Why Your DDoS Defenses Are Failing
Every damaging DDoS attack today traces back to one root cause — a configuration vulnerability in defenses that were supposed to work. Matthew Andriani, Founder and CEO of MazeBolt, sits down with Alan Shimel on Techstrong TV to share what nearly two decades inside the DDoS industry — first at Checkpoint and Radware’s emergency response team, now leading MazeBolt — has taught him about why point-in-time red team tests aren’t enough. Matthew breaks down why an enterprise environment with just 100 services has at least 15,000 attack points, why MazeBolt’s data shows a 37% average configuration gap across vendors like Akamai, Cloudflare, Imperva, and Radware, and how RADAR continuously validates DDoS defenses without disruption. He also unpacks how attackers are using AI for orchestrated and generated attacks, and why per-environment vulnerability data is the missing layer that lets defensive AI actually work.
Transcript
Hey everyone. Welcome back here to Techstrong TV. Let me introduce you to my next guest.
His name is Matthew Andriani. Matthew joins us today from Israel. Matthew, it's great to have you on.
Welcome to Techstrong TV. Thank you, Alan. Good to be here.
Great to be speaking to you today, and I'm happy to do this interview with you. I'm looking forward to it, actually. For those who want to know, Matthew's the founder, CEO of MazeBolt.
But first, let's talk a little bit about you. We were talking off camera, people want to know who they're talking to. Give our audience a sense of your journey.
Thanks, Alan. So I've come through an interesting path, I think. I've been in some of the more legacy companies in Israel, like Check Point.
Originally, I was there for four years. I then continued, I actually got into image recognition for a little while, which was a long time, more than a decade ago now, where we were identifying images within images. Then kind of the last company I worked at before founding MazeBolt was Radware.
Radware- Sure ... is a well-known DDoS mitigation company, right? Mm-hmm.
They were also load balancing, but I think they probably, at the time, in around 2010, 2012, had the top mitigation technology in the market. They still have very good technology. And I went there and was part of a transition from a research team.
We pretty much got everything that was security related, Radware was just getting into that security space, and it eventually transitioned into an emergency response team. So it started more as a research team, and then transitioned into a fully dedicated emergency response team, kind of from IDS, IPS into full-blown DDoS. There was some malware analysis at the time connected to that.
Then it got into a full-blown emergency response team because that started to become the cash cow in the company. And I got an incredible amount of experience in the DDoS space at that time, seeing real attacks. We were responding to some of the best-protected organizations in the world.
And I was seeing again and again and again, we got involved when the technology didn't automatically block, right? So a customer purchased the Radware product, and the attack got through. They were taken down, and then it was our job to come in and make sure that that attack is mitigated in real time.
So I was involved with companies at the time like the largest religious institution in Europe, some of the largest e-commerce companies around, like eBay and these were just massive organizations leveraging our technology at the time. So that's my background. I think seeing all of these successful attacks and looking at how these attacks happened, it always came back to the same thing.
Almost every attack that I can remember could have been prevented had the organization known what to block, before. Because we always came in and were able to mitigate that attack, but the organization had no data to show how that attack would get through if that attack arrived. So these were known attack vectors getting through configured DDoS protection systems, crippling large organizations.
And after I saw a couple of hundred of these events, I essentially went and founded MazeBolt, pretty much around 2013. Got it. So this is another overnight sensation.
Right? Well, I wouldn't say it's overnight. We started off as more of an offensive cyber company dealing with a lot of- Ah, okay.
So you pivoted a little bit ... in 2021, we were dealing with a lot of red team DDoS testing. Mm-hmm.
But other things, we were doing other things, too. But very quickly, again, the majority of our business was coming from DDoS testing, from traditional point-in-time red team DDoS testing. And we weren't able to help our customers.
So our customers have essentially, over 87% in the BFSI space, banking, financial service industry space. Sure. So we've got customers that are banks, insurance companies, credit card, payment processors.
So in that industry, downtime isn't an option, very risk averse. We were working with payment processors there and credit card companies that were under severe attack, and government, that were under severe attack at the time. We were doing their red team testing for them.
I'm talking around, I don't know, 2016, 2017. I don't know how much you know about a red team test, but this is a point-in-time test that you need a maintenance window. Sure.
We were convinced we had the best kind of testing at the time, and if we close these issues, we're going to solve their problem. And bam, the customer came down again. What we understood is that we're actually training the teams.
Yeah, we found some issues, but how many simulations did we run? We ran maybe 10, 15, 20, 30 simulations over some maintenance window period. And even though we closed those issues, the company came down again, and we realized what we were training the team to do is actually how to handle a damaging attack.
We were not really improving their resilience posture. We were improving their human procedural and response handling to a damaging event. That realization took a little bit of time because in order for us to understand that, we had to see that these companies still got damaged once we had done these great red team tests that we thought we had done great.
Then we realized, hey, the attack surface is so large, you need to be able to scrutinize all of your defenses and controls on your attack surface, and there wasn't a technology out there to do that. Absolutely. And this was the opportunity.
What we understood at the time is that in order to actually mitigate an attack, every single attack we had seen and the reason for the damage was always because of a configuration issue in the defenses. An organization today cannot have a damaging attack if the defenses are working in DDoS. There is no software vulnerability in DDoS.
The vulnerability is in the defense of Akamai, of Amazon, of Radware- Radware ... of Incapa, whoever it is, Cloudflare. They all have the same problem where they've deployed these defenses, but the proof that these defenses work just isn't there.
And actually, an attacker today in a relatively small environment with just 100 services, enterprise environment with 100 services running, has a minimum of 15,000 potential attack points. Now, traditional methods couldn't find out if those points would actually work when under attack. That data doesn't exist.
And the only reason you have a damaging attack is when one of those points aren't protected properly, you go down emergency response and so on and so forth. That's why you see organizations like Akamai with SOC teams of 300 people, 350 people, all these large SOC teams. Because when the technology doesn't work, you need a great team to come and bring you back up.
Of course, those manual processes, by their very nature, indicate that you've had a damaging attack, right? So what Radar does is it's a-- what our product does today is it's a validation layer that scrutinizes all of those potential entry points and gives you that proof and allows you to manage that risk in an ongoing way by de-risking based on that data. That vulnerability is the only way you can suffer an attack today.
If you think about an Akamai customer or a Radware customer or any of these vendors, without pointing a particular one, the only reason the customer has a damaging attack is because the vendor didn't mitigate it. The vendor doesn't go down, the end customer goes down. Web goes down.
Right. Get it. I get it.
Yeah, actually, the Akamai DDoS team was based down here in Florida because they had acquired, I forgot the name of the company they acquired years ago. Prolexic. Prolexic, right.
Prolexic. So, by the way, Prolexic, I was actually very involved in getting Radware technology working in Prolexic at the time many years ago. Really?
They were very heavily-- Keep in mind, Prolexic was one of the first scrubbing centers around. So at the beginning, now everything is always on, and you're always going through protection. But back then, they had something called on-demand, and our technology had to be kind of re-engineered to work in this on-demand to learn immediately what's going on.
So I was actually very involved in Prolexic at the very beginning when they were- Yeah, no, I had a lot of friends, actually, still have friends who are at Akamai now, in the SOC there and everything else. But Matthew, I want to turn the conversation to AI. AI's kind of really blown up on both sides of this issue, right?
The bad guys are using AI to do better DDoS attacks, more targeted, they don't need to take over 50 million bots or zombie machines or IoT devices, right, to flood. They're much more insidious, much more effective. At the same time, and this is the story in AI, the two-edged sword, right?
The promise of using it to help us defend against DDoS attacks is there as well. Right. How's this playing out for your company and what you guys are doing?
So I think, AI, of course, it depends on the area you're looking at. Like Mythos, I think, highlighted the problem in cyber in general with AI at such a big public event. But they're very focused on the software vulnerabilities, of course.
Yeah, there, it's finding vulnerabilities. Correct, in the software. So what we do is we kind of are the Mythos of the DDoS world, where we need to find the vulnerabilities actually in the defenses that you've deployed.
So if you've got DDoS defenses, the only reason you can suffer a damaging attack is because of a vulnerability in those defenses. You have nothing to do with your software. That's where you're finding them.
Right. So we've got well over a million data points to date of how all these vendors are actually protecting their customers in the wild. We're able to understand how to best find those in your large attack surface as quickly as possible in order to get you the relevant data to start patching those problems in your defenses.
And I think the thing, AI in the DDoS world, of course, in the world in general, AI has transformed everything, whether it's your marketing, just everything as a company. But in the DDoS world, I think what it's really changed, the fundamental problem hasn't changed. You don't have visibility on your defenses.
You don't know if your defense works. You've got no proof to show that your defense will work. Now, that basic problem hasn't changed.
What has changed is we see roughly a 37% on average Gap in your configuration, meaning 37% of the attacks we will launch will get through your configurations. Now, that's one in three attacks randomly launched, and I'm going to get through. Now, if you've got AI, I would split AI into two clear categories.
You've got AI orchestration, and you've got AI generation. So you've got generated attacks and you've got orchestrated attacks. Orchestrated means I'm a bad guy, if we look at it from the bad guy side.
I go attack an organization, a small bank. I go attack an e-commerce. I go and I do my attacks with my botnet.
I have a model learning what I'm doing, how I'm attacking, when it's working, when it doesn't work. My model's getting trained. When I've trained the model on the method and how my approach to attacking an organization is working, my model now starts to learn in terms of the orchestration, the coordination of how this is working to succeed.
So now, instead of me clicking attack with that group, attack with that group, try this, try that, check monitoring, whatever, as an attacker, my model's learned enough to pick a target, push play, and the AI is going to be very effective in getting through there now and going to get creative with taking your organization down with known attack vectors. I don't need an AI-generated attack vector because there's a huge vulnerability already in your defense today that you probably haven't closed if you're not using a product like Radar. Got it.
So now when you bring AI-generated into the picture, now you as an organization, as a bank, as an insurance company, as a payment processor, e-commerce, whatever you are, you're now purchasing a whole lot of new AI defense. You now bought from Cloudflare or from Radware, the new greatest shiny tool of AI defenses. Now, you've got to be able to show that those defenses work.
How are you going to show that they work? You've got a model that, don't worry, AI will know. Well, if it knows everything, that means you'll never have another attack again.
It will just stop everything. Of course, we know that that's far from what happens in reality. What we are now doing with vector AI is we're generating an attack, true generation.
Generating means that right now, just before my attack, it didn't exist, and now a brand-new attack exists and I'm launching it against your target. You've now deployed AI defenses. Will those AI defenses have the capability and be fine-tuned to stop that attack on that target?
This is the data we'll be providing to you, to your vendor. Keep in mind for the vendors, this is also useful if you've got AI-enabled defenses. Every AI model needs to learn.
Well, where do they get that vulnerability data from? Our platform provides that vulnerability data for the vendor so that their own model can learn how to mitigate those threats. Because the core of our technology, we didn't really touch on this, is we're a patented technology that we can launch a DDoS attack against an organization without disrupting the target we're attacking.
That's the core of our patent. This allows us in the AI world to get something called unique data. Unique data is what fuels the, think of an AI model needs unique- Unique ...
data to learn. Right, for the training, exactly. And we're the only company today that has unique data on vulnerabilities in DDoS because we're per environment.
A DDoS vulnerability is per environment. I can have the exact same known attack vector in one environment blocked by a mitigation vendor, the exact same one in another one not blocked. Why?
Why? Because it needs to be tuned and fitted. That data that we generate allows those AI models to work much better for that particular environment.
Got it. Matthew, we're about out of time. I got to get some stuff done here.
People who want to find out more about Radar, where do they go? com. You can contact us.
There's many ways to contact us, through chat, through an email. We've got an AI bot that will answer any of the questions that you might have about validating, proving your defenses work, getting the reports for your regulators, for your executives. You can come and learn about Radar, how it gives you that layer of validation that your defenses are actually working, and make sure that you get that information before an event actually happens.
And you mentioned you work a lot with banking, finance, that kind of stuff. But really, anybody who's a high-profile target for DDoS, this is something they should be considering. Of course.
Critical infrastructure. Anyone that's a high transactional environment that they can't afford to be down, you need a validation layer checking your defenses. Otherwise, you've got a high chance of going down when you are targeted.
I love it. Matthew, thanks for coming here on Techstrong TV. Come back and visit us again.
Will you be at Black Hat? Yes, I will be. We'll be there.
We'll be there doing videos. Maybe I'll see you in person. Excellent, Alan.
Good speaking to you. Matthew, thank you for joining us here on Techstrong TV. Hey, guys, just so you know, Matthew Andreani, founder and CEO of MazeBolt here on Techstrong TV.
com. Radar's the product. Check it out.
We're going to take a break. We'll be back in just a minute.