Scaling Security in the AI Era with StackHawk’s Scott Gerlach
Scott Gerlach, co-founder and CSO at Stack Hawk, addresses application security challenges and innovations. He emphasizes integrating security into the development lifecycle, especially with AI’s rise. StackHawk focuses on improving application security testing, particularly through business logic testing for API vulnerabilities. Gerlach discusses the evolution of security practices, the scalability of testing, and the importance of proactive measures in security.
Transcript
Hey everyone. Welcome back here to another Textron TV interview. You know, I'm happy to have my friend Scott ick on.
We were, we were talking before we started rolling on the cameras. I think the last time I saw Scott was in person in Boulder and, uh, it was years ago. Years ago at the Foundry office and, you know, him and Joanie and the rest of the, uh, stock clock team.
They were really, I, I think at that time, Scott, I would say he was still molding market fit. You know what I mean? You yeah.
You, you, you kind of had the idea of what you guys had wanted to do and, and it was about market fit. Of course, stack Hawk has come a long way since then. But before we get into that, Scott, give people a sense of, of who Scott Gurley is.
Yeah. Awesome. Thanks.
First of all, thanks Alan for having us on. Having me on. I always enjoy talking to you and the tech strong audience.
Um, yeah. I'm Scott Gerlach. Uh, I'm the co-founder and chief security officer here at Stack Hawk.
Uh, my background is actually running security teams, so I ran security teams at GoDaddy for like 10 years, was the CISO at Srid, uh, for three years. Uh, so in charge of, you know, running different security teams, application security happened to be one of those almost every time. Um, and when Joni was out doing some research on the space, she and I got connected and had a really good chat about things that are really screwed up in application security.
Um, and we, we set out to kind of try to help fix one of the biggest problems, which is just developers are the last to know about security problems in code that they Right. And we were trying to flip that on its head a little bit. So that's, that's sort of how Stack Hawk started and, and what my background is.
And this is my first foray into, uh, founder of Startup Life, which is a little bit different than Security Guy Life, but not totally different. Well, so I, I'd done that too, you know, um, I I would, I would say this about it. Scott, you didn't take off one hat to put on another hat, you just put one hat on top of the other hat.
No, that's right. Right. That's absolutely right.
And, And, and, and everything that goes with it. So basically you're working twice as hard, but you know, you, you, you don't start a company as a founder, co-founder unless you have a real lot of passion for what you're doing. Yeah.
And so hopefully, you know, that compensates for wearing the two hats and, and God knows when you first start a company, you wear more than two hats even. I wish it was only two. That's, that was what I was thinking when you Said that.
But you know what I, I've heard people say that's their philosophy to startups is as the company grows, you take less, you take hats off, and that's how you know your company is doing well. You're wearing less hats as, as the founder or co-founder. Yeah.
Um, and, and there's some, I think there's truth to that. Um, Scott, you know what? Well, and how, just to give people a sense, how long ago was this?
Yeah, 2019 is when we started. So Stack Hawk has, has been around for some really weird stuff in the history of the world. COVID and bank failures and market turns, and now AI stuff this happening.
It's, there's some, there's some weird things. I don't know if it's Irish or Chinese people tell me all different, you know, origins. But the, the proverb is, may you live in interesting times.
Well, I think we've done that pretty well so far. You, you Have, you've only existed in interesting times. Um, so, you know, the mission was doing AppSec better.
I you, you know, it's interesting, Scott, I interviewed, uh, last week, my friend Jody Zel, who's the CEO founder of Harness. Yeah. Right.
And, and harness. I mean, they just announced a huge round and a huge valuation. Uh, huge valuation.
Um, but, but he, he, he said, you know, one of the things he credits to his success was his vision has stayed center the whole time, which is there's a better way to do cd. There was a better way to do cd. And that's what they set out at Harness.
And over the course of that, you know, they've added security does SEC Ops. Mm-hmm. Even AppSec into it, they've added now AI into it.
They've added, you know, as a service into it, but the core is still do CD better. Yep. And I think it's similar, similar to in Stack Hawk it's, it's do AppSec better.
Yeah. Stuff has happened, stuff's been added, but it's still, that's, that's the mission. Yeah.
I think, you know, when we started Stack Hawk, the whole, the whole idea was we were able to ship code because of things like Harness and CICD systems that gave us the power to get code into production at a pretty fast rate. Um, and the idea was every time, like at the time, security testing or application security testing was really focused on, I know about this one or two things in production, and it gets changed every now and then. And so we'll test it in production, make sure there's no problems in it.
And at the time when we were starting to ship software pretty fast where people are making changes and deploying once or twice or three or, you know, seven times a week, that kind of methodology is just sort of broken and it, it doesn't help you stay on top of what's going on with, uh, applications and APIs that are getting published. And it doesn't enable the business, right? It doesn't help you go faster.
So the whole idea was how can we, how can we pull that into be part of the development life cycle so that as we're publishing stuff, we have high confidence that there's not security vulnerabilities in it. That problem got exponentially worse when we started introducing LLMs and, uh, coding agents that can help you not only ship code, but write code at an insanely fast rate. So I know a ton of engineering teams that are, you know, eight x 10 x more efficient at writing code and delivering value to production.
And our application security programs largely haven't evolved anywhere near that speed. Um, and so our problem has just gotten worse along the lines of, can I keep up with what's going on? So that's, that's where Stock Stack Hawk started out.
And what we were trying to help, uh, application security teams do is just, you know, understand what's out there. First of all, what's my, what's my inventory? Second of all, how safe is it?
Are we testing at a, at a reasonable cadence and are we putting safe software out in the world and enabling the business to go faster? I always, when I talk to some of our customers, I always say, my goal is so that when someone comes to you, whether it's the CISO or the CEO to say, how's our security posture, I want you to be able to say it's great, go faster. Instead of what kind of happens today, which is like, uh, I'm kind of keeping up by the hair of my teeth.
Uh, we're Okay on by my fingernails. Yeah, Exactly. Um, so that's, that's where we're, that's what we started out to do and we're, that's what we're still doing and we're, we're helping a lot of customers do that today.
Very cool. Um, look, we only have 15 minutes. I'd love to dive in more and go, you know, through a lot of recent stuff with you, but we, we could, well, we'll see each other and hopefully in person in RSA and we'll go dive deeper.
But I love that. I want to get to, um, news you guys recently kind of in Yeah. And we wanna leave time for us to discuss that.
Why don't, if you don't mind, share it with our audience. Yeah. It was super exciting stuff that's coming, uh, from, from our engineering team, specifically business logic testing.
And the thing that's really exciting about it is not that the problem is new, it's that the solution is new. Uh, and so, you know, business logic testing has been around forever where people are like, okay, if I add an item to the cart, how many times can I apply a coupon and then make you send me the item and money? That's been business logic testing forever.
The problem has gotten worse because of this code, um, code explosion and API explosion where 37% I think of recent breaches have been due to authorization issues or kind of this business logic problem that exists in APIs. Um, that's a, a wasp stat recently. And the ability to, you know, do business logic testing inherently was upon the AppSec team or the security team.
Like they have to understand how things are supposed to work and then be able to write tests to do that work, really expensive process. The really cool thing, as scary as AI is for an AppSec person, it's also this huge opportunity to be able to do a bunch of, was impossible stuff. And this is kind of one of them, which is use AI to do its probabilistic, uh, action and kind of understand how an API was intended to be written by looking at it, looking at the API kind of decomposing it and being able to go, I understand how they intended this API to be used like with some certain, with some certainty.
And then use that information to then test the API for some of that business logic problem. And that business logic problem could be authorization issues, whether it's cross user, cross tenant, like this company shouldn't be a company A should not be able to see company B's data, user A, user B, those kinds of things. But then also stuff like, can I change Alan's, uh, password via the via the API itself?
And so those, those are some of the authorization issues that exist. But the cool thing is, um, a couple of things. One, uh, the Stack Hawk dynamic testing engine, the Hawk scan, um, are dast, for lack of a better term now, has this intelligence built into it around APIs.
It can look at an API and go, I understand how this is supposed to be used. Then exercise it that way and gather, capture all the data that the a p is returning while you're making calls. So if I have to register a user and it returns a user ID and I need that in the rest of the API, we can now do that very, very simply without other user interaction.
That's the first part that's really cool. It's called the Smart, smart Crawler, uh, smart Crawl pen. The second part of that is then using that information to look at the API and go, okay, this looks a little fishy.
I should go test this with a user or multiple users to make sure that we don't have those authorization issues. Um, and so that's, that's the stuff that we've released today. But the really, really cool thing, those are very cool as well.
I'm super excited about that because it's the foundation of being able to do, take the AI and look at the API and come up with test scenarios that we wouldn't normally have done ever. Uh, and then be able to build more deeper business logic testing across an API or across many APIs in the organization. Uh, today we started with that smart crawl plan and some of those authorization, uh, detections, but there's a ton more that we're continuing to work on and deliver, um, for, for the customers out there.
So business logic testing is what we're doing. Absolutely. Now.
So I'm really proud of ourselves, Scott, here we are. It's the, we're we're more than 10 minutes in. We really didn't talk a lot about ai.
Right. Which is unusual. Unusual.
But you, you did mention how much more code is being generated. Yeah. And a lot of that code, you know, face it is AI generated code.
You know, we had a discussion on text drug gang this morning. Have we reached the point where AI generated code probably has as many vulnerabilities, so human generated code versus a, a human written code, AI written code. What, what's more insecure?
What's more, you know, that's more, and yeah, I saw a a actually a survey from Ferra Veracode that actually it's approaching parity. Mm-hmm. It 'cause it keeps getting better, but nevertheless, there's also a lot more code if we need to, you know, you know what the bane of all testing is.
There's never enough, enough time, never enough to finish my test, uh, you know, scheduled. How scalable is this business process testing? Yeah.
Uh, I think it's pretty scalable. The, the testing is not as fast as a normal testing, but it's less destructive. So when I say that, I mean our normal kind of what we do is, um, specifically kind of behavior testing, right?
We're checking how that written code is behaving while it's running, whether that's in production or in test environments or whatever that is. And I would actually say that, um, the how a, how an API behaves is probably more important than, is it spelled correctly for lack of a better term? Because I agree that parody is happening with AI written code and human written code.
Um, and there's just some things you can't find without testing the behavior. Yeah. So the, the thing that's super interesting about, um, what's happening with this business logic testing is it can be very focused where you want it to be focused.
And we're trying to help teams understand where the most important things to test are, whether that's, um, what APIs are handling PII data or PCI data or PHI data, um, as well as how frequently are they changing. So the rate of change that's happening in the code base is equal to how risky a thing is. So helping people understand where should I be testing to get the most bang for my buck?
Because to your point, I can't test everything and get all of the alerts because that's not gonna get me anywhere. I have to be pretty focused and intelligent about where I'm testing and what I should be fixing. Um, so scalability wise, I think it's, I think it's pretty, pretty good because we always advocate people test on smaller microservices as part of CICD systems, those kinds of things.
So wiring it into the, the release process for most of the code really enables that kind of testing to be super scalable and it's very focused and it's very much real when it pops a thing, when it pops an issue and says, Hey, there's a problem. Agreed. Agreed, agreed, agreed.
Um, Scott, it, it, so is this like part of the, the whole Stack Hawk system, is this a separate module that people are just interested in this can buy? What, what's, you know, how is it, how's it going to market if you will? Yeah, so it's part of the Stack Hawk system.
Um, it's part of, uh, there's a couple of, there's basically three things that are part of the Stack Hawk system. One is discovery and it's part of discovery. So we can, as a dynamic testing, uh, company, we can actually look at code and help you understand what APIs you're building, how often they're changing, which ones you should be testing, where, what code is building those APIs.
Then obviously the testing part is really important, making sure that we're surfacing the right things, helping developers understand those problems so that they can fix them as part of the development cycle. And then the oversight of what's going on across those different pillars, uh, of the program. So it's actually part of, uh, discovery and also testing because we can not only look at that code and go, Hey, there's an API here, but in open API land, we can build an API spec out of that code and then we use that API spec to do the testing.
So those two things are, are part of this program. Um, you can do the testing without the discovery part, but most people that I talk to don't have open API specs. So that's why we built that for them, uh, to enable, you know, not only the visibility, but enable stuff like this kind of testing.
Absolutely. You know, it's interesting, there was a time a couple years ago where API security was its own category. Yeah.
Companies just API security companies. And you know, like it's lesson I learned in my still secure years was, especially in security, a lot of programs or a lot of products become features. Mm-hmm.
And, and the whole API security thing has become features. Right. Yeah.
Is a great example of it as well. Scott, we, we are about outta time for people who want to get more information from Starhawk and specifically about this business logic testing. What, what's your advice kind of, where should they go?
What should they do? Yeah, if you want to come check out what Stack Hawk is doing, you can always visit our website and get ahold of us there. com.
Um, and then I know we've got a bunch of stuff going out on our LinkedIn channels. Oh, our LinkedIn page is obviously Stack Hawk, maybe not obviously, but hopefully, obviously Stack Hawk. We keep PO posting a bunch of stuff about business Logic testing, some of the new stuff that's coming out of the company as well.
So you can always give us a follow on LinkedIn. Um, those are two of the many channels that we're putting information out. Uh, and you can, you can follow along with us.
Alright. Hey, say hello to Joni and Casey and the rest of the gang out, out there in Boulder. I do hope to see you in person a few months at RSA.
Same Good man. Have a great holiday and happy new Year. Thanks Ellen.
Did you do the same? Have a great weekend. Alrightyy Scott Gerlach, uh, co-founder at Stack Hawk.
Go check them out. Business logic testing. It's another thing we're solving.
Delicious BLT sandwich. Yeah, That's one way. Um, it's about lunchtime.
Anyway, we're enjoy, stay tuned for more text on tv.