Workload Classification and Incident Response with Sweet Security’s Eyal Fisher
Sweet Security has added generative artificial intelligence (GenAI)-powered capabilities to its cloud runtime security suite, featuring the ability to classify workloads by business impact, and get granular incident response playbooks on the fly.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
You know, we've got black hat coming up this week. Uh, I still think it, it's not the black hat I used to go to 20 years ago. It's more like RSA in the desert now, but it's still a formidable, sizable, uh, security conference.
A lot of my friends will be there, including my next guest here. Let me introduce you to Al Fisher. Al is the co-founder and chief product officer, CPO at a company called Sweet Sweet Security.
Uh, yeah, first of all, welcome back to Text Drug tv. It's good to see you. Thanks for having me again.
Ah, it's my pleasure. So you're coming to Las Vegas? Yeah, so we're coming to Las Las Vegas and still, uh, I still very important tv, um, in which, uh, we, we have making improvements and the upgrades of, uh, our offering.
We have broader offering, interesting offering. And, uh, we have added, uh, a a GI, uh, capability to our, uh, a solution which we are going to show actually in, in blackhead. It's a good opportunity to anyone who would like to see boost 3 1 1 3, but let's start from the beginning, right?
Sure. Yeah, no, we got off on that. Let's start with, so tell it from the beginning.
God created the heavens and earth, but yes. So talk To me From your beginning. Yeah.
So, um, my beginning is like, uh, professionally at least, um, uh, unit eight, 200 for 20 years. 20 years, 20 God years. Yeah.
Yeah. I retired the second from that unit. I was the, during the last year in the, in my, uh, last role I was heading the largest Australian steel style operations center in the unit.
Meaning that I had more than 1000 people doing the research development and operation offensive operations. Quite a unique position. Very, I mean, you don't get to, to, to do those things where when you are a citizen or like, uh, when you are not working for your government, right.
When you're a civilian, you don't get that. Yeah, Civilian. A civilian.
That's what I meant. Exactly. So it's unique.
It's unique. And, uh, and, uh, I had an, I had amazing time since the thing that I, you know, I took out, uh, from, from that, uh, um, in that period of time is the attacker perspective. I mean, getting it, bringing it to the security world, the attacker perspective, understanding that, uh, no matter how good your, uh, uh, security tools are going to be tackles, they have like very easy job cloud environment specifically are very, very complicated and messy.
And, uh, the, they're complicated. They get, it's easier for attackers to sneak in and do whatever they want because on one end you can do things that will be buried under the noise. And we are going to talk about it in a minute.
Buried under the noise, meaning that you'll get, because the cloud is very busy, uh, the application and things happening, it's not a laptop, it's, it's, it's, it's, it's, uh, a huge environment. We spent many applications running on it, so it's noisy. So you get a lot of alert from world security, um, uh, solutions.
And when there is something significant, it might be buried under the noise. So that's one. Second is that, um, a lot of things can happen actually without triggering any alert, because they seem legit.
So, you know, if you succeeded to get in to the environment, now you can do things that are quite like, uh, that's not of fine, okay? You can access data because that data can be accessed from where you are in the environment. So that's fine.
No alert need trigger. You can execute out the data outside because that it address you are using is fine. It's not forbidden.
It's, I mean, it's fine. So nobody will notice it. Notice it.
So at the end, you can like be buried under the nose or do things that are considered legit and nobody will, will, will, not it. So that's where we came in. Mm-Hmm, Exactly.
So I tried, I tried to bring in that perspective understanding of how things can be done, can be done, uh, specifically to cloud environments, complicated cloud environments, and bring, you know, a new innovative approach to, uh, security in runtime to cloud environment. And that's a, you know, we, we talk about cloud security. 'cause the cloud security is very different than network on premise security, which is kind of when I got into security was all about the network deck.
And for a lot of people, cloud security became about identity and access control, right? Where, because with all security, you need chokepoint somewhere, right? How can I, right.
How can I, where can I limit here? And, and so real runtime security like this, I think it's been something that's been lacking in cloud. Exactly.
We, Yeah, we identified, you know, the mission piece, like, uh, the path, um, we identified, identified that, uh, there are no good solution solutions for runtime that were built specifically for runtime environment, for cloud environment, and not solutions that were shifted and lifted on, uh, endpoints and on-prem environments. And now they also the u as the cloud security solution, but they were not built for a cloud environment. So Perfect.
They will not detect they were I attacks. They generate a lot of noise, but, so we started our Good. Um, before we jump into our topic of discussion, if you don't mind the website for sweet With security.
That's right. Very good. Remember that.
And then secondly, can you repeat the booth again? You're gonna be a black hat. Yeah.
Thank you. So the booth is 3 1, 1, 3, 3, 1, 1, 3, 3, 1, 1 3. We didn't, We didn't pay for that, uh, number.
We just got it. Sweet. Wait, what else can I say?
Sweet. Anyway, so yeah, you guys, uh, just, just last Friday, right, right before the weekend here, um, unveiled a new gen ai, well, it was actually Thursday, but a new, a new gen AI powered functionality for Sweet look. Exactly.
Everyone is jumping on the gen AI train. I, I came in here after just recording a segment for a Textron gang, and we were discussing is, is is AI du gen AI thing going, you know, the hype cycle, where is it in the hype cycle? Is it on its height?
Is it on its way down? You know what, what's happening? But certainly VCs and companies are investing in AI because they see the, the promise.
It may not be there today. You can't do everything we're going to do, but the promise of what it can do is so valuable, so mesmerizing that we all wanna figure out how to use it. So let, let's hear.
How, how are you, what did you do here with the gen AI powered functionality? Right. So, um, when we are all aware of the hype, right, uh, of, uh, gen ai and, but, but we were very picky, let's say, uh, on the specific use cases that we wanted to harness the Gen AI to our solution.
Uh, we, I mean, we could have done many things, but we wanted like to, to make sure that we offer something that can really, uh, give benefit on one hand, but can rely on the data that we gathered during the, like the last year. Um, we have a solid data set. We have, uh, we, we, we understand what we are doing now, so we can bring in something that, uh, we not suffer from, like hallucinations and other problems of the evidence because we intend to bring something that they can be relied on.
So after, after thing that, uh, I mean, we decided to pick two areas in our solution. One is, um, the use of stories or, um, you know, specific like step by step remediation to the, uh, uh, alerts that we bring in. Um, we bring in very little amount of false alerts, very little amount of alerts.
That's our claim to pay. But what we did now is going like to the next step, uh, next step and, uh, offer a playbook. Okay?
So after you get like a very limited amount of, uh, uh, alert. Now, the next step is utilizing Delaware give you like a, a a a playbook, a step by step instruction. What should be done when you get that alert, okay, do that.
Open that, please run that code, piece of code, see what the result is. And so, you know, the SOC suddenly not only I got got like a very specific alert and, and just the, the, the relevant alert. Now the stock is like, uh, on steroids, things that, uh, needed to be done manually.
Um, and, and, and, and they are, and took them a lot of time. And air four, uh, can be done by just following, like, uh, following, um, uh, a step by step cookbook. Those things were very, uh, very popular for on environments.
Cloud environments are more sophisticated. So it's, uh, uh, it's more, it, it's even more needed on one hand, but both more, more complicated on the other hand. So we did that.
Uh, so that's one. The second thing is, uh, we have, uh, vulnerability management tool, um, that helps you understand which vulnerabilities to be addressed first. And we, in order to decide which vulnerabilities should be, uh, addressed, we, uh, use, uh, um, we, we use our runtime, uh, capabilities.
We can tell you which library it really in you, uh, the application is really, uh, running it, using it, so you know that you are not wasting your time on a, a, a library with a TV that is not in use by the application. It's just there, it can't be exploited. So we have few parameters that we rely on to prioritize the work for vulnerability management.
So access on the internet, the executed, uh, part I talked about right now, and now we are adding the business impact on your environment, again, utilizing the, uh, LLM to, to that purpose. Now, we can tell you that that library is in a, uh, in a, in a specific environment in your, uh, uh, application that is very significant. The impact of the business is huge.
And that can be done because the NLM can analyze, you know, the application and tell you, okay, what I see here is that this is a database, this is an engine talks to your database. So sensitive data is here. If you have, uh, A CVE in the library, that it, in that environment that that should be handled immediately.
Okay? So we have added that as well. Um, and, and we get, uh, amazing without, uh, again, prioritizing even better the vulnerability that needs to be handled.
You know, what I like about DIY out? You, you're not pie in the sky. You're not, we're throwing a hail Mary, you know, you, you, you're trying to do these, these are sensible, as you said, smart about it, right?
Using the technology with what's capable today, not what's going to be capable tomorrow or five years from now to, to, you know, make it easier for people to, to, to do the product and to be secure. And that's, I think, what we should be doing today. I mean, you look, you gotta experiment.
You gotta see what it's capable of. But when you're talking about rolling out product, you can't roll out, we called vaporware, right? You can't roll out vaporware.
You gotta roll out solid what people can use and Works. We want our customers to start using it. If it's going to be like something that is not, I mean, you can benefit from it.
Nobody's going to use it just, or like nobody has time for playing around. Uh, they need value, value from our, uh, solution though. Uh, we identify the, uh, areas in which we can bring, uh, value right now, right here.
Agreed. Agreed. Yeah.
Al, congratulations. That, that's great news. Um, I'm also, you know, as you mentioned early on, the is really trending up and building block in here, but congratulations to you.
You know, you put 20 years in, as you mentioned, to uh, 8,200 into a military career, you retire and it's good to see you get out into, you know, the real world. So I don't know if that's the real world and this isn't, but either way, um, you know, and, and you make a go of it. And so, you know, I, I can't give you enough credit for that.
I'd be very proud of what you've done here. Um, and continued success. Make it sweet.
Thank you. That's all right. Again, that's sweet.
Do security, there'll be a blackout. 3, 1, 1 3, you said, right, Ruth? Exactly.
Check 'em out. Um, actually, if you come by the Textron party Tuesday night, maybe you run into the there, you get to talk to 'em in person. But anyway, yeah, we'll see you in Las Vegas.
Continued success. Thanks for coming on today. And great news on this Gen gen AI powered, uh, functionality and suite.
Thank you very much. All righty, we're gonna take a break here on Tech tro. We'll be back in a little bit.