Pursuing a Ph.D & Hybrid Cloud Security

Keith talks with Cyber Security expert Dr. Wade Holmes( @wholmes ) regarding the challenges associated with the pursuit of his doctorate and current cyber security project that looks at the increased attack surface of hybrid infrastructures. The CTO Advisor Pursuing a Ph.D & Hybrid Cloud Security Play Episode Pause Episode 1x 00:00 / Subscribe Share Apple Podcasts Spotify RSS Feed Share Link Embed <blockquote class="wp-embedded-content" data-secret="ObV5HwG2BE"><a href="http://thectoadvisor.com/pursuing-a-phds-hybrid-cloud-security/">Pursuing a Ph.D &#038; Hybrid Cloud Security</a></blockquote><iframe sandbox="allow-scripts" security="restricted" src="http://thectoadvisor.com/pursuing-a-phds-hybrid-cloud-security/embed/#?secret=ObV5HwG2BE" width="500" height="350" title="&#8220;Pursuing a Ph.D &#038; Hybrid Cloud Security&#8221; &#8212; The CTO Advisor" data-secret="ObV5HwG2BE" frameborder="0" marginwidth="0" marginheight="0" scrolling="no" class="wp-embedded-content"></iframe><script> /*! This file is auto-generated */ !function(d,l){"use strict";l.querySelector&&d.addEventListener&&"undefined"!=typeof URL&&(d.wp=d.wp||{},d.wp.receiveEmbedMessage||(d.wp.receiveEmbedMessage=function(e){var t=e.data;if((t||t.secret||t.message||t.value)&&!/[^a-zA-Z0-9]/.test(t.secret)){for(var s,r,n,a=l.querySelectorAll('iframe[data-secret="'+t.secret+'"]'),o=l.querySelectorAll('blockquote[data-secret="'+t.secret+'"]'),c=new RegExp("^https?:$","i"),i=0;i<o.length;i++)o.style.display="none";for(

Transcript 3,905 words · about 26 min to read

Machine-generated from the episode audio and not hand-corrected, so names and technical terms may be imperfect. The audio is authoritative.

All right, you're listening to another episode of the CTO Advisor podcast. We have a returning guest. I don't think Wade has ever been on the podcast. We've had Wade Holmes. Wade, what's your new title over at Google Cloud? So I'm a security global lead within the solution management organization within Google Cloud. So maybe we'll end up talking about some Google Cloud, but if you haven't looked at the title of this episode, it's about pursuing a PhD. Wade just announced, or actually he didn't even announce, one of his colleagues announced about a week or so ago, Wade, that you finished your dissertation and was awarded a PhD in, is it cybersecurity?

Yeah. So yeah, specifically it's a doctor of science in cybersecurity. And my dissertation topic was threat actor lateral movement within hybrid cloud. So that's funny. I usually don't understand the titles of some of these dissertations, but I actually really get that thing. We've been doing this way too long and this has been kind of your passion between, you know, when you were at VMware to now, I absolutely understand at least the concept of the research. So we'll get into that in a minute.

But before we do, I got to just ask the question, why, man, I mean, you, you're already like you have a great title at, you had a great title at VMware. You had a great title. You have a great title. You have great responsibilities. You're well-known, you're an author. You're very accomplished from a individual and career perspective. Why at this point in your career pursue and achieve a doctor's of science? What drove it? Yeah. So Keith, there were three aspects that were important to me to actually complete this journey, which really started a long time ago for me, at least in my mind.

And the actual pursuit started also many years ago. There's a career aspect in managing my career, and I always like to manage and have control of my career as much as possible. There's a societal aspect in being able to be a leader through actions for others in pursuing an academic, a terminal academic degree. And there's a personal aspect to it in, from my family, and once again, being able to inspire others with my family, those younger than me, those older than me.

So many of you, those who don't know my career, been in the industry 25 years now, and security has always been underpinning within my career, and it's been an interest for a long time. So many know me as being one of the focus on VMware and virtualization, and early in my career, I became a subject matter expert in virtualization in the early 2000s. At the same time, security was always an interesting challenge to me, because it's an impossible challenge, but I always gravitated to, and I have had areas within my career that I've focused on security.

I mean, very early on, I mean, part of my earlier academic career was getting a master's in information assurance, which was my first dive in to the security space from an academic perspective. I got my CISSP in 2005, so a long time ago, and I participated in many of those early security forums, which I can kind of talk about, and it's actually where this idea around my thesis started, the idea around breaking down the perimeter within organizations, and it all really came together for me from an interest perspective as I was, like I said, once again, this is 15, 20 years ago, when I was a practitioner running a virtualization and, well, really, everything practice.

0, it just came out, and also had dived into OS virtualization at the time, so containers, the precursor containers. Before Docker existed, this was things like Linux jails, BSD, and Virtuoso, and I implemented some very interesting architectures within a couple of different organizations, where I saw that there was a scaling factor. Let's pause there for a second. Yeah. You're describing the career path for many of us. As you're talking, I'm nodding my head. I'm thinking, yep, yep, yep, but I'm sensing there's a pivot here, that at some point, and we all get there when you have a 20 plus year career, that you're kind of like, you know, I'm spinning my tires a little bit, like I've done it.

I'm a subject matter expert. I've been on the customer side. I've been on the ISV side. You've been on the vendor side, and there's a kind of, at least for me in my career, there was a kind of like, you know, what's next moment? Get us to that point, to like, you know, this decision point of like security is now a huge part of your career focus. You had many options, and back in VMware, for those who don't know, we literally wrote the book on NSX.

So NSX, a security zero trust model, a lot about, you know, I imagine your research or your job influenced your research. Get us to why the PhD, like what, because you could have done a bunch of things. You're at Google. You're challenged. You know, you're seeing security at a scale that most of us don't get to see, and you can get that like personal knowledge. What about the PhD helped you in your career focus or pivot? Yeah, so it's a little bit like the approach you may be very familiar with, Keith.

You at the CTO Advisor run a data center that you have procured, and many people ask, I see all the time, why do you have this data center? And you said because you want to be able to walk the walk of your customers that you're advising. I also, as I mean, my career has progressed in a leadership position. It isn't something that 100% wasn't needed to pursue a doctoral degree, but I also want to be able to be grounded in actually walking the walk, especially as I wanted to pivot to a security focus.

So that was one big driver from a career perspective, being able to walk the walk when I talk the talk, and being able to have something that was structured to allow me to have focus in uploading myself and my skills to be able to walk the walk while I talk the talk. So that was one big piece of why from a career perspective. Wow. So talk to us a little bit about the process. How long did this all take? So I started in, well, really, I started thinking about this a decade ago, and that's where it kind of alluded to the whole VMware and rise of virtualization and containers and such, because I saw that this challenge around the attack surface of an organization was only increasing as the agility of bringing up resource increases and such.

And obviously, there is many ways that I've approached this. You mentioned that I wrote the book on micro segmentation while I was at VMware, which was 100% tackling that problem. But the actual doctoral program, I really started to put the pedal to the metal in 2015, 2016. Obviously, I've still been working a full-time career. I didn't take time off to focus on this. So it's been a labor of love on and off with many nights and weekends. And in different times in my career, it's been what I've focused on from a security perspective in the career.

So it was very synergistic. But at other times, it was very tangential. And at that time, it was extremely difficult and kind of would take some time off and such. But started that journey then, it still required the actual going through the coursework and credit and research methodology design and statistics and all that stuff until for a significant time, I was basically at ABD status, All But Dissertation. All But Dissertation status, then that's where the fun really starts, where you go in, you have to have a thesis statement that you're proposing, and you have to have that be accepted by a board and committee, have a chair that is going to sponsor your work.

And once you get to that point, you then have to go through a literature review, went through literally 370. Well, there are 370 cited works within my dissertation in books, journals, articles and such, all peer reviewed works. And once you get past literature review, then it's the research phase. My study is a quantitative study of experimental design. So that's a plus for me. Since it is an experiment, it's something I could control greatly from a time perspective. If you're doing a qualitative study or a mixed method study, a lot of times where PhD students get hung up is in gathering the data and not getting back the amount of survey results or not being able to engage in the interviews and the amount of interviews and participants that they need.

But with having a quantitative study where I actually would run an experiment in a hybrid cloud environment, I was able to time box that well just based on my ability to perform the experiment. So we're going to have a whole lot of trouble fitting this podcast. Yeah, I know there's a lot here. And just to this, because there's so much that I can relate to. I reached out, we were going to do some research, some qualitative research. And I reached out to a qualitative research firm.

And they said, oh, so you've never done research. And I'm like, wait, what do you mean I've never done? My data center is literally a quantitative research thing. And it really put me off thinking, how do you not take quantitative research as research? Anyway, there's a thing I want to you talked about that I want to key in with a little bit. So obviously, in your current role at Google and your role at VMware, talking about Zero Trust, this idea of perimeter security, and we'll get a little bit more into the actual research.

Perimeter security and what I call IT is additive. Like we don't ever, well, maybe sometimes, but we rarely ever, whenever we add a service, we rarely take away a service. So if we add something like VMware, NSX, it's rare that we go back and we take away our Cisco tools. It's usually our Cisco tools plus NSX. And the tech service just continues to grow. That is great when your PhD is related to, your PhD research is related to your day job and your current job and your previous job at VMware related to that.

Let's talk about for a brief second, your first role at Google, that wasn't related. Like how did you juggle focusing on delivering VMware, the VMware cloud solution that the VMware engine that Google offers, which is kind of a broad topic to your security focus and work? Yeah. So one of the things I've always done in my career is try to figure out angles to make things synergistic. It absolutely was not directly related, but, and I evolved my study over time. So I mean, I started this back in 2015, 2016.

Initially when I started this, I was looking purely at the rise of virtualization and attack surface based on virtualization. When I moved into, or later on in the study, I realized, well, that was still not, there wasn't a unique aspect to that. Part of the dissertation is you have to have a original work that of knowledge, a body of knowledge that you contribute. And so the, looking at it from a hybrid cloud perspective was actually an angle that's like, well, no one's actually quantified how the attack surface is impacted when you shift from on-premises to hybrid cloud.

So what I actually did was I utilized GCVE to represent really a private cloud, which analogous to a on-premises environment because the compute stack is a hundred percent the same. That's the whole beauty of GCVE is the same as on-premises in, but in a cloud environment. And the study is focusing on segmentation from a networking perspective and attack surface mitigation from a networking perspective. And then the hybrid cloud component was the GCVE with backend connectivity to a Google compute engine environment and having hybrid applications across that Google compute engine and GCVE environment.

But that's how I tied it all together while I was focused on GCVE. So that's amazing. You, you, you leveraged your, the, and this is the thing that's the beauty of about being a experienced practitioner. There's an angle to security and everything we do to your, your original point. And you were able to take GCVE Google cloud VMware engine and replicate your research or use it as a platform for your research. Going back again to the process again, you've produced at a high level.

So looking at the mountain that you have to climb to get your PhD, that process for a lot of people, that's intimidating. And it is intimidating. I don't want to take away from like the difficulty of it. When I hear it, I have no desire to do it. My wife has asked me, Hey, Keith, why don't you pursue a PhD? You've met her. When I told her that you got one, she was like, see, but yeah, thanks a lot.

When you, when you when you look at like what you've done in your career, can you relate the experience of pursuing like this mountain of just hurdles to what you've accomplished or what you've had to go through to achieve what you've achieved at your career level? Is it analogous that can you compare the two even? It absolutely is analogous. It's funny you bring that up because it's something that I was just thinking about recently. I mean, recently I just in parallel while I was working on the doctoral degree, I've been driving an internal project in Google and I was thinking about how the parallels of challenges that are needed to get a, to launch a new product, to launch a new solution was very similar to the process that was needed to complete the degree.

So, I mean, it starts with a baseline while figuring out the problem, figuring out an approach to the problem, figuring out your research methodology, gathering research. And then there's a buying process to make sure you have stakeholders that sign up for this and this has been played through your committee that are going to support you. The same thing within any organization you drive a product. You need to have leadership support. You need to get stakeholder support. Then there's the execution phase and triggering out how you're going to execute, how you're going to perform research, what research methodology, what tools, how do you put it all together?

And then there's the actual getting the work done, which is blood, sweat, and tears. So, it is very much analogous. And like I said, it's funny you mentioned that because I was thinking about how the process that I've been successful in my career, I appraised the same approach with my doctorate. And then the additional, especially some of the pieces from a research methodology perspective actually will help me in my, will greatly help me in my career to have an even more structured approach as I approach projects going forward.

So, as I said, so much to tease out. Let's end with the talking about the research itself. So, there's so many different ways I can go with. I know where I'm going to go, but I just want to inject a idea and concept for people to encourage people to check out your work. Because even if you're not thinking about hybrid from the traditional sense of having on-premises equipment connected to the public cloud and needing to deal with those, the security perimeter around that, I think the core computer science and IT operational aspects are true when you're dealing with multi-cloud and multi-dimensional security issues.

When you go from one security paradigm to another security paradigm with different parameters and you have to integrate those, I would imagine the challenges are very similar to a hybrid. While your research focuses specifically on hybrid infrastructures, I would imagine that some of the security concerns are, exist in the multi-cloud in general. Not even multi-cloud, within the same cloud, I would imagine. Absolutely. It all comes down to what is the scope of a homogenous control plane that can control policy within either a portion of the hybrid cloud, a portion of the multi-cloud, or sometimes it's a portion of the same cloud environment.

That's actually the piece that I contributed to as an original body of work, is developing a blast of radius algorithm that, based on the number of components or the number of control planes within a hybrid cloud, with an assumption that to optimize risk, you want to have a least-privileged model, and how do you achieve that based on the number of control planes within an environment? By default, there are very few ways with native capabilities within hybrid cloud to have a consistent homogenous control plane across a network layer to implement policy both in the public cloud and private cloud piece of a hybrid cloud to achieve that least-privileged model.

To your point, it gets even trickier if you add multi-cloud. It gets even trickier if you add additional deployment models. If you add multi-cloud plus an application that spans across Kubernetes, plus virtual machines, plus physical machines, the research 100% applies and expands more than just hybrid cloud. If you look at things even going further in the future, when cloud providers start to manage IoT devices in your house, how do you manage all these devices that are now this attack surface within your house?

Your Google Home can attack your watch, and your watch can attack your pacemaker in your heart. How do you make sure that these things are segmented, and how do you understand the actual blast radius and risk? So the study, because of scope, is focused on hybrid cloud, but it is 100% applicable to additional environments. So we have a couple of minutes left, and I want to hear – again, I have a bunch of questions, because I've talked about hybrid cloud security as a tangent.

In my lab, how do I make sure that I take a cloud run or a Lambda and make sure it has least privileges to Oracle database on-premises? That is something that we didn't worry about when the perimeter was just within the four walls in our data center. We just simply – this VM can talk to this VM, yes or no. The – when we add hybrid, it really complicates it, because we're not trusting just network security. We have to get to application identity, et cetera, et cetera, and that's not just – and we're talking about at the workload level.

We're not talking about at the data level. If I have Salesforce data, how do I enforce my access control rules that I used to apply to my Oracle database or still do to my Oracle database to my Salesforce data, et cetera? How do I audit it, enforce it? It's just so many, so many questions. But let's talk hero numbers. What did you do in GC – you had access to GCVE. What did you build? So, yeah, within GCVE, I utilize NSX, the surprise, surprise, from a – to be able to have a GCVE environment that replicates a private cloud environment that is using the GCVE NSX distributed firewall to either turn on or turn off a least privileged model with specific controls implemented, connected to a Google Cloud – a Google compute engine environment through a back-end private connection that is available in Google Cloud called private service connection.

So, this is actually a transparent connectivity that would be analogous to your dedicated interconnect or VPN if this was a true on-premises to cloud environment, and basically spinning up multiple VMs with a web – a multi-tiered application with the web tier in the public cloud GCE environment and the back-end databases in the Google Cloud VMware engine environment. And from there, utilizing an open-source attack simulation software called Caldera, which actually utilizes what maps through the MITRE framework attack portfolio to implement specific lateral threat techniques.

There are specifically nine techniques that are documented from a MITRE perspective, and based on a – so, now we're getting to the specifics of the study. There is a NIST document called NIST 800-S125B that defines specific architectures to protect virtualization utilizing firewall methodologies. So, the whole premise of my study was how effective is that guidance based on – that was given for virtualization in a hybrid cloud model, and that's where the quantitative study came in, measuring the efficacy of those different architectural recommendations based on the hybrid cloud versus what had efficacy of just a private cloud.

And then, based on that quantitative measurement, based on a series of attacks that were formed through the Caldera attack framework, then documenting that, analyzing that through an analysis of variance, and then that's how we – it came about devising or making the recommendations that – of the efficacy of each, and then basically quantifying the BLAST radius algorithm. So, I'm assuming the research is available publicly? So, in the process of publishing, I will be sharing out the link. As soon as I get the official link to publish, going through that process now.

I am super excited to read this research. This falls right into my wheelhouse of things that I'm interested in. Wade, thanks so much for joining the podcast. com. When Wade's research is eventually released and published, we'll have a link to that because that's right in the wheelhouse. This is a little bit deeper than what we would go in the CTO Advisor hybrid infrastructure, but this is right in the wheelhouse of something that we would love to do and sponsor. So, I'm super excited to read the work.

Wade, if people want to follow you, how can they do that? Yeah, wholmes on Twitter. Definitely feel free to reach out if you have any questions or want to engage. All right. If you want to learn more about me or reach out to me, I'm at CTO Advisor on Twitter. Until the next episode, make sure to rate us in the – your favorite podcatcher. com forward slash projects. Thanks a lot.