Bridging The Security Gap With Cloud Native Vulnerability Management | RSAC Virtual 2024
As organizations move to the cloud, security teams are being tasked with cloud security. This often means replicating on-prem security practices in complex multi-cloud environments. This approach can leave critical blind spots and create organizational inefficiencies. In this session, you will hear how you can use a CNAPP solution to empower your teams to become cloud security experts and work across departments for better security outcomes.
You’ll learn how you can make the best use of your security team’s time by understanding resource relationships and their blast radius. For example, how an unpatched OS paired with an over privileged EC2 instance can contribute to overall risk and the easy fixes that can make the biggest differences in your environment.
What you will take away from this session:
–How to inventory assets, identify vulnerabilities, and prioritize remediation in AWS, Azure, and GCP
–Best practices for managing risk such as malware and container image vulnerabilities
–Approaches for assessing identity risks and entitlements in cloud environments
–Tips for unifying vulnerability management across on-prem and cloud environments
Transcript
Hi, uh, my name's Nick Burke. Um, I work for Tenable as a cloud security specialist engineer. Today I'm gonna be talking to you about cloud security, um, and jumping into the, the platform and, and showing you, uh, how Tenable solves problems.
A couple of quick slides to go over, uh, just to talk to you about and set the scene around our, our platform. So Tenable has always been around, um, and about to, to help our customers, help our partners and their customers, uh, solve and prevent breach. The key word there being prevent breach, where we're trying to move to a proactive, uh, process and technology stack that stops an organization from being hacked.
And ultimately, that's the key. Rather than wait for them and try to recover, it very much becomes a process to help us understand what your attack surface is, help you get insight, um, and make the right decisions around prioritization. They're gonna really drive a, a, a de-risking and an understanding of the attack surface In the, in the modern day.
Um, you know, particularly looking at, at cloud, uh, we've seen attacks multiply the advent of, uh, LLMs. GPT has really meant that attackers have the ability to understand the external, uh, the external attack surface, as well as the ability to not only attack computers, but also attack people, attack them, fish them, steal their credentials. And then we're seeing the traditional process, the one that we've always been dealing with for a long time.
The lateral movement, um, evolve. You know, it's a lot easier these days to, to go out and, and, and find credentials on the, on the dark web, and we don't even need to, to exploit a vulnerability in the system anymore. Attackers are using those processes and those identities to get visibility into your environment.
We've got a number of high profile breaches that have occurred with just this, uh, capability. You know, organizations which have had third party compromise, you know, have we have seen that lateral movement take minutes and then elevate and take action being the, the, the key that we've seen, you know, I can talk to any number of breaches, but one that comes to mind is a, a software vendor and they'll, they're able to have their ICI said a tooling, uh, pipeline taken over. And that actually meant that the, the attackers were able to launch a crypto mining, um, piece of software and crypto mining farm in their environment.
And in terms of the cloud, understanding that capability, understanding how quickly an an, an organ, an attacker could move laterally through the environment is absolutely key in preventing further exfiltration of information, extortion of potentially things like malware. And obviously then the, the potential impact of, of, of every operation being disruptive. One of the challenges that Tenable sees is very much around prioritization.
Now, I've chosen some traditional kind of, uh, references, but I'll talk through this in, in, into the, the platform and show when I show it to you. If we take a, a window server, a web application, or a machine identity, and they've all got a risk associated with them, we're up until today, we've had a real challenge to help organizations make the decision of what's the most important. Now, you know, if we go the technical detail of a web application or a machine identity, we may have a high score or a pass or a fail with our vulnerabilities, we may have A-A-C-V-S-S score.
There is no consistency across the board. And so Tenable is addressing this through, uh, capabilities to, to make a, a, a better decision. It's harder to understand not only the technical risk, but also the business risks associated with that resource.
So technical has been, uh, so Tenable has launched into this space, um, for a number of years, and we really have been driving to help organizations make the right priority decision. The reason we talk about this in the cloud is it's always about the context of which it sits in the technical risk and the re the business risk resources are ultimately related to each other. What we can do with our Tenable One platform is start to normalize it, uh, associated with the, the asset criticality and the vulnerability priority rating.
They're ultimately giving us an asset exposure score, which is a normalized scoring platform within the cloud environment. It's, it's almost more challenging because of the relationships between those resources. So I'm gonna jump across to my demonstration now, and I'm going to, um, present the, the cloud security platform.
It's gonna be a very quick demo demo. Today I really want to go over just one or two quick use cases, talk to, um, really about what's important and why we see the, the priorities. I wanna put it together through some building blocks though, just to help understand the power of the platform.
If I look into my, my cloud environment, I'm gonna go to a traditional compute resource, such as an EC2 resource. Now, I would like to keep in mind that this is very much a, a fundamental process that we have across all of our types of workloads, not just our traditional vulnerabilities, our traditional, uh, servers. I've got a, a greatly named awesome request, a web server here.
Um, and we're actually actually, uh, interrogating this system not through deployment of agents. Uh, we're actually leveraging it, um, not through a scanner. We're actually talking to the API.
And the reason this is important is it's non workload impacting. So we're able to produce and our security outcome without affecting the business continuity and performance of this platform. So super important in the cloud that we're not generating additional, um, you know, compute cycles as we say.
You can see here that we've produced a, a lot of rich metadata, um, a lot of information that we can process. We're also looking through and establishing, um, an understanding of what this resource is related to. In this case, you can actually understand its, its network and how it's talking to the rest of the platform.
The, the cloud platform that is now, if I drill into the network stack, um, you can start to understand and, and help the human visualize an understanding of the, the firewall, in this case, the security group, access to that resource. It very much drives in and provides a visual clues and I understanding of what's going on. You can see here, um, I've got a expose ports to the internet on port 80, and I've got Port S 22 SSH, um, to some management IP addresses.
That's not an overly large security concern, it's a web survey. You're probably expected to do some capabilities. Now, the reason, context and understanding of the platform is important is we need to understand what the actual workload does.
So very much from a software perspective, we're then gonna understand the software inventory on that platform, understanding the, the resources, understanding what the software is, how it's used, allow us to then do an, a vulnerability assessment to understand the CVEs of, of that system. You can see here I've got some fairly nasty ones over some, some software. Um, but ultimately we're not, we're not too worried about it at this point.
Ross able through the platform, and luckily, thankfully, this server doesn't have any known malware on it. So we can move on. We're gonna drill into and understand the known risks into the environment.
So building a little bit of a story arch here, understanding this, this system, like every system has a story, has a, has a risk, has an understanding of, of what is it important, is it vulnerable, and what can it do? And so when we look into the what can it do, we're producing again, a visual representation of its, uh, its entitlements. So this web server has access to a number of other cloud resources, other things that it's related to.
Now from a security perspective, understanding the lateral movement or the impact radius of a single resource is vital to doing that preventative security and vital to prevent breach understanding and trying to triage as well. We've now accelerated the triage processes because we understand what this resource has access to. We know what its impact radius is.
You can see here very quickly that this resource has access through Amazon to S3 buckets, and it has the ability to write, uh, full access. So delete, write control over those S3 buckets. That's a risk, that's a common attack scenario, uh, in today's environment.
And so very much an understanding here of what the potential risk and impact could be. One of the interesting things, you know, everyone will be aware that there are some, some red arrows there unless you're colorblind and I door apologize. Um, this is all about the permission this resource has and if it's ever been used.
So this is an excessive permission, which from a security perspective and a breach perspective means it's never been used, right? So I'm confident that we haven't seen that from movement from this host, even though it's got software vulnerabilities and exposed to the internet. However, we wanna apply a capability like lease privilege.
We want to understand why that's important and we wanna minimize it. If this hasn't used these resources, why does that have access? So it's not just Nick that has to work through those capabilities.
The platform is actually doing it itself. So we will generate a finding, and that finding always has the context of which I've just described. So very much a a key capability here and some context around this, this finding and risk to the organization.
You can see here I've got critical vulnerabilities. I have, um, 270 vulnerabilities, but I've already run one, raised one finding. We rate this as a critical severity finding.
Yes, that's a bit confusing with this, the vulnerabilities, but the finding always has context. And the reason for that context is very much the reason of that context is very much around what this resource can do. The EC2 instance is accessible from a high range of IP addresses as in the internet, and at least one relevant vulnerability is remotely exploitable.
It can be popped externally or by a third party over the network. Not a great combination there. And ultimately, we're raising the, the, the level of severity additionally because of the permissions it can have access to.
So it's the combination of resources, the combination of relationships that's driving the context. So we're accelerating the prioritization of organizations, leveraging intelligence, leveraging understanding of the environment. We're not just, hey, it's, it's one thing you need to go fix.
And we are minimizing and reducing that. Now tenable, we refer to those as toxic combinations. So that's the toxic combination of resources, but, uh, of relationships between resources, a public workload with high, uh, high severity permissions and critical vulnerabilities.
So very much what I just displayed there and and helped understand is, is how the platform is building its findings up, how it's showing and surfacing relevant high risk, uh, capabilities to our customers and to your cloud environments. Now we're going across multiple cloud providers and providing that same level of visibility and insight. The ability for Tenable to do a hybrid capability on premises Kubernetes, starting to drill into those environments.
When I talk to my customers and to my partners, I'm very, very proud to be able to help them with something that I refer to as the next section. A little bit of a self-deprecating joke, but the, if you have five minute section very much tells us what we need to go fix. If we get five minutes spare.
I'm not sure how many security professionals that I talk to, how many devs that have five minutes in their day, but this is really calling out the worst of the worst. These are things that have slipped through the pipelines, slipped through the build processes, and we're hitting live resources, hitting live capabilities that we need to go fix quickly. So the platform itself is providing all of this insight through the front page, through the dashboard.
Now, in the limited time I have today, I don't want to burden everyone with too much information, so I'd like to finish it up there. Um, would like to say thank you for your time. Appreciate it and uh, I hope you have a good day.