Remote Desktop Protocol Weaknesses – Raj Dodhiawala, Remediant
Remediant CEO Raj Dodhiawala explains why inherent remote desktop protocol (RDP) weaknesses require a different cybersecurity approach to prevent malware from moving laterally across an extended enterprise.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with rajdonia Walla. Who's the CEO for remedian? And we're talking about the current state of remote Computing and what's going on with already P protocols because it seems like there's a lot of malware moving through these systems is more people are working from home, but we're not doing much about it Raj.
Welcome the show. Thank you, Mike. Appreciate the opportunity and appreciate your time and this Q&A.
So we see all the time that somebody has a vulnerability and invariably somebody who's working from home and it gets traced back to some sort of flaw and they already P protocol and yet we keep using these things. So, you know is this just us being our own worst enemies or is there something else going on here? Yeah, I think it's a little bit of that being our worst own enemy.
You know, if you really look at it. There aren't that many options in order to to get the job done when you have to connect to a remote system and and have the flexibility that you need in order to get your work done. Right?
There are protocols or applications that are available that provide some narrow set of capabilities and and our DP certainly is one that besides being durable has been the one that provides the maximum that's flexibility particularly in a Windows environment. So it's here to stay in a sense. Right?
So if we can't replace it then how do we secure it in better manage it because clearly there's a problem. So we need to figure out what the remediation efforts gonna look like. Yeah, I think I think that is an element here.
We kind of look at it from a speed perspective. So let me kind of explain that a little bit right so you connect to a system and if that one system is is infected or has some some malware on it. And of course the objective of any malware is to move around laterally because wherever it lands it's not going to find the crown jewels, you got to work from home employee.
For example, they don't have access to a lot of things that are generally operating in an island. But once they can act or once something connects them to we are DP or VPN or whatever the case might be. Now this thing wants to move around quickly, right?
And so and and that's what's kind of lost that outside of respective of the protocol and his weaknesses Etc. Whatever that may be in the end even under legit circumstances one infected system that hacker is going to try to move around laterally quickly and I think our defense and our protection should think about that element, you know, it's like today we assume credential or already comprom. How robust or resilient is my organization similarly an endpoint that you're connecting to our we are RDP for example is already compromised.
How am I going to protect myself? Right and then you start from that you may think about the problem a little bit differently and figure out how to really solve it much more robustly. It is all about protecting access in our sort of the way that we look at it.
Can we track the behavior of the malware as it's moving around laterally because that is something of an anomaly in itself. So are there signals to look for that are I mean again, this is where a lot of the network parameter security as well as endpoint security does pretty well, right, but in the end it is defense in depth and what I mean by that I know that's kind of often times overuse word, you know, I want to protect my perimeters and network then if something gets to the network, I want to make sure that I'm protecting my endpoint and this is where a lot of endpoint Technologies come and best practices policies come into play and then the Third Leg of the school which then I'm kind of trending towards zero trust Concepts, right and the third element of that is protecting your identity. Right, so I think yes, so as the malware moves around this sort of defendant depth infrastructure is looking at all of this different points of presence.
If you feel if you will and and and and trying to discover the malware trying to figure out how to protect against it Etc, right but again because it is defense it is always going to be one step behind right a new strain comes in or some Oddball one vulnerability exists that is being exploited. None of these elements are going to catch it. And that's really the the reason why we see the number of attacks and the successful attacks out there that we need about every day.
So will this movement towards zero trust solve that issue we've been talking about it for a while. It's not clear to me that a lot of people even understand what the term is they everybody kind of hears it in nods their head, but perhaps they all have different understandings of what that means. So from your perspective what exactly are we trying to do with zero trust?
Yeah. You're exactly right. I mean this is yet another sort of buzzword.
That's invoke today, right? But I do think it has met it. Right.
I mean just the fundamental concept of you know trust but verify is valid that's been proven and physical security lots of other Realms as well. So it really should be applicable in in a security and particular in our cybersecurity and environment. So I I do think now of course the confusion comes in because everybody has their own definition.
There are Frameworks out there. I don't Nest has done some really good work on it. But how many people really examine that and then if they do they feel like it's overwhelming do I have to do all of these things in order to get to to kind of zero, you know, so there is it becomes that that challenge of how do you how do you get there?
How do you get to zero trust and and I think again we're working with our customers and so on the those that we see have had any kind of success or moving in the right direction if you will is because they've sort of done it in layers again, go back to what I said previously that you figure out on the network side and try to implement that zero trust element on the network side, you know any protocol any application API that's trying to you know access a system. Is that kind of can it be protected at the perimeter level right you examine? You so you cannot defeat the problem up and then prioritize where you feel your greatest weaknesses bolster that and then you move around and you continue to kind of do that iteratively and hopefully you have a very thoughtful potentially immersion, but thoughtful security posture.
It feels like this is a bit of a journey and it's some of it is just recognizing that certain networking connections shouldn't be happening. But then as we go along and we get further down the path we start managing Things based on identity, but when people hear the word identity they tend to think about well, that's a person but in reality it seems to me that machines have identity applications have identity. So do we really appreciate all the nuances around identity management?
Yeah. I I do think that you're absolutely right. There are machine identities human identities.
And then there's a second part a kind of an overly on top of that is our do they have privileged access? So write some machine identities can you know have certain level of privileges where they can do a lot more on a particular endpoint like, you know, can it stop services start Services, whatever the case might be like even some of this vulnerability scanners need service accounts that have privilege access because they need to grow into different corners of the operating system of the running system. In order to figure out if there are any vulnerabilities there application systems kernel whatever the case might be and then the other side on privilege users.
I think that's where is the biggest challenge we feel right? So again, think about if you think about zero trust where you say trust but verify this assume that that's a basic premise we want to start with. Why is it that today with hybrid environments with digital transformation moving to the cloud Etc?
We have all these privilege identities on these systems 24/7 is that necessary? So let me kind of May perhaps at the risk of oversimplification. I'm a help desk person.
I'm going to be managing somebody's laptop. But my account on that laptop is always there 24/7 whether I'm accessing it today or once a month or once every week doesn't matter. I'm not obviously no help desk person.
I hope is accessing a system every few minutes. Right. So the idea is on occasional use we are over-provisioning that particular access.
We're not protecting that access adequately and therefore even if you have strong password and you know, I go back to my earlier comment where a zoom credentials are already compromised no matter how strong they are. How complex they are Etc right or if they're not compromised. There are remnants like hashes in memory that you can scrape and masquerade which is where privilege escalation comes into play.
You can masquer it as the as a super user and now you can do a lot more things in the environment much more easily, right? So the idea is that if you start thinking in those terms why is access necessary 24/7, let me peel back on that. Is there a way to solve that problem?
Is that a way to bring that and then so again, this is not easy and I think we have to think a little differently think about it this way, right? Let's kind of take this example further. You say?
Okay Help Desk person doesn't need 24/7 access on somebody's home computer or some work from home situation. You remove that access. Now people are going to wonder well, how am I ever going to manage that laptop?
Right. First of all, it's isolated whether you connect by RDP or watch you need some level of privilege, right? So and there are ways to solve that problem.
But but the thing is we have to think hard about different environments or remote systems access to our DP Cloud systems that devops are accessing through scripts and what have you that got per existing, you know, standing privileges and the credentials are perhaps embedded in a script or something like that all of those things. We just need to examine and think about how we can do this this differently in order to protect our access. And then from there you can go to endpoint and network Etc.
Do you think the bad guys are getting better at discovering and finding credentials that have privileged access and part of our issues that we're not appreciating how sophisticated they've become. Well, absolutely. I think look I mean you look at the miter attack framework and privilege escalation and because of that lateral movement becomes is the top attack Vector you look at Verizon dbbr again.
These are the popular reports. But even when we talk to customers their biggest fear is Like my somebody's going to elevate privileges in my environment because an admin logged in logged out but the remnants of his or her access is still on that system for some period of time that creates the exposure. Right and that window again speed becomes important with an attacker is opportunistic.
They will get in there will quickly look for these remnants, you know, there's hashes and memory Etc and we'll figure out a way to then go from there and all of that oftentimes happens below the radar of any detection system. Do you think that? Developers and it folks are part of the problem because it's a dirty little secret but it seems like they all have created some sort of back door into these environments that they use for shorthand.
I send to gain access to things without realizing that the bad guys are looking for that very thing. Yeah, you know, I think I would have said, you know a strong. Yes a few years ago a couple of years ago, but I think it's changing.
It's improving and I think the reason why I believe it's not of course, we're not there. This is a journey the read but I the reason I think it's improving is because I do believe and I do see Where it and devops are working much more closely with security. So previously it was like I got an IT department.
I got a secure security department and the twin shall never talk right? It's like I got my own problems. You got your own problems deal with that.
Right? But today security is everybody's problem and security teams and it teams and they're at the top of the pyramid right and then you go down to you know users that have a lot of different access and you go on to even to individual users that become the actor of attack. So but today I do see it and security and devops and devs like Ops therefore a lot more collaboration happening in that environment.
So as more responsibility for security operations shifts to it and developers take more responsibility for applications security. Is this becoming much more of a team sport file it is I think it is it absolutely it has to become that way right because security cannot be solved in isolation much like an application is not secure right out of the gate right developers have to take us a very judicious and well thought outstep before releasing their application to make sure that code is secure which and and that's why we have all these products that help you do that. They have to figure out that that the where they're getting the software from right?
This is sort of the Bill of material saw where stuff that's coming supply chain that's coming up now much more frequently. So yes security is become much more pervasive and I believe it'll become much more pervasive over the next 12 to 24 months. Us all functions within the organization but it and devops and developers leading the way.
What is your best advice to folks they kind of achieving that goal though. I just take everybody and throw them in a room and lock the door and hold rational thought prevails or is there some way to like kind of gently nudge everybody in the right direction? I think it's a little bit of both look that isn't there has to be increasing awareness that as you build this applications or as you develop your entitlements and policies of how you administer systems security has to be woven into that.
You know, it's like I'm reminded of my days working at a Manufacturing Company in my early part of my career. Of course, I was in the computer and there was this this concept of concurrent engineering meaning that whatever you build you have to make sure it's also maintainable, you know, that that certain elements of the product have to be incorporated into the design so that it's not just manufacturable is not just you know, all the widgets are going to fit properly to create the full part, but also that it is maintainable, you know, just to be called there was a particular phrase for it, but the idea here is what I'm going with this is the security has to become sort of concurrent and ing Into all of our processes whether it's developer, whether it's it's it and even line of business, right? I am I am working in my sales and Erp systems and I have to put the right kinds of checks and balances every time I'm going to issue an invoice or release a payment or access a bank account or whatever, right?
Those are normal business processes then need to inject some level of security and you know, we've been saying MFA and that's been pretty good it is so and I'm bringing up MFA as one way where this is happening much more broadly, right? It is it is a tool it's not foolproof, but it is a tool that if you put MFA in part of Erp applications, we put MFA input of it administrative access you do that in in the developer environment where access to code repositories and what have you now you building a certain level of resilience in your organization through that right? But it by itself it doesn't cut it but I'm just saying that these this is I see this sort of security being part and parcel of a variety of developer it and business processes is going to be the norm.
Otherwise, we won't be able to solve our security problems or you know And it would seem like that's the only way we're going to manage this in scale because one of the issues that we seem to be having come in Full Circle here is that there's more endpoints to secure than ever. So if we don't figure out some way to rethink the model we're never going to get there and then it's just a matter of time before something is breached. So as you kind of put all that together, do we need to kind of have a big giant off site Retreat somewhere where an organization just says.
Hey, this is our new thinking about security to everybody at the same time. Yeah. Yeah.
I I so you I agree. I mean, you know, we started this conversation or RDP and so on and those are specific items that highlight sort of either flaws in our processes or frogs in our systems. Right?
And we take that those as examples and figure out how we can then Elevate the conversation and make people more security aware security and more importantly a process. As well, so it's not just you know fishing training for employees right that it's great. But that doesn't go far enough.
Mmm starts with the people and processes as usual. Hey Raj, thanks for being on the show. Of course.
Thank you very much. Mike. Appreciate the time.
All right back to you guys in the studio.