Attack Surface Management with Kunal Modasiya | Qualys QSC 2023
At Qualys Security Conference 2023, Kunal Modasiya breaks down attack surface management from an attacker’s and defender’s view.
Transcript
This is Textron tv. Hello. And we're back at the Qualys Security Conference Americas, and we're talking with Canal Monte, vice President of Attack surface Management and application security for Qualys.
And we're gonna have a chat about, well, just what makes attack surface management so challenging these days. Canal, welcome to show. Thank you Mike for inviting me, and I'm super happy to be here.
Second time, We have seen the attack surfaces expanding. Everybody kind of understands that we're getting more distributed, more stuff at the edge. There's more different kinds of things in the cloud.
What makes managing the attack surface so hard? What are people challenged with? Totally.
This is a great question, Mike. And, uh, this is what we hear from our customer, that the managing the attack surface has been a very challenge. And then as we dig deeper into it, to understand why, right?
So let's, let's step back and see what has changed, right? Over the last five, six years, right? So the first thing is many organizations are going through their digital transformation journey, right?
Where they're embracing the cloud, multi-cloud, different SaaS services, right? And they have a connected car. They have IOT and environments, right?
So sort of a very dynamic environment that has come through as they have done a digital transformation. Now, COVID added another challenge, right? With the covid, everybody had to work remotely.
So you and I and everybody were working remote. Now, the organizations were responsible to continue or increase the productivity of employee, so they had to launch more remote online services, right? Mm-Hmm.
Now, when you have more and more things comes online. So for example, in Asian country where I grew up, people pay the money with just scanning the QR code, and then money is transferring to the destination account, right? What does that mean?
That means as the digital transformation have taken place, the more and more assets, more and more infrastructure, more and more services have come online. Second, this space is so dynamic that things comes and go very fast. This is where the challenges multiplies, right?
If it was a static, then, you know, the, the defenders or the organization, IT team can find out things and then just, just slip, right? But that's not the case. You have a constantly, the machines come up in the cloud, you have a developer checking in the accidentally checking in the code with the credentials into the GitHub repository, right?
Mm-Hmm. So this is where the challenges are multiplied because things are coming online from many different sources, and IT practitioner cannot keep up that. How long do you think it takes the ban guys to discover either a new attack surface or a fundamentally changed attack surface?
Yeah, I'm glad that you asked this question. And this is where many organization where we speak to understand their attack surface and how much they know upon a time they say that, oh yeah, we know, and we have manual pen testing and all of that, right? But when we run our tools automated tool, we figured that it is so easy to locate at the internet facing assets.
It is as simple as like, we have a Google search where you do the Google search for the things that you don't know. Similarly, we have a tool called shaan, which basically is a repository of all of your organization's internet facing assets, and it's free, it's exactly the Google search equivalent to search organization, internet facing assets. So all I have to do is just go to the shaan, search your organization, search for the assets, and on those assets, it is showing me what ports are open, what vulnerabilities.
So it's a red carpet for an attacker. It is so easy to find this kind of a thing. For example, any GitHub GitLab public repository, you see, and you take any organization, developer accidentally and unintentionally end up submitting the code with some credential because they're coding it.
So they need that, and while they're submitting the code, they're supposed to take back, but they forget, we are all human, we make mistakes. So from the attacker perspective, it is very, very easy for me to find for an organization what is on the internet. Mm-Hmm.
With the shaan and many other tools exist on the planet that helps them with a dark web, deep web, and all of that media that is available, it's very easy to locate the, the assets or whatever is exposed on the internet for any organization. During, uh, his keynote this morning, your CEO talked about how you guys might be applying AI and ML to help figure out where these attack surfaces are. What does that look like?
What can we expect? Oh, fantastic. Great question.
Look, the generative ai, machine learning and all of that right now, uh, they are helping many organize, especially the security vendor like a Qualys, right? In helping build the, the unique algorithm, okay? Machine learning models or a unique algorithm, if you will, to look into the organization's footprint.
And as Qualys has a 10,000 plus customer worldwide, and we are ingesting the petabytes of data into our platform, now you have a data, right? Data is this the, is the new currencies, how they say, right? Mm-Hmm.
So Quass has already the data about our organization, because they have deployed all of our agent and sensors. We have a hundred thousand, a hundred million plus agents deployed worldwide, right? So we will, we know already about organization's assets and we have those telemetry.
Right now, what we are doing is with the newer set of product that you are seeing today, attack surface management and the cloud and all that is adding yet another data set into our platform. Now, this is where the generative AI machine learning model comes into play, where we have so much data that we are slicing, dicing, mining and generating some behavior analysis, finding out some risky assets, automatically calculating that which asset is more critical and crown jewel that is of more interest to the attacker, right? Because look, in an organization, you have thousands of assets from the attacker perspective, the crown jewel asset is a finance department server or CEO's machine.
So with our machine learning and AI model that some of that is already there, where we are with the data that we have, the advantage is the data. If you don't have our data, you are not going to be able to leverage the AI AI model, right? The AI or machine learning model is as good as how much data you have.
So this is where, uh, we are working on, and we have some of the things already available where we can leverage the data and help organizations in finding out their crown dwell, their business critical machines, what the, or if, if we see any of the attacker's behavior within environment as we are deployed on their agent machine. So we can see those behavior and we can connect the dots, right? That's the power of the platform.
Yeah. Do we need to worry about the bad guys collecting data and connecting their own dots to use machine learning algorithms to discover these things that they can attack? Uh, this is a, this is a very interesting, uh, question.
Look, obviously the attackers are going to be, uh, one step ahead, uh, of the organization. They, they are very innovative and the hacking right? Is, is a business, right?
It's, and there is AROI in it, right? Every time when the attackers are targeting a particular organization, right? They have AROI model also defined with that, right?
So now when they are, uh, trying to attack a particular organization, and if organization with the defender's view, if you implement the control and the policies and all of that is recommended by our platform or any other vendors platform, in that case, what is going to happen is that when attacker are trying to steal some data from your environment, you will have, they will have a problem in doing that, and it is going to take a longer time with the security control that you put in place. Now, what does that mean? Like I said, attackers are not doing this for a fun.
There is AROI involved in it, and when they try it multiple times when they're spending couple of hours or a couple of days or a week, then they're going to give up, right? So the better you fix it proactively, all of these things, there is no guarantee that you will not be breached. But you could make it very, very difficult for the attackers, Or at the very least they're gonna go attack somebody else who's maybe not quiet as hard.
Exactly. Right? Right.
So, so this is where the power of the platform and strengthening everything and all of that comes into play. Mm-Hmm. You also run application security.
And I feel like that has been something of the redheaded stepchild of security. And I say this because the security people focus on the things that they can control. So they spend money on infrastructure and perimeters, and they think that the development community is doing something about application security, and the development community thinks that the security people are doing something about application security.
So yeah. Do we need to rethink our whole thought process around application security? Totally, Totally.
This is, this is a great question, right? And the, as you rightly said, the development team, the r and d team is responsible for building the application, whereas there is another team security team which is responsible for securing the application. Generally that's how the many organization have right?
Now. The problem is the developers are focusing on shipping the good quality code at a faster rate so that it gets shipped and their end user get those services in a form of a mobile app or a website or whatever, right? How whatever way business you are serving, uh, to the customer right now, the security guy, right?
The application security guy, generally they are basically not within the same team. So now he's, when the, when the developer is pushing the code to the production, this team comes into play and then they apply the application security, like dynamic security testing or API security testing, and they find a lot of issues. Now, there is always a friction between the application testing team and the development team, because now the application team says, you cannot push this code in the production because it has so many flaws, bugs, security issues and all of that.
Okay? This is outside of a quality, quality is done as a part of the r and d cycle, right? Devs DevOps, right?
They, all of that is done, but we are talking about security. Now, the development team continues to think that, you know, you guys are slowing us down. We want to move so fast, but you guys are slowing us down.
The security, the development community thinks that the security is a blocker, but the reality is that the security needs to be enabler. And the way the landscape is changing is that now these two teams are coming together and while the developer is building the code application, there are built-in plugins. There are built-in processes as a part of their DevSecOps pipeline.
So every time they kick in the build automatically application security test gets kicked in as well. So now they get the feedback there and then it itself, so it's sort of a ship lab. And also when we say that shipped lab, that doesn't mean that everything, you are fixing it beforehand, but then you need a runtime security also.
It's like, okay, I have locked my house within all of the windows and everything, but you still have a outside and nest camera to monitor the traffic and the Right. So all of that you need it, right? So, but what we see is that now both the teams are coming together, the businesses is seeing the security as enabler, and they know that if you have a vulnerable application, for example, a retail organization, you end up submitting the vulnerable code on the e-commerce portal.
Now, what happens if the attackers breach your website and steal the PII and the credit card information of your millions of user, your brand is at stake, plus you are supposed to pay the penalty to the regulator. So this is where it is driving both the teams together. How far left, and I asked the question 'cause developers are complaining that the cognitive load is too high and their head hurts and they don't wanna know all this stuff.
That, that this is, this is like, uh, the reason why it makes me laugh is that we have a same problem with our own company. Mm-Hmm. And I have many friends in a software development organization, and then they see me as a, you guys, every time when we want to do something, you guys are like, you know, stopping us in doing all of this right now.
Thing is, there is no one size fit all approach here on how much you want to ship left, right? I, I don't think there is any cookie cutter approach or a success recipe that guides you only shift left, right? I think it is more about having the right balance.
You do not want to become the blocker also at a time because there is a business agility, business need that you want to go fast, remain competitive. Correct? So it's more about striking the right balance of how much you want to do at the time of building.
And it's, it's defense in a depth. It's a multi-layer defense in a depth approach that, okay, if you are a hundred percent shiplap, does it mean that you do not need on your production and environment at a runtime on the right side? No.
If you do that, it's like not having a camera and still somebody will break in and come into your house. So you need a multi-layer defense in a depth approach, both shiplap and do ship as much as possible, but do not ship to the point where developers even thinking more about the business now they start thinking about you as a blocker that okay? And that further delays, you, delays your delivery of your business application to your end customer, right?
So I don't think there is a one size fit approach here. And it's about the organization, their priorities, their resources and criticality again. And let's say some applications are less critical, okay?
Then you apply a stricter policy, some applications, sorry, other way around, right? If your applications are more critical, then you want to apply a stricter policy and so that you have to fix this, this, this before you hit the production. If there are some internal application used by your own employee, maybe you apply a lesser stricter policy.
Mm-Hmm. Right? So it is more about, I will summarize this saying that it's about knowing your risk and accepting that risk.
You are not going to be able to fix everything and there is no one size fit all here. Developers, if anything, are creative and they will almost spend as much time figuring out why not to do something as actually doing something. But that said, clearly there are both technical and cultural issues at work here.
What's your advice to folks about how to bridge the cultural side, which I think in some instances is harder? Yeah, I think that the, this is the hardest problem, right? I mean solving the, catching the detections and all of that with the machine learning and AI model, which is more about the tools and processes, but then changing the culture is about human right.
And, and that, that change takes time. What we have seen, right? If, if I, if I go back, I'm in industry for, uh, now 20 years and last 10, 12 years, I'm in cyber security and I have been seeing this, how this market has been evolving six, seven years back, five years back.
When I go and ask my development team that hey, at the time of doing all of this, you have to do this, this, this, this, this, blah blah, blah. We are not doing any of this. Now, fast forward today, the culture has changed.
And from a DevOps, it has become a DevSecOps, right? There is a reason for it, right? As the organization understand that the security is a business risk, it's not only about fixing the vulnerability, it's a business risk.
If you don't have a security at the, in your application development lifecycle, then you are going to have a problem later, right? So there is definitely a cultureship, but still, and every organization is different. Some organizations highly governed by, regulated by uh, regulators, right?
They are adopting this faster. Because if they don't do this and if their e-commerce portal gets breached, there is a severe penalty that they have to pay to the regulator, right? So we are seeing all sort of things.
Some organization says, no, these two teams are complete separate. They will not talk to each other. Development team will simply push the code.
Security team will do everything after. Whereas there are teams, in fact, at our college when for my product shipping it, we have a security team, they put their foot on the down and said, no, you cannot ship it. Right?
So we are saying makes and it's going to take time. It's going to take time. All right folks, you heard it here.
Developers are not the enemy. In fact, you might want to go figure out where they're hanging out, buy 'em some pizza and start to get to know 'em. Exactly.
'cause they could be your next best friend. Hey, thanks for coming by. Thank you so much, Mike, for inviting me.
Pleasure talking to you. Pleasure.





