Security Confidential S11 E1 Huxley Barbee

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Huxley Barbee. Huxley is a Security Evangelist at runZero (formerly Rumble Network Discovery), a company founded by Metasploit creator HD Moore that helps companies discover unmanaged devices for asset inventory. Huxley previously worked for Cisco, Sparkpost, and most recently, Datadog – where he formulated the Datadog Cloud Security Platform. He has spent over 20 years as a software engineer and security consultant. He attended his first DEF CON in 1999 and holds both CISSP and CISM certifications. On top of that, he’s also an organizer of ⁠BSidesNYC⁠.

00:00 Introduction

00:15 Our Guest

01:00 Huxley’s Origin Story

02:27 Proactive Security, Risk, and Asset Inventory: What’s the connection?

04:56 Using the right tools

07:17 IPv4 and IPv6

11:15 What do you need in terms of an ACCURATE Asset inventory?

21:56 Asset Inventory Playing a Role in Ransomware

26:17 Connecting with Huxley

Transcript

Rory Meikle (00:06.901)
Good afternoon, everyone. Welcome back to another episode of Security Confidential. I’m your host, Roy Meikle. With us today is Huxley Barbee. He is a security evangelist at RunZero, formerly Rumble Network Discovery, a company founded by Metasploit creator, HD Moore, that helps companies discover unmanaged devices for asset inventory. Huxley previously worked for Cisco, Spark Post, and most recently, Datadog, where he formulated the Datadog cloud security platform.

Huxley Barbee (00:35.982)
Thank you.

Rory Meikle (00:36.113)
He spent over 20 years as a software engineer and security consultant. He attended his first DEFCON in 1999 and holds both CISSP and CISM certifications. On top of that, he’s also an organizer of B-Sides NYC. Huxley, thanks for joining us.

Huxley Barbee (00:54.634)
Thank you for having me, Rory. Happy to be here.

Rory Meikle (00:57.385)
Absolutely. So first question for you, what is a security evangelist exactly?

Huxley Barbee (01:04.65)
Yeah, so a security evangelist is somebody that has placed multiple hats really. So you need to have a technical background in order to do it. And you’re frequently having conversations with customers, but also the public. So there’s definitely an element of public speaking in this particular role. And as you’re speaking with the public and customers, you’re also bringing that information back to help shape the roadmap.

for whichever product that you’re evangelizing. There are some places where, or some companies where they call this role field CTO. You might’ve heard that before as well, but it’s essentially the same thing. You’re sort of like a spokesperson, but also the type of person that’s gathering feedback from customers and the public.

Rory Meikle (01:55.305)
Gotcha, kinda working as the middle man.

Huxley Barbee (01:57.982)
Yeah, well, many of us are, of course.

Rory Meikle (02:01.939)
Right. Very cool then. So how did you get from where you started in your career to where you’re at now? What was kind of your road progression?

Huxley Barbee (02:12.19)
Yeah, you know, there was a time in my career when all I ever wanted to do is just be in front of the screen. Um, but you know, as, as you get older, you mature, you gain more experience, you are called upon to do more than be hands on keyboard. And as I sort of came out of my shell in terms of doing presentations and speaking with the public, my role naturally gravitated.

Rory Meikle (02:17.973)
Mm-hmm.

Huxley Barbee (02:42.098)
in this direction. I also ended up having more responsibilities in my job where I had go-to-market responsibilities. So as somebody who’s leading a consulting practice at Cisco, there’s a certain amount of public education that you have to do for the services that you provide. And so that was another thing that sort of propelled me in this direction. And happily, I enjoy what I’m doing here.

Rory Meikle (02:50.665)
Okay.

Huxley Barbee (03:10.442)
speaking on this podcast with you is part of that evangelism responsibility.

Rory Meikle (03:15.733)
Absolutely, bringing the information more public, reaching more of an audience.

Huxley Barbee (03:20.99)
Yeah, yeah. And sometimes it’s a more technical audience, sometimes it’s less. So that’s where the, the technical background comes in.

Rory Meikle (03:30.049)
Okay, now that’s awesome. So proactive security, risk and asset inventory. What is the connection between those three facets of security?

Huxley Barbee (03:41.058)
Hmm, that that is a good one. I would say. The bedrock of any. Security program. Is acid inventory. And it’s not. It’s not something that I’m just saying. It made up out of thin air, but if you look at the CIS critical security controls, right? This control number one. If you look at this CSF, it’s also one of the core core components.

Rory Meikle (03:53.545)
Okay.

Huxley Barbee (04:10.73)
But you know, if, if you’re going to go and protect something, you, you need to know about it plain and simple. So when you’re, when you’re talking about proactive security, you cannot be proactive without a good asset inventory. If, if when you are compromised or if a device is compromised and your reaction is, Oh, what is that? Then you’re on the back foot by definition. It shouldn’t, you can only be reactive. If.

when a device is compromised and you said, and your reaction is, or your question is, I wonder who owns that thing? Like what is the function or what is the value this device provides to our business? Then by definition, you’re going to be reactive. A good asset inventory allows you to become proactive. I’m not saying that that good asset inventory is sufficient for a proactive security program, but I’m saying it is necessary. There may be other components, other…

tools or principles that you need to apply in order to have a proactive security program, but definitely asset inventory is a part of that. And the third part of your question, risk, risk is all about management of that risk, right? Risk in a vacuum doesn’t really mean anything. It’s all about how you’re managing that risk. And risk management is necessarily a proactive activity. Like nobody’s matching risk reactively.

There’s no such thing. When you’re reacting, you’re fighting fires and running around with a chicken with his head cut off. Like that’s not risk management. So if your goal is to manage risk, you need to have a proactive security program. And a bedrock component to that is good asset inventory.

Rory Meikle (06:00.009)
Right. When you are working with someone for the first time on this, do you find that this is kind of a newsflash to them? They really haven’t thought of a live asset inventory system or tool as a critical part of their security that they’re trying to build out.

Huxley Barbee (06:16.906)
You know, more and more I find myself preaching to the choir on that point. But what is a surprise to folks is that the current tooling that they use for asset inventory or as discovery isn’t really covering everything that they need. So there’s this, I don’t know, maybe it’s cognitive dissonance or something else, but folks believe in asset inventory, but at the same time, they don’t see.

Rory Meikle (06:22.919)
Okay.

Huxley Barbee (06:46.55)
that the things that they’re doing are very, very reactive, that there’s actually a better way, that if they had different type of tooling, that they can actually do a lot more.

Rory Meikle (06:58.045)
So what can you explain to us kind of what you see as the tooling that they’re think is doing a good job for them and then what you bring to light as far as what they need to upgrade to.

Huxley Barbee (07:09.098)
Right. So funny enough, I often hear folks say that, Oh, yeah, acid and Tori is so important. It’s great. And I have my EDR for that. Another one would be my vol I have my vault scanner for that. I’ve also heard. Well, we have these things on spreadsheets and I, and I’ve also heard, I’ve also heard, I use a knack for that, right?

Rory Meikle (07:32.755)
Classic.

Rory Meikle (07:37.237)
for a while.

Huxley Barbee (07:39.426)
And, and the fifth one would be CMDB. Right. But the fact of the matter is none of those really solve the S and inventory problem. It might have 20 years ago. It might have 20 years ago when you and I were both sitting in an office every day and you know, as, as a security team member, your job is to protect the laptop or the server room, the servers in the server.

Rory Meikle (07:43.902)
Okay.

Huxley Barbee (08:07.97)
But these days that landscape has completely changed. Right, we have devices maybe still in office, but in our remote employees homes, in the cloud, our factories are now connected to the internet. We have all these smart devices, IOT devices that are on the network doing who knows what. I just recently, there was one recent scan that we did where we found a photo frame connected to the network.

of all things, right? So the things that we protect are not the things that we protected 20 years ago. And some of these other approaches that I just mentioned, the five, this tooling might’ve worked back in the day, 20 years ago, but it’s completely unsuitable for the reality of most organizations today.

Rory Meikle (09:00.593)
Yeah, that it makes a lot of sense. I mean, I think the whole work from home and how advanced technology has become and integrated into every aspect of the business is obviously your asset inventory is going to have to change to from a spreadsheet to something a little bit more intrusive and it gives you more visibility into what’s going on exactly.

Huxley Barbee (09:21.718)
Yeah, yeah, absolutely. I mean, spreadsheets may be okay for like a five person in the accounting office, but that doesn’t scale. Yeah.

Rory Meikle (09:32.423)
So how often do zero-day events and asset inventory have a connection?

Huxley Barbee (09:40.47)
High connection, high connection. So let’s say an ODate comes out. So typically what’s gonna happen is there’s a vuln check that needs to be developed by the vuln scanning vendor. That takes a certain amount of time. Even if it’s like super critical where everybody is at risk, like a log4j type of thing.

Rory Meikle (09:41.662)
Okay.

Huxley Barbee (10:10.182)
Even then, it’s going to take some time to develop a vuln check. That has to be delivered to the deployment of the vuln scanner. And then it has to be operationalized into another scan. And then there’s the scan itself that takes time.

Depending on the type of organization you are, you might be waiting for a week or something like that.

Huxley Barbee (10:37.322)
I’m not saying that acid inventory replaces vuln scanning. You’re always gonna need vuln scanning. That’s very, very important. But in order to quickly deal with a new ODE.

you can use your asset inventory, not as a replacement for the bone scanner, but to give you a very quick punch list of what to go after based on telltale signs that tell you which devices are potentially vulnerable. Right. So let’s, let’s, let’s think about it this way. Right. I’m looking at you. I don’t know. This is probably gonna be an audio podcast. Right. So I’m looking at you and I’m going to guess that

you have some sort of vision that needs correction. Right? I say this because you’re wearing glasses, right? Now, I’m not an optometrist. I did not give you an eye exam through this Zoom call here, but I’m gonna guess I’m right. Am I right? In fact, the matter is, if we go on the street and start walking around,

Rory Meikle (11:45.213)
Yeah.

Huxley Barbee (11:50.202)
95% of the time, we’re probably going to be right about identifying who needs correct, who needs, who has corrective vision or vision that needs correction based on whether or not they’re wearing eyeglasses, right? Because we as humans, we could tell like, oh, those are eyeglasses versus those sunglasses and all that, right? Very similarly, right? A vuln check is like an optometrist making sure, 100% sure that this is, this device is vulnerable to this particular vulnerability. Whereas with as an inventory, there are details. If it’s a good as an inventory,

There are details that you can use to say, aha, that thing, that’s, that’s probably vulnerable. That is probably vulnerable. And you can say that with a high degree of, of, of fidelity and a high degree of confidence. And in a situation where you have a new vulnerability in the news, where you need to very quickly go and just hunt down what are the things that potentially vulnerable and deal with it. Like that’s good enough. That is more than good enough. That is, that is exactly what you want to do.

And you’re going to do this while you’re waiting for your phone scanner to catch up with the new phone check. Right. The other part of this is I see a lot of customers, a lot of folks who have phone scanners, but they don’t scan everything on their network and they either do this because of a cost issue, right? So they don’t want to scan everything or they don’t know everything that needs to be scanned. Right. So a phone scanner can.

And in fact, your entire volume management program can get better if it is supported by a good asset inventory. So, uh, those are, those are some of the ways that, uh, zero day events can be approved by, by asset discovery, right? One is a more immediate response to that O day. And then the other one is helping scope your volume scanner to, to do its job better.

Rory Meikle (13:46.465)
Okay, I mean that’s a good way to look at it, the whole optometry thing. I mean, getting a broad idea of what you know you need to go fix and how to go fix it. That’s, you know, those are actions you can take right away when you know something bad.

Huxley Barbee (14:02.582)
Yeah, absolutely.

Rory Meikle (14:04.277)
So what kind of differences are there between IPv4 and IPv6 in gathering asset inventory data?

Huxley Barbee (14:13.302)
Mm. So part of this comes back to what is a cyber asset? So I’ll just quickly define that. And cyber assets is different from an IT asset. A cyber asset is a compute device along with all the associated detail that security teams care about, right? And this includes hardware, software, services, which ports they’re listening on, security controls that are on there.

Rory Meikle (14:19.177)
Okay.

Huxley Barbee (14:41.878)
user’s information, like who the owner is, vulnerabilities, misconfigurations, and all that stuff. Whereas an IT asset, it’s a different set of concerns. There’s some overlap here, of course. They also want to know about hardware and software, but on the IT side, you care about licensing, you care about replacement cost. So that’s something that I wouldn’t consider to be part of a cyber asset. Cyber asset is like the compute device plus what security people care about, IT devices.

Rory Meikle (14:54.163)
Right.

Rory Meikle (14:59.913)
Mm-hmm.

Huxley Barbee (15:09.75)
the compute asset plus what IT people care about. So one of the things I mentioned, one of the related details is services. Okay, and this is where IPv4, IPv6 comes in. A lot of folks, when they do asset discovery, they assume that the attack surface on their devices is the same, whether it’s v4 or v6. And that is not true. That is absolutely not true.

there’s been many cases where we have found a particular device has a certain port blocked off or turned off on IPv4, it’s not listening, but on IPv6 it is, okay? Now, the adversary is gonna be smart enough to be checking both on IPv4 and IPv6 to see whether or not there’s something they can exploit. Right, and depending on how your firewall’s configured and so on and so forth,

Like that is potentially another attack vector for the adversary. And so when you’re doing asset discovery and when you want a full asset inventory, full of all the details that you would expect from a cyber asset on cyber assets, you wanna be checking like both versions of IP to understand the full picture of that particular device. So there’s definitely some differences that you need to understand.

You know, one of the things, one of the challenges is having a full acid inventory is not just finding all those devices that you don’t know about. That’s not known to your EDR. That’s not known to your volume scanner. That’s not known to your CMDB, but also the unknown subnets. Cause it doesn’t take a genius to just set up a new, you know, private IP address range off of another Nick on a laptop. And. You know, when done wrong.

or when allowed to organically fester, it’s potential that becomes now an open bridge that goes around the firewall. In some cases, these networks could potentially be IPv6 networks as well. And that’s a much larger IP address range to do discovery on, right? One of the biggest challenges in NASA discovery is white space. When you have lots and lots of white space in a particular subnet, it takes a long time to iterate.

Huxley Barbee (17:38.286)
through those IP addresses to verify that there truly is nothing in there. And with IPv6, obviously there’s way more addresses to go through, so it’s highly challenging to do as a discovery in IPv6.

Rory Meikle (17:54.665)
So then let’s get into the meat and potatoes. I probably just say this whole conversation, but what are the processes and tools to achieve an accurate asset inventory count for both your managed and your unmanaged, your cloud devices? I mean, what do people really need?

Huxley Barbee (18:12.138)
Right, so as you can imagine, I’m gonna say, it’s not your EDR, your voltage scanner, and so on and so forth. And I’ll talk about why they’re not good candidates. And then that sort of lays the groundwork for what I think is a good approach. So the thing with EDR, it’s an agent, right? It’s a piece of software that you put on a device. So if you can put software on a device,

Rory Meikle (18:17.461)
Right.

Rory Meikle (18:32.83)
Mm-hmm.

Huxley Barbee (18:41.474)
That means you know about it clearly by definition, you know it, you know what it is. And that means more than likely you manage it, more than likely you’re already protecting it. Like this is not where your problem is gonna be from a security defensive perspective, right? Right, so that’s not a suitable thing when you’re thinking about what has an outsize impact on your security posture.

Rory Meikle (18:53.653)
Chop. Ha ha ha.

Rory Meikle (18:59.144)
Absolutely.

Huxley Barbee (19:08.502)
Right. Which is where those, those unmanaged devices, right? The things that have been orphaned because Bob left the company and nobody, nobody’s working on that box anymore. And therefore it’s not up to date on its patches. It’s not up to date on its version and so on and so forth. It’s the rogue devices. It’s the shadow IT stuff. Like the, that the developers started up in the cloud and never decommissioned. It’s just sort of sitting there with an open S3 bucket, right? That is the unmanaged stuff. That’s really going to cause you a problem. And EDR.

Rory Meikle (19:37.044)
Okay.

Huxley Barbee (19:37.734)
is not going to find that for you because they just they don’t do that. So volume scanners, the thing with the volume scanners is most of them, they do authenticated active scanning, meaning they’re logging into as many devices as possible. They could also be using agents, of course, but if they don’t have agents, they fall back to authenticated active scanning. And this goes back to the same thing. If you can log into a device, then you probably know it. You probably manage it. You probably are already protecting it. And as I said before,

Many folks that use vuln scanners, they’re not even scanning everything. So it’s not giving you a complete picture of what is on your network. And so you’re definitely going to be missing some of those and unmanaged devices and on, on those unknown networks. You could, um, I don’t know how much I want to talk about spreadsheets. Cause I think it’s pretty obvious that spreadsheets are not going to work. Uh, CMDB, CMDBs, they have discovery capabilities that also use authenticated.

Rory Meikle (20:30.383)
Yeah.

Huxley Barbee (20:36.734)
active scanning. So very similar to a vuln scanner. It’s not quite there. And more often than not, they’re not catching like OT devices and IOT devices and things like this. That’s a weak point in those areas. And in fact, with both vuln scanners and CMDB, I would say that they oftentimes entirely avoid OT simply because they’re afraid of crashing OT devices. Some of these OT devices are, are

Rory Meikle (21:00.808)
Okay.

Huxley Barbee (21:06.098)
very prone to disruption. They will freeze up, they will reboot, they will shut down if they have arbitrary input over the network. Right, so if you think about it, these OT devices, they were programmed to respond to somebody pushing a button or flipping a switch. Like arbitrary input is not something that they were programmed to handle, right? And of course, with EDR, you can’t put software on an OT device or an IoT device. So that’s just completely.

being missed by the EDR as well. So we go on to Nax. Nax are somewhat on their way out, I feel like. But there’s still many companies that still have it. And they tend to identify the device that is trying to connect to the network. And they’ll do like a rudimentary profiling of that device.

only for the sake of selecting the policy that they want to apply to that device. It’s not really trying to do at scale discovery on the network. So it’s not his job. It’s not, his job is not to go out there and find everything. In fact, the matter is when you start looking at OT environments, a lot of those Mac addresses of OT devices end up in some sort of Mac address bypass list just to get them on the network because they’re not identifiable anyway.

Rory Meikle (22:15.838)
Okay.

Rory Meikle (22:31.166)
Mm-hmm.

Huxley Barbee (22:35.242)
And then with all of these, with all of these, particularly with CMDB and bone scanners and NETX, there tends to be really, really poor accuracy. Oftentimes devices will just show up as Linux, right? Right, and like, does that help you? I mean, cause if this Linux device is an internet enabled coffee mug,

Rory Meikle (22:47.398)
Okay.

Rory Meikle (22:53.169)
doesn’t surprise me.

No, no way.

Huxley Barbee (23:05.354)
versus this Linux device is an IP camera that is, video taping your factory floor or the bank vault door. It makes a difference to you as a security person. In one case, you don’t care. It’s a bad cup of coffee if it goes down. But in the other case, it’s very material that the adversary might be able to surveil your facilities. So,

The hardware matters, the software that’s on there matters. You need to know these things. And these other tools, they just tend to not be able to tell. Anything beyond like the superficial identification of what is the operating system that’s running here. You’re not working with a full deck when you can’t tell the difference between a network attached storage and an Android tablet.

Rory Meikle (23:43.589)
Lack of visibility.

Rory Meikle (23:49.374)
Right.

Huxley Barbee (24:03.854)
Right? So anyway, these are some of the things that, uh, folks say, Oh, I have, I think asset inventory is important and I have my X that handles it for me. Yeah, those are all X and in all cases, there’s some shortcoming that doesn’t allow you to handle the realities of today. Right? Like I said, 20 years ago, you know, everything was a, was a desktop or a laptop or, or a server in the server room, like in Iraq.

Rory Meikle (24:12.309)
Mm-hmm.

Those are all X.

Rory Meikle (24:23.814)
Mm-hmm.

Rory Meikle (24:29.673)
Right.

Huxley Barbee (24:33.562)
all nice, the cables all nicely laid out, but like these days it just doesn’t work anymore. So what are some of the things that you can do? Well, one interesting approach is to talk to all these other things that are in your tech stack, right? So you can go out there and you can use API integrations to pull data from multiple sources.

Rory Meikle (24:36.082)
Hehehe

Huxley Barbee (25:02.894)
And that gives you some picture of what is on your network. Right. But the other part of it that is really important is the use of unauthenticated active scanning.

Okay, so with unauthenticated active scanning, it means you’re not trying to log into every single device as opposed to authenticated active scanning like a Vuln scanner or CMDB discovery module. And so you’re not hampered by…

having to know something about the device beforehand. You’re not limited to only the devices that are being managed, that are already being protected. It allows you to have a broader view of your network and go after all the things that are unmanaged as well. Now, unauthenticated active scanning in of itself is not gonna be the full solution. You need to couple that scanning

with the capability that essentially acts like a security researcher, right? Because if I were just to do an unauthenticated active scan, I just like fire up Nmap and then boom, I get back a bunch of IPs, here’s some operating systems and so on and so forth. What you need to be able to do is as you are scanning, you are also trying to pull as much information from every single service that’s running on that box.

and also the network nodes among all these devices to get a full picture, where you’re leveraging all the information you can get from layer two all the way up to layer seven in order to come up with an accurate identification of what that thing is. Right, and when I say layer seven, I even mean like the webpages that are running over HTTPS on that box. I mean, I mean like,

Rory Meikle (27:04.165)
Wow. Okay. Full picture.

Huxley Barbee (27:07.454)
even the little icon on the corner of the browser tab there, that can be used as useful information for fingerprinting services. You’re essentially acting like a security researcher or a pen tester, if you will. You’re going there, in there, to try and identify what’s on the network, get an accurate picture of what that is. Or to put it another way, if asset discovery is done right, it is no different than recon.

Rory Meikle (27:36.377)
out. Okay.

Huxley Barbee (27:37.406)
Right? The best asset inventory is one that’s developed when you are taking the view of the attacker or you’re going through the lens of the adversary because they’re doing the exact same process. You need to do it too. And you don’t want to be in a situation where the adversary knows more about your network than you do. Right? So, unauthenticated active scanning coupled with API integrations allows you to get that full picture of your network.

Rory Meikle (27:57.841)
Yep, yeah, that’s a great point.

Huxley Barbee (28:06.99)
It allows you to find out about IT devices, IoT devices, OT devices, and it doesn’t matter where those devices are, whether that be in the office or in the cloud, or in a remote employee’s home.

Rory Meikle (28:21.897)
Okay.

Yeah, that’s…

That’s a lot better than a spreadsheet.

Huxley Barbee (28:29.442)
It’s a lot better than the spreadsheet, a lot better than NAC for sure, and it’s a lot better than an EDR, Vault Scanner, or CMDB.

Rory Meikle (28:38.869)
Okay, so is this process, would you say it’s applicable to both a small business and an enterprise organization as well? Are there things that you would tweak for the smaller scale companies organizations that maybe are essential to have at an enterprise organization?

Huxley Barbee (28:57.686)
Well, I suppose if it’s really a five person accounting company, maybe you don’t need it. Or if you’re a small company that’s sort of born in the cloud, like you don’t really have an office, everybody has a laptop, and all the services you use are SaaS services that’s sort of outsourced to some other organization, then it might not be necessary.

Rory Meikle (29:04.97)
Mm-hmm.

Rory Meikle (29:24.869)
Mm-hmm. Okay.

Huxley Barbee (29:27.67)
But anything beyond that, you’re going to want, you’re going to want asset inventory simply because it’s not like your house, right? You’re the IT administrator of your house, I’m guessing, right? You have a pretty good idea of what’s on there. But

That works only because you are the same person day in and day out. Right. You’re not, uh, you don’t have people coming, coming and going in your family. Typically. Whereas with a business, there are staff changes, the business changes direction. Ownership of devices and responsibilities around devices. They, those, they change. Or if maybe, you know, two companies were to merge or there’s an acquisition ownership of those devices change.

Rory Meikle (30:06.761)
Uh huh. Right.

Huxley Barbee (30:15.854)
through that evolution is when the gaps in asset inventory start to happen. It’s that change of ownership or also this sort of diffusion or decentralization of responsibilities, where developers are empowered to do whatever they want and with cloud instances without proper governance or just different groups, different business units.

Rory Meikle (30:21.895)
Okay.

Huxley Barbee (30:44.874)
going in their own direction without some sort of centralized governance over how they’re interacting or the type of life cycle that they’re applying to devices. That’s when there gets to be a problem. And even some small organizations, that’s going to be very important.

Rory Meikle (31:05.161)
Okay, well, we know, yeah.

Huxley Barbee (31:07.947)
It’s more about people. It’s really more about people than the devices themselves.

Rory Meikle (31:15.733)
straight on.

As far as asset inventory, how does that tie into ransomware right now and the future of where you see ransomware going? How is asset inventory going to play a role in this conversation?

Huxley Barbee (31:34.078)
Yeah, absolutely.

Huxley Barbee (31:38.41)
Let’s say, let’s say you’re compromised and the ransomware gang pops something up and say, Hey, I’ve ran some of this data.

Rory Meikle (31:41.322)
Mm-hmm.

Huxley Barbee (31:49.03)
If the security team says, oh, what is that device? That’s a problem. But if the security team can say, oh, yeah, that’s that file server from 20 years ago that has files that we don’t care about. Okay, whatever. Go ahead, ransom that. That’s fine. But on the other hand, if they say, oh, this is the NAS that has all of our financial data. Okay, this is important.

Rory Meikle (31:55.187)
Yep.

Huxley Barbee (32:18.07)
Having good asset information allows you to make much better decisions about ransomware, right? And then more generally, some really good things that you could do with a full asset inventory is to proactively go out there and understand what are the misconfigurations and vulnerabilities on the device and then close them out, remediate them. Right, so in both cases, good asset inventory can really help.

with ransomware.

But in terms of where ransomware is going, I think it’s going to continue. And it’s purely economics, right? Some of the, I think I was reading a Verizon data breach incident report and it said something like, average ransomware was like $30,000. Something like that, right? And if you think about it, like, okay, if for me to make a living like that, you know, living in the United States,

Rory Meikle (33:03.835)
Okay.

Huxley Barbee (33:19.214)
If I want to make a good living, I have to like do like 10 of those a year. Something like that. And so it’s like, huh, yeah. And so you’re like, I’m probably not worth my time. Like I can just go do something else that’s a little bit, that’s much less risky, right? Not going to land me in jail. But if you think about what $30,000 per ransom means to somebody living in a different country, oh, it’s a no brainer. Like of course I’m going to do that.

Rory Meikle (33:26.505)
At least make it worth your time, yeah.

Huxley Barbee (33:48.586)
Right? It’s good money and that jurisdiction is not going to come after me over here. Or it’s much harder for that, that jurisdiction to come after me. So it’s a no brainer. This is going to continue. This is going to happen. And don’t think that you are going to be exempt from this if you’re a small business or what have you, it’s $30,000. Right? I mean,

Rory Meikle (34:16.442)
Yeah, and at a small business, yeah, a small business, 30,000 could make or break, you know, payroll for the week.

Huxley Barbee (34:16.479)
They don’t need to go after the big companies for this.

Huxley Barbee (34:22.846)
Right, exactly. Right? The ransomware gangs scale by increasing the number of targets. And it can’t be the biggest companies every single time. Why? Anyway, like the biggest companies have more security controls. It’s gonna be harder. It’s a harder job. Right? They do so much more by going after the smaller companies that don’t have the security controls.

Right? And.

$30,000 is like a reasonable amount to be asking for. So if anything, I feel like small businesses are at higher risk for ransomware than larger companies.

Rory Meikle (35:09.285)
Yeah, I would totally agree. Lack of skill, lack of knowledge, and then lack of physical and software assets to not just asset inventory, but security tools across the board. They don’t, you just don’t find them.

Huxley Barbee (35:22.834)
Yeah, and if 30k is the threshold, that means there’s a large pool of small companies to go after.

So it’s just gonna get worse.

Rory Meikle (35:35.722)
I hate to say it, but I definitely agree with you there. So as an organizer of Besides NYC, for those of us who didn’t attend, what can you fill us in on from the event?

Huxley Barbee (35:38.289)
Yeah.

Huxley Barbee (35:49.818)
Well, first and foremost, the event is back. So it was on a hiatus for five years. It’s one of the, one of the last casualties of, of the pandemic in New York city, I would say, but it finally came back and it did very, very well. We had more attendees than five years ago. We had 50% more submissions for talks than, than 10 years ago.

Rory Meikle (35:56.753)
Okay.

Rory Meikle (36:16.213)
awesome.

Huxley Barbee (36:18.838)
We had 127 submissions for only 121 speaking slots. And we had speakers flying in from Sweden, from Italy, from Israel. So it turned out to be a somewhat of an international event as well. Um, I would say another important highlight is the accessibility of the event. So even, even with some of the other besides.

Rory Meikle (36:23.529)
Wow.

Rory Meikle (36:43.177)
Okay.

Huxley Barbee (36:47.646)
The tickets cost something like $75, maybe even $100. But we charged $15. And if you register with a.edu address, you automatically got a refund. And if you couldn’t afford the $15, you could just email us and go through this process to get a free ticket. So we were making this as accessible as possible. And it’s one of the, I’m sure there are other examples of this. But.

Rory Meikle (37:07.718)
Okay.

Huxley Barbee (37:15.926)
As far as I know, it’s one of the few examples where you have a technical security conference that’s also super accessible to the public, that’s also somewhat large, right? It’s not one of your hundred person security conferences or anything like that. We had close to 800.

Rory Meikle (37:32.949)
Okay.

Rory Meikle (37:37.161)
So if people want to attend this next year, what can they look forward to?

Huxley Barbee (37:44.714)
Yeah, that is being decided upon right now.

Rory Meikle (37:47.956)
Okay.

Huxley Barbee (37:50.226)
We are working on a post-mortem review of the conference, lessons learned, what to, what to start, what to stop, what to continue and things like this. And then we’ll go back into planning stages for what the next one’s going to look like. Definitely. It will continue to be a community conference with technical topics that is accessible.

Rory Meikle (38:02.398)
Okay.

Huxley Barbee (38:14.838)
Beyond that, the sky’s the limit in terms of what we’re going to do and so on and so forth. One thing I hope to see come back is five years ago, we had a business track. So New York city, we have a large investment community. We have lots of cybersecurity startups. And five years ago, we had this business track, which was very well received. So I’d like to see if we can bring that one back as well. In addition to the technical tracks, but

Rory Meikle (38:26.185)
Okay.

Rory Meikle (38:41.925)
Yeah, that’d be awesome.

Huxley Barbee (38:43.05)
But we’re not giving up on the technical tracks. There are plenty of other non-technical security conferences, and that’s, that’s not our interest. So that something that’s very core to us is to have those technical tracks. So that’s, that’s not going to go away. Even if we introduce something that’s non-technical on the side.

Rory Meikle (38:49.598)
Mm-hmm.

Rory Meikle (38:58.969)
Right. Awesome. Well, if people want to, you know, reach out to you, get in contact with you, what is the best place to do that? LinkedIn?

Huxley Barbee (39:08.446)
So you could just search for Huxley Barbie.

Yeah, I’m the only Huxley Barbie you’re ever going to meet. And I’m active on LinkedIn, Twitter, as well as Mastodon. I’m on the infosec.exchange instance. That’s H-U-X-L-E-Y. And last name is B-A-R-B-E-E. Two Es.

Rory Meikle (39:16.904)
Hehehe

Rory Meikle (39:31.785)
Perfect. I’ll have Emily make sure she links all that stuff and we’ll link the B-sides, NYC as well. So if any of you listeners here want to get info on when that’s coming up next and get in touch with Huxley, have all that stuff right there.

Huxley Barbee (39:47.978)
Sure. Or if you just want to email me, you can email me at huxley at runzero.com. That’s R-U-N-Z-E-R-O.com. But, you know, connect with me on LinkedIn or Twitter or Messdome as well.

Rory Meikle (39:51.387)
Okay.

Rory Meikle (39:59.282)
Perfect.

Rory Meikle (40:06.001)
Awesome. Well, I appreciate the time and I definitely appreciate all the info. These are always, I feel like I learned more than anybody else when I do these. So, yep, absolutely.

Huxley Barbee (40:16.834)
Thank you for having me.

Huxley Barbee’s Twitter

Follow RunZero

Huxley Barbee’s Linkedin

Visit BSides NYC

 Check out the other episodes in Season 11:

Ep. 0 Cyber Basics: Lean Six-Sigma

Ep. 1 Huxley Barbee – Having ACCURATE Asset Inventory

Ep. 2 George Kamide – From Disinformation to AI (pt 1)

Ep. 3 George Kamide – From Disinformation to AI (pt 2)

Ep. 4 Phillip Wylie – He was once wrestling a 750lb Bear, Now he’s a Penetration Tester

Ep. 5 Bec McKeown – The Psychology behind our Cybersecurity Choices and Teams

Ep. 6 Bec McKeown – You CAN Train Your Mind

Ep. 7 Ben Johnson – What makes a great DevOps team?

Ep. 8 Kevin Metcalf – The Recovery Of Missing and Exploited Children

Ep. 9 Chris Rock – Terminated from Speaking at TED Global

Ep. 10 Chris Rock – Can Cyber Mercenaries Overthrow the Government?

Huxley Barbee's profile picture for Dark Rhiino Security's Security Confidential podcast

Huxley Barbee is a Security Evangelist at runZero (formerly Rumble Network Discovery), a company founded by Metasploit creator HD Moore that helps companies discover unmanaged devices for asset inventory. 

Huxley previously worked for Cisco, Sparkpost, and most recently, Datadog – where he formulated the Datadog Cloud Security Platform.

He has spent over 20 years as a software engineer and security consultant. He attended his first DEF CON in 1999 and holds both CISSP and CISM certifications.

On top of that, he’s also an organizer of BSidesNYC

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top