Security for the Atomized Network – Martin Roesch, Netography
Netography is the only company that delivers Security for the Atomized Network. In the Atomized Network, applications and data are scattered across a complex environment consisting of multi-cloud, on-premise, and legacy infrastructure, all being accessed by increasingly mobile and remote workers.
Transcript
This is texturing TV. Hey everyone, welcome to another texture on TV interview. I I'm I've been waiting for this interview probably going on eight nine months now ever since I found out that he was back, you know in the security space.
I want to introduce you to someone I've had the pleasure of knowing for a really long time now probably 20 years or something like that. It's Martin roach. For those of you who are maybe from my devops crowd or not security people and not familiar with with Martin Martin basically invented the IDS open source idea snort that's in no RT.
I think you Martin we still working at the government at that point for the US government or is this after? Yeah, I was I was a contractor at the time and yeah, my day job was doing stuff on government contracts. Yep, and then you know He then founded sourcefire, which was kind of a vehicle built around snort initially, but then it became so much more clam AV was added as the world move from ideas to IPS and then UTM and everything else sorts fire grew along with we didn't even call it cyber security.
Then we called it info SEC it's security but sourcefire grew with that and eventually was sold to Cisco where Martin stayed through there for a bit, but then you kind of left this go and you know, we didn't I didn't hear from you for I didn't see you out on you know on the on the webs as much. And now you've you've come back with a vengeance here with nitrography. I don't hope I didn't embarrass you by any of this but So Martin first of all, welcome and thanks for being here.
Second of all, tell us about netography. Okay. Wow, so natography, you know, it's it's interesting.
I did come back. I took some time off post Cisco and you know went out and enjoyed myself for a little bit till the pandemic hit and then you know much like everybody else. I found myself sitting around the house a lot and thinking about what I was gonna do with my time.
So I've been advising a number of companies number startups and including natography since about 2019 and the company had gotten to a point where they were ready to really start pushing the product out building out go to market and you know Marketing sales operations Finance all the other stuff and the co-founder CEO Company Barrett Lyon asked if I would like to come on the show, so what natography was doing was a flow based analytics platform that was essentially giving you this this view into what was going on in your Cloud environment as well as in your on-prem environment, but all Under One Roof, so you didn't have to do anything fancy to make it work. In fact, it's the most frictionless network security technology that I've ever seen because it's all sass it's all cloud-based. So there's nothing to deploy no Hardware no software anything like that.
So, you know, but it's it's meditated analysis, you know, I've built my career doing Deepak and inspection. So there was always kind of this this Great Divide between the metadata guys and the Deepak inspection guys because Deepak inspection is High Fidelity very finicky. Now tuning rules and stuff like that on one hand, but it's very precise.
It can be very precise on the other hand. If you know what you're doing and then on the metadata side you get a much broader view of what's going on in your ability to deploy and follow what's happening is is greatly expanded because it's not a sensory based architecture necessarily it's you know, it can be done in a number of ways. So anyway, I spent a little time coming in high about you know, do I want to cross the divide and go into the metadata side and I asked for the competitive Intel now at the time the company was kind of styling self as a new way of doing ndr Network detection and response which is kind of the the second coming of intrusion detection.
I guess you would say and I asked Barrett to give me the competitive Intel that he had on, you know, the other company is that we're doing ndr. I look through it and I was like, holy cow. Everybody is still doing Deepak and inspection and everybody believe it.
Yeah, right. Everybody's still doing Appliance architectures. It's like Oil networks are becoming increasingly encrypted.
You know, we saw this all the way back in the source fire days and at Cisco it was turning into a problem. So, you know, like five years ago. So, you know move forward five years and Deepak an inspection architectures are going to be really problematic especially given how much money you have to spend to deploy them and get clear text packets to them essentially.
So then re-encrypted to send that traffic to destination. Yeah reduce some sort of weird. You got to keep getting bigger and bigger machines at the edge to grab it whether you decrypted at that machine or up in the cloud and send the fact.
Yeah. It's it's l capital for latency, but good. So because you know because once again, I you know, spent 20 years plus building and so that was an issue and then the appliance architectures that they were almost an issue.
It's like science don't really translate to the cloud World very well at all and Appliance architectures. Got this life cycle management curation thing that's got to be done. It's just it's really clunky in this world that we're in now.
So I was like, you know what this is like there's big opportunity here. Nobody's on the right architecture except us. So all we have to do is is stay smart and keep you know pushing and we're gonna be well positioned in space.
So that was the thing that got me to join and then once I got on board something else happened, I started talking it like customers and Prospects and I started hearing the same thing over and over again, you know, since the pandemic we're multicloud hybrid Cloud was on Prem infrastructure still and mobile remote workforces are hybrid work for us tonight. I heard it this many times. I started kind of putting the pieces together and I said, you know, what like up until the pandemic hit like moving to the cloud for most Enterprises was kind of this early transition, right?
We had a program. It's like we're gonna decommission the data center in Chicago, we're gonna move it to the cloud and we're gonna move these applications. So, you know people came up with plans or committees and all Stuff another pandemic hit and it just blew up overnight because everybody got sent home and you have these massive Enterprises with tens of thousands of workers.
Everybody is at home. They got one job right one rule, you know one order from on high which is just get your job done. So what do they do?
They go out stand up Cloud infrastructure everywhere across all the major Cloud providers. But there's nobody. In the buildings to decommission the on-premit infrastructure anymore and you can't stand up new stuff in the out-prem infrastructure either.
So what do they do? They start building dependencies between it all as well, right? So all sudden this this very distributed hybrid multi-cloud architecture gets cemented in place due to these dependencies.
And I started hearing this and I was like, it's like your networks of atomized isn't it? It's like you got Adams of presence atoms of compute that are scattered across all these different Cloud providers and in your on-prem infrastructure and all your atoms of users that are scattered out to the Four Winds where you were home and Starbucks and wherever they happen to be and you know, everybody's head started going up and down. I was like, this is something new there's something new here and what it is as I kind of like wound back a little bit.
I started thinking about it just kind of two classes of vendors out there, right? There's the the hard work guys The Appliance Guys, you know, Cisco Palo Alto FireEye checkpoint whatever, you know, and that is kind of the foundations of the security industry and a lot of ways but as they've tried to stay relevant to the cloud, they either acquire Cloud vendors or they roll out Cloud appliances. Of course, once again, nobody loves a cloud Appliance right people want to use the native capabilities of the cloud, right?
So, You've got kind of an oxymoron. Yeah, you architecture is he's kind of tortured architectures that results because we're trying to you know, still be an appliance vendor on the one hand. Then you got the pier cloud guys.
And that's all they do. They don't even think about your on-prem infrastructure anymore. So what you end up was you got these massive gaps between all the solutions that are out there.
You know, I would say attackers live in the gas. So by building this very gappy architecture that doesn't integrate very well together and you know, just dump it all in the Splunk and crossing your fingers isn't really a solution. It's expensive.
Try though. Yeah, right. I mean, you know, I don't expect a lot of value out of Splunk.
So I'm not saying they don't it is powerful, but that's that's a tough way to live. So as I started looking at it and I looked at what photography is that bill I said guys we are security atomized network. That's us because we don't care where you happen to be on-prem or in any of the clouds and it all is the same to us.
We're meta Platform right? We just operate on metadata and we are pure sasp base. So like you turn it on you have sample account you point your sources at us and we start telling you what you've got what it's doing.
What's happening to it straight up right each one of those buckets those three buckets you you know take the lid off. There's a lot under each one like telling you what you've got in a atomized Enterprise or across anonymized network is actually pretty complicated could be, you know could be a factory floor could be a data center could be a bunch of cloud apps. So actually the question of what I have and we hear this over and over again, we're blind right we move to the cloud now, we're blind the tools aren't there and we try to use the native tools that the cloud providers give us but really can't tell what's going on.
We certainly can't see who's talking to who especially because everybody's built these dependencies between all the stuff that they've got out there like cross Cloud traffic and things like that. So we are built for that World by hooker by crook like, you know, it's almost like it's almost like snorting away in that. The guys who built this Barrett and Dan and the natography engineering team.
They built the thing that they thought was right just like I built the thing that I thought was right 20 plus years ago and it happened. You know, it was it was the technology for the moment like and you know, here we are 20 something years later stores still very relevant very widely deployed at the core of billions of dollars business Cisco certainly, but this is a new architecture for the world as it is and is going to be not an architecture for the world as it was and what you've got out there and a lot of ways from the major vendors is architectures for the world. That was so that's you know, that's why I'm super like I get up every day.
I know I've got a cool technology platform. It's it's built for the world now and the world that we're going into and there's lots of stuff that we can do here and you know as I think about security for the itemized Network, you know, which is our our tagline. There's more that we can do here, right?
So we're a visibility control platform, you know, and kind of the Big sense of you know visibility show me everything that you can show me control. Let me control the things. I understand I kind of stuff but there's there's more to be done here this This atomized network problem is a problem of the scope of architecture that a company builds to control these atomized networks.
And if it's you know Legacy architecture that's trying to be extended to the to the new world or a new world architecture that forgets about the old world. I think there's you know, there's this this middle area where you you contemplate and and can manage both sides of the world. So anyway, that's that's what we're up to here.
Absolutely, you know. Let me put my two cents in on this Marty. One of the problems historically with security is we're kind of like the French and World War Two.
We're always looking to fight the last war. Or we're looking to fight the next one with the last words technology or tactics. and you know what it took us as an industry a long time to wrap our heads around cloud.
Right because we we had this Moten Castle perimeter inline at a band heuristic. I mean you, you know better than anyone. Right what we were all about and and we we have now we we now see Cloud Security in its own.
Light being effective guardrails for developers the shift left the devsecops all of the identity and access control and all all of you know these kinds of things. And just and this is the way life is right just one we're starting to get our heads around this this the pandemic comes that kind of scrambled because we accelerated digital transformation. We accelerated Cloud migration.
But as you said, it was really smooth. It's a little lumpy right? We still got some stuff here.
We got some stuff there. We got something. But in my mind, we are also at the same time on a general one of these generational changes of hey, the cloud is the cloud it's not going anywhere the data center.
We decommissioned some of them, but we still have a lot of stuff in data centers. But this do anything from anywhere movement that covid kind of. gave birth to or at least accelerated right has also accelerated this Edge Computing, right and and you got 5G kind of, you know, powering that up and and the edge and and iot connected devices and and points anywhere.
So now you know, you want to talk about was chaos before it's it's Mega chaos now, right? Yeah you get another front. That when we talk about something like an atomized Network, you gotta you got to kind of normalize all this right.
You got to equalize all of them and lay down a security blanket or you know, some sort of insight. To all of that, right? It can't be a bunch of unique things.
Right? No, you can operate on so, you know, one of the things that we did this is actually a riff on how we did Enterprise section response back in the sourcefire days where we had a cloud-based detection back and that we could you know, update the back end once and our entire deployed footprint of EDR Tech, you know connectors became smart about it. We're doing the same thing here right wants to detect everywhere kind of architectural backend approach.
And that means you have to consider everything is being the same right? So that's what we do is we aggregate all the data together we enrich it be all this stuff and then you know, we run it through our real-time detection models and you know, we see all sorts of interesting stuff. But the thing is is I don't care if if you're on-prem, I don't care if you're at Starbucks, I don't care if you're in the cloud in oracle's cloud or you know Amazon's closet.
It's it's all the same to us. So and we make it all the same. We make it look and feel the same so that you know, you can operate on one thing and you don't care about encryption anymore because you know, we're operating above that level.
So, you know, one of the things that you have, you know, so almost like one of these things for you know, the first step to getting better is admitting you've got a problem and the first step here is admitting hey, you know, what packets like packet says the coin of the realm for doing network security they're going away and like We've admitted it like internally we talked about we live off the land and living off. The land meet means packets aren't available anymore living off. The land is the data types that are available, you know and everything speaks flow the clouds speak flow all the infrastructure speech flow.
So that's what our our corner of the realm is. And you know, that's going to be you know, if you learned to operate on that that's immune to kind of some of these Mega trends like zero trust encryption of everything. Yeah.
Yeah. Let's talk a little bit about metadata. if you don't mind right for our audience out here who maybe is not a you know, our audience is pretty diverse.
We get devops Cloud native cyber digital transformation. That's kind of the audience. Everyone's heard the term metadata, there's metadata and everything right binaries and so forth, but in terms of security, how do you turn how do you weaponize metadata?
And I know me from the bad. I mean weaponized metadata for the good as a security tool. Well, okay, so there's there's a few ways to go about it.
So one of the ways for like people who don't swim in this pool every day, I don't know the ways to think about it is, you know, if you look at intelligence agencies, it's kind of informative and what I mean by that is, you know, we have organizations like the NSA and their job is to crack codes to keep track of who's talking who and things like that. Well as we all know if you know really studied up on encryption a properly implemented one-time pad system is effectively unbreakable with current technologies that are out there. So Oliver adversaries know that we know this so, you know their levels of encryption that just can't be broken and we've known this since the you know, the 40s and 50s.
So one of the things that the US intelligence apparatus does is tracks metadata who's talking to who and how much and how does that change? What are the behaviors of these operators and these, you know control points and stuff like that. So, you know if we all sudden see headquarters calling red Fleet headquarters You know while a an international incident is going on that we know who okay.
Well, you know, they're they're preparing their Fleet juice something. We don't necessarily know what but let's pay attention to the harbors and see what's going on. This is kind of you know of the same elk.
So we're admitting hey, you know what network traffic's encrypted now, so let's look at who's communicating and how they're communicating and how their behaviors are normal and how they change and so it's not just a behavioral system. It's not just a not only detecting system. We can characterize very specific things.
We can look for very specific things. We can also bring contacts to the table as well. So if I know things about a network like, you know, The you know, whatever.
This is. These are the phones the desk phones and everybody's you know, and everybody's desk in the offices. We don't go to anymore.
If I ever see a desk phone talking to something that's not a PBX like that's a problem and that's that's very deterministic. It's behavioral. I know the behaviors of this thing should be but it's very deterministic search in that.
Hey look never does something. That's not this that's a problem. So metadata is all about kind of defining the operational footprint of organization.
It's behaviors and being able to look for anomalies outside of that and things like that. So it's not pretty at the next level over kind of the raw data essentially. So anytime you're doing context-driven security any time you're doing behavioral analysis anomaly detection and things like that those all operate off of this this notion of what is the the metadata that I can get about this environment and we did this all the way back into the you know into the old days the source for our days where we characterize the networks that we're defending with our intrusion detection and prevention.
So we can make the the IDS IPS engine smarter about their environment. So they were harder to evade and they gave us more valuable information. You know kind of reminds me that want to bring it up as a throw point.
But remember the Ron and the tenable would had passive vulnerability scanning. They called it. Yeah, I think Source fire had a similar kind of Technology.
We would just listening and based upon what you were hearing. You were able to make some assumptions that you know would help you sharpen up what what's there but you know the beautiful thing about the metadata model is The more the more meta data it collects the more accurate and better it becomes. right, and and so You know, it's almost like continuously self-improving if you will getting sharp or get learning better.
Yeah, yes have these the data sets, you know this kind of confirmatory and discomfirmatory information being able to model all that out things like that. So that technology is Source fire that did the passive mapping stuff like that. I build the Prototype of it and then we hearted a team to turn it into a product.
And yeah, I understand the problem really well and it's a it's very interesting problem letting the network tell you about itself and then like taking that information and building into models that you operate on is is one of the kind of metadata e things that you do. Yeah. So let me let me get business here a little bit here organizations people watching this their organizations.
Maybe they want to take a look at this. How is it kind of packaged sold? How did they engage engaging is?
Super simple? You can go to our website and say please give me a demo and you'll be contacted. So it's really simple.
We're we strive to make our engagement processes low friction as possible trying this technology out is oh if you have the passwords for your switch router firewall load balancer, whatever your on-prem flow generation technology. So any piece of network infrastructure basically capable of generating flow, or if you have in any of the major clouds so Azure AWS gcp IBM Oracle, they all generate flow records, too. So you can turn on Flow collection set Three bucket and point us at that and you're up and running we stand up an account.
You tell us where the flow sources are flow starts coming in you're in business. I mean deployment of this technology can usually be done like initial deployment could be done and getting value from it in less than 30 minutes and we've seen this over and over again. It's crazy fast compared to the Appliance days.
And the other cool thing about it is that you know, if you do deploy it like in Earnest as a deployment, it's subscription base sales. So it's based on number flows per second. We're going to ingest and how long we're gonna retain the data.
So that's what the pricing model is around. So it's essentially a usage based model, but the really neat thing about it is if you have something if you have a little excess capacity and your subscription and you want to go see something that you currently don't have visibility into say, you know, you're threat hunting with the product what you can do and you see an attack or go some place on your you know, your atomized network that you're not currently monitoring. You just spin it up.
It's not like geez we got to ship. Appliance to Buenos areas and it's going to take a month to get through customs and we got a fly guy down there and get commissioned and plugged into the Matrix and stuff like that. It's not like that at all but our stuff you want to see buenoseries.
Turn it on. That's it. It's been literally minutes.
It's very close. One of the things that gets me the most excited about it because it's like you can like in the appliance days. You can follow anything if you weren't set up for something you're done.
I'm just there. Yeah, we can follow the attackers and it's really it's really cool and Powerful it lets you do things that we never even thought about doing in the past and also the right ones to detect everywhere back and you know, if you figure out something you're interested in you just deploy it and your entire infrastructure. It's not like you deploy it into a management platform and schedule a deploy out to your sensing infrastructure and it takes yeah hours or days to get it all out there.
It's like update once boom everything smart now, so it's it's really cool. But we're we're super easy to work with, you know, we've got a Team here very experienced team and a lot of familiar names and faces on that team exactly. Yeah, you know a lot of people there and yeah, if you click give me a demo on the website, somebody will contact you we can do a demo for you.
We can actually the demos so we usually if you have the username and password for something generating flow that you can stand up we can actually stand up and account for you and get you on board so you can see the product with your own data in a one hour demo. Fantastic, man. Hey Marty, it's great.
It's great. It's great having you back first of all, but it's also great having you here on Tech strong. Just one last thing people watching this, you know black cats coming up in probably another week or two from when you're seeing this.
I know you guys are at blackhat doing meetings. And I guess I'm also whatever. So if you if you are going to Black Cat and you want to check out nitrography, I suggest you go over there tonight.
I think you can request a meeting or meeting, you know, and in person as well. Yeah, absolutely. We're also having a cocktail party on Wednesday night.
So if you go to our booth or if you click on our website, you can sign up for the party. fantastic Martin Look, this is the first time you're on since netography. Don't be a stranger come back and keep us posted.
Okay? Absolutely. Love to Allen you yeah, I really appreciate that.
It's good talkery great having yarn man, Martin roach CEO nitrography masters of the atomized network and metadata. com. We're gonna take a break and we'll be right back here on Tech strong TV.