Patrick Sullivan on Akamai’s State of the Internet Report
Akamai released a new State of the Internet (SOTI) report that shows how growth in demand for applications and APIs has transformed them into lucrative targets for threat actors.
Transcript
This is Textron tv. Hi everyone. Welcome back here to Textron tv.
I am happy to introduce you to Patrick Sullivan. Patrick is the VP NCTO of security strategy at Omo. And of course, that's a, a, uh, venerable title and chair that you sit.
It's kinda like the guy at auction who sits in, uh, Isaac Newton's chair. You know, Patrick, it, it's an important, important role for all of the internet, not just for Akamai. So first of all, welcome to Textron tv and, and thanks for joining us.
Yeah, Ellen, thanks for having me. It's a pleasure. So, look, as I said, this is an important, where you sit is an important vantage for you, I think, for the internet in general.
But how did you get here, Patrick? Give us a little bit in your background. Yeah, absolutely.
So, you know, I started, uh, my career at the Department of Defense. Uh, spent some time, uh, at very large tier one ISPs. Uh, and then I have been at Akamai for, uh, 19 years at this point.
Uh, and I think to your point, uh, you know, uh, really my focus has been, you know, taking this platform that, uh, you know, at one point was exclusively focused on speeding websites and streaming and, and considering how we could build security, uh, on what is probably an ideal architecture for, uh, the protection of, of applications and APIs and, and enterprises, uh, uh, applications in general. Absolutely, absolutely. And you know, Patrick, of course, you know, we talk about Akamai.
I think every, I'm gonna say 99% of our audience knows, and sorry, of Akamai. Uh, but, you know, Akamai is a, a many technical thing, and, uh, there's always new stuff going on. Why don't you, if you, if you don't mind, give people sort of a quick Akamai update.
Yeah, absolutely. Uh, so we do have a diversified business. Uh, I think to your point, uh, people probably, uh, best know us, you know, from the early days kind of pioneering, uh, CDN uh, you know, maybe, uh, it would come as surprise to some that haven't followed Akamai as closely, uh, security where I focus, that's more than half of our revenue, uh, these days.
Uh, and then sort of the third area where we focus is on, uh, compute. So running application, sort of edge computing, um, leveraging that, that same platform, you know, focused on scale, distribution and, and performance and everything that we do. Absolutely.
So you mentioned, you know, security is almost half, maybe more than half the revenue states that occupy for good reason. Um, you know, a good chunk of the internet, the commercial internet, let's call it, runs through OMA servers through the Akamai network. And and part of your mission is securing that traffic, that data E Exactly.
Uh, so, so I, I think as you say, you know, we see, uh, a, a very significant chunk of the business, internet, you know, government commerce, um, technology, uh, finance, healthcare, um, big chunk of those APIs and web applications flow over the Akamai platform. Um, and then we leverage that, that, um, point in architecture to introduce security. Uh, and then also, you know, we have a responsibility we feel to the community to report back what we're seeing, you know, what are the attack trends, what are attackers doing?
Uh, and we're, you know, I think this year marks the 10th year of our state of the internet report where we summarize attack trends, what's new, what's different, uh, and report that back to the community. Absolutely. So the, so d report stated the report.
Jim, uh, Patrick, if you don't mind, before we jump into that, you know, saying IDE does security is, is kind of up here. I want to talk a little bit about the product, right? For instance, I, I know being based down here in South Florida, there, there was, I assume there still is a significant aka i presence.
Uh, you had bought a company down here that was, uh, God if I remember the name, but they were kind of the experts and DDoS, right? And, and DDoS mitigation, DDoS prevention probably, I'm assuming it's still one of the big items on the aka my security, uh, rate sheet, right? That, that's a big shock.
It, it is, Alan. I mean, we look at it sort of our role as protecting applications, right? And, and we consider that broadly.
Uh, so as you, as you mentioned, uh, sort of Prolexic, uh, had its global stock in South Florida. Uh, great team, uh, still, still, uh, you know, a big chunk of that team is, is in south Florida. Uh, and you know, there, it's part in the infrastructure that, that supports applications.
Uh, so that's a core function, you know, DNS DDoS mitigation, uh, you know, the, another area is protecting the, the applications and the APIs themselves. So protection from, uh, injection attacks or, or o osp, uh, attacks. More recently, our focus has really been on protecting the unique attack surface of APIs.
Uh, they sort of have all of the, uh, traditional attack surface that you get with a web application and then some API specific attacks that, that we're seeing play out. So that has been the primary area of investment for us, uh, for the past 18 months or so. Uh, you know, really, uh, thinking about protecting APIs comprehensively, uh, injection attacks, DOS attacks, business logic attacks, um, inventory management of, of APIs, they're, they're so easy to lose track, uh, as developers can spin them up just so quickly these days.
Uh, so that's a big chunk. Uh, and then the final piece is protecting the, the workload itself, uh, that supports the application. So, um, we're also sort of market leaders there in the software segmentation.
So rather than firewalls to, to segment your applications, doing that in software, um, you know, not based on network constructs like VLANs, but, but more on the attributes of the application and, and sort of minimizing, uh, reachability within the network to only, uh, those communication patterns that are, uh, essential. Mm-Hmm, uh, zero trust segmentation sort of. Yeah, I was just gonna say zero trust, classic, zero trust.
Yes. All right. I think we've done a great job laying that foundation.
Patrick, let's turn to this ladies iteration of the sodi report came out, I guess about three weeks ago now. Um, you know, we were, you guys, as we mentioned off camera, we've been covering the Sodi report for many, many years here of the text on tv. What, what, what's new and exciting in this, uh, edition of the report?
Or doesn't have to necessarily be new, I don't know if it rises to exciting, but what, what's of interest, let's say to our audience? Yeah, I think, uh, what's interesting to me is, is the emerging trend. Uh, you know, sometimes you see reports and they sort of contradict each other's.
Uh, you know, we will call out some of the things that we've observed, uh, but I think it also, uh, dovetails with other reports from other leading security companies. Uh, and I think the key takeaway is that, uh, attacks targeting APIs and web applications continue to rise to sort of staggering volumes. Uh, so we saw year over year, uh, a 49% increase.
Uh, but that's on a very, very large, uh, base. So I think if we look at, at just the month of June, uh, alone, we saw 26 billion, uh, you know, layer seven attacks against, uh, web apps and APIs, right? So that would, uh, give you an indication of, of, that's an area where attackers, uh, continue to focus.
Uh, you mentioned DDoS. If we look at sort of layer seven DDoS over the period of the report, we saw 11 trillion, uh, DDoS requests. Uh, so that, that is probably an area that's picked up a bit more.
Uh, some of the ddo s kind of feeds off of geopolitical trends. So unfortunately, we see if, uh, a government official in one location, you know, voices support for another, um, you know, part of the world that's embroiled in conflict, uh, that geography will receive attacks. And it could be, you know, DDoS attacks against the government, or it could be against, uh, healthcare finance in that area.
But, uh, pretty strong correlation. So that has been, uh, another trend that we've observed. Um, pretty heavy, uh, uptick in DDoS as well.
Absolutely. And, you know, a victim of your own success, I think a lot of people don't, uh, worry as much or focus as much on DDoS attacks anymore because we don't see what we used to see, which was this, now, this site being taken down that site, this company being taken down the DDoS attacks because the DDoS mitigation has gotten so good that even though the DDoS attacks are more frequent and perhaps bigger than ever in terms of, you know, per seconds and stuff, that it's, it doesn't take stuff down. We, we, we see they've gotten better with that.
You mentioned API traffic, and that's something too, right? Seen many studies now where, look, a majority of the traffic on the internet is probably API driven traffic, and, you know, securing that has become yet another frontier, another attack surplus, if you will, Without a doubt. Yeah.
I, I think, as I said, that's the area that we're the most focused on from an r and d and investment perspective. Uh, you know, I think there's a couple of drivers. One would be just development trends.
You know, we've seen a shift from building sort of classic monolithic applications to microservices based architectures, which are all APIs. Uh, yep. You know, there's more collaboration, uh, you know, with partnerships, uh, APIs, uh, so, so, you know, uh, rich experiences on a mobile device, API, uh, I-O-T-A-P-I, you know, it's, uh, every trend that we've got seems to be pushing more towards, um, API centric development, API economy.
Uh, and you know, the, as I mentioned, we sort of have the classic, um, attack surface for a web app, your DDoS injection attacks, all of that, uh, carries over. Uh, you know, in fact, I would say probably the most impactful, uh, attack against an API, maybe the most impactful attack, uh, in 2023 overall was the SQL injection attack, um, used by ransomware operators against, uh, the, the move it, um, uh, functionality, right? So that, uh, not only do we see this with profit motivated attackers trying to, you know, fer data, but now ransomware operators, um, you, you know, are preferring, uh, vulnerabilities over classic phishing, right?
And, and I think when we look at this report, you know, we talked about the, the dramatic increase in, uh, attacks on web app and APIs. Uh, but when I correlate and look at other reports, there seems to be sort of a, a trend line there, right? Um, Akamai partners with Verizon, with the data breach, uh, investigation report, which has a different lens that's looking at breaches and then kind of reversing into techniques.
So there you see, you know, web app one, and then, uh, web app credentials, number one, phishing two, and then, um, web app VULs number three. Uh, the top target is the web application, uh, email number two. So I think the classic notion of, um, you know, all attacks begin with phishing, uh, you know, uh, we're seeing kind of vulnerabilities and attacks against web applications across, uh, different threat actors.
Um, usurping kind of that classic phishing methodology. Um, and I think even, you know, looking at forensics firms that are reporting, you know, what was the primary, um, you know, vector in 2023, there again, uh, vulnerabilities, um, you know, are outpacing sort of phishing. Uh, so phishing certainly hasn't gone away.
It's still out there. Uh, but it's, it, it's interesting to, to see the focus on, uh, APIs and web apps and vulnerabilities. Absolutely.
It, it, and that, that's where the, that's where the action is today, right? Patrick, what else is in this, so I report that you think might be of interest? Yes.
Y you know, obviously I, I would recommend, uh, you know, that, uh, that your, your viewers, uh, you know, search for, uh, Akamai, so do your report in their, uh, favorite search engine or chat bot, uh, for a summarization. But, uh, you know, we break down by geo, by vertical. Uh, I think it's notable that commerce, uh, is the victim of more than twice as many attacks as the, the next closest, uh, vertical.
Um, so there again, you know, I think, uh, first of all, there's value, you know, for an attacker behind those, uh, web apps and APIs, uh, you know, credit cards and, and other, uh, opportunities for fraud. Uh, but also, you know, commerce websites are in a brutally competitive environment, so time to market is vital. Uh, so software pushes are happening at a very, very high rate.
Uh, there's a push to have very engaging, uh, web experiences. Um, so all of that, uh, you know, push to, to increase sales, uh, you know, perhaps leads to more exposure. Uh, so I think that's a, a finding that maybe, uh, surprises some, You know, what it is an election season, Patrick, and yeah, we've seen it, it came out in the tides today.
Supposedly Iran was behind, uh, spearfishing successful. That's one of the candidates, not that we know of against the other, but what's our, he says, I'm sorry to pull it outta left field, but are you guys on extra vigilance here with election season looking for these kinds of attacks? And Yeah, Al always, I, you know, I think 2024, uh, you know, in, in good news for democracies, more people will vote around the world, uh, than any other year.
You know, not just the us but we saw the uk, uh, India, uh, all over the world. Uh, tremendous number of, of elections just happened to line up this year. Uh, so obviously that does lead to an increase in, uh, and threat, as you said.
Unfortunately, there's a, a trend these days to go after, uh, you know, campaigns and try to embarrass. Uh, we also see an up uptick in DDoS, uh, you know, either against news organizations that are trying to report, uh, results, uh, you know, anything that an actor may wanna do to undermine confidence in the, the election, even if they can't influence the election directly, uh, that's part of the, the concern that you have. Uh, so we're keeping an eye on that, uh, for sure.
But I would say, you know, I kind of alluded to it earlier, I think we've seen more of the, the, the geopolitical conflict, uh, driving attacks. Um, you know, one unfortunate stat we've been, uh, you mentioned Prolexic earlier, uh, you know, providing services, uh, market leadership position in, in cloud-based, uh, DDoS for, uh, you know, a decade and a half. And unfortunately, we saw more attacks, uh, targeting victims in Israel in the first six months, uh, following October 7th than we had, uh, in the previous 15 years.
So there is this strong correlation to real world events, um, motivating, you know, some individuals to, to lash out, uh, you know, and, and launch attacks. Yeah. I mean, there's no doubt what goes on in the real world is reflected in the internet.
And, and that's, that's a great, uh, stat to, to correlate that. Anyway, Patrick, we're about outta time. I wanna thank you for coming on here and giving us, uh, a, a peak into this, into this version of Sodi.
How often Sodi comes out quarterly or twice a year, I forget. Yeah, we do it about quarterly. Um, Yeah, that's right.
And, and as I said, oh, I, I do want to congratulate, uh, all my colleagues who have worked on the, so d over the years, we're celebrating our 10th anniversary. Uh, so we're very proud of that. Absolutely.
I, I know many of the folks who did it, including a shout out to my friend Martin Be Gay, who worked on it for many years. Uh, he sure did. Yeah.
Yeah. Martin's good people. I know Martin and I go back to the beginning of blogging 20 years ago in security.
com. You can also just Google, uh, Akamai Sodi report, SOTI and find it there. Doctor, thanks for coming on and, and giving us a, a peek in.
Keep up the great work and we'll hope to have it back on here soon. Thanks for having me. Alrightyy Patrick Sullivan, VP and CTO of security strategy at Akamai here on Textron tv.
We're gonna take a break. We'll be back in a minute.