Back
David Aviv
CTO, Radware

Podcast: Radware CTO on security threats for 5G & edge computing

🎥 Apr 01, 2021 📺 Light Reading Video ⏱ 25m
David Aviv, CTO; and Mike O'Malley, VP of Strategy for Radware join the podcast to discuss security concerns that companies ...
Watch on YouTube

About David Aviv

At RSAC 2025, Aviv stated that the democratization of AI is "changing dramatically not only the security posture but our lifestyle" and argued that human abilities will not keep up with AI abilities. He described seeing "agentic AI bots" that forward JavaScript anti-bot challenges to large language models, which quickly solve them and allow attackers to bypass protections. Aviv said Radware uses AI to build deeper security controls and to protect AI infrastructure, noting that running AI applications creates a new AI supply chain and new threat surfaces. In earlier appearances, Aviv discussed the shift to edge-centric architectures driven by 5G, stating that security must be pushed to the edge and that the 5G core, built on HTTP/web-based protocols, opens networks to web-based attacks. He noted that account takeover has gained momentum via spear-phishing, allowing attackers to assume identities and install stealth agents in cloud environments. Aviv also described Radware's approach to self-learning security algorithms, stating that in one week their devices produced about 130,000 attack events and roughly 99.9% of mitigations were performed automatically.

Source: AI-verified profile updated from David Aviv's recent appearances. Browse all interviews →

Transcript (47 segments)
P
Phil Harvey0:07
Welcome to the Light Reading podcast. I'm Phil Harvey, I'm an editor here at Light Reading, and today on the podcast I'm joined by Kelsey Zeiser, my co-host here at Light Reading. And our guest today, we have two guests, they're both from Radware. We have David Aviv, the CTO, he joins us from Tel Aviv, and Mike O'Malley, the VP of Strategy, and he joins us from Chicago. And on the podcast we'll be talking about security concerns that companies are having in light of 5G deployments and multi-access edge computing. Changes in the network architecture, of course, are changing the available surface area and the types of threats that enterprises are facing. So we'll get into a little bit about what technologies they're looking at, how they're reacting to those threats. They've also done, Radware's done a security survey of senior executives that talk about cloud migration, and we can get into some of the findings there. So it's an interesting conversation that we have about how the network is changing and how the security profile of companies is changing, and how security, you know, can be maintained, cybersecurity can be maintained as these networks evolve. We'll get into all of that right after this.
Welcome to the Light Reading podcast. This is Phil Harvey, I'm an editor here at Light Reading, and I'm joined on the podcast by Kelsey Zeiser, my fellow editor at Light Reading. Hello, Kelsey.
K
Kelsey Zeiser2:13
Hello, Phil. How you doing?
P
Phil Harvey2:16
Pretty good. Um, took a nasty spill walking the dog this morning, but I'm okay.
K
Kelsey Zeiser2:20
Oh, how's the dog?
P
Phil Harvey2:23
Really, he's fine. He's consoling me.
K
Kelsey Zeiser2:27
I was worried about that. No, um, but you're not getting... is this wet weather or just clumsy?
P
Phil Harvey2:34
Yeah, I, you know, thought flip-flops would be fine, but I was wrong.
K
Kelsey Zeiser2:40
Well, yeah, it's pandemic dress code, everybody. We have to flip-flops all day long. Let's see, okay, we could get into your clumsiness and your dress code, but we do have bigger and better industry topics to talk about. So joining us today from Radware is David Aviv, the CTO, and Mike O'Malley, the VP of Strategy. First of all, hello, David, how are you?
D
David Aviv3:05
Hi, hi everyone from Tel Aviv.
P
Phil Harvey3:09
Yes, you're... so it is what time in Tel Aviv now? About...
D
David Aviv3:14
Eight o'clock at night. It's 9, 9 PM.
P
Phil Harvey3:18
Nine PM. Okay, so it's two, just for everybody's reference, it's 2:20 or two o'clock Eastern US time. And thanks for staying up, I appreciate it.
D
David Aviv3:31
No worries.
P
Phil Harvey3:35
See, Mike, you're not anywhere near Tel Aviv, are you?
M
Mike O'Malley3:37
No, I'm in beautiful sunny Chicago today.
P
Phil Harvey3:41
All right, fantastic. And winter hasn't hit you yet, right?
M
Mike O'Malley3:45
No, I think we have three more days.
P
Phil Harvey3:48
Okay, all right. We'll enjoy them.
D
David Aviv3:48
Good. Here in Tel Aviv, we have 90s right now. We are on the 90s.
P
Phil Harvey3:57
Wow. Yeah, yeah, weather for the Mediterranean.
D
David Aviv4:01
Yeah, yeah.
P
Phil Harvey4:01
I was about to say it's still very much balmy and sunny and all of that stuff. Whereas in Chicago, you have two seasons: you have winter and not winter.
M
Mike O'Malley4:17
Yeah, yes, and we relish every day of not winter.
P
Phil Harvey4:22
Can imagine. Right. Well, okay, well, we, you know, to have a CTO on for a company this is as well known as Radware, it'd be silly of us not to ask him, you know, what he's seeing in the market right now. So, David, if you don't mind, give us a kind of a state of the industry in terms of, you know, security trends and other developments that you're watching right now. What's on your radar?
D
David Aviv4:49
Well, it's a very broad question, but definitely we do see the 5G and the ecosystem around the 5G as one pillar. Interesting with the edge compute, centralized, and we'll talk a little bit later on the impact on the moving to an edge-centric architecture, a cloud-centric architecture, cloud-native. Security threats is another topic, very, very hot topic also as part of the COVID and the remote access and the lift and shift. Companies that move workloads from data centers into the cloud, the public cloud, and obviously application security. So everything is around how to build, maintain, and secure applications. And the centric point in that world is containers. Everything is moving to run into containers, using most of the time Kubernetes orchestration for many reasons, as resiliency, scale, and control. And if you package that within a cloud-native architecture, well, we have a quite complicated security posture to protect. So cloud-native security, which encapsulates all the application security, which is web, API, etc. The other end, we have the edge-centric network architectures, both for enterprise and service providers. So this provides quite a wide umbrella of security solutions.
K
Kelsey Zeiser6:41
And you mentioned cloud applications. Are there some new security concerns with so many people now relying on their home networks for work from home? Are there new security challenges to accessing those cloud applications?
D
David Aviv6:56
Oh, yeah. We are going into a new environment in which, you know, usually the DevOps team are using their password and then, you know, all the access posture to provide access, secure access into the cloud. We have recently noticed a high, you know, gaining high momentum on the ATO, which is account takeover, in which via spear phishing, you are able to actually fake identities and run into the cloud. When you have affected an identity within the cloud, you are able to run, you are able to install a stealth agent that starts to investigate the internal cloud, map the cloud, find the assets, the more interesting assets in the cloud. Remember, the APIs, the cloud APIs are well known and well mapped. So everyone, if I'm using AWS, Azure, or GCP, I have visibility to all the APIs. I know those are not hidden APIs. I know them, I can utilize them. And from there, we have seen so many breaches, you know, some of them are in the public, some less on the public. But everything is, again, is manifested in I'd like to find out your critical assets, your critical data. If it makes sense in there to blackmail you through ransomware encryption of the critical data or maintain a stealth way exploitation, data critical data exploitation. So the cloud-native infrastructure provides a lot of opportunities, but requires also a very intensive security.
P
Phil Harvey9:10
That is interesting because you do kind of, when you're moving to an environment where, I guess, because of the scalability of the cloud, things are spun up and torn down at a record rate, you know. So having to protect an application throughout that entire process just seems a lot more complex.
D
David Aviv9:33
For sure. Oh, you are hitting an excellent point, Phil, because, you know, one of the challenges when you move to an application security, a new generation application security, is that you need to spin up the security at the rate, at the speed of the container. There's no way to build a security posture which is static and then expect from that static security posture to provide you protection to dynamically changing applications. So you need to spin up the security posture at the speed of the containers. More than that, all the container world is a declarative world. So the security is also a declarative security. So whenever you start spinning up the security, you need to bake it within the DevOps pipeline. So it starts from the left shift. But, you know, when you are building the image, and you are building the image that you are going to run there, also well-defined security scanning that needs to be done for vulnerabilities and well-designed image. And then when you move it to the runtime, you need to move it packaged with the security container, within the security container. Mostly, companies' solutions are using a sidecar solution, which is easy to package and encapsulate within the image. So when you spin up the image, you spin up it with a security solution adapted to the application that is spun up. So you see that the security world, especially in the application side, at the cloud-native side, is very dynamic, adaptive, and not reactive.
K
Kelsey Zeiser11:40
Thanks, David. And just switching gears a little bit, Mike, you all recently published a cloud migration and security report. Can you give us kind of a high-level overview of what some of the key takeaways were there, and were you surprised by any of the results?
M
Mike O'Malley11:59
Sure, yeah. The results were surprising in that we saw a lot of the trends that David talks about, particularly with regard to cloud migration. You know, we saw a real step function in terms of those trends accelerating during the pandemic, and now as we look to post-pandemic. And so what we saw was, you know, even though 60% of service providers reported reductions in headcount and 40-some percent reductions in budgets, we saw accelerating changes in things like cloud and automation. And if you add that to what they were already doing with regard to IoT and 5G, they're really investing very heavily then in shifting to these new architectures that David's talking about. So they made a step function in terms of architecture, and now they're making those changes permanent. And so what we see is we see them building networks kind of around three ideas going forward. One, making the network more remote, so preparing for a contactless economy, and so that you can have remote operations and monitor the network remotely and do that cost-effectively, but also with fewer humans, automation around, you know, making it remote by eliminating human error. So that's number one. Number two, making it more resilient and building in additional redundancy and resiliency, and that's where you look at a lot of the new architectures that they're looking at in terms of securing the cloud to make that a more resilient posture. And then the third thing is to future-proof their network for the next recession, so make it more efficient, make it more agile, as David talked about, you know, in terms of deploying microservices and things like that. And so what we saw then is even coming out of now, those changes they had to make a lot of those changes quickly, and now they're patching a lot of the security holes in the cloud to do that. And so even though overall budgets are down, we saw many of them report, in fact, 25% reported that they're shifting money into improving their security posture, investing in better security. And when we asked them where that was going, three-quarters of them said that that was going to both cloud and automation, but ties very, very well to the types of solutions that David's talking about.
P
Phil Harvey14:30
Did their security strategy change throughout this, or did it simply accelerate? Because I think it's interesting to note whether companies had some of these things on their mind and sort of in process, and then the pandemic just sort of fast-forwarded those plans and those budgets.
M
Mike O'Malley14:51
Correct. I think it's the latter, Phil. From what we saw in the survey results, basically plans that they had to move more towards cloud, to move towards automation, to move towards changing their security posture with some of these technologies that David's talking about, we saw an acceleration in those plans going forward to really move that timetable up for efficiency and resiliency reasons.
P
Phil Harvey15:20
Makes sense. So now let's talk about, you know, I guess what's on the horizon, what's upcoming. So obviously, we've talked a little bit about the difficulty in protecting enterprises while they're doing things like cloud migration and moving more business to the cloud. And then, of course, multi-access edge computing also adds more complexity to it, you know, more endpoints and things like that. Maybe David could tell us what sort of new emerging technologies are you looking at, and where and when might we see those arriving in the market?
D
David Aviv16:01
5G arena and the edge compute, that convoluted, I call it a convoluted environment when you have spectrum, you have edge compute, and you have new services, is actually providing some challenges but a lot of opportunities. So we do see some, I would say, some challenges and there is an infrastructure impact on that. We are moving from a well-defined edge to edge cloud to far edge sites, many local breakouts. As you pointed out, we are moving from an order of tens large data centers to the order of thousands of micro data centers or edge compute. A lot of them are called and considered as micro data centers. And there's also an evolution or revolution at the vendor, hardware and software, where you move to white-label approach, a lot of move to white-label approach, etc. So the outcome of that is a very clear outcome. 5G inspires transformation to an edge-centric architecture. By that, 5G inspires also the move of computer resource and application push to the edge itself. So in that sense, everyone that goes and tries to build a security posture to fight 5G, we need to address three key areas. How do we protect the network and the edge, or more focused on edge protection, namely, can we do defense at the silicon scale rather than what we do today? The second pillar will be we need to protect the control plane. The 5G core control plane is changing. The control plane is moving to an API rather to Diameter in the past. Everything is REST, everything is web-based, HTTPS, end-to-end, packaged in containers. All the vendors are packaging in containers for resiliency and scale. And the third, obviously, is protecting the service or protecting the applications, and which we have now a triad: we have data centers, we have edge compute, and we have cloud deployment. So all of those provide a very clear trend that security is now pushed or placed at the edge. When you push that kind of security to the edge, it's not only a new placement for security functionality, it's also you need to ask yourself if you have the correct algorithms to defend the network for inbound traffic, which is the edge itself. And that positions another challenge being packaging everything together, those two things. And all of the service providers we are talking right now to are building those kind of new architectures and are thinking on how to protect the network from the inbound and from the outbound itself. Does it make sense, Phil?
P
Phil Harvey19:46
Yeah, it does. Just to make sure I understand it, and I'll kind of repeat those three areas or three things that are happening. So first, there's edge protection, which maybe at some point we can do that at the silicon level, and, you know, instead of higher up in the stack. There's the 5G core control plane, because everything's moving to containers, it makes everything more scalable, but it also makes it harder to protect. And then the third thing I picked up on was protecting the applications and services, and that has to be done, you know, not just at the data center or in the cloud, but also at the edge of the network as well. I get the idea.
D
David Aviv20:30
Yes, perfect.
P
Phil Harvey20:34
Okay, well, it's interesting because it's a big job, and the threat, you know, the size of the threat is expanding in terms of, you know, what is that word? Oh, attack surface. There's a bigger attack surface, and then of course it's moving around in the network to different places with different layers of complexity. So that does make security a much more interesting proposition and definitely something that seems like it has to be thought through at every step of the network, you know, as new services are rolled out, not just something that's put on after the fact and once the service is live.
D
David Aviv21:28
Yeah, absolutely, and exactly. And I would say that you need, in a way, to break the security into the network, and that's not easy. This is very challenging. You need to bake it into the network without shaking the boat too much. So you need to do the forwarding, the routing, and the security well. It's a challenge.
M
Mike O'Malley21:55
And I think the other part of that, Phil, is just the idea that, you know, given the fact that service providers pushed so hard into, you know, had plans to push so hard into cloud and into the edge, right, what we've learned over the past few months is that people very much want those types of services. So now it's about rolling it out more aggressively and plugging those security holes, as David said, because it's very complicated.
D
David Aviv22:22
Let me add just one point: is the economical point. I mean, you need to find a way to provide security at the edge. As we said, edge points, we have thousands of thousands of edge points. You know, the large tier ones in the US will have 40, 50,000 far edge routers covering, you know, cities and everything, and this might be accelerated to the suburbs as they cover work from home, and those are wide open for different attacks. And the economy of scale is critical because if every endpoint, if it used to be before, let's say, one gig, two gigs, every endpoint today could be 100 gig, at least 400 gig, maybe one tera as well, depending on the coverage, depending on the slice. If you are running business slices, that might be in the teras. At that point, you ask yourself, okay, I cannot implement the current business model on top of that. We need to find another one in order to address the economy of scale. You know, because you need to price the bit per second and the security, how much it will cost you to secure a bit. So let's assume that if you pay one dollar per bit forwarding, one bit of forwarding, you need to find the right balance: how much do we pay for the security for that kind of one bit forwarding? So that's another challenge that we're working on, and I must say that we have some creative, innovative solutions for that.
P
Phil Harvey24:12
Yeah, definitely a lot to juggle there. Well, we're heading up on time for the podcast, but before we go, I wanted to ask Mike, where can our listeners get a copy of the survey results?
M
Mike O'Malley24:26
So if you go to our website, we have it posted there on our site in C-suite research, and we also have some great interactive web graphics that you can take a look at, so you can see some of the different slices of the information as well.
P
Phil Harvey24:41
Great, thanks so much. All right, David Aviv and Mike O'Malley, thanks so much for being on the Light Reading podcast. We appreciate it.
D
David Aviv24:48
Thank you.
M
Mike O'Malley24:48
Thank you very much.