Extended Detection and Response – Jamie Arlen, Aiven
Alan and Jamie talk about the latest developments with Aiven as well as XDRA.
Transcript
This is Textron TV. Hey, everyone. Welcome back to techstrung TV.
I'm happy to be joined by one of my buddies in the security space, you know. it's one of the nice things about doing my texture on TV interviews is I get to I just get the chat with people. I know very long time and security when they were serious and now they're more serious, but it's good to have them here.
Let me introduce you to my friend Jamie Arland. Jamie is with avian. Jamie's great to have you back.
How are you? I'm fantastic, sir. Fantastic.
Good good. Good. Hey, I know we want to talk extra and stuff, but I I Other than being my friend, I think you're gonna I don't know if that's enough cred on the show to get you know on a subway even but why don't we do a little bit of your background and then also a little bit about the company there are so hey everybody.
I'm Jamie Arland. I've been doing security for a long time. That's a odd claim to fame.
I've worked in Cloud for better part 15 years right now. I'm the ciso at Ivan. We're an open source database as a service company.
Our claim to fame is all open source all the time and multi-cloud. So if you're looking for that solution that lets you do the interactions with the databases that you're developers want to use you want it to be seamless friction free secure compliant and run pretty much anywhere. Where your next best stop predictable pricing too that's always fun, isn't it?
It's refreshing in this world. And I apologize I had said avian, it's Ivan and I always just turn that I apologize. So.
Ivan is about open source, Jamie an awful lot and we're gonna talk a little bit about that in a moment, but I wanted to talk today about xdr. right and You know X. Yes, what's xdr?
Everybody seems to say that their thing is xdr. You're right. And and I was just so you know, and it was interesting.
I well. You asked the question answer your own question. What is it?
Xdr is practically an umbrella marketing term at this point and that's got sort of elements of frustration associated with it. You know, it's the old timer being cranky. You're about to get the old guy wave like ah, You're not here.
He's good for that. But yeah, the theory is it's extended or or magical detection and response. So the thing that we were promised 30 years ago, the antivirus would make sure that code that we didn't want to run on our computers didn't run on our computers.
This is just the latest evolution of that phraseology, you know, we went through any virus anti-malware and point protection and we're on xdr and what I think it really comes to for most people in most organizations is It's it's almost. It's almost a point of proof when you're dealing with vendors if they're coming at you and they're saying hey, our thing could have saved you from that bad thing that happened last week to somebody else. They're probably trying to sell you xdr.
And if you dig in and really look at what you're purchasing what you're probably purchasing is observability. And and this is an area where you know sort of that those old conversations I used to have with with Rothman and Rich Mogul where you're sort of splitting in between the dev and the Ops and you're sliding a little bit of sec in there to do the security part in in devops. We're really talking about the security version of operational observability.
What are my systems doing? How are they doing it? When are they doing it?
What are they doing that they should or shouldn't be doing? That sort of element of you know for your situational awareness. As a service is I think what most xdr tools are trying to do with various levels of success.
Sorry that you finish it was hard for me, but I let you finish. I don't disagree with you to me xdr was a new name given to and Point Security and for so many of us in the security World. There was a period there was right around maybe when Microsoft started just like giving away their own.
A v whatever it was. Well, you started questioning. This stuff is such bloated Pig where and what is it really do between the heuristics and the pattern matching and all the fancy little bullets AI ml but it was it was damn near worthless.
But you know for the most part no see so it's no organizations kind of had the balls. Did you say I don't even need this. I'm done right?
I'm not what everybody's built in a Windows my Max pretty good. I'm stop I'm gonna stop wasting money and slowing my machines down with this crap and and you know, so we they had to come up with something new because that is look those those endpoint security vendors their cash cows, right? They are very true cash cows so xdr.
The the latest greatest iteration of endpoint security. So there's more than endpoint to it in a perfect world detection and response extends Beyond The Four Walls of my device and maybe there's an element of threat Intel in theirs or you know, that's making it a little smarter. but again Same old Pig just in a different suit if you ask me in many ways.
So observabilities are loaded. Word as well, Jamie and you know that has its own set of issues. But yeah, absolutely.
I think the the point that matters though is, you know, when I sit in my chairs to see so the thing that I need to understand is what's my condition? What's my state? Am I under attack?
Is there something bad going on? Do I have a known weakness? Do I have?
Do I have a team that's not performing the way they're supposed to perform. And I can ask that question status meetings are the best. Or I can have a system that tries to show me the shape of my environment.
You know, we you know that Ivan, obviously we need to make sure that we secure our systems for our customers and the biggest part of that is understanding what we refer to as the shape of the fleet. So when you think of, you know, all of these database nodes that we operate on behalf of our customers. I need to understand.
You know, how close to secure is it? Our customers have the opportunity to choose their own maintenance windows so I can have a patch ready within a day of vulnerability release, but it could take a customer six weeks to get that installed. And while that exceeds my comfort zone if it was my system, it may not exceed their comfort zone.
And so I have to be able to begin to understand these things and that's where I see the value in xdr for you know, the the management of your information assets. It's understanding what's going on in central broad stroke kind of way. It's collecting that.
security tinged operational information That's the the piece that kind of matters for me and you know walking around the floor at blackhat USA or most recently at sector and in Toronto. The vendors that we're talking about xdr. We're talking about situational awareness and that's not the wrong thing to be talking about.
When the conversation drifts into you know, we can protect you from that bad thing that happened to those other people last week. You might have been able to let me know that that bad thing was happening. And this tosses us Alan right back into the old IDs versus IPS days.
Detection versus prevention. I I'd rather know than have a system taking some unnowable or unknown action. Now you can take your xdr and hook it up to your store.
Let's throw all of the buzzwords in there. And yeah get that that automated response to a security situation. But the point that matters the most and the point that I really wish more vendors were willing to hammer home is this is about understanding your condition.
And if you understand your condition, then you can make rational decisions. Mostly risk-based but based on facts rather than feels. Yep.
sending Teen problem we have insecurity, especially as vendors. It is we are we always say I could have prevented the damage you got from last week's attack. But what about next week's attack?
Because last week's attack everybody's now on last week's attack. It's next week's attack that I worry about. It's funny our friend, you know, Andrew.
Hey, I'm sure right and you had to post up in LinkedIn. Evidently, he must have a new post that a new position at Laura's, you know with Nickerson in them and he's researching cold email. Techniques to see so right what's gonna get them going and everything and that was one of the things that he brought up is the the proverbial I could have helped you last week.
and big BFD everybody could have helped me this week for what happened last week. What are you doing for me next week and you know is xdr really gonna help with that. I hope it does look and let me just got done it.
I don't want to be the curmudgeon here who says I bah humbug on all this crap. We've made some progress we have absolutely. Antivirus is built into the major operating systems.
That's huge. And no doubt about it. No doubt about it.
It's actually harder. To break into these things though, you know, the vector still is fishing, right? You know, I I was in the middle of writing an article last week.
I haven't finished it yet about You know ran somewhere and it's effect on the xdr. Market Yep. Right.
Oh, I got Ransom. Well, if you had next to your art wouldn't happen to you. Well, if the idiot wouldn't have clicked and downloaded that thing it wouldn't have happened to you either.
But you know that never changes Jamie. It's still the same old same old. Yeah, and I think that's You know not to force the segue on you anything but that's that sort of conditional response that you can get when you mix open source with the idea of xdr.
It's that the open source world has a lot of tools for understanding operational systems observability, you know, literally what's happening on which systems and how using tools like open search and grafana using interesting databases like Apache M3 and like click house. And even Apache Flink, you can start to process the data that your world is providing you and really climbing that ladder from data to information to knowledge and understanding what's going on. You can start seeing those, you know, either positive or negative behaviors happening for for years.
Now, I think you know rich and I wrote this stuff in one of the earlier versions of the the cloud security Alliance guidance dock was, you know, the the need to move from plain old are back to a back attribute based access control and if you can start feeding more information about what's happening into your decision-making process feed more information about what's happening into your comprehension of State you end up in the place where you can start to make better more interesting security decisions. You can start saying well, you know if this is happening and this is happening then. Maybe we've got an oops.
And until you can start collating that information and honestly until we start doing a better job of sharing it with each other. We're not going to get there and in the same way that the problems tend to get caused by people. You know somebody clicked something, you know, I think in a lot of cases the solutions come from people we want that mass scalability that comes with the magic of AI and the magic of ml.
But somebody who knows what they're looking for the human ability to detect anomalies is astonishing. You know, if you think even now you could probably do a fast scroll on a Unix logging system and your brain just sort of spaces out a little bit and then you see that one thing and you scroll back, you know, 50 or 100 lines and say ah, there's the problem. Because that some part of your brain found that thing.
Well, the story of Open Source all along has been don't pay for the software pay for the operators. Maybe open source Dr. Breeze up some budget to invest in the humans that are going to see that weird thing.
You know the the best the best security guard I've ever seen for for an office is the receptionist. Because she knows When Something's Strange is going on. Yeah, no doubt about it, and you're right.
Here's my issue. It's because it's open source doesn't necessarily mean it's cheaper. And in terms of total cost not in terms of total cost in shifting that cost over to spending it more on the humans who are running it unless on.
The ideologies that you can call support and get a license. You know, yeah, I and look there's a long Rich history of Open Source and Point Security. Clam, a v is a lot more tripwire.
Absolutely. So yes, maybe that allows us to allocate our resources, you know more about this than me James. Jamie excuse me.
I regressed I apologize Jamie. Let's talk about some open source xdr. Is that something I've been plays in?
In a way. Yes. We we bring the difficult piece to you.
So the the difficult piece in all this is managing the databases that underlie everything you need to have very performant and honestly Oddball databases to be able to do xdr using open source tools. You do need to bring other things to the table. You need to bring things like OS query and so, you know go and talk to the the good folks that Collide or or elsewhere you need to bring log ingestion from everywhere not just production systems, but all your non-production systems as well.
Where are you going to stuff all of those logs? You need big databases. Do you want your security operations folks or your your Frontline sock workers to be dealing with the configuration details of a Kafka Eventing system.
Or would you rather Outsource that work and do the good work that you can do with those staff members? So using opens our sourcing Outsource them? Outsourcing security is is probably another a topic for another day weekend discuss.
com days. Well, you know, we all offering posted Lotus Notes people saw some Oracle managed firewall and you know lessons I learned about what companies should Outsource or should an Outsource. Um stick with me to this day 20 25 years later.
I think in security a lot of people Outsource stuff just because they don't have the in-house expertise to do it. Well who does is a handful of companies that really can do the whole enchilada, you know when it comes to security but the flip side is if it's core and critical to your business. Should in Outsourcing.
But anyway, we could talk about that another day. You can Outsource pieces of it. You don't have to Outsource the whole thing.
You can Outsource the pieces that you don't want to do. I don't know. You know, I don't write my own operating systems.
I Outsource that to someone else. So selective because operating systems are not necessarily Cordy your business. That's not what you do for a business.
Exactly. Right? It may be critical to your business, but it's not core.
Jamie unfortunately, we're low on time though fruit. Who listen to us ramble here like too old? Where can we where can we send them to get really smart?
Where can we help? Where can they go get help? All you can come and visit us at Ivan.
com that is Triple w dot Aiven dot IO. Dot IO and any particular place within the website they should for this xdr stuff. They can focus in on it.
Just have a look at our open search offering and there's at least one or two case studies or white papers on there that you can read as well. Okay. for my security friend and even for security novices out there look.
Jamie and I are at this a long time. We we unfortunately have seen. Transcoming go Technologies come and go new tools come and go.
It doesn't necessarily mean next. ER is worthless or that you shouldn't look at it or even use it. It's just like everything else.
There are no silver bullets. There are no magic Solutions here. All we have is that ever ever wide a quiver and we keep more and more arrows in there and you know using the right tools at the right for the right jobs is critical.
So, please don't take this to think that xdr is not No, it was easy. It's understanding. What are you going to get from exterior and had a maximize what you get from it?
Yes. Yep, Jamie. It's great to see you man.
Hope I see you in person soon. Yes, we will. Alrighty, we're out go check out Ivan a i v e n dot IO right sir.
This Allen shovel, we're gonna be right back with another guest here on Tech strong.