Saeed Abbasi on Advancing Vulnerability Research and Threat Intelligence at Qualys
Saeed Abbasi from Qualys talks about his role in security research, focusing on vulnerability detection and customer training. He explains the True Confirm process, which prioritizes critical vulnerabilities by providing proof without affecting production. The conversation addresses the evolving threat landscape and the need for contextual threat intelligence to enhance vulnerability data. The session ends with appreciation for Saeed’s dedication and a preview of future coverage.
Transcript
Hey everyone. Well, we're back after lunch break here at Qualys Rock on day two, coverage wrapping up. We still got, I don't know, six more, I think really good interviews.
Well, five, not counting Sayeed here. Let me introduce you to Sayeed. Abbasi.
Sayeed, welcome to Text Drunk tv. Thank You so much. Thanks for having us.
Pleasure to have you on here. Sayeed. Let's start with a little bit about you, if you don't mind, share with our audience kind of what, what your role here is at Qualys and what you do and what's your passion.
For Sure. For sure. Definitely.
My name is S Abbasi. I, uh, work with the Qua Research Unit. Uh, I'm a senior manager for security research and I oversee our research and also, uh, work that we do for Zero Day Hunting as well as building detections, cutting edge research for finding uncovering vulnerabilities, as well as, uh, we will help with, uh, uh, gathering all the training that it require for our customers to help them with their prioritization and things like that.
Uh, majority of our work is related to, uh, finding a new vulnerability, building detection for those and as well as provide a timely and accurate way for them to identify it and plan for it going forward. Excellent. You know, Sayed, we, you, you talk shop, we're here at this conference.
There's a lot of Quas customers and you know, different Quas people and, uh, sometimes you forget that not everyone watching at home knows what all of these terms mean. So let's, let's take true confirm for instance, right? That's a name we get, you know, that we gets batted around here.
Let's start with explain for our audience, what do we mean by true confirm. Perfect, true confirm. Uh, first of all, the TRU at the beginning of that, it means that it came from quality research unit initiated from over team, which we already have a 120 plus white hat expert that we are work, they're working with one mission to stay ahead of ADV addresses.
And, uh, this was the idea that we bring up and we had similar capability inside our, uh, vulnerability management platform. And the whole idea behind this true confirm was at some point when there is a vulnerability that is super important to our eyes, but how can we convey that message? How can we convey that message to our customers in order to prioritize that, right?
We need to provide them with the proof and the validation that yes, this is fire, right? This is the vulnerability that they have to prioritize. And with that mindset, we take a look at how we can do that because we want to give them the point of view.
We are not gonna ask them to go install this agent, go give us this, uh, option profile credential, get us approval for this or that. We want, give them something that when there is a vulnerability that is super important, critical and weaponizing the wild, we provide them with the capability that they can run and a scan, find out that if that vulnerability is exploitable or not, then the way that it works is the feature inside ETM and inside ETM, they can bring up all their vulnerability data. It could, it could bring from this from defender, you name it, or even VMDR.
We populate all of these vulnerability and we should list the one that we are able to apply true confirm check on it. And the moment that we show list that they are able to run a scan and we mimic exactly the way that the attacker approach these vulnerabilities the same method, but we run a safe check. By safe check, it means that the attackers mission is to get the code executed there, download the malware, do something malicious.
We are using the same approach, but we swap the content with something that is more safe and it doesn't harm the machine. All we do is we confirm that the method, the approach is exactly the same as the approach that the ER take, but we are not harming the machine. We are not harming the production environment.
All we do is we check to make sure that if that vulnerability exists in that environment or not. Uh, if you like, we can discuss a little about how we do that, that that's also, uh, is a area that it could be, uh, interesting for the audience, but we can take it later. Sure.
Um, you know, I, I'd like to jump into that, but I'd like to talk for you to talk about that in the context of kind of today's changing threat environment where these things are, first of all, exploits for vulnerabilities. Are there used to be a time you, you would find the, this is vulnerability to the exploit that's gotten like this AI just doing more, finding more vulnerabilities using AI to attack these vulnerabilities? How does that all feature in here?
Yeah, perfect. They are, uh, very aligned, right? What you are seeing that the pace of exploitation are so fast, like recent data from Manian that they came the time to exploit, it was negative one, right?
From five days of last year, that was across 112 vulnerability. And what does it mean negative one, right? It means that out of 112 vulnerability that they were interacting, it was so many cases that the attackers were first to weaponize those vulnerability and the patch came later and it was so many that eventually end up being the negative number and bring down from five days to negative one.
And by that, we need a way to provide the teams something that undeniable, a proof, the exact way to tell them that we run this scan how we done it, and this is the result. And we already know that you have to, uh, go and fix this on a priority. And the way that we do it with true confirm is we are running experiment and we don't need to have a CVE even assigned to these vulnerabilities.
Similar to all cases of of cases of, uh, zero day. The way that we approach that is we are sending a prop to the, to the target or a scanner, assign a unique ID to that request, and then that request is exactly similar to exploit, but we are asking to do a read only action or make a, uh, external connection like it should be post or a DNS check to external service that belong to us, belong to through confirmed service. And then once the target make that connection, the scanner from ETM, start looking and communicating with that, uh, true confirm of service and say, I launch a scan, I assign this ID the target if it's vulnerable, should come back to you with this type of request, with this specific id.
Have you seen that? And if that happened, what we're gonna have, we are gonna go back to the scanner. We're gonna say that, okay, we found the vulnerability, it is exploitable, go back to ETM, update the prioritization, bring up The top The, to the top from whatever it was, and provide the proof of the exploitation and the, the biceps.
You know, the problem is, is if everything is a top priority, nothing's a top priority. A hundred percent, you are a hundred, right? So When you move one up, sometimes that means you gotta move on down, right?
You can't just have everything at red all the time. It's always been a problem. Yes, this has Been A problem.
Yes. That that is, uh, another aspect of true confirm. Exactly.
We run these tests on a only certain vulnerabilities, bio estimate, it might be around 3000 vulnerability that could have such a capability that they are super important and we are able to do this externally. 8 or something high, but you can bring it out, fix the layer because we confirm at click externally exactly the way that the advocate does it and is not exploitable. You can do it later on, but eventually they have to update it.
They have to patch it, but well, we gonna give them some time, Patch it, remediate something we gotta do. Um, want to talk to you about how does this all play into the rock? Definitely the rock.
Uh, it, it provide couple of key players to the each organization. One, it provide the context. We add thread intelligence, we provide industry data, we provide active remediation and things like that.
And this is part of the threat intelligence part that we bring to the picture. We enrich every single cv, every single thread with all the details. Let me give you an example.
8 in the backup server. Normally in non rock environment, you will see something like that, just a line in rock because we brought, brought all these enrichment and enhancement from, uh, the context and also the intelligence. We will provide you the full picture.
We are gonna tell you that this is the whole disaster and recovery that you have in past. You take 11 days to fix it, which is not good enough. And then we're gonna enrich it with the data similar to, uh, industry data.
And we're gonna say that you are, for example, in a manufacturing and these couple of ransomware gang that they abusing and building detection, uh, building exploit for that. They're targeting your industry. And even we tie that to, uh, the dollar value that how much pain you're going to get if that vulnerability eventually get, uh, exploited.
And we talk, uh, tie it to the money, uh, and business side and all kind of enrichment like this, which are gonna be game changer because just having the fact that this vulnerability is something that we, we have seen in the past, and we're gonna give you the start that okay, there are 10 other exact same, uh, vulnerability in the same product in, then you have a full context. And then based on that, you can make a decision how you operate it. Because you have the asset, you have the intelligent with the actual vulnerability, you have the context with the threat, uh, actors, how they do it.
And then with this enrichment, you can, uh, make a better decision. Actually, all of this goes inside the tru lens part of a rock. And uh, it provide a full visibility for our customers and, and they can leverage it for their prioritization because all it matters as sum yesterday in the keynote mentioned, is to have the right tele intelligence to focus on the handful of vulnerability that is most impactful for your environment.
And forget about the rest. You can do it later on. But today, what you're gonna do, we are gonna provide you with the full picture and how to approach every single one of those.
I love it. So you know what I love most though? I love people who are passionate about their job.
And I'm glad to see your passion come you loud, so much loud and clear. Appreciate that. Keep doing it what you do, man.
Of course. Thank you so much. Appreciate, appreciate it.
We're live here at Rock On. We're gonna be back with more of our, uh, wrap up afternoon coverage. We still have, I don't know, five, six people to come.
So stay tuned. You're watching Text on tv.