Go back

Ten o nowoczesnych firewallach z AI, analizie szyfrowanego ruchu i Hypershield (NP #058)

41m 28s

Ten o nowoczesnych firewallach z AI, analizie szyfrowanego ruchu i Hypershield (NP #058)

The interview delves into the transformation of firewalls over the last two decades, highlighting the shift towards advanced security measures and the incorporation of AI technologies. Machine learning on firewalls enables sophisticated threat detection by analyzing data and user behavior. Data processing and model training for AI solutions occur locally on the firewall device, ensuring privacy and security. Communication between firewall solutions within an organization is facilitated through systems like ICE and the PxGrid protocol, allowing for seamless exchange of threat information. The interview underscores the importance of evolving firewall technologies to combat cyber threats effectively while maintaining data privacy and security.

Transcription

6793 Words, 38330 Characters

[Music] Hi! Welcome to the next episode of "On the Dry". This is not a standard episode, because today there will be an interview. An interview with a guy who has a big experience in safety. And in the devices we will talk about today, the devices that secure the company, but also in the context of ordinary users. Along with me is Łukasz Bromijski. Hi Łukasz! Hi! I have to say that I will officially introduce you, so right now I am the director of the product department of Cisco Systems. I managed to say this without any mistake. However, I remember Łukasz from the posts on the Krakowsk AGH, which was also led by Andrzej Targosz. These were posts about you, I remember well. Where Łukasz fell into my memory as the man who hit the router with a hammer. And I think it was the Cisco router. If you want, we can come back to it, but if it was traumatic, we don't have to. Anyway, since then, much has changed for sure, because it has been running for tens of years. So the first questions that open Łukasz, what does it say in the firewalls? Well, a lot has changed over the past 20 years in the firewalls. When I hit the router with a hammer, our great router, the Cisco 2500, to show that even if you lose your memory, it will work. The firewalls basically look at the packages and that's all they can do. They did it faster or slower. And today we have firewalls that, using various advanced techniques, including the favorite AI, not only look at the packages, the sessions, but also look at the applications and pull some conclusions there. Or they rely on the external devices to pull conclusions, block malware, make miracles and such things. And over time, of course, the hardware and program level of the firewall has developed in order for it to be as advanced and beautiful as we have it today. Exactly, in these firewalls, the things that are happening, I think they are probably coming out of the classic definition of a firewall that was still required in those times when you hit the router with a hammer. If you were to emphasize the two areas in which this change is the most dynamic, but with such a definition of where today's solutions in firewalls, I don't know if we can call it a new generation, because it is in the end already quite an old term, so maybe the newest of the new generation, where these solutions make the administrator actually have more rest, he can deal with other things, and everything is done on its own. I hope that there is not yet a magic button in which you click and all the necessary rules that the company should apply to the production magically appear. Yes, I think you're just looking at the slides then, of course, everything is possible, but in real solutions I think we have to do two areas today where there is the most action, right? The first area is the unification of everything we do in the context of such a traditional network security, and I'm talking about the network, because we will probably talk a little about the applications later. And this means the situation when one device, i.e. one solution, looks at many dimensions of the movement that we are receiving, is able to analyze what is in this movement from the perspective of applications under the IPS systems, decoding, decoding of the movement, and so on, and so on, and make some decision or pass the verdict proposal to some operating system. Well, this is the evolution of these 20 years, right? Earlier we had dedicated package firewalls, then state ones, we had separate IPS systems, and we had separate sandboxes that made the attempt to hide criminal programming. Now, all this has been integrated thanks to the technological progress, and it is kind of one black box. The second solution that is now slowly starting to get more and more attached to the so-called mainstream, well, this is the use of the marketing and technical speaking machine learning. In order for the firewall to make decisions much more complex than so far, it was possible. Based on the movement that is observed and the behavior of this movement, or the behavior of the users who generate this movement, in order to take off from the administrator as much as possible, as quickly as possible, to make various kinds of decisions that can stop the attack. And I'm talking here about two different aspects. The first aspect is something that I think is probably the best we can do, if not the only one in the world at all. This is the solution, or the attempt to solve the problem, relying on the fact that more and more movement is encrypted, actually the whole movement is encrypted. By buying the firewall, the user does not usually want to pay for the device that will decrypt the movement, and only after that the inspection of this movement was done. He just wants to have a device that investigates this inspection at the level to which he bought this device. So we came to the conclusion that we will, of course, participate in this race, based on the addition of another standards, such as the ELS-1-3, the new IPsec expansion, and so on, and so on. But on the other hand, we have to find a way to look at the year encrypted and make some decisions without decrypting this movement, because this allows us to save a lot of work. And the subject may seem funny, or even kind of unambitious, how can you look at the encrypted movement and say, "Oh, here is malware," but it looks a bit like magic, but we have a lot of success on this field. About ten years ago, we created such a solution that was addressed to the campus and exactly performed this operation with the help of such a disbanded system. That is, the end of its network, the movement was collected, and on the central station, all this was analyzed. There was a very heavy machine learning engine, and it fell into various concepts based on the model that was once trained. Of course, it was updated. But on firewalls, you can't do everything in 20 or 5 minutes, because then there is no sense in this activity. So for the last 10 years, we have done various kinds of work related to how to locate this topic on the firewall, and then on the firewall to directly place the model that will be the subject of looking at this encrypted address. And today we are able to, for the movement that goes through the firewall, encrypted with the appropriate level of confidence that this is actually this application, this operating system, say, "Listen, this is a movement generated with 80% confidence through Microsoft Windows, and with 95% confidence, this is a normal movement from Chrome to Office 365." However, what is more interesting is that in the same movement, we are also able to identify potentials of various types of passwords, or also small ones. Again, with different accuracy, depending on what application it is, how quickly it changes, it is different, but this is one aspect. And the second machine learning, using them on firewalls, is of course the protection of the applications, protocols and the behavior of the user who sends this movement through the firewall. Because regardless of whether you are doing sensitive things or not, in a movement that goes through the firewall, you will have to decipher it, and then determine whether the user who is currently confident with MFA in order to get access to the application, and now it suddenly starts sending some 500-megawatt applications by Google Mail to their friends, and if he still has to be able to do it, or maybe it's better to stop it and escalate the problem to some other team to make the decisions. From what you said, two questions immediately come to mind. You mentioned that analysis takes place on the device. And the question that is present is about the new NURD of various solutions with AI. This is whether all the data that are used to teach a model or to be processed by some artificial intelligence solutions, are data that are left within the company, within the organization that has such a solution. Is everything that is AI, machine learning or, as they say, more advanced ifov programmers, based only on components related to firewall, are left within the network? Do you use any network service where the firewall has to knock down somewhere in order to confirm something, check? I will answer this again. These are two separate questions. The first one, the so-called Cryptid Visibility Engine, because that's what we call on our firewalls, works autonomously on the firewall itself. On the firewall we set up a model, which is two or three weeks, we send an update to this model, you take it along with the updates of the signature, as it is normally done for the firewall, so you can do it for the environment such as AirGuard. And this model is simply perfect, plus it has its definitions of these encrypted applications in order to better recognize them, as it has already been trained by Cisco. All this activity is done by our TALOS, i.e. our Thread Intelligence network, which tells us to prepare the definition of threat for all Cisco products. And which, in turn, we make great reports related to threats on the Internet, so I recommend the analysis of these reports from the heart. Thank you for mentioning TALOS, it is a really great team, we do very cool things besides reports. They also train us, explaining to us that maybe it seems to us that this is the case, but it is a bit different with this threat, and so on, and so forth. I think it is, I will use my favorite quote, "The largest non-governmental organization of Thread Intelligence in the world today, i.e. more than 500 people who work only and exclusively with research and Thread Hunting all over the world, they help, for example, in Ukraine, actively. This is probably the first time when Cisco said officially that it is engaged in some cyber operation, which is potentially directed at the defense of another country or against another country." And so on, and so forth. So TALOS builds this model, trains it on the data it has access to, and again TALOS is the only organization in the world that has access to all our data. They maintain a good reputation all over the world, they collect information from other companies, from other organizations, and they only have access to data that our products collect. For example, our umbrella, i.e. our security solution for DNS. It collects questions, but they can look at it and say, "Listen, now we are looking for threats coming from the fact that the umbrella has learned something or we are receiving such a different move." And from this, for example, some updated force will come out to describe the application that we have then on our firewall. So all this is working only on the firewall, and there is no need to contact the wall, so this privacy is preserved. All the solutions in which we need to have a trained machine learning engine, which then is a real engine, based on these large language models, require this access, right? We do not offer solutions for now, such as those that we install with the client, they are on their own, they are these engines, they can chat with us and introduce some changes or suggest some changes. And here the need to ingress is. And this is the firewall part. We also have new solutions that we will probably talk about later. And there are also some elements that can work in terms of machine learning, without the need for sending even telemetry to the CIS cloud. But even the components that are located outside the organization, infrastructure of the organization that uses the product, they are in your cloud. These are not the solutions in the third company, such as, for example, the most famous OpenAI. I am asking here a real example, when sending some questions according to the licenses is used later for training models, which creates some kind of risk and we observed it in the past, the escape of these data at the least awaited moment. Yes, well, there are also a few words to explain. CIS has a few different walls. We have walls that are currently only dedicated to specific services, but we are trying to resign from that. We have walls that CIS has reserved in the third company, for example, in AWS in Google, for its needs. And they meet the highest level of certification regulations, because there, also, of course, in the isolated so-called tenants, there is work for various types of organizations that do not want to know that something is being done for them, right? And we also have walls that we use in such a model as you said, for example, you could imagine such a language model, which would be asked by OpenAI, by API, but it would look like CIS would talk to you directly. And now, when it comes to what TALOS does, TALOS is only used to connect our own walls. They release these data anywhere, with many different reasons, but the main one is safety, we do not look for it, right? The truth is, of course, there is a lot of discussion around that the power of walls and the power of machine learning is about the fact that the more you have data, the better you can lead the application, and the better you can identify the threat. But unfortunately, here we will have to go for some compromise, because yes, but we cannot mix our users' data, and then risk that some data will escape, because someone will find out who did it, or how it was trained. And here I have one more question, because you mentioned that the signatures that are sent to the device, they are controlled by this engine, they improve this model about the new model. And what if I am a very specific organization that has such a, I would say, a daily movement, and I would like to use this model to myself, do I have the opportunity to insert some rules, including training in learning this model locally? Not yet, but we are planning it on the road. For now, it is evident from the user's perspective, such as the ANSA-PROVICE engine, it means learning from what was received from us and the end. Eventually, I observe various anomalies, which you can identify as an exception, for example, that the movement, even though it was recognized as malware, was not blocked, or even though everything was transferred or you just want to examine it with the help of a normal engine. However, in the meantime, we also want to give the user the possibility of the ANSA-PROVICE model, that is to say, based on feedback from the operator, you will start to learn that this is a new application that you should recognize in this context, and this solution will be more mature. So this is the part of the disease that is completely isolated. However, the experiments that we are doing today with some tools, for example, we have a solution called AI Assistant, which is generally available for all our security solutions, this is a solution that works just based on OpenAI, i.e. with the help of API, it is connected to OpenAI, despite the fact that the CISCO cover is in the front, it is used from the backend that is learning. Again, we have it signed with Microsoft with the appropriate contract for the isolation of these data, but it can be different, right? Yes, anyway, it can be broken everywhere, this is just a matter of how much you want. Exactly. Now, after finishing the topic in Firewall, one question that came to my mind. The installation of Firewall in the organization practically never ends on one device. And there is more. Is there any communication here between these solutions? I do not want to use these words, because it is speculative, but it will probably know what I am talking about, chaotic. One Firewall will learn a little differently, the other will learn a little differently. And somewhere at the end there is this poor administrator who has to log in on each of these screens and do some fine-tuning there. You mentioned earlier that these systems can give information somewhere. But does this mean that if someone wants to enter the solutions that we have talked about today, is it enough that they buy Firewall? They have to buy something else. Yes, again, very good question, thank you very much. Starting from the beginning, you can use Firewall as a separate island. And most of our clients, of course, do it. Sometimes they use the active standby model, so it has two, but one does not work. Well, it is a bit of a loss, as if, of course, we offer on our Firewall such a possibility of active-active work. It is cool to scale up with every device you add. However, somewhere there must be a system for these Firewalls. It can be on Firewall itself, it can be centrally located in the client network, i.e. in the form of a physical server of servers or a virtual machine. It can also be in a cloud as a virtual machine, i.e. you can outsource it, for example, someone else can order this Firewall, saying that it is not in its infrastructure. Generally, today, I would say that most of our clients use physical servers or Firewall operations, however, it is slowly changing. This model of using virtual managers for Firewall is once again more popular for various reasons. We also have our own service, which also works in the AWS cloud, as if it is hosted in the AWS cloud, which is such a SaaS, i.e. a service software, i.e. we give you a panel that looks exactly the same and is exactly the same as the order system, and it lives in the cloud held by Cisco, updated by Cisco, and from this cloud you can order your Firewalls. And the majority of these functionalities that require the functionality of AI require this third approach, i.e. the demand of this service offered from the cloud, because behind this engine is the entire processing of AI. However, coming back to what you asked, whether they will, or will they start learning in an uncoordinated way and create a house, because one Firewall, which is better created, and the other today, has not yet learned it, so it will not be created for a long time, regardless of all the stories related to AI, machine learning, and other mechanisms. Our Firewalls talk to each other and talk to the order system, and also talk to the system we use to store information or such a central system to store information of the same size, which we call ICE, Identity Services Engine. This is a rather popular system, because there are customers who do not use our Firewalls, but use the ICE system. In order to simply have it, because they like the interface, or they just like it, right? And now ICE, using a special protocol that we first created, and then we created it and pushed it to standardization, i.e. the PxGrid protocol, communicates on both sides with all the devices that it orders. There may be exchanged information not only about this, okay, this is the user, this is his challenge, I will answer you with a token or anything else, there may also be sent information under the title, listen, and this is a new description of threat, or this is something that I blocked and I completely do not understand it, but maybe someone else will understand it and it will be able to take care of it. So we are able to create such a network of exchange information. The Firewalls system itself is from Pradawian time, because it is still a solution that was once created by the management system and the threat of the Sourcefire company, which we bought and then integrated the PSO Parts OSNOT engine with our solution. It also correlates various types of events and also looks for threats. In other words, it is good to say that in such a case, since this is a new protocol or a new rule that should be used for the rest of the Firewall, I can threaten it. And finally, so that this is not too small, we still have a solution that will be able to be a broker of information between any other system that works somewhere. And in particular, we use it, for example, to the cloud systems. In the Firewalls, traditionally, when you create a rule, you say, I would like to secure the movement of IP addresses or from this host group that has such IP addresses or other attributes, whatever you identify, or from this user to this user. And maybe I'm not interested in what is underneath, because we are trying to get away from this network layer and from the side of who really communicates. The problem with cloud environments is that naturally we use them in situations when we have to scale up or the overall burden of our cloud is quite dynamic. And it may turn out that suddenly there are 20,000 IP addresses that are still based on data and one, but in a moment there are only four IP addresses. And it would be nice if Firewall knew all the time that these are the same IP addresses to a host group that we trust or not, and which is responsible for the set of rules that we should take. And this is the third fragment of the component related to collecting information about the identity that we are able to integrate and potentially connect to Firewall. Of course, this is happening with some delay, like one or two seconds, but in general it is almost the same. More or less with the speed in which the cloud changes. A lot is happening, a lot of information is being exchanged. You have used it several times in a row that you do it yourself. The question is, will it be exciting? Does it mean that the administrators should feel threatened because they do not need their data? Not necessarily. All the time, all the discussions that we have and we also have interesting discussions around AI, even, which seem to be the most dangerous for operators, are very strongly directed at the fact that the administrators and operators of these systems can finally start doing things that they should actually do. That is, looking for threats and potentially deciding how to neutralize these threats. And not dealing with the fact that now you just have to add another IP address to check if this rule is still an actual rule, because maybe you need to change it to some other rule, or you need to have five other, which will also create a group of rules, which is a bit of nonsense, right? And today, when we look at it apart from the dedicated teams in Security Operations Center, as you say, the administrator of Firewall deals with this rule, that is, to adjust, do the tuning, change something and get the attention from the customer I am talking about. From the smallest companies, five, ten changes to Firewall, the biggest companies can have 24 hours to get continuous changes to Firewall, only resulting from the fact that this application is no longer working here, someone wants to update something here, someone is doing some tests here, so you have to change something, and basically it is not even known if this rule works, so maybe we would open wider and so on, and so on, and so on. These communications that we receive from the customers does not have any value and not a stupid click on the screen. Right. The value of the work means that in today's organization such awareness and modernity does not only focus on filtering the movement, I will say so colloquially in the flight, on the way out to the network, on the way out to the network or on the network, but I also look at it, and it is much more and more often what happens at the endings. So you have such a cool solution which is called Hypershield. What is it? Yes, this is our youngest voice of the youth, when it comes to how microsegmentation is done, and I use it for the latest technology, i.e. IBPF. This is a solution that we introduce, among other things, because when we look at the history of the last 20-30 years, then basically you can get the impression that we are constantly proceeding according to such a model of sinusoid. On the X axis we have the time, and on the Y axis we have where more safety is taken, and on the one hand it can be extremely focused on the final station or the final device, on the other hand, in an extreme case, it can only take place on the network, and then we say, we are not interested in these endings at all, we will do everything and we will be safe. Of course, the golden middle is inside, because as the truth of life shows, safety must be taken everywhere. But the truth is also that in the last few years, the topic of microsegmentation has started to be very important, because there has been a network like a container network, more and more, of course, today we are all using a virtual network, simply, and filtering the movement between two virtual machines or two containers starts to be more and more problematic if you have to pull this movement into a virtual, quite well integrated with this virtual world and turn this movement back just to say, okay, this movement can pass, not saying that it leads to additional delay. And what we did looking at first these trends, secondly, also on the second kind of rough look at how we add security in the network and application environments, all these devices and solutions we talked about today generate huge tons of data. These data can be used to use this type of machine learning system to start learning what is normal or what should be preserved in our databases and accepted as a normal behavior. And what should be meant as something evidently or simply defended. And looking at all these things we did, plus the imperfections of traditional network solutions, we came to the conclusion that it would be nice to expand this layer of unified not only network firewall, but also to solve the security of the host itself, the end user or the server. And we decided to implement this new technology called EBPF, which allows us to look deeply at the kernel of Linux, although Microsoft also said that in Windows the infrastructure to EBPF will appear in a while. And EBPF is a mechanism which allows us to look very low level at what kernel does, from application operations to network operations, and of course with some very large network, but with a rather large network, to make some kind of decision what to do next. It seems that this is a quite safe technology, because in every situation when we set up some agent, especially when this agent is set up in kernel, we know that there are companies that have suffered a lot recently. They did not test at the end of certain solutions that were directly on the highest level of trust. Therefore, we use the fact that EBPF has a whole group of solutions that protects even an evil programmer before introducing to kernel solutions that could destabilize this kernel. However, because we are in the middle of what the operating system does, of course, we have access to practically everything. And here, instead of doing everything manually, our colleagues who started this product, came to the conclusion that from the very beginning the telemetry, which such an EBPF agent could carry out on the outside, can be used to train various engine engines. And this, again, makes us able to achieve various interesting effects. For example, we are able to hide threats that are not yet described, which are commonly known, but are evidently preserved by such hosts or some application, which should not be done. Trying to simplify it very, very much, we can say that we are finding a new host of the PSA, but really looking at what we can use this solution and what are the applications, maybe I'll tell you about it in a moment, it looks like it's actually a step in the right direction and it is needed so that our security policy that we would like to be the same for all types of devices, can be used in the whole company without problems and automatically. Because as you said, implementation of firewall sometimes takes a long time in big companies these are times, like months or even years. And here we have a solution that we are able to start very quickly and effectively implementation within a few days. So is this a solution for all types of final stations, both mobile and desktop? No, no, no, no. Hypershield is such a solution which for now is only intended for servers and actually hosts that do some tasks for us. And as I said, Linux is this operating system in which the IBPF is today native. We can also work on Windows but it requires installation of plugins so if there is some system of orchestration on existing Windows systems you can install these IBPF plugins and then we have similar possibilities. So here the idea is that we focus rather on where the service work takes place, so probably on some data center or at least on a distributed working environment. Of course, you can potentially start having such an application on the phone if it is to protect something on the Linux kernel. But these are not cases where we focus experimentally, it is possible. In fact, it also has a package of solutions to mobile devices which is true under a different name but it would probably be possible to talk to each other there and tell you about the information. I think that I know that now such an internal discussion has begun in the hands of Hypershield and this entire scale is kind of an application i.e. the IBPF has the use of Linux kernel and many of our products are based on Linux. It is also good that we can use it to protect our products internally. So before the situation when we set up a firewall, there is a loop connected with SSH and someone gets into the device through this loop and then he starts doing bad things. Potentially, you can imagine that such a Hosti.ps could stop it. We had examples of such integrations a decade ago, more or less. We had a communication system on which our Hosti.ps worked and then it stopped. After there was a loop in this system, it was created on the Internet because the client wanted it so much and suddenly it turned out that it is a potentially compromised Host. So listen, such a question at the end of the day which is certainly about the majority of people who listen to us and who already had smaller or larger reports about your solutions to your infrastructure. It is known that this device rotates, it changes. How would you be able to pass your professional advice from such experience? What and in what order? What and how to replace it quickly. Considering that the budget for investments related to network solutions in the company appears. Because what I hear more and more often on various conferences is that there is a paradox of choice, diversity of solutions. The money companies have are one supply of one, the second supply of the second supply. It is known that this unification would be beautiful and some people can afford it. However, often we lack some solutions of the given supply and we have to make such delays. If we look at such a typical company, which has these delays and would like to replace them for something newer, let's be honest, these older solutions still work. These are not rooters of the link, which are outside the time of supporting and give up on nothing and the manufacturer does not blame them for any mistakes if it was a year in 2023. Then what would you start replacing, looking at modern technologies and the fact that we are talking about this egg so much let's say, I don't know, from the year when effective uses actually work, I would say, correct if I'm wrong, for half a year they work functionally that I can look at it and say yes, in the end it makes something sense. Yes, this is very good but also a very complex question. If we have to share the answer in 60 seconds, then I would probably start from Banauw and Ogólników, look what you have in the company is the oldest and in the first place requires replacing, because maybe you don't have any support for it and this support can sometimes be useful. Plus, if you don't have support, then probably the solution is as you say, not broken, so in a moment someone will give you this device or the solution will go into the company. The core solution today, in which this AI element is functional, in my opinion, it is still rather not a device, but a solution for supporting people's work, i.e. any kind of system like manage-soc and so on and so on, where the fact that the user is already infiltrated by various kinds of information can be of great value in order to be able to deal with the most dangerous topics. And then it would probably be good to analyze what your security policy looks like and what you should mainly protect in the company and start focusing on these areas. Because today we talk a lot about how great Firewall is and how Hypershield can be used for supported data center protection. And probably in the data center you have the most of your intellectual value in your own business, but if someone betrays you, I don't know, the customer base you have on your computers, for example, Mrs. Stasi, which you often hear in these podcasts then this is a different problem, the company has a problem. So I would focus on certain things that will have a real impact on whether the company will be able to maintain its business. And this can mean a huge pity, but we also have this type of solution that you choose in the first order a solution for the safety of hostages or endpoints or mobile devices and you invest in it in the first order. But probably only then, when people who deal with security will have a comfortable job and they will be able to say, "Yes, now I know what is going on in the network, in our applications, I know what threats are approaching us and what potentially can happen in our doors and we will have to deal with it. I have this on my mind. That's right, the question is a lot, we are running out of time, but is there anything else that you would like to share or that we haven't talked about yet? It would be helpful for people who listen to us and who are interested to increase the security of their infrastructure, understood not only as a seat, but just as you mentioned, as endpoints that come from desktops, from mobiles or anything that is now connected to the network, and many of these so-called Internet things are connected. Yes, yes. I think that such a universal advice which is very simple that many of the decision-makers often miss it or, for example, they don't want to sign a budget, these are solutions to ensure your network visibility. These are very different solutions from the simplest ones that you can construct yourself, i.e. just set up a port that will sniff out the whole movement from your network, which you also have to check if it will be compatible with your security policy, but it will allow you to see how you have the influence of the network movement, which applications with other applications despite the fact that, theoretically, the documentation is written that it should not or that users are making the suspicion of a large number of data in short or long sessions, because these are the tools that give the first line of defense, because you see different things. Maybe you don't have these simple or easy tools for their stopping, things that will take place at the level of the threat, but at least you will be aware what is happening in your network. The worst situation for people who have experienced breaking this situation is that they have conducted data for six months, and I didn't know anything about it, because we have all the rules and the software has even support from the manufacturer. And only then, look at the rest of the mystery, I brought a book which, I don't know if it was translated in Polish, but originally it was called "Range". It's called "Range". And the author says that it's good to have very rich experience even coming from other areas, to deal with problems of very narrow areas. So people who focus only on one area, they will not be so flexible to deal with problems of other areas. And this is a beautiful analogy to what we have today in the network. Namely, a lot of breaking happens only because we forget about boring, best practices. The first best practice I have not said is visibility, so if you do not see it, how will you know that something has been stolen? Well, hurry up, or they will find out later. Exactly, yes, but it's later. And the second rule is to try to segment those people you protect and users as well. Because there is no reason for users to communicate without any need directly with each other, maybe with a server, but you can try to protect yourself and so on. A lot of breaking ends with such a recommendation, if there was a big segmentation in the network, breaking would not have happened. A lot of French attacks end with such a recommendation. Such a recommendation would not have happened at all. Such tools as Firewall, such tools as Hypersheet, are tools that serve to make such a segmentation more automatic and possible. And this is the next step when you can start to design how to protect yourself in the network. What I encourage very much. Great, and with this optimistic accent and a wide range of important advice, under which I also sign up, I think I will say goodbye to you. Thank you, Łukasz, that you devoted your time to us. I hope that we will meet again because you are also an expert in protocol routing. Today, you mentioned them so gently in the context of virtual machines, but I hope that this topic will be given to us once again. Because there are also interesting things that also serve safety. But this is already the other time. We wish you a pleasant evening, cleaning, riding a bike wherever you heard us. Bye! Thank you very much, bye!

Podcast Summary

Key Points:

  1. The interview discusses the evolution of firewalls over the past 20 years, emphasizing advancements in security devices like firewalls and the integration of AI.
  2. The use of machine learning in firewalls enables complex decision-making based on observed data and user behavior, enhancing threat detection capabilities.
  3. Data processing and model training for AI solutions on firewalls are done autonomously on the device, ensuring privacy and security.
  4. Communication between firewall solutions in an organization is facilitated through systems like ICE (Identity Services Engine) and the PxGrid protocol.

Summary:

The interview delves into the transformation of firewalls over the last two decades, highlighting the shift towards advanced security measures and the incorporation of AI technologies. Machine learning on firewalls enables sophisticated threat detection by analyzing data and user behavior. Data processing and model training for AI solutions occur locally on the firewall device, ensuring privacy and security.

Communication between firewall solutions within an organization is facilitated through systems like ICE and the PxGrid protocol, allowing for seamless exchange of threat information. The interview underscores the importance of evolving firewall technologies to combat cyber threats effectively while maintaining data privacy and security.

FAQs

Firewalls inspect network packets and have evolved to analyze applications, sessions, and use advanced techniques like AI for better security.

The two main areas are unification of network security functions and the use of machine learning for more complex decision-making.

AI and machine learning are used to analyze encrypted traffic without decryption, identifying applications and potential threats based on behavior.

Training and data management for machine learning in firewall solutions are done locally on the device, ensuring data privacy and security.

Firewalls communicate with each other, central management systems, and identity services engines to exchange information and ensure coordinated security measures.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.