Integrating Security into Software Development with Imperva’s Luke Babarinde at RSA Conference 2024
Luke Babarinde, a global solutions architect at Imperva, delves into the intricacies of application security and API protection. They explore the evolving landscape of security, emphasizing the need for a holistic approach that integrates security seamlessly into the software development lifecycle. Luke discusses the importance of governance, collaboration, and platform solutions in addressing modern security challenges, highlighting the role of generative AI in accelerating development while emphasizing the need for proactive security measures integrated into the CI/CD pipeline.
Transcript
This is Textron tv. Hi, I'm Mitch Ashley here at On Textron tv at RSA 2024, talking to all parts of security. Of course, I always love to chat not just about traditional security, but application security and what's happening in that space, supply chain, et cetera.
I have the pleasure of being joined by Luke Baine, who is Global Solutions architect with Imper. Thank you, Luke. Thanks for having me.
Great. We haven't talked before, so I'm excited to chat with you. Tell, tell us what a global Solution architect does beside architect global solution.
Well, you made it sound like a global solution. Architect takes all the global problems and tries to find a way to make it easier. Here's the guy doing that.
Oh, man. I'm glad we finally met. Yeah, so I, you know, I I, I travel around, uh, ss and r you know, strategic customers, uh, in being able to optimize what they have and being able to see the opportunities, uh, getting ahead of the trend, uh, before it becomes a problem.
Right? So optimize scale and, um, secure, right? You know, it's easy to think about companies just offering a solution or product or service or a combination of, it's a lot of the times, the reason why we work with each other, where we select to work with the company is the talent, the people, the experience that they have, not only working with us, right, but they bring to the table from other customers and kind of seeing what's coming or how to solve something maybe I as a customer haven't done yet, right?
I mean, what's, companies always are, we always try to stay ahead of the curve, right? For our customers. 'cause in a lot of cases, they're not aware of what's happening.
They're so kind of head down trying to operate a business and stay ahead of their competition, right? Uh, but what's really coming from cyber threats, uh, that's something that are each individual's kind of doing their very best to, to get on top of, right? But because of our visibility where we stand in the chain, we are able to help leverage the experience that we gather from across different customers and be able to help that, you know, kind of concentrate that and help clients benefit, right?
From that global threatening intelligence that we have. Interesting. At imp es Now, do you focus primarily in the kind of app sex space?
I mean, I'm sure you do lots of different things, right? Is that, is that kinda home base for you? Or just one of the areas that you Well, the best way to answer that would be if you care about your applications and maybe anything else around that, APIs, and you definitely care about data, right?
So data is my primary kind of passion, okay. But application is where I do a lot of my, you know, analysis and help, right? But it, the real, the real essence of that is to protect the data, right?
So I started as data engineer and then kind of, you know, branched out of that to applications and, and all the paths that are touching the data or communicating with the data. Interesting. Do this isn't a trick question to hear anything.
No, please go ahead. Do, do we do data protect? Do we do ourselves a disservice by thinking it just as a data protection versus application security?
Are they really kind of the same? I mean, what app doesn't use data? Well, I, I, I love that question, right?
Because you think of the objective what each entity or business or enterprise organization is trying to achieve is ultimately to protect the data, right? Uh, you think of their, the motives of the, uh, you know, adversarial actors, right? Whether it's service disruption or abuse of your service, or just, uh, steal, right?
Some, you know, fraud, right? Uh, you think of those use cases ultimately leads back to data, right? Or ability to make that data accessible to your customers.
Uh, that's, those are really the motivators, right? So if you care about application security, like I said before, you really need to think broadly about your overall data protection strategy, right? If you're not doing that, then you are kind of like, you know, it's kinda like you have a house that leaks and you are, you're kind of mopping the floor and cleaning it up, but the house is still leaking.
You gotta fix the roof, right? So we, we kind of have that approach in, in technology right now. We need to converge to, uh, kind of outcome based, right?
Uh, approach to better solve the problems. I think it sounds, part of what you're describing is kind of holistically addressing security, not patchwork Of not patchwork. Absolutely.
Yeah. Is sort of the Dutch finger in the d**e, right? Exactly.
Actually pops up and we go chase that issue, and meanwhile, we're not getting ahead, we're getting behind it. You, you mentioned to me, you've been with Aveva for about 10 years, right? A lot has happened in the ex AppSec.
I'm not sure if we talked about AppSec 10 years ago in that period of time, where do you kind of see where we are? Where application security, two years ago, we might probably didn't talk about it very much, I'd already say, versus now it's very much a topic of conversation. Where are we, where do we need to go next?
I mean, the, the transformation has actually been our, it's almost like, uh, you, you're traveling the street of light, right? Um, I, you know, I was around where it was, you never want to mention the word cloud and people like, oh, I'm not going to the cloud. Oh, yeah, that worked.
So we accelerated, we powered right through that. And now we are now at our, at another point where you have generated ai, where the inference engine is out being the, every business is like AI first, now, ai, first ai, but the fundamentals is still, the, the great part of this is the fundamentals is still the same. Networking is still the same, uh, you know, SQL of some kind, or no, no.
SQL is still consuming data somewhere. Data storage is still the same. So the fundamentals are the same, but the extraction layers are changing, right?
So, um, what, what the abstraction layer now becomes a major problematic area, right? Where you think about application security, where we are going, we see over 70% of the, the traffic that's going through our platform right now, being on the API calls, that was not the case five years ago, right? So now that number keeps going up.
So essentially every business application that you, you see, or digital service that you come across is being driven by Microsoft architecture, right? To make it easier, again, to scale for businesses, scale and, and, and respond to market trends, right? Uh, and what's really driving that, the API protocols that are normalizing that transaction to make it it go faster, right?
So that's kinda where we are right now, where that factor is still unknown to a lot of businesses, right? And actually accounting for what are your critical spots that you need to take care endpoints and you need to take care of to remain fully operational within the secure fashion. And so that's, that's, that's a problem area that a lot of our, I see a lot of costumes still struggle with.
Okay. Yeah. I, I'm curious your perspective on, you know, traditional security software development of sort of peanut butter, chocolate, like didn't talk to each other.
Now they're starting to, um, when it comes to APIs and application security, are, are we having the right conversations yet? Or what conversations do we need to be having between, I don't wanna say traditional security, right? 'cause that's, that's evolved.
Traditional security is firewalls and intrus prevent absolute, right? Absolutely. Right.
Um, but, but what we think of is security today, and we think about kind of application, DevSecOps, whatever you might want to call, right? It, it's, so you mentioned traditional security, right? 10 years ago that traditional security was like, you've gotta have this.
Well, we're begging people to have it. You've gotta have a web application firewall. Now that has become traditional, I would use the word foundational.
Like if you have an application out there, you doesn't have a web application firewall, you ask the question, what are you doing? Right? Believe it or not, there's still, you know, the niche customers that are, that still don't have that, right?
But now you accelerate to the point where even if you have a web application firewall, you have a, a really fully locked down software development life cycle, you know, all the dependencies, you know, all the supply chain factor, you, you fully count it for that. Uh, we're starting to see two major key, you know, problematic areas, which are, I call it two unknowns, right? Where you have the API factor, which a lot of enterprise still not accounting for, right?
And then secondly, the, the nature of the threat, right? So you, you're talking to the attack, you know, the tax surface being APIs, so that like expanded. And then you have the unknown factor, uh, from the, from the attack vector, right?
Mm-Hmm. Which are human mimicking bots automation tools that are now going after that data, after the API, the way that they've been designed to operate, right? Uh, and I think that's the, that's the main shift that we've seen over the last couple of years.
Uh, and a trend is going to keep, you know, becoming a, a key hotspot, right? For, for enterprise's users, uh, in the next, or in the next iteration of our, uh, innovation that we, we we're going through here. It, it seems like we, wow, we're trying to kind of the traditional security approach of, of protecting, put things around APIs, um, and now we're thinking more about how we build APIs securely, right?
Not just the API themself, but the kind of entire infrastructure, the stack that they run within the operating, whether it's Kubernetes and microservices, or it's a just a traditional rest, right? The type API, how do you, how do you advise customers on, here's how you start to think more holistically. Here's how you think about think APIs while thinking security.
I Would actually say it starts first with better governance, the little of a knot, right? Right. Where, uh, I would say for, for the first time, we have the need to kind of all move in the same direction, security digital teams, the business requirements, like kind of all converge and actually start having the right governance structure in place to facilitate the outcomes, which is to continue to scale and accelerate the business, right?
Uh, but a key part of that is how do you bring that together, uh, in isolation? Security cannot just write a governance document and digital teams that cannot own that, right? So we've gotta start cross-functionally collaborating now and making sure that security is part of that decision making process and the digital teams are involved, right?
Uh, working collaboratively together to achieve those business goals. Now, how do you do that? You start with governance and you start building out the right strategy in place to utilize, again, the traditional stuff that you already have, but how can you expand on that to accommodate for the cloud native development, you know, cycle that we're going through right now?
That's a huge challenge for businesses, right? Because we still have that legacy mindset where we actually need to shift where security effectively becomes, you can think of the security as code, right? Where you can actually pull security right into your CICD pipeline and not wait until the end of your pipeline and say, Hey, security person, come over, secure this.
It's gotta be natively pulled B, right? Uh, and, and moving tandem together, right? To achieve the goals of, of our business, uh, business objectives effectively.
Very Good. Um, you know, I mean, not news to you, but, and Perva covers many areas of, of cybersecurity, AppSec being API, security being one of them. Uh, what's kind of happening in that world today?
What are you here to learn about? I mean, we all come to do our normal job and they come here with our curiosity to say, I wanna hear about this. I wanna go to this session.
I want to find out, can keep my, my finger on the pulse of certain topics. What's, what's piqueing your Interest, right? The key thing right now is, again, API sits at the bad rock of that.
Uh, but a reason why we really care about the API I is the nature of the attacks that they face, right? So the business logic attack the api APIs enable your business logic layer, right? So the bad actors are effectively going after the APIs, the way that the APIs have been created to operate, right?
So now when you see business logic abuse, it's really to the EPI layer, right? But the implication of that is really the problem, right? What's the implication of that to a business, right?
You're talking, I think, is there a research out that as much as 10% of your revenue can be lost to APIs, right? And that's, that's pre that's a lot, right? Uh, and we're still not accounted for now going forward.
I think we, you know, at least from Imper perspective, we are bringing out the approach where you have a holistic view from governance's standpoint. We have the technology to support that holistic view as well, right? Where we're not, we're not creating fragmented solutions to solve this problem, but we are doing our very best on the technology side to make sure that we are bringing the solutions together, fully integrated, vertically integrated, to deliver value to businesses, right?
To support that agile motion the businesses are going through. So that's what we're going through that consolidated approach, holistic approach, uh, to make sure, you know, business can get the most value outta, you know, security investment. That There's a big emphasis on platforms, right?
Thinking about absolutely not just a set of vertical products that, you know, quasi integrated sorta, yeah. Uh, or, or a lot of work by the customer having to integrate those. When you think about platform solutions, what does that mean to you?
Well, Platform solution would mean that you're not, again, the, the new one that I'm starting to use more this week is our, are you fragmented, right? Because in a lot of cases, I ask clients that are, what's your, what's your application security strategy? What's your data security strategy?
And then we'll communicate 10, 10 different things, right? Uh, meaning you're fragmented, right? How can you bring that together, right?
Uh, using the best of breed platforms that are available, right? Uh, what we do very well, uh, starting with the data side, we have a platform that takes care of that. On the application side, we have, you know, the same kind of philosophy driving that platform to effectively make it a one stop shop for our customers, right?
Uh, if you put your applications online that are supported by APIs, third party APIs, it doesn't matter what it is to be able to get on that platform once and be able to tap into any of those services to give you our, you know, agility to respond to the modern threats, uh, that we see out there on the other, Instead of doing, spending your time doing greater transformation between products and trying to put it into some tool that'll be Exactly, we innovate within the platform to make sure that we stick to that mantra of like, one stop shop right? To nullify the threats that customers are likely going to face from the internet. Very good.
Well, I have to ask the AI question. Generative ai, this is a, there's no right answer yet 'cause we don't, haven't invented the future. How do you think generative AI plays in the world of AppSec and API security?
Any thoughts on that? I Mean, the great thing with generative ai, I use generative AI for copilot co-piloting. I want 'em riding my co right?
Uh, that's extremely powerful. It means now a pipeline that will take me days to complete, I can do that within hours right? Now, the implication of that is I can take my product.
If you think from a business standpoint, I can take my products to market a lot faster because now the codes are, you know, being completed in a rapid fashion with co-piloting, through AI generated ai. And when you think of the implication of that, again, on security, if we're already running or, you know, running the race with our hands tied to the back, it just got a lot faster, right? So how can we get on top of that where you have proactive controls around that and not wait for the code to drop before you pull in security?
Again, I mentioned security as code before. That really has to be the mantra going forward where security gets pulled into the CIC cycle, and then we move as fast as the code needs to go online. So where you have the protection built in to really make sure that you're not, you know, you're not having security as our second thought, right?
It becomes one metal part of the process. It's almost like we're pulling these three threads to the CICD pipeline of application, business logic, security infrastructure goes through absolutely all the testing, all of that Coming test cycle has you, you pull security and you've gotta be able to, uh, you know, complete the, you initiate the test and complete the test with security fully formed in it, right? Not just functional test or, or not.
You actually, you, you, you are always moving everything in the same direction in unison and to, to accomplish those, uh, those goals. Very Good. It's been a pleasure talking with you.
So always great talking to someone who's regularly working with customers and that's best point kind of fighting the BA battle with them, getting the speed that's figuring out on the ground in the trenches as well as kinda looking forward. And so it's been a real pleasure. Thanks.
Thanks for coming by. Um, I hope all of our watchers, listeners, readers I have folks will continue to follow and per a great stuff that they're doing and, uh, we hope we'll see you again on another. Thank you very Much.
Interview with text. Thanks for having me bb. Okay.
Alright, we'll be back with another great interview. Just a few minutes on Textron tv at RSAC 2024.