Data-Centric Security and cyDNA with OpenText’s Paul Reid at RSA Conference 2024
Paul Reid, head of threat intelligence at OpenText, discusses cyDNA at RSAC 2024 with Mitch Ashley. OpenText’s annual revenues of $6 billion stem from its strong background in information management, informing their cybersecurity focus on protecting data. cyDNA addresses evolving threats like federated identity attacks by extending protection to content delivery networks and hyperscalers, providing early warning of attacks. Reed emphasizes the importance of understanding data in cybersecurity and looks forward to integrating generative AI and LLMs into their products to enhance threat intelligence.
Transcript
This is Textron tv. Hi everybody. Mitch Ashley here at RSAC 2024 in San Francisco talking.
So call things security cloud, endpoint software, supply chain, you name it, we're talking about it. So I have the great pleasure being joined by Paul Reed. Thank you.
Paul Reed with OpenText, um, global cyber Threat intelligence. Threat intelligence. I, you knew I was gonna mess that up 'cause I already did.
You closed so I was in the ballpark was so, so, so the few folks that don't know, tell us about OpenText. Tell us about what you do with the company. So OpenText is a company with annual revenues, about 6 billion.
Um, they have a very strong background in information management past 25 years doing that. And because of that, it really gives us a differentiation in the marketplace. For our cyber products, it's really hard to protect what you don't know about.
So information management's all about understanding where your data is, what it is, what's it contained, what's the importance of it. So because we have that background in, in our company, when we build our cybersecurity products, they're focused on protecting the data and protecting what's most important to these customers. That is a different perspective.
When you understand what you're protecting with that depth, That it absolutely is security part. It absolutely is. Because if you understand what your data is, the importance of it, we can help put solutions together that are focused on your needs.
Right? And if we understand where the data is plus the proper protections, we can make you more cyber resilient, which is really important today. Forget Your role at the company.
So I'm responsible for our threat hunting team. So we have a series of thrivers that hunt in our customers environments throughout the world. Uh, we look for ongoing emerging threats and we work with them to keep them as cyber secure as possible.
Very good. Uh, and I imagine businesses of all size, but especially large Enterprise. That's right.
Everything from small medium enterprise all the way up to large enterprises, uh, take, take our services and of course, buy our products from opens. Mm-Hmm. Excellent.
Excellent. So you had a big announcement at We did sac. Let's talk about side DNA.
Yeah. So side DA is a really interesting product. It came out of our recognition that there's really a new generation of threats that are, that are attacking our customers.
And it's really about the threat actors working together. Um, they're really spending a lot more time doing reconnaissance and open source intel and getting to know their victims in more detail. Part of the reason for that is we've had the shift to cloud, right?
We've moved a lot of our workloads to cloud. We store a lot of information in cloud, and we've done a really great job as an industry starting to take care of identity, right? For protect your identities.
So we've done things like picked federated identity providers, right? So I now have a single point to manage all my, uh, employees' identities and be able to federate with all the different services and things we use. While that works really well and solves a lot of the identity problems, that presents a whole new set of problems.
Now attackers have a single point they could try to compromise. Mm-Hmm. So we see a lot of focus attacks now against those federated identities.
And if I can compromise those, then I can take that compromise credential and go to a number of different places, right? So I don't have to, to break into three or four different places. I just have to compromise why.
So threat actors know that, obviously customers know that and they spend a lot of time protecting that, but threat actors are really getting smart, right? They're working together. They are, um, leveraging each other's, uh, tools and techniques and skills.
And we really need to start thinking about cybersecurity beyond the endpoint, right? The past several years, we've done an amazing job with EDR and other technologies, like a web route technology to take and protect those endpoints. 'cause really, at the end of the day, that's where the attackers want to get to.
But with these new threats, we need to look beyond that. We need to see the cyber horizon. You need to see what's coming at us across that ahead of time.
So most companies have some form of threat intelligence, right? We all buy threat intelligence. That's really important and it does a great job telling us, here's the threat actors, here's what they're doing.
Here are the ones active in the industry, or you're vertical, and here's the type of tools, techniques, procedures, and other things they're using against you. What it doesn't give you though, is the specifics of who is attacking. Mm.
So side, DNA tries to answer that adv adversarial signal threat intelligence problem by telling you exactly who is attacking. So we do that the following way. We take, we help the customer define what we call covered space.
So we say to the you, what is the parts of your network externally facing that are most important, right? So standard stuff, what's your ASNs, what's your siders? Things like that.
But then we have a conversation and go, you know, you, you also need to think beyond that, beyond the corporate structure, what you have in a content delivery network. What do you have in hyperscalers? What you have in other places that have became compromised could be very detrimental to your company.
So we extend that protection into those CDNs and those hyperscalers to help protect those workloads, protect that content so we can see the adversary coming and going use. Interesting. So talk a little bit more about the CDN part of it.
Um, yeah, it it's one thing if you're hosting things in your own right, you know, uh, cloud services that you're purchasing from whoever, but once it kinda leaves that into a CDN visibility index, it's pretty hard. It is tough for a Business. It is, it is.
So we work with our customers to understand what parts of the CDN they're using, where their data is stored, uh, what's the IP ranges, things like that. Uh, we have one customer who if they lost their content in their CDN, they'd basically lose business overnight, right? Yeah, Absolutely.
Because they're, they're dependent upon that delivery mechanism to get content to their customers. And if they're not delivering content, they're gonna make a revenue. So attackers know that, right?
Sometimes it's just not simply, I wanna steal data, but maybe I could harm you in some way or virtue in some way. And the other thing we're seeing too is that a lot of large, um, enterprise customers are doing a really good job on their cyber. We hear about all the breaches and all that.
We never hear about how well other companies are doing. Everything Worked really well today. That's right.
In the news. Exactly right. And, and no one's is interested in that.
But what we're, what we're finding is because you has such a great job, the attackers know that, right? You know, if I'm a $5 billion company, am I going to be attacked or are they going to attack a software part of my company? In that case, we see a lot of attacks going against the supply chain, right?
So if I can compromise one of your providers or your supply chain, and you have a trust relationship with them, then essentially I've compromised you as well. And I can get in through that way. Other times, if I want to degrade your company's ability to do business, or if it's in the nation state, I want to degrade the ability of the nation to deliver goods and services to its customers or to their, um, uh, partners and other places, they, they may be having geopolitical interactions, then that's just as good as attacking you.
So with side DNA, we can extend that coverage we talked about to their supply chain as well. Give them visibility wouldn't otherwise have. Hmm.
Interesting. You what the thoughts when I heard the name and then read about the announcement is in the software world, we talk about supply chain. We're talking about the entire creation process of software and security of everything that goes in it and the tools that it runs on.
Same kind of thing with, with data. We haven't really brought together security and data and information together and thinking about it as one cohesive thing end to end. How does that secure, you know, you don't bolt it on, right?
No. Secure It. No, That's right.
Built in, right? And I, I think that's, as we start talking about with OpenText, having that background information management gives us a different perspective. When we think about cybersecurity, we think about it from a data perspective, right?
What data are we protecting? How, how can we keep it secure? Do do you our customer know where all your data is, right?
So that's why when we have that conversation with side DA about your covered space, we let them think about, you know, do I have stuff stored in a, a, uh, a cloud storage device somewhere or a cloud provider somewhere, right? Because that can be as attached just as easily as you're ing that. Yeah.
How about the, uh, I don't wanna say next frontier 'cause it's already here. How about data and LLMs and AI and, you know, we can't go too long into a conversation, right? Without talking about that, right?
So There, there's been a lot of great analysis at RSA already in the past couple of days on the next generation of generative AI and LLMs and what that means for our industry. And there's great promise there. There's no doubt about that.
Uh, at OpenText, because our information management background, we take that very seriously. So we're already implementing that and our information management, uh, products today. So we have a series of what we call aviators that allows you to use generative AI to get more detailed information and more natural interaction with the data to get the information you need.
We're working now to bring that to our cybersecurity products, uh, and we're going to do it in a very similar way to what we did with our information management products, right? We want to leverage the information that the customer's providing us, but also the information we're generating as well. We generate some very unique threat intelligence and threat intel.
One of the things we're very, um, mindful of is the whole hallucination, right? If we're going to be giving, um, cyber recommendations using generative ai, we wanna make sure that we're giving the most accurate and informative information we can. To that end, again, our information background information manager background is really helping us define how we're gonna build those generative ais and those LLMs, our data science team thinks about that an awful lot and really spends a lot of time on how can we find the best information possible and deliver it in the most normal natural way to our customers.
I'm curious too, um, you know, data in generative ai, lms, et cetera, it's, it's not like your normal database or data structure, right? Even even unstructured data stores, it, it its own thing. We're talking about training Yes.
Models with data. Is that, does that cause any new sorts of challenges? Things you have to think about how to secure that.
So OpenText has had products using AI and machine learning now for seven, 10 years. Mm-Hmm. So we've dealt with a lot of the issues around how do you take and protect your models?
How do you take and protect the data you train from? Uh, we have a product called ArcSight Intelligence. So this is a user entity, behavioral nalytics product where we learn in the customer's environment what normal looks like.
So we have many years of experience on how to leverage AI and ML together, the human machine teaming aspects of it to better protect our customers and of course, protect ourselves from those type of threats. Good. Back to IDNA.
Talk about when you identify who the threat actor is, are we talking about the IP address of someone who's doing a country, you know, that's kind of the normal Yeah. Thing, or, or the historical answers we've gotten before. Are we getting more sophisticated on trying to determine who the actors are?
Sometimes, Sometimes we are. Um, sometimes threat actors are really good at hiding who they are. Mm-Hmm.
Oftentimes we see threats where we can't provide attribution, but we can tell the customer that they were targeted and how they were targeted, which is really important. So, uh, for example, we recently had a customer who had a supply chain attack. Uh, one of their manufacturers, uh, was, was targeted and we were able to show them he was inside DNA, the exact date they were targeted on and who targeted them sometimes why they targeted, right?
We see a lot of the geopolitical world coming into the cyber world, not surprised we've talked about it for years, but with the current, uh, environment we all live in, we're seeing more and more of that. And we are seeing it so much that when I talk to our large customers and some of the nation states, we've taken support, um, we can almost tell them within hours that, you know, if your country makes a geopolitical statement on the following things, you're gonna see the following threat actors come after you, uh, within the next 24 72 hours. And by the way, they're gonna use the following tools and techniques against you because we see it time and time again.
There's a, there's a playbook they use that they take and apply every time they go after someone for a statement that maybe their country made. So in doing that, we're able to help protect them better and give them forward warning. Right?
We really want to use side DNA as a, uh, early warning of attack, an early warning of compromise, right? If we can find the signals ahead of time that says something bad's about to happen, that we can prevent that something bad from happening, then the customer is much better off than waiting for the attack to take place in finding it and then trying to remediate it. Interesting.
It's almost like before you say something, not that we have this level of discipline, but you know, whichever side of whatever thing it you, you know, a comment you're gonna take That's right. That side is potential threat actor. Absolutely.
What you're bringing in, what you're stating in the public. It it, it is, it is. And it's really interesting sometimes just to see how, how often that happens.
And a lot of our customers are surprised, like, why were we targeted and we're not a, you know, national brand, we're not a national name. Mm-Hmm. But, you know, you may supply something to the country or supply something to someone else that is critical for that company to be successful.
That's why. Right. It's just not the big names that get attacked, but everyone's really a target.
Mm-Hmm, Absolutely. Just relative to how big you are, right? That's right.
Usually notoriety. Yes. Um, what was it about what customers were telling you that led you to believe, hey, this side, DNA, whatever the, the code name Yeah.
For the project was At the time Yeah. That that's a thing we should go create and bring into market. What was it the customer said that said, that's the need we can fill?
So it was, it was really this need to get visibility beyond the borders. So today there's a lot of standard ways that companies do that, and it's been well known and well practiced, but a lot of times there's a lot of friction to getting that done. We wanted to find a way that was almost frictionless for the customer to get that visibility, and we wanted to have it in such a way that we could take and very easily control the, uh, how we produce the results from that.
So we leverage our existing technologies we have in house and how our existing products and they fit the bill really well to take and provide that visibility. This is something we've been trying, you know, for the next past couple of years and really spent a lot of time researching and thinking about and trying out in the wild, right? We wanted our product to, you know, face the fire, so to speak and show its metal, which it did very, very well.
Right? I was very fortunate to be part of some of the early, um, beta testing, if you wanna call it that with, with some early, uh, countries and, and companies. And getting their feedback was absolutely critical.
Them telling us that we show them things other people don't show them is, is a really good validation of what our technology was trying to do. Right. Do you get it?
Do you and your role get into the privacy aspects of information data? That's obviously a very, yeah. Not as fast as ai, but a no.
Much more fastly fast than regulatory landscapes of the wallet And fast. Yeah. Um, data privacy is, are very important, right?
Uh, OpenText takes data privacy very seriously and we have products that actually help our customers protect their data both in motion and at rest. Um, for us, from a cybersecurity standpoint, we believe that our customer's data is very, very important to us. It's what we use to protect them, and in turn, we feel the need and the responsibility to protect their data when they share it with us.
So we take the utmost, um, security that we can to protect that data and of course to protect our results as well. Right? Um, when we find things for our customers, we share it with them and let them know what's taking place and then we let them decide how they want to remediate and deal with it, right?
It's not up to us how they wanna go about doing that, but it's definitely our responsibility to protect them and show them what's taking place. Very good. I would imagine in your role, you not only, which is a huge responsibility, you know, help, help shape and do the threat intelligence around the, the product and services that you offer.
But I imagine you come to RSA thinking about, I'd like to kind of get, keep an eye on some things of what's developing in our, in our interest for, are there any things that are peaking your interest while you're here? Well, Clearly the whole generative AI conversation's important. I think me personally, my background in cryptography, the whole quantum safe conversations that are going on right now around quantum safe, uh, algorithms and what does that mean for everyone?
How soon is that gonna happen? I think that's gonna be interesting. I was fortunate to be here when DES was broken at RSA for those who remember those Topics.
I was gonna say, this is all about encryption originally. Right? Exactly.
Right. Right. That's where we all came out of.
So to me, you know, going back to look at what's happening in those is still important. A lot of times it, it's, it's really interesting, you know, my, myself and my threat hunters will look in a customer's environment, we'll help them understand their threats. And there's generally a point at which in an attack when we hit that, if they had only way, right?
If they had only had two factor authentication, if they'd only had separation of duties, if they only had stronger encryption algorithms, if they'd only encrypt data at rest or in motion, right? So when I come here, I'm looking for what's happening in those areas, what's coming next, and seeing how we're solving those problems. 'cause there's still a problem today to solve.
Uh, a lot of times people ask me, you know, how are we gonna deal with the generative AI issues and the type of attacks are taking place? We hear of all the amazing research that's gone on, where now we have LLMs that can dissect malware, tell you if it's malicious or not, and that's absolutely incredible. And then we have customers ask us, you know, what's gonna happen when the adversaries start using generative AI to create new attacks into the threats?
And it's actually going to be a change, right? The, the peace and the veracity of attacks is gonna change, right? Just like we saw in our, uh, threat report we put out this week, right?
The malware and the, the phishing and spear phishing campaigns have increased because of generative ai, right? It's a lot easier now to write a spear phishing email or a phishing email using generative AI is to do it by hey, but if you think at the end of the day, how do all attacks take place? They know something we don't or they leverage something you haven't protected.
So a lot of times it comes back to the basics, right? Did you patch right? Have you put your patches in place?
And when you talk to customers about patching, they know it's something they have to do, right? It's kinda like eating your vegetables, right? It's good for you, you gotta do, but nobody necessarily wants to do it.
It's like cleaning the garage. Do it. Exactly.
That's right. I don't always do it Right. But, but one of the most important things around that is there's only only so much time, money, and effort to be able to do that.
So with side DNA, we're actually able to say, Hey, Mr. Customer, here are the threat actors that are targeting you specifically. They're using these type of tactics and they rely upon the following CVE.
So it allows them to prioritize what they're gonna patch first to match the attacks we're seeing. I'm curious, just to get your reaction about this. We, we hosted an event here every year called DevSecOps DevSecOps Connect, and our, this was yesterday that we held it and it was focused on AI and, and security.
Well, interesting things that themes that came out of it was in an evolutionary sense, there's a point of which they're doing testing now of LLMs testing other LLMs, and yeah, there's benefits to not the same LLM testing itself, right? Of course, in other portion of itself. Um, but also doing that in a security standpoint, using that to test Yes.
Security Of the LLM or software coming out of it. Have you seen any interesting ideas like that? Doesn't it be that one, but kind of No.
So this is kind of unique novel. So, so some of the companies that I follow and talk to are really looking at how they can use that to automate threat posture management, how to automate, uh, threat testing, right? So if I can take and have something generative done based upon someone disclosing a, a new zero day, but yet we don't know what the attacks are yet.
If I can use the power generative AI and feed it in that information along with its corpus of information already has, it might give me a head starter, a heads up on what could potentially take place. So that ability to imagine the art of the possible, I think is something that's really gonna help us in cybersecurity. It's interesting if, if the attacks are driven by ai, ai, maybe we need AI to help us Quite possibly, right.
Respond to, yeah. AI plus humans. That's the perfect combination.
Right? Very good. Well, Paul, it's been a pleasure talking with you.
Thank You for your Time. Thanks for your, you and your threat hunters, you know, scouring the net. Thank you.
Always all know what's happening. And congratulations on the launch of side DNA. Thank you.
Wish you the best with that. So people doing the heavy lifting, right? Figure out how to keep our information, uh, secure.
So Paul Reed, uh, head of the threat intelligence with OpenText, again, site DNA, check that out. And that's what that happened today was as well as the other great, uh, security technologies coming out of OpenText. We'll be back with another great interview here on Textron TV at RSAC 2024.