Enhancing Security Management with Sandeep Potdar at QSC24
Sandeep Potdar, Senior Director, Product Management at Qualys, discusses the VMDR product, emphasizing asset discovery, vulnerability assessment, and response. The session highlights the integration of tools for better asset visibility and analyzes risk scoring systems.
Transcript
This is Textron tv. Hey everyone. We're back here in San Diego and we are, uh, happy to have this gentleman.
You know, we were just reminiscing, you know, the, the security world's a very small world, as big as it's got and it's a lot bigger than when you and I first got involved in it. But it's still a very, you know, incestuous world where the, the connections are all, there's layers and layers of them. I want to introduce you to Sandeep.
Poddar. That's Right. Now Sandeep is with Qualys today, but Sandeep and I first met nine years ago, eight, nine years ago.
Around then. Yes. Uh, he was, he was at White Hat Security at the time.
He was the security guy at White Hat Security, which was one of the pioneers in, in application security AppSec. And then went from there to Tenable, which then acquired White Hat. Right.
So They acquired Bit Discovery. Uh, discovery Is what White Hat By, by by Jeremiah, which is a, an asset, uh, an asset management company. And That's right.
But still, Jeremiah Grossman was the founder of White Hat, founded Bit Discovery. That's right. And now you're here at Qualys.
That's Right. So welcome. Thank you.
Always a pleasure to, Always a pleasure, my friend. How do you, tell us what you do at Qualys? So, I'm the senior director of product management for our flagship offering, VMDR.
mm-hmm. And, uh, I'm privileged to work with a very passionate team, essentially drive, uh, both strategy and execution for the VMDR offering. And this is the, this is a dream, So, yeah, I know for a security guy, right?
It's a, it's a catbird seat of a, of a job. So VMDR is of course, the flagship, the heart that's right. Of the entire Quas suite of, of products.
Started off as just your kind of regular vulnerability scan, aquas card, I think it was called. That's right. Back in the day.
Um, it was a vulnerability scanner. But today, tell us what else besides just pure vulnerability scanning. Sure.
So is Encompassed in there? We, we look, we look at it more holistically. There are essentially four aspects of real vulnerability management, and that's why it's VMDR.
So we wanna make sure that we are discovering all of the assets your, essentially your entire attack surface. Once you've discovered these assets, so you know both the known and the unknown assets, then the next step is to now assess them for vulnerabilities and misconfigurations. And then make sure that as you're assessing these vulnerabilities, which you're gonna have a ton, you are then applying effective prioritization methodologies on top of that to make sure that you are able to prioritize the, the, the most riskiest vulnerabilities and misconfigurations first.
And then that's when a lot of other tools and other products stop. Right. All you want to do is basically, do you want to create a report and then send it over to the other side, the IT team to go and remediate it?
No, we don't stop. There we go also to the ARC piece of it, where after prioritization, we also not just provide you, uh, remediation patches, but we will also help you to respond to it. So what do I mean by response?
A response can be sending an email to somebody or creating a, a ticket into your ITSM system. A response can also be to actually go and patch it or automate a particular patch. It can also be, uh, there's no patch available.
Let's say it's a vulnerability that doesn't have a patch yet. So you are then able to also mitigate that. And worst, worst thing is many times you and I sometimes forget to restart your system or apply a particular patch.
We, when we know the IT team has worked hard to provide it, um, basically isolate that system so that it does not, basically It's not, it's not reachable. It's not, if it's not reachable, it's not exploitable. Yeah.
This entire cycle is a repeatable cycle. And that's what VMDR provides. Discovery of assets, assessing those assets for vulnerability and misconfigurations, prioritizing so that you're able to pick the, the most critical, the most riskiest vulnerabilities and misconfigurations.
And then if essentially responding to it by either communicating with the teams that are own IT or, uh, automatically, uh, in this case patch it or mitigated. Now the interesting thing is from up until the VMDR, this, this basically used to take about four companies, four different vendors, right. And then they had to work together, hopefully sometimes to communicate this.
And it made for a very clunky, I mean, look, it was a system that didn't work and this was a big problem in vulnerability manager for many years. And, and that was, that was just vulnerability scans post-deployment. We we're not even talking about AppSec kind of scans, you know, pre-deployment, if you will, and stuff like that.
So the, you know, one of the, one of the, uh, you know, the thing that makes VMDR what it is, is it brings all of this together into one interface. That's correct. So we don't look at it as a siloed, Not anymore.
It's one, it's one Asset management was not even part of voluntary management. No, it was, you had to have that 'cause you had to know what to scan before you could scan. Exactly.
But now that's all, and there's another piece, I don't know if you mentioned it, I missed it. The agent, Yes. You know, vulnerability management to us used to be, I could do what we call an internal scan behind your firewall.
Or I could do an external scan, give you that hacker's eye view. We used to call it, right. Cloud came along.
I, if you told me what cloud assets you have, I might be able to scan them from back here, depending what the cloud provider let me have access to. But now with agents, we don't play that game as much anymore. Right.
You, you still can do that 360 degree scan, if you want to call it that. But with the agent, I have much more insight into really what's the state of any particular system or node. That's right.
So we approach this with a sensor approach, right? So we want to have the network scanners and the agents, because these are essentially complimentary technologies. What the agent is providing you is an inside out view into your assets information.
And a scanner on the other hand, is providing you your outside in. So instead of trying to choose one over the other, we wanna make sure that we are providing the best of both worlds. Additionally, we also have passive scanners who, uh, which is looking at your, your network packets.
Essentially the idea is to be able to identify known and unknown assets out there. And like I said, assess them for all vulnerabilities in different, different manners and make sure that we provide the best coverage. Because if we are not able to provide the best coverage, that really means that there are holes that our customers basically are not able to seek.
So this is, this is a very unique to Qualys type of offering. To get all of this in one interface, one vendor, one throat to choke is and One agent. And one agent, one agent.
How many Times do you scared of all of that? So yes, Because God knows the world doesn't need more agents. Right, exactly.
We have enough agents. Now there's another piece we roll into this and that's the true risk score. Right?
Right. And in my mind, what this does is it, it translates security talk to business talk. So tourist is very interesting.
We started with the world where, uh, prioritizing of these vulnerabilities was being used. We were using different sorts of parameters. CVS and CVSS.
Right? 0 that is upcoming as well. The problem with CVSS is that CVSS, and this is what we analyze, the CVSS, um, categorizes 52% of all CVEs as critical or high, which means every other vulnerability that CVS can, And if they're all right, they're all critical or high, that makes it, if Everything is critical, then nothing, It's then nothing.
Exactly. So that's the problem with, um, CVSS, I like to call it the problem of false positives. There's another newer way of scoring vulnerabilities, which is EPSS, the exploit prediction scoring system.
Yeah. I think it's around three or four years old now. There's a newer, newer version that has come, uh, but it looks at the probability of a vulnerability to be exploited in the next 30 days.
Okay. The Problem with EPSS, however, is that only 2% of the vulnerabilities that are Exploitable Are called exploitable. It even ignores the vulnerabilities that are currently being exploited, but still basically starts rating them though.
So this is a problem of the false negatives, right? Yeah. Too few.
What tourist does is essentially marries both. And as a matter of fact, CVSS is providing you the exposure context. The EPSS is providing you the exploit context, and both are important.
I'm not saying we have to choose, we Need to No, no. Both of them go into the equation. Tourist goes one step further, it also looks at evidence of these exploits, the third E and not just that, it also breaks in the fourth E, which is your enterprise business context.
Marry All. And to me, that's the most important thing. That's exactly right.
Because what might be a critical vulnerability for you is not a critical vulnerability Or for the matter between the same two assets, the same vulnerability. Right. Would basically take shape of a form for different, uh, Part.
Sure. It all depends. It depends on my network setup.
That's right. So there's a lot of context. It's exploitable Required and that's what tourist, uh, does.
Absolutely. But now what we're seeing is the true risk becoming or working with this, uh, true risk management where we're talking the language of business. That's right.
0. 0 not only supports your IT host, it also supports web applications. It supports cloud resources, it supports cloud workloads.
It supports ai LLM. So it's basically a complete coverage of all of your risk sources. In terms of risk factors.
It's now looking at not just vulnerabilities, but also misconfigurations incidents. Anything that we are ingesting from our third party partners and connectors. 0 is more expansive, but it's also more accurate.
We have fine tuned the algorithms that we use to, to correlate all of this data together and spit out a number that we believe now is more accurate. It doesn't use averages or mean times. It instead uses it a very nuanced precision formula so that the scoring that it, it is producing, especially when we're ingesting third party data, is very accurate.
So that's what tourist does. And like you rightly said, tourist goes one step further where we are not only providing you numbers or vague numbers to it, but if we've configured the new ETM module that we launched yesterday, you're also able to quantify it using currency, right? You're able to provide dollar value, Power values, And now that starts driving prioritization decision.
Your budget decision. Well, It starts, it starts enabling the board to look at this from a business context, because the board doesn't understand that we have 23% critical vulnerabilities. That's fine.
And only 4% not critical vulnerabilities or I've, I've remediated 62%. That's Glock to, you know, Gish to them. Exactly.
They wanna know what, where's what, what risk exposure do I have here? Precisely. And they would like to not just quantify it, but they would like to also track it, measure It.
Absolutely. Month to Month. The investments that they have made, uh, are producing the ROI that, uh, was essentially Well, and that's, that's probably the single biggest problem in the security industry is the board is saying, you're asking me for more money asking, I've been giving you money for the last 10 years.
Where's the ROI? I'm still as vulnerable as I was. I'm still getting breached.
I'm still getting, you know, where where is I? I I don't see the reduction in risk. You're telling me I'm more secure, but I don't, we don't see It.
That is the golden question. I was talking to a customer earlier today and his board was asking just one question every time the CSO went to the board to ask for more money. Are we secure yet?
Yeah. And that's the precise question that we wanna answer by providing the CRQ, the chief, uh, the, the cyber risk quantification. It's an exciting time.
It is. It's, I'm looking forward to see how this plays out. Same here.
Thank you, Sandeep. It's always a pleasure. It's good to see you, man.
All right. We're live in San Diego. We've got a few more.
Yeah, we got a few more to go. Uh, really good, good content here. I hope you guys are enjoying us here in, uh, at q Aqua Security Conference, uh, QSC.
We'll be back in a moment. Stay tuned. You're watching Text on tv.