This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Change Your Perspective: View Your Network Like a Hacker

Download resources

About this session

Scott Register, VP of security solutions at Keysight, argues that defenders spend all their time watching what they block and almost none on what they are missing, and that most breaches come from misconfiguration or overlooked alerts rather than failed products. His remedy is breach and attack simulation: Keysight's Threat Simulator safely emulates the full kill chain (malicious attachments, malware through firewalls, web attacks on cloud WAFs, endpoint malware and lateral movement) using real tactics mapped to MITRE ATT&CK, then hands back remediation steps and indicators of compromise to tune your SIEM. It is a SaaS product with lightweight agents that only talk to each other or to a 'dark cloud' of attacker instances, so no real systems are hit; assessments auto-update and can be scheduled continuously. A product manager, Vivek Delekar, demos two scenarios: a WannaCry external kill chain against a Palo Alto and Splunk sandbox where remediation lifts the detection score to 100%, and a MITRE lateral-tool-transfer test blocked by a Windows Defender firewall rule. Register contrasts the approach with periodic pen testing and full-time red teams and closes on ThreatArmor, a threat-intelligence gateway that blocks known-bad connections to shrink alert volume.

We all spend a lot of time and a lot of money trying to manage risk. We buyfirewalls and NDR and EDR and maybe even XDR, and we buy a SIEM to pull all the
logs together into one place we can’t keep up with. We run Vulnerability Assessments and get thousand-page reports on things we probably don’t have time to fix. We pay penetration testing companies a small fortune to find the holes in our network we really thought we’d closed. We hire as many SecOps staff and security analysts as we can afford, and we try to keep them long enough to get something done before they move on. Then we sit back and look at the logs of all the stuff we’re blocking, and we wonder: What are we missing? What aren’t we seeing? Hackers can be in the network for weeks or months without detection –are they here now? All these headline breaches – they all deployed similar
security technology and staff. If they got hacked, why won’t I? At the end of the day, am I safer than I was yesterday? Last month? Last year? Well, now there’s a better way. What if you could see your network the way an attacker sees it? And what if you could do that every day, and find and prioritize every security gap in your network in real time? With Breach and Attack Simulation, you can do just that. Join us for this webinar and learn how.  

Key takeaways

  • Stop measuring security only by what you block; look at what gets through, since most breaches stem from misconfiguration or missed alerts, not failed products.
  • Use breach and attack simulation to safely emulate the full kill chain continuously and get a measurable before-and-after security posture.
  • Re-test after every major change (cloud migration, firewall upgrade, new endpoint tool), because default configurations and cloud WAFs behave very differently.
  • Feed the indicators of compromise from each simulation back into your SIEM so the same attack is detected next time.
  • Running real attacks trains analysts to recognise an attack live instead of only spotting it in forensics after a breach.

Speakers

Scott Register
Scott Register
Vice President, Security Solutions · Keysight
Scott Register has more than 15 years of experience leading product management and go-to-market activities for global technology companies. In his current role, he is tasked with bringing new security solutions to market across Keysight’s broad… Read moreRead less

Scott Register has more than 15 years of experience leading product management and go-to-market activities for global technology companies. In his current role, he is tasked with bringing new security solutions to market across Keysight’s broad solution portfolio. Prior his current role, Scott was vice president of product management leading the development of new Ixia products in the areas of Security, Virtualization and Cloud. Earlier, Scott spearheaded the company’s visibility product line. Prior to Ixia, he led product management at BreakingPoint Systems where he was responsible for the industry's highest rated network performance, security, and resiliency testing equipment, before the company was acquired by Ixia.

Resources

Tags

More from GoSec 2021

Also from Scott Register

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.