Buyer Beware – Techstrong Research Review EP 2
Mike and Mitch tackle cloud-native security and API management security in this week’s Techstrong Research Review. They highlight a Sysdig survey as a means to make the point about the importance of continuous monitoring of both the container and the API environments.
Transcript
here Hi everybody. This is Mike Rothman. And it's our text wrong research review.
This is episode 2. I'm GM of texturung research. I I keep for getting introduce myself at the beginning of these things.
So I wanted to do that and I'm joined as always by my partner in crime. Not really right. He's he's definitely not upselling in any way shape or form, but just that I don't know admit a video but yes, thanks my good to be here course principle of text wrong research and CTO with tech strong group, and I also forget to introduce myself and I'm doing hosting a video.
So yeah, you know kind of often enough where we just kind of forget and we make assumption and we really should so just to review right review the review right? So the tricks strong the text strong research from you the review squared the extra research review is really kind of our internal research meeting so so Trap, you know for three or four minutes before we get going about hey what you're the general topics that we want to talk about but it's not like a newsy thing. Right?
What we want to do is kind of, you know, focus on on area that we've either had calls out we're doing cool research or what have you that we can really dig into for you know, 15 20 25 minutes every week to give you guys a sense of you know, kind of how we do a research, right and what it is what we're thinking right? What's in our heads? Yeah, what's in our heads and they given day so so you're a couple of different topics that we have underway today.
Why don't we start with Mitch? I know you were looking at I'm assisting report that really focused on kind of the latest and greatest in you know, kind of container posture and and images and typical squatting and all sorts of other things that I don't know that I quite understand yet. So what why don't you Enlighten all of us about?
Oh, yeah. No certainly, you know sister came out with their report. It's their Cloud native threat report they do annually and you know, they talk about crypto crypto Mining and all that kind of thing which is of course gets outlines, but you know, okay who cares?
I don't I mean we do but you know, whatever what I found particularly interesting was, you know, we used to talk about virtual images vsms having, you know, potential vulnerabilities Beltone because you've got all that software and operating system and everything, you know, whatever's in that VM, of course, there's libraries of VMS and all that kind of thing. So scanning images was always a important thing we talked about with with whatever we were using VMware, whatever and now this kind of same thing is really true, of course about containers that we haven't really talked about that heavily. They did a nice I think good job.
They're they're GRT research team did some scanning of Docker Hub is one of the public most common of course resources. They're they're library of container images. And of course Docker has You know some processes to go through they have some guidelines that are defined have independent software vendor program for people to upload images.
You can also others can also upload images. Of course, they're not the only source for For container images, of course. There's a lot of software not just our own that goes into a container right open source, you know operating systems up Etc libraries all kinds of things.
And it was pretty interesting. They scan. I think it was like 250,000 images and the kind of things that they found which channel would be surprising to a security person.
But when you think about the supply chain issues, you know, they're finding of course embedded credentials and things like that, but there's other things like proxy avoidance, you know Dynamic DNS registrations malicious code, of course SSH Keys API Keys things are gonna let attackers get back in. So what it really reminded me of you know, we're like, oh go check out containers this next greatest thing. It's party got to do it to do Cloud native and we all go out and go to doctor whatever and that's that's now part of our Dev test production environment.
We've been through that cycle before my What we have right so so when you were first talking about the findings to me, I'm like God that sounds a lot like the discussions. I had to have with you know, all sorts of people as we were getting into Cloud, right and they were starting to pull down, you know, AWS Amis or you know kind of images for VMS in Azure and and or even if we go back in time a little bit further right any app that you're loading up on your phone, especially the Android phone, right? I mean apples a little bit more of a closed ecosystem from that standpoint, but Android, I mean all sorts of you know nonsense and bad stuff was getting into their app stores until they they locked it down kind of right so they they are unfortunately a little bit better policies now and same thing AWS the enforcement a little bit policies, but you still have things that you know, kind of sneak through so verified right using verified images verified containers.
It's critical and you actually have to have that within your pipeline, right? So when you go to your artifact repository or Up or whatever you're doing when you're kind of doing the CI process. You've got to have, you know, kind of a verification hopefully assigned type of verification so that you can you know, go back and and attribute it to a certain, you know, kind of Provider because you're gonna get that kind of stuff.
I mean anytime you're pulling a component from anything. There's an opportunity for it to have a little surprise in there. Right and and for most Security Professionals, we don't like surprises, right?
No surprise. So, I mean, that's really just best practice on that front. Yeah, I think as Security Professionals, you know, it's sort of the X-Files trust.
No one right. It's a little trust trust but verify, right and I think you know, it's been a whole idea of you know, kind of requiring signed images containers apps. Whatever it is is a way to start do that verification process.
Is it foolproof? Of course not right. Nothing is gonna be foolproof.
Some stuff is gonna you know kind of fit in but what we're trying to do is really kind of narrow that attack surface really, you know, kind of make sure that we're doing the greatest level of diligence that we can upfront and it's just highlights the fact that again you're going to find nonsense in these, you know, kind of hubs and and aggregation points and Market places and buyer of aware right buyer. I think that's probably the best message. And I think I think the good news about this is we've worked since we've already been through this process before right with other kind of images.
Is as the Security Professionals want to work with the software developers, they can easily come and say hey we know about this issue. We already have scanning tools. We can help you plug that into your workflow pipeline your tool chain, whatever process you may be aware of this issue.
You may not be but let us help you and then that way you won't have any issues down the line anything anything you do download. We have a good chance of catching. But yes, it's good hygiene to get them from these locations.
They're verified that kind of thing. So so while there's a lot of this stuff present, Um, it's it's not you know, the sky is not following sent Chicken Little right? We've solved it right he gets back.
We we're trying to reduce the attack surface from that standpoint. You're always gonna have exceptions where you've got a new library or something that I absolutely have to you know, integrate into the code or the container or what have you and that's fine. But I would rather kick that out of the pipeline and force a separate, you know human intervention at that point to basically say no we've got to go through some process to make sure that you're doing at least a smidgen of diligence on that to ensure that again, you're not putting the rest of the production environment at risk and that's what we're talking about here.
Right if you have you know, kind of and it's not just you know, you just okay. So you leave some credentials in there. It's bad they get access to you know, some of your Cloud stuff.
Okay, not great. But you know, you you put you know, kind of compromise code in something that you deploy into Broad and that's not something that's gonna be obvious, right? That's something They can get in maintain persistence and and run roughshot over your infrastructure for an extended period of time and that's the stuff.
We really have to avoid. Which by the way time back to crypto mining that was the most common exploit they found in images was embedded ways of people getting back to use your resources to do crypto money here. Listen remote access Trojans are still a thing.
They don't work exactly the same but you know, there's still a thing. Anyways, they're doing the same way. We want it, you know figure out a way to penetrate the environment and and maintain presence there and you know kind of do Recon and then, you know, loot it out, right and that's that's the game.
That's still the game. Yeah, they're so talked about typo squatting that you mentioned which and maybe that's the term you'd heard of. I hadn't heard that before but it's fancy name for fishing for developers.
Right? Let's rename something to a nice open source package. That isn't Or what he dealing with Amis you've been dealing with you know, and and especially on the app side.
I mean, you know, you're looking for a popular app. They change like they put a hyphen in or an underscore or something. It shows up in the library and people don't do their diligence and they just you know download stuff and and it's compromised and you know, mayhemian suits and you know wash rinse and repeat and you know, so we see the same common things like the same types of attacks every time you get a new, you know, kind of mechanism to do the same thing.
Right? And this is a repository. So we're gonna see the typical attacks that you see on repositive on public repositors.
Yeah, so it I mean, it's the thing about containers I think isn't interesting about this is And we're vsms often are like operating systems and a lot of software in it. We're containers can be be parts of that. But also a lot of application stuff so I can't think of it like the processor architecture right Northbound and southbound East and Westbound.
You got to go both through the stack and then also in and out of what you're talking to so think about security at all layers and alter in both directions in and out and and you've got a better chance of catching those things or finding them early. That's right. And that's what it's it's finding them earlier and that and and having a process to deal with it.
And again, you know, just to kind of Bring It Back full circle, right you you when you build out these containers you do it, you know via pipeline you want to have you know, kind of testing and you know, kind of really failing builds, right, you know in that pipeline when when they don't adhere to these specific policies and that is going to be your best defense over time. Speaking of apis you were you had some thoughts on that. I know you've been looking at some things I did and you know, it was as always right.
It's just a number of calls that we have. We we've had this API security report. We've been working on out there for you know, since I start right so, you know, so it's it's about a quarter now that it's just been kind of, you know hanging out there.
So, you know get back here we start to do some research, you know, we've got the cloud container Summit coming up on October 4th. So come in and register for that. We're also, you know co-promoting an event on October 26th with our Pals from Salt security, you know called API security Summit context matters, so you can register for that both of those events or you can link find the links on the text wrong events event or I guess Tech strong events calm link and just hit upcoming events and and that stuff will be there.
But you know, the interesting thing to me is you know apis or becoming just comment right and everybody does it and you know, we kind of we're working on a report. You can you know, we were using terms like API first, you know development mentality and stuff and and I kind of reflected on the fact that you know, this isn't my world at this point. So I'm still you know, kind of drinking from the fire hose and and figuring things out so I figured it would be good if we just kind of went through a little bit in terms of what that process looks like, right we decide we want to do an API we build the API.
How do we instrument it to make sure you know, we're understanding what's happening and tracking, you know, kind of activity there. There's the API management layer. Obviously, there's the API security layer as well, which is how we, you know, evaluating what Access that API provides to internal data and critical data on that front how we ensuring that those apis aren't misused and it could be a DDOS type of thing.
So I just wanted to you again have just a stream of Consciousness type thing for my API expert here in terms of you know, really that whole process of you know, kind of I start and I need to build this thing out. What do I need to do to protect it and make sure that it's done in a performant way since we deal with obviously much more than security and in our world it's extra research and bring it through that whole process of you know down to actual deployments and then, you know kind of monitoring and and management to ensure that it's not compromised in this used. Yeah, I think maybe just double our security friends.
You know, we used to think about apis is how you got into something or go out right? Mostly how did people get to my app. Right?
And it was pretty limited set of apis we might publish or make accessible API first is about Everything is accessed through an API in the container World containers talk to each other that's you know, microservices talk to each other through usually kubernetes API Gateway or a message bus or some kind of structure but the point being is, you know, every service is an API. It's not code that's all linked together and calls each other. Well it does but it does that through apis and and it's kind of like the application uses its own apis to you to use other parts of itself.
So, for example, you might have a product that has apis that doesn't have a gooey your product is. All right. Well through apis a lot of cloud services.
Are that way? Maybe you have an API to manage it or configure it. Maybe not even that and that's the whole idea behind API first and then there's sort of one more Step Beyond that which is API is products and that's what I was referring to is people use our products through apis.
That's what you're that's how you get to it. That's how you use it. That's how you gain value from it.
And so reason why I say all that is there's now this idea idea of continuous API management where you think about apis having a life cycle? Like we would a product or we would a router or a switch in the network world right where the sort of the definition period where you're defining and your experimenting with it and you have some initial prototyping people using it in an alpha way it publish it make an accessible. What's your own internally as well as potentially externally, there's a point where you may kind of get into the maintenance mode you get into a sunset mode and a deprecation mode or you know, you have some kind of Grandfather backward compatibility with the next API this can replace it apis a little difficult to replace because now you got to go change code.
So that's why this whole backwards compatibility with apis and thinking about it as a life cycle. In an evolution and and kind of layers of how it evolves and that's how software developers now think about apis not just getting in and out of my app because you really have to manage it or else it's chaos. I mean, it's you know, that's right.
And that's kind of you know, the first point that already there's a class of tool right for API manage right to help you do that and manage these things across it's entire life cycle, right? Maybe give a little sense of what those things look like and how we integrate those into the development process. Mm-hmm.
Yeah, absolutely and and you know it when we talk about API security oftentimes, it's about Discovery Well, you know in security world will always try to go we gotta know what we have to be able to secure their manager, right? I think another thing that's mindsets that has to change is we're talking about scanning before we're talking about discovery of apis that isn't a point in time activity because in the software world everything can change at any moment and without your notice whether it's third party Services of your own code your own apis by use being used by some other group or whatever. So it has to be built into the process of how you create create applications built code tested to play have it in production.
And that is a continuous, you know, the the devops loop that looks like the infinity Channel. It doesn't really work that way. It's a bunch of a bunch of infinity circles and all those steps all at the same time and even one of them can change production or multiple at any point in time.
So we have to think about security as continuous. It's always we're always in it's in a posture mode of checking security managing and like we do in a network, you know from a protocol and and transport across the wire right seeing those packets or whatever flowing. It's kind of the same way with software.
I would actually positive it's exactly the same way with software because ultimately those requests they look different than you know, kind of the session type information that we had to and stay information that we had in common more traditional applications with you know, kind of the protocols that ran those so these are Bring but they still Traverse the network, right? So so monitoring that Network looking for API traffic understanding using that as a mechanism for Discovery, right? It's wonderful, if you know about the apis you can build instrumentation code into the API.
You can have it paying other services. So you're understanding about performance and and usage and and be able to track and profile and identifying misuse from that standpoint. It's the ones we don't know about that can hurt us, right.
So that's why you know kind of doing the analysis on network traffic doing passive monitoring understanding what API traffic is there, you know kind of using kind of like a tax service management but API service management and I don't know if that's a thing right in the category. It would sound you know, it is right. So, you know, what you're doing is is your identifying this traffic then you're going hitting the API seeing what it can access right, you know profiling all of that using fancy math, you know understand what would you know kind of be anomalous in that kind of situation and this is a thing.
Because this is the way applications are being built now, so it's not a matter of hey, I'll just use my API Gateway as a mechanism to do that. Well sure. I mean if we're trying to groom the traffic and we're trying to make sure that it's performant and you know, we want to try to aggregate stuff that's there necessary but not sufficient I think is a great way to put that is that yes, we still need the API gateways.
We want to layer security and just like we do on, you know, kind of laughs as they work with, you know CDN devices and they've gone towards services on that front, you know, we want to embed security within the API Gateway layer to the degree that it that we can right but it's not enough. We need to be watching outside of that as well. But I think that's a really important part because the gateways and essential element, you know, EPA Gateway, whatever application firewall whatever might be But it's not just filtering and controlling traffic.
Yes. It's doing kind of access control for apis but there's also things like Key Management key rotation, and these are things are being done and you know seconds and minutes not days and weeks right how offering may be rotating keys in the apis that are being accessed in credentials, you know, not talk about credentials being stored in containers and of course in our code and things like that, we don't that with that exposed. So there's that's all part of that continuous API management when you think about the security layers and all aspects of it.
It's a continuous process to your point. Yep, exactly. So, you know anything what we're trying to do here is to bring up some of these things that everybody needs to keep in mind.
Right? Yeah, and we'll Peg them to news things like our conferences right October 4th, you know, October 26th. Visit us learned learn a lot more but really the point of what we're trying to do here in a fairly crisp and and quick format is is to give everybody a sense again.
Not just what we're thinking but some depth and some context for why this stuff is important as you move along that Journey from how we were dealing with a whole bunch of traditional stuff. Now that we you know are embracing both Cloud native but also devops as a mechanism to you know, kind of build and then deploy a lot of these Cloud native Concepts and and and infrastructures and obviously the code that kind of runs within all of the above. So yeah, you know, very interesting space very Dynamic again.
I'm kind of the new guy still have still have a little bit of new car smell although after my first quarter. You know, it's starting to wear off and it's starting to become my problem from that standpoint, but it's been great for me because I'm able to you know, really just learn right? And then what I'm trying to do is learn and and feel all the context.
So I'm not a lot different than a lot of you folks out there. I'm trying to get my arms around all the different nuances of how these things fit together. Obviously.
I have a grounding on the security side that helps provide a lot of the context and being, you know working in a number of different dead SEC Ops type motions and and you know kind of following the API security space for you since it began, right so that's given me a bit of context on there. But you know kind of how the the sausage is actually made that's that's another thing entirely right and that's exciting for me to learn. Hopefully it's exciting for you guys to learn and hopefully you're you know, picking up a few tidbits here and there from our Tech strong research review so many parting thoughts Mitch before we gonna let everybody get on with their day.
Well, I want to shamelessly plug our website Tex. com because all our reports are free. There's a lot of great stuff.
We have pulse meters and things like that that will get published up there. The other thing I want to recommend apis are a great thing for security people to kind of sink their teeth into in the software world to start because it makes sense. Like it's a protocol right?
It's things that we understand but it gets you an understand about okay API microservices and containers we kind of get and you can put the pieces together and there's some really great, you know, 15 minute overview on kubernetes 10 minute overview on containers and Docker whatever, you know, you don't need to be a software expert just like we you know, shifting left is not gonna make software people's Security Experts. There's a lot of great videos though that I always recommend people take advantage of it because it's just it gives you that context and like, okay one thing that you know, you folks can try out there something that we're doing right here as well. Right?
You know, we've got a Workforce that you know may not be, you know, technically grounded to the degree that We are and and training them on, you know, kind of the coverage areas and the things that we do is a corporate imperative. So what we did is we basically have a theme every month right in every week. We Post in our you know, internal slack channels a number of resources for everybody in the company, but somebody who does sales right somebody that's managing events, you know, the our social media folks.
I mean everybody in the company has to participate in this ask questions. And by the way, everybody has the main it's a mandatory thing. You've got to ask questions in the slack Channel during the week and then at the end of the month, we actually do a Jeopardy game and that's where we're recording that today or we're playing that today in fact, and it's been great, right?
It's been great because everybody feels like, you know kind of their learning they're growing their understanding the core kind of content Concepts that drive our business and it's fun because it's a game right people can win so we get some prizes and you know that kind of thing, but I really love this idea. I mean it really Just a fantastic idea that one of our folks I think are our CEO our head of operations came up with because you get you need to have a way to really engage everybody in constant learning because if there's one thing about these areas and technology is that they are changing very rapidly and having a real mechanism to kind of force that you know learning on a weekly basis is absolutely critical, you know, and it helps the people in the know, you know, I'm often answering questions like yeah, how do you use aside which container technology to use or how you just like what APA so I'm happy to like, okay explain this in a way that I'm talking to an audience that's learning this so I have to really put my thoughts together and be clear about it. And sometimes I am sometimes like more black messages but to get there but it helps us as we communicate with with each other internally as well as externally so it's all good.
And we have our Jeopardy today and host Alan Schimmel, you know, I don't like to do anything we do he listen. He's not Alex Trebek, right? Oh, no.
Nobody is nobody. Nobody is I'm not even sure he's my mbialic. oh, yeah, you know but he's now in civil.
Yeah, there's only one Allen channel. So that is that is absolutely Well good be sure and check out our website and you mentioned the cloud container SEC Summit on October 4th. And the salt API security context matters on what the 24th October right 26th.
Thank you for that correction good chatting again with you mike always and we will see you next week for our next tech strong research review in the meantime get be safe. Enjoy yourself and learn a bit, right? com reach out to us.





