State of API Security – Richard Bird, Traceable AI
Traceable AI recently published the results of its “State of API Security: A Global Study on the Reality of API Risk” survey, which polled over 1,600 cybersecurity professionals across the U.S., U.K., and EMEA. Richard discusses the key survey findings.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
I'm happy to be joined today by Richard Byrd. Richard is the, uh, chief Security Officer, c s o over at Traceable ai, a company we've been, I think we've been following traceable since they launched. Hey, Richard, welcome back.
How are you man? I'm doing well. Thanks for having me back on.
It's a pleasure to have you here, Richard. You know what? Give, let's give start off with, with a little bit about you, give people a little bit about your, of your background, if you don't mind.
Sure. Um, I, I've been with Traceable for exactly a year. Um, but as I like to tell people, I'm, uh, Benjamin Button living life in reverse.
I spent, uh, 20 plus years in the corporate side, uh mm-hmm. About 17 of those in banking, uh, financial services, payments, um, 11 of those, which JP Morgan Chase. So I have had, uh, a number of stops that led both to a c I O role and then, uh, on the security side, a CISO role.
And, uh, and then I made a decision about five years ago to get, uh, out of the corporate side and try and help, uh, be a voice, uh, universal translator, uh, and the solution side and help out there. And, uh, thankfully, uh, Joe t Bonsal and Sanjay Nagar, their founders at Traceable, called me up one day and said, uh, we'd like you to join the team. And, uh, and I ended up in, uh, a p I security, which has been a blast so far.
Absolutely. And, and it, and it's funny 'cause you know, the whole arc if will of a p i security just isn't that old. And, and, No, no, not at all.
I, I think for, and for the first two, three years, I think the, the, uh, we were dealing with sort of the, the primary question of do you even know what APIs you have? 'cause you can't secure what you don't know you have. But, uh, I'm hoping, and, and we're gonna talk about a new study that you guys did.
I'm hoping we're moving beyond the, what APIs do you have to, how am I securing my APIs? But before we do, you know, we mentioned traceable a few times for those who maybe aren't familiar, 'cause I imagine some folks in the audience are not. Why don't you give 'em a little traceable background?
Sure. It's, it's impossible to talk about traceable without talking about our roots. Um, I like to always say that, uh, we're the most unfairly advantaged startup company possibly in the world because our founders, uh, were the founders of AppDynamics.
And AppDynamics basically created the entire application performance metrics space. And, um, you know, Joet Bonsal was successful with that company to the point that, uh, he sold it the day before I p o to Cisco, uh, in 2017. Took a bit of time off and then started looking at the market on where there were key problems and actually started two companies simultaneously Harness, which is a C I C D platform, and then traceable.
And I love the story about Traceables background because I think it speaks directly to what, uh, makes us different, um, which is, uh, the application dynamic, uh, or the app dynamic roots, right? AppD built, um, you know, an enterprise level solution that can handle massive amounts of volume, um, using trace technologies. And in using, uh, those capabilities to build, uh, traceable, it answered a really important question.
One of our engineers at one time was looking at, you know, AppD and what was going on with the customers they had and said, you know, we collect all this information about performance metrics and we take all the security information and we kind of toss it on the floor. Do you think that security information is important? And that really became the genesis of, of traceable.
So the goal state for traceable is to use an entirely different architecture than is available out in the marketplace today to monitor, not just collect all the information about your APIs and, you know, auto discovery and cataloging and all that, but, um, really take and evaluate every a p i every single, single time it's used against a normative baseline of what the A p I is supposed to be doing. So we take that catalog and then we take all of the information from every time that a p I is used and we do comparative analytics, um, against this normative baseline. And that helps us discover, uh, you know, huge numbers of unknown vulnerabil vulnerabilities that aren't published, haven't been, uh, uh, shared internally within research communities or, you know, discovered by any other sources.
Um, and that capability to discover these unknown vulnerabilities is incredibly important because, um, when it comes to a p I security, back to the point you just made about, um, we've only been talking about it for the last couple of years, regardless of the fact that APIs have been existent for 15 or 20, um, the bad guys are on the job training too. They're learning how to use all of these APIs and abuse them in new ways, which means that things like published vulnerabilities are functionally worthless. You, you have to be able to keep pace with how the bad actors are manipulating those APIs.
And really the only way to do that is to use this comparative analysis between how an API is being used and what it was designed for. And that's what traceable excels at. Agreed.
Excellent, man. Good, good background. ai is the website.
Yes. Cool. Alright, Richard, so you guys have been doing this state of a p i security report now, this is what going to be the second or third year?
Um, so this is, uh, this is a second, but in this particular case, we took a slightly different, um, direction, um, on our most recent, um, we, uh, we partnered up with Larry Poman on the P**n Institute, which, um, is always a great thing to do. Um, I've, you and I have been around the block a long time. Larry's been around the block, probably, probably longer.
Larry's actually down here near us. We're in Boca Ratone. Larry's down right down here.
Yeah. Yeah. And I, I think that, um, the value of going with the PAMA Institute is kind of the, the, the depth and breadth of their experience and doing studies and analyses.
Um, and, and I think that, uh, you know, even, um, you know, in Larry's case, he was, and as I was, I, I was shocked by the founding, uh, the findings in this study that we've, uh, we've developed. And we think the most important thing about this study is, is that it doesn't rely on, you know, let's do case studies on breaches and, and hacks from the past. Um, let's talk to people in the enterprise and ask what their current state understanding is of a p i security and whether they have programs.
And, you know, the percentages have come back, uh, that, that are really kind of shocking. They indicate, and I think we can dig into this, they indicate that there's a substantial cognitive dissonance between I know I have a problem and I'm doing nothing about it. And I don't know that there are many points in cybersecurity or information security history where the gap has been as large as what this study is, is suggesting.
Um, and it raises a lot of questions. Why are people, uh, you know, slow to address this issue? Why are people slow to form up programs and, um, invoke, uh, controls to be able to address a p i security?
And I think there's some indications in the study of what some of those answers might be. Um, but really the, the, the, the degree of the problem, um, is mention in this study, uh, in a way that, like I said before, it was really shocking to me and I'm an old practitioner, um, and I don't see many things to surprise me anymore, but this study did I, I agree. So I always like to say, Hey, Richard, we we're going to get into the surprises in a second, but let's take the, the key findings, the three big key findings, if you will.
Sure. If you don't mind sharing. Yeah, absolutely.
And I don't, you know, I don't typically read off the percentages, um, you know, in rote, I don't Need the percentages. Yeah. I encourage people to go out and pull down that study and take a look at themselves.
But what we, what we definitely see as kind of the three, um, you know, or so major issues that have, have been highlighted in the study is first of all, the landscape of APIs is much bigger than anybody's really acknowledging. And, and one of the things that I found fascinating in the study is, uh, 88% of the responding companies, nearly 1700 respondents, um, across, uh, the world, uh, because it was a global study, um, 88% have more than 2,500 cloud applications. That's a staggering number.
Um, and what's interesting about all of these cloud applications is, is that they're incredibly dependent and some of 'em are exclusively dependent upon APIs in order to be able to do and provide the functionality and features that these companies need in business applications and technology applications, 2,500 applications to be exposed to that all have a p i dependencies is a massive number. Um, and that's just an average. Um, and, and I think that, you know, the other thing that really materializes out of these, uh, out of this study is that, um, there is a universal, uh, understanding, you know, nearly, you know, in the seventies and 80%, uh, range of, of concern that APIs are a, a substantial threat and risk.
Um, and you kind of couple that with how many of you are doing something about it and it's 80 some odd percent acknowledging and 20% on doing something about it. There's that cognitive dissonance gap that, that gets me so concerned. And then I think the other thing that really, um, you know, kind of jumps off of or out of the pages, uh, of the study is that, um, everybody is acknowledging that their a p I situation is going to get worse.
Um, they're acknowledging that that APIs have created a dynamic where, um, attack surfaces are growing within their organization every day. And if we look at, you know, security frameworks, whether it's NIST or ISO or, uh, zero trust or any, there's no security framework that suggests that what you really want to have happening in the organization is your attack surface growing out of your control, right? Your, your goal state is to du reduce your attack surface.
Um, yet the survey respondents and study respondents for, for, um, the work that we've done in the state of a p I are all clearly saying that, um, this world is moving faster than we are, and that attack surface is growing exponentially. And it kind of, you know, leads you to that conclusion of why is anybody in the marketplace thinking that this particular problem is going to age well? Um, because this problem is going to age very badly, very poorly.
Um, and, and again, the numbers are simply concern, uh, confirming what we've talked about anecdotally for the last two or three years around a p i security problems not aging well, you're not doing anything about it. You recognize that as risk, and then frankly, your attack surface is even bigger than you thought it was. Agreed.
Agreed. Man. Um, you know what?
I'm a half full kind of glass half full kind of guy. It, this is progress to me. I mean, it's, look, the world's full of potholes and time bombs and yeah.
You know, but this is progress for me because I think at least we're acknowledging a, how big a, a part APIs play in our development, in our applications, right? In, in our connected world. And b, what what some of these issues are beyond, do I have APIs?
What APIs do I have? Right? And, and, and so that's progress.
Um, you mentioned, you know, you and Larry were very surprised at some things. Let, let's kinda highlight those for, if you don't mind. Yeah.
For, for the audience. I, I think I can really just boil that down to one, um, you know, key finding that all other surprises radiate off of, um, which is just this, this finding that, um, the vast majority of enterprises are doing nothing currently, um, relative to a p i security. And in the cases when we look in the, uh, It's not progress.
It's not progress, right? Right. But, but in the cases where we're looking in into that, um, into those findings even deeper, um, what we, what we are seeing are numbers inside of that study that suggests that a lot of enterprise security as well as enterprise business leaders strongly believe that their current state solutions are solving for a p i security.
And this is a point that I find fascinating because if you look at the, the, the news cycle, if you look at the breaches, uh, that have been a p I enabled, and this is not throwing rocks at any of my, you know, brethren and sisters at, uh, any of the other solution providers and, you know, all the security solutions that have come up in the stack. But the reality is, is that every massive, uh, a p I breach of the last two years, uh, were large enterprise customers with huge, uh, you know, customer and account volumes that were exposed or data that was exposed. In every case, every single one of those large enterprise customers has gateways in place, has web application firewalls in place as encryption in place is using, uh, you know, authentication protocols.
And there's not this recognition that all of those different components, like if we think about authentication protocols being used for a p i security, which a lot of people say, well, if I authenticate it correctly, then everything's gonna be good downstream. Um, we have to kind of be intellectually honest with ourselves and remind ourselves that APIs, which are virtualization in this layer seven making all of this cool magic happen are dependent upon authentication technology that was created about 25 years ago. So this, we, we have this disconnect where security architectures and security solutions, um, are, are being overlaid onto this cloud, uh, enabled world.
And those technologies, like I said, I'm not throwing rocks, I'm just simply looking at outcomes and results. And when a company like T-Mobile has 37 million accounts, uh, you know, exfiltrated from their organization like that, you know, it raises questions like, okay, so why didn't securities technologies that were currently in place that are managing a p i traffic and all of that catch that the truth of it is it didn't catch it because it was still dependent upon a security architecture, um, that is based on 15 or 20 years ago. So I do think that one of the things that, um, kind of radiates off of that, too many people not doing anything about this currently, or they think that their current state solutions will protect them in this a p i security space, um, is we're starting to see, and this is a, the glass half full, uh, kind of, uh, position.
We're starting to see people understand that maybe, um, some of our most pressing challenges aren't specific to a solution like a traceable, um, but they're specific to the fact that our security architectures have not changed to reflect that the way, the way that the bad guys are actually attacking us. And, and that security architecture conversation starts to lead us in the conversations about the sufficiency of our current state solutions and whether or not we need to change those. So I think all of that is, is very clearly, um, pointed to, right, not explicitly talked about in the study, but clearly pointed to in the, in the, um, information that we have.
And Alan, I wanna come back to something that I think is so important. Like you said, you know, we, this is progress, and I agree it absolutely is progress because it matches a pattern that we know from history, and sometimes it takes the folks that have been around security for a long time to see these patterns. Um, but there was a time in history where I could walk into a data center and ask how many firewall rules I had, and a security engineer would look at me with a blank stare and say, I don't know.
Right? Or how many virtual machines do I have, say 10 years later? I don't know.
Right? How many, uh, web applications are my employees using? I don't know.
And, um, that, I don't know, phase happens perpetually in the evolution of technology. And we're beginning to come out of that, I don't know, phase the study proves this, the, I don't know, phase and into the, I better know and I better do something about knowing, and from knowing I'm gonna understand my risk dimensions and from understanding my risk dimensions, I'm going to start to take action. So we're in that window now, that inflection point has been achieved.
I think this study proves it. And I think that that's a very good thing because now we'll see, see companies and organizations begin to take this particular threat seriously. Way to, way to put a smile on at the end of that, Richard.
Um, and, and I'll tell you something else. You know, it's almost the nature of the industry that there is a lag between what's going on, sort of at the front lines, right? Yep.
And that information intel making, its way back to the architecture groups and it being, uh, reflected in new security architectures and processes and so forth. It's just the kind of the nature of the beast. You, you wanna shorten those lines, right?
Yeah. You want to increase the communication, but the, but it is taking place. And as we both said, it's a good thing, Richard, you know what we didn't mention?
ai is the website for the company. Where can they get this report? Um, there's a stub for traceable, or for this report on traceable ai, you can actually go right to, um, our, our web slash page.
You'll find a link to go directly to it. Um, and anybody's able to download this report. We encourage people to do so.
We're actually broadly distributing it, uh, to agencies and organizations, um, and, you know, everybody in the industry that's willing to, uh, take it on because I think it, I, I think it is a unique study. Um, like, like I said at the top of the conversation, I think it's a unique study because it's looking directly at the levers and the mechanisms and the decision making processes around, um, why a p i securities in its current state and how to move forward from here. Like I said, instead of doing some kind of, you know, forensic analysis of how many dollars were lost or how many people, you know, impacted an account fraud or account takeover, those numbers are really, really important.
But that's just a scoreboard, right? People really need a playbook. And I think that the numbers that are in this study are giving indications of a playbook, um, that people can begin to form up in their organizations to attack this particular issue.
Excellent. Richard, man, thanks for coming on, keeping us in the loop here on, on this latest study and what's going on in a p i security regards to Jody, Jody, and the entire traceable team. Come back and keep us posted, man.
Until then, enjoy Absolutely up for it. And as always, thanks again for having me on, Adam. Thank you.
Keep doing what you're doing. Richard Byrd, chief Security Officer, traceable AI on their new traceable AI state of API security study. ai.
We're gonna take a break. We'll be right back here on Textron.