Continuous Secrets Management – Itzik Alvas, Entro Security
Itzik Alvas, CEO and co-founder of Entro Security, discusses secrets management challenges across many technology and communications platforms, including code repositories, cloud services, storage, vaults, collaboration tools like Slack and more. Rather than a point-in-time discovery approach, Itzik explores the merits of continuous discovery, classification and enrichment, anomaly detection and response, and compliance reporting.
Transcript
This is techstrong tv. Oh, the great pleasure being joined by Sic sic avi. He's CEO e o and co-founder with Intro.
Welcome. Thank you Mitch. Thank you for having me.
Fantastic. Having here. Um, I'd love to hear, I'm gonna dig right into it cuz this is a very topical thing here.
Uh, but first tell us a little bit about yourself and tell us a little bit about Intro. Right. So yeah, again, it's Alva, uh, the co-founder and c e o of security.
Uh, I spent the last two years building security and today, uh, we are the first and only end-to-end holistic secret security solution. And we are helping, uh, CISOs and security teams to claim control over their, uh, secret keys. Uh, we are helping organization at the point their hundreds or thousands of secret, uh, they need to protect.
And we are helping them getting full, uh, secret inventory, classifying and enriching its secret, and basically to understand what are the risks that are associated with each secret and monitoring them for any abnormal behavior. Um, so I actually started my career as a software engineer at one of the intelligence units of the idf, the Israeli Defense Force. Mm-hmm.
Uh, I worked on several positions since then. I was a c o for a while. Uh, and before was security.
I was in charge for the eternal, uh, security and DevOps, uh, of Microsoft Defender Raju. Perfect. So you, you get the security and software, software creation and inflow and, you know, it's that, uh, it's not just getting to the directory and getting access there.
Right. Secrets are everywhere. Yeah.
As I'm sure every CISO knows and is, is concerned, maybe afraid of, but, you know, sometimes you don't know how widespread the problem is. But before we, before we kinda get into all that, today's secrets are just passwords, right. You know, account information, there's a whole variety of types of secrets.
Why, let's check a little bit about what is sort of the scope of what we mean by secrets. Alright. So to Flame Secret, every application that is being developed within any organization, uh, nowadays need to use cloud services.
They can be databases or storage accounts and et cetera. And in order for those applications to access or authenticate against the cloud service, they need the key. Uh, those keys are secrets and they come in many different types and forms.
They can be API keys, connection strings, um, cloud access tokens and, and et cetera. So programmatic, essentially programmatic access keys. Yep.
Any kind of key secret token. Um, do you consider digital certificate, um, part of the secrets as well then? Yeah, Yeah, definitely.
Okay. And, and those things, you know, it's not like issue it for 30 years, it's, or, or three years. They can be minutes, hours, you know, issuing kinds of things in terms of how fast we rotate secrets and certificates and things like that.
So in this dynamic world that you're talking about a software, right? And it's not just we're good for nine months till it renews and maybe it's a month, maybe it's a week, gimme a much shorter intervals. Yeah.
Maybe they're not being rotated at all. Right. And even it's a requirement of SOC two and, and a lot of other regulation and compliance.
Most of the tickets are not being, uh, unfortunately are not being rotated at all. And someday, if it's not a breach path, somebody's gonna ask Right. For your attestation, some evidence of are you following these processes?
Right. Well, let, let's, let's jump in then to, um, so talk about, given your background, um, both in security, ciso, software engineer developing software, leading software, now starting a company, how do you, how do you think about secret manage management or secrets across that entire sort of scope? Because it's a pretty wide ranging scope.
Yeah, so I've seen, uh, our secrets are the building blocks of each application, right? Because every application needs those in order to access cloud services. Mm-hmm.
Uh, and then secrets are being created by the teams that are not responsible of securing them. Secrets are being created by the different r d teams. They that are being created by developers and devs and service, uh, and et cetera.
And they're being created without any, uh, proper oversight by the security teams. Uh, and basically those teams are scattering secrets everywhere. So you can use a vault and vaults are basically secret storages or, or databases in which you can store your secrets set.
But then you probably need a vault pair region or a vault, uh, pair environment and et cetera. And then if you're using Kubernetes, you probably have Kubernetes Secrets. And if you're using GitHub, you are emerging GitHub Secrets or Jenkins Jenkins Secrets.
So you have a lot of vaults out there actually. Uh, for small size organization, there's a lit, at least five different balls. And then secrets are being sent over Slack messages or saved within our manuals that Confluence and et cetera.
So secrets are, are scattered everywhere. And even if you find a secret, and I guess you, you've seen your first share of secrets, there are basically long strings. You can't make anything out of them.
You, you have no information about them. So even if you find a secret, if security professional find one, he have, he has no idea who created the secret why, what cloud service it can access. Um, so those are the main challenges that security teams are struggling very ly to know.
How many security kids do I have? Where are they? Who's interacting with them and how to protect them.
Well talk a little bit about that discovery process then, because, you know, even, even if you're doing good coding practices and you know, you create a little config up UI file or whatever language you're in, and here's where all my variables go, and maybe I've put some secrets in there that I shouldn't or connection to my vault, but it isn't just cuz you find it doesn't mean you know, where it's easily know where it's being used too. It's a challenge just kind of connecting all those dots, Right? Right.
Again, stickers are, are long strings. You have no idea who's using them. Um, so at enter we are, we're calling it pulling in, putting in air tag on stickers because those stickers are being copied and duplicated and, and scattered around.
Uh, so yeah, you have no idea who's using them and if someone, uh, copied your secret and publicly exposed it, um, you have no idea. And, and it's also a challenge that that is the main reason why our organization are struggling to rotate or place a secret even, even if they need to as part of compliance because they don't know which application is using it. And then if they replace the access key, the secret key that the application is using to access the database, the application will fail.
Uh, so they need force to map, uh, which application are using work secret in order to rotate it. Well, and, and I know that, um, intro you have a process, right? You know, most security starts out with discovery or some form of like, how big is our problem?
What are we trying to secure? Where is it, et cetera. But then what you're talking about is sort of a classification, um, knowing who the owners of these, of these assets are, um, you know, where it's being used and going through that kind of classification process.
Correct? Correct. Yeah.
So context is, is the king, right? Mm-hmm. Um, and then what we are doing in it, or we are able to integrate to all places in which secrets can be stored or, or exposed, uh, by the different entities that are creating those secrets or by anyone who's interacting with those secrets.
Uh, and then we are able to give you as a cso, uh, a list or a secret inventory of how many secrets do I have, where are they? And then we are classifying and enriching its secret. Uh, we have a unique algorithm that is able to do it without even seeing the secret.
We're not asking for, uh, permission to see the secret and we are able to classify and enrich it and, uh, visualize the map around it. Which application is using word secret in order to access workload service and other vital data around that secrets such as when it was created by whom? What privileges does it get within the cloud service and when it was less rotated, what are the risks that are associated with it?
And of course how to protect those secrets. What are what are the, some of the sources you're looking at then? So you're looking in, in, um, you know, code repositories, what, what are other kind of vaults or what are all the assets you're kind of investigating to discover all those secrets?
Alright, so of course cloud service, uh, cloud services cause secrets are within your C two virtual machines within your lamb environment, variables within your parameter store or, or storage accounts and et cetera. So cloud services and then code repositories because they're always being committed into code for some reason. Mm-hmm.
Committed into code, uh, c, cd, uh, we are searching, actively searching for secret, the c cd of course the different, uh, votes and, uh, secret soldiers as mentioned earlier, Wikipedia such as conference, uh, teams, um, slack and, and basically every collaboration channel and service or solution that secrets can be stored or exposed within. Uh, and then, sorry, Go ahead. Yeah, so what we are doing, we are integrating into all of those places, uh, and then we are also integrating into the cloud service itself where the secret was originated in.
Uh, and we are looking at both of those logs and we are able to map, uh, the secret lineage, uh, and basically understand when the secret was used, why it was used, who used it. Um, and maybe that secret is, is disabled, right? Maybe we found 500 secrets within your code requisite, right?
But then so hundred of those are disabled at the cloud service level or deleted at the cloud service and they can't access it. So okay, they're in your code repository, but who cares, right? And maybe that secret, you've got a secret over there, which is publicly exposed and can access your most sensitive database, uh, and you should probably do something with it.
Mm-hmm. And some of those aged or no longer relevant things are also go back and check cuz they may get updated and now you do have a, you know, access to a current secret or so this is something you have to do an ongoing basis. Correct.
It isn't sort of a one-time discovery. You've gotta see the activity that's happening, whether it's Slack or the code repository or C I C D, it's a continuous process for keeping up on these, correct? Correct.
Yeah. So we are discovering all secrets give you a secret inventory, then we are classifying and enriching IEC or visualizing a map around them. And then we are continuously monitoring those secrets for any abnormal behavioral.
So we have a machine learning algorithm that tracks the secret usage, and from there we're able to raise an alert about any, uh, threat to your secret. So if your secrets are being used from China and you don't have business over there, we will let you know. If you, if you have an application that fetched two secrets and now they're catching 10 or all of your vault, uh, we will let you know and et cetera.
So we are taking the secret usage and letting you know about any anomaly, abnormal behavior, misuse or abuse. Yeah, I think that's key. It's, yes, it's where it is, but it's the activity of how it's being used, who's using it, where that usage is coming from are the, where, when, when are they abnormal behaviors and then of course remediating those situations, um, when they do a RISE team and that's, you know, security team wants to know that dev team wants to know about that, right?
In certain cases, maybe it's something inside our C I C D pipeline and we're creating exposed secrets, so let's fix that and we solve a, you know, world of problems that way too. Um, is this, so is this a cloud-based service and then you connect into those different sources and monitor it? Is that how your offering works?
Yeah, so mostly, uh, we are, we are a cloud first, uh, solution. So, uh, most of our integration are cloud based, but then again, we are supporting, um, ASCO Vault on-prem and, and other, uh, on-prem solutions as well. Um, yeah, because again, it's, uh, secrets are a major problem nowadays.
Uh, if you've seen the latest reports of ibm, the Verizon, um, secrets target attack Saudi and the number one mostly tractive or costly effect to an organization. Um, and we've, we've seen many, right? We've seen, uh, slick Toyota, um, we, we, we've seen in the past three months, uh, at least 10, uh, different bridges.
So Yeah, you can self-serving statement, but you can go to Security Boulevard and at least a couple times a week see some major Yeah. Things happen last pass. Um, Okta, Samsung.
Yeah, exactly. Well, and and also, um, even if you don't have a fully, fully locked down, I would imagine intros got also help you in those cases of a breach, right? Oh, okay, we had something happen.
Let's find out where this might be located at. Do we have some way of seeing how it's been used? Is, is there things we didn't know were anomalies we now know because it, it did get breached.
So that also can be a good investigative resource, I would think. Oh, definitely. Uh, once you, sorry, once you will lose a ticket, once an an owns one of those secret, it's, it's it's game over, right?
It will just use the secret in order to create more secrets, more permission. We'll keep bridging that environment in endless waves. Uh, and we will let you know what the techer has been doing within your network, uh, if he created more cigarettes.
If so, where are they? What they can do. Um, and, and also we do offer, uh, automatic, uh, remediation steps as well.
Mm-hmm. Very good. Talk, talk a little bit.
One of the, one of the things that can be challenging about security technologies is, uh, there can be some, you know, setup involved some work to get to the point where you can start to get, see some value, see what's happening. Um, talk a little bit about how customers would implement, uh, your technology when they're gonna start to see some of the discovery or the results of the anomalies or more. Right.
So the onboarding is very, very fast and easy. Uh, it's will take us about 10 minutes to onboard, uh, an environment and the result, so the system will scan, uh, the environment and it, I mean, depends on how, how large, uh, the customer environment is and how complex, but within couple of hours you will get a full report and understand how, where are they, who's interacting with them, what are the risks that are associated with them and, and how to protect them. And also we have a lot of other, uh, pillars as well, such as vaults, misconfiguration.
So maybe your vault is publicly, uh, open to the, to the internet. Um, maybe, uh, least privileged it is another one. So let's say you have a secret, you have an application which is using a secret to access a storage account.
And that application is only doing read operations against that storage account. But the secret have admin or right permission, uh, you can ensure to reduce the permission of that secret. And it's also a great mitigation step.
So let's say that that secret is also exposed within your, uh, code repository. Mm-hmm. And, and challenge to remove it from there.
Okay. At least in the meantime, reduce the privileges of that secret to the needed privileges. Uh, we are searching for secrets in the dark web and, and et cetera.
We have, we we're an holistic solution around secret security and we're the only ones who's doing that. Um, yeah, Very nice. Well, I think that'll also give, um, you know, potential customers, customers some insight on where to go start working on some of the issues first, right?
You may have a wide, wide variety of places where secrets are located and being used, but maybe it's the unknown ones or like we weren't aware on e c two or wherever it might be. Uh, let's go figure that out first, make sure we know what's going on. Uh, right.
And we also, so we prioritize our, our risks according to how easy it is to resolve it. So A quick use case, right? You had the, your, the system and that system was deprecated, so it's not in use anymore.
No one deletes their secret, right? So you have enabled active secrets that can access your infrastructure and it's allowing fruit. You can delete all of those.
Uh, it'll take you five minutes, uh, and you are reducing your attack surface and, and the blessed reduce, uh, of those secrets. I mean, so there, there's a lot of lowing fruits that, uh, security teams need to be aware of and, and reduce drastically the, the tech surface is around our secrets. Mm-hmm.
Very good. Uh, so where can folks go to find out more about intro? Uh, you center up for a demo, check things out, Right?
Um, just Google intro security or um, https, intro security. We do offer a free assessment. Um, so within 20 minutes you will get, uh, full report of how many you have, where are they and what you can do in order to protect them and basically reclaim control over your secret kids.
Wow. Okay. Sounds like a very helpful, helpful, quick 20 minutes I think.
Well, thank you so much. It's great talking with you Sik and uh, love to have you come back and share some more with us as things continue to progress. And congratulations on your success so far.
We look forward to talking with you more. Thanks Li, thanks for having me. You bet.
Intro security, be sure and check it E N T R O and we'll talk again. Take care.