Travis Smith, Qualys | Qualys QSC22
Travis Smith, VP of malware threat research at Qualys, joins Alan Shimel at Qualys Security Conference 2022 to provide an overview of TRU and the launch of the Qualys research team rebrand, as well as provide oversight into the data analyzed from the Qualys Cloud Platform.
Transcript
This is texturong TV. Hey everyone. We are back.
We're live in Las Vegas at the Venetian for koalas's QSC conference. 2022 is day two will be here all day and the second day of the conference. Hope you had a chance to catch yesterday's show.
It's some amazing guess it's a great discussions. tv next week as well as on the koala sweat sites. You can check it out there right now though.
Let's kick things off today with Travis Smith Travis heads up true. What's true? It's a good question.
That's how we're going. Travis is true true. So true is our a rebranding that we're doing at the koalas true stands for our threat Research Unit.
So threat Research Unit. I love it. Yeah.
Okay. So it's it's a combination of what we've always done. We've always had and just now we've collectively be brought everybody together.
So now we have our vulnerability that's paired with our malware that we can tell a whole cohesive story. That's true to the industry. Absolutely before we go any further in case I forget people who want to maybe, you know login subscribe or at least know where they can go to get information from true.
Yep. There were website set up. Yeah.
Absolutely. It's and it's very easy. com/tru.
There it is. com/dru. Alright, so let's be clear though Travis right choose the name.
Yep, and there's a whole new emphasis on on the research team and what you guys are gonna do but research isn't something that's new to qualis. No, no, not at all. If you know my share with the audience a little bit of maybe about the history of the research team in Charlotte.
Yes, so mean qual has been around for 20 some odd years, right? So what we've always really been known for is vulnerability research want to be signatures vulnerability management. That's what we've our bread and butter is Right.
We've been doing that for for decades and we have a very robust immature research team that has always done that research the vulnerability research. We've been really branching out as a company doing a lot more than just vulnerabilities and doing a lot more research and not only feeds the content of our products. But now what we're really trying to do is provide that data that research out to the industry because that type of research that we're doing and how to track adversaries and what all the bad guys are up to.
It's not useful. I mean it is useful as an individual company, but the threat actors they're Information right and we should be sharing information as an industry as well. So that's really what true is all about is not only feeding the content engine behind qualis, but also giving that information back out to the industry at large.
Absolutely and look I've been in the industry 20 as long as quality has been around. maybe longer over the years you guys have discovered a lot of vulnerabilities and they will always call us was always very good about, you know, responsible disclosure, but disclosing them and helping the industry wasn't just it wasn't a kind of thing where Only College will be able to find this vulnerability, right they were on, you know sharing it with the industry at Large. now so now we're true though, right and say one more time threat Research Unit.
That's right true. What's changing really? I mean really not much.
What we really want to do is just have a singular front that we go out to our customers the industry at large and really have something that they can resonate with. We spent a lot of Time Around The Branding of it and because we have a new logo for it as well. And you know, when we first did it look like a thumbprint we've changed a little bit looks like a maze changed a little bit looks like the quality Shield changing a little bit and it looks like a map thumb print and you know, whenever I show this to various people at the company or my wife or these people everybody says, oh that's what it looks like or you know, it looks like a thumbprint or it looks like a maze and the good thing is is you know, they're all right, right.
So there's always something that somebody can resonate with and because we just we do so much and you know and what we do qualities at the center of it and if you look at our logo the keys at the center of the logo and you know really resonates that's the complexity of what research does and how you know how difficult it is to be able to figure out how a vulnerability Works how to do, you know how to disassemble and reverse engineer malware. It's very difficult to do and you know, we want to be able to highlight that and provide that information back out. Yeah, I think Like to really share with the audience Travis is kind of like vulnerability data is one part of the mission.
Yeah, but there's more to it. Oh, absolutely. Yeah vulnerabilities by themselves, you know, that's just one data point right if vulnerability is sitting there is, you know, not useless but the vulnerability is there because a threat actor is gonna use it a piece of malware is gonna leverage it right?
So being able to help tile those different data points together and that's why I have various different teams in in true in the three Research Unit that do all those different things so we can actually build that kind of graph and cross correlate. All those different data points to say. Well, here's the vulnerability who's leveraging it.
Here's how it's exploited. Oh, these ones are associated with ransomware. These are the ones that you need to really pay attention to He had one of the big waves.
I've seen wash over the security industry. Let's say in the last seven to 10 years. That's seven years.
Thread Intel. Mm-hmm, right? So but you know and you hit on some of it who are the bad guys?
What are they up to what what's coming down the pike from them so that we you know, because it's like you said in my mind anyway, right you you have your job thank God. I don't have your job but you got it. It's like you got to paint the 3D picture here you do.
Yeah, it's well, it's a concept that we call threat informed defense, right? And that's you take a look at this whole thing. If you know, what are the vulnerabilities through the threat actors.
What are they doing? What can they do? What have we known?
They're gonna do so we can try to anticipate where you know, try to stay two steps ahead of anticipate where they're going and you take that, you know that thread intelligence and you know, you do you threat informed offense so you can show up your defenses past the vulnerabilities, you know, fix the missing configurations or apply that detections, you know for based off something like the miter attack. so And I don't know and forgive me but is there plants to sort of package this into a kind of Standalone offering you have the you know the quality true team and maybe you can get other threat Intel feeds that come into it. Yes.
I mean closet large. I mean, we we consume both consume and generate a lot of threat intelligence. Right?
We have over two and a half billion different data points on vulnerabilities how they're leveraged why they're leveraged the threat actors that are using them to just all the malware iocs that you could really throw a stick at all of that data we have in our platform and I don't think we really want to you know show that as a package offering out what the package offering that that true is gonna do the threat Research Unit is really providing the insights into it. What's the actionable information with these two and a half billion data points that we have that people need to pay attention to and we're gonna roll that up and next year. We're gonna be releasing a yearly threat report.
That's we're gonna be, you know, we re-establish what we used to call the laws of vulnerabilities and that's coming out in 2023. I love that. and you know, we should mention you talked about all this information that call us has you know, some of it is just doing good old-fashioned vulnerability research right looking at stuff and finding Finding bugs and so forth but a lot of information is generated was that 80 million or 80 billion some of that what the amount of Agents?
Oh, yeah. We have we have a lot of Agents. I think it's like 90 90 million billion.
I don't know what the number is. It's it's astronomical. It's more than I can wrap my head around when we're doing all this statistical analysis of all these vulnerabilities like we have to leverage machine learning to to help us turn to those numbers because it's a lot of data to be able to look through and find the real insights.
I mean I mean that many agents out there and just Anonymous, you know, anonymizing the data collected. Yeah still gives you probably as good or better inside than anyone else I can think of. Yeah, I mean, so we're taking all that data from all of those agents Anonymous, you know, so when I get the data that we're looking at to provide stats, you know that we're collecting.
I don't know, you know, which customer which agent, you know, I don't have any that I just know here's the vulnerability and you know, is it patched does it not patched how quickly was it patched and then I can take all the other thread until I have on top of that right? Is it being leveraged? How quickly was it leveraged?
Right, is it being leveraged faster than we can patch it, right. Those are the stats that I'm trying to pull out. Absolutely.
So you mentioned another Bingo buzzword machine learning, you're right, you know without doing this amount of data. It's more than you know, maybe a human mind can wrap around. Yeah, you can't do it without machine learning absolutely not want to call it AIS whatever you whatever your term is.
Yeah, but let's talk a little bit about you know, what are you guys without disclosing obviously, you know, Proprietary info what kind of machine learning or AI kind of algorithms are a play here. Yeah. I mean we take a look at there's a lot of different algorithms you can use for machine learning right and you want to use the one that is able to answer the problem that you do right?
Because you go in with a lot of data and you make sure first that the data is good right? Because if you put garbage data in you're gonna get garbage results out. All right, so we do a lot of curating in the data and massaging it.
So here's the actual data that is good that we're putting into these algorithms and we need to ask a question. Right what and then that algorithm helps to answer that question. Right and you different algorithms will give you different answers, right?
So you need to figure out which one is telling you the right story and then use those algorithms to then feed more data in and then prove that hypothesis out. cool Curious for my own selfish reasons for no reason are you guys gonna be doing like regular release of a reports or updates or just kind of ad hoc as you find things you'll yeah, I mean a little bit of both right? So we I mean, we regularly write blogs in 2022 alone.
We've written over 100 blogs just from the threat research team itself from the threat Research Unit we've done, you know, a few dozen webinars, right as we do regular ones and hot ones. So if you know log for Shell comes out or you know, one of these other major vulnerabilities or a new threat actors being, you know, running reeking Havoc, we'll talk about that. But we have the regular ones.
We do a monthly one on Patch Tuesday all the vulnerabilities that have come out the previous month. We do another one that we call a threat Thursdays where we look about threat actors. They're tooling you know, which ones are more active.
You know, what are the the different data points behind there? So a lot of different things that we do out but as I mentioned before, you know, we want to provide that data back to the industry, so we are regular contributors to the minor attack framework because we want to be able to you know, increase the defense for everybody not just our customers, but we're also going to have that yearly threat report. So the laws of vulnerability so it hasn't been released at quality since 2009.
Rebranding that bringing that not rebranding it but bringing it back for the first time in the last 13 years. Yeah, that's great. I don't put you on the spot one might be one might we see that early 2023.
That's the goal. I don't official release date. com/true.
That's where I'm gonna post it. Excellent. You've got to be psyched about this, right?
This is a I mean, it's more than the name change. It's it's making, you know the threat research team. It's always been a part of college but really bringing it front and center now.
Oh absolutely. It's a core concept of what we do, right? We have our product we have our content in you know, and it's it's we want to be able to provide that and provide that thought leadership because we have some of the best Minds in the industry on our threat research team.
I mean there they are better than anybody I've seen in the world and what they do. I'm trying to highlight what they're doing and give them credit for all of this amazing work that they do love it. All right one more time for our audience.
com tea are you yes, yep threat Research Unit threat Research Unit remember that? Hey, man. Hey, congratulations.
Best of luck with the keepers posted. Thanks so much. I will.
All right Travis Smith from Was threat Research Unit true here at QSC. We're in Vegas. We're going to be back in just a bit with our next guests.





