How Observability Leads to Better Cybersecurity

Transcription

hey Zs car from ZK research here and I'm in uh YB waya Gardens in San Francisco uh happened to be coming through and I ran into a good friend of mine Michael Dickman who's the chief product officer from gigamon uh Michael how you doing I'm doing great yourself yeah so I thought uh we would take the opportunity to sit down and have a little discussion on uh one of my favorite topics I'm sure one of yours which is uh encrypt or visibility and I guess how it pertains to security encrypted traffic are you up for that absolutely all right so uh let's Baseline kind of the problem in Security today you know um I've had a number of conversations with different security Pros uh just about the state of security I'm here if you're seeing the same thing where Cesar are telling me that they're spending more money than ever on security tools they're buying xdr SIM sores uh you know sassy and despite the increased level of spend uh they feel like they're falling behind and and the bad guys are winning how is that possible what's going on here that despite record levels of security spend companies are still being breached at record rates yeah I mean I hear the same things as well and I think a lot of it has been you know kind of the pendulum from you know more tools best of breed tools and then back to consolidation it's gone to a lot of these you know best of breed tools so you kind of take traditional endpoint security now you have EDR you take maybe traditional IDs or APS and now you have ndr and so these tools come out and they're more modern and they're great um but what we've seen is as they get deployed as kind of Point Solutions and each of them maybe has only incomplete visibility like even the best EDR system in the world will only see what it sees on a managed endpoint and it won't necessarily see more than that or the best ndr system in the world we'll only see what it happens to be sensing and I think what we're hearing from some of the breaches that are occurring is the traditional challenging vectors of humans you know like Insider threats you know misconfigurations other gaps and issues as well as the fact you have these visibility blind spots so once you have some kind of weak point any weak point there's that ability to move laterally within the organization sometimes you know using encryption against the company itself which I know we'll we probably touch on where you think like oh my gosh it's secure because it's encrypted but it actually may be an attacker using that so you got all these tools but each of them is only solving a point problem and even looking at sweets and bundles still doesn't solve that you really need to have that full I think visibility to see the the whole challenge yeah so there's there is that expression security I'm grad you brought up encryption that you can't secure what you can't see absolutely right and encrypted traffic I think um there's two schools of thought right one is well it's encrypted it's secure and the other one is well it's encrypted so I have no idea what's going on in there and it can be used as transport for malware where where do you stand on that argument yes right I think it's definitely one of these two-edged you know S two-edge Storage kind of problems where you've got you definitely don't want to be sending your important uh information and plain text out to the world like of course but to say if it someone or anyone has encrypted traffic I'm going to trust that it's secure is a terrible idea so you know I think the um statistic is 92% of all lateral movement attacks are themselves encrypted right and you have at this point encryption is now a standard you're encrypting data at rest you're encrypting data in motion but we know that there are breaches and we know that there are Bad actors you absolutely cannot trust that just because something is encrypted it is safe even while yes you Absol should use encryption to protect the confidentiality of the data and so it's really both it becomes yet yet again like many things like AI right which is a you know hot thing these days it can be used for good it can be used for bad and I think we need to make sure there's a way that we arm the good guys to overcome uh the bad guys using encryption against them yeah and the to me the real threat of encryption um is as you mentioned those lateral threats it's not you know very rarely the minute you get breached something bad happens that's right right you have that uh the threat actor make your way in the organization the traffic's en crypto so you can't see what's going on and then it spreads laterally across the organization that low slow traffic so even if you're looking at Network performance stats there's nothing out of the out of out of the out of the usual there that's right right but eventually it meanders its way around and all of a sudden you know you're breached right and uh I I think that's what companies really struggle with no I mean that's true and if you think about how someone might exfiltrate data that's getting really sophisticated you know you might fragment a file and take it out in pieces if you look at the initial um you know initial breach or compromise it might seem like something small but just like you said you kind of move and hop around the environment and all of those moves and hops are themselves encrypted and so definitely you got to look you know East West right at the lateral movement as well as north south and our our view would be that you have to be able to have that power to see PL Tex data for security purposes inside the organization and not only you know say at the firewall or at the perimeter so if the traffic is encrypted uh and visibility is important how do you uh reconcile that because how do you you can't see inside encrypto traffic how does gigamon help with that well yeah I mean fortunately there's some good Technology Innovation here right there's obviously classic decryption which can be done um but when you look at the lateral movement the scale of that traffic is very high it may you may not want to reroute that through you know kind of a middleware appliance so to speak so what do you do and there's a lot of those middleware appliances and that goes back to your first m one thing that you could do is you could say let me pretend East West is nor South and I'll put like a million Firs everywhere that may not be practical or cost effective right so how you know how can we solve this yeah a lot of companies do that though it's possible my my opinion would humbly be that that may not be the best um and so what we've done at gigamon is we use uh an ebpf based solution which means we're actually leveraging the workload itself to provide that plain text visibility without even without decrypting anything and so by by enabling the workload itself to provide a plain text copy out only to the security team and by the way we can encrypt that unencrypted data so that it is secure in transit to the security tool but by doing that you don't actually have to deal with key management or the decryption itself and you get the true security benefit which isn't decryption but it's seeing the plane text um for security purposes and so basically that's what we do so we deployed this we call this prec cryption because it's being able to uh observe into that data into that traffic before it's encrypted or after decrypted uh within the workload itself and so there's really it's very efficient there's low overhead it's easy to deploy um and you can get that benefit in a controlled manner to security yeah and so that obviates the need to deploy appliances everywhere exactly and uh uh and you mentioned firewalls but there's Network probes and there's different monitoring systems and and I and I think uh in a lot of ways companies have almost become overwhelmed with visibility tools and uh yeah you don't really get your bang for the buck on those yeah and I think what I see a lot is there's a lot of visibility tools which are which are dashboards and you know views to literally visualize the data but you know garbage in garbage out or incompleteness in incompleteness out you know more more specifically and so potentially you could have fewer uh visualization tools you have to have that right Telemetry um and so one thing that we we talk about at gigamon is you know that observability Trend everyone talks about that both security and otherwise and how do you get the depth of network intelligence into observability so it's not only what logs might be telling you or other things but what is actually happening and that applies to encrypted traffic and so having a more complete uh Telemetry pipeline data view you could then potentially have fewer kind of end tools and the swivel chair and the cost and all those other issues that you talked about yeah and from what I understand too the other benefit you bring is you can normalize some of the traffic there different the different tools they pull at different intervals they collect different information and uh you mentioned the swivel chair management style it's really up to the security operations team to figure out how to connect those dots correct yeah today that's right and so yeah what we you know kind of what you're probably alluding to is we can D duplicate which improves signal to noise as well as helps with cost we can curate the data so you can only take a subset to certain tools and we can ourselves extract metadata which would say actually I don't want to see everything but I want to know who or what or where and pull out some of that metadata that I can I can do that in a curated fashion and like you said it's all normalized because Network traffic in many ways is the a natural normalization method and then if you get that from all your different environments private Cloud public Cloud physical whatever um you can bring that all together in a really useful way yeah and so talk about the uh uh the impact that hybrid hybrid Cloud brings because I am sensing in the cloud industry there is a shift going on now where more and more companies are starting to repatriate their data back um all the cloud providers now have Edge Solutions as well and so this Vision that we've had for a while of hybrid multicloud is actually becoming real yeah right and um but that brings up its own visibility challenges correct oh absolutely yeah cuz what you what you get and what again we see with customers today is there there's a desire to use the native Tools in each platform which makes a lot of sense because they're easy to turn on but then you get this challenge where you have new silos so we talked about silos of tools or domains you could have silos of infrastructure so you can be like I get this data from AWS and some different data from Azure and some other data from VMware and some different data from physical versus having that consistent view that you can see all together so we think that's that's absolutely critical and then the other challenge with some of the environments is you can't actually see the data in the first place so sometimes it's just feasibility and in all cases it's efficiency and completeness and so the way you handle that that data um how do you how does that affect company's compliance and and privacy uh mandates yes it's a good question right cuz you know whenever you're looking at Gathering data or things like decryption it's it's a natural question um the first is it can help compliance because you can actually prove and guarantee that you are logging what you're required to do so there's a lot of US Federal Regulations right now about increased logging and visibility and so you can actually achieve compliance through these Solutions but then the other side is yes to be um very aware of when might there be personally identifiable information things like gdpr knowing the DAT of residency and so on and having that complete view actually lets you satisfy that we definitely do see though cases where a customer will want to selectively look at PL Tex data so they might say I only want to decrypt this or with the prec cryption that I talked about I only want to look at this kind of a workload and we enable that full flexibility and power so you can choose based on risk compliance privacy all your considerations what you want to see but really now the power is up to the customer versus you know the technical challenges which would otherwise be there you know and uh I think the other one of the other big Topics in Security today is uh Ai and that requires doing a lot of analytics on a lot of data and um encrypted traffic I think companies would have a hard time um using that as part of their data set do you do you help with that as well I mean definitely yeah that's that's a big thing I think with with AI um which is obviously the big trend for everyone now but you think about the fundamentals of AI is machine learning identifying Trends and patterns and then you build up on top of that with all the llms and so on but if you're not getting at the ground level a complete view by definition you're not going to catch the trends I mean just to give a simplistic example if you only ever saw data from managed endpoints you would by definition never see a threat or anomaly from an iot device right yeah you just I mean you wouldn't see it and so to have that completeness is absolutely essential and there's so many AI tools now and so many models and so many llms The Innovation is amazing but it has to be built on a solid foundation and so yeah going back to your direct question the plane text is necessary because otherwise it's just you know it's just kind of a mess uh with garbage that can come into the uh AI tools and they really can do heris and some things uh that they can try but that's not going to keep ahead of the bad guys they really need to see the full um the full payload of what's actually being transmitted versus guess yeah you know there's an expression in data sciences that says good data leads to good insights oh and uh but silos of data will actually lead to fragmented insights and I think that's what companies have today is a lot of silos of data right I agree yes and and as I mentioned earlier sometimes even those silos of are incomplete within the Silo and so you get these kind of layers of Challenge and yeah definitely our our mission as gigamon is to bring a lot of ease and simplicity to solving that complex problem you know understanding the environments understanding the data giving those tools uh so that the security teams can do what they do best which is hunt down threats set policies Drive compliance you know protect protect the Enterprise and you and uh again correct if I'm wrong but gigamon can actually bring visibility to devices like you mentioned iot devices where historically you would just have no visibility because there's no way to put agents on those things there even putting probes on them it can be difficult uh they don't generate any net flow data yeah right and so those devices historically companies were blind to that's exactly right cu the only way you know they're there um other than kind of layer one things like power or something the only way you know they're there exactly is to see when they communicate when they actually speak on the network and that is something that you can use your gigamon infrastructure to then feed in again in that normalized consistent way into all of your favorite tools for you know asset inventory on the simple side to threat detection and AI based you know Intelligence on the more sophisticated side all right uh one other the trend I wanted to touch on was this concept of observability uh when I talk to in fact if you look across the industry there's been a come together of observability and security I know observability has been a big part of gamon's mission in fact uh gigamon has been using the term deep observability you know for a number of years now so can you talk about the differences first of all the importance of observability and then the differences between observability and deep observability no absolutely one of the things that I like about the term observability is it comes from a philosophical place of being able to see everything without imposing change on the infrastructure of the workload and I I at least for me that's the difference between observability and visibility and so when we see that observability and security coming together the devices and applications naturally produce log which is basically most of the observability industry today is let's look at those logs and what we can do with gigamon is we and what we mean by deep observability is to bring the depth of what the devices and applications and services and assets are actually doing what are they actually communicating and that is a depth you can only get from Network intelligence and so when you see not only say a a router um you know saying here is a report on the traffic I've transmitted but you actually see the traffic you can now go deep into who who communicated with whom how long did it take what was shared and if you want you could even go into the payloads themselves and that level of depth you cannot get with traditional observability approaches which are very useful and important especially for um application performance and those use cases but uh for security you need that depth of seeing what is actually being communicated and that is something we believe that gigamon to uniquely provide through nwork intell so it's a good way to think about this that traditional observability tools give you the what but you're adding the who the where and the how yes yeah and even more what yeah and even more what okay absolutely yeah when that helps you iner the why that's right right which is really going back to your point earlier around you know good data leads to good insights we would say deep deep data leads to deep insights well that makes sense so okay good well that was a a great discussion and finally I'm super glad you were able to try boba in San Francisco I think this is an important you know it's interesting we uh decided to get a couple bobas and I confessed to Michael I'd never actually tried a boba before so I didn't know what they things were they're delicious the giant straw can can be surprising but yeah and you said your big takeaway from this meeting was the fact I had never tried Bas before although now I have more but so thank all right Michael uh so on behalf of Michael Dickman the chief product officer at gigamon I'm Zs caraval from CK Richardson thanks for watching uh please hit the Subscribe button I'll see you next time on my next episode of zcast

This transcript was generated automatically from the video's captions and may contain errors.

Écrit par
Zeus Kerravala
Zeus Kerravala
Published: Jul 10, 2024
Updated: Sep 23, 2024
1 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

I spoke with Michael Dickman, Chief Product Officer at observability vendor Gigamon, about observability in the enterprise and the many challenges of network security.

Zeus Kerravala

Zeus Kerravala is an eWEEK regular contributor and the founder and principal analyst with ZK Research. He spent 10 years at Yankee Group and prior to that held a number of corporate IT positions. Kerravala is considered one of the top 10 IT analysts in the world by Apollo Research, which evaluated 3,960 technology analysts and their individual press coverage metrics.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.