Securing Attack Surfaces with Graph Technologies – Tal Morgenstern, Vulcan Cyber
Tal Morgenstern, co-founder of Vulcan Cyber, explains how graph technologies will play a critical role in enabling organizations to better secure ever-expanding attack surfaces that are becoming more challenging for cybersecurity professionals to discover and protect.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Tal Morgan Stern at vCAN Cyber, and we're talking about the attack surface that we need to defend and some technologies that are come down the pike that will help us figure out exactly where that attack surface is and how far has expanded since the last time we checked.
T welcome the show. Hi. Happy to be here.
Is it your sense that the bad guys are getting more sophisticated in their attacks, or is it simply a matter of our attack surface has gotten so wide that we don't have the resources to defend it all equally well, so there are just a lot more exploits and, 'cause there's tons of vulnerabilities out there, but which is it? Are the bad guys getting smarter or are we just having too much to defend? So I think it's a little bit of both.
Um, the, the smart, the, the bad guys are getting smarter for sure. Um, and you see more advanced attacks and more types of, uh, um, components that are attacked that didn't used to be attacked before. Uh, but also it's becoming very chaotic.
I, as Vulcan, we work with very large organizations. Um, the attack surface is increasing, uh, day after day, more applications, uh, more cloud infrastructure. Um, it's just getting bigger and more, more complex.
The technology is getting more complex, um, and it's harder to defend In this day and age. It's hard to believe that people are still connecting things to the internet without telling the cybersecurity folks. So what tools do the cybersecurity folks have at their disposal to kind of discover what it is that's connected to the internet?
How big is their attack surface and what they need to defend? Yeah, so that, that's, that's a tough, uh, that's a tough job. Um, coverage and managing, um, security coverage, um, and security coverage tools.
Um, that's a, that's a big, uh, big work for, uh, security teams. Um, there are many, many tools that can, uh, that can help you, um, discover assets in your, uh, in your cloud, um, on premise, um, applications. Uh, but I think that the tough job is, is making sense of this.
So you've discovered a new asset, a new application, or a new, uh, workstation or server. Then the real job starts, you know, who owns it. Um, if, uh, if there is, there are vulnerabilities or any kind of risk on it, how do you mitigate this?
Um, and kind of starting this process is, is definitely the more challenging part. I also have to figure out which one of these attack surfaces to prioritize, right? There's just too many of 'em for me as an organization to defend equally.
I think some emperor one said he defend everything, defend nothing. Um, so how do I kinda look at all this stuff and determine where should I focus my remediation efforts? So I, I think prioritization is the key today.
Um, in, in Volcan we see many organization with, um, thousands, tens of thousands and even millions of, uh, vulnerabilities, um, and risk and, and misconfiguration alerts. Um, and, and the key thing is, is to prioritize, um, and prioritization. Um, in general, I, I would, uh, I would split it to three parts.
Um, really understanding, you know, the actual technical severity, um, the, the exploitability level, and lastly, the, the business impact of the, the affected assets. Um, so gaining an understanding of these three, um, is key. Um, but today we see that even systems and, and platforms that help you do that, um, is, is not enough.
Now you guys have been driving, uh, an approach to this that's based on graph technology, which is relatively new. Um, how does this work and what exactly does it give me in terms of an advantage as, as the defender? So, yeah, that, that's something, uh, really new that Vulcan is now, uh, is now launching.
Um, the, that, the, in general, instead of, uh, looking at silos of, uh, vulnerabilities. So what you see in most tools today, or, or even, um, all the tools, is that they look at each vulnerability individually and try to prioritize this. Um, comparing to other vulnerabilities that approach is, is really how to scale.
Um, so what we did is we look at the entire environment. Uh, we build a connectivity map of all the different assets, whether they are in the cloud, um, or on premise or applications, um, and connect them all. And we put on a attacker hat and try to understand, um, if, if I'm going to attack, what is the most likely path?
So what, what's gonna happen? How will I get in? And then how will I move within the network?
Um, and with that, what vulnerabilities would I take advantage of, um, and, and exploit, um, in order to do so? And we visualize you, um, these attack paths, um, and let you prioritize them in order to remediate. And we see, uh, reduction in, uh, in scale, um, that could be, um, 10 times or even a hundred times less of, uh, of vulnerabilities, um, to actually action, um, with, so, um, that, that's, that's the key, the key part here.
It seems to me also that a lot of the time we're discovering that the same vulnerability exists in tens, maybe even hundreds of places. So can we change the way we think about remediation because now we can just go after that one vulnerability a thousand places at one time? Yeah.
Um, so it's, it's actually, it's actually both. So the, there could be the same vulnerability, um, in a thousand places, but also, uh, you can have multiple tools detecting the same vulnerability on a single asset. And that, that is also happening because you, you maybe you are scanning your network, uh, from, from an external source, maybe you're scanning it from, uh, from an internal source, um, and they both, um, are going to alert you that the same, uh, on the same vulnerability.
So a big part of this is, is also de-duping the, the information and correlating the data from, uh, for many different tools. And, and this is part of what Volcan does, Of course, these days. You can't walk down the street without somebody talking to you about their great new AI thing.
So where will AI kind of get applied to all of this from your perspective? And is there, can we save ourselves from using the machines? Yeah, that's a, that's a good thing.
So I, I, I think like, um, that, that, those two, those two parts of this, I think that like any technology company, you know, we, we also using AI for, for very long time now, but now with kind of the new L l m hype, uh, even more to, to improve the, you know, the product, uh, quality, give better descriptions, more better remediation advice, um, in, in, uh, in a better way. Um, on, on the other side, AI as, as you kind of allude to, you know, poses new risk, um, we recently released a, a research about this, about a AI package hallucinations and the fact that, um, developers may rely on, uh, on AI answers basically. And, and I think a lot of people, like if you've used chat G P T or any other, or bad, um, you sometimes you ask something and you get like a completely, uh, wrong answer.
Um, if you do that, uh, when you are planning, uh, your, your next holiday, maybe that's not too bad. Uh, but if, uh, if you are actually using code that has been generated by an AI and copy pasting this into your, uh, application, the data on goes to production, that could be a very serious impact. Um, so I, I assume that in the, in the coming, uh, in the coming weeks, um, or maybe months that to, to the most, we, we will see, um, new detection tools for, uh, for AI as well, um, as, as it happened with all the technologies, uh, we never had, um, container scanning, uh, tools, and now we have, uh, data scanning tools and, uh, um, identity and access, uh, um, vulnerabilities.
So, um, this space keeps on evolving. Do you think the bad guys are using ai? I mean, is it just kind of nation states or is this starting to be used on the other side by your everyday common cyber criminal?
Oh, for sure. We, we, we already saw some evidence on this. Um, we see phishing, you know, phishing campaigns are, are getting smart there just because you can, uh, you can have some, uh, someone write a very nice, uh, nice convincing email, um, using LLMs.
Um, and, uh, also detecting the attack surface, building more complex, uh, workflows. Um, definitely, um, the attacks attackers have started to use, uh, have, have, have used the AI to, to improve their, uh, their attack techniques. Um, I probably in the next year or so, we will see some more sophisticated attacks, you know, that that could be fingerprinted to, to ai.
Every day somebody reports some new vulnerability, and sometimes it's a big deal, and other times it's kind of this rare instance where, you know, if it's a fifth Tuesday of the month, on a rare occasion, this vulnerability may be exploited by somebody. I guess my question to you is, do we focus enough on just defending against the simple everyday vulnerabilities versus maybe spending too much time in all these unique vulnerabilities that may be not as likely to be exploited, and can we figure out, you know, some way to rank these things in a way that's meaningful? Yeah, so I think there, there's two things that the, we've been doing wrong in the industry for, uh, for a long time, and it's starting to shift, but not, not, uh, good enough.
One is relying on, you know, basic prioritization like, uh, C V Ss SS scoring and saying, okay, let's fix all our highs. And, and that would be, um, that would be good. Um, as you, as you mentioned before, um, usually it's not scalable and a lot of the time it's not effective.
There's a lot of, uh, research on the fact that, um, uh, the, like a lot of these high, high school vulnerabilities are never getting exploited. So it's, it's basically work for, uh, work for nothing. Um, and, and similarly, these, what you call celebrity, uh, vulnerabilities in, in a lot of cases, um, cannot be even exploited.
So they, they get, you know, they, they get a lot of, uh, feedback in the news, um, and they get this, uh, they get this buzz, um, but they're not, uh, not really effective to, to actually mitigate them. Um, and, and the, the, the impact, um, the impact on, on the operation could be high, uh, but the risk, the security risk is, uh, is, is could, could be very low. Um, so I, I would suggest to just, you know, examine on a, on a case by case, uh, vulnerability and really understand what's in the environment.
Um, each organization is different, uh, and you need to, you need to really know what's, what's out there. Um, and you can do this manually. You can use, you know, tools like, uh, like work kind of others to, to do this more automated in a more automated fashion.
Um, but, uh, but going one by one and, and just, uh, fixing vulnerabilities in bulk is a very ineffective, uh, process. What is your sense of the current state of the relationship between security teams and developers? We hear a lot about DevSecOps is not clear to me that we're kinda implementing that in the most efficient way possible because of what you just described.
A lot of times the developers are, uh, shall we say, cynical of the alerts that come across from the cybersecurity team. So, um, what's the state of the culture and how do we make it better? I, I've, I've been working in cybersecurity for the last, uh, 20 years.
Um, and um, it, it's like one of those things that, uh, that, that were out there from the beginning, you know, the, the developers or the DevOps, they never wanna do, um, security, security work. Um, and I think the security team need to, you know, need, need to improve on, on how we, how we communicate with the other teams in the org, um, in a way that makes sense. So, um, you know, everyone in in the organization has their, their job has the key, key role.
The security owns the risk. Um, the, the dev, they, they need to bring new features to the, to the table, the DevOps. They, they need to maintain performance and, and availability.
Um, and, and we as security practitioners, we need to help our, our fellow, uh, DevOps, um, to do their work in, in the most, uh, efficient way. So we need to focus them on, you know, the, the, the, the top priority risk, um, and give them the, the most amount of information that we can in order to, how, how should they solve these vulnerabilities, um, and, and really reduce the risk. And, and again, not not going with the spray and pray approach of, you know, just fix these a hundred vulnerabilities, uh, because then we'll generate too much, uh, too much work.
Um, and, and we are losing trust of the, of the, the DevOps team. Um, with, uh, DevSecOps, I think there's, there's been, uh, a lot of, uh, attempts to, to do something, uh, different and kind of, you know, assigning, uh, dedicated people in, in security, uh, on the, on the DevOps team. Um, I've seen, I've seen places where it works great.
Um, I've seen places where, uh, where not, not as, uh, as much, um, it really, it really depends on the, the team, the team dynamic, um, and, and also the risk appetite of the, of the organization. You know, sometimes, um, it's not the one one shoe fits all, so, right. Folks, you heard in here, there's still lots of work to be done, but it all starts with visibility.
You can't defend what you can't see. Tal thanks for being on the show. Thank you very much, Michael.
All right. And back to you guys in the studio.