Java Security Platform – Doug Ennis, Waratek
CEO Doug Ennis shares show Waratek’s Java Security Platform takes the approach of identifying and remediating vulnerable in applications while running in production.
Transcript
This is techstrong tv. Well, the great pleasure of being joined today by Doug Enes, who is c e o with Pex. Welcome, Doug.
Thank you. Uh, thank you to you, Mitch, to you and to, uh, your viewers for, uh, listening today. Happy to, happy to.
It's a great, it's a hot topic, great space to be in. We'll get into that. Matter of fact, why don't we, if you wanna introduce yourselves, tell us a little bit about you and, and tell us a little bit about War Tech.
Yeah, absolutely. So, um, as mentioned, Doug Annas CEO O of War Tech, um, I came into the company a couple years ago, um, from the board of directors and the founder to, to really give War Tech a, a fresh look on the market and feel. And so we've gone through and completely revamped the company colors, logo, messaging, um, the tech and the focus on it hasn't really changed.
Now, for me, uh, my background is very varied. I've been in networking, I've been a developer and I've been in security. Um, and so I have this very unique view on what we do, but War, tech itself is a security platform for application and APIs that combine software and security expertise to automate the manual process of fixing code vulnerabilities.
That's what we do. Interesting. You and I share that, those three things as well.
I've, I've have spent my career in all those areas, sometimes all at once. So that was Joke with my team. I, I, I don't write code anymore, but I'm, I'm, I'm dangerously can read it.
I write code, but I don't let anybody else see it. No, I'm just kidding. Um, anyway, well, the, you know, it's a great, it's a great market.
It's a hot space. There are of course, a number of companies in this space and, uh, as, as you know, running a company, you always have to differentiate yourself first. First, talk a little bit about how you approach the market.
Do you target more the security, security teams, traditional security organizations who are trying to work with software teams on API security? Do target more of the infrastructure, more of the application developers themselves? Where do you, where do you tend to point your lens?
Yeah, great question. So let's look at it a little bit differently to answer the question, which is what's the problem we're solving? Um, which sort of answers the question, right?
And when you look at security today, and you look at vulnerabilities, security owns the risk associated with the vulnerability, but the C I C D pipeline specifically in applications and API owns the fixing that vulnerability and getting through that. Mm-hmm. So security doesn't have the full control through that.
And that's the premise of, of War Tech is giving security the immutable control to set policies so that you're not reliant on the ci cd pipeline, which thus then, you know, gives you strategic misre litigation. So then the answer to your question by looking at it from a problem standpoint, is our focus is really around the security teams. Now, we are also absolutely seeing DevSecOps start to pull into the mix, um, versus DevOps.
Um, we're not talking as much on the DevOps side from that side. Mm-hmm. So it's really around DevSecOps and then security.
Okay. Well kinda unpack this for, then, take us kind of down that path of how your customers work with your product, with your technology to, to help kinda enforce that at a policy level. Yeah.
So when you look at what the actual root cause of, of vulnerability is, it's a defect in the code, right? Um, sometimes, um, known, sometimes unknown. Um, as we roll through that, and that's what creates the complications from a security standpoint, is that even if you have all these tools that will do scanning and make sure that your code is secure and you've got a solid c i t pipeline, once it's out in the wild executing, you, you're still at risk.
Um, you know, if you think about defense in depth from a strategy, everyone basically has a laugh protecting the perimeter. Although the perimeter today is no longer just like this, right? Mm-hmm.
But everyone's gotta laugh. But as we saw with Log for J, the hackers can get by and can get through. And so the last line of defense is to really be at the execution of the application.
And that is where war Tech comes in and differentiates ourselves that we actually are at the execution of the application in the api. And our special sauce or unique blend is to be able to look for that vulnerable code, remove that vulnerability at runtime without, um, affecting the actual application itself from performance. Okay.
You're doing this through like an agent or, or, uh, you know, application API firewall, API gateway kind of approach? Yeah, Exactly. So, so what we're doing is, so we're app, we're an A, we're an agent, um, led, um, SAS-based solution, and our agent uniquely attaches at the runtime.
And then in memory, um, we watch how the application performs, what it's doing, and then we give, uh, the ability to set policies based off of that that, um, can go in two different ways, declarative and or imperative. Mm-hmm. That makes a lot of sense too, because the enforcement policy, like during the dev cycle, you know, that's a different proposition than when you're in production.
And of course things tend to come out of, you know, they may have gone through a C I C D process, they may not have actually, maybe one applications got that and the other one doesn't. Poof. Now your apps exposed, right?
Absolutely. And if you just think about the cloud and the movement to cloud and the acceleration of the release cycle of applications, you know, security just has not been able to keep up with that. And we were talking a little bit earlier about being at rsa, and there are a lot of companies talking about how they're utilizing AI and machine learning to give security that advanced warning on, on threats like, you know, ransomware and, and things of that nature.
Clearly not a war tech focus, but when you look at that from, from that perspective, that rapid development, no matter how great everybody is and, and the processes you have in play, there's still a risk that that gets out there. And, and Lockford J is sort of, to me, an interesting classic example of it, because the vulnerability itself was in the code for a long period of time. Mm-hmm.
But the exploit didn't hit until December of 2021. Mm-hmm. Right?
Mm-hmm. Um, and so from our standpoint, when that hit within 12 hours, we were the first company to actually release our virtual patch for Log four J. And just to give you an example of sort of the power of war tech is that one of the world's largest semiconductor companies over that weekend, within four hours, patch 2,500 systems with zero down time and no false positives.
Wow. That's, that Is powerful. Lot of people spend a lot more time than that.
Well, so interestingly enough, so our studies show that 80% of the companies still have risk associated with Log four J and 71% have not even gotten to fully patching log for J at this point. So the numbers are showing that Mm-hmm. Interesting.
And well, and Log four j like anything else, frankly, but of course that can show up anywhere in your stack of a code, right? Whether it's stuff you've written, and if I remember right, that was a Java environment. That's Exactly right.
Yeah. And, uh, logging, but that can be your stuff. It can be somebody else's open source stuff that you're using.
Could be third party, you know, library that you included in that, that has a lot for Jayna. So it can appear multiple times in many different places, not just code. You wrote A Absolutely.
And so one of the customers that after Log four J was out, that, that became a customer of vortec. Um, we found in three minutes of installing that, one of their third party applications, which swore up and down to them was secured from Log four J was not, um, fastest POC we've ever done. You know, it took three minutes to show that they still had that there.
Uh, and then, you know, the, the ability to be able to remediate that in, in quick fashion is that, and that's the strength of war tech. Yeah. I guess it's still true.
It did security company in the early two thousands, and we quickly learned the best day to be selling security as the day of or after they got attacked. Not that you want 'em Attack, it's, but yeah. You know, it's just sort of a fact of it.
Well, uh, so tell me a little bit about then, is this something that, um, the, uh, SEC ops people are gonna be monitoring and watching? Is this something that, you know, you, you're really setting at a policy level and other fo other ops organizations gonna be paying attention to what's happening? Is there a is an ops component to this since you're talking about runtime?
Yeah, so our goal is to, to live within the ecosystem, right? Um, everyone already has a bunch of of solutions. Um, that's the only way security really can be, is having a bunch of solutions to, to fill all the different holes that are out there, um, from there.
So, so we really like to live within the ecosystem. And what does that mean? Um, and what it really means is that what we see from our customer standpoint is that when we go through our journey to production, it's about detecting and understanding how applications in their environment are talking, making sure that we understand the uniqueness of their environment because everyone has that uniqueness.
And then once you understand that, um, all of our customers flip into protect mode or in line, um, as you want to say, and then our goal is that, is to really make us sit in the background. Um, and it gives us the ability to do, do, to do what we do and then let other tools like the SIM or, um, the c cd pipeline or you know, uh, a change management database, be the source that we're extending that off to so that people can work on what's out there. The uniqueness of sitting in line like we do, and the way that we are able to actually watch the application happen, we have negible false positives, and that is a massive difference between us and the rest of the industry.
So when we say there's something going on, there's something going on. Um, and what that does is security now is truly focused on what that's going on. So if you think about it from a SecOps side, if they get an alert through their sim that war tech has found something, one where we've already remediated it, two, they can now go find the source and resolve the source from what that is.
Mm-hmm. Yeah. That's, that's the clearly benefited being in, in runtime in production environment is all, all the false positives from scanning and all you, you're missing context, right?
Versus, you know, what's actually being executed out. It's being executed is a big advantage. Exactly.
Interesting. Um, so tell me, you said you're a SAS based service, so this agent's talking back to your service in the cloud. Um, so I meant one of the questions people are always gonna ask them, well, tell me about performance and, you know, delay and blah, blah, blah.
Does everything go through? Are you through you? Can you tell us how that works?
I'm sure you've answered this question a million times. Yeah, no, yeah, great question. Um, so, so this is another part that that's unique in terms of where we were designed from the beginning.
Our agents are autonomous in the sense that they are actually executing based off of what, what they've been told to do. They're also zero trust, meaning they do not get anything from the SaaS portal until they go check and say, Hey, is there something I'm supposed to know about that I don't know about? Um, so there's no communication that's happening this way without it being coming from the inside, um, from there.
So you can really tighten that down. You can get a lot of security controls in place around that, but then from an execution, it's happening at the agent and it's a lightweight agent that we run. Um, and so, and we see that in our performance test and, and everything we do in our customer base.
Um, just to give sort of a quick example, I, I actually got to meet finally the ciso, one of our largest financial, um, customers, and they've been a customer for five and a half years. And when I met with them, I said, well, the good news is you don't know me. The bad news is you don't know me, which means mm-hmm.
You've been running me in some of your most critical credit card transaction, um, processes. And the good news is we haven't impacted them. We haven't created a performance problem and you're secure.
The bad news is you, you didn't know who I was, right? So how do we grow our relationship and, and go from there? And that, that was the premise of sort of meeting was, Hey, we're already there securing you.
You probably, it'd be good to know who I am, um, from there. And then, so they know the value you're bringing That's exactly right To them. And then so when instance do, do occur, then they know, okay, all right, we've got this.
I know what I know what we'll do, I know who to call, right? If I have questions as well Exactly. Production that we've got.
Um, so tell me about, then, I'm really curious about your assessment of the market and, um, are there places where, uh, a runtime agent protection, you know, is, is a great fit and others that it's not? Is it other API solutions, security solutions like gateways and things that I mentioned scanning other, other approaches? Are those complimentary to what you do, or, or no, really this is what you need as you need something in, in production and runtime?
Yeah, great question. So, um, you know, blackout last year, rsa, this year, our, our theme was don't make us laugh. Um, and it, it makes people laugh.
Um, it's not to say you don't need a laugh, that's not the purpose. It's, it's a better together story. So I think that's the end, you know, result when you look at it.
Mm-hmm. Um, there's protections that need to happen at the perimeter. You know, we all know if you can stop it from even getting in, then you're great.
Right? So if you get that north-south traffic stop, you're in good shape. The question is what happens when they're in, right.
That EastWest traffic, so mm-hmm. When somebody's already gotten into the environment, where are you protected? And that's where we see the better together story with War Tech being able to sit at the application layer.
And then in terms of APIs, the real push was between us and our customers. Um, they really came to us and said, you're already securing our applications. Why not just secure the APIs at the source itself?
And so that's where we really jumped into from a Java standpoint. Now being able to give our customers that single policy set for a Java application at the source of where it's happening, um, and where that call is going on as you look to that. And what we found, for example, is, is one of our large European banks already had us deployed in that place.
We just hadn't given them the formal parts to say, how do I harden these APIs? Now they have that ability to be able to do that, and that's really what sort of the premise for us jumping in is, you know, customer driven, um, as well as market driven. Interesting.
Well, there's, there's certainly enough, uh, job code out there that needs protection APIs. I'm curious if people have moved to contemporary architectures, microservices, that kind of thing, uh, doing the app modernization, you know, sort of the new word for, for digital transformation, least in part. Uh, does that transformation or that change to a contemporary modern architecture impact you in any way?
Is that a plus? Is that a, just kinda looks like another API to you? How do you see that?
Yeah, good question. So, um, so you know, there, there's a couple of answers to that, to that one. net.
So any applications that are built in that side of it, when you look at other languages, um, we have the, the, the basic ability, uh, to be able to secure those languages to get to the special sauce, which is really running in the runtime. That's where we build an agent. So we continue to, to look at our customers and our market base and then add as we grow from there.
Mm-hmm. Um, so we can get to those levels of protection. It's also the better together story back to what we were talking about, right?
Um, where you can have a solution, a WAF protecting at that high layer and us protecting those mission critical applications. You, you mentioned one thing about where do we not fit? And, and I always use this example, um, and it's gonna be a little old school, but I'll bring it up.
You know, we do an amazing job of securing people's on-prem e r p systems. I know it's hard to believe, but there are a lot of people still running PeopleSoft. S A p JD Edwards go through the list, right?
What I don't do is I don't secure Workday. So when they move to Workday, I don't secure Workday. I can secure, and I'm not saying Workday as a customer, I can secure Workday on their side, but I can't secure that SaaS solution.
So that's where the line comes into play. Now, if it's making API calls into other applications in the network, then that's where we would come into securing. Hopefully that makes sense to everybody from the audience.
I, I think it does. I mean, frankly, one of the benefits of focusing on API security is just knowing what API calls you're making to who for what, right? It may be completely unknown to, uh, to the CISO or or to the security team that week ago co got deployed that suddenly we're talking to work Workday solutions, so nobody knew it.
Right? Well, what are we doing and is that the right thing to do? And are we using yes, I'm sure they've got great security.
Are we using it? Right? All those good things, right?
Which is what security teams think about, right? So just knowing those things are happening too seems to be a big benefit of a runtime environment approach. No, it, it absolutely does.
And, and you know, when, when I look at the market and, and what got me excited about War Tech, um, when I came in, and I sort of talked about this at the beginning, is, um, a lot of the market was very much focused on what the end result was, which ended up being a lot of high false positives. And so security teams already have a bunch of things saying, you know, flashing lights going off here and there, and, and the goal is to get them to where the real, you know, issue is. And, and that when I evaluated Vortex from my standpoint to come in was what I realized we were doing unique to the market space.
And so my challenge was how did I get that message out to the market? Um, you know, besides the really cool, oops, sorry, it's over here. The really cool octopus that we've covered up, You've got the crack in there, the octopus We have.
So, you know, here's the piece, right? So, so the story on that is, so when you look at an octopus, what, what the octopus does is when it defends itself, there are a lot of different ways it does it, but it uses its arms autonomously to actually pull in the information, protect itself, make shells, put barriers around itself. That's what we do for an application.
We put that shell and that barrier and that protection around an application. So, and we do it in an autonomous fashion as we were talking about the way our agents work. Very cool.
Um, so you're not making announcements here, not necessarily asking you to make any, but I'm curious what's sort of next for war tech? Were you taking the company next? Yeah, great question.
Clearly I'm not making announcements. I think, um, I had an opportunity at RSA actually to, to chat with, um, a college student who was working on a research paper. And one of the things that I, I said to them as we were chatting about it is that, you know, my job and our marketing team and product team's job is to, to look at the market down the road and start to put together and formulate what does that plan look like?
Where do we see things going? Clearly there's a lot of buzz today about things like, you know, chat G P T. How does that get into it generated, you know, um, uh, ai, how does that play into the way that you're looking at security?
Uh, you know, we're, we are like everyone else are looking at all the different possibilities that could fit into that. I'm not making any announcement about jumping into that yet because I, I think most people would say that it's, it's probably not there yet that you'd wanna stamp your security on, on generative AI at this point. Mm-hmm.
But, um, but you know, that's, that's our space looking at it. Real focus is how do we continue just to secure? And the most important message, you know, to the, to the viewers today is how do you continue to secure your application estate, whether it's an API or the application in a single spot where you can create an amenable security policy and security can now say, we have done strategic risk mitigation, we have a compensating control potentially in a war tech where I'm no longer relying on someone else to solve that problem or that risk that I now have, and it can happen on its own in the natural time.
That's the key thing about war Tech. Great. Well, where can folks find out more about War Tech?
Yeah, great question. Um, so, you know, the, the easy answer is our website. But one thing that, that our VP of marketing and I very much pride ourselves in is that we have a ton of undated content.
Um, I spent a lot of time talking to CISOs and they are tired of going out and doing research and having to get a phone call. Our goal is to give you the research, take the time so that you understand who we are, what we do, and when you're ready to come talk to us, then you'll let us know you're ready to talk. And that's been very successful so far for us.
Excellent. com. Thank you, Doug.
It's great talking with you and, uh, congratulations. Congratulations on the success so far, and I wish you the best. Come back and tell us how things are going.
Will do, Mitch, I appreciate the time and to the viewers, have a wonderful day. All right. Thank you much.