Securing Cloud-Native Application Runtimes – Dror Kashti and Eyal Fisher, Sweet Security
Sweet Security CEO Dror Kashti and Eyal Fisher, chief product officer, dive into what’s needed to better secure cloud-native application runtimes following raising $12 million in seed funding to launch the company.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Jra Khi and Eyal Fisher.
They are the co-founders of a new company called Suite Security, and they're focused on cloud runtimes. And we're gonna jump into what all that means. Gentlemen, welcome to the show.
Thank you. Thank you. Thank you, Mike.
All right, Joel, let's get started with what is the problem you're trying to solve? I mean, we've had the cloud around for 10 years now or more. We've been talking about security for, uh, nine years and 364 days ever since then.
And so my first question to you is, you know, what's left to solve and why haven't we solved it already? Well, look, uh, there is a very good solution for the cloud, but there is just, I think, one main gap regards to detection and response in runtime on the cloud. You know, it used to be the cso, the chief security of the I D F.
It means that I was the c o of, of our nation. And I, we, I have the responsibility. I had the responsibility to go to a huge program called Nimbus, and I look for a good tools to do the detection and response in runtime on the public cloud.
And I couldn't find anything, something in the short responsibility between, you know, the government or the people and the vendor, the, the public cloud vendor. You know, that if someone will try to breach into the infrastructure, it's the cloud vendor responsible. If, if, and if you, uh, uh, don't, uh, put a good programmer, it's your responsibility.
But something, the shared responsibility, if someone and wants to assume that some someone will, uh, uh, breach into your environment. I look for a good tools and I couldn't find anything. No good tools doing the detection response on the runtime, eh, on the cloud.
So this is the my pain, my personal pain. And when I retired, I try, I, I, I, uh, told myself I must solve this problem. And I called my co-founder, tell him, let's do this.
So yal, how did we solve this problem? Because, um, to Drew's point, we have this shared responsibility model. And sometimes I feel if it's a shared responsibility, it means nobody's responsible for it.
So how do we take control of this thing? Exactly. So, um, so that's, uh, our, our unique approach.
We take into consideration the fact that in Nat, that that native AppSec that are running on cloud are actually applications and not just, uh, computers connected to a, a network. So we take that into a consideration, and we built, uh, a solution built specifically for that scenario, cloud native AppSec. And, uh, uh, we have a, a unique, um, mechanism, uh, uh, that, uh, eh, auto learns your environment, the application, and, uh, detect abnormalities that ha that are happening.
So, uh, so, um, it, nothing is going to to fall between, you know, uh, responsibilities. It's not just the cloud. It's not just a programmer.
It's our responsibility to understand what is running on the cloud and when something weird is happening. So draw, I think part of the issue that we've had all these years is we've tried to lift and shift an on-premise security model into the cloud, and it doesn't really work. And it takes a while for us to all figure that out.
I'm not sure why, but it seems to be the case. So what have you seen, what's your best advice to folks about how to kind of make that transition? 'cause it seems it's as much a cultural issue as it is a technical issue.
So yes, as you mentioned, I really believe to go to the public cloud, but I don't call it, uh, a lift and shift. I call it lift, adapt, and shift. This is what you should, should do.
And I did it for many years in the, in the I D F, you know, uh, there is many advantage going to the public cloud, uh, very good, even in the security essence. But you must adapt your solution to the cloud. It's not just to lift and shift, it's to adapt it to, uh, enable your, uh, uh, from your, the site, from the development through the application to, to the new, uh, environment, to the cloud environment.
And you could, you can't just take, uh, your legacy and put it in the cloud because you lose and you can't stand in the then the on-prem solution. You must take it, adapt it, and move it to the cloud. Yeah.
What makes cloud native applications different? I mean, in some ways we, going back to the lift and ship thing, we took virtual machines and put 'em on a cloud and called it something different than a on-premise environment, but it just seemed like it was, we were moving r m ss from our data center to somebody else's cloud native AppSec or containers, Kubernetes. What makes that more challenging from a SEC security perspective?
So the, the, the main, uh, issue is that the attack surface is huge. I mean, you have now microservices, each one can be, you know, an entry point to your environment. Uh, so it's a lot more complicated.
Uh, when, when, uh, when a server just moved to the cloud at the end, it's the same server. You can protect it the same way you did. Now you have piece of, uh, uh, software, many pieces running in, in various places connected to each other, connected to the world, running a library that you don't, I mean, this security team might not even be aware of the way everything works.
So it's a lot more complicated environment to protect, and that's the main difference. Jora, How smart are the bad guys getting about all this stuff? I mean, are they targeting these applications more?
Are they looking for Kubernetes and containers? Sometimes I talk to developers and they're like, my container's only gonna run for a few seconds. What could happen?
So not can run, come in a few seconds. First of all, the attacker became, uh, most matters. And, uh, there is a, the supply chain, uh, attack that goes through, uh, into your container.
And, uh, it'll be always vulnerability in your code. Always. You can't, uh, you must assume that it'll be breach.
So you, there it can be container or, uh, microservices. Uh, the attack surface is huge. And, uh, I, I believe, and I see in my eyes, I saw it in my eyes that the attacker will be there.
Uh, they change. It's not the same attack that it was in the endpoint and OnPrem, uh, and the endpoint, uh, attack because you don't, you know, you don't need to do the lateral movement or other thing. You just attack breach into the container.
And then from there, you can take everything you want. So I think it's different attack, different way of attack, but they with, uh, a large, huge volume and a huge space, but it'll be attack. Yeah, I'm not sure everybody takes all this stuff seriously enough because they're basically think that their worst thing that happens is there's some crypto jacking, somebody comes along and steals some C P U power, and some people even consider that a nuisance crime.
But, um, do we need to take this more seriously and why? Yeah, we, um, we already have seen a few attacks that, uh, that, uh, um, made, uh, a huge, uh, um, quite a disasters for, for some organizations that data can, can be leaked out of organizations e easily. And, uh, if your production environment is on cloud, I mean, you will probably would like to make sure that, uh, it's going to, uh, continue working, uh, uh, without any, uh, interruption.
So if, if a, an attacker can make your, can, can cause you a downtime, for example, for your environment, that's, that's a huge problem. So, uh, so there are various ways in which attackers can actually harm organization organizations quite easily in, in, in cloud environments. Actually, it's going to be even more easy for them than they used to do it, uh, on, on-prem environment when they need to harm many computers to do to, to, uh, a store said, uh, to do the lateral movement, get to to many endpoints, go to your servers, find the backups and and so on.
Now you have production environment that can be down in, in, you know, in no time. Sure. Why don't the cloud service providers do more about this?
I think a lot of developers assume that the cloud service providers are doing more than they are, and maybe someday they will, or is that not likely to happen just because it's, well, they don't wanna be responsible for this First, I think that the service provider are doing better, and they have, they do the security job, but you always need to, uh, protect your environment. You can use some of the, these tools, but you must build an autonomous tools that is under your responsibility. And as a cso, you could, you could, you cannot, you couldn't just trust, uh, the, uh, service provider.
You need something that you under your responsibility to do it. So I think that are good tools of this provider security tools, but just a lack of the responsibility of you to, to use your tools in order to protect the environment. Yeah.
I can't walk down the street without somebody leaping out to tell you about their great new AI thing. So my question to you is, at some point, is AI gonna save us from ourselves here? Uh, so, uh, for, for AI to help us in, in, you know, in, in cloud security, I think that first we need to do it our ourselves, you know, uh, and, and AI is going to come just, uh, afterwards, uh, yet, uh, we can, uh, uh, utilize AI technology, uh, even now, uh, in order to understand, uh, for example, what should be, uh, the next step after we found everything that happened in, in a, in a bridge or an attack, uh, recommendations for next steps, uh, remediation and stuff like that, that can help because you have the history in order for the AI to learn from it.
And then, you know, you get a good, uh, you might get good recommendations, uh, for next steps. So that's where I see ai, uh, come, uh, um, uh, into that area. Your, what's your best advice for folks, especially CISO that are looking at all this stuff, and they might not be conversing in cloud native, they might not even know what the cloud is per se.
So how do they proceed down and have this conversation in a way that makes them credible? Well, first, I think that you must learn and adopt the new, uh, technology and, uh, always learn and adapt it. And second, from my perspective, from my perspective, I think that you to, in order to make a good, uh, difference, you must have, I call it boots on the cloud.
You can't just, you know, uh, go up and, uh, believe that everything will be in your logs or believe that the provider, the service provider will give you the security. You must, I call it ev uh, boots on the cloud in order to fill it, know everything that going over there, uh, and, uh, can, uh, detect and, uh, uh, response to the attackers. All right.
Speaking of boots on the cloud. Yeah. What's that one thing you see customers and security teams doing that just makes you shake your head and go, folks, we need to be better than that.
Yeah, so maybe the one thing that, uh, we see all the time is that SOC teams, uh, need to adapt as well. It's not just, you know, the, the r and d uh, that adapted to cloud nicely and, uh, uh, you, you need also your soc team to get used to protect cloud environments. And, uh, and usually it, uh, it doesn't happen.
So you, you, you have a, a very, uh, expensive SOC team protecting your not so important stuff in, in, in the organization. And that's quite a, a quite a challenge because you need to, uh, upgrade, uh, the knowledge and you need to give them the tools. So that's what we are trying to do to make sure that the SOC team will have the visibility to the cloud environment and will get the, uh, important stuff that is needed in order to understand that you got bridged and how to get out of it.
So that's, uh, All right, folks. You heard it here. Cloud native security is a whole new ballgame.
Don't bring your prejudices and biases to this whole area because what you used to know probably doesn't apply. Gentlemen, thanks for being on the show. Thank you.
Thank you. It was a pleasure. All right.
And back to you guys in the studio.