Hugh Njemanze, Anomali | RSA Conference 2023
Hugh Njemanze is widely credited as the ‘father’ of several cybersecurity mainstays including providing real-time analysis of security alerts generated by applications and network hardware (SIEM) and sharing threat information through trusted circles. In this interview, we will be discussing where we’ve been and where we need to go within cybersecurity as well as zero-trust, the cloud, supply-chain issues and automation.
Transcript
This is texturong TV. Welcome back to our Sac 2023 in San Francisco. It is a great conference.
There are so many more of us here this year and it's great to be interacting with each other. And actually returning is is Hugh in Germany who is president and founder of anomaly, he's back here again this year. We talked last year checking in on things how things are going.
Oh, you've got some some announcements we want to talk about but tell us about yourself. Tell us a little bit about anomaly. Yeah good to see you again A lot has happened in one year it has so things are always moving.
And I'll be very happy to discuss anything that catches your interest. Okay, great. Well, tell us a little bit about what anomaly does with the company does sure anomaly is a cybersecurity company.
We've been very focused on how you can make good use of threat intelligence to improve security effectiveness. And threat intelligence is something that has grown in people's awareness of it over the last I would say 10 years. And so one side of it is collecting that intelligence which is finding out who the bad guys are what they do who they target.
And the other side of it is taking that information and applying it. So obviously intelligence is useless unless you do something with it. And what we're focused on is applying thread intelligence to make security more effective.
So so there are the researchers who collect the threat intelligence. Usually that's disseminated as feeds. And then there's the application of thread intelligence which includes collecting it managing it Distributing it to security tools in the operations center that can make use of the intelligence.
And mapping your research to actual threats and organization is facing and so all of those tools are what we focus on you could consider us. A weapons provider in the war against cyber criminals to the good guys. That's right.
Good guys. Yeah that's important to note. We know you you've invested in and brought so much to the community in your career in this how do you see this part of our industry has changed.
I mean you mentioned 10 years ago and you think of the rise of rams it's wearing fishing and that's sort of the visible things that hits the the papers if you will in the newspapers if there are such a thing, how is it about how does it change from your perspective? Yeah, I would say over time the curve sort of has been that things started to get specialized in terms of the kinds of tools and what their focus or use cases where So we had firewalls which are basically focused on what you let into your network. And what do you block?
We had intrusion detection systems which basically people create rules to describe an activity that they want to identify and take action on and so it's essentially like did somebody delete a bunch of files? Did somebody log into a system they shouldn't have logged into So we have that as it applies to the network. We also have that as it applies to the host systems the servers and the desktops.
So I'd say what happened over time is these became more and more specialized and over time what you have is silos. So every one of those systems is collecting data from the environment. Typically, they're the only tool that can use the data they collect.
And if you have another tool they could collect actually exactly the same data, but they don't talk to each other. So you end up with these silos you end up with particular. What we call use cases things that you can do with the tools.
but I think over time as Everything has developed. You have more and more horsepower available to the good guys available to the bad guys. You have more and more collaboration between bad guys because they're not bound by IP or patents or anything like that so they can share more or less freely whether for free or for profit.
And so the Advent of cloud has taken things yet another level of scale. And it actually made the Enterprises the good guys. If you will have to decide between running their sensitive data on premise with their traditional data centers.
Or moving work to the cloud and the bias was towards moving the work that didn't require putting sensitive data up there. So as things progress the cloud becomes more and more powerful. Data centers become more and more of a thing for companies that had them before the cloud transition.
And so things are shifting as to where the center of gravity is where the data is that you want to protect where the even the logs are that you want to analyze so the notion of Big Data came about which is really processing data at scale. When you're dealing with security, this is very important because typically all of the activity is happening on machines being captured machine speed machines scale. So even if you compare it to it when somebody logs in in the morning, that's one event when they log out at night.
That's another event. But if a bad guy is scanning your network, they could be doing thousands of scans per minute per second per hour. So it's really a different level of activity.
And so what's been missing is sort of the same kind of Big Data approach to security data that has been applied to it successfully in the past. It's interesting all things. You said about data and silos you could take the word security or firewall or intrusion prevention and talk about Financial Services manufacturing or different parts of you know processes across the business.
It's been a challenge fortunately. We've we've worked on that challenge and it's domains too. Yeah, how do you think how do we solve that problem in the security world?
Because I totally get what you say. I mean your firewall is going to see probably a lot of what your intrusion prevention system let through and it saw as well as application firewalls and all kinds of other things that are in line to see those events. That's right.
I think you're insight about how this technology Evolution applies actually to multiple domains and not just security and in fact the way we look at the problem is There is kind of the infrastructure and the platform you can build and then there's the DNA that relates to the subject matter. So you could build a very high scale high-powered Big Data System. And then you could inject security DNA on top of it or it Administration DNA or medical procedure DNA set context that's exactly you know, that's what this data is doing what it means.
Yeah with the connections of those are yeah, and so what we've been very excited about recently. Is the notion of taking all these silos that have matured? And bridging across them.
So a year ago, we were at the same RSA where pretty much the word on everybody's lips was xdr. Mm-hmm. It was and it actually promises solving that problem.
However to go from a promise to a solution is a big step and I think a lot of companies that were already in one of those silos renamed their Silo xdr for the next release of the product. but that doesn't make the silos get bridged so long as in fact so long as the the core goal of your company is to be the site. Look it's also great way to get your project funded rename it to whatever the hot exactly.
Yeah. So what we've done is we looked at xdr as a pure play opportunity. And we actually don't care what it's called.
It could be called xdr. It could just be called. I want to solve your security problem.
Mm-hmm. Right? And so what we have built as a result of that is a platform that spans across silos.
is built on a modern Cloud architecture and the purpose of that is to give you a very high scale at lower cost. So in other words One of the deterrents for people especially in the Sim world in the past has been that you can only afford to provision a SIM for 30 to 90 days. Exactly.
That's many of them priced on that model exactly very prohibitive to yeah. So to have an attention span that goes to a year costs you four times as much as 90 days and to go to seven years people don't even consider unless it's a government-funded agency with a particular mandate. Hmm, so So if you take into account the fact that people are less.
allergic to analyzing their data in the cloud. And the fact that there is more computing power available if you build a good architecture. So we now have the ability.
To take Telemetry from all silos. Analyze it for specific use cases. Provide extremely fast search so that you can create your own use cases.
And provide answers to questions that actually go beyond specific categories. For example, we just ventured into a tax surface management. traditional attack surface management tools basically, we'll scan your system from the outside and tell you what where they see the vulnerabilities, which is very useful.
However, if you have 20,000 servers and it turns out 10,000 of them are vulnerable. Then you can call it prioritizing but it's granular the granularity means that you still have 50% of the work you would have done if you knew nothing. So if you combine that sort of traditional analysis with knowing what's going on in your network.
Then you can pinpoint which of the 10,000 that are vulnerable are being targeted are being explored are being reconnoitered. Are being scanned or actually have been accessed. And so that allows you to say, okay.
I've got 20,000 out of them 10,000 of vulnerable out of those 10,500 have been shown interest out of the 500. Some of them actually have bad guys dwelling in those systems today that gives you a very very clear picture not just of what you need to address, but the different responses you need to have for the different elements in your network or in your Enterprise. And so that just takes this notion to a completely different level.
In fact a year ago log for a j became a big thing. And again, the typical tools could tell you that there were 10,000 systems that were vulnerable. and I met several organizations where Is there even all the way up to their cisos?
We're busy writing Python scripts to try and sift through just the volume of candidates that they had that they needed to get down to a human manageable priority list, right? And so this is the sort of stuff that now can be automated in seconds. What's really fascinating to you.
If you think then now the the run the thread through that of that environment's also changing right because right it might be microservices that are you know, scaling up and down in clusters and kubernetes things in the cloud native or apps, you know, our infrastructure as code, you know, it's being changed. Yeah, so it isn't that you know, when we one report that we ran January 2nd and we're still working on today, right exactly that landscape has changed several times that day as well as every day true. So keeping up on that and being able to say We now have two more higher priorities than we did yesterday.
Let's make sure that's in our in our workload our pipeline. Yeah, in fact what you mentioned it reminds me of probably what's this year's buzzword, which would be chat GPT. Yes.
Yeah, so we do time with how long until the the conversation right that comes up. So we haven't quite hit the record, but we're close. Yeah.
Okay, very good, but the thing is All of those buzzwords artificial intelligence machine learning ETC represent actual technology Evolution and are relevant for solving problems years ago. We built a system called lens that reads articles. For humans, so typically if you go see a briefing from CNN or anywhere else and it's and you find it on the web as an article or a report.
It's going to tell you this has, you know, reading time of two hours and 30 minutes or 23 minute read whatever. And so for humans that pretty quickly adds up to eight hours and you can't do anything else with your workday. If you're going to read those so lens lets you read these kind of cybersecurity documents in seconds analyzes and extracts a report or a summary.
That's all clickable. To show you any threats that have been mentioned any techniques tactics people who are familiar with the miter attack framework. It can map all of these things that are being described in a document or a briefing that you're reading against your actual security defenses and tell you where there are holes.
You might want to look at it can also tell you if there are have been any vulnerabilities or successful attacks in your system that relate to what's being described. And with the Advent of chat GPT, which we are currently in the process of integrating into our workflow. Not only can you get the kinds of summaries and reports that we were providing already?
But it can expand give you recommendations tie different articles together show you Trends. So it's becoming more and more like having a human analyst expert sitting beside you guiding you through your work and actually doing some of your work for you. So it's very exciting.
And I'm sure we're going to see many incarnations from many different vendors. and finding I think finding good use cases and useful applications is what's going to separate the wheat from the chaff over time. I think one of those might be the csos writing python code.
They'll just use challenges right you exactly yeah anything else any new other news are kind of events happening with anomaly. I think that covers kind of what we're really focused on and excited about right now and we'd love to going up to an Eddie with anybody who cares to to look us up. com.
And always happy to chat with people great. Well, you're you're fascinating and enjoyable to talk with so thank you at our conversation. Thanks for coming back.
It's good to have you come back from last year and apprecially you will again next year. I would love to I'd be fantastic. You from anomaly is you can tell this gentleman knows his stuff and anomaly does as well, so please check them out check out their website if you heard RSA see be sure and stop by and and have that in-depth conversation.
I think you'll enjoy very much. We'll be back with another interview very quickly. Thank you.





