Norman Menz, Flare | RSA Conference 2023
Flare CEO Norman Menz joins Mitch at RSA to discuss how the platform helps customers identify data leaks from their environments and prevent data exfiltration.
Transcript
This is texturing TV. Hey everybody. Welcome back.
We are at rscc 2023 here in San Francisco, California. It's been a great conference so far. We have some great interviews and conversations kind of feels like roc's back, you know a little different than last year.
So let's begin being back. I've got to meet a lot of new people as well as folks that I've known for a number of years and one of the new folks is my my guest Norman mints. Welcome Norman.
It just had lunch some kind of like building back the blood sugar level here. So well, thank thanks Mitch nice to to meet you. It's great to be here.
And I agree. It's it RSA feels like it's back. It does feel like I said the first time and well in three years, so it's good to see the energy and all the people here.
Thanks. Everybody happy they're glad to see things kind of steer one time every year guaranteed to see all the people that you haven't seen in the year. I was just coming up the elevator.
There's somebody I know, you know for 20 plus years and he's going up to zoom call for Mars. He's so You're with Flare system. Let's talk about that.
We're introduce yourself and tell us a little bit about flare. Yeah, absolutely. So I'm I'm Norman men's.
I'm the CEO at Flair and flare is a cybersecurity startup that develops a platform to help customers identify anytime data leaks from their environment whether that data leaks on the dark web the clear web any type of public services such as GitHub paste bin sites Etc. And we want to help detect that immediately for our customers make them aware of it prioritize the leaks that they do have and then help them to take action to mitigate them or to take them down. Very cool, you know, one of the new terms that x-filtration right of data.
So which I mentioned falls into your camp and there's so many different ways that data can be exfiltrated. Right oftentimes. It's accidental.
So you have employees perhaps making a mistake maybe using an unauthorized service and not realizing the data is not secure and it's available in the public. We have third parties and then obviously what everyone gets excited to talk about is is the malicious actors right and and dark web Etc. But ironically enough the majority of the malicious actor activity is moved from the dark web and it's moved to the clear web or other services like telegram the open where if it's open in the open.
It must be okay that kind of philosophy which we all know, it's not a great. Well, it's not. Okay.
Well tell us a little bit about Flair and kind of some new things that might be happening. Well first before we do that how would people engage with flares that online service portal kind of action do they have to do certain things to set themselves up to be able to work with your product? How does that go?
Yeah, certainly. So we're a SAS platform. It's it can be full Self Service.
It's very easy to configure because we're monitoring things that are in the public domain and that frankly that are visible. We need very little information a lot of times just when the customer initially logs in we take their domain name from their email and we automatically start discovering their digital footprint. And so with that again, it requires very little configuration, but certainly There's an opportunity for our customer to come in and provide information that we can automatically detect that may be specific to their organization that will help us find other data leakage and thing and things of the past and so customers can go they can they can sign up online.
It's full self-service, but we always support all of our customers as well with the client success. Manager, so every customer has a client success manager can help them with strategy help them interpret results to some extent or if they do have an issue can help them with the takedown. For example.
Mm-hmm. I'm curious then how often is it more often that the customers engage with? You pre-breach something happening.
So they're prepared or is it you know, oh well now we should probably find out you know, but exposure looks like propose breach. Yeah. I don't think there's a clear pattern there but there's definitely use cases in both of them.
So ideally, you know and oftentimes too because we're dealing with things related to a breach we would like to make the customer aware of that. So we do we have a ransomware of file monitoring capability. So a lot of times if there's ransomware there's data exfiltrated and then also the threat actors will extort them and release some of the information and if they don't pay more they'll threaten to release more of the information and so we'll we have a capability to detect that information allow customer to download it very quickly essentially getting of life just to verify that it is their data and then make a decision for the business about how they want to do that in the instance where it's post breach flares use very often for forensic information.
So we've taken an archive of the all the cybersecurity related sites on the dark web since 2017 customers can search that offline. That's good because it's Anonymous and it also is by its nature allows them to see things that maybe aren't aren't there tomorrow or what they're yesterday, but may have been there a week ago. And so that becomes very effective and then due to the nature of having access to the entirety of the internet.
They can see all the information that's out there even something that might not be part of a particular breach. It may be used in the future. There may be other people at the same point now that there's some awareness of that trying to exploit it and what you kind of is one of those layers of you start to discover this and that takes you down to certain.
Yeah, but with with security cyber security in general like best practices always the best prevention and and so hopefully customers can use our technology and other Technologies to you know to prevent Shower breaches, you know and mitigate those risks, you know, there's several kind of different types of dataex filtration and exposure. One of them is your own corporate information employee information. There's also customer data.
I mean, I've heard scenarios of post breach if you're not negotiating good faith, they're not paying the ransomware, you know, suddenly your customer gets an email that says by the way Mitch's company has been compromised and they're not playing well and if you don't want your data out there, you know, so it's interesting knowing that would also be helpful is like just not our stuff but it's our stuff about other our customers. Yeah, and that's what makes it really tough. I mean we even ethically to you you have it, you know, if if you have engaging with a threat actor, you know, they're gonna be asking for a ransom.
Do you want to enrich them through that and it's that balance of protecting the information that you have and the trade-offs that are associated with it. And that's not typically something normally customer. Our customers are working with their their legal teams.
And other people were involved in incident response for those types of decisions. We're very cautious about doing anything to enrich the threat actor community. So some more I'm curious about moving from the dark web and more of it into kind of in the public domain.
What does that look like? Why is that happening? Um, I think there's a couple of things first of all, you know, the dark web if we Define it as the onion Network or tour and so the nature of that network is very slow.
It's difficult to use there's a lot of anonymity that's possible now through the clear web, but the number one clear web Source we see is telegram you we currently monitor, you know close to 4,000 telegram channels for actors, you know malicious actors engaging and you know, sharing techniques exploits vulnerabilities and specifically targeting organizations. Interesting. Do you see, you know, we all heard about the Discord attack.
Do you see other platforms like that Discord maybe better protected than telegram. I'm not just familiar. Maybe you know, but you see other platforms like that is go where people are sort of hide in plain sight kind of strategy.
Yeah. No exactly. So there's a lot of it's interesting if you look at a lot of for example, Starting with telegram.
If you look at a lot of the telegram posts, they'll link to other services like you've mentioned so oftentimes you'll see because these different Services have different capabilities, right? So if you want to do something that's effective at sharing screen sharing or something like that. You would go over to Discord for that.
Right? So you'll see a link in a telegram post then redirecting over so to speak to to a Discord server, but we see, you know, probably telegram being the number one source as I've said Discord being an interesting emerging one Reddit. In fact is actually one as well.
And you know, these are the ways in which people are kind of communicating interactively. And then you also have these One Way Communications things such as different pace sites where people are sharing information or perhaps even using this to as part of command and control architecture, right? So you've got some type of malware.
It's got to get its command and control instructions from somewhere and we're seeing that also now on the clear web services because you can just use normal, you know Communications to get that information. I've heard people you've been using Dropbox and Will drives and all kinds of you know things we wouldn't like. Hey you that you would want to hide it better than that.
But yeah, you don't need to because they can move it so quickly. Yeah, there's some you know anonymity just through the the volume of it and and the obscurity of it at the same point great. Well tell us a little bit about what's happening at flare me with some new things that either recent or kind of coming down the pike.
Yes. I'm sure everyone's been talking about chat GPT and measure how far into the internet we did. We're doing pretty good ever not quite the quickest but we're in the we're in the top three.
Yeah. So certainly I mean our team our data science team has been using, you know machine learning on other forms of AI for the past several years and obviously to analyze data help prioritize the events that we see for customers and recommend actions and and make predictions as well. And it's been very effective at doing that in the right cases and with all things when we talk about AI it's the right application and you have to do it responsibly and and I say cautiously optimistic right but one of the things that Really excited about kind of giving that as the backdrop and all the hype around generative AI is about a month ago.
Actually, we released a generative AI capability that we call AI assist in our platform and the intent of it is is several fold. So the first one is as we know there's a there's a great shortage of skilled cybersecurity people. I think the statistic I often quote is there's six to eight million unfulfilled cyber jobs.
It's not getting fewer. It's not going to get fewer and so you have a lot of people that are interested in coming to cyber but don't necessarily have several years of experience to interpret that. So if you think about a dark web post or post on telegram, right, so we look at the malicious actor events, you know oftentimes it's difficult to understand what they're saying.
They're using slang. It may be in a different language. You might not understand the technique they're talking about or the importance of the vulnerability.
It's impact on your organization. And so with our AI assists what we do is we take all of these posts and we essentially Socialize them in real time using generative Ai, and so instead of just looking at a post that you're talking about folds and caching out and all these other slang that you may not be familiar with or maybe you are but you don't necessarily know the other context to it. What generative AI is able to do for our customers is provide that full context so it can take that information and tell you what else is that threat actor talking about what type of organizations do they typically or Industries do they typically Target this vulnerability that they're talking about.
How is it relevant to my organization? Is this a new vulnerability is an old one? What potential platform is is being exposed by this vulnerability and then even organizational specific context such as is this relevant to mind.
Is it specific to me? And what is the criticality of this particular event? So you can take something where it would normally take an analyst perhaps several hours to go through do all the research to understand who the threat actor is and in the impact on the organization and it's done instantaneously in the platform and allowing organizations to respond more quickly.
And then also allowing people to get full context and awareness even though they may not have the experience and it's impossible for anyone to know everything. So that's something they were really excited about and as we continue to push in on, you know, I think some of the recent advancements because it's amazing, you know, we started evaluating some of the degenerative AI back in the summer and looking at it and frankly, it wasn't ready. It didn't really produce results that were useful and and really I kind of defining the the generative AI epoc is like three months ago where everything started a fresh and and then you know with the the recent advancements of it, you know, we're getting continue to push that so one of the other things that we did as I mentioned before we took we've archived the entirety of the dark web for the last five six years now and you know given that using generative AI in the last two weeks.
We were able to generate over 2 million threat actor profiles from the day that we had previously and prior to that you would have to do that manually or through a lot of other methods and so the technology Be very difficult to do it would be very very expensive. Yeah. interesting, so you know, we haven't really thought about sort of the Your way back machine for the dark web if you will.
Yeah. Well, they roughly the equivalent but that is a treasure Trove of information of what's happened. How's it happened whose communicated to what we mean that who didn't know who they are personally, but you know, they have various personas personalities online that you can track back to those activities.
And where's that trajectory of that heading based on what you're seeing now? Yeah, and and actually through I hate to say more traditional forms of traditional House of three before the epoch, right? So we've been one of the things that we did along that note is we used some machine learning models and and natural language processing to actually look because a lot of times when you look at threat actors, you know, they'll post on Discord using one person or handle and then on a dark web form and other and another dark from perform another but sometimes it's the same person and so what you can do is you can use natural language processing for example to look at their patterns of speech look at their words.
Look at their abbreviations. They're slang Etc and and other Telemetry information that we can get from those posts and start grouping them together. And the reason that becomes important is imagine, you're a large organization.
You're currently tracking 200 threat actors that are targeting you well imagine if 50 of those thread actors based on their their handles are actually the same person or same group of people you now have a much more targeted threat and something that you want to look at and so that's kind of you know, that's the benefit of having that large archive or you know, I like the way back machine example of all of that data so it becomes useful in the future not just for Trends but also for building more context about about different different activities oftentimes the methods that we that are used are changed to keep security high, but what they're fundamentally doing if it works. Oh keep doing the same thing if you can pick that across multiple profile or handles look at that volume of activity and say the names have changed or maybe some of the places that but The same yeah activity so you might be able to provide some Predictive Analytics of what are the likely next? Yes steps that could occur and and as you know, like I know we're talking a lot about malicious actors, but there's no honor among Thieves, right?
They're they're you know, and with some of the malware as a service platforms and things of that nature you'll see like almost complete codes swipes where you've got the, you know, a particular a malware platform being stood up with one name that's clearly, you know, 95% identical to another and and so, you know, but the same happens for techniques as well where it's constantly being traded and and that information there. So there's some very novel approaches and then there's a lot of reuse of of other techniques as well. How do you differentiate in that case service, right.
We'll see actually it is a business. There are like support for a lot of those those toolkits and things what do you think? Where is this headed?
Where do you think we're headed with data that's been exfiltrated from you know, anywhere in organization was the cloud or local. What's the next kind of Frontier? You think that that threat actors are going to be going after or maybe how they're gonna how they're going to be able to get to it.
Yeah, it's an interesting question. I'm think the first thing I would I would just emphasize is that the majority of the data leakage is coming from in employees and vendors right like by the by the numbers and statistics. But again, these are accidental and the intent of them is different.
So the risk is typically lower which is why you want to detect it quickly and perhaps remove it right? But you're absolutely right on the the threat actors because the intent is malicious and it's it's almost always financially motivated. Obviously we've seen recently some instances of Activision, you know, where they're ddosing, you know different Services because for political reasons that they don't necessarily agree with them.
And so I think you're going to continue to see that so in terms of where is this going I think we're going to continue seeing application of Technologies to detect and defend against it in the example of DDOS. We see a lot of adoption of some of those platforms to help organizations deal with those attacks and you know, the other thing is organizations have to you know, continue to be vigilant. I won't Use the word do a better job but I don't want to be critical because it's a really tough job.
You have to be vigilant about classifying the data, you know restricting access to it where it's minimally possible, you know, but it becomes it's a very difficult thing. I mean you've mentioned before the Pentagon papers, right you look at what were the methods of exfiltration there, you know, somebody took their camera. They took a picture of it, you know, not impossible to detect right but you had a little bit of obscurity there because it's on Discord clearly.
There's OCR capabilities where even though it was a picture of an image or a presentation of a file, you know, clearly the Technologies is there but you had to see it first, right? And that's the the broad scope of it. So I think in order to you know to be specific about the question is it's really having that the technology and the visibility to as many of the far-reaching places if you will of the connected Network Cool, what would you say kind of last thought here?
What would you say is maybe the Maybe most misunderstood or least understood aspect of you know data loss and and how that can either be used or what you can do to recover what people think about this domain a certainly when that's not their key expertise. So sometimes we sort of fill in the blank. So what we think logically makes sense and that isn't always true if you had to help someone with like one thing I would think about a little bit differently that might help you is is this I would think that the and I may give an answer that maybe different than You're Expecting but I think there needs to be a mind.
Shift in terms of people's expectations around that there's a lot of people who believe their data isn't out there and that all of the property security controls have been implemented because there's so many ways to bypass it. It's pretty assured that the majority of organizations especially as they get larger all have data. That's that's leaking and it's sitting out there waiting for people.
So, you know, the one thing I'd say people don't expect is they don't expect necessarily to find data about their organization and it's and and I don't mean to be to create fear but it's almost always the case statistically that there's needed out there. Even the largest organizations except that and they have very mature programs set up in place to detect it quickly and to mitigate it right because a lot of times when that information is out there, even if you take it down you don't know who else has already has access to it. So you have to monitor, you know, if there's a particular asset or user for example that's been part of that data leakage.
You have to monitor that and look for suspicious activity. You have to continue to do that. Vigilant about it, but I would say the one thing is a oftentimes people feel that they're they've done everything correctly and that there's no data out there.
And unfortunately, it's not the case another percent now. Well nothing in insecurity of the 100% so it's kind of like so if you'll be attacked it's yeah, it's when or how often not if your date exactly it's there. It's just how much of it and sometimes like it's interesting.
You say it's not If but when the interesting thing is sometimes organizations don't know right like especially if you're a third party to that organization, right? So let's say for example that you're dealing with a a law firm or something like that. They're doing m&a work for you and maybe they have a ransomware attack and some of your data is part of that gets exfiltrated.
They may not be aware of it. We know the average time to detection for a lot of data breaches is over a hundred days and it varies by industry. And so you may not know right away about that.
Also, even if you're doing everything right exactly all of your partners and employees are yeah. Well remember it's been great. Absolutely.
Yeah with Flare. I hope you come back and talk with this again. It's a great topic at RSA and anytime during the year, too.
Yeah. We'll Mitch it was a pleasure being here and thank you very much for having us you bet. Yeah and folks where they can they go to they give some ways that they can check out.
Yeah. io on our website if Interested in seeing what Flair does you can certainly get information from some of our online research papers some of our blog articles and and frankly if you want to look at the technology the best way to do it is we've got a full self-service free trial you can go sign up for it and get full access to the flare platform start to see what data is out there. Absolutely quickly.
Okay. Thank you very much. Good to see you again best of luck with the rest of the show and hope to see you soon.
Absolutely. Thank you as a pleasure great. They said fantastic conversations with some amazing people as we did with Norman here.
So please stay tuned come back. We've got more great videos coming up with the topics and interviews. I'm sure we'll be interesting to you all.
See you in a bit.





