Glasswing: Mythos demands a new model for infrastructure — Transcript
Full transcript
- 0:11Hi, I'm Tom Gillis. I'm the general
- 0:13manager for infrastructure and security
- 0:15products here at Cisco. Russ?
- 0:17>> Hi, I'm Russ Smoke. I'm a vice president
- 0:20in the security and trust organization
- 0:22reporting to our chief security officer
- 0:24and I look after vulnerability
- 0:25management and offensive security for
- 0:27Cisco.
- 0:28>> So, Russ and I have been working
- 0:29together for many years.
- 0:31Um I build products, he breaks the
- 0:33products, and I must say he and his team
- 0:35quite good at it, right? And they we're
- 0:38working together for a common cause,
- 0:39which is to making sure that our
- 0:40customers has infrastructure which is
- 0:43safe, resilient, and trustworthy. And
- 0:45that matters more than ever these days
- 0:47because the whole landscape is being
- 0:50changed by the power of what we call
- 0:52frontier models, which is the new models
- 0:55uh from the major providers that is
- 0:56really really taking a step forward with
- 0:59their capabilities. As we got our hands
- 1:01on these next generation frontier
- 1:03models,
- 1:04there's been a shift in in what the
- 1:07models are capable of, what we find, and
- 1:09that shift is leading to, you know, what
- 1:11I'm going to argue is pretty significant
- 1:13changes
- 1:14in the way that we think about building,
- 1:16testing, deploying, and most importantly
- 1:18for this audience, operating
- 1:21infrastructure at scale.
- 1:23So, let's start from the beginning.
- 1:24Yeah?
- 1:25>> Russ
- 1:25>> I would absolutely agree. The the
- 1:27introduction of frontier models have
- 1:29have really changed the cybersecurity
- 1:32game from one of being, you know, very
- 1:35operationally focused, very
- 1:36conservative, and in some cases, you
- 1:38know, a lot of risk management, and in
- 1:40some cases risk averse, to one where
- 1:42we're going to have to move at machine
- 1:44speed. The the days of taking weeks and
- 1:48months to qualify software and take, you
- 1:50know, long periods of time to upgrade
- 1:51software really over.
- 1:53>> Yeah.
- 1:53>> The the adversaries are going to find
- 1:55these vulnerabilities in a matter of
- 1:56days. They're going to find exploits in
- 1:58hours.
- 1:59>> Yeah.
- 1:59>> And it's our job as defenders to enable
- 2:02our customers to go out and and protect
- 2:04themselves.
- 2:05>> Yeah, so we're kind of jumping to the
- 2:07punchline here and and I think the
- 2:08punchline for our audience is that um
- 2:11you know, I call it the summer of hell.
- 2:13It's going to be some turbulent times
- 2:16because
- 2:18every piece of software
- 2:20everywhere in the industry, like the
- 2:22thermostat on your wall has software in
- 2:24it.
- 2:25All of these software components have
- 2:28vulnerabilities that will need to be
- 2:29fixed. And so that's going to create a
- 2:30scramble of patching.
- 2:33But when we emerge through this
- 2:34turbulent summer
- 2:36I believe that we the industry can can
- 2:38be in a much better place and that we're
- 2:40going to have truly adopted
- 2:42more of a CICD philosophy, that agile,
- 2:45constantly taking lots of little steps
- 2:47to upgrade our infrastructure, which
- 2:49will make the upgrades easier. No more
- 2:51gut-wrenching, heart-stopping, like oh
- 2:53my god, I took it offline and now I
- 2:55can't get it to reboot
- 2:56type of upgrades.
- 2:58Um and we'll be more secure in the
- 3:00process, which is you know, I think
- 3:02encouraging. But Russ, let's maybe start
- 3:04from the beginning. You and your team
- 3:06have been doing, you know, red teaming
- 3:08and product testing
- 3:10for for years now and we've been using
- 3:12AI tools for a long time.
- 3:14What changed? What's what's different
- 3:17now?
- 3:17>> Sure. So you know, we certainly have
- 3:19been using AI enablement in the
- 3:21offensive security world for for several
- 3:23years. What really changed for us in the
- 3:26last last few months were two things,
- 3:28right? There were step function
- 3:30increasing increase in capability and
- 3:33quality for the frontier models.
- 3:35>> Yeah.
- 3:35>> Uh for sure. So the the mythos models,
- 3:38the open AI models that are out there in
- 3:40the world today absolutely do do a
- 3:42better job with cyber security.
- 3:45But one of the discoveries that we made
- 3:47as an offensive team is that the the
- 3:49driver or the user of the model actually
- 3:51makes as big a difference as the model.
- 3:53So, we're able to take all the
- 3:55experience of an offensive security team
- 3:57that has 20 plus years of Cisco
- 3:59knowledge, and now we're able to do that
- 4:01at machine speeds. We're able to get
- 4:03through more products, more coverage,
- 4:06more features, and and the agents just
- 4:08don't take vacation, and they don't shut
- 4:10down. They run
- 4:12constantly, and and this allows us to
- 4:14bring really high-fidelity
- 4:17vulnerabilities and and areas for
- 4:19architectural improvement in the code
- 4:21that we take to engineering and and for
- 4:23everything we bring our engineering
- 4:24partners, we bring a proof of concept,
- 4:27and we bring a recommendation on a
- 4:29patch. So, it really has just changed
- 4:31the the entire relationship between an
- 4:34offensive team and an engineering team.
- 4:35It's much less adversarial, and and
- 4:38there's much less back and forth, and
- 4:40much much less debate on on the on the
- 4:42findings, which has really allowed us to
- 4:44increase the velocity of fixes.
- 4:47And we have the capability in some cases
- 4:49to actually refactor features
- 4:52>> Yeah.
- 4:52>> if the density of the vulnerabilities
- 4:54are too deep in that in that particular
- 4:55feature.
- 4:56>> let's let's pick that up. So, I think
- 4:58one of the more interesting
- 4:59uh uh developments is anyone in the
- 5:01software industry has been using AI
- 5:04coding tools for, you know, more than a
- 5:06year now, right? A couple of years. What
- 5:08I observe looking at our software
- 5:10development teams is that with the
- 5:11previous generation of models,
- 5:13um for a new project, something
- 5:17greenfield, where we're starting from
- 5:18scratch,
- 5:20we would get a 20x increase in
- 5:23productivity. Like just a surge in
- 5:25productivity. You you couldn't miss it,
- 5:26right? A small team using these models
- 5:28could create really, really big things.
- 5:30But, we struggled to get that same
- 5:33productivity
- 5:35on a complex product which has lots and
- 5:37lots of code. So, think about a Cisco
- 5:40Catalyst switch, a Cisco firewall. These
- 5:42are products that have been developed
- 5:44over a decade and that have, you know,
- 5:47many, many million lines of codes. And
- 5:49so,
- 5:51in my view, this is one of the big
- 5:53changes is that the new class of models
- 5:56coming from the model providers, these
- 5:57what we call frontier models,
- 6:00are capable of understanding these
- 6:01large, complex products in their
- 6:04entirety.
- 6:06And it's because they can understand
- 6:07them in their entirety,
- 6:09they can look for these kind of unusual,
- 6:12you know, circumstances where I change
- 6:14the state of this process, and then it
- 6:16changes the state over here, and then it
- 6:17goes to this thing, and then it finds
- 6:19this, and so there's these kind of chain
- 6:22of events that will lead to a
- 6:24vulnerability. They're finding
- 6:25vulnerabilities that our best humans
- 6:27that have looking at this code for a
- 6:28decade have not been able to find,
- 6:30right? So, that's a that's a big
- 6:31development.
- 6:33But at the same time, and you alluded to
- 6:34this, is super important.
- 6:36Because they understand the model in its
- 6:38entirety, they're able to help us
- 6:40develop new approaches to these complex
- 6:44products, and to to to to fix the
- 6:46vulnerabilities, but not just fix the
- 6:47vulnerabilities, to to look at the
- 6:49kind of basics of the code, and to to
- 6:51shrink the code base, and to compact it
- 6:53so that we can prevent, you know, future
- 6:56vulnerabilities, as well. And that's a
- 6:58that's a leap forward, right? We have
- 7:00not been able to do that with the
- 7:01previous generation models. You think
- 7:02that's a fair assessment, Russ?
- 7:04>> Well, I think it I think it is a fair
- 7:05assessment. I mean, the the context
- 7:07windows, the ability for these models to
- 7:09look at things in context has absolutely
- 7:11improved.
- 7:12>> Yeah.
- 7:12>> Um but in some cases, we use open weight
- 7:15models to do some of that work as well,
- 7:16right? So, we balance, we have a we have
- 7:19a what we call a harness at Cisco, where
- 7:20we have a group of models that do
- 7:22purpose-built activities. So, for things
- 7:24that we need,
- 7:26you know, deep inspection and and deep
- 7:28context, we'll use a frontier model. But
- 7:30if we're writing a bug report or
- 7:32suggesting a patch or creating
- 7:34documentation, we use other models,
- 7:35right? And, you know, we pull all that
- 7:38data together. The other forward step
- 7:41that we were able to make with these
- 7:42models is the frontier models as as
- 7:45we're operating them. We're actually
- 7:46able to go from a static review of our
- 7:49code. So, we index software, we look we
- 7:51look for vulnerabilities
- 7:53through what is effectively static
- 7:55analysis at high speeds. It does a
- 7:57really good job. The false positive
- 7:59rates are lower than than than those of
- 8:01the past, but they're still quite high.
- 8:03But, then we take that data and we move
- 8:06it into a live testing environment and
- 8:08and that's where the offensive security,
- 8:10you know, capabilities at Cisco really
- 8:12start to shine. We put everything we
- 8:14know about the product into a folder. We
- 8:17work through we under we we talk about
- 8:19all the architectural issues, the threat
- 8:20models, its SDL status, all the
- 8:23vulnerabilities we've ever found in the
- 8:25product and documentation.
- 8:27And we turn these agents loose to go
- 8:29exploit these boxes using what they've
- 8:32discovered through static analysis
- 8:34and research and and these agents just
- 8:36go, you know, through the device piece
- 8:38by piece. If it needs to configure a new
- 8:40protocol, they get configured. If it
- 8:43needs to download, you know, a different
- 8:45set of tools to go and do some reverse
- 8:47engineering, they will do that. And this
- 8:49orchestrated group of models that we
- 8:52have in this layer we have have just
- 8:54taken us to a level where we're doing
- 8:56this at machine speed.
- 8:58Uh the offensive security team at Cisco
- 8:59is is less than 100 people.
- 9:02But, we're getting the productivity over
- 9:03500 engineers right now at senior
- 9:06engineering level. So, the productivity
- 9:07has just been astronomical along with
- 9:10the quality.
- 9:11>> Yeah, so I love talking to Russ cuz he
- 9:12always says things that are interesting.
- 9:14There's a couple of points that I want
- 9:15to pick out from what you said. The
- 9:16first thing we just established is that
- 9:18these new models
- 9:20can understand the complex code base.
- 9:21And what this means for our customers
- 9:23is that we're going to be able to
- 9:24provide fixes and improvements to those
- 9:26complex code bases. The second thing you
- 9:28said, which I think is really
- 9:29interesting,
- 9:30is you your observation was that the
- 9:32model by itself
- 9:34is sort of okay from an attacker's point
- 9:37of view, but when you put the model into
- 9:39the hands of a skilled attacker that
- 9:41understands the context of what they're
- 9:44doing, that's
- 9:45where you see the big result. Am I
- 9:47saying that right?
- 9:48>> That that is absolutely fair. We get
- 9:50another layer or another step function
- 9:52improvement in findings when we add the
- 9:55the live testing and and the and the
- 9:57knowledge and the experience of the
- 9:59offensive team and and what it really
- 10:01does is it helps us bring an incredibly
- 10:03high fidelity set of vulnerabilities. It
- 10:06allows us to chain them together in
- 10:07attack chains and create proof of
- 10:10concept. So, when we go when we turn
- 10:12these over to engineering,
- 10:14there's a deep understanding of what
- 10:15happened, why it happened, and there's
- 10:17actually guidance in in our
- 10:19documentation that we give to
- 10:20engineering on how best to fix it. One
- 10:23of the other advantages that we've
- 10:24really taken taken hold of is the
- 10:26ability to create test cases to go
- 10:28validate the fix. So, where it can find
- 10:30a vulnerability, it can create a
- 10:32thousand test cases in seconds to go
- 10:35exercise our fix and make sure that we
- 10:37don't have additional issues and and
- 10:39we've actually seen testing turn out new
- 10:42new vulnerabilities, right? Of even of
- 10:45AI-generated
- 10:46a vulnerability finding. So, so we're
- 10:48seeing the agents and the skills they're
- 10:50learning.
- 10:51>> Yeah.
- 10:51>> And you know, I can even anecdotally say
- 10:54that if we went back and we've done this
- 10:56and scanned a product that we did 3
- 10:58weeks ago with the same same set of
- 11:00harnesses, we're finding new
- 11:02vulnerabilities just basically on
- 11:03learning.
- 11:04>> Another important point that we got to
- 11:06make here is that sometimes I think
- 11:08customers would like to think, "Oh my
- 11:10gosh, uh these new tools find every
- 11:12single vulnerability, you know, that's
- 11:14theoretically possible. So, once we get
- 11:15through the summer of turbulence, I'll
- 11:17be done and there'll be no more no more
- 11:19software vulnerabilities."
- 11:20Unfortunately, gang, that's not the
- 11:22case, right? There are new
- 11:23vulnerabilities, there are you know, as
- 11:25the code changes and matures, there are
- 11:26are, you know, new ways to exploit it.
- 11:30And the tools are incredibly good at at
- 11:32finding those new ways. And so so we as
- 11:35an industry we've got to get ourselves
- 11:36in a position that this is an ongoing
- 11:38state and that the bad guys, the real
- 11:40adversaries, not Russ and his team, but
- 11:42like the real the real foes here are
- 11:44going to have the ability
- 11:46to find and exploit these
- 11:47vulnerabilities at a speed that was
- 11:49never possible before. And and we the
- 11:51industry have to make structural changes
- 11:55about how we manage and update our
- 11:57infrastructure. We simply can't live in
- 11:59a world where we're running you know,
- 12:01sort of old systems that haven't been
- 12:02updated. And so we've got to bring
- 12:06the CICD philosophy, more continuous
- 12:09updates, into the infrastructure. What
- 12:12that means as a vendor is that we're
- 12:14going to make it easier to do these
- 12:15upgrades,
- 12:16but as a customer, you know, we need to
- 12:19start thinking about an operating model
- 12:21where we're not hardening our data
- 12:22center infrastructure and updating it
- 12:24once a year,
- 12:26but we're going to be moving to much
- 12:27more frequent updates. Like is a
- 12:29quarterly update reasonable? You know,
- 12:31like where do you see this going?
- 12:33>> Yeah, I I think models is going to vary.
- 12:35It's going to be based on product.
- 12:36>> Yeah.
- 12:37>> It's going to be based on its position
- 12:39and risk factor in the network. Edges
- 12:41and firewalls may have a different
- 12:42cadence than something hardened inside
- 12:45of a data center. So it's going to
- 12:46depend,
- 12:47but the volume is going to increase and
- 12:50and I think even after we finish the
- 12:53summer of turbulence as you're using it
- 12:55for Mythos, the overall pace of
- 12:58vulnerability disclosure vulnerability
- 13:00discovery is going to stay at a higher
- 13:03base volume level than the industry has
- 13:05ever seen before. It's going to
- 13:06continue. Models are going to get
- 13:08better.
- 13:09>> Yeah.
- 13:09>> We're going to find new things and you
- 13:12know, I can say, you know, right now in
- 13:13Cisco
- 13:15for everything that we've worked on so
- 13:17far and everything that we're finding,
- 13:19we haven't discovered a novel new type
- 13:21of vulnerability. It's more of what
- 13:23we've all experienced in industry.
- 13:26I think we can expect, you know, in more
- 13:27advanced models maybe to start finding
- 13:29new vulnerabilities or new classes of
- 13:31vulnerabilities that we may not
- 13:33understand. So,
- 13:34we need to be in a mode to to upgrade
- 13:37and respond quickly.
- 13:39And being flexible and being able to
- 13:41upgrade still doesn't reduce our
- 13:43responsibility to have high
- 13:45availability. The The devices should
- 13:47have 5/9, 7/9 of availability. They
- 13:50should run. But, when you choose to take
- 13:52them down, you should be able to take
- 13:54them down, upgrade them, have a
- 13:56resilient infrastructure that allows you
- 13:58to upgrade in stages because we we all
- 14:00understand what availability means.
- 14:03But, I think the the bias or the culture
- 14:05that just has to change for
- 14:07infrastructure
- 14:08>> Yeah.
- 14:09>> is we have a bias of mitigate and work
- 14:11around to save downtime. And that is
- 14:14going to have to invert to one of
- 14:16upgrade.
- 14:17>> Yeah.
- 14:17>> It may be very temporary mitigations and
- 14:20then upgrade. But, the concept of
- 14:22holding out for months and years before
- 14:25you upgrade are just frankly going to be
- 14:27over.
- 14:28>> For decades, people have been operating
- 14:30infrastructure this way where you kind
- 14:31of resist the upgrade, you know, you're
- 14:33like, "Oh god, I got to upgrade." And
- 14:35you do the upgrade, you know, Christmas
- 14:37Eve or New Year's Eve or the 4th of July
- 14:39when things are quiet, hopefully. Um
- 14:42um so, that's got to change.
- 14:44Almost a year ago, about 8 months ago,
- 14:47uh we embedded the Tetragon agent into
- 14:51uh Nexus operating system, NX-OS.
- 14:54And what this allows us to do is when we
- 14:56discover a vulnerability in our own
- 14:58code, so in our operating system,
- 15:01we can create a compensating control
- 15:04that you can deploy in a switch or
- 15:06router without rebooting that switch or
- 15:08router.
- 15:10And notice, I did not use the word
- 15:11patch. This is not a patch. It doesn't
- 15:14obviate the need to patch. It doesn't
- 15:16modify the binaries that are running in
- 15:18any way. So, it has very high levels of
- 15:20stability.
- 15:22But, what it is is it's a pinpoint
- 15:25policy change. And it could be as
- 15:27precise as if this process tries to
- 15:30access this file, don't allow that. And
- 15:33what we see is is we can implement a
- 15:35compensating control
- 15:37with virtually no impact on system
- 15:39resources on the machine. Like the CPU
- 15:41utilization doesn't change. I never say
- 15:43never. Like we're always very careful to
- 15:44make sure that new controls we issue
- 15:47meet that same test. But, the idea here
- 15:49is that you can apply
- 15:51these, we call them vulnerability
- 15:53shields,
- 15:55onto a system while it's running without
- 15:58rebooting the system.
- 16:00And we're building the management
- 16:01mechanisms. You can test one, then you
- 16:02can put two, then you do four, do you
- 16:04know, kind of a phase rollout. And so,
- 16:06the idea here is that if we discover
- 16:10something new in between your
- 16:13maintenance windows, you have the
- 16:15ability to put this a finger in the
- 16:16dike, right? It's an emergency control
- 16:18that you can put on a running system
- 16:20that can provide
- 16:21compensating controls
- 16:23to shield those vulnerabilities. And as
- 16:25I said before, I'm going to say it
- 16:26again, it does not eliminate the need to
- 16:27patch.
- 16:29We still want to go through and patch.
- 16:30We want to update these systems more
- 16:31frequently we did. But, Russell, from
- 16:33your perspective,
- 16:34is this a big deal? Is this just kind of
- 16:36a,
- 16:37you know,
- 16:38incremental thing or is this like a
- 16:39meaningful step forward?
- 16:41>> Um I think for embedded systems, it's
- 16:43going to be a a really big deal. It's
- 16:45going to allow you to
- 16:47do very short-term mitigations while
- 16:49you're, you know, moving to patch really
- 16:51quickly.
- 16:52>> Yeah.
- 16:52>> You know, the reality is many of these
- 16:54things are are not going to stack up in
- 16:56a unit, right? They're very pinpoint.
- 16:58And they're going to be built for issues
- 17:01that that are super critical that, you
- 17:03know, we know may or be may or be an
- 17:05exploited or potentially going to be
- 17:07exploited. The the concept of building
- 17:10tens of thousands of these things for
- 17:12every CVE is is not what we're after.
- 17:14These are emergency controls.
- 17:16>> Correct.
- 17:17>> But, that also ties into the need to
- 17:19stay current in hygiene, right? These
- 17:22are These are technologies that are not
- 17:24built for products that we put in the
- 17:26market 15 years ago, 10 years ago. So,
- 17:29currency in making sure that end of life
- 17:33end of support things in your network
- 17:34are are migrated out or if they can't be
- 17:37deeply protected in other parts of the
- 17:39network
- 17:40>> Yeah.
- 17:40>> because these kinds of technologies are
- 17:43out on the edge and they're they're
- 17:45they're they're newer technologies and
- 17:47they rely on all the capabilities that
- 17:49we've built over years with better
- 17:51speed, better scale
- 17:53and and better resiliency in the
- 17:55product. So, so these are not a silver
- 17:57bullet but they are certainly something
- 17:59to help you mitigate and protect.
- 18:01>> Yeah, let's let's be specific about
- 18:02this. So, so as Russell alluded to,
- 18:05we've been shipping this in the Nexus
- 18:07operating system, which is our data
- 18:08center switch
- 18:09for many months now. And it is a
- 18:12software upgrade. To be perfectly clear,
- 18:14this is free. This is func-
- 18:15functionality that's built in
- 18:17>> [clears throat]
- 18:17>> to the product. Doesn't require any
- 18:20particular hardware. And we are able to
- 18:23implement this feature on every version
- 18:26of a supported version of a Nexus
- 18:28switch. So, that's a really really good
- 18:30sign. Now, there's another thing you
- 18:32said earlier that I want to circle back
- 18:33to. It was an observation you made that
- 18:36sometimes [clears throat] your team
- 18:38didn't have access to or didn't need
- 18:40access to the source code. And that
- 18:43these models in the hands of you know,
- 18:45uh your red teaming uh adversaries uh
- 18:48these models are capable of finding
- 18:51these vulnerabilities on a running
- 18:52system just by exercising the APIs.
- 18:55Obviously, they're going to be more
- 18:56effective when they have source, but
- 18:57they can just do it to any running
- 18:59system. True?
- 19:00>> They will absolutely find exploitable
- 19:03vulnerabilities against live configured
- 19:06systems. We get a a step increase when
- 19:09we have access to source code, so we can
- 19:10go deeper but there is absolutely a
- 19:13capability to find vulnerabilities. And
- 19:15it's going to depend on the operating
- 19:17system, the the language it's written
- 19:19in. Your your knowledge is going to
- 19:20vary.
- 19:21>> Yeah.
- 19:21>> So, yeah, I think web applications will
- 19:24be easier to find vulnerabilities in
- 19:25than deep embedded C or or some of the
- 19:28other programs. But yes, it is
- 19:30absolutely a capability.
- 19:31>> Yeah, which brings us to kind of the
- 19:33next chapter of the story, which is for
- 19:34our customers.
- 19:36All the conversation we've had has been
- 19:38talking about how do we make the
- 19:39infrastructure more resilient, more
- 19:42dynamic, right? More secure.
- 19:44But what about the applications that run
- 19:46on that infrastructure? And and I think
- 19:48this is a major major concern for
- 19:50customers because many customers have
- 19:53hundreds or thousands of applications.
- 19:55Sometimes they're third-party stuff that
- 19:56they don't control. Or sometimes they're
- 19:58in-house applications that were written,
- 20:00but the person that wrote that and the
- 20:02architects have long since retired. And
- 20:04you know, someone's got to fix all this
- 20:05stuff.
- 20:07And so, you know, I think one of the
- 20:08things that Cisco's doing that is
- 20:10interesting is we're taking the same
- 20:12philosophies that we have about
- 20:14providing dynamic compensating controls
- 20:17to our own application, which is network
- 20:19operating systems and control planes,
- 20:22and we're making it available for our
- 20:23customers, so they can provide
- 20:25compensating controls that can shield
- 20:28vulnerabilities in their own
- 20:30applications
- 20:31um
- 20:32while the app teams go about the the job
- 20:35of updating and patching those
- 20:36applications, which as we know from
- 20:37Log4j,
- 20:39that can take months, right? That that
- 20:41that is not a small undertaking. And so
- 20:44so there's a couple layers um
- 20:47of defense that we have here. And this
- 20:49shouldn't be too new to any of our
- 20:50listeners, but it's still pretty
- 20:52important. The first and I'm going to I
- 20:54want you to red team what I'm going to
- 20:56say here. Um
- 20:57but segmentation
- 20:59is just a good common sense approach.
- 21:01And the more fine-grained your segments,
- 21:03the better you're going to be because
- 21:04what we have to make the assumption
- 21:07that there are vulnerabilities in the
- 21:09code and that the adversaries are going
- 21:10to find them and they're going to
- 21:11compromise the endpoint. It's going to
- 21:13happen. That's the principle of zero
- 21:15trust, but it's more true than ever
- 21:16before.
- 21:18So, let's make it difficult for them to
- 21:19move around. Let's put walls in place
- 21:21that can, you know,
- 21:23contain the blast radius.
- 21:25Do you agree? Segmentation is like, you
- 21:27know, has always mattered, but boy,
- 21:28let's let's get let's double down on
- 21:30that
- 21:31>> Uh especially if you need to defend
- 21:33parts of your network that you perhaps
- 21:35can't upgrade or have, you know, devices
- 21:38that have limitations, you know, that
- 21:40you know, for modern technology. So, you
- 21:42know, protecting your assets based on
- 21:44class and and applications, of course,
- 21:46right?
- 21:47And and on top of that, all the things
- 21:50that we all should be doing matter.
- 21:52Multi-factor authentication,
- 21:54understanding your inventory,
- 21:56software currency, end of life and the
- 21:59support moving out of the network or
- 22:01being diminished in the network. All of
- 22:03the things matter. They just matter in a
- 22:06much greater depth and speed at this
- 22:08point.
- 22:09>> Right. So, you know, segmentation has
- 22:11always been something that is part and
- 22:12parcel to a network, therefore Cisco,
- 22:14the networking company, has always been
- 22:15really good at segmentation.
- 22:17Um, you know, you can do coarse chunks
- 22:19of segmentation, VLANs, you know, EVPN
- 22:21fabrics, etc.
- 22:23We've taken a step further where we can
- 22:24do segmentation where we can put a layer
- 22:274 stateful firewall, very high
- 22:29performance with hardware acceleration.
- 22:31We bake that right into a switch.
- 22:33So, every switch port gets its own
- 22:35little
- 22:36baby firewall, right? And it allows you
- 22:38to create much more fine-grained
- 22:39segments that have true stateful
- 22:42inspection, and we think that's
- 22:44more important than ever before. The way
- 22:47you do this is called a smart switch.
- 22:48So, so it's a type of switch that can
- 22:50do, you know, very very high performance
- 22:52uh segmentation at scale.
- 22:55Um, and then the software that goes
- 22:56along with that is what we call
- 22:58HyperShield. Now, building up a layer
- 23:00from that, having the ability to apply
- 23:03compensating controls, even like on a
- 23:06foundational issue like an operating
- 23:07system vulnerability. So, the Linux
- 23:09um uh kernel had a bunch of very
- 23:11significant vulnerabilities.
- 23:13With Hyper Shield, we have the ability
- 23:16to provide compensating controls that
- 23:19can shield those application
- 23:21vulnerabilities as well as
- 23:24um
- 23:24uh the infrastructure, right? And so,
- 23:26you can do segmentation and you can
- 23:28shield your vulnerabilities for your for
- 23:31our customers' applications. And I think
- 23:33that's going to matter a lot
- 23:35because, as you said,
- 23:37the tools don't need source,
- 23:39right? If you've got some custom app
- 23:41that you built in your environment, like
- 23:43the tools are going to keep poking at
- 23:44it, especially if it's web-facing,
- 23:45right? The tools are going to keep
- 23:46poking at it until it finds
- 23:47vulnerabilities.
- 23:48And it may take months
- 23:50for the app teams to be able to patch
- 23:52all these things. And so, having the
- 23:54ability to to to put a dynamic control
- 23:57in place that doesn't touch or modify
- 23:58the binary of that app, but can shield
- 24:02that vulnerability, we think that's
- 24:03super important. So, it's a
- 24:04multi-layered approach. Segmentation's a
- 24:06foundation, and then the more
- 24:08sophisticated compensating controls for
- 24:10the application,
- 24:11that's going to matter. So, in this
- 24:13post-mythos world, what our customers
- 24:15need to think about is a multi-layer
- 24:17approach to this problem. And some of
- 24:20this is fundamental, some of this is
- 24:21stuff we've known for a long time, but
- 24:22it's taken on a much greater urgency.
- 24:25The first and most important is that the
- 24:27the days of
- 24:28uh updating your infrastructure once in
- 24:30a while, like every year or 18 months or
- 24:332 years, those days are gone. And we
- 24:35need much more frequent updates to all
- 24:37of the infrastructure as well as the
- 24:38applications that are running on it,
- 24:40okay? That's fundamental. Now,
- 24:42in between those updates, having the
- 24:44ability to apply a dynamic compensating
- 24:47control, like we can do with Live
- 24:49Protect or like we can do for
- 24:50applications with Hyper Shield, that's
- 24:52also a huge step forward.
- 24:55And then, having the ability to
- 24:57implement common sense security hygiene
- 25:00like segmentation, limit the blast
- 25:03radius because as good as we are at
- 25:05trying to shield these vulnerabilities,
- 25:07we know there are going to be
- 25:08vulnerabilities that that the attackers
- 25:11are going to find before those shields
- 25:12are in place and the attackers are going
- 25:14to get in. That's the principle of zero
- 25:15trust. So, let's pay a lot of attention
- 25:18to this, put the segmentation in place.
- 25:20And then, kind of at the top of the
- 25:22stack, we're putting a lot of energy
- 25:24into building automated AI-powered
- 25:27detections that can run in the SOC, that
- 25:29can look for these kind of anomalies and
- 25:31identify when a compromise has happened
- 25:33so that we can then go into remediate.
- 25:35So, multiple layers of defense here, all
- 25:38of which matter and all of which need to
- 25:40be done in a coordinated and thoughtful
- 25:41fashion.
- 25:43Russ, if you could maybe share with us
- 25:45your view of what does a customer need
- 25:48to think about? What is going to change?
- 25:49Maybe even like within Cisco IT, like
- 25:51what are we doing differently to manage
- 25:54our own infrastructure?
- 25:55>> Sure. So, I've got a number of just
- 25:57no-regret items that that we're advising
- 25:59customers to undertake and and this is
- 26:02gathered from many customer
- 26:04conversations and customer visits I've
- 26:06done over the last few weeks. So, this
- 26:07has been refined and and tested and
- 26:10challenged and we have general agreement
- 26:12that these are the right things. So,
- 26:14one, segmentation as we talked about,
- 26:17multi-factor authentication everywhere
- 26:19you can do it, solid inventory and asset
- 26:22management, understand where things are,
- 26:24categorize the risk of that asset, be it
- 26:26an application, a device, or or whatever
- 26:29it is,
- 26:30and really challenge your operations
- 26:32team to log in and refine what the
- 26:36software qualification looks like, how
- 26:38to speed that up, think about using AI
- 26:40tools, the things we've talked about for
- 26:42the last 30 minutes, how I can speed
- 26:44software qualification up, configuration
- 26:46management, all of those hygiene things,
- 26:49and then more importantly than all of it
- 26:52is be willing to be open to
- 26:55expand your risk window a bit to take
- 26:57software faster. The adversaries are
- 27:00going to be moving faster than all of
- 27:01us, and we have to go defend this, and
- 27:04it's going to mean some risk I think in
- 27:06taking
- 27:07upgrades and taking making changes in
- 27:09the networks. This is nothing that my
- 27:12boss Anthony Greco is not asking Cisco
- 27:14to do. We're doing the same thing to
- 27:16ourselves. We are in this with you. We
- 27:19have We are a large enterprise network.
- 27:21We have many suppliers, so we're on the
- 27:23receiving end as well, and and this is
- 27:25exactly what we're doing.
- 27:27>> Okay, Russ. We covered a lot of ground
- 27:28here, and and you know, the changes that
- 27:30are happening in the industry, these are
- 27:32significant. I've been doing this for a
- 27:33long time, and I've not experienced any
- 27:35kind of change at the pace that we're
- 27:38seeing. And so, as I think about what's
- 27:41the one thing I want to leave our
- 27:43customers walk away
- 27:45thinking about, is that we together need
- 27:48a new operating model for
- 27:50infrastructure. And the old model of
- 27:52like hardened it, prove it, and then
- 27:54don't touch it,
- 27:56that model doesn't work anymore.
- 27:57And so, we're going to move to a new
- 27:59model together. We're going to be
- 28:00working with with you our customers to
- 28:02take lots of smaller changes, and in
- 28:06between those changes, having the
- 28:08ability to apply a compensating control
- 28:11to the infrastructure while the
- 28:12infrastructure is running.
- 28:14Right? Using things like live protect to
- 28:16to to put that finger in the dike to
- 28:18plug those holes as we find those holes,
- 28:21that has to be the new operating model
- 28:24going forward. And I think once we get
- 28:26comfortable with that,
- 28:27we're all going to be better off. Like
- 28:29the upgrades are going to be smoother
- 28:30and easier. You don't have this
- 28:31gut-wrenching change, and we'll be much
- 28:34more resilient in the face of a
- 28:37you know, an adversary that has
- 28:39remarkable amounts of automation with
- 28:41these tools. Would you agree with that,
- 28:42Russ?
- 28:43>> I agree with that heartily. The the only
- 28:46nuance that I would put to that is the
- 28:48summer of turbulence.
- 28:50The the upgrades and the changes are
- 28:52going to be more significant. We have to
- 28:54get over the volumetric hump hump.
- 28:57And then we will move into what I hope
- 28:59and we believe is a more normal cadence.
- 29:01>> Yes. I I you know, I share share your
- 29:03pain. We're going to be here for you all
- 29:04during the summer of turbulence and and
- 29:07make that process as smooth as easy as
- 29:08possible. And thanks to all of our
- 29:10listeners for tuning in and you know,
- 29:13the one thing I'll tell you is is things
- 29:15are changing and changing rapidly as a
- 29:17market leader at Cisco, we're going to
- 29:18continue to innovate here and we're
- 29:20going to continue to communicate with
- 29:22you about these changes and what the
- 29:23impact that's going to have on your
- 29:26operations. So, stay tuned.
About this transcript
This page contains the full transcript of Glasswing: Mythos demands a new model for infrastructure by Cisco Security, generated from the public captions YouTube serves with the video. The transcript has 5,472 words across 890 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.