Cybersecurity Challenges with Ken Dunham at QSC24
Ken Dunham shares insights on cyber threat intelligence at the QSC24. He discusses the complexities of making intelligence actionable and the unique challenges faced by security companies in protecting clients and addressing supply chain vulnerabilities. The role of AI in both enhancing phishing attacks and providing defense tools is explored, along with the implications of cyber warfare for nation-states. Effective digital transformation strategies are emphasized for managing cybersecurity risks.
Transcript
This is Textron tv. We are live in San Diego at Qualys, QSCA Qualys Security Conference for those of you who are, uh, alphabet challenged. Um, and I'm here with Ken Dunham.
Ken is an interesting fellow. We spent the last 20 minutes just talking. He's lived in Australia right up in cons by near the Barrier Reef and up in the rainforest up there.
Um, and he has a pretty unique kind of role within Qualys. It's both, uh, well, I'm gonna let him, Ken, first of all, welcome to Techstrong tv. Yeah, thank you Alan.
Yeah, it's great to be here. I'm gonna let you sort of describe what you do here at Qualys. You bet.
Yeah. I'm the director of a cyber threat intelligence, and in a normal CTI type role, you look at what the threats are and you try to create context to make that actionable decision. But unfortunately, actionability really never comes.
It's like a nice buzzword in the world of intelligence, but it's actually difficult to achieve because mm-Hmm. You have to have tactical, strategic, and operational outcomes. And usually what you get is smart guy research that's tossed over the fence.
So at Qualys we engineered that differently, and my role involves purple teaming and demonstrating and coordinating with different business leaders and different units so that we look at the threats that are facing Qualys and our clients, and we go in and see are we protected or not? And then where we see gaps, we identify those gaps, we prioritize those, we use our own true risk, uh, methodologies, and then, um, we go and remediate those. And then I go back in and I retest.
And we're constantly hardening and using framework driven approaches so that we're consistently lowering that risk in the areas that are most important to us and our clients. Got it. What's unique about this particular role at this particular company though, is you could be a computer threat intel guy or cyber threat intel guy at a bank, and you are going to subscribe to various CTI feeds and, and look at your stuff and you're gonna protect your bank, but you're only really worried about your bank.
Correct. You are a CTI person at a security company that stores thousands of companies security data in the cloud, or, you know, off-prem. And in some ways that makes for a giant honey pot, almost an irresistible honey pot.
And so your role is not just to protect the bank, but this particular bank, Qualys actually has thousands of customers that it's your job to protect them as well. And there's a little bit of, well, if it's good for Qualys, it's good for them. Right.
But there's also a lot of, well, I gotta make sure the bank is safe. Right? But I gotta make sure we're conveying to our customers and keeping them safe.
Yeah. We absolutely use our own products. We eat our own dog food, if you will.
Mm-Hmm. And so it's essential that our stuff works good for us and it works well for our clients. And, uh, you're right now, you didn't use the words, but we are a supply chain.
Right. And a lot of people now realize that over the last few year, there've been multiple supply chain attacks. Yes.
There have, Especially from a nation state perspective, it only takes one client downstream for a nation state to target you. So with 10,000 plus clients, we have at least one, and I'm certain many more. In fact, I know right.
Where nation states are wanting to go through us in order to get to them. So as a supply chain provider, it's critical for us to make sure that we're aware of that and, uh, through the entire lifecycle of threat modeling and how we provide security internal and in our product and in our operations, we've hardened against that and we've lowered our risk for ourselves and for our clients. We have that responsibility as an ecosystem.
Agreed. You know, you mentioned supply chain security. I mean, this is exactly happened.
A friend of mine's company, they were compromised Mm-Hmm. They were in the identity space, they were compromised. They were just like four companies based in Asia that were the true targets of this compromise that they were trying to get to through this company.
Right. Um, and it was a nation state involved. I'm not here to name names, but, um, it, it's, it's a real, it's the real issue out here today that, and it's an issue that unfortunately is, is getting worse.
Right. It's not necessarily better. So Jeff, what do you do?
What do you do to stay on top of this? How do you constantly improve the intel? The, Yeah, that's a good question.
So intelligence is really a, uh, it's not a, a stopping point or an end point. It's a continual lifecycle. It's ongoing and it's very dynamic.
Just like in our IT stacks. Uh, I can set up something and think it's gonna be great, but then somebody goes in and opens up telnet or they change a configuration temporarily and then they forgot to change it back. Everything is dynamic and it's changing and the threat scape is changing, right?
Like adversaries in the last year, for example, have innovated and started to use QR codes in their phishing. We didn't see that five years ago. And so now we have these new tactics or TTPs that are being utilized in the threat scape.
So we have to constantly be evolving and adapting to the changes in our defensive and also adversarial threat scapes in order to stay up with it. So we have to constantly stay up with it. You know, ed, uh, the CEO here, Carlos was on this morning with a, I forget her name now, I interviewed her this morning.
Hmm. Uh, from Harvard, uh, uh, Kennedy School at Harvard. And they were talking about, you know, the time to boom.
Right? So in other words, the runway of Mm-Hmm. How much time you have before boom.
Right? It blows up in your face. Um, that time to boom is getting shorter and shorter.
And that's, I think what we're talking about. And then we have things like AI now, right? Right.
You talk about QR codes in phishing, what about phishing being written by ai? Right? So all of a sudden the English is a lot better on those emails.
They're not so obvious to spot, right? Yes. But they're also more, they're written, you tell the ai, I want this to be convincing.
I want this to be authentic sounding. Right. Official sounding.
And you know, so that's notched up the game here. Absolutely. On the other hand, you could use AI to help you.
Right. It has a pro con As well, right? There's well, there's a double edged sword, Correct.
Yeah. AI is complicated. So there are a lot of different layers.
Uh, to answer your question explicitly on phishing, I'll give you an example. I have a respected colleague of mine who's a cso, and he was at a CSO event with a bunch of other leaders. And within a very short period of time, literally just a few minutes, he was able to use AI to go out to a website and have it automatically collect all of the logos, the colors, themes, and everything from a target company and have AI craft and code, the coding level, the whole thing, put together a customized phishing email that was very believable, customized, and outstanding, and then link it to a website, you know, to mimic that of a phishing email.
And it was like a hundred percent amazingly beautiful and believable. And it was all done by AI in just a matter of minutes. It was very efficient and cost effective from an adversarial perspective.
So now we have weaponization of AI being used to make the job easier and more affordable for the bad guys. Uh, and everybody was kinda like jaw drop. Wow.
I had no idea. And of course, we already live in a world where it's very hard to tell truth from fiction. Uh, and we have our adversaries with disinformation and misinformation campaigns, especially around the election period.
And it's like, how do we, you know, and you've probably seen the AI faked videos. Those are shockingly real. They sound like the candidates and they can be really funny.
But it's disturbing too, because they're using it for disruption and division of the American people right now during the US presidential election. We have a blog coming out on that here in the next few days, probably next week. You'll see that on, um, activities around that.
In part related to that, You know, I I quite a bit, I'm glad you brought this up 'cause I usually don't like to bring it up, you know? Mm-Hmm. Politics and all that.
But, you know, we, we tend to think of, of a lot of malicious hacking activity as being like financially motivated, right? Right. The bad guy's looking to make money, they're gonna break into your credit or Right.
Money wise, then you have nation state sort of espionage. I want to steal trade secrets. I want to, I want to get the blueprints to your stealth plane.
I, you know, strategic assets and stealing them. It's, it's, it's it's nation state espionage is what it's, right. But what you are talking about is something altogether different.
It's, it's sowing mistrust discord Mm-Hmm. Discontent into a society to hopefully set it, set it in upon itself to rip itself apart. Correct.
It's pretty insidious when you think about it. Yeah. But this is exactly, and it's not just one country, first of all, I I, I want to Say there's three of 'em.
Yeah. The axis of evil, right? Absolutely.
And, and I'm not saying the US are angels here and we don't do offensive cybersecurity operations and so forth, but this, this sort of evil access, if you will. Yeah. Um, I don't know what the answer is, is, is the, Well let me help you think of it in a different way, Alan.
Go ahead. Cyber warfare is, uh, we, I think we think of it often as a cyber tool or a nation state. We, and we need to realize it's cyber warfare.
So we've had a few things change along the ways and now we have cyber warfare tools and tactics that is a real world way to weaponize and do military and nation state things. So that's what we have today is cyber warfare tools and capabilities. And it can have a really big impact on you because you can go out and impact social media and spread fake news and totally play off the biases or cause people to react in a certain way or cause disruption or these great big things, or right before the elections spread some news that might cause people not to go and vote or whatever.
Like we don't know what's gonna happen. But that's, that's a Possibility, a surprise. And we have seen, for example, advents in the Russian Ukraine war and how cyber has been used there in various capacities.
So, uh, if you're not doing cyber warfare in 2024 as a nation, you've missed the boat. Everybody's doing it right. So, doesn't make it a bad thing.
It's just a new tool that did not exist prior to the information age that occurred around the turn of the century. So it's a new tool and it has pros and cons. Uh, but we are in the information age and especially now with lower breeding satellites, uh, the new advent of the race to space and all the things we have that are happening up there.
And we have a tremendous amount of information that can be weaponized or used against us that people haven't even really thought about that are in low orbiting satellites and space on our phones, our devices in the cloud. Um, there's so much smart going on around us that we've become stupid with the context. We have no idea even what our phone carries or can do to us.
And we have, we're just completely ignorant to this. And it's scary when you realize that like, if your phone is compromised, I could listen to you, I can track you, I can see all your texts. I, there's a lot I can do that it gets scary real quick.
Absolutely. And I'm not here to spread fud and scare people. But Let me ask you, let me turn this around to you now.
How the heck can you do your job well in, in the, in the face of these threats? That's a great question. You what Success for you?
Uh, success is extreme prioritization and, uh, being aware of everything. So like you were just talking about cellular phones and not fud, did you know recently that, you know, there was an attack using cellular phones that killed people that was used in warfare? You know, this actually occurred.
It's a phone Fall in Lebanon. Well, beers No, it's bull lot. Yeah.
Yeah. And that's not fud that actually happened, right? No, that absolutely.
I'm aware of that from a nation state perspective and weaponization of phones and is that impacting Qualys? Is it impacting our clients? These are things that we look at because this is a cyber threat that could potentially be used to attack us.
So we size that up and we look at that and we assess the risk. And that's what we do every single day. We, we look at the threats and we figure out, is this something that's high risk or low risk for us?
We use our true risk strategies and we deep de-risk. That's what we do. I mean the, the, the beers in Hezbollah and sort of truly classic supply chain Mm-Hmm.
And that appears they were manufactured, manufactured with bombs inside of them and then sent a little different than your usual computer code. Right. Kind of thing, but a supply chain, right.
In every sense of the word supply Chain abuse. Yeah. Yeah.
Um, I just can't, and I've been in security myself a long time. Right, right. And, and look, you know what they always used to say about security when you're doing your job, no one knows you're there.
Yeah. 'cause no one hears about it. Nothing happens.
Yeah. As far as they see can, is that still doable? I don't think so, because I believe that if you're doing security properly, right?
On the extreme secure side, like I've been in some pretty secure systems. I've touched the root servers of the internet and helped to manage and protect those. Um, they're pretty secure.
Alright. Um, five layers of physical security, et cetera, that's, uh, not easy to get into physically, let alone digitally Right. And facial and all these other things.
Uh, it's pretty intrusive as opposed to I look at my phone and it just automatically does a bunch of stuff and unlocks and I authenticates who I am. Uh, that's a very non-intrusive security set of controls. Right.
So if you're doing your job well in the world of security, you should know that you have security. It shouldn't be super intrusive, but there at least should be some awareness or at least some level of effort, but not so much that it becomes so intrusive that it's not worth it for the level of effort compared to the asset. For example, if I'm logging into my banking records personally, then I should have a higher level of effort.
I want to have multifactor authentication. I want to be notified, uh, because I have more at risk there personally than if I log into my, you know, social networking site or my Yahoo Fantasy Football. I could care less about some of those things compared to my financials.
Absolutely. And so I, you have to assess the level of intrusion and security efforts and the controls and the intrusion that goes with that. So if people thought about it from a risk asset management level of effort and they said, this is just the price that has to be paid in order to secure my stuff, as opposed to, gee, I hate this or I don't want it, I wanna pay the, you know, it has to be an attitude change.
And you have to say it's important. 'cause I remember at the turn of the century we were like, do we really need security? That was really the talk.
Right. And do we need to even have security roles or CSO roles? And now we all know we need it, but I'm not sure we've really reached the point where people have really adopted and embraced the essentials of this along with Well it's because security is still too hard.
Yeah, exactly. Number one, right? The perception.
True. And the second thing is sometimes I think as an industry, we beat our head against the law passwords. Yeah.
You know, the average person has 150 or 170 something passwords doesn't Work a good And there's no way you're picking a different password for every site. There's no way you're remembering them all. Yeah.
We could use password managers and those have been hacked into Mm-Hmm. Um, just the whole concept of passwords, I think it doesn't work. Something we, we gotta get away from.
Agreed. And we do have passwordless based systems. Yes, we do.
And we do have zero trust architecture. Yep. And so we've got better ways to do it and give you just in time security.
Just in time permissions. There's far better architectures, but most organizations don't know how to do that. Well.
They bite off too big. They go too far down that rabbit hole too quickly. Yep.
And it's two or three times the effort that they think and then they get into a situation where instead of it taking a year, it ends up being three to five years of risk acceptance. And they get hacked in the meanwhile because then they have, uh, all these open vulnerabilities and holes and accepted risk and it's a nightmare because they don't know how to do digital transformation properly. No.
So it goes from bad to horrible. So you gotta do digital transformation, right. So start small, something simple that you can easily deal with, and then move into your VIPs and your areas of greatest asset management and roll it out to where you can protect your most important assets and de-risk in the areas that will give you the greatest bang for your buck.
That's really what you need to do. And do it wisely. Ken, I wish we had an hour to go dive into this 'cause this is what people need to hear.
Oh, thank you. Fortunately, We gotta get our next guy in, but hey man, thank you. You do Been a pleasure, Alan.
It's been a pleasure and thank you for what you do. Thank you. Honestly, because again, it's our pleasure, right?
What we say is when nothing happens, no one knows, but nothing happens because people like you are doing your job, man. Thanks. That's what we try to do here at Qua.
Absolutely. Thank you. All right.
We're live here in San Diego. We've got another guest coming up here in just a moment and we have some great content. Until then, stay tuned.
You're watching Text Drunk tv.