Improving API Security – Galeal Zino, NetFoundry
According to NetFoundry CEO Galeal Zino, Orgs have strengthened API security by improving the authorization of the users of the apps. With NetFoundry, orgs authorize the network connection to the API servers. The result is the API server becomes inaccessible from the networks, even for B2B APIs. That is important because the top 10 OWASP API attacks require the attacker to get network access to the API server.
Transcript
This is Textron TV. Hey everyone, welcome to another text junk TV segment. I am happy to introduce you to a new company to our text on TV audience.
Well, maybe not to all of you some of you I bet you have heard of them and have used. an open source project that they're behind that's pretty popular, but I want to introduce you to Galileo Zeno Galil is the CEO. glial welcome Allen pleasure to be here You know what?
I didn't even mention the company there right? You said you were to see sure you did mention the open source. So I'll mention both and founder and CEO of net Foundry where Alan was going.
Our open source is open ziti z i t i taste great, too. Open vdk. Okay Viti.
You got it kind of a play on zero trust and have a lot of pasta fans here at net Foundry. Well zero tries to certainly a Hot Topic. I you know thinking back to like last February of RSA conference.
I don't know if you guys were there but zero trust was certainly the The buzzword it's funny. We I just got off a call at the RSA conference folks for next year already. It's in April RSA a week of April 24th will be there with our devsecops event doing videos.
Maybe Julia will see you there at our same person. We're doing a few speaking slots. And I believe today was the deadline actually for the submission.
So yeah, hopefully we'll absolutely see each other there. Good. Well, we're always on broadcast alley there broadcasting live and that we put on Old devsecops event.
Nice Monday of our essay. So this week RSA again this year. Alright says Monday Tuesday, Wednesday, Thursday, no Friday, but Monday, I think four clock starts Keynotes.
We'll be doing our devsecops event in Moscone south. Monday morning till 3:30 or 4:00 anyway. That's not what we're here to talk about.
Great. We'll see you at RSA but let Galileo. Let's start a little bit with your background.
yeah, so about 20 odd years now Alan of basically trying to take packets. Over the internet and make it simple secure and reliable started by Voiceover IP in the late 90s when you know voice over IP was difficult to do help build itxc into the world's largest wholesale VoIP Network that takes he was a 99 IPO. Eventually.
I went into video unified Communications web RTC always Allen just literally trying to get packets from point A to point B, really simply really securely with good reliability, but it's always like Full duplex stuff right like video voice and then finally on the light bulb went off, you know a few years ago, and I was like well, wait a minute. What we're doing here? Applies not just to voice and video and you see that stuff is great.
But increasingly with the way the world is going it applies to everything like applies it just about every packet flow. So let's start. net Foundry to provide a platform to enable folks for any type of use case to be able to do simple secure reliable Network and That's fantastic.
I'm also from the 99 IPO Club interliant a init. Yeah. Well, I wrote we were an early ASP.
So Cloud before there was Cloud we could have used something like that Foundry then but anyway, so when was that Foundry actually? Founded and started. Yeah, I started a few years ago.
Mainly just doing a lot of prototypes a lot of Pilots talking to folks out there. We do things a little bit. Differently Allen, so there was a large build here from a platform perspective at the end of the day.
Everything is you know. Is becoming software but in this kind of like whole software each World thing. You know networking.
and security kind of got left behind in the dust. And so we had a lot of build to do to make secure networking in the software to make it so a developer. could take an SDK in a simple manner compile his or her application with that SDK such that wherever that application would go or API or webhook or iot solution, whatever it is would natively have.
Secure network and rather than Allen as you know, like the old model of like while I build my app over here and then I'll put it on a network and then I'll try to bolt on a bunch of stuff for security and reliability and performance. Yeah, that's not software. That's that's not where today's world is that's where you and I were like in between This and like 99.
Well, you know what? I don't want secured Network at a 99 that we want to give the secure network enough tomorrow kind of this Cloud error this software Arrow secure network. Absolutely.
All right. You mentioned the open source project. Let's let's dig.
I'm sorry we're doing this kind of one block at a time. But let's dig into the open source project. It's great open ziti, really exciting because if you think about Alan what I just described Which is giving developers control of secure network and regardless of what clouds what edges what what networks well.
The Innovation and and the community aspects that we've seen in many other open source projects, right we've seen this again and again again kind of secure networking is like the the last one and so what open ZD says to you Alan is listen, here's all The Primitives. That you need to do secure networking in a simple Manner and you know what set of Primitives you take and how you use it. It's up to you with our goal.
Basically Alan Bean. Okay, let's let's see. how developers will innovate in ways that we haven't even dreamed of If we just kind of give them the tooling and that's what open ZD is and then of course we went ahead.
We ate our own dog food Drinker on wine. However, you want to say it and we built net Foundry AS Global managed says on top of open ziti. So, you know, we're we're using open ZD every day in a very very big way with you know, a lot of customers, etc.
Etc. And at the same time we have the open source development community and they're doing all kinds of really cool and Innovative things with with open ZD. So that's that's the balance.
We're hoping to get and you know so far so get out and spend a lot of fun. Absolutely, and you know we started this conversation off talking about zero trust which of course open. Zdza is a play on but I wanted to talk a little bit or I'm good.
I don't want to talk. I want you to talk a little bit about API security and and you know that because open ZD has a big play in here. What what you guys are doing in that Foundry has it has a big relevant surround API security which is a you know, a huge piece of the puzzle today and increasingly bigger piece of the puzzle and how that all fits.
And so, you know, and that's something we I had personally haven't seen connected in the market much which is this idea notion of zero trust where the API Security in the cloud. I'm not you can say it better than me Galileo. No, absolutely and listen.
It's a really perfect use case from the perspective of apis API endpoints, of course. Need to be public right if you Allen are offering me an API, you better make it really easy and simple for me to consume that API. Otherwise, you're probably not going to get many users and as such.
All the kind of private networking options things like private circuits like an mpls Network or maybe a VPN or maybe Alan just taking a bunch of you know, firewalls and doing like whitelist Blacklist type stuff, you know, complex ACLS to differentiate between like me and maybe someone who you don't want using the API that stuff. has basically been seen as Forget it. Like really I'm gonna have all of my API consumers on the same VPN or I'm really going to do all these firewall manipulation like in feasible, right?
So as a result, what we did is we said okay as an industry, we said, you know what let's try and do all this stuff at layer seven, right? We'll do API gateways. We'll do certificate based authentication authorization.
We'll do a whole bunch of good stuff to kind of make up for the fact that Initially, you know when that first API query hits my Edge whether it's my API Gateway or my firewall doesn't matter, you know, we don't know who it is. There's no identity the authentication authorization and the result of all that work has been pretty good. Like we've managed to have some you know, an API based world if you want however on the flip side apis are attacked like crazy not because they're out there on the public network.
So like when someone like Gartner comes out and they're like, yeah 2022 apis will be the most attacked thing on the planet. Well, of course, right they're out there in public and so, you know with open ZD and that Foundry we fill in that missing layer because now all of a sudden kind of have your cake you needed to like you can make your API endpoints your API Gateway your firewall, whatever the perimeter around your API gave us. You can make that private but not with wires not with boxes not with firewall rules with code and and you know, just in a very high level Alan if my API at the end of day is is, you know, regardless of you know, rest web each, you know, grpc, whatever.
It doesn't matter right at the end of the day. There's a bunch of traffic going back and forth. It's computers talking in Computer Service talking to servers and because now The API developers can add a few lines of code to their existing code?
That results in a private Network between the API consumer over here and let's say you the API publisher over here. Now you get the best of both worlds out right now all of a sudden you have private apis without the baggage of of the old school private Network in Solutions I love it. It's good stuff now.
Foundry Is you know in terms of we go to market here offering this is a sass sort of offering, you know, similar to what others like what zscaler is done. You're not not API specific obviously, right? It was more of a Sandbox for all kind of traffic but offering it is a service like this, right?
Is is I mean, you're the only people I think that I know of right now doing that especially based on an open source Foundation, which is nice. Talk about let's talk a little bit of Galil about this, you know the commercial offering here sure you are spot on Alan in that what we seen is a lot of our customers have said terrific. Give me the open source and I will make zero trust apis.
There's another set of customers that want like you said more of the Cloud approach and in our case, there's kind of three things that have been important to customers. When I mentioned kind of like the API consumer talking to the API publisher, I kind of left out Alan. What's in the middle?
Right? What's in the middle is is networks routers in our case. They're open ZD routers.
They form an overlay fabric. It's a zero trust overlay Fabric and depending on where your API consumers are and where your API Publishers are, you know, that can be a global Fabric and we've done a lot of things in open ziti to make it simple for folks to be able to kind of spin up that fabric and manage it and get performance reliability There's real time routing algorithms all that type of stuff. But there are plenty of folks.
Also Allen who say listen. I'm gonna focus on my apis. And I want you.
Net Foundry to host and manage that fabric. So the cloud offering that you're referring to includes net Foundry hosted and managed Fabric and it's the same hosted manage fabric. We've used for all of our Solutions.
So it's pretty well known and well vetted out there and then of course you get The support the sla's all the automation capabilities are kind of built into the net Foundry says things like updates things like management visibility metrics all that type of stuff. That's all in that cloud offering that you're referring to and you're entirely right. I mean, we're just, you know, we're standing on the shoulders of giants if you will, right we're replicating what other folks have done in terms of a cloud model and we said, oh my gosh, you know, there's there's no zero trust apis.
Okay. We solve that with open DD. There's no zero trust Cloud for apis.
Okay, we solve this with essentially what is is cloud ZD for apis, which is what I just described. Sorry, okay. I feel like obligated damned we have so we talked about how it's packaged how it's consumed the cost who's named for typical customer friends will finish that out.
If it's okay sure consumption based model Alan just like most of the cloud world so you can get started actually even with the cloud service free forever for up to 10 endpoints. So in other words, we want to make it really simple for you to be able to separate between like, you know, the marketing fluff which you know zero trust there's a lot of marketing fluff give you an easy way to say. Okay, like, you know book a little now and talk about sounds pretty interesting.
Let me see for myself so you can go sign up on that found for the free service. It's literally free forever for up to 10 endpoints and you can build an environment really really easily on the open source side. It's the same thing.
You can go to open ZD you can start playing before you know it you're probably thinking about some pull requests and some extensions and some cool things that you want to do and we have a vibrant discourse Community where you can talk about that with other kind of Leading Edge developers and Engineers who are thinking about the same things. Both options are out there Alan. We see some folks do do both as well.
And then If you're happy with what you see. And it matches what we're talking about. And now if you want to go into a larger environment like a global environment, so you want to buy the the cloud ZTE API solution then it's a pure consumption-based model, right?
You're just gonna pay for what you use. but I just want to clarify something for the audience, you know, we the open source world is so You think back to the open source of 1999 and you know? And we're open sources today.
Open ZD is that Like a net Foundry created project that you manage is a part of an eclipse or Apache or something like that. Yeah, it's CNC. It's a cncf project.
So it is a clinics Foundation clinics Foundation. You're right. We were the initiator.
We're still the leading contributor and maintainer of the project. So and it's still listen to Just from a quick, you know, licensing perspective Etc. We build it.
To enable people to use it without friction, right? So it's like MIT license in cncf, you know Linux Foundation project. Like it looks like any modern open source project that look that's the model today, right?
This is it that's not 1999 anymore. People want that kind of stamp of hey, we're it's this project isn't Run for the benefit of one company. It's it's Run for the benefit of the community.
And that's great. Are you guys gonna be a cute con? Yeah, we will also.
Turn there's a few events we have coming up where Oracle world next week kubecon reinvent. I mean, you know the whole fall tour. Oh most of them myself.
I was just gonna take this where we're broadcasting live from cubecon. And if you're there Google come stop by our boat. We're right on the floor right a broadcast Booth right on the floor broadcasting live.
Love to have you on and continue the conversation and of course you've caused a great Your oracle's a big event reinvents. I think going to be crazy this year. We'll be doing some videos there as well, but cards October 25th or 26th.
I forget now. Let's go be great coming to you there. Yeah, I listen love to do a cup of coffee.
We can yeah 1999 we can talk about 2029 and everything in the Middle Island. But yeah, I just want to get through 2025 would be nice. But Goodwill thank you for coming.
You know what we didn't make net found is it net Foundry that I owe or yes that that's what I thought that Foundry that I know Galileo. Thank you so much and I hope this was a good first time on Tech strong TV for you, but it won't be the last yes, fantastic on very nice to meet you and look forward to Future conversations. io open zdcncf project.
You can check that out. You can see it if you're going to be a coupon with us. We're going to take a break here on Tech strong.
We'll be right back here for in a moment.