S6E22: Daniel Shechter - Application Detect & Response (ADR)
Jul 7, 2024
auto_awesome
Daniel Shechter, co-founder of Miggo, shares his journey from the Israeli Defense Forces to pioneering Application Detection and Response (ADR) in cybersecurity. He explains the increasing complexity of application security in modern tech environments, including Cloud and microservices. Shechter addresses the struggle organizations face with vulnerability overload and offers insights on balancing proactive security with operational realities. He also highlights the critical role of AI in enhancing cyber resiliency against evolving threats.
The concept of Application Detection and Response (ADR) is crucial as it addresses the limitations of traditional security measures against evolving application-layer threats.
Organizations can better manage overwhelming vulnerability backlogs by utilizing ADR to prioritize and mitigate vulnerabilities based on real-time operational insights.
Deep dives
The Evolution of Application Security (AppSec)
The rise in cyberattacks targeting applications necessitates a distinct focus on Application Detection and Response (ADR) within the cybersecurity landscape. Traditional security measures such as Web Application Firewalls (WAFs) and Endpoint Detection and Response (EDR) have proven insufficient against evolving threats that bypass existing controls. As cyberattackers adapt to exploit the application layer, understanding the complexities of modern applications—including their distributed nature and the growing reliance on external components—is crucial. This underscores the need for a paradigm shift in which security practices evolve to address the vulnerabilities introduced by these changes in application development and deployment.
Combining Shift Left and Shift Right Security Approaches
Focusing on the runtime environment in addition to pre-deployment measures is essential for comprehensive application security. While shift left strategies emphasize early secure coding practices, they often fall short in anticipating real-world attack paths that can only be identified during runtime. Integrating operational security measures with development processes allows organizations to effectively verify how applications function in production, thus enhancing their security posture. This combined approach emphasizes the importance of real-time monitoring to swiftly detect and mitigate potential threats.
Managing Vulnerability Backlogs with Contextual Awareness
Organizations face overwhelming vulnerability backlogs, often numbering in the millions, complicating their ability to prioritize critical security issues. By implementing an ADR approach, security teams can gain essential insights into their applications’ behavior and the potential attack scenarios they face. This methodology supports prioritization and effective mitigation of vulnerabilities based on real-time operational context, rather than a purely theoretical risk assessment. Consequently, integrating observability tools enables teams to maintain situational awareness and react proactively before exploits can manifest.
- For folks not familiar with you or the Miggo team, can you tell us a bit about your background?
- How do you define ADR and why do you think we have seen the need for this new category of security tooling to come about?
- Most organizations are struggling with vulnerability overload, with massive vulnerability backlogs and struggles around vulnerability prioritization. Can you share some insights on how you all tackle this problem?
- We're increasingly seeing the AppSec space become more complex, with Cloud, API's, Microservices, IaC and more. What do you see as some of the most critical trends in the AppSec space currently?
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode