Overcoming Rapid Remediation Challenges with Zafran’s Ben Seri
Ben Seri, Co-founder and CTO of Zafran, focuses on quickly finding and fixing vulnerabilities to prevent exploitation. Ben discusses the challenges of rapid remediation and the importance of automation and AI in improving vulnerability management. Ben Seri also invites engagement with Zafran through their website and free assessments.
Transcript
Hey, everyone. Welcome back here to Tech Drunk tv. My next guest on Tech Drunk TV today is Bensi.
Uh, Ben is the co-founder and CTO of a company called Zaffron. Hope I pronounce that right. Ben, did I get the name right or is it Zaffron?
Yeah, Zaffron Saffron. It's like, it's a bit like the spice, but, uh, it's zaffron. Yeah, it's like Zaffron.
Excellent. So Ben, before we jump into Zaffron and Spice and everything else, let's talk about your journey. As I said, you're the co-founder, CTO there.
Yeah. Leads me to believe you probably have a technical track, a technical career, but true. Let's hear about a little bit about your path.
Thank you. Yeah. Uh, and nice to be here, Alan.
Thank you for, for inviting me. Um, yeah. So, so I, I grew up in the cyber security space really from the, uh, IDF background, 8,200, that kind of scene.
Like, uh, many other, um, Israeli founders. I was the kind of the vulnerability researcher, exploit, um, mechanics as, as, as it, I sometimes, uh, refer to my, uh, old position in the IDF. Um, so researching everything from embedded devices, uh, low level, uh, reverse engineer, engineering, that kind of stuff, uh, came out of the army and joined, uh, army security.
Uh, I was there Sure. Uh, first employee, and I was VP research there. Really.
Um, yeah. So I had the opportunity of, uh, being through such a journey of a company that starts from really nothing and grows into, uh, a multi-billion, uh, dollar company, uh, which is today. Uh, and in, in my six years there, um, I also had the opportunity of leading the research department that actually, uh, found some very groundbreaking, uh, vulnerabilities, uh, back in my days, uh, like Bluetooth vulnerabilities, uh, that we named, uh, blue Born, uh, really going back, uh, and some others that, uh, showed the impact of, um, vulnerabilities on, on unmanaged devices, iot, um, ot, uh, medical devices.
Um, and so that, that's where I grew up in, in the research side, um, uncovering vulnerabilities, uh, and, um, and the understanding really the impact of, uh, them on wide enterprise wide scale enterprises, um, you know, throughout industry. So what would make a person leave a successful company like amis heading up very prestigious research team to go start a new startup? Yeah.
Um, well, that, that, that was the, there was a very specific incident actually because, uh, that that led me there. Um, I can say about myself that I never imagined starting a company. Um, I, I really, uh, enjoyed my time at arm, and I, I think I, I could have continued to have, have a successful career there.
Um, but there was a major cybersecurity incident, um, a couple of years ago, uh, in a hospital in Israel, and, and I was still in amis, uh, and they, they had amis, um, and installed there. Um, but that incident led to ransomware, widely deployed throughout the hospital. Uh, and actually the beginning of that incident was a vulnerability that was not patched in time on, on an, on an external facing server that they had.
Um, and for me, that was a moment to see all of this research, uh, that I've been doing, all that bidding edge stuff, um, on one end, then the reality of a hospital and the lack of, uh, their ability to stop that attack. On the other hand, um, I actually met my, uh, co-founders doing this investigation of that, uh, incident in that hospital. Uh, each of us, uh, were in different place in different companies.
Uh, our CEO was leading Mandiant, uh, in Israel, um, and, um, and they were, they were involved in doing the IR investigation response to that incident. Uh, so we, we partnered to try and solve or understand that incident in depth. Uh, and for me, this was a wake up call because it was much less theoretical than the research stuff that I was doing back at Armes, uh, and Armes, while being a great tool to understand the unmanaged devices of a hospital, the visibility side of it was ill-equipped to actually prevent that attack from, uh, from occurring.
And, and I understand that it's not only arm, the industry was not ready to take the next leap, uh, on its journey from a trying to manage vulnerabilities in the sense of visibility, uh, and asset management and all that to actually proactively deploy mitigations and deploying patches at scale. And our understanding how to, to take actions on, on what, what matters, uh, before it become, becomes a, a breach. Excellent.
What a great story. You know, and, and sometimes that's what it is when you, when it kind of hits you in the face that it's all fine when you're in the lab, right? And hypotheticals and theoreticals, right?
But when, when, when people's lives are in danger because the ransomware is taken down, you know, critical network infrastructure or what have you, it, it, it gets real. Um, so what, what, what's the mission at Zaffron that find vulnerabilities faster, fix them faster? What, what's the mission?
It's Actually, it's actually, you know, all, all of these steps are required for this for the last mile, but the last mile is the mission. The mission is to stop exploitation of vulnerabilities every, everywhere possible on all types of assets. Um, and so that is the goal of the company.
That is the mission. It's, uh, the visibility, finding the vulnerabilities. You have so many, uh, mobility scanners nowadays.
Um, enterprise is actually inundated with, uh, uh, hundreds of millions of vulnerabilities already. Uh, and really the, the piece that is missing is how do you act on it? How do you stop the exploitation of these bilities as fast as possible?
Uh, this is what Zaffron is about, that last mile. Got it. Um, you know, as I mentioned to you off camera, I, I started a security company early 2001 and 2003, we came out with a vulnerability management system, you know, and, and we, we quickly, well, I will tell you internally, we used to call it the bad news generator because it generated bad news, right?
You would do scanning and testing, and you would hand over a, you know, a telephone book if people out there, no, remember what a telephone book looked like, A telephone book worth of vulnerabilities, and some poor guy, it was his job to just, you know, you gotta prioritize them, find out what the fixes are, fix 'em, all of these things. And it seemed, finding vulnerabilities in systems wasn't hard. Right?
Though, you know, certain zero days and everything else, they're a little, but I mean, once you have a known vulnerability, scanning them and seeing 'em if they're on your system is not crazy hard. Getting them remediated, however, was a problem, right? That's fruit.
And, but, and this was a lesson I learned the hard way I thought we should remediate as fast as possible. And the way to do it as fast as possible is with automation. We didn't have ai, we didn't have agents, but what we ran into where people were saying, wait a second, no, we don't want to fix 'em that quick.
I can't roll out a fix until I make sure it doesn't break anything else. I've gotta test it. And so, you know, I remember going to large enterprises, Citigroup, Citibank back then, and they, it took them 90 days from the time you gave them, let's say a patch until they could roll it out.
They tested it for 90 days. In 90 days, all health break loose. Yeah.
Yeah. Um, why are things different now? That, that's a great question.
Yeah. I think it's many things, um, that, that we've, uh, done in our, we in the last three years that's, uh, that, uh, we exist that, uh, enable us to, to claim that we can solve this now that we have a chance to, to do this much differently. And AI is really going to be the, uh, cherry on top, uh, in the sense that it can, can connect all of the dots.
Uh, but, but the dots that we, uh, that we, our system populated over the map of the, the graph of, of the enterprise, uh, is the, the initial enable of that. Uh, one of the things that we very quickly understood from looking at that at this problem is that, uh, you're correct. It's not difficult to find vulnerabilities.
And, and there are many, many of these, uh, that are found by existing tools, but the majority, maybe more than 90% of them are not actually exploitable vulnerabilities that an attacker can amuse. There are noise that you need to understand and, uh, with evidence prove that there are noise. Uh, and, and there could be, uh, a thousand reasons why vulnerability is not actually exploitable.
Uh, it's, it can be because it's not loaded to memory that piece of software that is vulnerable. It's not in runtime. Uh, the asset is not reachable.
It's from the network where the attacker might come from, right? From the internet, uh, or there is a security control. And this is really the piece that Dran does the most uniquely to find connection between the configurations of your security controls and the posture issues that impact in organizations.
So, for example, you might have a vulnerability, but there is a WAF in place, or an EDR or an I guess, and each of them might have a specific configuration that I've actually very good at identifying exploitation attempts of that vulnerability, either creating an alert or blocking it. So taking all of this context into account when trying to assess what is an exploitable vulnerability in their environment was part of the map that, that we created. And that map was then, uh, effective to say to your customers, you can actually deploy this mitigation through your firewall or a DR or another tool, and it can reduce the risk of that mobility significantly.
And this can happen while you're doing the 90 days of testing right in, in another part of the organization. So this was the basis of what we are doing before adjunct remediation came into play, which is our latest, um, innovation in this space. Um, and what we found is when we give an AI now access to this data, when we give an agent the ability to, uh, re in real time access the endpoint and run safe read only commands on it, to, to provide you more context on how to do the patch, and even to emulate the patch in a way, again, before doing the patch itself, uh, this really, uh, can bring us into that last mile of automation, of remediation, uh, really, uh, to just the user in the loop saying, I want this run, this, this looks good to me.
Um, and, and all of this, uh, foundational steps that we've done, uh, and now I believe can put us in a really good place to do automation at scale, to be able to remediate much, much quicker. I love it. I, I do think a gentech remediation is gonna change the game here for, for sure with it.
Um, it's interesting. I, you know, I had a friend, I dunno if you ever heard the name Giddy Cohen. Giddy, uh, giddy.
Well, he's out in the Valley now. He's in Silicon Valley now. I interviewed him, or I spoke to him, I have an interview coming up with him.
He started a new company, but he had done a company maybe 15 years ago, um, not Skynet, whatever Skybox would they, Skybox Skybox Security. You're familiar. Yeah.
So Giddy was the founder of that. He moved on, then came back, then moved on. But anyway, but you know, they used to generate those attack maps, right?
That was the first time I, I came across sort of that whole type of thing and show you where on your network, how you can mitigate until you, you know, a temporary patch, if you will, or a temporary mitigation till you can actually fix the underlying vulnerability and great technology, great technology. And, but I would imagine with in the age of AI and AG Genix, man, we could do it so much better now, so much That's true. It's gotta be so much faster.
It's true and better. And it's really a scale, scale issue. How do you solve, um, a exposure management, uh, in Read Enterprises?
Because you can think of this and, you know, there are a couple of, I don't need to name names, but a couple of products that tried to do attack path analysis. Um, um, and, and when you, when it comes down to it, uh, visualizing and trying to put on a graph every endpoint and every network appliance, and how all everything is routed from, it's not that it, it's not possible that it's quickly unmanageable. Um, and to, to the medium, to the let's the median, uh, user of, of these tools, uh, and AI here, um, can be the bridge between all of this great data that is actually powerful and a user that wants to know what should I, what should I do now?
Where is my exposure? Um, you know, um, what is the thing that I can do in my environment that is, uh, the most practical to reduce risk, uh, as fast as possible? And so, um, being their translator of a free text question, I am the analyst right in the company.
I'm the cso, I'm somebody that understand my organization. This is my position. So this is my responsibility to say I care about this business unit, or I know that this, um, asset is specifically critical to the business.
I'm going to give this insight to the machine, but then the machine can take this and really iterate and, um, and hunt throughout the environment for through what, what is the impact to, to that environment. And it's, it's, it's going to be a complex part that the agent does for me, right? To, uh, to, to, to walk through this map, to walk through this craft to understand what matters and what doesn't matter in it.
I love it. Ben. We're almost outta time, but we didn't really tell people if they want to get more information or they want to engage with zaffron, what, what's the best way to do that?
So go to Zaffron doo, that's our website. Uh, we do have their, um, uh, free assessment, um, form that you, that you can register for. And we, we can give, uh, any reprisal is, uh, uh, looking to, to test out this tool access.
Um, and essentially, um, you can also, there see the blogs and some of the demos if, you know, prior to you wanting to test out the tool to understand how it works. And maybe in more detail, uh, some of what I described, that agent that has the ability to access endpoint, but also the security controls. And I don't understand all of this context that is shown in more detail in the website.
And, uh, we'd be happy to, to get in touch and to, to, to show the, to show you the product, uh, uh, in greater, greater length. I love it. Ben, I wanna wish you continued success with Zaffron.
It's good work you're doing, it's important work, and come back and keep us posted of what's going on here. Okay? Definitely.
Thank you, Alan. Thank you so much. Thank you.
Ben Siri, co-founder, CTO at Zaffron here on Tech Drunk tv. We're gonna take a break. We'll be back with more tech Drunk tv, so stay tuned.