Joshua Wells -- Application Security in the Age of Zero Trust
with Joshua Wells
on API Security and Privacy and Compliance
Audio hosted by Buzzsprout. Nothing loads until you press play.
What is zero trust, and how does it impact the world of applications and application security? We dive deep into zero trust with Joshua Wells, a seasoned cybersecurity expert with over ten years of experience. Joshua explores the intricacies of zero trust, a cybersecurity model that dictates no user or machine is trusted by default and must be authenticated every time.
Listen in as Joshua discusses his journey from aspiring to be an NFL player to becoming a leading voice in cybersecurity. He shares insights on how zero trust operates in different domains, including architectural security, endpoint detection, mobile device management, and risk assessment. He also touches on its implementation across various government bodies and private organizations.
Further, Joshua sheds light on the challenges of implementing zero trust, such as the need for a mix of different security tools and the stress of smaller teams when handling this robust framework. The episode also covers important considerations for Application Security (AppSec) professionals in a zero-trust environment and the role of attribute-based access control within this model.
Don’t miss this enlightening discussion on cybersecurity’s current landscape and future direction. Whether you’re a cybersecurity professional, a tech enthusiast, or simply keen on understanding how your data is being kept secure, this episode will surely provide invaluable insights.
Mentioned in this episode
Enjoyed this one? Get Reasonable AppSec, the newsletter with new episodes and picks from the archive.
Transcript
6,697 words · assemblyai
0:00Chris RomeoJoshua Wells is a seasoned cybersecurity expert with over 10 years of experience leading teams and organizations through intricate cybersecurity situations. His extensive background includes working with various government bodies and private sector organizations, specializing in areas such as architectural security, endpoint detection, mobile device management, and risk assessment. In addition to his professional work, Joshua is a distinguished instructor of cybersecurity at several renowned universities, imparting valuable skills and expertise to students. He's currently pursuing his doctoral degree in cybersecurity and is also an active community volunteer in the Northern Virginia area. Joshua joins us to help understand the intersection between Zero Trust and AppSec. We talk about what Zero Trust is, what are some of the challenges, what are the things that work well, and then we also dive into what is the role of the application and ultimately application security In Zero Trust. We hope you enjoy this episode with Joshua Wells. Are you struggling to measure the effectiveness of your secure code training? You're not alone. That's why we're proud to share that on average, Security Journey learners increase their knowledge an average of 33% and as much as 85%. Our diverse training content satisfies a variety of adult learning styles, from conversational training videos to hands-on secure coding activities, ensuring that learners are engaged no matter their learning style.
1:35Joshua WellsVisit securityjourney.com to try our training today.
1:37Chris RomeoHey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo, CEO of Curve Ventures. Ventures and co-host of said podcast, also joined by my good friend, Robert. Hey, Robert.
2:06Robert HurlbutHey, Chris. Yeah, Robert Hurlbut, and I'm a principal application security architect at Acquia, also focused on threat modeling and always interested to talk about some interesting new topics in cybersecurity that we don't always touch on. And today is going to be one of those days where it's a new topic for us.
2:26Chris RomeoYeah, new topic. And let the record show that this is the first time I think I've ever worn a collar on the Application Security Podcast. So, for those people watching on YouTube, yes, I do have a shirt with a collar. I do own more than one, and I did in fact happen to be lucky enough to be wearing it today. So, with that, let's welcome our guest, Joshua Wells. And Josh, we just throw people in the deep end here. We don't believe in, like, you know, a lot of warm-up questions. There's no softballs here. Let's jump right into your security origin story.
2:58Robert HurlbutI like it.
2:58Chris RomeoHow'd you get into security? Take us as far back into your history as you want to go.
3:03Joshua WellsOh, man. First of all, it's definitely a pleasure to be here, Robert and Chris. Thank you guys so much for having me here. I'm trying to figure out how far back I actually want to go. I'll start at high school. I think that's a pretty good starting point. So, I started in high school. I was a very dominant football player. You know, not to brag on myself too much, but I did at one point lead the state of Virginia in rushing. I've always been a football fan and I had aspirations of going to the NFL. Unfortunately, you know, through college, through injuries and certain scenarios that didn't pan out how I wanted it to pan out. So at that point, I was left with a fork in the road, right? In terms of, making a new career for myself or just trying to still go the football route, which obviously you only know you get a small window to actually make it to the next level. So from there, I've always been interested in tech. I was that individual where in high school, I would create websites and I would put my friends, I post my friends on the website with some goofy hair, goofy mask, or et cetera. But I've always had a passion. And from there, I had to make the decision to pivot. And now my wife now, but at the time, she was my girlfriend. She definitely gave me the motivation and she gave me the backbone to really dive into this space in terms of cybersecurity, and especially just pivot and go into a new direction and something that I've always been passionate about. And a lot of the times you don't really understand how passionate about your— that you are about something. until the number one thing you're passionate about is actually stripped from you, you know, so that really creates resilience, perseverance, and etc. So from there, I dived into cybersecurity, you know, I started off doing small contract jobs, IT help desk, IT, you know, project coordinator jobs. And then from there, it was pretty much a self-study route, like I would break down, you know, operating systems such as Windows, you know, Whether it was a Dell, any type of PC, I just wanted to learn every component of it because I was the type of individual where if I'm going into a space, I want to know it 100% and I want to bring everything to the table as far as what I know and dive in there 100%. So from there, yeah, just really built up. I learned different types of processes, methodologies, and I've always been big on security when it comes to securing devices, securing operating systems. And from there, that's where I started to get into engineering. And then from engineering, I started to go into cybersecurity. And then cybersecurity, I pretty much went through that intermediate level and worked up to a director and then worked up to obviously lead positions and et cetera. So that's pretty much how I got started. And honestly, just pivoting from football, I always had that hard work and that integrity to, to, you know, help me go forward, help myself go forward and really dive into a new, uh, career field. So, um, that's pretty much me in a nutshell. And, uh, you know, here I am today. So.
6:15Robert HurlbutYeah.
6:17Chris RomeoAnd as we were talking before the interview, I have to add a question here that we didn't discuss, and that is, how'd you get the nickname Cyber Steve? That's a pretty cool nickname. And I want to know that— I want to know the origin story of Cyber Steve.
6:32Joshua WellsSo the origin stories of Cyber Steve, I would say it probably happened about 6 years ago. So my wife— so I walk around the house, and I love to watch sports. I love to work out. I like to just— I like to do activities, like outdoor activities. I like to do activities inside. Obviously, I love being on my computer. But anytime when I'm on the computer and I have glasses on, she's like, man, you look like Cyber Steve. You look like you're about to hack somebody or something. And then from there, it just turned into the whole nickname of Cyber Steve. So when I take my glasses off, I'm me. But when I put these on, I'm in front of my computer, she calls me Cyber Steve. So that's a little bit about me.
7:13Chris RomeoSo it's like the opposite of Superman.
7:15Robert HurlbutThere we go.
7:15Chris RomeoSo like Superman, what was his name? What's Superman's name? Not, uh, Clark Kent.
7:20Joshua WellsYeah.
7:21Chris RomeoSo Clark Kent, when he wears the glasses, he's not the superhero, but when he takes them off, that's when he becomes a superhero. So like, you're the opposite though.
7:28Joshua WellsYeah.
7:29Chris RomeoYou put them on and you become a cyber superhero. 100%.
7:31Robert Hurlbut100%.
7:33Joshua WellsThey're not ready for it. They are not ready for it. Anytime I'm on a meeting, I put these on, they already know what time it is. So, oh man. Yeah, but that's the origins of it for sure. For sure. So it's something that's stuck around with me throughout the duration of my career to this point. So absolutely.
7:53Robert HurlbutExcellent. So Joshua, so thanks again for joining us today. You know, you and I got in touch and we reached out, and one of the things I noticed is that you have a passion for zero trust, which is, as we mentioned a moment ago, is a topic we haven't talked about on our podcast. And so we want to dig into that today for our listeners. So if you could help us, what is zero trust? How do you define it?
8:21Joshua WellsSo I would label zero trust as Trusting but verifying. So a lot of the times when you're dealing with information technology and nowadays cybersecurity, we have different conditions in terms of whether we trust a specific person or a specific device to gain access to specific resources, right? And zero trust pretty much eliminates all of that. So for example, if I'm working or walking into an organization, if I want to have access to this computer, I now obviously have to authenticate, but I have to verify on every different level. I no longer have special permissions, right? So if a machine is on the network, that machine isn't granted access to a specific area or perimeter based off of its history, right? We're considering everything a threat, and you have to successfully authenticate regardless of who you are, how long you've been here, or what you bring to the table or the primary use case. So pretty much in a nutshell, it's trusting but verifying at the same time. A lot of the times when you're dealing with organizations or like organizations that pretty much have a legacy mindset, they're dealing with individuals or dealing with devices that maybe have conditional access depending on who they are, whether you're a system administrator or whether you're a server. Okay, we don't have to put this server behind this firewall, or we have a firewall behind there, but this server communicates with this. firewall communicates with this operating system. But no, it's on every— at every level, we're trusting, but we're verifying. So there's no longer any conditions in between that says, hey, like, I need to talk to this, or I need to gain access to this. Okay, we trust that you have the right intent. But we also need to understand, and with that understanding comes authentication. So pretty much in a nutshell, that's what zero trust is. And it's becoming very, very big to a lot of government organizations. And I think majority of them, if not all, have to follow that specific framework and guideline. And I think they have a deadline by the end of 2024. So you see a lot of these government agencies quickly adopting to that methodology. And I would say it's based off of a lot of the frameworks that I've worked with, whether it's NIST, CIS, SOC 2, et cetera. This is definitely one of the dominant ones, and it's taken me by surprise, and that's why I'm so passionate about it.
10:50Chris RomeoSo, with zero trust then, I primarily think of network architecture is what conjures in my brain when I think zero trust. Do I have to throw out everything I have? Like, does zero trust start from scratch? Or can I upgrade to zero trust without rebuilding my entire network from scratch?
11:18Joshua WellsYes, absolutely. That's a great question. So there's 3 phases you can take. There's a traditional, and there's an advanced, and there's an optimal. So, you know, as an architect, the first thing I would say is let's see what's already existing in your environment, right? If you have an antivirus solution, right, is that something that we can leverage and automate to detect certain activity or detect certain suspicious behavior, right? Do we have a VPN? Is that configurable? So really just assessing and seeing what we actually have in your infrastructure and tuning that and configuring that before we bring in more security tools, right? Based off of the traditional level, as I mentioned, there's 3 different levels. There's traditional, there's advanced, And I think the last one, the most automated one is, I think that's optimal at the moment. But let's just say traditional is probably the easiest, right? So let's just say if it's something password-based, password or multifactor authentication has to be there at a minimum, right? But let's just say on an optimal level, it has to be continuously evaluated. Maybe that information is logged into a SIEM, et cetera. It has to be more in an automated fashion. It has to have more eyes, more ears, and et cetera. Yeah. But I would say a lot of organizations just starting out, you do have the option of starting as a traditional, at a traditional level, opposed to going more advanced or more optimal. So that's the benefit about it. And I think once they actually started thinking about forming this whole methodology, I think they took that into consideration. And the funny part about it is a lot of organizations are maybe more compliant than what they think they are. You know, if you're working with NIST, if you're working with CIS, if you're working with all these different types of, you know, regulations and methodologies, you have to have some type of structure in place, or you're probably a little bit more advanced than what you think you are, right? So if you're adhering to, you know, having VPNs and, you know, having a SIEM, you know, or having a SOAR where you're actually responding to certain security events, an automated fashion, you probably have a more advanced security approach than other organizations, or you're probably further aligned along than you actually think you are. So I've worked with agencies where they're like, oh man, you know what? We're probably about 85% compliant in this area, and we didn't even know it. So that's what zero trust is meant to actually be. Sometimes it's just turning on a button. Sometimes it's bringing in new technology. So it really all depends.
13:54Chris RomeoSo there's already— so there's some of the pieces that I have. I likely can reuse, and you can provide some other things on top of a foundational layer, assuming I haven't completely neglected security.
14:07Joshua WellsCorrect.
14:08Chris RomeoFrom end to end.
14:09Joshua WellsCorrect.
14:10Chris RomeoSo, I have something that it's not going to be a total tear-out. So, another— I want to— as somebody, you've thought about zero trust a lot more than I have, but so I want to get your take on this because I think I've been confused. about zero trust. Early on in the days of zero trust, I read this paper that Google had on BeyondCorp, which was their kind of zero trust enterprise architecture. And the thing that always caught me, and I think I accidentally attached this to all zero trust, and so I want to get your take on this, but Google's BeyondCorp, they're— and this is what Google runs inside of their production, inside of their offices and everything, like it's how they do it.
14:52Joshua WellsYeah.
14:52Chris RomeoEverything is internet accessible. Everything is public IP addressable. All the devices are. So that like, and IPv6, I believe, as well. So like, so is that, does, does zero trust in, in the way that you think of it, is that the same thing? Is zero trust equivalent to everything is on the public internet and has a public IP address, or is that just Google's flavor? of zero trust?
15:18Joshua WellsIt may be Google's flavor, and there's a lot of nuances probably included with that, I would say. Maybe they have a set of public servers that people need to quickly access, but maybe the information on those servers are not as intense in terms of sensitive, or maybe they have justifications in place for it. Because even from a traditional level all the way to an optimal level, again, the optimal level is more automated fashion. It's more advanced. It's more of, okay, we are tracking, we're authenticating everything, We are not letting anything get out of sight, opposed to traditional, just showing that, okay, this is what we have in place. These are the best practices that we have with our security tools, and this is what we're actually doing. I think there's so many different ways to address zero trust, and even from having servers exposed to the internet, what's on those servers? Are those servers STIG'd, right? Are we in compliance with certain—
16:15Chris RomeoYeah.
16:15Joshua Wellsrules and regulations in terms of NIST? Does it cross over to like NIST 800-53 security controls, right, when dealing with privacy? So there's a lot of conditions that are actually involved. But before the mandate, a lot of organizations probably practice zero trust, but if they're not doing business with the federal government or they're not mandated to actually be compliant with zero trust, that's probably a completely different story in terms of that.
16:42Robert HurlbutYeah.
16:43Chris RomeoSo, and the more I'm thinking about it, the more I'm remembering like when Google Zero Trust, this BeyondCorp stuff came out a long time ago. I don't remember what year it was, but it was really early in the Zero Trust conversation.
16:55Joshua WellsGotcha.
16:56Chris RomeoAnd I'm remembering there was something called Borderless Networks, I think, back in those days too. And so, because I think Google's idea was we want to prove that we can put all these devices on the public internet for our employees to do their jobs. And nobody can get into it because it's so solid and so locked down. But I think what's happening though is I'm interpreting a little bit of what Google's doing as being the bare-bones zero trust. And I think I'm accidentally mixing a few things together here. But you're helping me work it out.
17:33Joshua WellsNo, 100%. And the thing is, a lot of, you know, Google, I would say, is a creative organization. They love to, Pretty much, they love to adhere to certain rules and regulations, but they also like to prove that they're actually capable of doing certain things at the same time. So I've noticed that with a lot of different types of industries and maybe Google being one of them where they're probably like, okay, we'll test zero trust, but maybe we'll stretch it out a little bit to see what we're actually capable of doing. So very, very interesting.
18:05Robert HurlbutYeah.
18:07Chris RomeoSo back to the regularly scheduled programming here. When you think about zero trust, I heard you mention authentication as one piece. What are the other main pieces of zero trust outside of authentication?
18:22Joshua WellsSo I would say authentication is pretty much— that's going to be at each level. So CISA, I think they break down 5 modules. I think it's identity, device, network, application, and data. So data in transition, data at rest, we want to make sure that encryption is emphasized on each level, and whoever needs to have access to that needs to successfully authenticate, whether that's a device or whether that's an actual person. When you're dealing with identity, you're dealing with IAM controls. When you're dealing with device, you're dealing with probably mobile device management, mobile application management. You're dealing with compliance of operating systems. Another example I can give with that is bring your own device versus company-owned cell phones, right? The biggest hurdle has been if I have my own device, how can organizations make sure that if I'm trying— if I'm attempting to get their resources, how am I actually remaining in compliance? And a lot of that is through MAM, which is mobile application management. And that's a form of zero trust. If I want to have access to this container, let's just say it has Microsoft Word. Let's just say it has Microsoft Outlook. I need to make sure that my device is compliant. Maybe that's password requirements. Let's just say, you know, 9 or 10 password characters with uppercase, lowercase, special character. Make sure that my— based off of the operating system, let's just say I have regular iOS updates, maybe the latest updates. And let's just throw another restriction out there. Let's just say I got to make sure Bluetooth is off. So make sure at a minimum, if I want to use this application, I have to make sure that my phone is in the correct standing to actually access these resources, opposed to, you know, organizations just managing my phone. So that really just shows the flexibility in between how we can enforce zero trust with mobile application management versus mobile device management. So there's a lot of ways to deal with it, but I really like CISA's guidelines, and that's pretty much how they break it down in terms of those 5 pillars, which is identity, device, network, application, and data.
20:37Robert HurlbutSo thinking through that a little bit, for an organization when they've heard the mandate— now, as you mentioned, government certainly is received the mandate from the executive order and through certain agencies saying, we've got to do this now. But for other organizations outside of the government, what are some of the advantages for them to take a look at and start taking a look at zero trust? For example, I've seen financial start to look at it. I've seen healthcare start to look at it as well. But what are some of the advantages?
21:16Joshua WellsI would say number one, staying ahead of the game. So for just even for business purposes, like if you're adhering to the latest methodology, whether you deem it as something that's efficient or not, you're staying ahead of the game in terms of business. You know, you see a lot of organizations, you'll say, okay, are you certified in this? You know, ISO certified? You know, are you certified in these areas? And you just increase opportunities by making sure you're actually in compliance with these new rules and regulations. And number 2, I would say it's a very in-depth framework. A lot of the times, organizations think that zero trust may just be accomplished by a security tool, but it's not a security tool. It's a mix of different security tools, and it's a mix of processes all combined to one. Obviously, one security tool can do more than the other. Like, one is Zscaler, which is a very complex, robust, really, really great tool. And maybe that can accommodate for maybe 60% of your problems in terms of zero trust, but you still need other processes. You still need other security tools. But I would just say in terms of that, it's adaptable. It's adaptable. If you're zero trust, I would say certified or compliant in that area, majority of the time you're going to be in compliance with NIST, whether you follow NIST guidelines, ISO, CIS, or whether you're just going through a SOC 2 audit or something, you're going to have those, you're going to have everything in place that you need to. So I would say even if you're just a new company looking to create a solid baseline, starting from the very, very top, my opinion was zero trust is really, really great. And, you know, you would think I'm a zero trust ambassador, but I'm not. But I really believe in that methodology. And it's a Really, really a great approach to take, especially for business purposes.
23:10Chris RomeoSo, all right, so we talked about the positive side. I mean, we're security people. Let's just jump right to the negative. Yeah, like, what's the, you know, what are the challenges here? Why my users are going to hate this, I can already tell. That's, that's one challenge. I'm just guessing because basically they're not going to be able to get into stuff that they used to be able to get into, and I'm going to have to teach them how to get into new stuff using new procedures, and they're going to hate that even more than the previous thing that they hated or whatever. So, but what else are the big challenges on your mind when you're thinking about a deployment of zero trust?
23:45Joshua WellsNo, I think you mentioned some great points, Chris, in terms of like testing and breaking things. That's always going to be number one in terms of creating a pilot environment or pilot accounts for users to actually test out some of these capabilities and features. But I'll also say number 2 is going through this, you realize what you actually don't have. So if you're going through this process, let's just say the first thing I like to do when going through a Zero Trust audit is to assess what we currently have in our environment. And it's an eye-opener in terms of, man, we need more stuff, man. We need to really increase our processes. We really need to increase our— the security tools that we actually have in place. So it's an eye-opener in terms of what you're actually probably not doing better. And just from my experience, just working with organizations, that's really created a lot of— it's created a lot of urgency in other areas. So maybe if we're working on zero trust, they're like, okay, like, I know that going through this process, it opened up my eyes to us needing maybe a different firewall over here. Let's go ahead and focus on this project. So it opens up a lot of areas in terms of if you don't have things existing, it may be really, really costly, you know, if you don't have security tools turned on. But I've come across a lot of organizations where they have a lot of security tools in place, some of them actually being redundant, where it's just like, okay, this worked out to your advantage to actually use it and compile everything together. So I would just say the growing pains that I actually introduced And I would say like the testing phases that come along with it are really, really big and they can really become exhausting, especially if you're working with a small team. I've worked with small teams and large teams when it comes to implementing zero trust. Obviously, the larger the team, the more you can get done, but the smaller the team, it can really create a lot of stress. It can create a lot of, you know, I would say just exhaustion in terms of manpower and getting things done, especially on a day-to-day basis. So, I would say that those are probably some of the biggest concerns when implementing a framework as robust as this.
25:58Robert HurlbutYeah, and I've seen similar, and you probably have too, in terms of, you know, this is a great idea, but it's tough. It's not an out-of-the-box type of easy thing that I can buy and implement and it's done. type of thing. So, one area that, you know, we're focused on application security here on the podcast, we haven't heard a lot about zero trust and the AppSec side or application developer side, but I wonder if you could help us understand from an application developer, what are some things that they might take away in terms of how will this impact their work? moving forward? Do you have some thoughts or ideas on that?
26:44Joshua WellsYeah, absolutely. So even with dealing with the 5 pillars, I know we mentioned the device and the other ones. Wells, application is actually one of them. And if you're a DevOps guy and you're working in, let's just say, AWS, you're working in GCP, you're managing some type of application that's embedded on a container, you have to make sure that that application is secure. And a lot of that ties into zero trust. So let's just say you have your own application that you've built. It's inside of GCP. A lot of that ties into zero trust in terms of monitoring. So if we're dealing with applications, a lot of the times we're probably dealing with brute force attacks, right? Somebody trying to compromise the system using certain credentials, or somebody trying to execute some code, right? So we need to make sure that we're actually monitoring that. And that's why I feel like, to me, application security tied with zero trust is probably one of the biggest areas, right? GCP, they have a lot of great security in terms of monitoring, but obviously, we're working with SIEMs nowadays. We're working with SIEMs, and we're working with SOARs. And if we can leverage that to actually monitor, to automate certain security alerts in a certain fashion, that will definitely be great. But the more I see DevOps working on applications, depending on what organization I'm working with, the more I'm seeing the need of a SIEM, the more I'm seeing the need of security, whether it's code-related, whether it's just the basic interface with just logging in. Everything well-rounded ties into zero trust in terms of application management, application security, and making sure that the correct cybersecurity hygiene of that application is being managed.
28:37Chris RomeoSo, when we think about areas of focus that an AppSec person should look at, so let me give you a scenario, and how would you advise someone as an AppSec person when they're coming into zero trust? So, let's imagine that We did a zero trust implementation, primarily network-related. So, we've got all the pieces. We got authentication, we got authorization, we got logging, monitoring, all those types of things happening. And now, we've got a new application that development wants to deploy, new internal application. So, it's not on the public internet, but it's an internal application that's part of our environment inside the company. What are the things that you would tell— you would advise me as an AppSec person that are specifically in the realm of zero trust? You know, like, so not things like OWASP Top 10, API Top 10, you know, looking at potential secure coding flaws or whatever, but from a zero trust perspective, what should I be investigating with a new application?
29:51Joshua WellsA new application, I would just say at the ground level, Can anybody get access to this? What are the potential connection points in terms of how is this application communicating? And from all of its communication points, is it secure, right? Are we dealing with APIs? Are we dealing with certain access controls? Because everything pretty much ties back to encryption or authentication. You know, what's being encrypted? Is any information being encrypted from the application level? whether it's specific servers or within the outside world or whatever. I would say those are the main points we got to touch on in terms of not everybody should be able to communicate with this application. Not everybody should be able to access this application. And how are we actually creating roadblocks where, okay, let's just say I've been out of the office for 3 months or something, right? And I want to access this specific application. What rights does it give me to actually try to access this? Is it going to successfully force me to authenticate? Am I going to be able to reach out to Joe to reset my password? All of these things that— these are all the things we should be thinking about in terms of application access, and even what our application is connected to. Let's just say it's a little bit more layered too. So we're not just securing the application, we're securing the GCP environment or the Azure environment, whatever it's actually existing on. So it goes so deep into that in terms of we're securing it at the application level, we're securing it at the hosting level, and we're making sure that whatever it's communicating to at every point, if it's connected by API and it's doing specific API calls, where's that being detected at? That's being detected maybe by a SIEM, unauthorized API calls on, or excuse me, unauthorized activity by your APIs. So really just digging into each layer and asking those top-related questions in terms of, you know, if I'm dealing with an application, what is it communicating? And who has access to the application itself? So just dealing with those questions, I would say in a nutshell, would be the first thing we can approach, opposed to even dealing with MITRE frameworks or OWASP Top 10.
32:14Chris RomeoSo, as I'm listening to you talk about applications in a zero trust environment, it's making me think that my favorite type of access control would be a good fit inside of a zero trust environment. So, my favorite type of access control, attribute-based access control, just because you mentioned that scenario where somebody's been out of the office for 3 weeks, And the system should know that. The system should flag a particular authentication/authorization request if somebody's been away for a while, so that becomes not the norm anymore. It becomes this person's now outside of how the policy is. And so, have you had any kind of interactions with attribute-based access control in a zero trust environment where I can set a policy that says, hey, Robert should be able to access these applications from 9 to 5 from these coordinates, which happen to be his office, for example, in a government agency somewhere. But as soon as 5 o'clock rolls around, that policy no longer lets Robert access particular things. So how does that play out in your world of zero trust?
33:29Joshua WellsYeah, absolutely. So I've configured those settings in a SIEM, and I've configured those settings through Microsoft. So for example, in Microsoft, you can set a specific threshold of If this person tries to access X amount of files, I want to get an alert, and it's going to alert me. It's probably going to send it to my email or even just route that information over to a SIEM. But the beauty of it is a lot of the technologies that we leverage today already has a lot of these capabilities built inside of them, especially if you're dealing with the SOAR, which is more of an automation and response. If he were to touch that, it would automatically flag, and depending on the SIEM, it would automatically block him from actually trying to execute that. So there's so many different technologies that actually block that, very similar to maybe like DLP rules, where you can actually set certain permissions, set certain thresholds. So that individual, let's just say he wanted to go on vacation, and anytime between, let's just say, 5:00 PM tonight to next Monday, if there's any activity going on with his account, we need to be alerted. We can even flag his account. In our SIEM or our SOAR. So any suspicious activity or any activity as a whole will be alerting on there. So I would say there's many ways of doing that, which is leveraging different technologies. And I've leveraged Microsoft to do that. I've leveraged even AV products to actually do that. But the most seamless way for me, it was actually leveraging a SIEM and a SOAR, whether it was LogRhythm or whether it was Sumo Logic, which is one of the better ones that I've utilized on the market today.
35:08Chris RomeoSo, as we come towards the conclusion here of our dive into the deep end of the zero trust pool, luckily we had you, Josh, as a lifeguard.
35:22Joshua WellsThank you.
35:23Chris RomeoIn the deep end of the zero trust pool, what would you say is a key takeaway or Let's do this. Let's do— give me a key takeaway first, and then we're going to come back around because I got another question about call to action. But specifically, key takeaway. If you could only— if we could only— if folks are only going to remember one thing coming out of this conversation, what's the thing you want our application security-focused audience to remember?
35:47Joshua WellsI would say adopt to the technology at hand. Application security is so big to me because Everything that we try to execute or everything that we leverage on a day-to-day basis includes applications. And a lot of the times we only see just the front interface of it in terms of what's going on, but there's so much that needs to be monitored on the backend. You know, I always compare like Facebook or, you know, Instagram, like these are all great robust tools, but what are the security elements involved in there? Like, you know, just thinking from a DevOps perspective or security perspective.
36:25Robert HurlbutYeah.
36:26Joshua WellsAll of this ties into zero trust in terms of how are we protecting it, how are we getting notified on it, alerting, and just all the different types of security components that go along with it. And I would just say my takeaway and my recommendation is don't be afraid to adjust with the times when it comes to security. Security's forever changing. There's going to be new tools. There's probably going to be new tools next month, tomorrow, who knows, new methodologies. And this stuff really, really excites me. And my job is to really know the ins and outs of every methodology that's released to figure out how we can create a better world and secure our organizations and our most valuable asset, which is our data. So that's definitely my takeaway and my recommendation.
37:13Robert HurlbutOkay.
37:14Chris RomeoSo as far as a call to action, so let's just assume that most of our listeners are relatively new to zero trust. And they probably read some articles, but they haven't really done any deep dive into zero trust. Is there one place that you would send me as a newbie zero trust person where would be a good place to start? Is there something I can read? Is there something I can watch, something I can listen to? Like, what would be your— what would be the first reference, first thing you would send me to, to get me started in zero trust?
37:47Joshua WellsSo the first thing I would send you is I would definitely recommend going to CISA's website in terms of scrubbing, like, their zero trust architecture is very detailed in terms of how they break it down. And number 2, I would send them to me. I also do consultation on the side in terms of helping people become aware of their ecosystem and organization and figure out ways to actually enhance their security posture. As I mentioned before, at the very, very beginning, I, you know, I had a different route getting and breaking into cybersecurity. And I want to help other people reach that same level of success of where I was able to reach and, you know, keep going even from there, you know. And I would definitely recommend that they reach out to me. My website is actually called Cyber Vault Solutions. And you can book a session with me if you have any zero trust questions or just any consultation questions regarding anything cybersecurity architect related. I'll definitely be more than glad to sit down with you and talk with you about how we can actually break that down.
39:00Chris RomeoVery good. Joshua, thank you for sharing your zero trust knowledge and helping us connect it to application security. Joshua, AKA Cyber Steve.
39:14Joshua WellsThank you.
39:15Chris RomeoThank you for taking the time here. We appreciate it. Definitely learned some stuff from you about how zero trust comes together. I'm going to dive even deeper into it to try to learn more about the connection to the applications and the application security side, but you certainly gave us a good foundation to build off from right there. So, thank you very much.
39:36Joshua WellsAbsolutely. Thank you, guys. Thank you, Chris. Thank you, Robert. It's been an ultimate blessing being on here. Thank you so much for having me.
More on API Security
- Dmitry Sotnikov – REST API Security – there is no silver bullet
Dmitry Sotnikov serves as Chief Product Officer at 42Crunch – an enterprise API security company.
- Nick Aleks and Dolev Farhi -- GraphQL Security
Dolev Farhi is a security engineer and author with extensive experience leading security engineering teams in complex environments and scales in the Fintech and cyber security industries.
- Erez Yalon — The OWASP API Security Project
Erez Yalon heads the security research group at Checkmarx. With vast defender and attacker experience and as an independent security researcher, he brings invaluable knowledge and skills to the table.