AMTD: The Final Layer of Defense episode artwork

EPISODE · Jul 31, 2023

AMTD: The Final Layer of Defense

from Info Risk Today Podcast · host InfoRiskToday.com

In this episode of CyberEd.io's podcast series "Cybersecurity Insights," Morphisec's Michael Gorelik discussed automated moving target defense - or AMTD, which is a risk-reduction strategy and preventive measure that reduces adversary success rates and provides "the final layer of defense."

Episode metadata supplied by the publisher feed · Published Jul 31, 2023

Embed this episode

NOW PLAYING

AMTD: The Final Layer of Defense

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Welcome to Cybersecurity Insights, the podcast for the CyberEd.io learning community. Our goal is to bring cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern cybersecurity world. Good day, everyone. This is Steve King.

I'm the managing director at CyberEd.io. On our episode today, I've got Michael Gorlik, who's the chief technology officer from Morfosec, which is a company that has essentially led the charge in the automated moving target defense technology space, AMTD, which partner has raved about and other analysts as well. This has become an increasingly popular and significant risk reduction strategy and preventative measure that is seriously reducing adversary success rates. So Michael will give us some background on how that came to be and give us a little look into his background as well.

So good morning, Michael. Thank you for joining us today. Thank you, Steve. It's a pleasure to be here.

Great. So why don't you tell us a little bit about your background and then a little bit more about Morfosec and how the product came to be. Thanks, Steve. So, yeah, definitely.

So as Steve mentioned, I'm the chief technology officer for Morfosec, also one of the founding members. My own experience coming from about 20 years in cybersecurity from all the different places, reverse engineering, red teaming, blue teaming, moving to business product and everything in between. Morfosec, we created Morfosec about nine years ago. Actually, tomorrow will be nine years, if I'm not wrong.

And the idea was basically something that we worked on in the university with some of the founder members. And it's originated on technology that we presented and some of the army units were using manually. And what we've done is basically commercialize, automatize the concept of moving target defense to the industry. And starting from then, today we have around 9 million endpoints protected by Morfosec, around 5,000 businesses that we are protecting.

We see around 3,000 attacks per day that are breaking through the EDRs and EPPs. And we definitely I'm sure we will talk about the technology very soon. Yeah, sure. Maybe we can start with, you know, defining the problem that Morfosec solves and the kind of companies that you solve it for.

Yeah, that's a good question. So overall, as you know, the evolution as well as you see in the Gartner, the evolution of security stack, the progress over time, we also remember the AV antivirus and then which progress to the next generation antivirus, which led to the EPP solution that today becoming the R and the next DR. What do they have in common? In common, they have that they need the prior knowledge, right?

They need at least those first attacks happening on the targets to learn about them, whether signatures or patterns. Essentially, they didn't change for years with regard to protection. And there was at the time, I think, five years ago, six years ago, some kind of assumption that prevention is not possible. So let's invest into response.

And this is how EDR came to be as well. The problem with that, that you see all those breaches that you feel today and there are many examples with the Log4J and the recent Movit exploitations and all those ransomware that you see all the time. In most of those cases, you had one of the leading EDRs. I will not name them, obviously, but be sure that the EDR becomes the standard.

Why does it happen? Because they are predictable. The attack surface is predictable. The security stack is predictable, doesn't change a lot.

And the time to execute an attack becomes shorter and shorter. If at the time there was it took attackers to develop a new exploit for a vulnerability for weeks or months, it becomes days. And with the new AI, generative AI, it will take hours and even minutes. How do you fight with that constantly changing landscape with a constantly not changing security stack?

So this is what we came to be. We had to change this equation, right? Because the problem exists there. They cannot fight during those first couple of weeks, new threats, unknown previously unknown threats.

They have to hit someone. This someone is a target. And those someone are more and more. Yeah, no kidding.

And, you know, the advantages on the other side, right? I mean, it's so much easier to find out, to discover what, you know, what a company security stack looks like, what you know what products are part of that mix than it is to find out what an adversary's attack vector is all about. Right. It's the most easy.

Yeah, no kidding. Except the difference is, you know, one side knows a whole lot about where the vulnerabilities are. So, you know, it's moving target defense is exactly what it sounds like, I think. Right.

Why don't you, you know, the whole idea of morphing the target in, let's call it near real time, is a really cool notion. Can you help our audience understand kind of how that works a little bit? Yeah, for sure. Yeah.

So the whole concept of moving target defense is not new. It was established by the Homeland Security 2014. Even beforehand, you had some articles by NIST in 2012. And we were doing it for the last nine years.

The concept of moving target defense is, as I mentioned, and as stated by Homeland Security, is making the target, the attack surface that you have within the organization less predictable or unpredictable in a way. And when you change that attack surface constantly, you basically make it more expensive for the attacker to find a successful attack for you. It's not foolproof. It's not that, hey, anything is bypassable today.

Today is a question of how is it expensive for the attacker, because attackers are essentially opportunistic. It's a crime organization. So they want to earn money with little investment. And this will continue for the next couple of years.

So if it becomes more expensive, they will prefer usually to move to an easier target. Right. And the whole concept of moving target defense, as we push it forward, we focus on the endpoints and endpoints for us as are any devices that you can install an agent. It could be servers.

It could be end user devices, workstations, workloads, environments, etc. But as Gardner rightfully said, moving target defense concept is required as the next evolution on top of the existing EDRs and XDR solutions all across the security stack. You need to look at your cloud protection. You need to look at your network protection.

You need to look at your container protection. And Morphex is leading and probably the most mature company at the endpoint protection, which I defined just. What do we do really when we are talking about changing that attack surface constantly? Think about changing, hey, changing the concept of structures of credentials, right?

You are trying to steal credentials from home, but the attacker doesn't know where is the database of credentials. It's moved, it's constantly moved and randomized. Now, Gardner also states rightfully, and this is what we implemented, that the automated moving target defense is constructed of two concepts. One is changing and moving the attack surface.

The other one is deception, which plays a significant role because changing and moving that attack surface is great, but it's not necessarily providing you any threat intelligence or you can learn something from the attack. The attack just fails because it doesn't change anything. You have to have deception to basically give the attackers the option, the ability to find your own controlled resources. So a real moving target defense is composed of those two concepts.

So if we are going back to the examples of credentials, for example, then it's changing the structures where those are located, but at the same time exposing pixel, not real credentials in the same way doing things in memory and coping with the threats of defensive invasion, in memory invasion, credential theft, supply chain, et cetera. There are many attack vectors you can find and provide a real prevention to the existing detection stack, which is also required. Yeah. And in the process, do you acquire and store any information about the profile of the attacker?

In other words, you know, do you build your own sort of intel database so that it adds to, you know, the behavior or the known signature population at all? So that's a good question. And one of the biggest advantages and the more interesting advantages, because we prevent the attack at the very early stage before any traces have been raised or erased, right, or deleted, we do have an access to a very particular, interesting threat intelligence that others don't. And as a kind of work with the community and society, we even share some of those threat intelligence with the cyber threat allies and some vendors today to help them fight against this threat and update their mechanisms to delete the signatures.

We obviously have those the earliest possible. We prevent those attacks. But definitely the threat intelligence is one of the results that we get a side of this thing, preventing the attacks. Additional advantages are operational ones, which we can discuss, which are.

Yeah, sure. But you don't compete with, you know, traditional EDR, XDR solutions here. You're going to be a net add to those detection solutions as well. Right.

And I assume that any deception solutions, at least that I'm aware of, you don't compete with those either because they don't provide the breadth of use case that you provide. Is that correct? It is correct. Exactly as the evolution of EDR became from AV and then, you know, AV is important to have on every endpoint and then detection and response and audit are important to have on top of AV.

Moving target defense is important to have on top of EDR is additional preventative layer. Right. So we do not compete. 99% of our customers and I'll throw that threat actors leverage generative AI more and more to easily deliver a malware to the end site, to the target, to easily confiscate and change their threat.

So the obvious expectations that you would have the same kind of protection on your side once they change the targets, right, system. And we are doing it for the last nine years, so people that are protected with MorpheusSec in a way are much more protected to cope with this new and very, very scary threat. Yeah, I had a question about your work with the U.S. government, if you're able to answer it.

I know that, you know, the Pentagon is fond of referring to offensive security as active cyber defense, which I guess is the acceptable language around going on offense. And you have an ability to do that over what many other products would be able to do just because you're out there on the edge. Is there a use case for kind of a more aggressive offensive security position for your company? I would be very careful with that respect, though we work a lot with the FBI and the authorities.

Every time we intercept very interesting things or do an incident, we help the authorities to stop many bad guys and provide evidence in the court of law. But offensive by itself is a big thing. It's targeting people or organizations. We're not targeting them.

We are really a defensive technology. Yes, we provide a very sophisticated, proactive measures as a part of the defense, but we are not doing any offensive operations. And this is a different, more, let's say, more risky place to be for a startup or a company. There are definitely some Israeli companies in that area.

Yeah, no, of course. But just sort of philosophically, maybe I'm curious about if AlienVault, let's see, if I take a 5000 foot view and I just sort of dropped in from the general population and looked at all this stuff and I would say, you know, Movit has already affected over, what, 130 companies. And that's just within a week and a half of folks, you know, either discovering or revealing that they were part of that attack. But it would seem to me, again, my fictional person that's just dropped in, that if you were an early attack victim in the Movit attack and you had a way to say, hey, this is happening to the other, whatever it is, 18,000 customers that and you could do that in close to real time, that you'd have a much better shot at deflecting, preventing, however you want to determine it.

A lot of these attacks that end up being super successful. Now, maybe we're simply witnessing the evidence of attack and not the actual attack itself, which could have happened months ago. But, you know, I don't know how we're, I guess. So what's the question?

I guess the question is, I don't know how we're going to stop this stuff until we kind of collaborate as a group of targets to figure out how to go on offense about these guys. And I mean, what's your view of that? Yeah, so ultimately, collaborations and sharing definitely would help. Unfortunately, you know, based on many years of experience, it's not necessarily working.

We definitely have some alliances that we are part of them that try to collaborate and we definitely stop some of those. Obviously, as I mentioned, having MorpheusSec, for example, on the target defense on those environments with Movit or other exploits will help you to prevent it earlier and prevent the damage without having any signatures from known patterns beforehand and obviously share this information forward to help other organizations as well. But this is a really big, big thing that you're raising and it's a problem which may even require, you know, governmental regulations in a way because without enforcement of regulations, we will not be unfortunate. It doesn't matter how much I want the private sector is limited with how much they share with each other.

Yeah, I understand why they won't share. And we've been talking about it for decades now, it seems, but it never that never happens. And I can understand why that never happens. On the other hand, you know, if, you know, MorpheusSec could go to SolarWinds, let's say, or to Sera or Progress, which owns Movit, and say, hey, you know, you need to install this on all your customers' platforms, enterprise systems.

And in order to prevent another attack like this, and I mean, you know, obviously it should have been done like six months ago, but there are lots of, you know, third-party, open source, third-party vulnerabilities out there, lots of open source supply chain vulnerabilities out there. And it seems to me that if you just identified all those and say, you guys have to become customers, the only way you're going to stop the kind of attacks that we've seen. I mean, that I would love that to happen. Well, I know you've got a channel sales strategy.

We talked about that before. Maybe, maybe you can talk a little bit about that. But, you know, I, having, you know, with a company that's got 5,000 customers, 9 million endpoints, and, you know, looks at 30,000 plus attacks every day, you would think I would have heard of you guys earlier, but I haven't, you know, so my bad. But nonetheless, yeah, and I know you've got big name clients, Lenovo and Motorola to Green, et cetera.

Yeah, yeah, yeah. We have a couple of those big names that we are not allowed to share. Some of the 500 fortune companies and even more. Definitely, you know, and getting to those numbers is obviously a strategy of OEM partnerships, reselling partnerships, MSP and MSP partnerships, and also direct as well.

And you're right. I mean, not many are hearing about us. We are not doing as much noise as we would definitely want, but we are quietly providing this additional layer because essentially we are not competing with those solutions. You know, we're not competing with the CrowdStrike or the Sentinel Ones or the Microsofts.

We are there to protect you as a kind of the last layer of defense. And we find out that many mid-sized and enterprises definitely understand this gap. More of a more enterprises or kind of on a bigger side, mid-sized customers, they understand the gap. But I do find that the smaller customers, SMBs ones, they are rightfully going to the consolidation and they hardly understand what is the VR about.

And they are the ones to eventually make the noise. And yeah, there is a problem. They still don't understand the gap, but the gap exists everywhere. Yeah, it certainly does.

And by the way, you just said the magic words from a marketing point of view. You should tell your CMO your new tagline should be last line of defense. That's very compelling. You know, if you're a CISO or you're worried about all this stuff, and by the way, the stack is so deep, so high and so complex now that, you know, nobody knows what to do.

Right. Frankly, I mean, that's if I interviewed 20 CISOs, 18 of them would say I have no idea what else to do here. You know, I don't know where to go. I don't know how to stop this stuff.

I'm a victim of, you know, fill in the blank. And we never saw that coming. But we spent, you know, whatever it is, $6 million a year on software and other defensive stuff. And we get hammered.

Right. I mean, so and we've got a layered defense. You know, it's great. Well, you don't have the final layer.

Right. And that's what you guys, you guys are. And that's how you should go to market in my head. And you know what?

You know what? We do definitely provide this final layer of defense for the developers for the last nine years. So this is what is installed everywhere. But we do also understand the problems that the CISOs have today.

You know, having all those bunch of solutions right now while they just need to understand what is the risk, exposure risk of my organization right now and how do I reduce the risk? This is their questions. With that question, they come to the budgeting and their board and their CEO. Right.

And we understand that question. So we decided to expand our solution, not only provide the protection, but also the visibility to the risk. So very soon, though it's already running on many of our customers, we will officially be also presenting a larger exposure type of platform, threat exposure management, in which we also provide the solution, but also show you the problem. This will resonate with the stakeholders, the money holders, if you want, if you call them that way, and definitely provide you also visibility to your risk all across your endpoint.

Yeah, that makes sense for sure. And I'm anxious to see you do that. Last question. I'm conscious of our clock here.

But I just noticed that the, I think the research team at Resilient had audited some number of GitHub instances and found that 30,000 of them contained ChatGPT code and instances of access to OpenAI LLM, which of course, you know, creates an enormous, and we talk about visibility, right? An enormous security exposure here. And that's, you know, I mean, we're talking, what's it been? You know, like five months since that product was actually released.

So it's a, what are you, how are we going to defend against that in the future? Yeah, it's a good question. And by the way, so that you know, the Resilient folks, the guys there, we were sitting back to back, the same place, same investors, uh, and creating our companies. I know them personally.

They're great guys doing great work and they definitely show and prove

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on July 31, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!