Defending the Atomized Network – Martin Roesch, Netography
Martin discusses Netography’s latest paper, “A Reckoning: The Massive Implications of Losing Network Visibility & Control”. Martin will outline the exact struggles enterprises face when defending the Atomized Network and how they can change their approach to see the users, applications, data, and devices they have, what they are doing, and what’s happening to them.
Transcript
This is Textron TV. Hey everyone, welcome back to techstrung TV. I'm happy to welcome back my friend Marty resch of nitrography.
Yeah, I was really close to say it's sorts fire there, but I it's nitrography but he's also the guy behind swords fire too. Hey Marty welcome. I hope all is well.
Thanks. Sounds good to be here. Thanks for having me back.
Thanks. Thank you him Marty, you know look you need no introduction to our audience, but maybe netography does I don't know if everyone out here. Yeah knows knows netography.
So why don't we if you don't mind if we could spend a moment just kind of baselining that okay. So photography is a company that's taking a new approach to network security specifically Network visibility and control So speaking of sourcefire, you know back in the old days. We used to be on appliances.
We did Deepak and inspection we look for attacks and things like that and that obviously worked well for for a long time and it still works pretty well in a number of places, but the problem is that it's getting harder and harder to do it because in Cloud world and we'll kind of talk about the thinking around this a little more but in the the world that we're in now which is kind of what we call the atomized network multicloud hybrid cloud with on-prem infrastructure and mobile remote workforces. I have big problems if I want to understand what's going on in my network environments with Um figuring out where to put stuff and when to put it there and you know, this is this is a huge issue where you know getting capability where I need it when I need it and having it deal with the kind of pervasive encryption that's going on a network environment. So natography is a new approach where a pure SAS play.
We don't have any hardware software to install to make it work. We operate on netflow data or flow data coming out of cloud environments or IP fix or you know, all the different flow types, which are real-time data type that is generated by all of your deployed Network infrastructure plus all of your Cloud providers. So it exists everywhere most people don't mess with it, but it's a real-time data source, which allows us to do real-time analysis for visibility control of your network environment using essentially metadata about the environment.
So it's very powerful approach. It's much lighter in terms of what you need to do to get it and you know, it allows you to see basically what's going on across this entire atomized world. That's out there.
Excellent. So I have a confession when I first saw you were involved with netography. Of course.
I was very interested and said what's Marty up to now and you know, I ran into this atomized network thing, and I was like Marketing real what the heck does it mean? What what is it and and quite frankly in speaking with you on these interviews? I've got my head wrapped around it.
But I I'm gonna guess that for a lot of people in our audience, especially if they haven't seen the prior interviews and if you haven't they are available on Tech strong dot TV go check them out just search Marty's name and it'll pop but for people who aren't Marty and I know you've given this some thought now how to kind of boil it down and Bullet pointed out for people and and why they should care and why it's important and what it is. Would would you mind kind of educating us? Yeah, absolutely.
So I coined the atomized network term and I quit it after talking to you know, prospects and customers and things like that. So when I started at nitrography about a year and a half ago, you know, I thought we were gonna be going into kind of this post pandemic World which is you know, a lot more scattered than it wasn't things like that. But what I found out was that it was much more scattered and there'd been much less kind of oversight for how networks that expanded post-pandemic.
You know, everybody got sent home. They were told hey just get your job done, right? So, of course, they stand up Cloud infrastructure everywhere.
And as I you know talk to more and more people. I was like, there's you know, there's something new Under the Sun here these networks of animals and presence and compute their scattered all over the place and people are having a really hard time getting their hands around us. So I clean the term and I said, oh my nice Network and it's kind of a marketing term.
Obviously we mark it on it. But but it's also, you know, it's also a shorter way of saying multi-cloud hybrid cloud with on-prem infrastructure Plus mobile and remote Workforce, right that is heavily encrypted and you know all the other things. So, you know, I started saying that I saw a lot of heads going up and down nodding on Zoom calls.
Okay, cool. But you know as we kind of went down the road now, you know, you and me both been in security industry approximately forever. Right?
So, you know, when we think about stuff we say stuff there's a lot of kind of implicit things in the back of our heads from deck literally Decades of experience. So I kind of had that thing too going on which was like, well, you know at my network and obviously there's implications for all of your security infrastructure that you've deployed everybody. Oh sure Marty.
Yeah. Okay. And yeah.
I've been doing this. So I'm a lot of people won't call me at it's so but eventually I found out that hey, you know what people don't understand the implications so we actually have to figure this out and and talk about it intelligently, so I came up with you know, I turned I wrote myself basically a note that was like a ton of text and then turn it into a bunch of bullet points and then I turned it in four words to describe. What are the attributes of atomized networks.
And why are they important and I have even have an acronym for it. So it's so handy. Okay.
Here we go. It's deed so deed stands for distributed ephemeral Earth. Yeah.
I messed up my own action just first ephemeral encrypted and diverse so dispersed, obviously these atomizer dispersed or across multiple clouds or also on-prem infrastructure, you know one people out and started standing in public Cloud infrastructure during the pandemic. They didn't decommission all this on-prem infrastructure. That's what they actually did was they started building dependencies between all this stuff obviously have security implications, right?
So there's that they're also the ephemeral nature of atomized networks as we stand up in the cloud and we can spend workloads up and down. This is extremely problematic. The old way of doing things having appliances or even virtual appliances that you put in the cloud environment that require licensing and management integration and all these kind of pieces of the puzzle to make them work.
You have a substantial problem getting your capabilities to do visibility control of your network where you need it when you need it. So that's a big issue these networks also tend to be heavily encrypted between SAS and zero trust encryption is more and more the norm. So obviously that's a huge problem for deep packet inspection.
We saw this all the way back in the start days is you know, SSL was up and coming via e Commerce and then started getting used for more and more so that blinds Deepak inspection systems. And then the last the last letter here diverse is kind of interesting and this is something that occurred to me as a part of this kind of conversation with myself diverse environments. Are it plus Cloud, but they're also OT and when we talk about networks today that are multi-cloud plus it environments Plus.
The environments OT actually exists within a lot of our it environments in many places. So whether it's you know, the vending machines in the break room that are plugged into the network or the light bulbs now or you know some the corporate fish tank or whatever. All the stuff is on the Internet is cohabitating and a lot of times with your network environments or OT could be a factory floor or whatever.
Well we're seeing environments that are that have all these attributes and you know, the interesting thing about it is that you know, if I have Cloud environments a lot of people in the cloud they use the native tools. So, you know AWS cloud trail and sentineland Defender it Azure, you know gcp has its own set and So I use the native tools there. They use, you know on-prem infrastructure for on-prem defense.
So, you know Cisco or Palo Alto or Fortinet or whatever and then they have a and esoteric set of vendors that are available for the OT environments as well. So when something happens no, by the way, these all use different languages for talking about good and bad. They all have different Eventing.
They all have different reporting systems and they probably have different teams operating them as well. So when something happens And we try to do incident response. How do we you know figure out like the scope of the compromise that we suffered and all the other, you know, scoping container and remediating.
It's what we do Post compromise. So understand that you've been compromised as a scope container remediate, how do you even do that? When you've got all these tools across all these environments with all these teams and all these different languages to try to synthesize a picture together and if the answer is, oh we dump it in Splunk and run our report and yeah, maybe that's not as maybe that's not well, but that I mean look no knock on Splunk, but quite frankly that's where the security industry was or you know, I'd say from 10 to five years ago.
Well just you know Splunk go kind of bring all of this together for us, but hey, it's incredibly expensive be it. It's not all it's cracked up to be doing it that way. I think Marty nowhere does this come more into Focus than in your average Hospital right?
Think about what networks you got running in your hospital. They they have kind of your standard. T Network right there billing and there, you know what you normal office kind of stuff runs on their it network, but then you have a network for for medical stuff right medications and nurses and doctors notes and and all of these things and you have a network for these.
You know, the the intravenous pumps the heart monitors the cat scan machines the MRI machines and by the way, they're all hooked up into the cloud because they're storing all that stuff up there. God some of them are in public. Some of them are in private clouds, right?
Because you got hipper and whatnot. Then you have the network that the doctors use because they think they're guards and the rules don't apply to them. Right right.
So when something goes south in a hospital You know, I pity the poor fools who runs security there because where do they go? How do they How do they bring this all together? Yeah, it's it's a mess.
It really is. Well, it is a medicine and a lot of ways that's a great, you know, really crystallizes the problem and kind of one environment because he also have problems with you know, Hospital environments are very sensitive to a lot of security stuff. Especially that's putting packets into the environment that's doing things like Discovery scanning things.
Like hey, you just can't do it. No parts of the environment. So, you know, you need approaches that are that are practical for that.
But also they can Encompass the whole thing, you know, whether it's cloud on-prem or that they're OT Network which is you know, cat scan machines and Drug pumps and things like that hurt monitors. So, you know and so our opinion and and what we have architected for is basically operating in this in this world. So, you know from where you need it when you need it standpoint, we have nothing to deploy.
So obviously, you know, we got a a SAS service and you point your data sources us we start taking it and we also take in context now so we can if you have something like, you know accionists or you have crowdstrike or you know, an ipam system like info blacks we can take all that information in and start attaching it to labeling the traffic and the devices that we see an environment and then same thing with cloud vpcs and stuff like that. So once we have that you can start saying well, these are HIPAA devices they never they should never respond to inbound traffic from the internet you start monitoring for that Easter monitoring for how the cloud is being used when you see things kind of go off rails and when something does happen because the architecture is a system. It keeps the data around so retrospection and threat hunting or kind of like It already there.
So yeah, I'm talking my book. But but I believe this is the right approach. This is the reason that I unretired and came back to work because this is if you're gonna do network security it needs to be done.
This is the way to go about it. I did today's world. This is what we need.
Yep. Yeah for sure. So, you know and this is I was just on a call yesterday.
I was see so, you know big Co and we've been doing a POV in their environment. It was fascinating me. I really wanted I was really excited and interested to see the results because this is the first company that we've deployed in like we know what the product can do like right wants to detect everywhere and you know one platform for everybody to look at, you know, so on and so forth, but this is the first place we ever deployed into that had Cloud it and OT environments.
We were watching all of them simultaneously on one platform in one place and you know, we picked up some you know, some stuff that definitely was not great not great. But we also picked up a bunch of what we've been finding is that not only is it good for you know, there's bad guys here. In terms what they've been doing but also just for straight-up governance stuff.
Like hey, you know, why is this Factory floor browsing, you know social media and you know, why is this cloud service talking to this cluster is why is Dev talking to prod? You know, all those kinds of things we can see those things we've seen in real time. And the interesting thing is, you know, we've kind of figured out well, you know if you stack us up, Sometimes when we're talking about some of these governance things the people start saying well, we've already got cspm but it's like yes cspm is a report-based system.
We're a real-time based system. So usually think about it as CSP. I'm gonna say hey you're configured so devotalk to Pride go fix that and they fix it.
Then the next you know, push comes out of staging up to prod again and then I'll sudden they're talking again. We can see that as it happens. Nothing else really can so it's you know, it's it's a different philosophy and a different approach and I think it's complementary to stuff like a cspm.
It's like here's how you should be configured and how you are configured and you know, here's what's actually happening for two different things. So, yeah, it's been really kind of fascinating. I was really I was on this call yesterday obviously and I was really excited to like go through the report because it's like look you see this and your it.
We see this in your Cloud we see this in your own team. We see your OT and your it talking to each other where they shouldn't be, you know stuff like that. So so did the see so kind of say Look, I I had no idea right this is eye-opening.
This is you know, I yeah, he had some positive feedback for sure. Yeah. Cool, man, you know, so let's just bring this home for the audience.
So it's it's no good deed d e e d right good deeds. Marty I appreciate you going through this with us, but some people are visual where can they go get Deeds kind of spelled out for them. com.
We've got a white paper there that talks about, you know, kind of the this massive change that's taking place in the security World driven by Dean environments and how we have to kind of get to a new way of attacking the problem if we're going to continue to be useful in in the future. So yeah go check out our website. We've got this white paper.
We've got a bunch of we're doing a lot of blogging and stuff like that and talking about we're seeing what we're thinking how we see the world. So if you want to get plugged into it go check out the website check out our blog and read the white paper. So if you netography the atomized network deed decided it's in that order good check it out Marty fantastic stuff.
Listen as we come in on the end of the year. It's been a crazy year, you know 2022. I think we'll definitely go down.
It's a very unique year for so many so many reasons. Yeah. not all of them good I'm afraid but still a unique year.
What's going to catch you excited about next year? Well, I mean, you know besides the movies I'm anticipating things like that. I'm really interested to see it.
So obviously we're in the we're early stage. Right? So I'm interested to see how some of the initiatives that we've got in the pipeline right now are going to be in this are all kind of secret scroll things so I can't really talk about them right now.
No, it's okay. We don't want you too. Well, let me ask you this.
What movies got you excited. Oh, man, there's well. There's I mean John mcforest coming so he got that.
Yeah. Okay. You're putting me on the spot here.
It's like it's the the thing where people are like, what's the latest book you read and you completely black. It's like I can see the cover but I can't think of it. I went for it.
Definitely. There's there's a couple other science fiction ones that I was really interested. But in that Avatar too, I mean I'm kind of interested in that kind of intellectually tell the truth.
You're going to see that before Christmas with you. Good night. Yes.
Okay. So are we and I think it's gonna be nothing more than a repeat of the first one done up in today's technology and more water scenes, but still You know, you might my 21 year old who's my youngest one now said something last night to me. He said Dad.
I've been waiting 13 years for this. I was like eight when it when it the other one came out. I I can't wait.
Yeah, and I'm like, yeah, he's right. He's right. Anyway.
Hey Marty. I want to wish you in the whole netography team continued success. Keep doing what you're doing.
Stay in touch with us. I am you know, well, I'm sure hopefully in 2023. Maybe we'll see each other person.
I don't say or like that or something. Yeah, we'll be on conference circuit for sure us two will be doing live videos there. So maybe we'll have you in but if not, you know, you always have an open invitation to come on here talk whenever you'd like.
Nice appreciate that Allen, you know, happy holidays to you and your team appreciate you talking to you always as fun conversations. So yeah, let's definitely see if we can get together in the coming year. Absolutely, here's all right, Marty Rich.
Netography atomized Network deed check it out. Marty B. Well, we're gonna take a break here on Tech strong.
We'll be right back.