Rick Moy, AccuKnox | RSA Conference 2023
Rick Moy, chief product officer of AccuKnox, joins Alan at RSA to discuss the open source project KubeArmor.
Transcript
This is texturung TV. Hi everyone. We're back last day RSA here continuing our coverage.
You know, one of the nicest things I like about RSA is especially this year. It's getting to see my people this guy. Here's one of my people his name's Rick Moy.
If you're in security, you probably know redwoods. It's called cyber now, excuse me. So if you're in cyber, you probably know Rick and if you're not you may not but hopefully you'll get a chance to know him here Rick.
Welcome to text strong TV man. How are you? I'm excellent because I'm here with you.
We're here chilling on a 40,000 other people. Yeah. They're way over there.
No, they're out there. A lot of them are probably going home already because yeah that is that too right? There's the people like man.
I put in my two three days. I I got to go. You and I you were in kubecon with me in Amsterdam, we've been on the road for two and a half weeks guys with we have go go.
It's crazy. So Rick for those who maybe aren't familiar with you. Don't why don't you give him a little your background?
a little of my background well I've been in security probably longer than it's a little embarrassing when I start thinking about how long but I started actually as a practitioner managing that works was a software developer early on ran engineering and product management teams that early like you said security companies. Before they were called cyber, right? We didn't call him side.
Right? So I was with the company called that eventually became web sense. So I launched that product as you know, and then we crossed paths that.
A number of other startups protego Mars was I remember I got the same business. I got you got recruited into the antivirus business in 2005. I was a cash cow business wasn't it was a it was a cash cow business, but honestly, I went Kicking and Screaming originally when I was You know asked to to bring this Eastern European company to the US.
Because I thought this he said it was ESET because I thought this is the time of semantic and McAfee and you know, what else? Could you need right like it's a saturated? Yeah, but the more I looked into it the space was saturated, but there was a lot of dissatisfaction with the customers, right?
Well look, so no disrespect to ESET or any of them. But as we look back and sit here today. A lot of them weren't real effect of I mean they were cash cows, right?
And when you look at the top 15 Revenue based again companies, I think seven of them were we're antivirus providers, but in terms of Keeping a safe. Let's say then to now. A little different.
Well, that's a great segue to the next thing I decided to do which was my experience in the AV world was. Hey, everyone's got a hundred percent but customers still getting whacked. So all the time, you know, and it's not just AV but intrusion prevention firewalls, there's a lot of security products that people didn't understand.
How do I evaluate this thing? So me and a couple guys started a company called NSS Labs. Absolutely and our goal was real world testing to help help the buyers understand.
Hey, how does it perform against real-world attacks? That was not a term back in 2007 real world. Um, the way we folks were testing security products was static not on the live internet not not really facing the threats that the real act very controlled environment.
And the question was who was controlling it right? I mean There were a lot of pay for higher kind of evalued going right? Yeah look.
Suffice to say that the guys from SC magazine Labs never talked to me again. Because I called them on it. Yeah, right.
Yeah me just so people know right the state of the art when Rick started NSS Labs was that you know, the typical eval that was conducted in a magazine or something and I'm not pointing fingers at them. But yeah would be like every single one was five stars. There was never a four story let alone a two star right and and the list of the pros was always this long and the list of the cons was was dependent on how much they paid quite frankly.
well Look, it's I said you don't have to thank you. You know I try and try and be objective, right? That's really what was my goal with NSS.
So I didn't have any any bones to pick. Yeah, but I've been you asked about my history. I've been both on the vendor side and the practitioner side and the independent test lab side and I'll tell you squarely test is a four letter word.
Yeah. It is T right. It's difficult to do if you're the tester, it's embarrassing anxiety creating if you're the testy right and if you're trying to interpret the results as the buyer you really need some help and understanding.
What is a good methodology. How should I evaluate this thing? What's a fair price?
What are the trade-offs it's hard and it when you're in a business of selling magazines or ads oftentimes you don't, you know, that's a cost center to do a test. And sometimes I heard stories where products were sent for eval and they came back and the Box wasn't even open, right? and they'll did and it's unfortunate because you know, especially in this in this environment today where everything's moving so fast and you have You know kubernetes and Cloud native and you have so many different things the the cognitive load and the learning path those those things are very difficult for folks to really feel their way in and understand.
What is the landscape let alone of the 10 options or 20 options I have for product product Class A B C or D. How do I rate them? Is it by number of stars on their GitHub is it?
Whose ad I see when I walk through the 600 vendors on the floor. It's it's a little confusing. So look.
None of the above. All of the above is the answer right? I you know, I used to be a guy who put a lot of weight behind how many stars have died on GitHub or you know, what do people on Amazon said about a product or anything and you know, we've heard so many stories about how this whole thing is gained now.
Yeah. so you don't know who to believe and then there's some piece of it you left out on the NSS thing. Yeah it prevent a lot of anxiety and and angst yeah among the testes the vendors who were sending your equipment, but if they didn't like what you said.
I mean there was some of them. they got downright ornery about it and Yeah, you know they did I used to run the security bloggers Awards. We didn't do it this year at our bloggers meet up, but I still bloggers Awards.
It's a Was a fun humorous satirical kind of yeah. Yeah, you know we had companies that threatened to sue us. Over here.
Yes, because they should have won they had the best corporate blog. I can only imagine if everybody a gold star. I'm trying right everybody.
You got it. Right. Well, you know, but you know things like that they're and I think doing it satirically is great because there's some subjectivity inherently in this right there is there's not an algorithmic approach to that.
I buy it. Yeah. Yeah and whatever it is what it is man, but that was an education for you.
I know I remember when you left NSS that's fine. Yeah like man that was It's crazy. You know, I feel like I feel like I did a public service right put your time, you know, and I meet I meet people still today so I have been out of NSS for gosh almost a decade.
All right, and unfortunately, it's not around and operate anymore. There were some difficult conversations with folks. But you're right, you know in an initially when we started testing folks came after us in fact.
some vendors came after me personally, I remember and you know Thankfully we were able to get the message out about what we really doing and we're very transparent. And the other things, you know, when I was there the goal was not to beat up the vendor the goal is to raise the level of understanding of the security products and the environment and to raise the level of of effectiveness of those products. And so part of that is in the test.
We're not just telling you how many stars you get. In fact, we didn't have a star system. We would tell you the percentage of specific classifications of threats that you were able to stop.
And what impact that had on your network performance? we also had a service where we would help the vendors privately, you know without publishing the deep dirty details of the results of understand to a greater extent how they could you know, change their algorithms their detections to do a better job and Almost every vendor took advantage of that and those vendors, you know did better in test later on but they also made a much better product. Absolutely.
So and it's in a sense, you know, we function as an extension of their QA. And that was a very common healthy relationship to have with with folks. I mean, I've got great friendships from those times where people really were thankful for relationship.
I'd have I'd have Dev managers come to me and say thank God or product managers. Thank you so much for showing this because now I got budget. To do that things that I've been asking for in prds for the last two years.
That's a beautiful thing too, man. Yes stuff. Yeah.
All right. Let's fast forward. What are you up to these days?
So these days right now working on a couple interesting projects. Let me tell you about the The big one there's an open source initiative called Kube armor, and it's the basis for a commercial product called Equinox, which is an open source driven cnap Cloud native application production Pro platform. For all those who are following the acronym soup, but the gist of it what's really interesting.
Let's set the stage right now, you know where devops world devsecops world. We've we've moved from on-prem to hybrid Cloud native. Now.
We've got a very diverse World a lot of different, you know, operating systems coming into play. They're you know, kubernetes has taken over as the orchestration platform. um, and it's evolving there's parts of that are still an alpha and beta, you know, it's got orchestration is going very well, but security has tended to be a bolt on right right and so, you know the concept of workloads spending them up we can do that very well.
But how do we secure them? And that's very difficult. And so the Because by default kubernetes is pretty open right get into it, you know an environment a lot of a lot of pods are running as root service account tokens are automatically mounted folks are still adopting admission control policies.
There's there's a lot of knowledge that the devsack and Ops teams need to bring to bear to secure this this thing. Um, so what Kube armor is it's an open source project. We donated it to the cncf.
It's a Sandbox project got over half a million downloads last week at kubecon Amsterdam. We had our community meeting. Standing room only over 40 participants and you know 95% of them were brand new to the to the project.
Which which told me that the message of what it's solving is resonated, right? So I should probably tell you what it does. Well that would help that would help.
So what it does is it think of it as putting a permissions rapper around an application that is containerized. Or running on bare metal any kind of application that you're running it looks at the behavior of the application. From a file access process execution and network interaction perspective at the syscall level so it plugs into the ebpf.
layer for observability generates an observed profile and allows you to then translate that into policies a universal policy language for permissions that then moves through gitops with the workload and can be implemented in the different environments through the Linux security modules. Now quick sidebar does not everybody knows what lsms are but they've been in the Linux kernels for about 30 years their DOD US Department of Defense approved ways of securing applications and at the kernel level, so they're vetted their Rock Solid and extremely performant see less than 1% performance impact so think of us as a universal translator where you can have an you know, a yaml file that defines what an app can do and not do Now this project has taken on a life. There's a a library which open source repo where folks of contributed policies for CIS hardening right miter attack framework PCI.
So there's a lot of these different issues that people are saying I'm concerned about locking down my workload Beauty. You've had an open especially cncf project. Yeah, you get that kind of producation.
Absolutely. So so let's look at a you know, where would that come into Bear? Right?
Because right now most people just trying to get their stuff up and running and the shift that I saw last week was now they're thinking okay. I can run it. How do I secure it and I have done the admission control thing, but that's just allowing a container in to run now that it's running.
How do I secure that and it you know a firewall is not quite enough, right? A WAFF is not quite enough, so Think of it as a rapper inside of the containers, you know, it's a the present inside the box. So right now folks are have a concern about their secrets.
So folks are putting their secrets rightfully so into like a hashicorp vault or a secret manager, which is great that encrypts the secrets these run in in the containers. But the secrets are stored. On a disk.
There's a mount point, right? and so if an adversary is able to to land inside that pod, which isn't that Tough they can now have access to that file which means they could encrypt it and ask for a little bit a Bitcoin to get your passwords back. That's not you just erase it because they could erase you or just take it.
Hey exactly and then put it into their you can public make it public right or you know, put it through a cracking program, right? Yeah, but that's the food chain on the on the on the now on the bedside right? Once they get that day today.
They have buyers for it. Exactly and those it's a very vibrant ecosystem. Okay.
So so what do you do with that? Right and that's where the Kube armor comes in and it's very cool because you you can say this process is the only one allowed to touch this data file slash bins slash volt is the only process that can have read write access to slash data or slash Vault or slash my sequel data or you know, pick your pick your whatever it is. It's day to date is data at some point, right exactly.
Let's talk about the commercial version. It is sure. What's it do?
So the current then the open, you know the yeah. Yeah. So the commercial version kind of takes the the open source version and add some usability features, right?
It makes the discovery of the policies more robust, right? You can run this in in your staging for example run through your your tests exercise the code and get a to build that actual profile. You can also do that in production.
But you know, it's up to the user the other thing it does is it You know, we say a pictures worth 1,000 words. And so one of the things we've added is application Behavior observability, but it shows you graphically what is the app doing, right? So, you know the tie in here is to the supply chain side.
Developers are trying to get their products to Market as quickly as possible. So they're using libraries that come from, you know, package managers like npm, you know python, you know, there's a lot of Open source stuff being used to build an application and oftentimes when we simply upgrade the the version because always good to have the latest right? Well, what if that changes the behavior?
What if there was malicious code in there or some kind of a bug and on the malicious side we've seen that where you know data has been, you know deleted or The data has been exfiltrated to you know, some foreign country right not naming any names. But so that's a real risk. And so what we can show is graphically what does that application doing?
What's it doing on the disk? Is it spawning other processes? com.
And they can then make a decision if they if something has changed. Should they allow it? Or they should they ring fence it and prevent it.
So so that's part of it. Or does a better job, you know kind of easing the orchestration of policies across different Cloud environments. It's multi-cloud.
So the Equinox synap is also open source driven, which means that we're not trying to be the the best vulnerability scanner or you know, misconfiguration detector or identity. It's open you can bring in Exactly that you want. I got a hard question for you, man.
Okay, you spell this for the people out here so they can go look it up. A c c u k n o x. There you go.
There you go said so the reality is that everybody's got some set of tools absolutely and so our view and this is why I say it's open source driven is you bring what you have. We'll let you integrate it in so you get a holistic picture of your Cloud net native environment. It's an open platform and look.
I mean, this is the way the world works today, right? This is what this is what developers wanted security people want. It's what the platform Engineers the srees the office folks they want this.
So yeah, I agreement agree. Yeah, what else we got? Well, the the other thing that it's that it's doing is it's kind of like a sore platform.
In that it's not all about Cloud native. People still have a few. You know probably like 50 to 80 percent of their workloads on Prem in different places.
And so how do you it's not just solving this problem is not just about calling an AWS API, right? You need to get behind the firewall to see what's actually it's actually happening. Right.
So yeah, actually Rick a pleasure to see you man. Where you headed next. I'm headed home you both, you know, we get reacquainted with my garden my jacuzzi my family.
I I I'm right with you. Yeah, that sounds good. We're gonna take a break.
We're wrapping up RSA here today. We'll be back in just a minute.





