Unified Platforms and Multi-Layered Measures with Utpal UJ Desai | Qualys QSC23
Utpal UJ Desai, senior director for product management for Endpoint Security, sheds light on the current landscape of Endpoint Security. Desai highlights the ongoing trend of consolidation in cybersecurity tools, emphasizing the need for a unified platform approach rather than relying on multiple standalone tools. The conversation addresses challenges associated with excessive security agents on endpoints, emphasizing the importance of compatibility and information correlation for effective incident response. Desai discusses the evolving nature of threats, including ransomware and credential theft, and emphasizes the role of multi-layered security measures, such as Qualys’ approach using URL analysis, behavioral technology, host-based and network-based detection.
Transcript
This is Textron tv. Hello and welcome back to the Qua Security Conference in the Americas. We're here with Uj Desai, and he's the senior director for product management for endpoint security.
And we're gonna be talking about, well, what is going on with endpoint security these days? Welcome to the show. Thank you so much.
Yeah. Endpoint security, as many of you, is not a new thing. Uh, but however, if you look at industry or some of the things that are happening in our industry, massive consolidation is happening.
Organizations are realizing that they have too many point tools, uh, to, for cybersecurity. And when you're using, um, multiple products for, for security, you have to correlate information from multiple sources. There's no single source of truth.
So incident response becomes much harder. Mm-Hmm. So in endpoint security, now people are thinking of it more as a platform feature versus just a standalone tool that does its own thing.
It seems like there's a lot of agents running on these endpoints, and maybe we need to clean that up. I don't know anybody who stands up and says, gimme some more agent software. So, you know how much of the computing horsepower is being used to run all these agents?
Exactly. So yes, the agent com not only you use a lot of computing power, but then you also run into compatible tissue because your one agent may not be compatible with other agent, multiple agents doing the same thing. That obviously is one of the issues.
But the bigger challenge is if you're using different agents, these agents don't talk to each other. So whenever an incident happens, you don't know which vulnerability caused that incident, because vulnerability management tool does not know that actual malware incident happened. The endpoint security tool does not know which vulnerability caused that incident.
We don't know how many other assets can potentially be at risk because this information doesn't reside in a single tool. So organizations have to navigate from one tool to another tool, and in many cases, it's already too late by then. Some folks have it in their head that they want a couple of tools because, you know, if one doesn't catch one thing, the other will, but in my experience, it's just as likely that the two tools will find something and conflict about it.
So what's your sense of what is the right mixture of things we should be doing? Yeah, the conventional wisdom was always that, hey, you need to have multiple tools. Uh, in some cases, if there is an overlap, it's okay, because if one tool doesn't catch it, the other tool will catch it.
But I think that's a very old school thinking. I would say, uh, more and more organizations are now open to consolidation because they realize the benefit, right? It's not just cost saving or operational efficiency.
It's, you can respond to threats better. You can manage your risk better because you have single pane of glass visibility. You have single source of truth, so you can respond to threats better and reduce risk faster.
We live in uncertain economic times or more people having this conversation or willing to have this conversation to save money is and how much money can you save? Uh, we have seen with some of our clients, you can save up to 40% by consolidation. And, and many of these clients have said, well, we started this journey to save cost.
But then we realize now that we have consolidated on call and we are doing many things within our platform, we are able to respond to threats. Better teams are talking to each other more. Now they have common understanding of where we are, what needs to get done, and they're more productive.
So it's not just cost savings, that's, that's a very obvious benefit and an important one, but just communication between different teams. Teams are more focused, more productive, and now they're thinking about what next they need to do, right? Because they're now all focused, they're talking the same language.
So that's really some of the key benefits besides, of course, the cost saving. What is the scope of endpoint security these days? Because, you know, it used to be more about malware than anything else, but now we see credentials get stolen, there's ransomware inserted.
So how has that technology kind of evolved and how will it continue to evolve? Yeah, So I think ransomware still a big problem. Uh, we continue to see more and more ransomware attacks happening.
Uh, credential theft, like you said, that's another area that we see, uh, bad guys doing really, really nasty things. Uh, call is not only just has one technique to prevent these attacks, but if we have many different layers that we use in our solution, uh, so each layer is designed to attack, excuse me. Each layer is designed to block attack different stage of the attack lifecycle.
For example, we have URL, uh, technology that analyzes URL behavior. And if it's a phishing hosting site, we can immediately block saying that, Hey, this is a potentially phishing site, uh, that you, you shouldn't be visiting. If somebody downloads a file, we are able to analyze that file in real time using our behavioral machine learning technology.
We see suspicious we don't let you, uh, download the file somehow the file is already on the system, then our behavioral technology kicks in that will monitor running processes and if it sees anything suspicious, it'll immediately take, uh, action. Then we have our host base, uh, detection, uh, technology, excuse me. We also have our network base detection technology on the host that will look at things like brute force attempts and we see any, uh, such, uh, event that we can automatically take action and last not, but the least we have this EDR layer.
So whatever reason, if bad guy's able to penetrate all these layer, then our EDR layer will kick in and will take action. Are we gonna see AI be applied more to endpoint security? And what might that look like?
Uh, where are we? Yeah, there are a lot of talks about AI these days, but we've been using AI in our platform for, for many, many years. We use AI in our endpoint security as well.
A lot of our detection techniques uses very mature machine learning model. So without having signatures, we are able to detect malicious files at a very high degree of, uh, accuracy. And we will continue to apply ML for automatically prioritizing alerts for automatically taking action.
I think that's, that's what we're looking to do, so that we want to be comfortable where if it's a high risk asset and we know that there's critical data on the system, we want to be able to automatically take action if there's anything suspicious, uh, detected on the systems. How are the tactics and the techniques of the bad guys evolving as they look at endpoints? It seems like they're focused on endpoints again, but it's not the same kinds of attacks that we saw in the past.
Yeah, so now, so historically bad guys have been, uh, leveraging, uh, exploitation kits that are readily available. You can easily go to dark web and find out how to exploit a particular exploitation is a child's play. We know, and that's why you see a lot of malware attacks and, and breaches.
But now we hear that they're also using, um, AI and ml, right? So that means that we have to be one step ahead, uh, because they are automating 'cause they have business to run, right? They, they, they, cyber attacks is a business for them.
Uh, and uh, they've been leveraging AML, so we need to be even smarter to keep up with them and to defeat them. So those are some of the things we are looking at in on our side as well, where, where we want to leverage more and more, uh, AI ml, uh, to stay ahead in the game. It's all about staying ahead than the bad guys.
It feels like this is becoming more of a continuous process and I essentially manage all of this and I can have lots and lots of endpoints. Has the whole way we manage endpoints security kind of evolved and is it more sophisticated and, you know, how should people be thinking about it now? Yeah, I the way to think about endpoint security, one takeaway of this conversation, I would say for, for organization think they have to keep in mind that EDR or detection response at the end of the day is a reactive process.
'cause you're reacting to the alert, uh, incident response is hard. You need skillset in order to be able to triage and alert and take necessary action, right? So they need to start thinking about how can I prevent more attacks automatically?
Uh, how can I ensure that there are no asset blind spot? We find out that about 30% of assets are unknown to the IT team. They didn't even know that those systems existed.
We often even find out that I security team thinks that endpoint protection is deployed on, on the systems, but then we find out that more than 20% don't even have any endpoint protection, right? Uh, as far as vulnerability management is concerned, they think, uh, all vulnerabilities are equally important, but that's not true, right? So you need to prioritize, uh, what what matters.
And that's where call VMDR comes into play. We can help you prioritize, uh, the vulnerabilities that you need to fix first. Then you need to make sure that you are patching, you're patching.
Imagine in 2023 we're still talking about patching. Are there more vulnerabilities? Of course there are gonna be more patches, so you need to use automation.
That's where our patching capability comes into play, where you can automate, um, remediation for majority of the applications and vulnerabilities that are out there. And then the endpoint protection is just the last line of defense, right? So if you're good at managing your assets, if you're good at prioritizing the right vulnerabilities, if you're good at remediating those vulnerabilities fast, then your endpoint protection has to do less work.
Uh, you wanna save your time and resources for most important task, right? So, so that's what we, we ask our, our clients to focus more on prevention and more on patch management, more on making sure that they have a good visibility on what's in that environment and think from security from that, uh, perspective versus being reactive and responding to alerts after alerts. Does all this happen in the background?
'cause I think end users get a little annoyed every time there's a little security thing that pops up and says, we're scanning this, we're looking at this, or we found this. Um, you know, how involved does the actual end user need to be? Oh yeah.
It's completely transparent. So the way we have designed our solution, the end user would not even know that, uh, there is, uh, something happening on the endpoint. We do this in the background.
Uh, so is our, our solution, uh, is not disruptive to the end user. You talked to a lot of cybersecurity people at the show. What's on their mind?
What are they telling you? You know, what's their stress right now? Just they have lot on their plate.
So I've been talking to a lot of our clients here. They're saying just they many projects they're working on, there are a lot of risk obviously. So they're, they're concerned about cybersecurity, they're concerned about, uh, next big news coming out that hey, there's a new vulnerability or a new attack that is happening and how can they respond to that faster?
How can they be better prepared? Uh, so that when something like that happens, when they hear in the news about a vulnerability or about a cyber attack, they know what to do, right? 'cause in that time, when you find about find out about those things, you need to be able to respond quickly, right?
So they wanna be prepared. So I see more and more organizations, they want to be more proactive. There's a lot of talk about more stringent regulations and a lot of that seems to be focused on knowing what data is where.
And it seems like we don't always know what data's sitting on an end point. So how do I know whether the data is sensitive and then what measures I should take based on the importance of the quality of that data? Yeah.
So I think, uh, that's where call can help because with call platform you can maintain information about the asset. Is this asset business critical? Is this asset running some kind of database?
Is that asset, uh, externally uh, exposed, right? It's internet-facing asset and based on that we automatically tune our protection, right? So, so one of the things that we do with our endpoint security solution, we have the asset business context.
We know what the asset is running, we have our own threat intelligence, uh, we have our own dedicated threat research team. They, they know what is being exploited, uh, in the wild. So based on all that information, we correlate all that information and we automatically prioritize alerts or things that the IT team needs to be looking at.
Some smaller companies have it in their head that the tools they get when they buy the application or the operating system and the machine are good enough. So, you know, what is the value add above that and beyond that people should be thinking about when it comes to endpoint security. Yeah, I think to think about endpoint security, remember at the end of the day, endpoint security is the scene of the crime, right?
That's where the sensitive data resides and bad guys are after the data, right? So when you think about endpoint security, you really want to think about how I first make sure that I have complete visibility on of what's on my network. I wanna make sure that it is running commercial gate endpoint protection.
Like cos I wanna make sure that you're prioritizing the right vulnerabilities. There will always be vulnerabilities, but you want to prioritize the vulnerabilities that you want to, uh, that poses the biggest risk and that's where call can help. And then you wanna make sure that you are automating things like patching so that when a new vulnerability is announced by let's say Chrome, you don't have to worry because you are patching tool will automatically take care of it, right?
Mm-Hmm. So that's how you should think about endpoint security. I think also a lot of people don't appreciate the simple fact that most of the attacks that get discovered eventually started on some endpoint somewhere where it was compromised and then the malware move laterally.
So, you know, to your scene of the crime point, are we just not taking this seriously enough? Exactly. And also you have to remember, at the end of the day, end users are humans, right?
They're click happy when they get an email, maybe they're curious, maybe they're busy, they accidentally click and that's when the attack happens, right? So, so endpoint security for that reason always, uh, remains top of mind for organizations because they know the end users are doing a lot of different things and they're click happy and they're curious and the attackers are sophisticated. So sometimes even I am being cybersecurity professional, I have accidentally clicked couple of links that I shouldn't be.
I'm shocked. All right folks, you heard it here. People still are the weakest link.
And if we're gonna figure out it, since we can't really eliminate the people, we gotta figure out a way to secure them, it starts with the end point. Hey, thanks for coming by. Thank You so much.





