Web and API Security with Beatrice Sirchis and Asma Zubair at QSC24
Beatrice Sirchis from IDB Bank and Asma Zubair from Qualys discuss the evolution of web and API security at the Qualys Security Conference, focusing on how modern applications require proactive and continuous vulnerability management. They emphasize the importance of scanning applications in non-production environments to ensure security before deployment and highlight Qualys’ comprehensive tools for securing web applications and APIs. Both speakers stress the need for security teams to collaborate closely with developers, providing clear remediation guidance to integrate security without disrupting development workflows.
Transcript
This is Textron tv. Hey everyone. We're back here live in San Diego with more coverage from the Qualys QSC.
I've got two speakers here to introduce you to. First of all, to my immediate right is Beatrice Circus Circus, and to my far right is Asman Bert. Darn.
I got it right. Okay. Beatrice, why don't we start with you first.
Tell people a little bit about kind of your journey and what brings you here today. Okay. So, um, I work for IDB Bank in New York.
Uh, I am the head of application security and vulnerability management. Um, I started in security 20 years ago, uh, with a lot of experience in, uh, networking applications, um, if all that is related to this. Um, so today we are going to speak about Qualys web applications can, um, and how is this platform allowing us to keep the bank safe, um, to, to keep the bank within, uh, the risk appetite that is defined, uh, and to provide our customers, um, good and safe service.
20 years ago, security was all about network security. Definitely. It's come a long way.
Yeah, right. It was all network security. We had the moat and castle.
It was such a different, different place. But thank you for sharing that. Aswan, how about you?
What's your journey been like? Yeah, so currently I work at qualis. I'm leading web application and API security product line.
I have been in application security space for more than 10 years, and I have had the opportunity work to work on dynamic application security, interactive application security, little bit of sast. So I absolutely love application security space and I'm happy to be part of this conversation here today. So I remember when I first became exposed to AppSec, as we call it, right?
Application securities. I had a friend, Jeremiah Grossman, who started a company called White Hat. Yes, I know Him.
Sure. And that was my first exposure to AppSec. And of course then we saw, uh, uh, oasp and, and all of these things and application security became, if it wasn't AppSec, it didn't mean anything.
No more network security. It was AppSec. And then, you know, funny thing happened and we saw the rise of WAFs web application firewalls, and I got into DevOps and DevSecOps and that exposed a different kind of web application security.
So it was no longer just about scanning, whether it was a static scan, a dynamic scan, software composition analysis, SCA and so forth. But it was also, it became about software supply chain security. 'cause that's part of your app.
And all of a sudden everybody started putting, and another thing happened, you mentioned APIs. Yep. All of a sudden, APIs, now 57% of all the traffic on the internet is just APIs, talking to APIs.
Absolutely. And you know what, for the most part, they fly underneath the waf. So WAFs, which where all the rage quickly became useless, almost useless.
And we had to have a new, a new way of looking at security. API web application security through it all has been Qualys. Right.
I'm, I'm in this, as I said, 28, 29 years through it all. It's been qua. How has this evolution, this story impacted, it's obviously impacted you in your career, but how does it impact how you do web app security and scanning at the bank?
So, uh, that's, that's exactly the question. So, uh, most of the, um, applications today are web based even. So we see the migration towards mobile, uh, and that is happening.
Um, we still have most of our applications on the web. And of course those applications are using APIs because there are so many financial platforms that need to interconnect and interchange customer information through the APIs. So the API security became the critical topic of this year, and the top priority from a security perspective.
But I want to go to the basis first. So the web applications, the web applications, as we know from the SDLC, they are starting from a non-pro environment. And most of those applications are that critical, that have multiple non-prod environment.
And we scan those using Wally's web applications, scan in non-prod, and then make sure that we, uh, work with the application team, uh, to remediate the critical and high risk, uh, vulnerabilities in non-prod. That is, um, the, the threshold is zero critical and high risk vulnerabilities when moving into production, otherwise it will not be approved. Right.
Um, and we are doing so using, uh, the qualis, uh, infrastructure, meaning the cloud agent, uh, that is in the cloud for the applications that are in the cloud. And for the internal ones, we are using, uh, the, the scanners that we deployed into the bank infrastructure. So it's all based on ALI'S infrastructure, the scanners, um, and those scanners are used for, uh, more than only the application, but we are speaking about the applications today.
Sure. Um, so, uh, having the ability to scan from the non-pro, it means that in the production, the applications will be clear from a security perspective, they will still be skinned. But we see that, uh, critical and high risk vulnerabilities are already remediating and it give us the peace of mind to allow the application to go live.
So, and just to be clear, when we say non-prod, right? It could be in a test environment, a dev environment, it it, you know, if we look at the left to right timeline with the middle being deployment, it's to the left of deployment. So yes.
If you will shift left as we call it. Right, Right. Doing, doing that, the scans there, um, now that's a big change, right?
It's a Huge Change. When I was doing security due, we were lucky if we scanned it, we once a year after. But we also live in a dynamic world and what, what seems to be secure today is not secure tomorrow.
It's even more than that. What is secure today? It might not be secure tomorrow because a new vulnerability will be found out.
And then continuously scanning with the Qualys, uh, infrastructure, we discover those vulnerabilities in a timely manner and be able to remediate those because, you know, anything that is not remediated, it's, it doesn't worse, right? So we, we keep a very close communication with the application teams so that they get the right details, what is the problem, how to solve that. And then we re scan and validate that is remediating Zuma.
I want to ask you, we, we mentioned there's different kinds of scans today, right? And I apologize, I can't make these people stop talking, but our mics are good. They'll hear us.
But we have dynamic scanning, static scanning, software composition analysis, API testing, is it really called API scanning or API testing? Depends who you talk to. Qualys has all of these, So definitely, uh, for dynamic security software composition analysis, basically whatever is needed for, to secure your applications or to perform security testing, to be precise, Qualys offers that.
And our web application security testing is very unique for many different reasons. We scan for not only OVAs top 10 vulnerabilities, we also look for PII exposure. We also look for, uh, like using Qualys VAs, you can detect and monitor for the presence of malware as well.
So it is super comprehensive, uh, application security testing. And what about API specifically anything there? Absolutely.
So for API security testing, we have, um, like OVAs top 10, uh, for APIs. Yes. They have their own API list now, Especially, yeah, those checks.
And not only that, uh, QUAWAS also looks for compliance to open API specifications because that has pretty significant impact on how APIs are adopted. So we look for those weaknesses as well, or nonconformance to open API specifications. So, you know, when you look at the banking industry today, the banking industry today is a very different place than it was before Covid or 25 years ago.
There aren't a lot of banks putting a lot of money into opening up new brick and mortar branches. Everything is done via app, everything. Right?
I, I actually had to stop in my bank this week to get some paperwork done. It's the first time I set foot in a bank. I don't remem I don't remember the last time I was in a bank.
Now this puts a lot of pressure though, that these apps, they have to run flawlessly because you know how customers are te if if your internet on the airplane doesn't work, they're ready never to fly your airplane again, right? They need those bank banking's. Mission critical.
How does Qualys help make sure that your mission critical apps are not only secure? 'cause sometimes I think people, they talk about being secure, but it's more important they work for them, right? Yeah.
How does it help make sure that they're up and running all the time for them? Yeah, so, um, this is, this is really important. Um, we are able to use, uh, qua tags, uh, to tag the critical applications, um, also to tag the environments and also to tag the exposure.
So being able to tag, we will prioritize, uh, the scanning and the remediation for the ones that are more critical to the bank and why we do that, to make sure that there won't be any financial loss. Sure. Okay.
So this is all we want. We want to keep our customers safe, we want to keep the bank safe, and we know that, uh, the financial sector is the first one that is being attacked because there's money there. So Always, Yes.
So there's no, uh, there's no expectation that those applications will not be attacked. Uh, the only expectation is that when is this attack may be impacting. So we are constantly scanning, constantly reviewing, constantly looking at, uh, uh, risk level of the vulnerabilities that we found.
Uh, we are using also the, the quality true risk. Uh, so only speaking about the severity is not enough, right? Because it might be like a medium severity vulnerability, but Well, It could be medium severity on a Risk.
Exactly. Risk risk might be very high. So we do take that into account Sure.
And work with the application development teams to remediate those before, uh, before they are going on with an upgraded application or before they play a pitch. Um, and there's another aspect as well. net, um, Apache and those third party software are coming with other vulnerabilities that are continuously discovered.
So we use the software composition analysis from Qua to discover those and to remediate those as well. And that saves us efforts to, um, implement another platform because otherwise we should need to buy another platform that, that's software composition analysis. We have it in Quas with the very same agents that we are already deployed and uh, installed.
Uh, so this allows us to efficiently address and have one source of tools for all those vulnerabilities. Obviously we use another platform also to scan. We use velp.
Uh, so we, uh, import the XML files from Burp into Qualis so that we have one source of truth, right. And we have a complete report to our application development team. This is what you need to remediate.
Uh, and it's very good that, uh, the report includes not only what they need to remediate, but also how they should do that. And That that's an important part of this, right? Because I, you know, the old days you would get a, a vulnerability reporter looked like a telephone book and many of the people young out out here don't remember what a telephone book looked like Exactly.
But, but they were very thick. Right. But if you didn't know what to do to fix it, what good was it?
You had to sit and look up every one. It could take forever. The nice thing about the Qualys, uh, uh, web app portal is it tells you right there how to, how to fix these.
I haven't heard someone talk about bourbon a long time. Um, yeah. This, this is a very, very good platform, uh, very, uh, customizable.
Yeah. Um, and um, uh, it's, it's always a good way to, uh, test an application from different angles. Absolutely.
But the better way is to have one source of tools You have to, to, 'cause we won't be able to manage otherwise. It's hard enough managing with one source. It gets exponentially hard from there on.
It does. And we are also aware that, uh, developers that they need to remediate. They are not security specialist.
No. So the more information we are giving them from Qualis, the more they are able to do their work And, and the more they understand. com, so we speak to developers all the time.
Oftentimes they feel like the security people tell them stuff, oh, there's a, there's a vulnerability here. Why, why? What's vulnerable about it?
What, what Exactly. And so, and 'cause they tend to think those security people just make stuff up to make our life hard. They say, no, why do I gotta do this?
What's the policy? What, so when you could give them that kind of background, no one wants to make bad code. No one wants to develop insecure code, but they wanna know that this is not just being done arbitrarily.
So, So having one source of truth makes us cybersecurity to be an enabler for the business. Uh, and not saying not a Burden. Exactly.
Yeah. Agreed. We're about outta time Azuma beaches.
Thank you for being here. Thank you for presenting here at uh, QSC this year and good luck. Thank you.
Alright, we're gonna take a break. We are still live in San Diego. We've got some more content, we've got a lot more guests to come.
Stay with us. You're watching Text Drunk tv.