Parag Bajaria, Qualys | Qualys QSC22
Parag Bajaria, VP of cloud and container security at Qualys, joins Alan Shimel at Qualys Security Conference 2022 to discuss how Qualys TotalCloud will help security teams secure the entire cloud attack surface.
Transcript
This is texturong TV. Hi everyone. We're back live in Vegas for koalas's QSC 2022 one of our favorite events to cover we get to meet some really interesting people and the security conversations are top notch.
We're gonna have one here because you know, Carlos recently announced a new Cloud so the cloud security solution that I I want to talk about it. We got it and had some Cloud native. Functionality we're going to get into it.
I want to introduce you to Prague. Help me with your last name Park bajaria parag bajaria and parag. Welcome and thank you.
Thanks for your help on your name. But thank you for sitting here with us today. Love to do that.
So Prague introduce yourself. If you don't mind to our audience, definitely hi name is parag bajaria. I am VP of product management at Wallace being a college for around two years now interestingly so mad and I when we connected When I was joining, right this was the vision that we laid out.
So it's kind of realization of that Vision previous to joining qualis have worked in various startups. One being cloudnox, which was just recently required by Microsoft and bunch of other cybersecurity startups. I just feel like I love security and as always exciting things happening.
You know, it's interesting. I tell people all the time if your passionate about what you do it comes through to people and they get passionate right if if your job or your you know, what you do for a living is like pushing rope uphill. You you're not a happy person, but be people see that too and they sense it sort of so I'm happy to see your passion about working on security.
So let's let's jump right into it. Koalas made an announcement. I believe you were making the announcement here.
Yes USC show today. I don't want to steal the story you you tell them. Look, I think.
while we made this big announcement, right, but the announcement is is not about One more thing that you want to do for cloud security. Actually. What we are going is we are going the opposite of let's simplify Cloud security because with Cloud sick Cloud native security.
We have done this acronym. Jargon. cwpp cim Csbm, ISC and what's what is what we are losing in our is that by having these kinds of acronym driven conversations?
Right? We're forgetting what customer use cases we are solving because we need to solve that security problem. They these acronyms don't matter at the end of the day, right?
So with total Cloud what we are trying to do this, how can we simplify your your journey into Cloud security my focusing on what are the important use cases that you need to solve? Right? And let's look at those important use cases.
Let us provide you Cloud native Solutions when we say cloud native, right? This there's no magic that we are doing here Cloud native. All that means is that we are utilizing the cloud service provider apis to do some orchestration, right?
So let's take an example of Agent today when you use policies and I and you deploy you have to make sure that it's installed on the virtual machine that you're going to deploy but in the cloud we can completely automate that by inserting the agent automatically, right? So that that's all it is being Cloud native is nothing new per se. Yes.
We are doing some few new things. It is. Let's simplify.
We want you to not focus on orchestration of security. We want to focus on what are the results of the security. Hopefully that gives you a context.
No, it does. Look, I I think you almost have to go up another couple thousand feet. I think one of the things that's developed around Cloud security over.
Look. I remember when Cloud security became a very big thing at RSA conference and maybe 2005 you started everyone wants to know. Well, what's your Cloud security strategy?
What are you doing around Cloud security? Some people had what strategy some didn't. But what would develop would evolved is?
It was almost like I have one security here for on-premise. I'm gonna scan for vulnerabilities on my infrastructure and so forth, but that strategy that those tools I had a different thing for cloud because well the cloud provided did some of it for me. I didn't have to worry about the infrastructure and all of this.
I had SAS based third party apps. And then this whole so called Cloud native. Stack came right?
So the cloud when I first recognized it. It was a hypervisor situation, right? You did cloud provider had the hardware.
They gave you it was a hypervisor and then you build on top of the hypervisor. Yep. Well now this new stack.
Sometimes that's the hypervisor sometimes not it's container based. It's kubernetes talk about orchestration and kubernetes has some interesting security built into it, correct? Yeah, and and you know the whole idea of scanning containers while it's not totally foreign.
To the kind of scanning we've been doing for 20 years. It's a little different you got to scan the payload. You got to scan the container configuration and so forth.
But the you know, but there's a whole stack there's the service Smash and all of the other things that that are going into this. But one thing I know companies don't need right now is yet more. Solutions I got it solution for this a solution for that another solution for this and whatever is coming next right?
No one wants. I think people want to unify security solution. And that's what this kind of total Cloud.
This is kind of what I See with it. I I agree with you, right this is about. Seeing your picture right in in one place, right?
So you talked about container and there are so many components and then kubernetes security. It's it's fine. I mean all those Primitives need to exist so ensure security but you need an overlay layer right that can simplify some of this.
Right and one of the things that with container will has been very very good from a security vendor perspective right into container. Well, we have started to do a lot of things shift left. Yeah, right.
So before we kind of get into the mess, you know once you deploy stuff It's my operator doesn't know I need to clean up right you can mop up. Yeah, right and change the tracking and all the hassles somebody needs to now report on them. Why why do all of that?
Right? So runtime security is like your backup security, right? Clean it up early on right and that's where again this total Cloud vision is let's simplify security.
Right? Let's not introduce more things that you know, hey, let's do this one more piece, right? Let's get it right up front.
And then wherever a runtime security is only back up, right and same goes like now kubernetes, right? Even kubernetes can be misconfigured easily. Unfortunately is not easy.
Let's be clear so. you must have seen the news of kubernetes API server being public right? I mean really?
If you want to get on news. For being hacked. Do you want to get on news for being hacked on some simple configuration?
No. All right. I mean that you rather not get on the news, but if you do let it be the best soccer in the world.
Got it, right James Bond. There's exactly something that I can write a book about maybe it will be produced into Mr. Robot too.
Yeah, that would be nice. But yeah. 100% right It's about that.
things about this is the whole kind of infrastructure is code ephemeral nature of of this infrastructure. Where look I don't even want to patch my containers. I just destroy it out new containers, right?
We we just redeploy stuff. It's it's it takes place here left. not at the point, you know not when it's already deployed and out there live.
I'm just gonna fix it here. Push this out and get rid of the old right? It's a different mindset.
The good news here is containers were made with the mindset of immutability, right? That's there. I said ephemeral.
It's immutable. All right, so which is which is a great thought. unfortunately There's some shift and left going on even in container world.
Which means like so far. Customers are still going through that journey of Indian immutability, right? They're still installing puppet agents in containers and downloading software which is like I defeats the purpose but that's fine.
We want to support them in the gym their Journey. Right? But the immutability concept is is a great concept and it's actually percolating back even in the virtual machine world right now more and more of our customers are saying that we don't want to patch right even over watching machines.
We want to rehydrate them, right which means if it detect something I bring it down I push the new image in right and that's the thinking around that shift left facilitation right that now if I look at your terraform template, right and I can see that you're referring to an Ami, which I know has vulnerable, please and tell you right here stop it fix it. And redeploy exactly. I you know, so look it's easy for you and I to sit here and say why didn't they think of this before right what what you know, but it it's a rather simple concept.
But we did we just didn't have that capability. But this is a game-changing. I think capability of don't fix it.
Replace it. And I you know. again easy to say but it's it's not that hard to do with today's technology too.
Hey, I you know, I think it's the way we have to go we have to and the benefits. Outweigh any of the what? I would say Not even operational mindset change right once you get to that mindset the benefits far outweigh.
Oh, my absolutely. No doubt. No doubt because the other nice, you know, what's the reason?
We don't see more automated patching or remediation or because it's liable to break something. I have to test it first. You know what it's easy to test it in your Dev environment when you're not in production.
And so when you push it, you know, it's already been tested and and with automated testing back here. It could be done as as it's being developed and you know done. Yeah, it really is I think some mindset chain right remediation.
You still require mediation. Let's say that you're a new owner of that. He has been released.
There is a x you are exposed to that vulnerability, right and you want to prevent that exposure while fixes. I've been right you want to mitigate that risk until you can right. So that is a need for runtime mitigation not run time patching person.
Yeah mitigation, right? And and that that is to give you that buffer while you are rebuilding fixing those issues and redeploying, right? So in today's world, right you need to have both of you said sometimes I have conversations where you know customers thing they buy into the the Hold my Mantra right that oh everything shift left.
I'm all secure well, not really. So that that is it so look in addition to text strong TV, right? com Security Boulevard and container Journal.
So we play this is our this is where this is how sweet spot this is our farm and I think one of the things we've been guilt not me personally, but the industry has been guilty of is We put so much attention and focus and resources in a shift left. You can't ignore what's called shift? Right?
Right. You can't ignore shift right either because that's your production environment. If you got a problem there you can fix it by shifting left.
But until you do it's your neck on the line and and so we can ignore the right side. As we you know move this emphasis to shift left. We can simplify the shift, right?
Yes. That is because it's mitigation not necessarily remediation. I agree Prague is the is the solution available now or is it when will it be available?
How does how does one? So it's easy. We have a sign of page.
The solution is gonna be current Court in beta and of November, okay, and just like usual right? I mean when we release new functionality, right we have the usual mentality of we're going to start signing our customers in We build up a pipeline we get feature feedback and everything and then we will G8 sometime in q1. So but so that you have November about two two and a half way.
So yeah, I mean it's a very easy sign-up form. We have our sales guys who will be following up rather. You know, I'm collecting all the data, right and we're building we already have actually a set of customers what who are whom we did this early preview with and now we are kind of moving to okay.
Let's stop bring in other set of customers and then GA is planning q1. So I love it and q1 will have it available. Look.
I I think I think it's a great thing as I said. It's a shifting mindset, but it's if we can make that shift. I think we'll all be better off for it.
Let's simplify security right not driven by acronyms but by use cases. I agree. com is I thought it would be a better way of doing security associate.
Anyway, hey, we're live at quality QSC. We're in Las Vegas. Got a few more interviews today.
So stick around.





