Opens in a new tab
vmblog logo 2024 wht (updated)

Black Hat USA 2024 Q&A: Traceable Will Showcase Its Leading API Security Platform for a Cloud-first, API-driven World

Share: 

David Marshall | Published: July 23, 2024

blackhat-vmblog-qa 

Are you getting ready for the upcoming Black Hat USA 2024 event, an internationally recognized cybersecurity event providing the most technical and relevant information security research, now in its 27th year.  The event is quickly approaching, taking place August 3-8, 2024, returning to the Mandalay Bay Convention Center in Las Vegas, NV with a 6-day program. 

Ahead of the show, VMblog received an exclusive interview with Richard Bird, CSO at Traceable AI, one of the industry’s leading API security companies.  Make sure to add them to your MUST SEE list.

traceable logo 

VMblog: Before we get into it, can you give us a quick overview of the company?  What should folks know?

Richard Bird:  Traceable is a complete API security platform that allows for discovery and posture management, security testing, attack detection and threat hunting, and attack protection anywhere your APIs live.

Traceable is built differently. With the broadest and deepest possible data collection capabilities, Traceable secures your APIs no matter where they exist. The core of the Traceable platform is our API security data lake, which takes the rich API context we collect and provides complete API security – enabling organizations to minimize risk and maximize the value that APIs bring to their customers.

VMblog:  Black Hat is known for its energetic and interactive booths. What unique experiences or demonstrations do you have planned to engage attendees at your booth? What will you be showing off at the show this year?

Bird:  We are thrilled to share our exciting plans for Black Hat 2024, where we aim to deliver an engaging and interactive experience at our booth. Here’s what attendees can look forward to:

Unique Experiences and Demonstrations:

  1. Live Demos: We will showcase our market-leading API security platform, including comprehensive API discovery, posture management, security testing, threat detection, and attack protection. Attendees will see firsthand how Traceable AI can help achieve unparalleled API visibility and robust security.
  2. Interactive Sessions: Our booth will feature magical and interactive sessions where attendees can engage with our experts, ask questions, and see live demonstrations of our platform in action.
  3. Spin-n-Win Prize Wheel: Booth visitors will also have the opportunity to spin the Traceable Prize Wheel – everyone’s a winner! Spin the wheel for a chance to win from a variety of prizes.

This year, we will be highlighting our latest advancements in API security, focusing on:

  • Contextual API Security: Demonstrating how our platform leverages the largest number of data collection points and deepest contextual awareness to provide unmatched API protection.
  • Contextual API Security – The Data advantage: Showcasing how Traceable comprehends every detail of all your APIs, enhancing threat detection and response capabilities.
  • Machine Learning and AI: Highlighting our robust ML/AI-backed analysis engine that offers deep insights and visibility into API behaviors and threats.

VMblog: Is this your first time sponsoring Black Hat?  If not, how many times have you sponsored before?  And, what keeps you coming back?

Bird:  This will be our 3rd year at Blackhat, and we will keep coming back because of the fantastic engagement we get with the community.  We’re convinced that we’ll have another banner year.

VMblog:  What is your message to Black Hat attendees coming out to the show this year? If they take back one message about your company, what should it be?

Bird:  If we could send every attendee home having learned one thing we’d want them to understand the risks that they may be exposed to with the explosion of APIs in their environment and what a path to security with their APIs looks like. Traceable helps enterprises discover and catalog every API no matter where it lives and detect and protect from attacks against their production APIs. API security is a journey that starts with visibility and progresses through to a rich application and product API program that protects your customer and business data from attackers. API security is one of the fastest growing risks in the enterprise environment making it a mandatory component of any cybersecurity program.

VMblog:  Black Hat attendees are known for being security professionals at the forefront of the industry. What specific challenges do you anticipate they’ll be facing, and how will your solutions help them overcome those challenges?

Bird:  Enterprises continue to move applications into the cloud at a breakneck pace. They are breaking their applications down into bite sized API backed components to gain maximum advantage from cloud native development and deployment models. This is causing an explosion in enterprise API usage both internally and externally to the business. As API growth occurs, visibility, catalog, and observability will become a very important piece of the enterprise security and application security programs. It will become more and more difficult to maintain accurate inventory, threat detection, and attack protection capabilities with traditional products such as WAF and CDN offerings. API security platforms that maintain a holistic view into all APIs and have a significant data advantage will be required to secure the modern API enterprise infrastructure.

VMblog:  What are some of the key takeaways of your solution that Black Hat attendees should be aware of?

Bird:  Traceable AI is the leading API security platform for a cloud-first, API-driven world. We help organizations achieve complete API security to minimize business risk, and maximize the value that APIs bring to their business. The Traceable platform monitors over 500 billion API calls monthly from a diverse customer base across industries and geographies.

Traceable is purpose built to mitigate API security risk. With the broadest and deepest API data collection, advanced API security data lake, and fine-grained analysis engine, Traceable is built to address any API security use case now and in the future. This data advantage lays the foundation for our core product capabilities:

  • Continuous discovery and posture management for all APIs in your organization
  • Pre-production API testing with zero configuration required
  • High-fidelity detection of both common and advanced API threats including fraud and abuse
  • Runtime protection with the ability to block attacks in-line.

Traceable empowers security teams to confidently discover, manage, and secure all of their APIs. We offer multiple deployment options to meet the requirements of any organization, and are proven to work at scale in the largest enterprises.

VMblog:  The market is a crowded space.  What is it about your company and technology that sets you apart from the competition?  What are your differentiators?

Bird:  Traceable’s core differentiation is our OmniTraceTM engine, which powers our entire platform with the deepest data set in the market. Traceable collects API traffic both at the edge as well as internally to your API environment and correlates and analyzes that traffic to create a comprehensive, data driven understanding of your APIs. Other solutions focus on a subset of API data, leaving them with an inadequate view into the total behavioral context of all of your APIs. Traceable records and analyzes every API transaction over time, including north/south and east/west traffic, in a purpose-built API security data lake. The result is complete API context powering more comprehensive API testing, higher-fidelity detections, and fine-grained threat hunting and investigation.

Other key differentiators:

  • Deepest visibility – Traceable provides the deepest and most comprehensive visibility into API traffic. We discover all APIs including north/south, east/west (internal), and 3rd party APIs, and provide visibility into all API traffic, including mTLS encrypted traffic.
  • Sophisticated attack detection and protection – The OmniTraceTM engine analyzes API security data over time, produces insights into threat actor behavior, sensitive data flows, and baseline and anomalous API activity. This allows Traceable to detect and block the full spectrum of API attacks, from the OWASP API Top 10 to business logic attacks and sophisticated fraud and abuse campaigns.
  • Threat hunting, detection, and investigation with API security data lake – We capture, correlate, and analyze all API transactions in our purpose-built API security data lake. Other solutions only retain a subset of the data, limiting the ability to proactively hunt for threats, detect attacks that unfold over a long time period, and perform incident forensics.
  • Auto-configured API testing: Traceable’s API security testing automatically configures API testing from live traffic, leveraging the full API context to reduce manual configuration, run the relevant tests, and reduce false positives. Our auto-configured testing saves customers time and allows them to scale comprehensive API testing across their organization.
  • Proven to secure at scale: We are deployed in production in over 90% of our customer base,  analyzing and securing over 500 billion production API calls every single month (and growing!)

VMblog:  Is your company launching anything new at the show?  Without giving too much away, can you give us a sneak peek?

Bird:  

Generative AI API Security

Traceable will be announcing the general availability of Generative AI API Security at Black Hat. With enterprise adoption of generative AI is growing rapidly, Traceable’s Generative AI API Security focuses on securing applications that are leveraging generative AI capabilities by securing the APIs that connect generative AI systems to other application services and users. All requests and responses to generative AI systems pass through APIs, putting Traceable in a natural position to monitor traffic and detect and block generative-AI specific threats. Key features include:

  • Discovery & cataloging of generative AI APIs and “shadow” AI in your applications
  • Monitoring and blocking sensitive data flows to generative AI systems in your applications
  • Testing generative AI APIs for vulnerabilities, including LLM-specific vulnerabilities
  • Detection and protection against LLM-specific threats, including those in the OWASP LLM Top 10

VMblog:  What are some of the top priorities security leaders should be considering for 2024?

Bird:  API Security: With the rise of interconnected systems and applications, securing APIs has become crucial. APIs are the gateways to data and services, and if they’re not properly secured, they can be major vulnerabilities. Security leaders should prioritize identifying and protecting all APIs in use, ensuring they are monitored for unusual activity, and implementing strong authentication and authorization measures.

VMblog:  Looking ahead, what excites you most about the future of cybersecurity, and how do you see your company playing a role in shaping it?

Bird:  The rapid evolution of technology in cybersecurity is incredibly exciting. We’re seeing advancements in AI and machine learning that can help detect threats faster and more accurately. At Traceable, we’re at the forefront of these innovations. Our solution helps organizations understand and protect their API ecosystems, ensuring they can confidently embrace new technologies without compromising on security.

VMblog:  Beyond your specific offerings, what valuable cybersecurity knowledge or insights can you share with Black Hat attendees visiting your booth?

Bird:  One key insight is the importance of understanding the complete lifecycle of your APIs. This includes not just development and deployment, but also continuous monitoring and updates. Many breaches occur because old, unmonitored APIs are forgotten and become easy targets. Regularly auditing your API inventory and ensuring they’re up-to-date and secured is critical.

VMblog:  If you could add one thing to the Black Hat experience to make it even more valuable for attendees, what would it be?

Bird:  I would add more hands-on workshops that simulate real-world attack scenarios. These interactive sessions would allow attendees to practice responding to incidents in a controlled environment, enhancing their skills and readiness for actual threats.

VMblog:  Does your company have any speaking slots at Black Hat?  If so, can you tell us more about those sessions so people can get them on their schedules?

Bird:  At Black Hat 2024 Traceable has 2 sessions on the agenda:

     1. API Security Masterclass – Hacking and Defending APIs (Lunch-N-Learn)

    • Wednesday, August 7th – 12:00p

    Abstract: APIs are everywhere, they are the hidden mechanisms behind almost everything from mobile apps to IoT devices and of course web applications. And with good reason, they’re a great standard that allows developers to quickly build applications without caring about interfaces. So perhaps with how ubiquitous they are we shouldn’t also be surprised that they’re a common target for a would-be attacker.

    This 60 minute lunch-and-learn session will be a TL;DR Traceable’s popular free webinar series The API Security Masterclass. This session will cover why developers love APIs, the most common security vulnerabilities and how to test for them manually, how to build a basic API security program and we’ll discuss some of the open source API protection tools you can put into place to help recognise and respond to an API attack

    Speaker: Dr. Katie Paxton-Fear

           2. APIs and Contextual Security: The Devil Is In the Details

        • Thursday, August 8th – 10:20am

        Abstract: The age of contextual security has arrived, but most organizations are still attacking their API and Layer 7 security with a sledge hammer. Coarse grained security is the opposite of contextual security and API security capabilities that are more like a scalpel. What does it take to get to true contextual security with your APIs? Catalogs and visibility are only a small part of a much larger equation. What is an API supposed to do? What is an API supposed to access? What is an API actually doing? The devil is in the details.

        Speaker: Richard Bird

        In addition to our sessions at Black Hat, we will be hosting five different short talks at our booth, covering a range of critical topics in API security:

        1. GenAI and API Security
        2. Drivers of Change in API Security – Why is API Security so Critical
        3. API Security and Data: Why Context is King
        4. Digital Fraud and How API Traffic Helps Expose Fraudsters
        5. API Security Master Class (Short) – Building an API Security Program

        These short talks will be led by our thought leaders and industry experts, providing valuable insights and practical knowledge to help attendees enhance their API security strategies. Talks are 7-10 minutes long and start at the top and bottom of the hour.

        VMblog:  Is your company giving away any interesting items at your booth?  What is it?

        Bird:  Stop by our booth (#1774) and give the Prize Wheel a spin and WIN one of our many prizes. Such as: gourmet cookies, playing cards, tshirt, lego sets and more! And in addition to the Prize Wheel, after every booth talk we will be raffling off a pair of wireless earbuds to those that attended!

        VMblog:  As a show sponsor, do you have any tips for attendees to better prepare for the conference?

        Bird:  Plan ahead and prioritize. Black Hat can be overwhelming with so many sessions and vendors. Before you go, identify the key sessions and booths you want to visit. Make appointments with vendors if possible, and prepare questions or topics you want to discuss. This way, you can make the most out of your time at the conference.

        ##