Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 50. Alex, we're half the way to 100.
You never said we'd get here, didn't you? I was down on this the whole time, Robb. The whole time you thought we'd never make it. I thought it'd be a complete failure. We wouldn't get past episode number 1.
And in spite of all the protesters and the total apathy for what we're doing, we've made it to episode 50. Congratulations. Week of January 15th, right? Um, we have some, uh, some great news this week. Let's go through some great news.
But first, let's talk about some of the, the business, right? Slack channel, it's been blowing up. We're up over 180 people. Uh, I'd say it's, it's quite an active community now. If you guys haven't ever got involved with Slack, this is a great way to get to meet other folks in the Denver area.
And for those of you that are a little bit old school and are like, Slack, what the hell is that? Just think IRC. It's just IRC for the new generation. There you go. It's IRC for the new generation.
Absolutely. Also, we have a mailing list if you want to get the show notes delivered into your email inbox each week. Sign up. We'll send those over to you. Go to the website and get signed up for that.
Cool. So first, we have a video story this week. So you'll have to check out the link for that. Left Hand Robotics talking about their new snow clearing robot. Yeah, I was so excited to see like Judy— not Judy, what's the name of the robot from Jetsons?
Rose. Rosie. Rosie. Rosie. Yeah, I was thinking Rosie's gonna be out there with like a shovel, right, clearing my driveway.
That's what I imagined. It's not quite that. No, it's not. It reminds me a little bit of a Zamboni with a big brush on the front. Yeah, but it's pretty cool.
See automated snow clearing, you know, one other thing that can get hacked, right? So start clearing the snow all over the place. It looked interesting to me though. Like, it was not a small thing. It would be like for big driveways or parking lots for, for big companies.
I can imagine, you know, for me to not have to shovel my driveway anymore. I could imagine like an HOA putting in together and buying something like this that could clear the whole HOA in a couple hours, right? Yeah, just, you know, drive around the neighborhood, clear all the sidewalks. That'd be pretty cool. So next, there's a report from MoneyTree about Colorado's venture capital investment in the last year.
Good news is the venture capital in 2017 was the highest rate we've seen in 16 years. We had over $1 billion in investment last year. Yeah, and almost $270 million in the 4th quarter, which is pretty cool too. Yeah, and we saw 154 deals here. It looked like about a quarter of the money went into healthcare funding.
And a little bit less than that went into like mobile and telecommunications. I think it was WellTalk, I think, that had— well done. WellTalk. WellDyne. WellTalk.
One of the Wells. WellDyne, right? Had big funding last year. Yeah, very cool stuff. Also, we had a new VC round from a smart home company here in Colorado, Rachio.
They do smart sprinkler systems, which I actually have one of their systems. Pretty cool. What ports does that listen on? It listens on all of them. It's actually just a gateway into my network.
I just leave it open for everybody. So, so I can get wet any— anyone who's coming to your house if I, if I've also hacked your, your camera system? Yeah, so you could watch when I'm in the backyard, like, you know, standing right in front of the sprinkler and, you know, turn it on. That's good stuff. Spray me right in the butt.
Next, Gates filed for IPO this week. So they're formerly Gates Rubber Company. Yeah. I think we all know the former Gates site, which now no longer exists. Now it's hosting.com, right?
Yeah. It's one of the buildings. Yeah, exactly. And I thought one of the coolest things about the article was that Gates is trying to put out essentially one new product. I think it was a week or was it even a day?
A whole bunch of new products, but they're like a material science company now. Yeah. And they actually don't make any rubber. So they don't make any rubber anymore. Don't make any rubber anymore.
So I guess since they took rubber out of the name, it makes sense. Yeah. I do want to do an errata. It is Welltalk, not Weldyne. You were right.
Welltalk. That was— mark that, everyone. I was right. This will definitely come up in a trivia at some point. Which episode was Alex right?
Episode 50 will be the answer. Red Robin is doing layoffs both in their corporate headquarters, which is, of course, here in Greenwood Village in Denver area, and in restaurants. We had a— we had a story from them a few weeks ago that they had, you know, stopped any expansion of restaurants. And it looks like maybe the next step is, is this kind of cutting of employees. Yeah.
And hopefully things turn around for them. I like Red Robin. They make good hamburgers. So hopefully they can figure out how to adjust to the changing restaurant climate that's out there. Yeah.
So that is the end of our non-security stories. Now we're into the few cybersecurity stories that we had for this week. First, we actually got a press release from Debbi Blyth, the state CISO, talking about the Girls Go CyberStart initiative that they have. So this is actually a partnership between SANS, and it looks like a number of states, Colorado included, They had some training that they developed, and I believe they did this last year just sort of as a, a general training for, uh, for kids. And they realized that only 5% of those that signed up were female.
So this year they're doing a big push to get girls into cybersecurity. So this, this is focused on, on the girls. It was the first 10,000 high school-aged girls who sign up get into this pro— this program. It's really to, to teach them the basics of cybersecurity and identify that young talent that we can start to, start to invest in and, you know, create the next generation of security workers. Exactly.
Uh, next news, Optiv has named a new Chief Technology and Strategy Officer. Stu Solomon is, is the guy. Apparently he has worked at Optiv for a few years. He was hired in 2015, but just got promoted to this new CTSO position. Congratulations, Stu.
And they're, they're read— they're creating a new department in his name, a CTSO department, which is going to have a bunch of the big business units. So it's services and partners and and consulting, right? It was all under— gonna be under him going forward. Seems like a very important role. Yeah.
Next story, there was actually a Forbes article by Patrick Quinlan, who is of Conversant. We've talked about Conversant before, a local company that does ethics training, called Disrupting the Employee Experience. Interesting article talking about compliance training and the future of that. One interesting thing that I took from the article was, sort of a case study that they had about doing virtual reality training for ethics training. The idea being that they really wanted to have it immersive and for you to feel it, to really understand what it is that people are talking about as part of that training.
So, it's a neat article. I recommend you guys take a look at it. I actually interviewed Patrick this week for an upcoming episode of the podcast. Really dynamic guy, tells some really fun stories. At one point call him, say he works for a compliance company, and he says, no, I work for an ethics company, and we're really here to help companies find their ethical, you know, their ethical norms and really embrace that.
So it's interesting conversation. Yeah, great way to look at it. Next is a Ping ID Hardening Guide. So this is a blog post that's about a new artifact that Ping— actually, the Ping security team created. So a couple guys on my team created.
I'd say it's interesting for you guys to take a look at really just for the one graphic that's in there. Unless you happen to be a Ping customer, then maybe you want to look at it for the, the hardening recommendations. But the graphic in there shows the different types of MFA second factor. So, you know, there's SMS text messages, there's fingerprints, there's physical keys. Taking a look at that, at that graphic and seeing what are the most secure methods you can use for, for MFA.
I thought that was the interesting payoff part for you guys. Yeah, it is a cool graphic. Next, James Carder, CISO for LogRhythm, had a blog, 7 Common CISO Pain Points and How to Overcome Them. So, had some interesting stuff in there that folks might want to check out. Things like managing being on call 24/7, which many of us are being in security, you know, problems with asset management and other IT hygiene pieces.
So, he summarizes what the problem is, and then he gives a solution for what are you going to do about these problems. Exactly. And if only it was so easy to manage asset— to figure out the asset management problem as reading his paragraph, everything would be really good. No, no, it's that easy. No problems.
We love James. We do. A couple of announcements for new jobs. Big congratulations to Misha Danisow, who's the new CISO at InteliSecure. I think we mentioned this previously, but now we have a press release that InteliSecure released, so that's in the show notes there.
And also Scott Gerlach, new CISO at SendGrid. So Dave Campbell, who was there before, has moved on. I guess congratulations to Dave for moving on, and also congratulations to Scott on the new role. Yes, Dave's intention was to come to SendGrid, get them ready for an IPO. It took a little bit longer than expected to get that IPO, but successful, accomplished the goal, and he's moving on to his next challenge, and we'll let you know when we hear what that is.
Awesome. So that's it for the news this week. As a reminder, you know, please go out to iTunes and and Google Play and rate us out there. Say, say nice things or bad things, whatever you think. We're, we're okay with it.
Maybe say the bad things to us so that we can fix them, and then say the good things on iTunes or Google Play. Nice. Uh, so jump over to trivia. Yeah, let's go to trivia. Uh, so last week the trivia question that we had was name 6 security startups that have formed in Colorado since 2013.
Uh, and our winner was Brian Thornton. Congratulations, Brian. Brian is the first person to win twice There's the rule you can only win once a quarter. Yeah. And we are in a new quarter.
Yeah. So congratulations, 2-time winner Brian Thornton. So then, you know, maybe that will also be a trivia answer. So yeah, there you go. So the, the ones that he gave were Swimlane, Dark Owl, Red Canary, ProtectWise, ThreatX, and CyberGRX.
Dark Owl used to be One World Labs, so they changed from being One World Labs to now being Dark Owl. So is that— it's the same company as the revised One World Labs? Yes, the post-Chris Roberts company. I believe so. Okay, interesting.
So I think when they essentially sold their assets to the new company, they changed the name to Dark Owl. Very cool. And there's a bunch of other companies that what he could have said instead, SecureSet and Overwatch ID and Inversoft. There's a bunch of other options out there. But certainly he found 6 of the good ones.
Exactly. So this week's trivia. Yep. So the trivia for this week, I want you guys to let me know which local security company called Carbon Black the world's largest pay-for-play data exfiltration botnet. That's your 2017 trivia question.
Boom, boom, boom. We talked about that on a previous podcast. So send an email to info@colorado-security.com or come find us on the Slack channel and We'll talk to you there too. Yeah, any sort of methods. You could send a carrier pigeon if you have one too.
We'll take whatever submissions we get. So let's move on to events. Of course, we do have our event calendar on the website, so go check that out and see all the latest and future events. And there's a ton of stuff. 2018 is just as busy as 2017 was with events every week.
So first we have CSA. Their January meeting is on the 16th. Colorado Springs, this ISSA on the 16th has their dinner meeting and the 17th has their lunch meeting. OWASP has their January meeting on the 17th. DENSEC has their North meeting.
This is the kind of informal get-together to have some drinks and socialize with people around security. Really fun group. I hope you guys can make it up there. On the 18th, Optiv is doing their Solution and Program Insight focus group on application security. Robb has talked about this several times in previous episodes.
Highly recommend. I assume that registration is still open. If you have any interest in working on AppSec this year, this is a really good way to get resources, meet some people who can answer questions for you. Also on the 18th, ISACA has their GDPR meeting. That's going to be their normal January meeting but really focused on GDPR this month.
And also on the 18th, SecureSet is doing their Cybersecurity Expert Series. On the 26th, Red Canary is doing a microbrew tour. It's a— there's a small group of seats available. If you're interested in going to a bunch of breweries and maybe talking security, but probably just drinking some beer and hanging out with some cool people, sign up as soon as you can. It's— I think it's the afternoon of the 26th.
And then finally, also on the 26th, SecureSet is doing a capture the flag event. Yep. And I think that that starts off the first hour from 5 to 6 where they do a beginner's level capture the flag. They teach you how to participate and what you're gonna do for the rest of the night. And then from 6 o'clock on is the bigger event with with the full range of people.
All right, so let's go ahead and move over to jobs. First, TeleTech is looking for a Director of Information Security. I think we can make an announcement here. You know, congratulations to Tim Roundy, who was the Director of Security for TeleTech previously. He retired at the end of last year.
He decided that it was time to hang it up, maybe not forever, but at least for a little while. So congrats to Tim. Yeah, yeah, and so this looks like the, uh, his job now being posted. Yeah, uh, CHI is looking for a manager in their IT security risk group. Uh, you gave me this one.
Kaivu— is it Kaivu Consulting— is hiring an IT manager. Comcast is looking for a security operations center lead. Ping Identity is hiring a site reliability engineer focused on security operations. So this job does not report to me, it reports to our infrastructure operations team, but it's working on security work full-time dedicated in our, in our SRE team. Oh, that sounds cool.
DCP Midstream is hiring an IT Security Analyst 5. You know, I like to have any of these jobs with a number in them whenever we can get them on the show. Well, it's a V actually. I think— well, that's true. This might actually be much further along than 5.
It might be number 23 in the list or whatever. Colorado State University is hiring a Senior Cybersecurity Engineer. And that is actually in Denver. So CSU Denver is hiring this. Yeah.
And it looks like this is actually part of OIT, but it is supporting CSU. Well, that's interesting. So is it working for— we don't probably know, do we? I don't know who you would directly be working for, but if you're under Debbie somewhere, if you're in OIT, you're probably working under Debbie somewhere. Optiv is looking for a consultant in attack and penetration.
Are they teaching you how to attack and penetrate or are they doing attacking? They're probably doing attack and penetrating. And then we have 2 internships get posted this week. Arrow Electronics is hiring an IT risk intern, and Vail Resorts is hiring an information security compliance and risk intern. I assume that these are both for summertime internships, and this is just a chance to start getting signed up for it.
Yeah, it's making me feel bad that I'm not organized yet to have my summer internship jobs posted. Yeah, fair, fair enough. Uh, well, I think that's it for our jobs for the week. Um, we have a feature interview this week with Chris Calvert, right? You sat down with Chris?
I did. Yeah. Chris and I worked together a long time ago at IBM, did a lot of cool work there. And Chris has since done a number of things after that, including starting Respond Software. So he is one of the founders of that.
It's an interesting conversation talking about the science of detection and what they're doing around reducing alarm fatigue and making security operations better. Awesome. We're looking forward to hearing it. Thanks, Alex. We'll talk to you next week.
Thanks, Robb. All right. Hi, this is Rich Schliep, the CISO for the Colorado Department of State. This is Colorado Eco Security for Colorado security professionals by Colorado security professionals.
This is Alex Wood, and I am here with Chris Calvert, co-founder of Respond Software. Chris, how's it going? It's going great. Thanks for having me, Alex. I appreciate it.
Yeah, happy to have you. So, uh, Chris, you and I go way back. We do indeed. Many years now. Uh, we worked at IBM together a long time ago.
Um, I guess why don't we start by, uh, let's get a little bit of your background and how it is that you got into security and how you got to where you are today. Okay. Uh, well, I almost like everybody, I fell into it by accident. I think that's the— that's almost the best path. Um, I started out in the government working for the US Army and NSA in radio hacking really before there was such a thing as the internet.
I was actually working at an NSA field station in '89 when the wall fell, which was very interesting. Oh wow. Came back to Colorado to go to school, continued to work for the government. I ended up spending about 14 years working in the intelligence community in DC. Got tired of that.
Could tell you horrible stories, but I won't. And went to work for IBM where I met you and started working with managed security services. Group there in about 2000. So yeah, I spent 14 years with the government and now 17 years in commercial industry, a couple of entrepreneurial stints, a couple of large company stints. I can tell you which one I prefer.
Yeah, well, I would say since you're not in the government anymore, it's probably not that one. That is absolutely the case. Yeah, yeah. So, you know, we used to do some, some cool stuff back at IBM. I think it's funny because A lot of it actually led into kind of where you are today.
But one of the cool things that we sort of worked on together was some of the data visualization and other things like that, which is kind of coming around today. It's funny to see some of the things that are happening today around security intelligence and other things like that, that I look at, I'm like, we were doing that almost 20 years ago, right? We were. It is upsetting that it is still state of the art. It really should be presumed as sort of a solved problem.
And actually, one of the reasons I think it's not is a lot of people, they don't see it as enough of a product. They see it as a tool or they see it as a feature, but it's not enough to build a full company on. I know a number of folks, actually Rafael Martí, who also worked with us on this topic at IBM, who has worked on this visualization thread for security for a long time, and we've never really gotten a visualization product that's dedicated to security into the market. Yeah, I will say it can go a little bit too far sometimes. You know, ProtectWise, which is a company here in town, and we had a friend that was there for a little while, they introduced at RSA this year a virtual reality goggle edition essentially that you can navigate through your security operations.
That's maybe a little too far in my opinion in terms of visualization, but cool nonetheless, I guess. Well, you know, the science projects or visualization sells quite a bit. And I, you know, I haven't used their visualization, so I want to play with it to see if I really could find the right room in the house and have that be an incident underway. Yes. I can't say that I've played with it much either, but it was, it seemed like maybe a little bit of overkill.
But you mentioned science project. So you recently started Respond Software, and that sort of came out of what I will call a science project. Why don't you talk a little bit about that? I did. So actually, Respond Software had been around for about a year and a half, going— actually going on 2 years at this point.
When we originally started out, we had access to some new mathematics in the sort of advanced probability theory area, and we had a theory that says we can use this to automate human analytical reasoning. The way that we've taught level 1 and level 2 SOC analysts to evaluate a situation to decide whether or not it should be escalated, we could teach that to the math and have the math automate that and give it a process to learn. And literally, for the first 9 to 10 months of the company. And please, I hope our investors don't listen to this. We were conducting a science project to assume that it would work in order to get that proof point.
When we proved it, that's when we went ahead and raised a Series A and are now sort of coming out of stealth mode and becoming a public product. So I'm sure that everybody listening immediately heard everything you just said and thought, oh, they're doing artificial intelligence.
What is it that you have to say about that thought? So we avoid that term like crazy, as you can imagine. What we are really doing is an expert system, but it's not your, you know, 1980s expert system. It is an expert system that has a mechanism for it to learn going forward. The word artificial intelligence is so overloaded with meaning and just the marketing hype around it.
It's going to either solve all problems or it's at the top of the hype cycle. Nobody knows which, right, at this point.
The interesting thing about it is you break it into pieces. What does it mean to do artificial intelligence? Well, it means to automate things that humans do well, or maybe automate things that humans don't like to do well in some instances. And in order to do that, you've got to take a particular security problem and break it into pieces. What are the human reasoning aspects of this and where might automation or science be more effectively applied than humans?
For example, short-term memory. Humans have X amount, machines have X times a million or more. So is that what you guys were trying to accomplish as part of the initial pieces of Respond, trying to break those problems apart and then figuring out how it is that you represent those problems? That was actually— we came to that maybe backwards. The way we started out the company was we recognized that there was sort of a key problem, and that key problem was we have millions and millions of dollars of detection technology, and we have really well-orchestrated response and remediation processes and plans, and sitting between them is this itty-bitty human doing their best possible job to take all of this data and recognize what of it should be escalated for action.
That little narrow problem is killing the industry. It's removing value from a lot of the detection products, and it's making it where we miss these detections. So we really set out to say, how does that decision happen? That operational decision that something should be acted on, how does that decision get made? Yeah, and so it sounds like you're looking at sort of the, the positive side of that.
And I mean that like you're thinking about a way that a person might do this and trying to do it better. I've seen it, the problem sort of tackled the other way too, with people sort of looking at anomaly detection like, oh, hey, I can, I don't, I can go in there and not know what I'm looking for and just look for something weird. Here's a, you know, something interesting or a pattern or whatever. I might spit it out for you to investigate, but I don't know if it's a good thing or a bad thing or it's just something weird. I would categorize that as the traditional machine learning approach.
And you do anomaly detection. The theory is that anomalies, call it an anomalous user agent string, right? Anomalies that you're looking at are more likely to be malicious than things that are fitting well into a cluster. That ends up being only moderately true. So when we've looked at these anomalies, if you look at anomalous user agents, given the number of devices that are going on and, dare I say it, IoT and all of these other things underway, you end up having just as many false positives in anomalies as you did in the signature technologies.
Yeah, and I've seen that with a lot of anomaly detection. Yes, you might be able to cut down the giant field of things to a smaller number, But you still end up with a pretty large number of stuff. That's right. And unfortunately, the bad guys know that we're looking for anomalies. So, you know, having been an incident responder many years ago, you knew you never had a 3-day weekend.
Friday before the 3-day weekend, the pager would go off, guaranteed. You were getting on a plane, you were going somewhere. Well, nowadays these attacks tend to happen more often Wednesday at 10 in the morning because that's peak network traffic. They start to recognize that volume is their friend and find ways to be less anomalous. So, so then how do you tackle this?
Do you, um, do you— obviously there's the math piece that you have to build these models, but then are you, um, are you looking at, um, large numbers of, um, analysts or other people on, on how they do their job to try and figure out— I don't want to call it best practice, or, you know, how does it— that you're looking at the to determine what is good and what is bad? How is it that you guys go about doing that? So myself and my team, we've all built a large number of security operations centers. I've built 8 going back into the mid-1990s. My team, between all of us, it's 40+, 50+ security operations centers, and every one of those builds, we've had to train the analysts.
You can't hire a trained SOC analyst. You have to build your own. So that entire training process that we've done over time, we can now actually train the math in the same way. Because if you think about how an analyst reasons, an analyst observes certain things and then says, well, what's the likelihood that this combination of things really warrants an escalation and a response or doesn't? And so we teach it to reason the same way we've taught humans to reason.
Only we give it a method to learn, and it can work at full volume. So what we do in security a lot is we use some sort of SIEM to reduce the funnel, right? We funnel the volume down to something that's human manageable. When you automate that, that decision, you no longer have to have a funnel. You can look at every single event.
Yeah, you know, because that's one of the things that I've sort of thought about on this this topic is, um, that has been, I'll call it the promise of, of SIEM for forever, right? It's, um, you just give us as much data as you could possibly give us. Let's shove everything we could possibly think of, uh, into this SIEM or whatever log collection method you, that you have. Um, and then there's going to be these amazing rules that are just going to spit out the stuff, only the stuff that you care about, right? Um, and While that is maybe somewhat true, I've never found it to be particularly easy or still result in a small amount of alerts that someone can just go off and easily take care of.
You're talking about a problem near and dear to my heart. When you go back to the beginning of SIEM, right, the ArcSight founder Hugh, his goal was it would be a meta-alert. You are being hacked. You are being hacked. That was the, the type of content that we would build.
That ended up not being the case, but it's also because it gave us a method to deal with volume. I mean, you and I were, I think, the second ArcSight customers ever back at IBM's Managed Security Services. Over the years, that event volume or event funnel has been tremendously important. However, my last role prior to starting Respond Software was as the Director of Innovation for ArcSight, and where I owned all of the SIEM logic that had ever been implemented by our 200-plus person professional services team and many of our customers. And the number of truly useful, valuable correlation rules in a SIEM is under 150 total.
Wow. So it's really, it's really kind of harder to boil that data down and you end up ignoring things that you know you're ignoring. Yeah, one of the examples that I give folks all the time is people turn off reconnaissance signatures because it's so high volume. They typically have these sensors deployed at the edge of their environment, and external inbound reconnaissance, it's— there's no way to pay attention to it. Who cares, right?
It's going to happen all the time, right? It's just nonstop. But internally sourced reconnaissance is actually quite interesting, whether it's outbound or lateral. That is not something you would want to ignore. So by turning off those reconnaissance signatures, you're blinding yourself to something that's actually quite valid to look into, and you're doing it just because volume wins in a lot of these instances.
Yeah, I mean, I spent a lot of time in front of a console back in the day, and, and you would kind of get numb to that stuff, right? So it's, oh yep, there's another, another scan, another scan, another scan, another scan. And if maybe if it's something that was real but looked similar to that, it might get past you because you're numb to that whole thing. Yeah, I agree with that. Having trained people to sit console, I talk about this problem all the time, and then I have them watch me sit sidesaddle for a week, and I work the console for a week as they watch me and we talk about it.
Yeah. And they have caught me clearing the screen. Just, I get behind, I'm like, well, I'm gonna clear it and start over. Well, What did I lose when I cleared it? And if I can't do it when I'm beating the drum, it's going to be very hard for someone to do it at 2 o'clock in the morning.
So now that we've established that sims are useless— Oh, they're not useless. Seriously though, what do you feel like about that area? So you're obviously trying to make a tool that I don't want to necessarily say competes with a sim, but it does similar functionality. Is there still a place for tools like that? So I believe there are.
I actually wrote a blog post recently, I'll plug it right now, called the 8 Fragments of SIEM, and I think SIEM does a lot of different things, all of which are evolving at a different pace. So it collects data and normalizes it. It provides workflow for the analyst. It provides some form of logic to identify things that are important. It allows you to write up cases.
It allows you to integrate downstream with response tools. So there's a whole lot of elements of what is SIEM. You know, the plumbing is being commoditized by ELK and Hadoop, but we decided to be very, very, very narrow and focused and just be the logic, that logic layer. So we don't— we, if you collect your data in a SIEM, we'll get it there. If you collect your data in a Big data platform, we can get it there so that we're focusing on that one thing, which is make a decision about what should be escalated.
There's lots of other components that are going on in what used to be the traditional SIEM. I think SIEM will eventually reassemble. It's sort of fragmenting at the moment as all of these additional capabilities come on in big data and in logic and so forth, and eventually one of the larger companies will buy up a bunch of companies and put it back together into a coherent platform. I would, I would like to see that happen. It would be nice for, um, for it to, to get back to the useful state that it, it was in.
Um, so the way that you guys are operating, um, it sounds like you're complementary. Um, do you, do you see people working still in a sim Um, or working with your product or kind of doing both? Um, so I see people working in a SIEM. It's honestly, there's going to be a, there's going to be a change. The way things right now are set up in security operations is everything is focused on managing the event, and we put a lot of people at managing the event.
In my opinion, that's the wrong layer of abstraction, right? As security professionals, we need to be managing situations, looking for campaigns and things that are happening at the at the situational level rather than at the event level. So I think as we automate the monitoring of events and as we sort of automate the orchestration and all of these other tools, we're going to have an ability to come up a layer. And so security operations is going to look radically different in the next couple of years because it'll be more, you know, higher level, higher layer of abstraction. Right.
Yeah. You know, so today you get some sort of alert in You, um, you look to see if there's, you know, anything else by these same sources, uh, any— what else is going on with those destinations? Are the, are the same users involved? Let's look these IP IPs up and, you know, so on and so forth. And then maybe like half an hour later, you know, you get to the point where you're like, oh, is this thing real or not?
Right, right. Um, so yeah, I mean, I could definitely see with, um, uh, you know, security orchestration and You know, potentially what you guys are talking about, you know, getting all these things, get that first part out of the way and getting to the immediate point where you're saying, yes, I'm escalating this. No, I'm not escalating that. Right. That's— so, so where are you guys sort of in your, your journey as part of Respond?
You're as a company being out in the world, you're fairly new, but you've been around for a couple of years. Um, what's, uh, what is your path? What's the, the roadmap look like? Are you guys, uh, what are you building? All that kind of stuff.
So we've, you know, as I said, we started here almost 2 years ago, did a, did quite a bit of science experiment on sort of our initial seed funding. We're able to prove the, the technology that we're using works because what we're doing is not in TensorFlow or Python sklearn or any of the machine learning libraries. In fact, it's It's not really even machine learning, it's expert systems with some learning that comes sort of after that expert. But in terms of the path we're on, we've originally, or we've initially sort of set our beachhead as a network intrusion detection and prevention analyst, and we're adding antivirus here shortly so that we monitor it. Now, of course, antivirus is very interesting.
What you try to infer from that is not, is something infected? Infected because it's an older platform. It's really good at recognizing known infections. We're trying to infer, is this a critical infection that has some additional characteristic to it that really warrants an incident responder to interact instead of just a help desk or reimage the machine or something along those lines? We're trying to infer, is there a critical virus incident underway as opposed to just has a virus been detected.
So is it modern? Is it spreading? There's a whole bunch of different questions that you do to scope that. But then we have a laundry list of security telemetry that we're looking at where the, the long-term vision of the company is that we create integrated autonomous cyber defense so that all of the technologies that are event-driven get analyzed by one common analyst who's aware of everything going on around the environment understands the context, and can literally scope that all into one incident, which maybe even comes up to the situational level eventually. You have a campaign being directed against you currently.
Here's what we know about that campaign, and here's all the incidents associated with it. Yeah, yeah, it's a big, big vision. We got a lot of work to do, but that's really kind of the direction that we're heading. No, that sounds really, really cool. Cool.
Um, I want to loop back to something you said a second ago. Um, you said this is really an expert system, not even machine learning. Um, I'm guessing that went over most people's head. Um, what's— you would go a little bit deeper in that and, uh, more on, uh, expert systems? Well, so it gets mathy very quickly, and I'll try to, I'll try to walk my way around that.
I, I bent my head first year and some odd trying to read 4,000 pages worth of postdoctoral math textbooks. It was painful. But we are— the way what an expert system does is diagnose. So where we learned about some of this technology is it's been applied in the medical community quite regularly in order to do differential diagnosis. You have abdominal pain.
Well, there's 10,000 possible things that can cause abdominal pain, and based on a mix of other symptoms, you can get to the most likely explanation. And, and actually turns out when they did metrics, the doctors that taught the expert system ended up diagnosing at a lower level of accuracy than the expert system did because it captured multiple doctors' judgment, right, and could really consistently and mathematically evaluate the mix of symptoms most likely to be any given explanation. We're working in that exact same mode. We've just been able to frame the problem in a specific way such that we're trying to reason to the most likely explanation. And it is machine learning in some ways.
It starts out as that expert system or judgment, but then we give it a method to then learn from feedback going forward. So do you feel like this is— this sort of method is applicable not just to the problem that you guys are tackling, but, you know, other security problems as well? Uh, it could be. It absolutely could be. I'm not— I haven't really— I've been so focused on what is the precise problem that we're trying to solve that I haven't thought about all the other places that it could be applied.
Um, but we're— I mean, we intend to use it to make that decision for every piece of telemetry over time. And eventually it'll reduce the number of incidents you have to deal with and produce ones that are high fidelity, very high fidelity. Yeah. One of the other things that we had talked about previously was how traditionally people have tuned and tuned and tuned and spent all this time, you know, sort of engineering resource trying to tune all these sensors down to only get all the stuff that they really want to see because there's such a volume.
You guys are sort of advocating a different approach, right? So just let's open these up, let's get all the data that we can, and then we'll let the machines figure out what is more important. Well, that's right. We want as much data as we can possibly get, But there's a lot of nuance in that tuning conversation because there's what I would call the managed security services tuning, where they're trying to get the volume down to manageable by a large MSS. And sometimes that'll be, we're going to turn on these 40 or 50 highly specific signatures and that's it.
Then there's the tuning just for volume, like I'm going to turn off reconnaissance because it's just too much. But then there's— and both of those I don't agree with, but there is the tuning where I have diagnosed that this is a false positive signature in my environment and I don't want to continue to see it. And that's absolutely valid tuning. The machine doesn't care about false positives any more than a human cares about false positives. Its judgment, its expert system still says this is a false positive.
We don't need to see it. Right. Right. Yeah, that makes sense. And on 2 sort of aspects.
One, it makes me feel really good that you don't have to worry about all that tuning. But as someone who has tuned hundreds, if not thousands, of IDS sensors over my career, it also kind of hurts me thinking that my former skill set would now be obsolete, right? You don't need to do any of this tuning anymore. Well, I struggle with that thought regularly. And my attitude is, well, I'm going to have to make it obsolete.
Obsolete, or I'm the one who's becoming obsolete in some ways. Yeah, it, it's— I look at it as higher, higher order work, being able to do, you know, more interesting things. Tuning IDS sensors is only so interesting after a while, man. So riveting, so riveting. I loved it.
Um, so, uh, so Chris, what else do you have going on? I know that you're, um, you are involved in some teaching as well. Yeah, so I'm also on the board of SecureSet Academy, where they're training security analysts and security engineers and general security practitioners to— because obviously in this industry we just have a massive lack of talent, lack of people. I think the last statistic I heard was 1.8 million open jobs by 2020 in the security industry. So that's actually sort of my comprehensive plan is that, you know, we'll, we'll automate some of the drudgery with Respond Software.
We'll deliver exceptional capable analysts and engineers via SecureSet Academy, and we'll also have some managed services ability to deliver for people who can't do it for themselves with Alchemy Security. So that's why I'm involved with all 3. Nice. And we've had— we're big fans of SecureSet. We've had folks from SecureSet on the show before.
Before. Uh, we've also, uh, interviewed Jobo from, from Alchemy, so, uh, you're in good company. Um, it was interesting on the, on the, the, um, the shortage piece. We actually talked recently, um, on our news segment about one of the, uh, the statistics that just came out from Colorado. They said that, um, and I don't know where exactly they got the numbers from, but they said there's over 18,000 cybersecurity professionals in Colorado.
Wow. But within the last 12 months, there had been 9,000 job postings. So, you know, some of this is, you know, it's cumulative over the year. It's not like there were 9,000 all at once, but, you know, potentially 50% of the jobs out there, you know, being increased in a year, it's pretty incredible. Yeah.
So, what is your role? You're on the board of SecureSet. Yeah, I'm on the board of directors there, and I spend a lot of time with them advising on the content and the academics and what are the types of things to deliver. They've recently come out with a hunt analyst course, and I've been advising them that this is the way the industry is going. It leverages human strengths of curiosity and going and knowing which threads to pull and knowing how to pull those threads.
And so that was one of their recent additions. So what areas do you see coming up? Obviously, Hunt Team is something new. What other areas are we missing other than just the volume of people? What sort of skills do you feel like are in short supply?
Uh, well, I, I have a personal interest and, and focus on the science of detection. Yeah, I think it's been an art form for a very long time, and I've been a practitioner of that art form for a very long time and, and loved it. And, you know, sort of still defines my geek credibility is in that detection space. But I'm, I'm really trying to pull more science into it, whether it's advanced mathematics or visualization or any of the other sort of approaches to scientifically identify attacks as they're occurring. We just, we need to get way better at it.
All we need to do is watch the news to know that this is a major pain point. The average dwell time for an attacker is 200-some-odd days. We need to get that down to minutes or hours, and the only way we're going to do that is with automation, and you can't automate art. You can only automate science. Right.
So how do you think you get it to a science? Obviously, I mean, there's some math involved, but do you need taxonomy or how is it that you work more to make it more of a science? Well, to some extent you— so I actually— that's an interesting question. I went through an exercise to map what all of the analytical methods were and I found about 43 or 44. Distinct analytical methods.
And it was, you know, the traditional business intelligence disciplines, affinity grouping, aggregation, clustering, you know, all of the sort of those standards through data visualization, through machine learning, gradient descent, gradient ascent, various algorithms. All of these have their place. And so how we apply them, sort of what assembled itself in my mind was an analytic stories library where you say, I have this particular use case, this particular telemetry, and a host of algorithms or approaches to apply to it. Of those algorithms and approaches, what solves that use case and that telemetry most effectively? And a lot of it's you develop a hypothesis and you go test it and you try and like, hey, look, I visualized it and I found this low and slow attack going on in my environment that I would have never seen in any other way.
Of course, that's the obvious example we always use, right? But there's a lot of these, and assembling that library of detection science capabilities, I think, is something that we as an industry need to be working on. I've actually been interested in maybe starting up some sort of open source or shared repository of what these analytic libraries might look like. Yeah, that would be an interesting project for sure. Um, who do you see working on those types of things?
Because, um, you know, you're trying to, to get the, the, the low-level drudgery out of the way so you can move people up. But until you get the low-level drudgery out of the way, um, you know, people are worried about the, you know, the immediacy of things that are, you know, right in front of them. Is this something that's going to be, um, you know, resigned to, uh, to academics or to you know, people in security programs that are big enough that you have resources that can sit around and think on big problems. You know, a lot of the times it's, you know, you're in small teams or overworked teams or things like that. You don't have that time to sort of step that up to the next level and think about the higher level kind of things like that.
Yeah, so, you know, I would give you an analogy. I mean, when Elon Musk decided he was gonna put the entire world into an electric car, Right. What did he do? He produced a gazillion-dollar roadster that sold to very few people. Then he produced a Model S that was still, you know, a gazillion minus 50% dollars that sold to a certain segment.
And what he was doing was leveraging the higher-end economics to drive the cost down over time. And I think the large security programs, the large security vendors and people who can afford to spend time and money are going to be the ones who help drive down all of this detection analytic or detection science type technologies and approaches to something that then becomes far more commoditized and can be made available across all size companies. We would say go downmarket and you'd end up doing it as an OEM or an AlienVault app or things like that. Once you've solved it and sort of made it economically viable at the high end. What sort of runway do you see for something like that?
We've got, today cybersecurity is becoming more of a big deal in terms of perception, but I still think to get to a place like that, there's still a long way before we get there. So these people that are in smaller programs or even people that don't have security programs, small, medium-sized business that maybe you've got an IT guy that also does security, how long do you think it's going to be before they're able to benefit from some of this stuff? Not only do I have no idea, but I have a track record of being wrong on this topic.
Visualization being the perfect example. You and I were doing that 17 years ago. It should be mainstream at this point, and it's not. So I really don't know, even though I I feel like the venture capital community is going to drive some of this. There's a lot of investment in the analytics and the sort of higher-end cybersecurity technologies and capabilities, us included, that I think will start being able to drive those economics down by that VC spending.
Do you think that we can drive it enough through that sort of, I'll call it, organic, you know, community way, or do you feel like we need to have other methods as well? Do we need to have regulation? Do we need to have other things like that that are going to drive people down that path? You know, I'd have to think about that. Having been around regulations ever since it sort of started in security, I haven't been doing security for 30 years, most of the time the regulation is ineffective.
You end up with perverse incentives. They regulate to drive a behavior, but then the regulation ends up being more important than the behavior they were trying to drive in the first place. Yeah. And they try to set a low bar so that they're not economically, you know, overly costing small companies and medium companies money. It's a real balance, and it's, it's, it's gonna be hard as to what is the factor that moves us.
Yeah. Well, we are coming up on time, Chris. Any other topics that you wanted to cover? Any plugs? Any— anything else?
No, I think I got my plugs in all through the way. I appreciate the chance, Alex. Thank you for having me. You're welcome. Good talking to you.
This has been Colorado Equal Security, and we will talk to you all soon. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.