very problem very close to our heart and we've been doing that as well. So what you want to do is very similar to like, you know, think about how you would set up your testing and how you would set up your ci/cd pipelines how you would set up your automated vulnerability test and so on you want data security related activities all to be automated you don't want it to be manual. You don't want it to be a quarterly event where a bunch of engineers get together produce a report and move on and in between like, you know, a lot of things happen, right?
So so what you want is basically automate number one discovery of all your data stores and not only in production you want to be doing that everywhere including your potentially score in your testing environment staging environments pretty much connect your Cloud organization into a tool that automatically discovers and let it run. Second step is to classify the data you want to know what type of data is where and have a very high confidence about like, you know, what what exactly it is. So you don't want false positives.
You don't want you don't want to be looking at the same thing again, if you have duplicate copies of data, you should be able to connect. data stories a copy of data store B and so on third sticking out who has access this involves looking at your network relationships in the cloud DB roles. I am roles which eventually like give you a list of permissions are access permissions access permissions that any resource in your environment as to any piece of data that you have classified.
The last step is to figure out all the risks associated with all your resources and then cross reference this by connecting the dots from the most sensitive data that you care about maybe based on laundry value to how it's actually getting accessed and what are the risks around it? So having an automated solution that connects to your Cloud accounts all your Cloud accounts and then produces these reports and Bubbles at the most valuable things that you should do today is is what I would recommend right and we ended up using our own product on our own environment as well. And you know, but we you know, we cannot imagine living without it.
He certainly can't. Increase velocity and operate at scale without automation. It's got to be built into the process.
That's right easier to do that upfront. It's been great talking with you Robbie. I hope you'll come back and talk with us some more as we can get into 2023 and continue on our Cloud native Journeys and Deal with all the challenges we often create new things, but then we learn how to protect them later right with no different way of cloud native as it's probably been with most other Technologies working folks engage with normal eyes and get that get a chance to maybe kick the tires or check out what you have to offer.
Yeah, so you can go to our website learn about us. i. There are a few forms.
You can contact us there's a chatbot and that you know, it'll you can actually set up a Time to talk to one of us we can give you a demo of the product and so on so that would be the ideal way to reach out to us. It's normal. Is that AI?
Is that correct? That's right. i.
Fantastic normalize. Why is why is he the answer normal? Why is he just spelling therefore so please check it out.
Appreciate you joining us Ravi and look forward to talking with you again here in the future. Thanks for having me image you bet. Take care.