New Relic Interactive Application Security Testing – Esteban Gutierrez, New Relic
New Relic, the all-in-one observability platform for every engineer, announced the public preview of New Relic Interactive Application Security Testing (IAST). New Relic IAST goes beyond current approaches by providing visibility and context to security findings, advanced detection accuracy with near zero false positives and proof-of-exploit, as well as guided remediation. It enables engineers, DevOps, and security teams to focus on real security risks, remediate issues faster across the application lifecycle, and ship secure code with speed and confidence. Available with Data Plus and part of the New Relic all-in-one observability platform, the public preview comes with a free 30-day trial period to bring the power of observability and security to every engineer.
Transcript
This is Textron tv. Hey everyone. Welcome back to techron tv.
I'm really excited about this next interview because it's, it's right in my wheelhouse, kind of AppSec testing, and it's with a company. We cover a whole bunch here on a tech drunk tv, and that's New Relic, but I don't believe we've had this gentleman on Tech drunk TV before. Let me introduce you all to Esteban Gutierrez.
Uh, and I'm gonna make Esteban say his name because he says it with those great rolling R and it sounds much better than outta my mouth. But Esteban is this, uh, CSO and VP information security at New Relic. Esteban, welcome to Textron tv.
Thank you, Alan. Really appreciate it. Glad to be here.
And, uh, no problem. Very job of my name. Yeah.
I really appreciate it. No, Well, just for the record you say it, I'll do it. Yeah.
Esteban Gutierrez. Thanks. I love it.
All right. So Esteban, as we were talking a little off camera, it's not often I get to talk to someone who's been in the security game as long as I have. Yeah.
And but you're, you're right there, man. You got on. Just when I think around when I did, why don't we give people a little bit of your, uh, your background and your, your journey.
Sure. I'll talk about that. Uh, everything for me started in 1995, uh, when I was working for an internet service provider, uh, in San Diego, California called Surfnet.
Sure. We happened to be co-located next to the, uh, San Diego Supercomputer Center. And, um, one day this, uh, guy named, uh, ura came running into our office, and, uh, he was good friends with some of our system admins, and he was shouting, I, I caught him.
I caught him, I got him. And, uh, he told a big, long story about this hacker that was breaking into places like at and t and other big companies. And, uh, it turned out that that hacker was Kevin Mitnick.
Really? Yeah. And so, uh, that got me super excited about, um, um, the security career.
And, uh, you know, that whole long sorted tale, uh, unfortunately is, uh, ended recently with, uh, Kevin's passing. Yeah. Ironically, Kevin just passed away by last week, I guess it was.
Yeah, it was. And, um, you know, it's funny, I think this is gonna be a total rabbits hole we're going down. Not part of what we were talking about, but think back then, Kevin Mitnick, the hackers hacker.
He broke in all these places and, and, you know, when you look like, what was his motive for doing it? It wasn't to get rich quick. No, it wasn't.
You know, these are the days of, do you wanna play thermonuclear war with, with Matthew, uh, Roderick and so forth. Right, Right. Yeah.
I think for Kevin it was, you know, it's a mountain, it's there. I'm gonna climb it, you know. But, you know, we, we could talk about Kevin and, and the history of hacking for All we want.
It's, it's been a long time, but from then on, you've ba basically been in the security world, as we call it now, cyber, right? That's correct. Yeah.
So for a number of years I was at the, uh, US Army Corps of Engineers in their global network operations and Security center, uh, helping to build out their first, uh, true network defense perimeter. Uh, that was around the same time that first IO command came to be, uh, in the late nineties. And a very exciting time, very wild west, a lot of interesting actions like, uh, the, uh, Chinese excursion into military networks, like, uh, especially Titan Rain was one of the big ones that, uh, I worked at the beginning.
Mm-hmm. Um, after some time there, I was at Intel for about 10 years, and at Intel, I, uh, was helping to secure their engineering computing, uh, computing grid that they used for all the testing of the designs and products. Um, moved into risk management, cloud security, and, uh, worked on a lot of their initial cloud architecture, uh, and virtualization security at the beginning there.
And, um, in 2015, I joined New Relic to build a security team and eventually got promoted to ciso. And, and I've been there ever since then. So you, you, I didn't realize that.
So you've been at New Relic eight years. Yeah. Well, I'm a long time right here at New Relic.
Yeah, definitely. It was an interesting eight years too at New Relic. Right.
Think about the changes quite, Yeah. There's Big changes in the industry and New Relic kind of reflects that. That's fantastic.
You Know, really does, You know, I mentioned New Relic and we're talking about it. I, and as I think I told you off camera, our audience doesn't really need an introduction in New Relic, Este Esteban, but give us for maybe there's a few out there who are not familiar. Sure.
Well, we, uh, established the a p m, uh, industry and, uh, really helped developers learn and understand how their applications were working, how were they were breaking, uh, what was going on with them. And so, uh, we went on to build the observability platform that we have today. And so our biggest strength is really just giving you data, data to make decisions, data to drive your business data to understand your context, your customers, and, uh, helping businesses grow through that information and data.
And I'm very happy to say that that data now extends, that telemetry now extends out to, uh, computer security and security information and security telemetry. Yep. Uh, so today, uh, well, That's part of observability though, too, right?
I mean, 'cause that's one of the things you speak to a lot of the, you know, the pure play observability players and they, they kind of shy away from the cyber label from the security label, because observability is so much more Yes, but I, I think we do, they do themselves a dis just, uh, an injustice by not acknowledging how important security is to this whole observability piece of it. I think you're right. I think they do.
Um, it is, it's critical. Uh, you know, I think the biggest challenge that we've had in security for quite a long time is, is context. Is understanding what, what does this mean?
What is this vulnerability? What is this signal that I'm seeing? What is this, you know, traffic noise.
And so what we're doing here at New Relic is combining the intelligence that we have, the all the observability data, the context that, you know, through which we can provide you an understanding of your applications and services along with that security telemetry. So now you have vulnerabilities in context. You can have vulnerabilities that, uh, are confirmed and with the is product that we, uh, just announced, uh, you can get down to near zero, um, false positives.
You can get a proof of exploit, you can get all the visibility and context necessary to really understand those vulnerabilities and to prioritize them and to really, uh, reduce the amount of time that your teams are wasting trying to chase things down. Is this real? Is this not, uh, who do I need to go talk to about this vulnerability?
And it's, uh, it's a pretty exciting product. I'm really very, very excited about it. Cool.
I got a couple questions about it, if you don't mind. Sure. So in reading the kind of blurb that I was, you know, they provided to us, I, I'm not quite sure, is this New Relic has developed their own AppSec testing modules or engines, or, or are you using others?
Yeah, we do have a candidate deterministic technique by which we combine the intelligence and the telemetry and the C v E vulnerability data together. And so it's really the, the combined or the converged observability and security approach that's kind of novel here, right? It's, it's marrying these, uh, got it.
What, what are not, I don't think there's, you know, separate kinds of information really there. It's marrying the right information together so that we can actually give you that context. So what, what you're doing is you're using some of that innate intelligence, right?
That New Relic has in their observability, a p m platform gathering data, matching that to C V E databases and other sort of intelligence, right? And based upon that saying, Hey, we've got, you've got vulnerabilities here. Here's what you can do to fix it.
You, you're, you're, you're presenting this information, and another time we used, we might call something like that, ai, of course, today, that's a whole loaded term, right? Where you can't really, Yeah. Yeah.
That's a, that's a good, that's an interesting comment actually, and I'm sure we could rabbit hole down that one for a good while. Oh, yeah, yeah. What it does, what it, what this does is it really, there's a lot of analysts who, and, and application security engineers who spend a lot of time when, you know, when we get those alerts, we get the reports back from all the tools that we have, and we have to figure out, okay, so we've got a handful of highs, criticals, moderates, you know, all that data, which ones are real?
Which, you know, what, what actually matters to the business is this, uh, uh, a vulnerability that was tagged on a library, installed on a, uh, on a host image that was installed by default, but it's not actually being talked to by anything. There's no activation in that library. Then maybe that can deprioritize, and, you know, I don't have to run to patch that one, but with the, the IS platform, we can tell you, Hey, that you've got a vulnerability, it's a high C v e, it's running on a system or a host that has thousands and thousands of transactions per second.
It's part of your critical, uh, web services you should run to go patch this one. It's a high priority issue. And that's, that's really what we're talking about.
Not only that, we can also provide a proof of exploit so that you can confirm that this is actually a real exploit, not just, not just tagging on a string, for instance. That's right. No, but that's an important distinction that a lot of people who maybe are not insecurity don't realize just because there's a vulnerability there if it's not reachable and exploitable.
Yeah. You know, it's like the tree in the forest, but, um, yep. Esteban, let me ask you, and this maybe is more towards the business side of it.
Sure. Is this available to all New Relic customers as part of their existing, uh, install? Or is it a separate item?
It is part of the, uh, platform. Uh, it's available right now in limited preview, uh, and it's available to, uh, different pricing structures as well. Got it.
And we've got a lot more information about that on our, on our website. Well, you mentioned it. What, where should they go on the website?
com. Um, you mentioned limited release without holding your feet too close to the fire. When do you think this'll be in general?
Uh, it's a really good question. We're hoping to have it happen pretty quickly. Um, obviously we wanna get a good amount of, uh, customer usage out of it so we can really see how people are adopting and using it and, uh, continue to refine on that as well.
Yep. Now, I want to make sure people don't get the wrong impression out here. We're not advocating to throw away your AppSec test scanners, right.
Whether, you know, whichever ones you're using, and I A SS T or das, you know, static dynamic, right? Uh, uh, open source, I forget what they call software composition analysis. Software Analysis.
Yeah. We're not advocating that at all. What we're saying is the more of these sources that you can make available to New Relic, the better the picture New Relic can paint Exactly.
Of, of what you, what you've got here and, and what your risk is and what, where your, your, uh, vulnerabilities are and what you could do about it. Correct. Yeah.
It sounds like, yeah, you've really done your homework and I really appreciate that too. That's, that's great. Yeah.
No, that's exactly what it is, right? It, it's, mm-hmm. It's a component of the overall, uh, DevSecOps cycle, right?
The, this new way that we really need to be handling vulnerabilities. Right. You know, I kind of think of it as a democratization of the security work.
You know, it's no longer just an ops team or a dev team telling the security team, please help us understand and fix these things. Or, or the security team saying, Hey, devs, you need to fix this. Just deal with it.
You know, we don't have time to answer all your questions because we have thousands of other things to look at. Um, it's bringing all that information together. And then I think also building a bridge between devs and security teams and ops teams as well, and SREs, because it's actually allowing us to have a more intelligent conversation about the vulnerabilities of what we're seeing there.
And so the more sources of data that we have, the more rich the context and the information becomes, and then you can use something like our New Relic vulnerability management platform to really, uh, kind of have that complete picture and understanding of, of your end-to-end, uh, security posture and, uh, really integrate the rest of the information that you're getting from your software composition analysis tools, your, uh, static code testing tools, um, you know, everything else as well. Excellent. I love it.
Hey, Estaban, Esteban, we're about out of time. Wow. I want to thank you for coming on though.
This was great. Thank you. Um, you know, it's, it's interesting to see how far, first of all, I'm always excited when I see security kind of go mainstream, right?
Yeah. Like cross the Rubicon from just pure security monitoring or, you know, vulnerability into the broader monitoring world. I agree.
You know, and we, but we've seen that happen more and more, right? Yeah. Over the last couple years especially.
But it, it's a big step here for New Relic. It's an exciting, uh, new piece of, of functionality and look forward to seeing this in general availability soon. Me too.
Yeah. I'm very, very excited about it. This is something I've been wanting to see come to fruition for quite some time.
Uh, when I first joined New Relic, I and understood, you know, exactly what we were seeing, how much we saw across the customer's estates, uh, I thought, wow, this is a great opportunity for security to, to do something to do better, you know, to do better for the people trying to do the work of security all the time. So, yeah, I think Security people feel that, right? Yeah.
Yeah. Especially we we're always looking for a better bite of the apple on it. Yeah.
I, I know that for most of my career I'd always been really frustrated with just how many false positives I had to deal with. And so that's, now I'm very excited about that piece, so thank You. Amen.
Alright man. Hey, don't be as stranger. Come back and visit us on here.
Okay. I appreciate it. Thanks for your time and All Right.
Cheers. Thank you. Esteban Gutierrez, CSO, VP information Security New Relic.
Go check out New Relic, uh, interactive application security testing. com. We're gonna take a break.
We'll be back here on Text Drunk TV in a moment.