YouTube2Text

Glasswing: Mythos demands a new model for infrastructure​ — Transcript

by Cisco Security · 5,472 words · 890 segments · language en · Watch on YouTube

Full transcript

  1. 0:11Hi, I'm Tom Gillis. I'm the general
  2. 0:13manager for infrastructure and security
  3. 0:15products here at Cisco. Russ?
  4. 0:17>> Hi, I'm Russ Smoke. I'm a vice president
  5. 0:20in the security and trust organization
  6. 0:22reporting to our chief security officer
  7. 0:24and I look after vulnerability
  8. 0:25management and offensive security for
  9. 0:27Cisco.
  10. 0:28>> So, Russ and I have been working
  11. 0:29together for many years.
  12. 0:31Um I build products, he breaks the
  13. 0:33products, and I must say he and his team
  14. 0:35quite good at it, right? And they we're
  15. 0:38working together for a common cause,
  16. 0:39which is to making sure that our
  17. 0:40customers has infrastructure which is
  18. 0:43safe, resilient, and trustworthy. And
  19. 0:45that matters more than ever these days
  20. 0:47because the whole landscape is being
  21. 0:50changed by the power of what we call
  22. 0:52frontier models, which is the new models
  23. 0:55uh from the major providers that is
  24. 0:56really really taking a step forward with
  25. 0:59their capabilities. As we got our hands
  26. 1:01on these next generation frontier
  27. 1:03models,
  28. 1:04there's been a shift in in what the
  29. 1:07models are capable of, what we find, and
  30. 1:09that shift is leading to, you know, what
  31. 1:11I'm going to argue is pretty significant
  32. 1:13changes
  33. 1:14in the way that we think about building,
  34. 1:16testing, deploying, and most importantly
  35. 1:18for this audience, operating
  36. 1:21infrastructure at scale.
  37. 1:23So, let's start from the beginning.
  38. 1:24Yeah?
  39. 1:25>> Russ
  40. 1:25>> I would absolutely agree. The the
  41. 1:27introduction of frontier models have
  42. 1:29have really changed the cybersecurity
  43. 1:32game from one of being, you know, very
  44. 1:35operationally focused, very
  45. 1:36conservative, and in some cases, you
  46. 1:38know, a lot of risk management, and in
  47. 1:40some cases risk averse, to one where
  48. 1:42we're going to have to move at machine
  49. 1:44speed. The the days of taking weeks and
  50. 1:48months to qualify software and take, you
  51. 1:50know, long periods of time to upgrade
  52. 1:51software really over.
  53. 1:53>> Yeah.
  54. 1:53>> The the adversaries are going to find
  55. 1:55these vulnerabilities in a matter of
  56. 1:56days. They're going to find exploits in
  57. 1:58hours.
  58. 1:59>> Yeah.
  59. 1:59>> And it's our job as defenders to enable
  60. 2:02our customers to go out and and protect
  61. 2:04themselves.
  62. 2:05>> Yeah, so we're kind of jumping to the
  63. 2:07punchline here and and I think the
  64. 2:08punchline for our audience is that um
  65. 2:11you know, I call it the summer of hell.
  66. 2:13It's going to be some turbulent times
  67. 2:16because
  68. 2:18every piece of software
  69. 2:20everywhere in the industry, like the
  70. 2:22thermostat on your wall has software in
  71. 2:24it.
  72. 2:25All of these software components have
  73. 2:28vulnerabilities that will need to be
  74. 2:29fixed. And so that's going to create a
  75. 2:30scramble of patching.
  76. 2:33But when we emerge through this
  77. 2:34turbulent summer
  78. 2:36I believe that we the industry can can
  79. 2:38be in a much better place and that we're
  80. 2:40going to have truly adopted
  81. 2:42more of a CICD philosophy, that agile,
  82. 2:45constantly taking lots of little steps
  83. 2:47to upgrade our infrastructure, which
  84. 2:49will make the upgrades easier. No more
  85. 2:51gut-wrenching, heart-stopping, like oh
  86. 2:53my god, I took it offline and now I
  87. 2:55can't get it to reboot
  88. 2:56type of upgrades.
  89. 2:58Um and we'll be more secure in the
  90. 3:00process, which is you know, I think
  91. 3:02encouraging. But Russ, let's maybe start
  92. 3:04from the beginning. You and your team
  93. 3:06have been doing, you know, red teaming
  94. 3:08and product testing
  95. 3:10for for years now and we've been using
  96. 3:12AI tools for a long time.
  97. 3:14What changed? What's what's different
  98. 3:17now?
  99. 3:17>> Sure. So you know, we certainly have
  100. 3:19been using AI enablement in the
  101. 3:21offensive security world for for several
  102. 3:23years. What really changed for us in the
  103. 3:26last last few months were two things,
  104. 3:28right? There were step function
  105. 3:30increasing increase in capability and
  106. 3:33quality for the frontier models.
  107. 3:35>> Yeah.
  108. 3:35>> Uh for sure. So the the mythos models,
  109. 3:38the open AI models that are out there in
  110. 3:40the world today absolutely do do a
  111. 3:42better job with cyber security.
  112. 3:45But one of the discoveries that we made
  113. 3:47as an offensive team is that the the
  114. 3:49driver or the user of the model actually
  115. 3:51makes as big a difference as the model.
  116. 3:53So, we're able to take all the
  117. 3:55experience of an offensive security team
  118. 3:57that has 20 plus years of Cisco
  119. 3:59knowledge, and now we're able to do that
  120. 4:01at machine speeds. We're able to get
  121. 4:03through more products, more coverage,
  122. 4:06more features, and and the agents just
  123. 4:08don't take vacation, and they don't shut
  124. 4:10down. They run
  125. 4:12constantly, and and this allows us to
  126. 4:14bring really high-fidelity
  127. 4:17vulnerabilities and and areas for
  128. 4:19architectural improvement in the code
  129. 4:21that we take to engineering and and for
  130. 4:23everything we bring our engineering
  131. 4:24partners, we bring a proof of concept,
  132. 4:27and we bring a recommendation on a
  133. 4:29patch. So, it really has just changed
  134. 4:31the the entire relationship between an
  135. 4:34offensive team and an engineering team.
  136. 4:35It's much less adversarial, and and
  137. 4:38there's much less back and forth, and
  138. 4:40much much less debate on on the on the
  139. 4:42findings, which has really allowed us to
  140. 4:44increase the velocity of fixes.
  141. 4:47And we have the capability in some cases
  142. 4:49to actually refactor features
  143. 4:52>> Yeah.
  144. 4:52>> if the density of the vulnerabilities
  145. 4:54are too deep in that in that particular
  146. 4:55feature.
  147. 4:56>> let's let's pick that up. So, I think
  148. 4:58one of the more interesting
  149. 4:59uh uh developments is anyone in the
  150. 5:01software industry has been using AI
  151. 5:04coding tools for, you know, more than a
  152. 5:06year now, right? A couple of years. What
  153. 5:08I observe looking at our software
  154. 5:10development teams is that with the
  155. 5:11previous generation of models,
  156. 5:13um for a new project, something
  157. 5:17greenfield, where we're starting from
  158. 5:18scratch,
  159. 5:20we would get a 20x increase in
  160. 5:23productivity. Like just a surge in
  161. 5:25productivity. You you couldn't miss it,
  162. 5:26right? A small team using these models
  163. 5:28could create really, really big things.
  164. 5:30But, we struggled to get that same
  165. 5:33productivity
  166. 5:35on a complex product which has lots and
  167. 5:37lots of code. So, think about a Cisco
  168. 5:40Catalyst switch, a Cisco firewall. These
  169. 5:42are products that have been developed
  170. 5:44over a decade and that have, you know,
  171. 5:47many, many million lines of codes. And
  172. 5:49so,
  173. 5:51in my view, this is one of the big
  174. 5:53changes is that the new class of models
  175. 5:56coming from the model providers, these
  176. 5:57what we call frontier models,
  177. 6:00are capable of understanding these
  178. 6:01large, complex products in their
  179. 6:04entirety.
  180. 6:06And it's because they can understand
  181. 6:07them in their entirety,
  182. 6:09they can look for these kind of unusual,
  183. 6:12you know, circumstances where I change
  184. 6:14the state of this process, and then it
  185. 6:16changes the state over here, and then it
  186. 6:17goes to this thing, and then it finds
  187. 6:19this, and so there's these kind of chain
  188. 6:22of events that will lead to a
  189. 6:24vulnerability. They're finding
  190. 6:25vulnerabilities that our best humans
  191. 6:27that have looking at this code for a
  192. 6:28decade have not been able to find,
  193. 6:30right? So, that's a that's a big
  194. 6:31development.
  195. 6:33But at the same time, and you alluded to
  196. 6:34this, is super important.
  197. 6:36Because they understand the model in its
  198. 6:38entirety, they're able to help us
  199. 6:40develop new approaches to these complex
  200. 6:44products, and to to to to fix the
  201. 6:46vulnerabilities, but not just fix the
  202. 6:47vulnerabilities, to to look at the
  203. 6:49kind of basics of the code, and to to
  204. 6:51shrink the code base, and to compact it
  205. 6:53so that we can prevent, you know, future
  206. 6:56vulnerabilities, as well. And that's a
  207. 6:58that's a leap forward, right? We have
  208. 7:00not been able to do that with the
  209. 7:01previous generation models. You think
  210. 7:02that's a fair assessment, Russ?
  211. 7:04>> Well, I think it I think it is a fair
  212. 7:05assessment. I mean, the the context
  213. 7:07windows, the ability for these models to
  214. 7:09look at things in context has absolutely
  215. 7:11improved.
  216. 7:12>> Yeah.
  217. 7:12>> Um but in some cases, we use open weight
  218. 7:15models to do some of that work as well,
  219. 7:16right? So, we balance, we have a we have
  220. 7:19a what we call a harness at Cisco, where
  221. 7:20we have a group of models that do
  222. 7:22purpose-built activities. So, for things
  223. 7:24that we need,
  224. 7:26you know, deep inspection and and deep
  225. 7:28context, we'll use a frontier model. But
  226. 7:30if we're writing a bug report or
  227. 7:32suggesting a patch or creating
  228. 7:34documentation, we use other models,
  229. 7:35right? And, you know, we pull all that
  230. 7:38data together. The other forward step
  231. 7:41that we were able to make with these
  232. 7:42models is the frontier models as as
  233. 7:45we're operating them. We're actually
  234. 7:46able to go from a static review of our
  235. 7:49code. So, we index software, we look we
  236. 7:51look for vulnerabilities
  237. 7:53through what is effectively static
  238. 7:55analysis at high speeds. It does a
  239. 7:57really good job. The false positive
  240. 7:59rates are lower than than than those of
  241. 8:01the past, but they're still quite high.
  242. 8:03But, then we take that data and we move
  243. 8:06it into a live testing environment and
  244. 8:08and that's where the offensive security,
  245. 8:10you know, capabilities at Cisco really
  246. 8:12start to shine. We put everything we
  247. 8:14know about the product into a folder. We
  248. 8:17work through we under we we talk about
  249. 8:19all the architectural issues, the threat
  250. 8:20models, its SDL status, all the
  251. 8:23vulnerabilities we've ever found in the
  252. 8:25product and documentation.
  253. 8:27And we turn these agents loose to go
  254. 8:29exploit these boxes using what they've
  255. 8:32discovered through static analysis
  256. 8:34and research and and these agents just
  257. 8:36go, you know, through the device piece
  258. 8:38by piece. If it needs to configure a new
  259. 8:40protocol, they get configured. If it
  260. 8:43needs to download, you know, a different
  261. 8:45set of tools to go and do some reverse
  262. 8:47engineering, they will do that. And this
  263. 8:49orchestrated group of models that we
  264. 8:52have in this layer we have have just
  265. 8:54taken us to a level where we're doing
  266. 8:56this at machine speed.
  267. 8:58Uh the offensive security team at Cisco
  268. 8:59is is less than 100 people.
  269. 9:02But, we're getting the productivity over
  270. 9:03500 engineers right now at senior
  271. 9:06engineering level. So, the productivity
  272. 9:07has just been astronomical along with
  273. 9:10the quality.
  274. 9:11>> Yeah, so I love talking to Russ cuz he
  275. 9:12always says things that are interesting.
  276. 9:14There's a couple of points that I want
  277. 9:15to pick out from what you said. The
  278. 9:16first thing we just established is that
  279. 9:18these new models
  280. 9:20can understand the complex code base.
  281. 9:21And what this means for our customers
  282. 9:23is that we're going to be able to
  283. 9:24provide fixes and improvements to those
  284. 9:26complex code bases. The second thing you
  285. 9:28said, which I think is really
  286. 9:29interesting,
  287. 9:30is you your observation was that the
  288. 9:32model by itself
  289. 9:34is sort of okay from an attacker's point
  290. 9:37of view, but when you put the model into
  291. 9:39the hands of a skilled attacker that
  292. 9:41understands the context of what they're
  293. 9:44doing, that's
  294. 9:45where you see the big result. Am I
  295. 9:47saying that right?
  296. 9:48>> That that is absolutely fair. We get
  297. 9:50another layer or another step function
  298. 9:52improvement in findings when we add the
  299. 9:55the live testing and and the and the
  300. 9:57knowledge and the experience of the
  301. 9:59offensive team and and what it really
  302. 10:01does is it helps us bring an incredibly
  303. 10:03high fidelity set of vulnerabilities. It
  304. 10:06allows us to chain them together in
  305. 10:07attack chains and create proof of
  306. 10:10concept. So, when we go when we turn
  307. 10:12these over to engineering,
  308. 10:14there's a deep understanding of what
  309. 10:15happened, why it happened, and there's
  310. 10:17actually guidance in in our
  311. 10:19documentation that we give to
  312. 10:20engineering on how best to fix it. One
  313. 10:23of the other advantages that we've
  314. 10:24really taken taken hold of is the
  315. 10:26ability to create test cases to go
  316. 10:28validate the fix. So, where it can find
  317. 10:30a vulnerability, it can create a
  318. 10:32thousand test cases in seconds to go
  319. 10:35exercise our fix and make sure that we
  320. 10:37don't have additional issues and and
  321. 10:39we've actually seen testing turn out new
  322. 10:42new vulnerabilities, right? Of even of
  323. 10:45AI-generated
  324. 10:46a vulnerability finding. So, so we're
  325. 10:48seeing the agents and the skills they're
  326. 10:50learning.
  327. 10:51>> Yeah.
  328. 10:51>> And you know, I can even anecdotally say
  329. 10:54that if we went back and we've done this
  330. 10:56and scanned a product that we did 3
  331. 10:58weeks ago with the same same set of
  332. 11:00harnesses, we're finding new
  333. 11:02vulnerabilities just basically on
  334. 11:03learning.
  335. 11:04>> Another important point that we got to
  336. 11:06make here is that sometimes I think
  337. 11:08customers would like to think, "Oh my
  338. 11:10gosh, uh these new tools find every
  339. 11:12single vulnerability, you know, that's
  340. 11:14theoretically possible. So, once we get
  341. 11:15through the summer of turbulence, I'll
  342. 11:17be done and there'll be no more no more
  343. 11:19software vulnerabilities."
  344. 11:20Unfortunately, gang, that's not the
  345. 11:22case, right? There are new
  346. 11:23vulnerabilities, there are you know, as
  347. 11:25the code changes and matures, there are
  348. 11:26are, you know, new ways to exploit it.
  349. 11:30And the tools are incredibly good at at
  350. 11:32finding those new ways. And so so we as
  351. 11:35an industry we've got to get ourselves
  352. 11:36in a position that this is an ongoing
  353. 11:38state and that the bad guys, the real
  354. 11:40adversaries, not Russ and his team, but
  355. 11:42like the real the real foes here are
  356. 11:44going to have the ability
  357. 11:46to find and exploit these
  358. 11:47vulnerabilities at a speed that was
  359. 11:49never possible before. And and we the
  360. 11:51industry have to make structural changes
  361. 11:55about how we manage and update our
  362. 11:57infrastructure. We simply can't live in
  363. 11:59a world where we're running you know,
  364. 12:01sort of old systems that haven't been
  365. 12:02updated. And so we've got to bring
  366. 12:06the CICD philosophy, more continuous
  367. 12:09updates, into the infrastructure. What
  368. 12:12that means as a vendor is that we're
  369. 12:14going to make it easier to do these
  370. 12:15upgrades,
  371. 12:16but as a customer, you know, we need to
  372. 12:19start thinking about an operating model
  373. 12:21where we're not hardening our data
  374. 12:22center infrastructure and updating it
  375. 12:24once a year,
  376. 12:26but we're going to be moving to much
  377. 12:27more frequent updates. Like is a
  378. 12:29quarterly update reasonable? You know,
  379. 12:31like where do you see this going?
  380. 12:33>> Yeah, I I think models is going to vary.
  381. 12:35It's going to be based on product.
  382. 12:36>> Yeah.
  383. 12:37>> It's going to be based on its position
  384. 12:39and risk factor in the network. Edges
  385. 12:41and firewalls may have a different
  386. 12:42cadence than something hardened inside
  387. 12:45of a data center. So it's going to
  388. 12:46depend,
  389. 12:47but the volume is going to increase and
  390. 12:50and I think even after we finish the
  391. 12:53summer of turbulence as you're using it
  392. 12:55for Mythos, the overall pace of
  393. 12:58vulnerability disclosure vulnerability
  394. 13:00discovery is going to stay at a higher
  395. 13:03base volume level than the industry has
  396. 13:05ever seen before. It's going to
  397. 13:06continue. Models are going to get
  398. 13:08better.
  399. 13:09>> Yeah.
  400. 13:09>> We're going to find new things and you
  401. 13:12know, I can say, you know, right now in
  402. 13:13Cisco
  403. 13:15for everything that we've worked on so
  404. 13:17far and everything that we're finding,
  405. 13:19we haven't discovered a novel new type
  406. 13:21of vulnerability. It's more of what
  407. 13:23we've all experienced in industry.
  408. 13:26I think we can expect, you know, in more
  409. 13:27advanced models maybe to start finding
  410. 13:29new vulnerabilities or new classes of
  411. 13:31vulnerabilities that we may not
  412. 13:33understand. So,
  413. 13:34we need to be in a mode to to upgrade
  414. 13:37and respond quickly.
  415. 13:39And being flexible and being able to
  416. 13:41upgrade still doesn't reduce our
  417. 13:43responsibility to have high
  418. 13:45availability. The The devices should
  419. 13:47have 5/9, 7/9 of availability. They
  420. 13:50should run. But, when you choose to take
  421. 13:52them down, you should be able to take
  422. 13:54them down, upgrade them, have a
  423. 13:56resilient infrastructure that allows you
  424. 13:58to upgrade in stages because we we all
  425. 14:00understand what availability means.
  426. 14:03But, I think the the bias or the culture
  427. 14:05that just has to change for
  428. 14:07infrastructure
  429. 14:08>> Yeah.
  430. 14:09>> is we have a bias of mitigate and work
  431. 14:11around to save downtime. And that is
  432. 14:14going to have to invert to one of
  433. 14:16upgrade.
  434. 14:17>> Yeah.
  435. 14:17>> It may be very temporary mitigations and
  436. 14:20then upgrade. But, the concept of
  437. 14:22holding out for months and years before
  438. 14:25you upgrade are just frankly going to be
  439. 14:27over.
  440. 14:28>> For decades, people have been operating
  441. 14:30infrastructure this way where you kind
  442. 14:31of resist the upgrade, you know, you're
  443. 14:33like, "Oh god, I got to upgrade." And
  444. 14:35you do the upgrade, you know, Christmas
  445. 14:37Eve or New Year's Eve or the 4th of July
  446. 14:39when things are quiet, hopefully. Um
  447. 14:42um so, that's got to change.
  448. 14:44Almost a year ago, about 8 months ago,
  449. 14:47uh we embedded the Tetragon agent into
  450. 14:51uh Nexus operating system, NX-OS.
  451. 14:54And what this allows us to do is when we
  452. 14:56discover a vulnerability in our own
  453. 14:58code, so in our operating system,
  454. 15:01we can create a compensating control
  455. 15:04that you can deploy in a switch or
  456. 15:06router without rebooting that switch or
  457. 15:08router.
  458. 15:10And notice, I did not use the word
  459. 15:11patch. This is not a patch. It doesn't
  460. 15:14obviate the need to patch. It doesn't
  461. 15:16modify the binaries that are running in
  462. 15:18any way. So, it has very high levels of
  463. 15:20stability.
  464. 15:22But, what it is is it's a pinpoint
  465. 15:25policy change. And it could be as
  466. 15:27precise as if this process tries to
  467. 15:30access this file, don't allow that. And
  468. 15:33what we see is is we can implement a
  469. 15:35compensating control
  470. 15:37with virtually no impact on system
  471. 15:39resources on the machine. Like the CPU
  472. 15:41utilization doesn't change. I never say
  473. 15:43never. Like we're always very careful to
  474. 15:44make sure that new controls we issue
  475. 15:47meet that same test. But, the idea here
  476. 15:49is that you can apply
  477. 15:51these, we call them vulnerability
  478. 15:53shields,
  479. 15:55onto a system while it's running without
  480. 15:58rebooting the system.
  481. 16:00And we're building the management
  482. 16:01mechanisms. You can test one, then you
  483. 16:02can put two, then you do four, do you
  484. 16:04know, kind of a phase rollout. And so,
  485. 16:06the idea here is that if we discover
  486. 16:10something new in between your
  487. 16:13maintenance windows, you have the
  488. 16:15ability to put this a finger in the
  489. 16:16dike, right? It's an emergency control
  490. 16:18that you can put on a running system
  491. 16:20that can provide
  492. 16:21compensating controls
  493. 16:23to shield those vulnerabilities. And as
  494. 16:25I said before, I'm going to say it
  495. 16:26again, it does not eliminate the need to
  496. 16:27patch.
  497. 16:29We still want to go through and patch.
  498. 16:30We want to update these systems more
  499. 16:31frequently we did. But, Russell, from
  500. 16:33your perspective,
  501. 16:34is this a big deal? Is this just kind of
  502. 16:36a,
  503. 16:37you know,
  504. 16:38incremental thing or is this like a
  505. 16:39meaningful step forward?
  506. 16:41>> Um I think for embedded systems, it's
  507. 16:43going to be a a really big deal. It's
  508. 16:45going to allow you to
  509. 16:47do very short-term mitigations while
  510. 16:49you're, you know, moving to patch really
  511. 16:51quickly.
  512. 16:52>> Yeah.
  513. 16:52>> You know, the reality is many of these
  514. 16:54things are are not going to stack up in
  515. 16:56a unit, right? They're very pinpoint.
  516. 16:58And they're going to be built for issues
  517. 17:01that that are super critical that, you
  518. 17:03know, we know may or be may or be an
  519. 17:05exploited or potentially going to be
  520. 17:07exploited. The the concept of building
  521. 17:10tens of thousands of these things for
  522. 17:12every CVE is is not what we're after.
  523. 17:14These are emergency controls.
  524. 17:16>> Correct.
  525. 17:17>> But, that also ties into the need to
  526. 17:19stay current in hygiene, right? These
  527. 17:22are These are technologies that are not
  528. 17:24built for products that we put in the
  529. 17:26market 15 years ago, 10 years ago. So,
  530. 17:29currency in making sure that end of life
  531. 17:33end of support things in your network
  532. 17:34are are migrated out or if they can't be
  533. 17:37deeply protected in other parts of the
  534. 17:39network
  535. 17:40>> Yeah.
  536. 17:40>> because these kinds of technologies are
  537. 17:43out on the edge and they're they're
  538. 17:45they're they're newer technologies and
  539. 17:47they rely on all the capabilities that
  540. 17:49we've built over years with better
  541. 17:51speed, better scale
  542. 17:53and and better resiliency in the
  543. 17:55product. So, so these are not a silver
  544. 17:57bullet but they are certainly something
  545. 17:59to help you mitigate and protect.
  546. 18:01>> Yeah, let's let's be specific about
  547. 18:02this. So, so as Russell alluded to,
  548. 18:05we've been shipping this in the Nexus
  549. 18:07operating system, which is our data
  550. 18:08center switch
  551. 18:09for many months now. And it is a
  552. 18:12software upgrade. To be perfectly clear,
  553. 18:14this is free. This is func-
  554. 18:15functionality that's built in
  555. 18:17>> [clears throat]
  556. 18:17>> to the product. Doesn't require any
  557. 18:20particular hardware. And we are able to
  558. 18:23implement this feature on every version
  559. 18:26of a supported version of a Nexus
  560. 18:28switch. So, that's a really really good
  561. 18:30sign. Now, there's another thing you
  562. 18:32said earlier that I want to circle back
  563. 18:33to. It was an observation you made that
  564. 18:36sometimes [clears throat] your team
  565. 18:38didn't have access to or didn't need
  566. 18:40access to the source code. And that
  567. 18:43these models in the hands of you know,
  568. 18:45uh your red teaming uh adversaries uh
  569. 18:48these models are capable of finding
  570. 18:51these vulnerabilities on a running
  571. 18:52system just by exercising the APIs.
  572. 18:55Obviously, they're going to be more
  573. 18:56effective when they have source, but
  574. 18:57they can just do it to any running
  575. 18:59system. True?
  576. 19:00>> They will absolutely find exploitable
  577. 19:03vulnerabilities against live configured
  578. 19:06systems. We get a a step increase when
  579. 19:09we have access to source code, so we can
  580. 19:10go deeper but there is absolutely a
  581. 19:13capability to find vulnerabilities. And
  582. 19:15it's going to depend on the operating
  583. 19:17system, the the language it's written
  584. 19:19in. Your your knowledge is going to
  585. 19:20vary.
  586. 19:21>> Yeah.
  587. 19:21>> So, yeah, I think web applications will
  588. 19:24be easier to find vulnerabilities in
  589. 19:25than deep embedded C or or some of the
  590. 19:28other programs. But yes, it is
  591. 19:30absolutely a capability.
  592. 19:31>> Yeah, which brings us to kind of the
  593. 19:33next chapter of the story, which is for
  594. 19:34our customers.
  595. 19:36All the conversation we've had has been
  596. 19:38talking about how do we make the
  597. 19:39infrastructure more resilient, more
  598. 19:42dynamic, right? More secure.
  599. 19:44But what about the applications that run
  600. 19:46on that infrastructure? And and I think
  601. 19:48this is a major major concern for
  602. 19:50customers because many customers have
  603. 19:53hundreds or thousands of applications.
  604. 19:55Sometimes they're third-party stuff that
  605. 19:56they don't control. Or sometimes they're
  606. 19:58in-house applications that were written,
  607. 20:00but the person that wrote that and the
  608. 20:02architects have long since retired. And
  609. 20:04you know, someone's got to fix all this
  610. 20:05stuff.
  611. 20:07And so, you know, I think one of the
  612. 20:08things that Cisco's doing that is
  613. 20:10interesting is we're taking the same
  614. 20:12philosophies that we have about
  615. 20:14providing dynamic compensating controls
  616. 20:17to our own application, which is network
  617. 20:19operating systems and control planes,
  618. 20:22and we're making it available for our
  619. 20:23customers, so they can provide
  620. 20:25compensating controls that can shield
  621. 20:28vulnerabilities in their own
  622. 20:30applications
  623. 20:31um
  624. 20:32while the app teams go about the the job
  625. 20:35of updating and patching those
  626. 20:36applications, which as we know from
  627. 20:37Log4j,
  628. 20:39that can take months, right? That that
  629. 20:41that is not a small undertaking. And so
  630. 20:44so there's a couple layers um
  631. 20:47of defense that we have here. And this
  632. 20:49shouldn't be too new to any of our
  633. 20:50listeners, but it's still pretty
  634. 20:52important. The first and I'm going to I
  635. 20:54want you to red team what I'm going to
  636. 20:56say here. Um
  637. 20:57but segmentation
  638. 20:59is just a good common sense approach.
  639. 21:01And the more fine-grained your segments,
  640. 21:03the better you're going to be because
  641. 21:04what we have to make the assumption
  642. 21:07that there are vulnerabilities in the
  643. 21:09code and that the adversaries are going
  644. 21:10to find them and they're going to
  645. 21:11compromise the endpoint. It's going to
  646. 21:13happen. That's the principle of zero
  647. 21:15trust, but it's more true than ever
  648. 21:16before.
  649. 21:18So, let's make it difficult for them to
  650. 21:19move around. Let's put walls in place
  651. 21:21that can, you know,
  652. 21:23contain the blast radius.
  653. 21:25Do you agree? Segmentation is like, you
  654. 21:27know, has always mattered, but boy,
  655. 21:28let's let's get let's double down on
  656. 21:30that
  657. 21:31>> Uh especially if you need to defend
  658. 21:33parts of your network that you perhaps
  659. 21:35can't upgrade or have, you know, devices
  660. 21:38that have limitations, you know, that
  661. 21:40you know, for modern technology. So, you
  662. 21:42know, protecting your assets based on
  663. 21:44class and and applications, of course,
  664. 21:46right?
  665. 21:47And and on top of that, all the things
  666. 21:50that we all should be doing matter.
  667. 21:52Multi-factor authentication,
  668. 21:54understanding your inventory,
  669. 21:56software currency, end of life and the
  670. 21:59support moving out of the network or
  671. 22:01being diminished in the network. All of
  672. 22:03the things matter. They just matter in a
  673. 22:06much greater depth and speed at this
  674. 22:08point.
  675. 22:09>> Right. So, you know, segmentation has
  676. 22:11always been something that is part and
  677. 22:12parcel to a network, therefore Cisco,
  678. 22:14the networking company, has always been
  679. 22:15really good at segmentation.
  680. 22:17Um, you know, you can do coarse chunks
  681. 22:19of segmentation, VLANs, you know, EVPN
  682. 22:21fabrics, etc.
  683. 22:23We've taken a step further where we can
  684. 22:24do segmentation where we can put a layer
  685. 22:274 stateful firewall, very high
  686. 22:29performance with hardware acceleration.
  687. 22:31We bake that right into a switch.
  688. 22:33So, every switch port gets its own
  689. 22:35little
  690. 22:36baby firewall, right? And it allows you
  691. 22:38to create much more fine-grained
  692. 22:39segments that have true stateful
  693. 22:42inspection, and we think that's
  694. 22:44more important than ever before. The way
  695. 22:47you do this is called a smart switch.
  696. 22:48So, so it's a type of switch that can
  697. 22:50do, you know, very very high performance
  698. 22:52uh segmentation at scale.
  699. 22:55Um, and then the software that goes
  700. 22:56along with that is what we call
  701. 22:58HyperShield. Now, building up a layer
  702. 23:00from that, having the ability to apply
  703. 23:03compensating controls, even like on a
  704. 23:06foundational issue like an operating
  705. 23:07system vulnerability. So, the Linux
  706. 23:09um uh kernel had a bunch of very
  707. 23:11significant vulnerabilities.
  708. 23:13With Hyper Shield, we have the ability
  709. 23:16to provide compensating controls that
  710. 23:19can shield those application
  711. 23:21vulnerabilities as well as
  712. 23:24um
  713. 23:24uh the infrastructure, right? And so,
  714. 23:26you can do segmentation and you can
  715. 23:28shield your vulnerabilities for your for
  716. 23:31our customers' applications. And I think
  717. 23:33that's going to matter a lot
  718. 23:35because, as you said,
  719. 23:37the tools don't need source,
  720. 23:39right? If you've got some custom app
  721. 23:41that you built in your environment, like
  722. 23:43the tools are going to keep poking at
  723. 23:44it, especially if it's web-facing,
  724. 23:45right? The tools are going to keep
  725. 23:46poking at it until it finds
  726. 23:47vulnerabilities.
  727. 23:48And it may take months
  728. 23:50for the app teams to be able to patch
  729. 23:52all these things. And so, having the
  730. 23:54ability to to to put a dynamic control
  731. 23:57in place that doesn't touch or modify
  732. 23:58the binary of that app, but can shield
  733. 24:02that vulnerability, we think that's
  734. 24:03super important. So, it's a
  735. 24:04multi-layered approach. Segmentation's a
  736. 24:06foundation, and then the more
  737. 24:08sophisticated compensating controls for
  738. 24:10the application,
  739. 24:11that's going to matter. So, in this
  740. 24:13post-mythos world, what our customers
  741. 24:15need to think about is a multi-layer
  742. 24:17approach to this problem. And some of
  743. 24:20this is fundamental, some of this is
  744. 24:21stuff we've known for a long time, but
  745. 24:22it's taken on a much greater urgency.
  746. 24:25The first and most important is that the
  747. 24:27the days of
  748. 24:28uh updating your infrastructure once in
  749. 24:30a while, like every year or 18 months or
  750. 24:332 years, those days are gone. And we
  751. 24:35need much more frequent updates to all
  752. 24:37of the infrastructure as well as the
  753. 24:38applications that are running on it,
  754. 24:40okay? That's fundamental. Now,
  755. 24:42in between those updates, having the
  756. 24:44ability to apply a dynamic compensating
  757. 24:47control, like we can do with Live
  758. 24:49Protect or like we can do for
  759. 24:50applications with Hyper Shield, that's
  760. 24:52also a huge step forward.
  761. 24:55And then, having the ability to
  762. 24:57implement common sense security hygiene
  763. 25:00like segmentation, limit the blast
  764. 25:03radius because as good as we are at
  765. 25:05trying to shield these vulnerabilities,
  766. 25:07we know there are going to be
  767. 25:08vulnerabilities that that the attackers
  768. 25:11are going to find before those shields
  769. 25:12are in place and the attackers are going
  770. 25:14to get in. That's the principle of zero
  771. 25:15trust. So, let's pay a lot of attention
  772. 25:18to this, put the segmentation in place.
  773. 25:20And then, kind of at the top of the
  774. 25:22stack, we're putting a lot of energy
  775. 25:24into building automated AI-powered
  776. 25:27detections that can run in the SOC, that
  777. 25:29can look for these kind of anomalies and
  778. 25:31identify when a compromise has happened
  779. 25:33so that we can then go into remediate.
  780. 25:35So, multiple layers of defense here, all
  781. 25:38of which matter and all of which need to
  782. 25:40be done in a coordinated and thoughtful
  783. 25:41fashion.
  784. 25:43Russ, if you could maybe share with us
  785. 25:45your view of what does a customer need
  786. 25:48to think about? What is going to change?
  787. 25:49Maybe even like within Cisco IT, like
  788. 25:51what are we doing differently to manage
  789. 25:54our own infrastructure?
  790. 25:55>> Sure. So, I've got a number of just
  791. 25:57no-regret items that that we're advising
  792. 25:59customers to undertake and and this is
  793. 26:02gathered from many customer
  794. 26:04conversations and customer visits I've
  795. 26:06done over the last few weeks. So, this
  796. 26:07has been refined and and tested and
  797. 26:10challenged and we have general agreement
  798. 26:12that these are the right things. So,
  799. 26:14one, segmentation as we talked about,
  800. 26:17multi-factor authentication everywhere
  801. 26:19you can do it, solid inventory and asset
  802. 26:22management, understand where things are,
  803. 26:24categorize the risk of that asset, be it
  804. 26:26an application, a device, or or whatever
  805. 26:29it is,
  806. 26:30and really challenge your operations
  807. 26:32team to log in and refine what the
  808. 26:36software qualification looks like, how
  809. 26:38to speed that up, think about using AI
  810. 26:40tools, the things we've talked about for
  811. 26:42the last 30 minutes, how I can speed
  812. 26:44software qualification up, configuration
  813. 26:46management, all of those hygiene things,
  814. 26:49and then more importantly than all of it
  815. 26:52is be willing to be open to
  816. 26:55expand your risk window a bit to take
  817. 26:57software faster. The adversaries are
  818. 27:00going to be moving faster than all of
  819. 27:01us, and we have to go defend this, and
  820. 27:04it's going to mean some risk I think in
  821. 27:06taking
  822. 27:07upgrades and taking making changes in
  823. 27:09the networks. This is nothing that my
  824. 27:12boss Anthony Greco is not asking Cisco
  825. 27:14to do. We're doing the same thing to
  826. 27:16ourselves. We are in this with you. We
  827. 27:19have We are a large enterprise network.
  828. 27:21We have many suppliers, so we're on the
  829. 27:23receiving end as well, and and this is
  830. 27:25exactly what we're doing.
  831. 27:27>> Okay, Russ. We covered a lot of ground
  832. 27:28here, and and you know, the changes that
  833. 27:30are happening in the industry, these are
  834. 27:32significant. I've been doing this for a
  835. 27:33long time, and I've not experienced any
  836. 27:35kind of change at the pace that we're
  837. 27:38seeing. And so, as I think about what's
  838. 27:41the one thing I want to leave our
  839. 27:43customers walk away
  840. 27:45thinking about, is that we together need
  841. 27:48a new operating model for
  842. 27:50infrastructure. And the old model of
  843. 27:52like hardened it, prove it, and then
  844. 27:54don't touch it,
  845. 27:56that model doesn't work anymore.
  846. 27:57And so, we're going to move to a new
  847. 27:59model together. We're going to be
  848. 28:00working with with you our customers to
  849. 28:02take lots of smaller changes, and in
  850. 28:06between those changes, having the
  851. 28:08ability to apply a compensating control
  852. 28:11to the infrastructure while the
  853. 28:12infrastructure is running.
  854. 28:14Right? Using things like live protect to
  855. 28:16to to put that finger in the dike to
  856. 28:18plug those holes as we find those holes,
  857. 28:21that has to be the new operating model
  858. 28:24going forward. And I think once we get
  859. 28:26comfortable with that,
  860. 28:27we're all going to be better off. Like
  861. 28:29the upgrades are going to be smoother
  862. 28:30and easier. You don't have this
  863. 28:31gut-wrenching change, and we'll be much
  864. 28:34more resilient in the face of a
  865. 28:37you know, an adversary that has
  866. 28:39remarkable amounts of automation with
  867. 28:41these tools. Would you agree with that,
  868. 28:42Russ?
  869. 28:43>> I agree with that heartily. The the only
  870. 28:46nuance that I would put to that is the
  871. 28:48summer of turbulence.
  872. 28:50The the upgrades and the changes are
  873. 28:52going to be more significant. We have to
  874. 28:54get over the volumetric hump hump.
  875. 28:57And then we will move into what I hope
  876. 28:59and we believe is a more normal cadence.
  877. 29:01>> Yes. I I you know, I share share your
  878. 29:03pain. We're going to be here for you all
  879. 29:04during the summer of turbulence and and
  880. 29:07make that process as smooth as easy as
  881. 29:08possible. And thanks to all of our
  882. 29:10listeners for tuning in and you know,
  883. 29:13the one thing I'll tell you is is things
  884. 29:15are changing and changing rapidly as a
  885. 29:17market leader at Cisco, we're going to
  886. 29:18continue to innovate here and we're
  887. 29:20going to continue to communicate with
  888. 29:22you about these changes and what the
  889. 29:23impact that's going to have on your
  890. 29:26operations. So, stay tuned.

About this transcript

This page contains the full transcript of Glasswing: Mythos demands a new model for infrastructure​ by Cisco Security, generated from the public captions YouTube serves with the video. The transcript has 5,472 words across 890 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.