Mapping the Unseen Vulnerabilities of Zombie APIs episode artwork

EPISODE · Dec 5, 2023

Mapping the Unseen Vulnerabilities of Zombie APIs

from Info Risk Today Podcast · host InfoRiskToday.com

Zombie APIs are becoming more common, just because of the sheer number APIs and third-party vendors that organizations rely on. Joshua Scott, head of information security and IT at API platform Postman, says businesses need to identify "what is critical to the business and map backward."

Episode metadata supplied by the publisher feed · Published Dec 5, 2023

Embed this episode

NOW PLAYING

Mapping the Unseen Vulnerabilities of Zombie APIs

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Welcome to Cybersecurity Insights, the podcast for the CyberEd.io learning community. Our goal is to bring Cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern Cybersecurity world. Good day, everyone. This is Steve King.

I'm the managing director here at CyberEd.io and with us today on our podcast episode is Josh Scott. He's the head of IT and security at Postman, which is a billion dollar plus company that focuses on API management. Josh is also a member of the SBCI, which is that venture fund for cyber security investments by CISOs, and I know several folks that are members of that little club, and it's pretty cool. In addition to that, Josh spent 13 years as a CISO and IT director at Reelser.com in prior service, and his background leading up to that was service as a hands-on security architect and network engineer.

So Josh tells you what's going on, it's probably what's going on. Welcome, Josh. I look forward to our chat. All right.

Thanks, Steve. Pleasure to be on here and thanks for the warm welcome. Sure. In honor of either Cyber Security Awareness Month or Halloween, I guess, whichever you prefer, let's talk about zombie APIs.

For the folks in our audience who don't know what a zombie API is, Josh, could you kind of describe or define that for them? Sure. Ultimately, a zombie API is an API you thought was gone or deprecated, but yet it's still out there. It's something I've run across many times throughout my career is, you know, we thought we turned that off or that service was disabled, but it's still there.

It's still running. It's still serving up, you know, something within the business, and generally it's not secure. Yeah. And how do they end up like that?

Is that all kind of going too fast in the human error, or is there another way for them to sort of conge a lot? I mean, I think it's a combination of things. One of them is just, you know, the pace we move within technology, you know, new APIs are introduced regularly. Obviously, everything is, you know, moving towards APIs first and APIs are kind of the core of everything we do.

So they get forgotten about or they don't understand kind of the entire API landscape or a state that they actually have could be any number of things. Not to mention all the different vendors and third parties that you integrate that you may rely on. So it can come up in so many different ways. Yeah.

It represents a significant threat, doesn't it? One of the sort of top two or three threat vectors that sort of emanate from these little guys that are wandering around our networks. I mean, the first thing is, you know, number one, you don't know about it, right? So you may not understand what business processes or, you know, items are tied to it.

And generally, if they are forgotten about, they may not have, you know, the right security controls. They may be missing authentication. I've been in organizations where we had, you know, APIs on the back end where they had no authentication and it was something used for critical services, you know, and they were only discovered through crawling the website. So I think authentication or the lack of authentication is a big deal.

I think the fact that you don't know about them, you know, and not knowing what business process is tied to it. And things like, you know, the right logging or, you know, any kind of access checks and all that. Yeah. And I mean, that's, that's true of brand new APIs.

Yeah. Exactly. Yeah. And so it's a, you know, it's a whole world is a rapidly growing problem.

And I, you know, from my point of view, the lack of, shall I say, collegiate relationship within DevSecOps and security operational folks or DevOps and security operational folks seems to be to me part of the, part of the reason behind why we end up with so much of this. Is that a fair statement? I think that's part of it. I also think it's just, you know, because there are so many different teams that may be contributed.

It's not just necessarily development teams, but as we're seeing an explosion of even some of the, you know, lines of business or functional areas, also either having an API that's related to part of the business, whether it's VisOps or some other function, there's an explosion of APIs everywhere. And just having better relationships with the business to have a better understanding of, you know, what is critical? What are we using? I mean, even Tory in general, you know, knowing what you have, you know, you can't secure what you don't know about.

And that's always been kind of the bane of security. We never know about everything that's out there. There's always that whole set of, you know, unknown unknowns and that's the challenge we're going to cross with APIs. Yeah.

I've had read somewhere that I think that, um, well, percent of the code that we, or that code that gets generated, maybe I'm reversing them, maybe it's 98% or something that gets generated as largely, as large as APIs and, you know, I think back on shadow IT problems of, you know, a century ago, can you imagine what the impact of, you will have to deal with the impact of generative AI throughout your organization or your customer's organization, say, uh, who are out there doing, you know, got only knows what and sprawling APIs left and right, right? Yeah. I think that's an interesting point about just the generative AI, every single tool, every single platform, everything is adding that kind of capability today. And everybody's trying to capitalize on that from a product standpoint.

So, you know, we're doing the same year postman, right? And it's just, that means more APIs, more integrations and a lot of kind of R&D and, you know, how do we quickly get this up and running? And that's, that's kind of what's happening now is, all right, we got to get something up and running as quickly as possible, um, see what it, you know, value provides and then let's quickly move to the next thing, which means, you know, the first one that we created me may actually get forgotten about, it may end up becoming a zombie, but yet it's being used by, you know, 2% of the environment. Another report I saw recently said that a very small percentage of single digits of companies had, had issued any sort of policy around the use of chat GPT, for example, and, and to what you, to your point, you just made with all of that, you know, technology leveraging pressure, uh, around product and around, you know, improved service or, or, or extending your family, uh, very easily to additional services.

You've got people on sort of both sides of, uh, red line and the sand fighting with each other over cybersecurity, you know, I mean, how does that, how's this going to end? That's, that's a really good question. I think that that's the toughest thing we're trying to figure out from a security standpoint that as a CISO is trying to find, you know, better, better ties to the business, trying to get a better understanding of, you know, what we're working on becoming an enabler to the business, you know, historically security is kind of not always been the easiest to work with for various for a variety of reasons, but we've got to become more of an enabler of the business and have a better understanding about strategies and why we're leveraging these different types of technologies so that things don't get forgotten about so that we don't miss certain items. Like we can stay in line with what we're going to do instead of two steps back, which is where we've been historically.

Yeah. No way. I'm going to ask you a question that might be a little off the wall, but given that you've run IT and given that you've run security now, if you look at just personally, if you look at the, you know, hierarchical organization dynamics within a corporation, do you believe that the CISO, uh, should not report to the CIO or the top, uh, IT guy or person or, uh, or are you, uh, of the mind that the IT person has ultimate responsibility for the security of the information? That's, that's a good question.

It's a tough one to it. So I think it really depends on the organization. Every business is a unique, uh, you know, animal, you can't tell you whatever you want to call it, but I think where security lives and who it reports to and whether it's IT or, or somewhere or, you know, CIO roles, it really depends on, you know, the importance of security and the role of that individual and whether they're empowered. So ultimately, you know, the question comes up a lot of times too about, you know, where should security live and, you know, just a report to the CEO or the CTO and to be honest, I personally don't really care.

To me, if I'm empowered and I've got the right authority to do my job, it doesn't really matter where I report. As long as I have the necessary exposure, I think the same thing applies with, you know, both the IT relationship and all that. It's what makes sense for the organization and I think both work. Yeah, it's just seems to me that if you're running IT and you want to be held accountable for the outcomes, you would, security can't report anywhere else.

It seems to me, uh, it's kind of like, you know, saying you're running IT, but the data center operations are reporting into somebody else. It's kind of like, well, then how do I have any controller that's already over the, the, the wheels that make this thing move? Yeah. I mean, I think that's a fair point, right?

Having accountability and responsibility for those assets, services, functions that, you know, directly contribute to whatever you're responsible for, right? So from a cyber standpoint, this is a, you know, owning IT now for the past three years from a postman standpoint has been extremely beneficial because we've been able to move fast and take action. Whereas in previous roles, you know, there was a bit of an adversarial relationship at times, but it's more about the relationship than when both parties aren't, or what functions aren't owned by the same person than it's more about the relationship, like when it's owned by the same person, they just more about just getting things done, I guess. Yeah, sure.

And that's true of so many things, but definitely here. And I used to be over the mindset, having, you know, being a recovering CZO myself, that the CZO, you know, should report to the CEO or the board, which is, I think, a largely ego-driven or narcissistic or something, because when you, as you just said, when you examine the realities of accountability, it really does belong in information, information services, just another functional operation within that, within that scope of authority, it seems to be. Yeah. What are we?

So, zombie APIs are wandering around the network, and I think they fall into the technical depth category, and we have a lot of technical depth. What's the best way to blend, if you will, or make sure that you have both observability and visibility into the problem space so that you can eliminate the source of, or the threat itself? Yeah. So, I don't know that you can necessarily eliminate it.

I think what you can do is, you know, put in certain types of processes and measures to reduce the associated risk. So, for example, you know, things like attack service management have a better understanding of what's, what services you actually have, you know, that are visible, tying into the build pipeline, for example, and getting a better understanding of what's actually being released on a regular basis, and then just forming those relationships with the key stakeholders across the organization to, you know, get into their process to have a better understanding of what are they releasing, what's that rely on, and then really the company has to commit to, you know, maintaining these inventory items somewhere so that they can, you know, keep on top of it. That's probably the biggest challenge. It's something I've faced for, you know, the entire part of my career, you know, within any role is, there's never a clean inventory.

You never know about everything that's out there. There's always some news. You're an old network guy, if you don't mind framing it that way, and so are you of the opinion that as long as we continue to go down the path that we're on now, which is, you know, sort of layering in change to a network that was designed, let's say, 25 years ago versus ripping it and replacing it, that we're giving cybersecurity threat a whole sale advantage and that we'll never be able to get out from under. Yeah.

That's an interesting one. I mean, I'd love to rip and replace plenty of networks and environments that I've been a part of. The reality is it's just, it's so difficult and, you know, given the number of things that security teams are actually trying to tackle, like, all right, do we really need an architecture, you know, a redesign as much as I'd love it. In some cases, it's just not feasible.

So it's, I think the problem is going to persist because we're always, you know, from a security standpoint, we're always going to be, you know, five to 10% of the total employees that are being involved within, compared to what there is in engineering and other functions, right? So they're always going to be doing a lot more. So, yeah, I think the problem is going to continue to, to get worse or more challenging unless, like I said, you know, getting a handle on it, finding, you know, talking to those key stakeholders and then really working backwards, like finding one of those key areas that present risk to the organization, the key assets that you have, and then, you know, looking at all the different types of connections and processes and APIs and all that that leverage it and then knowing that these are the things I want to protect, these are my machine critical services, processes, assets, and then everything that's connected to that. And then from there, you know, there's going to be other things that, you know, we may not know about or that don't get discovered initially, and then to a certain extent, it's almost like an acceptable risk, unfortunately, because you got to protect the board of the business and we can't protect everything.

Yeah. If you had to do it all over again, I doubt you would decide on the network you've had right now. No, definitely not. I think there's definitely room for a kind of a re-imagining of how we do it.

You know, in previous companies that worked out, we always had a data center and offices which are connected up to, you know, kind of a, you know, an MPLS network and private networks and all that. I think the new way of doing things is at least kind of what, you know, cloud native companies that don't really have that. You know, we may think our offices is they're not connected to any of our cloud assets, you know, they're not connected to our AWS environment. So we're already starting to re-imagine that with kind of cloud native companies, but I think we can take it a step further saying how do we create these, you know, sort of like zero trust exist that you know that they don't have the access and there's better controls into what is important into the critical assets.

Yeah. It seems to me that kind of unless we, when you say not feasible, I am assuming you mean it's not feasible because of a resource constraint or budget constraints, it's certainly feasible technologically. Correct. And if I said to you, you don't have to do anything for the next six months, but go build a parallel network in using modern technology and architecture, you can go do that, right?

Absolutely. Yeah. And when you kind of look at the paradigm of people process technology, the technology stuff is, you know, relatively easy compared to like the challenges with process and getting people to adopt those new processes and those new technologies. So it's going to come down to ages, resources and be getting people to actually adopt those new resources in that new way.

Well, I think that, and this is not a shameless plug for cyber ed, but one of the things that we've found that is working really well is, is avatar driven course delivery. So if you look at a security plus or network plus or what have you, you look at it, you know, 28, 29 hours, whereas of course work that is, you know, turns out to be 67 course individual course. All of those are currently delivered by, you know, prerecorded actors, you know, quote experts quote in the field. And when you when you fold those rips down and look at them, more than half of that time is spent in, you know, what's supposed to be humorous interactions, it's supposed to be, you know, customer engaging, but when in fact it's just kind of a stupid eight year old boy humor.

If you eliminate it, if you pull all that stuff out and you hand it over to an avatar on the avatar delivers that course where it's not only more efficient, but it's also updateable and re-render and then I can re-render that particular avatar in less than an hour if I've got a new thread or a new technology that obviates a need for something that, you know, was three years old. And these things stay down level because the companies that produce them don't want to spend the money to bring them current. So then you wonder, well, what good is the security plus certification if it was developed in 2018? Yeah.

Same. The reason why I mentioned that is I'm going to ask you, don't you think that we could convert a lot of what we do now and make mistakes doing and let's say, engineer configurations, like configurations, just a pick two, for example, or alert analysis in the SOC, if we convert those to, you know, to generative AI bots or however you want to characterize it. I think there's definitely potential in that area. That's actually something that we've been exploring quite a bit of just, you know, how do you leverage generative AI LMs within, you know, nutritional security operational spaces and even with an app sector, you know, to do the security review process and make it easier.

I think there's definitely potential for that so that we can get out of, you know, kind of the mundane of doing, you know, the typical security operational or just operational work within security, right? Not just tech ops, but, you know, everybody has an operational component. I think there's a lot of potential there. I think there's a lot of potential for it not working as well either, right?

So I, you know, leverage the chat to be declared a bit and you ask a question and sometimes, what do you get back? You're like, wait, that doesn't sound right. And so that kind of concerns me on, you know, when we start using this in more critical functions, I analyze this alert and it comes back and says, you know, yeah, this alert's fine or there's nothing, you know, no risk here, but there really was. So I think it's just that combination of, you know, the human element and training it and providing better, you know, feedback mechanisms along with the generative side of it.

And also, you know, I think what you may have been asking to do was more about, you know, how do we leverage that for training? You know, how do we leverage it? I actually do security awareness and to do very kind of point specific role specific, you know, material that's relative to the new threats that are, you know, that are coming out and the new types of technology we're facing. I think that's an interesting idea too.

Yeah, it is. And the other amazing thing about these things is that they can do it in eight different languages today. So it was perfect lip sync, believe it or not, right? So that's pretty cool.

It is very cool. I can see that being, you know, extremely useful because I think, you know, at the end of the day, people are the greatest asset we have and they're, you know, one of the strongest controls we have from security. So the more we can actually invest in them, you know, security is a shared responsibility. So if we can upscale somebody's folks to the point where just what they need to know, like we don't need to train everybody on every single security topic with a security team, but even the rest of the business, we need them to do their jobs and do them well, you know, with proper guardrails.

But how can we enable them? And I think generally, I may also have a role in that too. Yeah. And historically, you know, the corporation, you know, Sally in accounting or what have you Bob in receivables looks at security is the separate thing.

And what we live in a totally digital world now, right? So security shouldn't be some separate thing that even though we have to learn should be part of our jobs, not insane. Oh, absolutely. I mean, security is a business problem.

It's not a technology problem. It's not, you know, it's not related to part of one specific domain. It's literally across every single aspect of it, of the business. So finances, items, HR, marketing, everybody has a security responsibility, but not putting too much on their plate, right?

So I think having that healthy dynamic between, you know, their teams and having, and whether it's security people or security knowledgeable people, security ambassadors, champions, whatever you want to call them that live within each of those teams that, you know, the security team spends time with those individuals to kind of, you know, upscale them to a certain extent. Yeah. Yeah. Yeah.

That worked in the last 10 years, but never one, it's boring. I mean, I've gone through plenty of it and I read this stuff and I'm like, all right, this is tough to watch, right? I've seen some of the more humorous videos and, you know, we used to, we bought a tool at my last place that had these, you know, funny videos that were actually pretty, pretty helpful. But even then the material still wasn't as relevant.

I think that's the, the other thing about most security awareness content is it's very generic in scope. So having it more kind of company branded company tied, having, even having speakers or, you know, the videos done by somebody you recognize from the company would probably help a little bit. And I think also, you know, I perfect example is like fishing, right? You know, we, we, we crammed down all the kind of, you know, anti-fishing and out of, that is about the fish to employees.

But that keeps on changing, you know, so fast, right? And of course, you know, we want them to be aware and know that if you see something strange, you know, tell somebody, right? I think that's a good thing to get across them. But teaching them all the different ways is just like, we need them to focus on their jobs, right?

So how do we put in better measures, better technologies? I mean, you know, that's one area where I would push back on the technology vision and say, why can't you do a better job? If a human could spot this pretty quickly, why can't the technology actually spot this? Yeah.

Yeah. That's a good point for sure. So one final question, if you don't mind, do you have any sort of final thoughts about ways to avoid the zombie API problem going forward? I'd say the biggest thing is, you know, making sure that you identify what's critical to the business so that you can then start mapping backwards on what's, you know, what are the connections and see if you can actually find them, but also just finding a way to actually get inventory of any kind of, you know, known assets, running assets from an organizational standpoint, can't just be a security thing to solve.

It's got to be an organizational item to solve. It says zombie API is not just a security, but it's also an operational maintenance cost issue, right? So you've forgotten about it. It's incurring a tone of, you know, cost that's also an issue for the company, right?

So committing to actually tracking all the different assets, having kind of a life cycle of anything that you're using, right? You know, here's when it got put in place and you know what, we're going to review things or, you know, have some form of attestation on a rate of basis. I think combined, you know, security, IT, you know, engineering the business, committing to that could actually be a big help and then just, you know, continually scanning the environments or finding ways to discover those ones that developer and, you know, that forgot about it just quickly put something in. You know, he's not going to add it to inventory either.

So you've got to have kind of secondary controls to go discover. Yeah. I should have rephrase that question to ask, you know, that's what I'm asking, is there a continuous automated process that people can put in place that will take care of this issue all by itself or does it still have to be kind of a manual audit every on some frequency? I mean, there are, so I've seen some interesting tools, you know, the tech service management, some of the newer like inventory style tools that can help you discover.

But those are, you know, going to be more from an external standpoint. I know that there's components from an insight, you know, from an internal standpoint that can do that same level of discovery in my experience so far, you know, it still misses a lot. So I think it's a combination of, you know, tools like that to populate some kind of inventory and then, you know, some kind of process or understanding that, you know, as a release is going out, as the code is being reviewed, finding those endpoints and I think it's more modern architectures. You know, we're going to get to the point where, you know, kind of integration CI is separate from delivery and delivery would have that understanding of, you know, what is the environment where is everything living and kind of tying into those systems to get that disability.

Yeah. You know, sir, what's Windows now? 150 million lines are covered? Oh, yeah, I know.

I know. Crazy. Yeah. That's a challenge to do, right?

You know, there's just, we're not going to see less code. We're going to see less code that we own, right? Yeah. Everything is a mashup nowadays, right?

Or whatever the number is, right? You know, 80% somebody else's code, 20% your code and your code is just blue between somebody else's code. So it's going to be, but we're not going to see a decrease. We're not going to see it increase.

We are. Well, I'm glad you're doing it. And I'm not. Yeah.

Thanks. Sure. Well, listen, Josh, it's been great talking with you. Thanks for all of the wisdom around the zombie AI issue.

It's a big one. And I wish companies would start to take the series. So I'm getting tired of talking about it myself, but yeah, but, but perhaps they will and all we can do is continue to, you know, push this boulder up the hill. So yeah.

Yep. So again, thank you for taking the time. It was great. And thanks to our audience for spending a half an hour or so with us on this topic.

And hopefully it was informative and educational for you. And until next time, I'm your host, Steve King, signing off. Thank you for joining us for another episode of Cybersecurity Insights. You can connect with us on LinkedIn or Facebook or send us an email at social at cyber F dot IO.

For more information about the podcast, visit cyber F dot IO forward slash podcast. Until next week, stay safe and secure, and we'll see you on the next episode of Cyber Security Insights.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on December 5, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!