Exploring Container Security with Kunal Modasiya at QSC24
Kunal Modasiya from Qualys discusses his role and insights on risk and security, particularly in cloud and container environments. The conversation highlights the challenges of container security, the integration of security into CI/CD pipelines, and the significance of runtime monitoring.
Transcript
This is Textron tv. Hey everyone, if you couldn't tell, we're live here in San Diego for QSC. Call US Security Conference.
It's been a heck of a day. It started very early this morning. We've been interviewing all day and our last guest for today anyway, 'cause we'll be here all day tomorrow, is Kunal Moria and Kunal.
We've interviewed him at QSCs before. We've had the pleasure. Kunal, thank you for coming in and finishing up our day today.
Um, as I said, it's been a heck of a day. We spoke a lot about risk, we spoke a lot about rock. We spoke a lot about security.
But we're gonna talk today a little bit now about container security. Yeah. Cloud and container.
Well, some will say, well, you could have containers without cloud. You could run containers on a mainframe even. You got it.
The cloud and containers are synonymous. They go together. Absolutely.
So yes, we can certainly talk about it. Before we get to that though, tell our audience a little bit about you. Fantastic.
So thank you Ellen for hosting me. It's my pleasure. It's always been a pleasure to work with you and your team.
So my name is Kunal Moia and I'm vice President of product Management, uh, for the three product line at Qualys. One is the cloud and container security, which is industry calls it as a synap. Mm-Hmm.
The second portfolio is the attack surface management last year, which is what you interviewed me for, I remember. And the third portfolio, is the application security also important? Yes.
It's been a six year at Aquas. Uh, quali is celebrating 25 anniversary, so I still have a 19 more years to go Before you get to Complete the 25 Years. I want you to know, I remember when Qualis started 25 years ago When I was in high school.
Perhaps. That makes me feel very good. Thank you.
Keep it up. We're gonna have a great interview. Yes.
But You know, we actually were talking about the qualis AppSec. Uh, we've spoke to Beatriz and um, I forget her name now. Is it s Eser?
Asthma. Asthma. Asthma.
Asthma. Uh, we spoke a little bit about the app sex stuff earlier. She's in my team.
Yeah. Nice. Asthma is in my team.
Nice. Very. It was a great conversation.
You get a chance to see the interview. It's a good video. Oh, really?
Okay, good. Yep. But let, we're gonna talk Cnap.
Synap is something that is very, uh, on people's minds in the security world. Um, talk to us about it. Sure.
Yeah. I would love to talk. So CA first of all, let's understand why Synap, right?
So if you really look at it, Alan, in the last decade or so, the organizations are now going through the digital transformation journey. And as a part of that, they are lifting and shifting some of their on-prem data center infrastructure into the cloud and containerized environment. Right?
They had applications that were running on-prem. Now they are containerizing those applications to get the business agility, the speed at which the industry is moving. Now, this is where as organizations are moving, the attackers are always one step ahead and they always look for an opportunity.
They never miss an opportunity. They Never miss an opportunity. There is always a guy with a black hat and looking for things exposed on the internet.
Things which are in the cloud, where things are very dynamic and things that are a lot of misconfiguration issue. So this is where, uh, this synap, the cloud native application protection platform has become a very critical functions that organization needs to define and implement and roll out. Right?
This is where Qualys has a, a product called Total Cloud. Okay. That I just, uh, today post lunch, I had a one hour talk with one of our customer in terms of understanding overall synapse strategy.
What are the different components that Qualys provides as a part of the total cloud to secure those cloud and container workloads. And we had a customer from Syntax, his name is Jesse Naira, and he did speak about how he has been using the Total Cloud product. I think I interviewed him too.
Oh, fantastic. Yeah. Good.
I'm sure. So you had a experience that he had to share, right? Yes.
It's great experience. So yeah, it's been a, a synap has been a top of mind for CSOs. Yeah.
Uh, so yeah, I'm happy to further deep dive. Well let, let's dive into it a little. First of all, I forgot what the, the last numbers I saw were something along the lines of 75% of all new applications.
Greenfield Green, not brownfield. Yep. 75% are built on a container infrastructure.
Yes. For all intents and purposes, Kubernetes containers, that's the new compute stack. Totally.
Right. And so it's, it's dominant and there's a good percentage of, as we tra digital transformation and we migrate to cloud, we are, uh, multi-threading putting applications into containers. 'cause it's, it's a, an efficient way of, good way of doing it.
Not the easiest way I might add. It's still hard token doing Kubernetes. By the same token though, canal, we're seeing, and I always mispronounce the word re reaper repatriation, people moving from the cloud back to the data center.
'cause the cloud's more expensive than they thought it was gonna be. But here's the interesting thing. When they move back from the cloud to the data center, they still keep the containers.
Right? They don't, they don't change the architecture. You could run containers on bare metal.
You can run containers in your own data center. So this is the dominant compute stack securing, it's a whole nother story though. And just like we originally tried to lift and shift applications to the cloud, we've tried to lift and shift security to containers and it doesn't work.
So what is Qualys doing that is container Kubernetes, this new compute stack specific, not just lift and shift what yesterday's security was? Yeah, no, great question. And uh, I really like the way you said the container and how customers are moving to the cloud and they're containerizing the workload.
And this is, and you said up to 70%. I would say that this days, modern days, any new application that is getting built, it is always a containerized workload with the microservices and all. Yeah.
And the beautiful part and the one that you mentioned was actually bang on, which is some customers now realizing that the cloud costs are skyrocketing. Yeah. Right.
So now they're taking those workload and moving it to the on-prem data center where they could control everything themselves. Right. The thing here is if it was not a containerized workload, then you wouldn't be able to lift and ship back again.
No. To your on-prem data center. This is where the containers are.
The one which are actually offering that agility flexibility, that once you develop your application using container environment form factor, You run it anywhere. You Run it anywhere. Yep.
That reminds me always. And, and Java. Yeah, Java.
Uh, and by the way, I worked at a Sun Microsystem. That was my first job. Uh, the company that invented, So we were in high school when I was there.
You're lying if you were working at Sun. Come on. Oh, come on.
Yes. I did work there. It was my first job right out of the college.
Okay. Uh, and so this always reminds me that analogy. And one more thing I'll say right in, in terms of why container, before we talk about what Qualys is doing, think of a container.
So before the container, we had a on-prem, uh, machines, uh, right. Fully the machines where you are running all of your application. Then came the, uh, virtualized environment where everything is virtualized.
Then came the containerized environment. Right here is the thing, when you are running your applications on your, on-prem era, on the bigger box, you still have to do vulnerability management compliance, threat management. Then it moved to the virtualized environment.
You still have to do the same function. Now when it moves to the containerized environment, you still have to do the security compliance and everything. But what has changed is with the on-prem, it was very difficult to move things.
When it becomes virtualized, it was little bit easy. When it is containerized, it is now very easy. So think of that as a single family home.
Then you move to the multi-story apartment, and then container is your rv recreational vehicle. You drive it anywhere You want. That's a great analogy.
Right. So this is where now here is the thing. Now when container is offering such a business agility, speed at which you can develop, go to the market, it comes with the challenges.
As you rightly said, the containers becomes the prime target for the customer. Now container goes through the entire lifecycle journey. The developers who are writing the codes as they're writing compiling the code, then it creates the images for the containers and they're storing some public registry so that people can take the, any of those images and then create a container out of it and run it in their production environment.
You see the entire pipeline here. And anywhere the attacker, the bad guy is always looking for the loophole while writing the code or it is available in the image registry or it is running. They want to get into that environment, modify some files, move laterally, do something with the container environment.
This is where monitoring the end to end pipeline end to end is extremely important. Absolutely. So as a partly of policies, total cloud synapse solution, we do have a container security, KCS we call it as a Kubernetes container security, which is part of the solution and which is included in the package.
So you don't have to yet another do the nickel and dime. It's included with a package. Now with our Kubernetes and container security product line, as the developers are writing the code, as they're building things, we can integrate our container sensors, the scanners into their CICD pipeline.
So as they're writing the code, we can scan for our vulnerability threats and other thing. That's the way it's done today. Exactly.
So it is more like a shifting left Mm-Hmm. Fixing things at a source Where it's a fraction of the cost to do versus down the more. Right.
Exactly. But then it also comes with an downside, which is now you developer how to do more work as they are writing the code. We are scanning things, we are finding issues.
They have to fix it before it gets into Ai. There you go. Right.
There you go. And I'm coming to the AI part, but with our Kubernetes and container security, we integrate right into the source, which is the CICD pipeline. And we tell them, Hey, Let me stop you here for when you say you integrate right into the CDCI.
CDC. Yeah. Yeah.
So you're not at the, you're not in the IDE, right? The the No, no. Is this like a GI ops type of thing where you're in GIT and or Jenkins as Well?
GIS and all of that. Right. Okay.
I gotcha. This is where the bill kicks in. So we even when they're, I understand and all of that right now, once the build pass, it becomes the image.
Yes. But with our product, they have an option to fail the build based on their organization's policy. You could say any build has a vulnerability or a malware or a secret that is checked in accidentally by the developer.
We look for those things and you could fail the build. You could ask developer to fix it right there so the compliance team can enforce this thing. Right.
That's a big thing. So you can fix the things before You want. Now, when you say the compliance team, it's not compliance like, uh, uh, PCI compliance.
This is our testing and our our deploy team. Exactly. Exactly.
So the SecOps team or the SRE team could say that, Hey, any build that has a vulnerability with the severity file or this particular cv, Whatever it is, Don't let it go. Mm-Hmm. Don't let it go And no automatically gets kicked back at that point, it gets Kicked back.
Now imagine you pass through that scanning with our CICD scanner and other thing, then it becomes the image. Now that image is hosted in the different different registry. We do support up to 20 plus different, different image registry like your GitLab, GitHub, you name it, and we have it.
mm-hmm. A-W-S-E-C-R registry, or you name it, we got it. Then we have a container scanner for the image registry.
So when their images are built automatically it's going to scan that image. Okay. When you say scan, it's, it's scanning the container image or it's, is it also scanning the container settings?
Both. It is scanning the container image, because often a time when it is built, it is also including some third party libraries. I know open source, right.
As bombs. As bomb. So when we do that image, image registry scanning, uh, then we look for all of those indicators.
Again, customer has an option to make sure that it, the image has a severity file or a CVE or this particular vulnerability or a secret checked in accidentally as a part of that image, or the third party library has some vulnerability. You can write a code, a policy and say that this image cannot become a runtime container. Fantastic.
You see the, again, the prevention at the source. Yep. And today, in my session today, I think you, you may have missed it because of the other interviews, Ma hash, the cyber insurance guy.
Yes. I interviewed him too. Yes.
And, And, and the fellow from Level Blue. Great. Right.
And as a part of my session, I did mention that the, there was a breach last year where attackers were very, very smart. What they did is that they look into this public registry where the container images were there, they injected the malicious code. Now what happened is that accidentally, when you took that image and created a runtime container, already the malicious code is running as a part of your containerized application.
So it is extremely important that you start with ship left, you scan your images. Now assume your images are good, they're ready to go. And then your application development deployment team, the SRA team takes those images and then they create a runtime workload, which is a container, right?
Where you are, where you are hosting your application. Right. Now, the question is, can you, if you have done these two things very well, then do you really have to monitor during the runtime when it is running?
Absolutely. There you go. There are a few vendors out there.
They're only doing this left side part, and they says, oh yeah, you fix everything there. Right. You don't have issue.
But that may, that is never the case. If that was the case, then the runtime never existed. First Of all, containers are ephemeral.
The average container lasts maybe 15 seconds or so. Something exactly The comment minutes very, very fast. You can't afford not to stop monitoring that.
com, we know this, right? There's this whole shift left piece. There's the, let's see, it, it's like having the, the, the deployment stage is right in the middle.
There are some people who look at the left. There are other people who look from deployment to the right. But if your security solution, and maybe it's not one vendor, maybe you have multiple vendors, it'd be nice if it's one vendor.
If you are not looking at it, you know, there's a term we use now instead of shift left shift everywhere. I like it. Right.
You Got shift everywhere. Shift Everywhere. If, 'cause if you are not looking at that whole piece, A hundred percent agreed, you're in trouble.
This is exactly our vision is that once it is in runtime, you still have to monitor that runtime. Kubernetes nodes where the containers are deployed and we have a cluster sensor, general sensor to monitor those runtime behavior. So what we do is that we have a deep learning and AI technology where we are monitoring the runtime container environment for the file system change, malware, hashes, and we do the behavioral analysis and whatnot.
And with that, we are able to find the malware. We look for, again, the secret, if the attacker, when they're in a container environment, they're in your production environment, they will modify some files. They will try to move laterally within environment.
Same techniques are still same. Just the form factor has changed. Absolutely.
Right. So now what we are doing in that environment is we are constantly monitoring with the EBP app, the new, uh, technology based sensor that we are building it where we are monitoring the runtime container deployment environment. So now we can look for a, here is a file, file system change event.
Oh, somebody is trying to move laterally. Oh, here is a malware that I'm seeing with the deep learning and ai, because in the container, you cannot deploy the agent. Right.
'cause as you rightly said, containers are coming and going very, very fast. There is no point in taking an effort in and deploying an agent when those workloads are going to be shortlived. Yeah.
A absolutely. And you know, for anyone who's not familiar with, with CCAP, that's exactly what you just described is the crux of it. And it's how it's done.
Um, we're almost, we're at, well we're probably past time. We were supposed to end 10 minutes ago. But it's okay.
We like to talk. So, and passion. I love passion.
Yes. I don't care what I tell my children this. I don't care what you do for a living.
Be passionate. There you go. At what you do.
It's all about passion. It's about what you do. Absolutely.
Kumar, thank you so much. Thank you so much, Alan. Pleasure talking to you.
You've heard it here. It's gonna wrap up our first day of Qs c Qua Security Conference. We're back here early tomorrow, right after Drunk Gang.
Check us out then. Until then, though, it's a wrap. This is Alan Shimel for Text Drunk tv.
We're out.