Open Source Intrusion Detection and Prevention – Éric Leblond and Peter Manev, Stamus Networks
In advance of SuriCon event, Stamus Networks CTO Éric Leblond and Peter Manev, chief strategy officer, discuss why a more introductory “Network Security using Suricata” book was needed to help make the open source intrusion detection/intrusion prevention (IDS/IPS) platform more accessible
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Peter Manny Who's chief strategy officer for stainless networks and Eric. Leban who's their CTO and we're talking about a new book that they have published that helps people navigate what's going on with the open source, cicada intrusion detection intrusion prevention system gentlemen, welcome the show. They don't make him anyway one.
All right. Hello good to be here. Eric let's start with you.
Why did you feel the need to write this book and there's clearly existing documentation. But you know, what is it that you're hoping folks will take away from this. Yeah.
So if you look at the accident documentation from the story gotta project but describe all the intelligence system or when it talks security monitoring capabilities of silicata. You have to read six or seven hundred pages. That are meant to be used as reference.
So what we wanted to provide with this book is a coverage of what we think is important with silica in a short term volume with easily accessible chapter where we describe different things that you can do with software. Peter do you think the adoption of this type of platform is on the upswing or downswing because we've been talking about intrusion prevention and detection for I don't know feels like a decade or more and it's always number three on the list of things that people do but it's usually below the 50% adoption rate. But what are you seeing these days in terms of intrusion prevention and detection or we're taking any more seriously.
Yeah, absolutely, especially with the rise the recent the past decade shall we say of all sorts of malware tractors, but you bring on a good point actually one of the advantages of circata is then it has a multiple benefits of instead when you actually deploy it and one of them is IPS, but it can also be full-blown network security monitoring engine whereas it will not only generate rollers, but all sorts of network protocol forensics that could be used by instant response teamers and to be very honest. That's one major part of why we actually Made the book because we actually Incorporated some of that knowledge in there, which is good. Not only for beginners but also for advanced users kind of experience from the field if you will that we hope many folks will find it useful.
All right open source is widely used in just about every it sector there is what perhaps maybe the exception of cybersecurity. So are we starting to see more usage and Reliance on open source in the security space and if so what's changing? I think this people are working more and more on together on working together.
They want open format to exchange. So even if open source security open source cyber security where something really versions very long. It is increasing in usage because as people want to work together, we are using open source store and open standard after communicate.
So we see I think larger different of Tours lecture I get up because it's easy to implement on you can schedule it super fast on you get a lot of information a lot of data but already valuable for the companies. So I think this is this mix that you are not down to the vision of one editor, but you can build your own. Set of tool and mechanism on process to have a solution that fits your organization.
Peter are the bad guys get more sophisticated or is it just the volume of a tax is increasing or or I guess I would like your perspective on are we winning or losing this here cybersecurity War? Maybe yes, the attacks are getting the attackers are getting better and the volume against bigger. We definitely need to actually keep up the fight for sure and that's what a lot of us and colleagues are doing both out on the field and we just have to keep at it.
There's no other ways around it because if we if we don't do it it will mean that we basically gave up and that's not what we're about to do and that's not what we will do. We are not in that business and businesses quit thing and we just keep up the fight against the bad guys. And this is why one of the reasons is actually we incorporate Knowledge from actually the field and experiences from different.
That we had from different one of some of the biggest cyber exercises in there as well that we find useful and we hope the reader will also find it useful as well. Very you think we're gonna rely more on Automation and AI going forward and does that have a role in this platform because we hear about the shortage of cybersecurity people all the time. So, how are we gonna level the playing field?
Oh the shortage of sorry. The shortage is earlier about 3D a big problem and it was the company we are ready to co-found with Peter. We are working on helping on top of silicata to have something that requires less work for the people.
So less people can do more stuff more analysis more detection with what project and to do that where you need some process. You need some algorithm on yes machine learning on stuff like this, ah solution for this problem. That's not very solution.
But it can help. I don't really believe it can be a silver bullet. We have seen a lot of vendor that claim to only use AI when we are using in fact a mix of technique because it's a by mixing technique that you manage to have a bigger coverage of a site on when managed to lower the tasks on the amount of work that is needed for the cyber security and it's Peter how big is this open source community and how do people get involved in it?
Because it seems like there's just a lot of places to join but what are you hoping for? What are you looking for? Well, actually our strength comes in numbers and versatility when we're talking now, we're talking about blue teams Defenders and that's all that's what we do.
We know in the cyber security aspect of it. So and you can our community is actually Global we have people from all continents all time zones. There is always somebody that will be there on either on chat on the email or on the Forum right to help out.
There is a live Discord server Champion form that I also record you can get all the homeless. You need to get plus including it's there's a high chance that there's always somebody that have already done a similar thing that you're trying to figure out or able to answer your questions. So that's always kind of helpful knowing that it's handy and knowing that that it's there.
So we have constantly grown our community. And we're actually next week. We have one of our annual conferences, which is a recony now and needs to be healthy.
Nothing's Greece and these numbers always grow and we see more more interesting ideas more interesting exchange. And that's where the real power comes in because with open source, you can actually you do that. You actually you open it and you share it for suggestions ideas collaboration and that's is a huge enablement in the in the cyber security industry, I believe.
Eric what's that one thing that you see people doing that makes you just shake your head and go I can't believe we're still fighting this issue or still struggling with this particular issue. I guess I'm asking you what's your pet peeve of the moment for cyber security? I would see people I'm not complaining.
People think that things are as they are. On things we cannot do a change exactly in line with your idea or no discussion and open source on community. If you start to exchange if you start to think that you can make a change only maybe just by complaining on better by contributing.
When things start to progress on move fast, so that's something I start to say since a few years now, please complain. Just say that things are not okay. Politely and then maybe people will find ID to fix it or will fix it.
And sometimes it's something that is not usable on in 10 minutes of God. You've got to fix when you know what to do it. So, yeah, please complain.
All right. Peter is a follow-up to that. Do you think this cybersecurity community in general has gotten a little too passive.
Do we need to get a little more aggressive? I mean, what's what's your sense of the the mood of the crowd? Not necessarily passive.
We're just getting hit on from all sides with very honest, which is normal unexpected. But we just I believe one huge potential plus could be in collaboration more collaborations more Integrations more openness about what we're trying to do and how and that ultimately comes to to feedback a feedback of two techniques that they use what kind of works what doesn't and get that all sorts of experts from different parts of the field kind of on it and discussing and making sure is beneficial for everybody and we move on forward but that is not going to happen without actually openness in collaboration and feedback is is hugely important. One of the benefits of the open sources regards as well is like The basic is of source.
So actually that enables a lot of feedback and a lot of complaining as a my colleague Eric mentioned. So but that it always helps if the different professionals from parts of the field actually collaborate and we do more towards integration. I think that's one of the key there.
Eric how do we achieve that goal because the bad guys are clearly collaborating much more aggressively than a good guys are and the good guys a lot of times in the security industry. They hold their cards close to their vest and they don't necessarily share. So is there something we need to do or maybe you know, we just put everybody in a room and figure out some way to collaborate or what's your what's your best advice or you know, what's your dream list and wish of ways of collaborating?
So I'm from France. So European on I think there is a strong movement. Maybe I will be BS because I'm former club and social Community.
But I've seen so many big names Associated to collaboration between omggs. For instance. If you take the project that is a missed malware information sharing platform.
It's just about multiple organization sharing threat intelligence sharing tactics from attackers together at the last scale. We are talking about some missing something with the biggest name in Europe. And governmental on a company's but are working together to exchange information faster from vertical can actions their information on their side.
So I think this is a big plus that's something that should spread out far more on to be even more efficient. I know that very some people that don't want to share information because they think that it's going to be a problem for them. But at least if some are doing it make them benefit from their finding it will help everybody and I think that's very something people should work more on sharing information.
You got level of trust in this kind of tool where you can just exactly what you know is not touching your property of any of Part of critical part of information about your information system. So yeah, please try this method and I think you can have better result if all the company from one sector. work together we will work together against attack here, but do exactly the same like going after all those people like going after all very or not this industry.
This is campaign that are often don't by state or by Mafia. At the same moment for us that we were same Target, so we need to work the same way. All right, folks, you're heard it here in the spirit of the books cybersecurity sharing is caring gentlemen.
Thank you for being on the show. Thank you pleasure being here. Thank you very much.
All right back to you guys in the studio.