Karl Triebes, Imperva | RSA Conference 2023
Bots are capable of more than scalping next-gen consoles and making it harder for consumers to buy the goods they want. Bad bots enable high-speed abuse, misuse, and attacks on the business logic of critical apps and APIs. Learn more about the security risks of these automated threats and what trends Imperva has monitored over the last ten years.
Transcript
This is texturung TV. Welcome everybody. We are we are at rsac here in San Francisco 2023 having some a fantastic conversations.
And I know the next one will be another one because Carl and I've had a chance to spend some time together and prior discussions. I'm joined by Carl trebus who is SVP product management and GM application security. Sorry to read the cue card, but it's quite a mouthful title.
It's a lot of responsibility. Yeah. I know.
I appreciate that. Thanks for having me here. I'm excited to be here and talk to you today.
So tell us about you and tell us about a little bit about your role at the perfect. No, absolutely so at imperva. I'm responsible for the application security business unit.
And we formed that about a year ago about a year and a half ago when I joined the company that's pretty release previously with AWS. I spent many years at F5 in previous company. So I have a long kind of history and the application security space and but the one of the builders be you because we specifically wanted to ensure we had you know, that that intense focus on our application Solutions and our roadmap and kind of what we're going to the Future and kind of bring you know, the experience that I've had and help build the team and you know a whole group around that.
That's what I've been doing this last year and a half and so very representative of the market kind of all of us have shifted from just security to also application security and how that's part of the bigger picture. Yeah. Absolutely.
In fact, it was interesting because you know, I go way back to the early days of application security and the whole idea around it was the perimeter was changing right before it used to be more you have an edge device. You have your firewall you have a TMZ and you're trying to protect there but but the real perimeter was around that user session and how they're accessing content that the application is managing. So how do you protect that and so now today we've we're extending that obviously over time is that because there's new types of threats that have come but the application is always been that kind of that fertile ground where these attackers go and try to mine and you know plant their seeds of Discord to extract your data and that's and they've been very successful in some cases with that.
So it To be an area ripe area for them to go off and attack an applications. Of course change. The application footprint has changed massively in the last, you know, 10 years.
It's no longer these monolithic apps. It's you know, it's now these very distributive apps that are running on different types of infrastructure. They could be apps that are running your Cloud vpcs.
They'd be running in kubernetes clusters and these could be of different types of kubernetes clusters. They were running as virtual machines, but they're highly distributed and you know part of the rationale for that is that it gives you in some ways I think of as like Java to dino, you know, Java when Java came out the whole idea right was that hey, I can run this on any hardware platform. I no longer have to just build my applications to be targeted for a particular CPU type.
That's what's happened with kubernetes and infrastructure and applications is now I can run them anywhere so that and containerization and now the fact that we build our applications more API for API Centric that is kind of the new attack service, of course Lots love. That right. How are things to go after talk a little bit about that because you actually are right in the center of that in so many important industries like finance and and others absolutely, you know, the world has gone to apis and part of that is that there's the whole aspect of automation.
So if you look at your your phone any individual app is accessing, you know, maybe 10 11 apis during any particular session. So, you know, that's the whole mobile, you know world now and in fact, we you know, we're going to be publishing our annual bad bot reports here in a couple weeks. This is our 10th edition of doing that but one of the things I think is interesting now is that when you look at the application traffic over 60% of it on the internet now is mobile based and so what we're seeing is that transition to more the mobile devices, but but on top of that there's interesting and unique challenges because now the mobile, you know, like apple and others are providing all these privacy features.
Is but with those privacy features, they allow your attackers now to obfuscate be obfuscated. So it's actually created a new attack surface for example, so that's that's one area that we look at but overall when you look at bot traffic about half of the traffic on the Internet is basically bot-based traffic. So just under 50% and that's a 5% increase in the last year alone.
And that's pretty steadily that we've seen these increases. There's a variety of reasons for that obviously, but badbot traffic is a large percentage of that, you know close to 60% of the bot traffic out. There is bad Bots doing malicious things in many different ways everything from trying to take over accounts or steal data or create DDOS floods you name it?
And so that that's the big Trend that we see and one of the areas that they focus their attacks on now our three apis because API is do not have the same Legacy of kind of a traditional web front end application back in and all the mechanisms you build, you know into that apis or freeform. They are developed by developing. They're built by developers managed by developers and the security teams have very little control or management over that because it's been part of that workflow.
And so those have become that big attack surface now in Bots just line up nicely with that. Yeah, what we've completed aside. I don't know whether to start to show called bad Bots bad Bots, or maybe there's a band I should start called bad.
But anyway, yeah. It's interesting because I mean just operating us as much smaller infrastructure myself. And you as a company who not only a product company, but you have your own, you know Cloud provided.
Yeah, it's something you deal with directly as well. So you see it yourself as well as what you see through your customers and what's happening. Absolutely.
Yeah. In fact, that's one of the benefits, you know, we provide a you know, we have a large SAS based service and we we have a run our own network of Pops Global pops. And we we see about nine trillion.
I would see attacks in a given year, you know, so we see a mat we get a massive amount of data and we leverage that data, you know, obviously we anonymized things like that but we leverage that because we're able to then see something that affects One customer or developing and then we can apply those rules that we create for that customer across our entire base. So basically you get kind of that crowdsourcing in a sense of the data now we use all sorts of other feeds as well. But but that's that's you know, we see a lot of benefits to being able to provide that type of service.
The other thing is that we Update it real time. So for log4j, for example, we saw that the attacks start to occur. We started seeing them about a week beforehand and we went analyzed those and we'd actually build signatures and had those deployed long before the announcement came out and then as the attacks mutated we were still on top of that we could see that and we're automatically updating and blocking on behalf of our customers.
We we literally add you know or change our rules on a daily basis, you know behind our WAFF for example, so, you know hundreds of rules, you know, and we do that transparent, you know transparent to our customers. So they basically they get the protections. They don't have to manage to roll.
It's just easy to onboard and so one of the stats is finding. So when I first joined imperva, like I said here 18 months ago, they said they go oh 90% of our customers using some blocking mode right out of the gate. And I said no way that's not yeah, I wouldn't have guessed.
I wouldn't have guessed. I would have said 25% best case at the time maybe and I thought yeah exactly, maybe 20% you know, maybe 50, you know, if it just couldn't my experience so and sure enough that was the case. We went through the data and I went wow.
That's an amazing for that. That's for Jack. So I was you know, so it just speaks to the effectiveness.
I think of of having that type of curated service that we can manage and provide out to our customers. And so you know, and when you look at kind of the way we were architecting our roadmap and our products and we talked about kind of this be able to run anywhere motion, but it's also about ease of Security Management, you know that, you know, we you know, there's an interesting report out that we published. Well we didn't publish it but security Labs published it and they basically tested a bunch of different providers in our space and we wound up having what they call the highest return on security investment of all of them by far.
We're kind of that whole position and what they evaluated was was Miss the security so that we block, you know, these different attack types. They measured false positive rates, which goes back to what I was just saying about people being putting us in blocking mode because you don't need that alert fatigue. And then the third thing was they evaluated ease of management, you know and updating and how you manage it and you take all this three into effect and boom.
We were the top notch by quite a quite a spread actually. So so we're excited about that but that it's exact. You know, finally we got recognized for something the other analysts don't necessarily recognize you for that speaks to the core value proposition of imperva and in our portfolios, so so we keep building on that, you know make that easier because at the end of the day, I think the threats continue to get much more sophisticated, you know AI is going to create a whole new spectrum of problems, you know for for applications.
And so we need to stay on top of that on behalf of our customers because it's so hard for them to be able to do that and that's hence why I think that whole, you know, the RSI is such important metric thing very much. Know, you know that that high automated block rate. I think I was also represent the patient of trust the customers having you right wouldn't do that if they didn't trust us if you're making that kind of change to adapt.
Then obviously they're counting on you to do that and do it smartly and wisely and you know proof is in the pudding. So that's that's great news. And yeah, absolutely.
I'm curious about your thoughts. You mentioned AI we monitor by the way have our end to every interview before AI comes up. We're pretty well on track here.
So I checked the AI bingo card very yeah exactly the deck comes down, you know, give me your thoughts about the role of AI today in security products and technology and also, you know, how do you see the attackers leveraging that I mean, none of us can predict the future it'll it'll happen the way it happens, but kind of what do you see that right look like yeah. So we use a lot of AI today on the bot front especially because you know, what the Bots, you know, if you'll see this in the bad bot report like I mentioned but the sophistication of these evasive Bots that's about half the Bots that bad Bots that are out there, but that's sophistication continues to go up. And so today though for an attacker to build that they pretty man.
They basically have to get the sit down with the code punch it all out. Try it. See what comes back update it try it.
Maybe they build some of that into the code that can do some of these things and more automated way, but they're the ones basically you have a human in the middle of this recursion as they go through and try to try to look at that. Well, you know and that works great for us because we can block and defend against that but now imagine being able to put a cell phone model in the middle of that instead of that human so it can much more quickly adapt and update so it's kind of like over your Star Trek fans out there. Remember the borgs, you know, and you know how you you know, you had attack and then they'd start rotating Shields and things like that and suddenly, you know, they get offend.
Well, that's exactly because they've learned. Well that's exactly a type of thing. I expect to see from the attackers.
They're gonna learn a lot quicker and be able to zero in on attacks. So for example, let's say you have a big breach like a data breach and they get a bunch of these files. They're gonna go out.
Start just instantaneously after all these ATO style attacks. And so as a as a security provider, we actually have to you know, essentially provide that rotating Shield as quick as we can as they learn we have to learn faster. And that's our that's how we think about our use of AI is the ability now with these generative AI systems is that we train the models based upon what we're seeing and quickly then update and iterate that and also use that in predictive ways where you can say, ah, okay based on what were these behaviors now?
What would we expect to see based on that? So we're actually trying to predict what the AI is, you know AI is going to do with that. And so that's why I see one major area of that but we're using now we're using it through all parts of the organization as well.
Like on my product marketing team, you know, we're actually we actually built an interface web-based interface that helps us create content much more quickly, you know, so to me, it's like a force multiplier, you know, things like that. And so we're using it elsewhere within the organization to help assist us do things. Faster not just on the security side, but also on helping educate customers and produce content things like that.
So it's very broad-based. We have to keep us from be all becoming look cute to support, you know, I might start. I was just watching Picard last night.
Excellent. Well, let's let's shift and I appreciate your perspective on AI very much very much not our first rodeo at rsac, right? Yeah, we've been to several of these.
I'm curious about your perspective on on how this year's changed. Yes. It's changed as in we're kind of backing us the kind of feels like the healthy vibrant rsac again, but what's your perspective on what's different about this year than maybe in years past?
Yeah, you know and we're talking about this earlier. But the one of the trends I think is going on is what yeah. Yes, we're back but I think what we're seeing now is an acceleration and change of customers infrastructure and the applications that that is that during the covid lockdowns.
A lot of a lot of organizations companies went into kind of stasis mode. They were trying to preserve what they had. They're trying to support the remote work force, their, you know, trying to ensure business continuity through kind of that that scenario and so they had to invest in those areas.
But now coming out of it, you know, one of the things that affect us at a ciso Roundtable a few weeks ago and this is pretty common when I talk to our customers is that the big quote was we want to do less with less. So they're looking at ways to consolidate their security services so that they don't have kind of this conga line of different products. They want to get to more.
I don't want to say a platform approach, but they want to be able to to the narrow down the number of their kind of trusted security Partners work like City, you know absolutely costs or managing that cost is a big factor in that in fact, and then the second piece of all this is that now as they're as they're trying to manage their costs. They're trying to to change their infrastructure to help manage with that cost. So, you know before that's all right.
We're in AWS, we're gonna stay in ebido at spite the cost. Well now it's like well, wait a second. We're going to go more multi-cloud.
We want to optimize. Maybe we'll run this service over here this one here, but we don't want to be so beholden to any particular Cloud Player and that's one of the big things we see. Out is multi-cloud.
And also even a lot of customers bringing some of their services back into their own infrastructure their own data centers. I don't think they're going to grow their data centers massively, but they want to have that choice and an optionality because once you get locked in to a cloud the cost just go One Direction, you know, and they can they can spiral pretty quickly having been in you know working for one of the major Cloud players myself. So I know exactly kind of that some of the challenges there, but but so I think those are the two big things is how do you manage costs and then on top of that it's like, how do I get on top of these new threats that are out there these business logic attacks.
These other very sophisticated attacks that are occurring so that I don't have to hire these very vertically oriented sophisticated security teams that are very expensive and pretty much unobtainium for most companies, right? So that's that's kind of how you know, that's I think those are the factors that are changing the conversations here at RSA. So what's been great for us as we've just had really good in-depth conversations with customers not these superficial kind of fly-by things.
It's been you know, very meaningful like Hey, how do you help us? you know try to solve these issues and so it's it's nice to see this, you know back, you know, it's a really good point because I was talking with your your CTO see so canal and on and here and I were talking about we've kind of entered a next generation of cisos who weren't strictly kind of came up through the Sort of paranoid Network, you know kind of mindset or don't tell people what you're doing don't share what products you're using to people that maybe have some more software experience, but are also have an open more openness about wanting to share Converse and talk and how you solving this problem. What's happening here.
Are we on the right track? Are you and you know, it's let's collaborate more across maybe within competing inside an industry. Yeah, absolutely.
In fact, you know, I think it's very analogous to what happened with CFOs years ago because originally CFOs were more focused on I'm managing the finance side of it. I'm you know, the accounting pieces of it but not necessarily a partner in the business and so over the last 20 years that that changed radically where this the the you feel good a CFO. Yes, they still have those responsibilities, but it became more of how do I partner with the business units or with the you know, the sales functions and all that to drive the business to grow and how do I become a piece of it?
Not just kind of you know, so being more proactive the sea has done the same thing. Yeah, and it's that the problem is that you can create all sorts of obstacles, you know and security because you know security is one of these it's a spectrum of things you can do. And in fact, you know, I've always said selling securities like selling an insurance policy that that you're only willing to spend so much for perceived level of security and and there's a lot of things that go into that right.
And so so the cisos could be way up here and they could be you know, hurting the business because they're not taking a more pragmatic partnering approach. And so when you talk to kanal that's been his approach is how do we partner and ensure that that we have the right, you know, absolutely the best security but let's ensure that that it's it's aligned with our business needs and our customers needs and what we're doing there and so it's a more collaborative system and I think that's a general a trend over most executive roles in the industry is as we've kind of moved more to that instead of these strict kind of you know, you know functions that would have existed, you know, 25 30 years ago, you needed that level of conversation the engagement with each other. Yeah, absolutely because you know, a lot of the problem too is that there's a lot of you know, we're going, you know, we do the PCI audit process for example, and so there's a lot of nuance to to understand how that your systems are either vulnerable or affected that that you know, you need to be able to have kind of that close loop conversation to say well Here's how data traverses our Network and here's what it accesses it.
Oh now I understand that. So yeah, you don't need to change that. But over here, we see that, you know, it becomes more of that kind of conversation like saying instead of them coming with some templates and saying You must conform to this and then you go through a to your Dev cycle or something like that, you know, you can't have that.
It's the business needs to move quickly. And so and hence every part of the company needs to move at the pace of the business and so security has to be a part of that. You know, we actually said this with our customers as well.
Is that like, for example, we're seeing you know, the business teams now have much more say in what security products are getting selected because again, it goes back to it goes back to the pace of business, you know, and and it's Things become competitive, which I actually you know, you see it in the tech markets, you know, all these, you know start, you know, startups is things are getting more competitive. And so you need to make sure that that you have a way to move faster than that competition. I think it's a great note to end on right there.
Terrific Carla. Hey, thanks for having me now good stuff. Excellent Carl trubis with SVP with imperva.
You're welcome back anytime love talking with you. Thank you so much you bet. Yes.
We'll be back. We've got some other great conversations. So from rsac to you.
We'll be back in a few minutes.





