Change Your Perspective: View Your Network Like a Hacker
Download resourcesAbout this session
Scott Register, VP of security solutions at Keysight, argues that most organisations buy layers of security tools yet cannot answer the one question the spend was meant to settle: am I safer than yesterday? His first half deals with non-traditional devices, badge readers, webcams, printers, PLCs, cars, whose operating systems and exposures are a black box, and describes three kinds of testing: conventional vulnerability assessment for known CVEs, weak ciphers and guessable passwords; protocol fuzzing, which injects malformed handshakes and out-of-order packets to crash or hijack devices, as a university team did on a billion Bluetooth LE devices, prompting an FDA safety notice; and cloud posture assessment. The second half makes the case for breach and attack simulation: safely replaying real attacks, phishing, malware download, lateral movement, exfiltration, across the production network so firewalls, EDR and SIEM rules are exercised, drift is spotted daily and analysts learn what an attack looks like before a real one, illustrated by a WannaCry test that exposed a live infection in a lab. Q&A covers safe testing, allowlisting, tunnelled traffic, pen testing and serverless.
We all spend a lot of time and a lot of money trying to manage risk, while deploying new IOT devices with little more than wishful optimism. We buy firewalls and NDR and EDR and maybe even XDR, and we buy a SIEM to pull all the logs together into one place we can’t keep up with. We run Vulnerability Assessments, and get thousand-page reports on things we probably don’t have time to fix. We pay penetration testing companies a small fortune to find the holes in our network we really thought we’d closed. We hire as many SecOps staff and security analysts as we can afford, and we try to keep them long enough to get something done before they move on. Then we sit back and look at the logs of all the stuff we’re blocking, and we wonder… • How are those connected devices expanding my attack surface? • What are we missing? • What aren’t we seeing? • Hackers can be in the network for weeks or months without detection – are they here now? • All these headline breaches – they all deployed similar security technology and staff. If they got hacked, why won’t I? • At the end of the day, am I safer than I was yesterday? Last month? Last year? Well, now there’s a better way. What if you could see your network the way an attacker sees it? And what if you could do that every day, and find and prioritize every security gap in your network in real time? By thinking like a hacker and attacking your own devices and networks, you can put that power in your hands. Join us for this presentation and learn now.
Key takeaways
- Test every connected device before deployment with vulnerability scans and protocol fuzzing; the flaw is often in the off-the-shelf communication chipset you inherited.
- Check devices for open debug interfaces such as Android ADB, deprecated TLS versions and expired certificates, and tune detection rules for exposures you cannot patch.
- Run breach and attack simulation on the production network with agents that only talk to each other, so firewalls, EDR and SIEM rules are actually exercised.
- Repeat the simulations daily to catch drift from new networks, acquisitions and zero-days; a twice-yearly pen test only gives a snapshot.
- Fix internal visibility blind spots first: lateral movement succeeds where east-west traffic is not monitored.
Speakers

Scott Register has more than 15 years of experience leading product management and go-to-market activities for global technology companies. In his current role, he is tasked with bringing new security solutions to market across Keysight’s broad… Read moreRead less
Scott Register has more than 15 years of experience leading product management and go-to-market activities for global technology companies. In his current role, he is tasked with bringing new security solutions to market across Keysight’s broad solution portfolio. Prior his current role, Scott was vice president of product management leading the development of new Ixia products in the areas of Security, Virtualization and Cloud. Earlier, Scott spearheaded the company’s visibility product line. Prior to Ixia, he led product management at BreakingPoint Systems where he was responsible for the industry's highest rated network performance, security, and resiliency testing equipment, before the company was acquired by Ixia.
