Highly Evasive Adaptive Threats – Mark Guntrip, Menlo Security Inc.
Mark Guntrip, strategy and marketing leader at Menlo Security Inc., discusses the recently released National Cybersecurity Strategy and its impact on the industry. Additionally, he will explore the trend of criminals bringing Highly Evasive Adaptive Threats (HEAT) attacks in new ways — like modifying their attacks to infiltrate the browser and/or adopting new twists for established attacks to prevent detection.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Mark guntrip who's director of cybersecurity strategy for Menlo security and we're talking about the new National cybersecurity strategy that was unveiled by the Biden Administration and what the impact of that might actually wind up really being Mark. Welcome the show. Hey, Mike, great to be.
There's been a lot of debate in a lot of folks are saying like most of these initiatives there's carrots and their sticks. Some people say they're on enough carrots and some people say they're on enough sticks. What's your sense of, you know, as you look at this document that they try to strike a balance between those two things and how effective was that?
Well, I think as as you as you look at what's what's been coming out of the administration in the white house. I think that honestly, I think we're walking in the right direction. I think that As you look at what they're trying to do ultimately.
It's to build a a country of infrastructure that is fundamentally secure against any the threats that might come in. And so I think looking at the the cyber security strategy the the way that I kind of look at it, you know that we had the zero trust directives coming out last year, I think or the year before and then this really starts to kind of Flesh that out a bit more in terms of what's going on and what what types of areas people need to look at and so I I think that that not necessarily carrot or stick when it comes to to the strategy side of things but really looking at I guidance and suggestions of how things can be implemented to make sure that we end up as a with infrastructure and more importantly are critical infrastructure being as secure as it can be and we're doing the right. Things so we're not just kind of blindly walking towards our future hoping that things are going to be the hoping the things gonna be good.
But we're making distinct decisions about how we secure that as we go. How strictive and enforcement do you think there's going to be some of this seems to require legislation in congress? Not everybody in Congress is pro regulation of any kind.
So what's feasible here versus you know what my ultimate just might not being a guidance and best practices. Lational notes, I'm not sure I agree completely with you mean they'll be they'll be people on either side of the fence for for whatever we want to do. But I think what one of the things that is very much across the board is is that we we do need to defend our infrastructure and you know kind of put in place best practices and and put our best foot forward.
So I I don't know if it'll actually come down to legislative questions to laws to requirements to punishments if you don't hit it, I I see it more as kind of the well as laid out within the strategy right the five pillars of what we should do and what we need to do in order to make America in the US is a safe place. I do think that one of the things that was in there which would which was very interesting. On one of those pillars.
So we talked very much in security about stopping the threats coming in but it seems to be taking it a step further which I think will require work on the government side of things and and some of the the three and four letter agencies in there to not just destruct disrupt the threat actors but also dismantle their infrastructure their operations their business. I think we saw this back earlier this year when the FBI took down Hive and so I think that's very much a step to the offensive rather than just trying to be defensive in there. But I also saw something this week with sister with the cyber security and infrastructure Security Agency putting out a a memorandum about ransomware and attack that had come in and sharing that information amongst other organizations.
So I think the government is really starting to say well I'm not necessarily just going to rely on on private companies to share what they've got to you know, talk amongst themselves. I will take the lead to actually start to proliferate this information so that if we see something then we share it with anyone else that might be that that might be impacted. And so I think that that is a point that the the government and those agencies are starting to step forward and go I'll kind of lead by example.
I'll put it that way. There was some language in there that kind of LED people to believe perhaps that we might see a government that's more aggressive in terms of Defense. They say the best offense is there they say the best defense is a good offense.
But yeah, do we think we're gonna see that we'll various government agencies start attempting to shut down attacks that are emanating from you know, foreign countries. And you know, theoretically that's an act of War right? Well, I mean you could look at it the other side and the attacks coming in from them is potentially also an act of War as well.
So I think it's it's kind of on both sides of the fence. But you know when it comes to the Internet, it's it's a global World anyway, right so they might be a Pick your country of choice group, right North Korean China Russia, wherever we throw the the arrow, but realistically where they're coming from is probably going to be somewhere inside the us because they can just tunnel in and get an IP address and a way they go and I think it's been it's been a very long time since I've seen source of attacks kind of money when you look at the like the volume of where the attacks come from. It's normally the us maybe the US and the UK that are normally number number one and two in there for where these attacks are starting but in terms of your question going back to you know, being more aggressive against these these threat actors and groups and nation states that are out there.
I think we kind of have to be unless you know, you kind of keep the tide back just by stopping the individual waves coming through but at some point you've got a step forward and go, you know what I'm gonna build a wall. I'm gonna stop this I'm going to do what what I need to do to to protect myself and I don't believe that just swatting away these threats as they come in is the right thing because at some point I'm gonna fail I've got I've got to be on the offensive so I I would be surprised if we didn't see that and I think the the taking down at the hive operational though, it was ahead of this strategy coming out certainly seem to be the the first time that I recall at least that they've gone out and actively disrupted business dismantle business. Probably not taking it down for good.
I think you know without they will come back but it's taking more time more money more effort for them to be in their business of ransomware and everything else that they throw around. So we're making it harder for them to to win and to get all the that they want what should the average cybersecurity person working in an Enterprise Computing environment take from this document. Should I just kind of like print it out roll it up and wave it at everybody or is there you know something more actionable.
Well, I so you used a very interesting word that Mike actionable. I don't think there's a whole lot in here that is actionable. It tells you what to do.
It doesn't tell you how to do it. And so I think that that that's very much left to. The reader whichever organization they might be coming from to figure out what what it means for them.
I think in principle it again as I've said it's definitely a step in the right direction that we do want to have critical infrastructure and just general companies that will invest in their resilient future that will defend their infrastructure. So it's pointing in the right direction, but in terms of what it means to an individual company or an agency or anything else it's very much left up to their imagination of how to do this and I think the the closest I've seen and it wasn't directly linked to the security strategy, but I'm gonna go back to sister again. They actually have released guidelines around a number of topics that the one which I read was around securing the web and the web browser and here are the four things that you should do as an agency and as Just a regular organization to combat threats coming through this this Channel and so it gives you the four things that you should do in there and that then starts to get down to the how I should start to build my resilient infrastructure and put in place my security policy.
So I don't think that that line has been or that string has been and drawn specifically to that those house but I think if you look then you can find out the how but again it's down to an organization to figure out what do I care about? Where is my Gap? What do I need to do?
How much money do I have to spend on this? How much time how much resource do I have and therefore what can I actually achieve by putting in place something along the lines of this strategy? You also think there maybe we'll see more collaboration among organizations.
The bad guys clearly are collaborating all the time. There's been a tendency to not do that because people you know, they want to hide their breaches and they don't necessarily want to cop that they're having a problem. But you know, if you look at this document if I'm gonna be publicly reported one way or another maybe I will be more open to the idea of collaborate.
Yeah, I think there's there is beginning to be collaboration between like companies. So maybe no Financial Services might share things amongst themselves Health Care might share things amongst themselves, but not necessarily broadly. And I I think that's it's good that they do share and that they will share what what's been going on so that that if one person gets your one company gets impacted then they can prevent that from impacting everyone else hopefully, but I think in reality this needs to that I would go back to your point at the beginning about the current and the stick that there are rules in place about public disclosure of data breaches and and impact of events that are coming in.
That's kind of half the story. So I think that they have to say that something happened. They don't have to say what happened.
And so I think that the next logical step is if The bidening administration or legislation is put in place. That would have to say how it happened. Then that would force the hand of all of these organizations to have to and I have to do it by law so I might as well just throw it out there and try and limit the impact of this to anyone else.
I don't know if they would actually go that far to make them include that much information as part of the disclosure. But I think there is very much at this point for for information sharing around what happened where how it impacted me how it infiltrated my network that the they can start to add on to that if they so choose to do that, but that I think that would be Maybe overstepping the mark of public disclosure. But again, we've taken one step down that path with with we have to disclose there was a breach.
So the next step in my mind logical step is well, how did that happen? And how can we protect everyone else from going through the same pain you are Well, they say Sunshine is the best disinfectant but what's your best advice to folks then as you know, what what should they be doing right now as they kind of look at this and maybe prepare for some new eventuality. well, I think from If so, if we look at the strategy and we look at the technology security technology.
That's that's kind of in place right now. A lot of the the organizations the companies that I talk with are focused very much on detection and response. So I'll try and figure out what's bad.
Once it's in I'll figure out what it's done and then I'll remove it and I think is And well, I'll say add one more point to that and that's very much kind of the first layer of defense is is that detection layer? And I think that doesn't necessarily help them when it comes to security of that being the first layer of security and I think it doesn't necessarily align with with the cybersecurity strategy and around prevention around resilience around disruption and dismantling. So I think from from my perspective looking to augment the existing detection layers that are in there with prevention type technology so things that would actually stop that threat from coming in in the first place.
So whether that's looking good going back to the sister example, I had about securing web browser and web traffic whether that's looking at implementing a secure browser isolation capabilities there whether it's looking at micro segmentation so that if something does happen then then you have your your blast radius contained whether that's looking at Deception technology, so That you're actually starting to both well more than disrupt the the threat actors coming in because they're trying to worm their way around a network that doesn't exist. And so they're wasting their time their effort their resources in there which means that they have less opportunity to put in place that that threat which which would actually cause whatever it might be loss of credentials data breach and everything else. So I I do think we need a bit more of a mind shift to to move from everything that we have today to kind of what it needs to be and what that extra step needs to be so that we can both meet the needs of the strategy which will ultimately result in enhanced security for organizations and agencies.
All right, folks you heard in here. No matter what age it is an ounce of prevention is still worth more than a pound of cure, right? Hey, absolutely.
Thanks for being on the show. Thank you, Mike. All right and back to you guys in the studio.