Open Source Security Development with Stamus Networks’ Éric Leblond
Éric Leblond, chief technology officer and co-founder of Stamus Networks and long-time open-source leader and contributor, discusses the advantages and challenges associated with open source security development and provides insight into industry trends and where things are headed.
Transcript
This is Textron tv. Hi everyone. Welcome back here to Textron tv.
You know, we're having, uh, some great folks on today. I have another new, uh, first time guest for us. His name is Eric Eric Labon.
Eric is the CTO Chief Technology Officer and a co-founder over at a company called Staus Networks. That's S-T-A-M-U-S, and we're gonna hear about that in a second. Let's welcome Eric, go to Textron tv.
Hey, Eric, welcome. Thanks for being here with us. Hey, if you want, ano nice to be up to date.
So, You know Harry Pro to have you here with your Fred Jackson while the Olympics are ongoing. Paris has done a great job. Uh, I was just in Paris in April, so it was fun to see all the back shots, but one of the spectacular games it's been so far.
Um, and of course I think we're all hearing a lot of French accents and French speaking folks, uh, on the Olympics, but Eric, you're not an Olympic athlete, at least I don't think you are. Anyway, I knew I'll be No, No, that wasn't me either. But why don't we, you know, so you're not an Olympic athlete, but you are a CTO and Co-founder, but give us a little bit more about Eric, if you don't mind, for our audience.
Yeah, so I, I started working on, uh, network security on open source, uh, around the year 2001. I first did contribute to the network project, which is the Linux, uh, firewall stack. Yep.
I end up, uh, as a core team member. So we were some first thing like eight people, uh, that were running the project at the time. And, uh, I did create a first company, uh, that was, uh, providing the authenticating firewall.
Basically, you were able to do, uh, policy based on user on not on IP addresses. And, uh, so it was from 2004 to 2010. And then after that I switched to another project, which is Serial, which is an open source, uh, network detection analysis tool.
And I did start to contribute a VD from 2000 up to 2014, where in 2014 I decreased stemless networks to build open Tata some product that will be, uh, useful for the enterprise. So what we have built, uh, at Stemless Networks is a network adaptation and response solution, uh, that is mostly targeting the big organization. Most of our customer are big organization, but the work that we are doing is about fixing the problem we have about tools that analyze the network traffic where a lot of events are produced, and it's not easy to really know where you are going to start.
So we propose a solution that allow you to have what I like to say, a pyramidal approach, uh, pi middle, sorry, approach where you can start with some critical events and then discover everything you need on your network based on the passive analysis that we are doing on with the product. Okay. You know, it's funny, I, I actually started my first security company.
I started a web hosting infrastructure company before in 2001 as well, and that to me was kind of a golden age for open source security, right? You had so many great pro projects and map and, uh, Nessus and Snort and Slam AV and, and the list goes on and on and on, and you mentioned some. Um, and then we also, we did in a network intrusion prevention network, access control, vulnerability scanning and management, all through that 2001 through 2010.
And a lot of what we did was based upon a lot of the great open source tools that were out there, great open source projects that were out there. So I, um, you know, uh, which is something you've been involved in. So we have very, you know, I'm surprised we haven't met before.
We said like we ran in parallel places. That's interesting. I'm a little unsure.
When did you start STEMIs Networks though? Well, it start, uh, 10 years ago in 2014. So another overnight success.
Yes, exactly. So we did that more like, uh, self-fund on runway way, something like two years ago. We did start the founding process, uh, once we had the project.
So that's nice because we are, we have a startup, but a product with history, so stability and stuff like that. So that's, uh, that's interesting. Absolutely.
Um, and now was it network detection and response? Is that what you guys are basically doing here? Uh, yes.
Yes. So we're doing network detection and response. So we install a prob in the customer environment.
It can be in the, in the cloud on site, depends, or then we have a manager that is going to orchestrate the detection so we can find the threats, uh, on the network, in the customer network. Um, then, uh, we work with, uh, security operating center, uh, that is doing an analysis of the data we provide to potentially trigger incident response, uh, when yes needed so we can, uh, act before the bad guys really managed to take over. That's basically what we're providing.
So, you know, for my snort based intrusion prevention detection stuff, right, it was a little easier then because there was no cloud, right? So you had that moten castle, you could put it right in front of the firewall or build it into the firewall as it happened. Um, of course the world's different now.
So when you say network detection, are you looking for sort of active malware or is it more, um, kind of probing kind of stuff? Threat intel? So it's a bit of all of that, in fact, because if you try to find one silver bullet in it, in us in the security area, it is not going to work.
So we have a, a broad, uh, detect detection mechanism. So we're using different techniques to be able to provide the best coverage we can when we see that only even data from the network. So we're complementary with solution like e you, what we really think is a good solution is to have ER on end d because if you have endpoint protection, you are going to only you are going to miss, uh, uh, information from the network and you cannot deploy endpoint protection on any device.
If we're thinking about what did happen to CrowdStrike, sometime deploying EDR can be a bit challenging. Enough said about CrowdStrike, I'm not gonna, I'm not piling on, um, you know, during my time in, and you know, beyond the security, I was involved in tech, I've been 30 years in tech. Um, I've seen the open source kinda landscape change a lot, right?
When I first got involved, open source wasn't, um, wasn't as welcome in the enterprise, right? A lot of people didn't want to use it. Then of course, open source became dominant, right?
Where today I think 99% of organizations use open source software, uh, 70 to 80% of all code and applications are based, you know, have open source components in them. Um, but recently we've seen kind of a, a blowback on open source, right? Go around open source security, specifically supply chain security.
Um, is the software and the components that of using free of vulnerabilities as if anything is ever free of vulnerabilities. You've been a contributor to open source projects a long time and you happen to be a security person. How do you reconcile that?
How do you uh, you know, I think you have to acknowledge that there's an issue or how do we solve it? Yeah. So there, there is an issue definitely with supply chain attack and you need to be cautious.
Uh, but first I, I, I would like to start with advantage of using, uh, open source technology. I was looking at just one example. So I look for vulnerabilities and I found one that is really interesting and that is going to explain my point.
Uh, it's a vulnerability on s Siemens devices from 2019. 2, then a debug part on the debug service is open on the device. So you can take the control of the device.
I just wonder, the first example I found, I did not look further. Mm-Hmm. 'cause it just explained you that when you are doing clusters, a lot of producer of cluster source technology are going to hide things under the carpet because they said nobody can look at it.
So if nobody can look at it, I can do whatever I want, even if it's the dirtiest things ever. So that's for me, one of the key points. When you are doing open source, you are writing public things on you.
A lot of cases you want to be proud of what you write, and you cannot really add things because it's public, so people will see it after, to get back to your initial point. Uh, your code, uh, is open. Also, in a lot of cases, the dependency are open so you can, you are vulnerable to early it just enough to, uh, attack one of the dependency to be able to get your project, uh, by rebound.
I think we have seen recently that with, uh, um, a compression library that was hijacked, let's say, to be able to, uh, uh, to, uh, add a backdoor in the SSH uh, server. So it happens, uh, we are seeing it, so that means that you, we need to fix this. And I see some initiative and open source where, for instance, uh, it's the state that you need to have fixed version in the dependency you are using, because if you always fetch latest version in the dependency at any build, then by consequences of a new version could be compromised.
So you can, uh, that's, that's one problem. So I think there is, uh, this type of system that allow the open source to be safer. And there is also all very far done by the platform like GitHub or GitLab to provide testing of the version, uh, automated and it's testing.
Sometimes just check the dependency, but in a lot of cases it's also static and analysis of the code, uh, for time to time dynamic analysis too. So that really help, uh, the quality of the code and also the check on the dependency of softwares. Absolutely.
Um, Eric, let me ask you a question. And again, you, you wear two hats both in open source and security. Do you see all of this?
How, how is it going to change, right? We've seen, as I said, over the arc of time, open source adoption and open source become dominant, but nothing ever stays the same, right? Things change over time.
How do you see open source use and development, uh, potentially changing, right? I mean, I, I think we've been in a golden era of open source for the last 10 years, right? You look at organizations like the Linux Foundation and stuff.
I mean, great stuff. Uh, so to answer, to answer your question, uh, what I see, what I have seen recently is a, a big shift in the obry industry where we have, uh, enterprise open source, uh, which means that you have one company developing an open source product and then trying to make money on top of it that has reached its limits. You can look at elastic search related closed source system.
You can look at Red Method done the same. And a lot of tools, a lot of open source software that are proposed by enterprise don't find their business model. Um, as a consequence, uh, we close source of, we try to limit, uh, the usage.
So you just mentioned Linux Foundation. I think it's, for me, it's a good example of what could become, uh, open source, uh, open source bond by foundation because it, uh, provide common, uh, uh, that's, uh, common benefit for the, for the, for the society. And at the same time, uh, you are a bit safer and with an enterprise and you are also already safer from the individual contribution that in the tough case at the point of 1% or whatever, if it is start to do something else, uh, you are into trouble.
So what I hope, and I I think it'll happen, at least part partially that I am sure is removed to foundation, uh, to ster console software A Absolutely. Eric, we're we're almost outta time, but you know what, we didn't even mention the website for stanis Network. How can people find out more information there?
com. Exactly. Eric, thank you for coming on today and, and talking open source and security with us.
Continued success with Stanis, right? We'd like to hear more, um, and we hope wish you nothing but success. Thank you.
Thanks a lot. And thanks. Have a good day, Ramon.
Goodbye. Okay, Eric LeBla, chief Technology Officer, co-founder, as well as open source ski reader extraordinaire from Staus Networks here on Text Trunk tv. We'll take a break.
We'll be right back.