Joe: How's it going, Benny? It's great to get you on the podcast. I know that we've been trying to plan this thing for a while from from different people at your company and and and then you and we had to reschedule several times, probably on my my part to be completely honest with you every time. but I really do appreciate you taking the time and remaining interested and coming on.
benny: How can I not be? I mean you are like kinda you have an amazing podcast, amazing followers. I've been following you and everything that you've been doing. Also your coverage with Avira and such. So Joe, thank you so much for having me and also thank you for being patient with me.
Joe: Yeah, no, I absolutely. You know, I I appreciate the the kind compliments. You know, like I I forget that people actually listen to the show and watch the show. It's it's an interesting problem to have, I guess.
benny: You have we have so many followers. I mean, everything that you do and and also it's pretty interesting to to kinda to get somebody kinda taking what more of a you know, a casual approach to to cyber, kinda interviewing folks from and taking so many different angles to to cyber and taking more of the personal approach to cyber and getting kinda different angles to cyber.
Joe: Right. Yeah, you know, I I feel like that is probably you know, in in my opinion, I think that it's probably the best way to do it to actually have those kinds of conversations because, you know, at the end of the day, no one is going to no no one's going to, you know, listen to like a a scripted, you know, episode. It it it just feels different. I I've I know some of those podcast hosts that that do it. And I've had them on the podcast before. And when I listen to their podcast, it almost sounds like, you know, they're chopping up someone else's story. You know, because like we'll d we'll dive into your background here soon. Right. And I was listening to another person's podcast with someone else. And, you know, I I had on the same guest. And we got like two different stories. out of the two episodes. And the reason is because this other person, you know, chopped up their guests their guest background so much that I didn't really even get the full picture, you know? And so like I I feel like that's where that's where the podcast really stands out. You know, like that's where that's where it really shines.
benny: That's great. Though I you I'm not gonna be Seth Rogan here. I mean, don't don't don't expect that.
Joe: Right. Right. Right. Yeah, no. That's that's definitely not the expectation. But, you know, Benny, why don't we why don't we dive in, right? So, you know, how did you get started? You know, what what made you interested in this world of just like absolute craziness and cybersecurity? Which it seems to have only gotten crazier over time.
benny: So I I was always interested in cyber. You know, you see this gray hair. So despite that, I mean I'm I was, you know, I was always I mean, since the first antiviruses, I mean since I was first programming kind of ZX eight eighty one. so after that first kind of first came the first PCs and the first antiviruses for McCaffee and in auton I was pretty much fascinated by kinda either command line scanning and so on. That was when I was in high school and after that later on. I mean I'm and then after that that when I went to higher education, I went to c you know, I pursued my passion in computer science and and after that I found myself at first I was working for I again I I I I ordered a vision that I'm gonna go and found my own company and And and that that inspiration actually came from my mother. She was actually running an architecture firm. So and that was more of a you know to to get more of a like was more of a personal inspiration to me about how to kinda to own thing, to to deal with employees, to deal with customers, to to build things and over the cyber thing was more of like actually the Software development and cyber was more of a my own personal passion. And then after kind of more developing the passion and also pursuing the degree in computer science, I'm I'm I I I didn't want to be these kids, I'm gonna go and raise some money and found an a company. I I want to make sure that I'm doing it based on some experience. And I want to gain experience, however, in that in a in a large company and in a small company, to see how a large company operates and how a small company operates. So at least I'm I'm gonna make myself more relevant and and and gaining the experience, especially in the larger company, wasn't r just about I how to do coding right and how to do SDLC in larger scale. This is more about how a larger company operates, how marketing operates, how finance operates, how sales operates, how you know how kind of this entire ecosystem works. So and and then I felt I was pretty much ready and then I was waiting for an idea and then when that came then I was then then Opsot was formed. So
Joe: Hmm. Yeah, Working working at a large company versus a small company, they're they're like two different worlds completely. You know? When you're when you're at a small company, like, yeah, you have a title and you have a role and whatnot, but like you're expected to do just about everything else. You know, like that's just how it is. And at a large company, like I I've worked at some very large companies, some of the biggest in the world, and you know, you what what you could get done at a small company in a month will take eighteen months at at a large company because people will just want to check everything and You gotta get approval, you gotta get the right buy-in, you have to like persuade people certain ways, you know, just to make the right technical decision. It's it's a crazy amount of, you know, politics and and just stuff that doesn't pertain to actually doing good security work, you know? And that's like it's probably for myself, that was probably the most frustrating thing, right? Because all I wanna do Is deploy the right product. I I want to do the best security job that I could possibly do. And it's you learn a lot of different skill sets from both environments. You know, what what are maybe some some key skill sets that you learned, you know, from that journey that paid dividends down the road when you formed Opswat?
benny: Well first I mean in a large organization it's like you know to scale, it's not like about kinda a single un you you under you you value you value sales department, you value marketing department, you value that integration between the the groups. you value scale, you value that there is other finance department, very col collaboration, you understand how a c companies scale, brand, marketing, the whole kinda ecosystem. And also you learn a lot of things what not to do. How to completely get innately disjointed, right? Although it was al already many years ago, it still kinda still resonates with me. I still think about it. how HR evolved between the small company to a large company. And also how HR at Opsot evolved from kinda whenever kinda you know a bootstrapped opsot. I end up hiring my previous boss at managed to it initially helped me out kinda with some coding initially. Though it's like though the the the interesting thing is that kinda in this tiny company then You the the the teamwork and the collaboration and hiring people that are more the jack of all trade is the mission. And teamwork and agility is above everything. So as you scale, then you need to go and start bringing experts. Then you try to bring and multiple functions, then you have to bring okay, accounting expert and support expert, and it maybe a driver development expert, and then a sales expert and an OEMS sales expert and a legal expert and then you start building more and more experts and and as you kinda you grow the company from like whenever you are midsized then you have like more of a hybrid between like experts and non experts. And as you scale becoming bigger and bigger, then you have less and less check of all trades and more like experts that hopefully works well with each other.
Joe: Yeah. Every everything that I've you know like read or you know seen people talk about that are that are entrepreneurs that were successful, they all say that like those first hires are extremely important because like you have to hire, you know, the absolute best, but you're not able to pay the best, typically, right? Like unless you take like outside money or you know something like that. So it's a it's a challenging balance. To have, that's for sure. you know, with with opswat, why don't we talk about the problem that you identified in the marketplace that drove you to forming opswat?
benny: So the the the first big idea that so first by opposite bootstraps, the first couple of years of the company, I would say two thousand and two to two thousand and four wasn't really about I actually did professional services to help fund the first product that was released in two thousand and four. And the first problem that identified was building a cybersecurity language. So in in two thousand and four there We start seeing pretty much a rise in so many different cybersecurity products like VPNs and antiviruses and firewalls and endpoint encryption devices. And a big challenge I identified is that with so many new cybersecurity products hitting the market, the challenge they fail we face as an industry is that they're was lacking we lacked a a single communication protocol that enabled all of these products to better communicate and then enabled a safer cybersecurity ecosystem. For example, Joe, imagine that you are like an antivirus and I'm a VPN and I'm trying to make a connection. to the enterprise and so we need to communicate. So are you really protecting my device before I'm making a VPN connection or your encryption device and I'm a firewall and also I want to make sure that we are you're encrypting the device before there is a before a connection is established, just to make sure it's there, because if we will not communicate, then a model will be able to propagate throughout the VPN connection. And there have been many instances, many, many, many issues that many malware and many malware writers that took advantage of of that. And so so that was the first big idea and so I developed a cybersecurity language, we call it Oasis framework. Let's solve that and the it was pretty cool because we end up integrating and to so many different pretty much to the entire industry to thousands of cybersecurity products and in different ways, so which enable cybersecurity product to communicate. So I could pretty much talk to an antivirus, I would say, hey, antivirus, who are you? update. what's your real-time protection status? Can you scan this file? anti encryption product. Are you installed? What's your name? What's your version? Can are you are you encrypting this folder? What's your encryption protocol? So and and so all kinds of kind of you know, language it yeah, and so and and that was enabled and the go to market was to OEM that. So and then I reach out to companies such as Palo Auto Networks and Cisco and HP and so many others and they really like that and it enabled them to power their network access control, VPNs, compliance device products and to go to market much faster. It really took off. We got pretty quickly fifty, more than fifty customers, OEM with very close very quickly to a hundred million deployments throughout these customers. Well, think about that, how
Joe: Hmm.
benny: many endpoints Cisco managed and many.
Joe: Great.
benny: So and and that really took off and enabled to kind of the company to scale. So that was really the first big the beginning, right? So and then really quickly, actually by testing this cybersecurity language, identifying something else that was pretty interesting, which is we we built a testing platform for All of this product, we actually installed it in virtual machines, each one of the products in virtual machines. And and we one of the products that was pretty pretty pretty common was antiviruses, and we installed pretty much any known antivirus to mankind in different virtual machines. And a part of the language was test antiviruses, for example, antivirus dot scan file and antivirus real-time protection. And in order to go and test the language, we had I Where to infect the virtual machines with live malware. Because we want to make sure to do the wrong, you know, we we we are really testing it. And we we we figure out something really interesting about antiviruses, which are that whenever we put the viruses on the viruses on the machines, whenever we ask the antiviruses to scan the virus, The efficacy was pretty low, around 50%. However, whenever we asked the real-time protection to identify whether the the it's a virus or not, the efficacy was really high. So real-time protection was like 99%. Our scan file was around 50%. And that was among all of the antiviruses, among many, many, many viruses. Again, file scan, 50%, real-time protection, 99%. And that's not only for one antivirus, for all of them, including the Sexiest antivirus you can dream of.
Joe: Why do you think that was? Was it just like purely hash based at that time?
benny: No, it's still the case now. Actually, now it's even aggravated with AI. Now with all of the AI antiviruses that you see, Centier One, CrowdStrike, Microsoft, it's even aggravated. Actually, it's lower. It's actually the situation is worse. Right now it's actually somewhere somewhere between five percent to forty percent. I can give you the data to support it. We still have the system. The reason is architecture. Actually I wrote a book, Cybersecurity Upside Down and I go over that. I just released it just released it. Actually, it's I just got this week best seller USA Today. So
Joe: Nice. That's
benny: Yeah.
Joe: awesome.
benny: so I think I sent you a book I sent you a copy.
Joe: Yeah.
benny: The reason for that is actually I go over that in the book. And I go over that I forgot the page number. I'll I'll go over that is the the reason for that is the antivirus architecture. And actually in the book I put a modern I put actually the the modern AI based the the recent AI based antivirus architecture. I took it from Microsoft and page fifty seven. so I took it from the architecture and you can see all of the LLM models and so on that I put in together. And the reason for that is that antivirus is built to protect the device. And so it installed drivers and LLM models and so on and kind of pretty much whenever something is kind of going wrong it's kinda applying registry files, network files, keep file It's checking up abnormalities, and after that it's designed to make a change. Right? However, whenever you look at a file, you need to predict whether a file is gonna be you know malicious or not. And then came the second big big idea of the company. I said, there's a problem. I start actually looking at kind of threats in the market, and I start saying, that's the reason. This is why. So many threads come from email, from file download. This is why everybody is blocking USBs. Because antiviruses don't know what to do with files. This is why everybody is so scared from file uploads, file downloads. This is why everybody blocking attachments in the email. This is why it happens. This was a great because because the industry is relying on antiviruses to scan file where. Antivirus are built to protect the device, not the scan file.
Joe: Hmm.
benny: So then came the second big idea.
Joe: That's interesting. So so the antivirus you're saying like essentially has a rule set built into it that protects like the core critical file files of the device rather than relying on detecting the malware and preventing it, stopping it and whatnot.
benny: No, the antivirus is designed as drivers and the d multiple
Joe: Mm-hmm.
benny: drivers, the network layer drivers, the file scale drivers, resistrice drivers, multiple drivers towards the Mac or PC. And these drivers is pretty much going on and pretty much sniffing abnormalities. It's taking all of this kind of sensors, bringing it to the engines of the antivirus. It can actually so many things happening now on my PC. So many things, by the way. I can go and and give you all of this data, by the way. I can I can I can give you all of this phylmon and also Regmon and all of this kind of netmone and get you all of this data. So many events are happening. And then you have an AI agent within the machine taking all of this data, making some LM rules, sometimes connecting to the cloud to go and get the LM rules back to the endpoint. Tons of events happening now. The the the antivirus is designed to block these events where there happens to go and prevent this machine from getting infected. However, if you're gonna go and ask a the same antivirus to predict whether a file is malicious or not, who cares? Yeah,
Joe: Hm.
benny: it's gonna go and try to do a best guess, though. Who really cares? I'm protecting the device. Why should it matter?
Joe: Hmm. That's interesting. So how would You know, how how would this framework apply to like critical infrastructure? Let's let's dive into it a little bit more.
benny: So then I said, okay, fine. So if we have a problem here, how can we s look looks like file flow to critical infrastructure is broken? We have a problem here. File flow to critical infrastructure because what can you do? Antivirus is not really a a solution for you. Sandbox, by the way, is also really a great solution for you. What can you do? Let's Maybe use all of the antiviruses in the market to go and scan them because, and then I try to apply a statistical approach. I say, you know what? If one antivirus is around 50%, by the way, later on I I got a more accurate data on that, though I said it's going to be 50%, two antiviruses would be 75%, three antiviruses will be 87%, and so on and so on, to a point that I estimated with 30 different antivirus engines, we'll be able to get to 99 and 99%. So that was the the and I by the way, also in in my book I've also put together the I I put together the whole the entire kind of development for that. Statistical formula for the for the ones that are into statistics. so I said how about we create a firewall of data? So it's whether you if you pay you go to page 70, I actually I I I did the full kind of development of kind of my statistical prediction. And And then I said, well what? I'll put it together. And then I'll build products. I'll create, like, for the USB, I'll put an endpoint and a kiosk if you're doing it on USB. And then for network traffic, I put an ICAP product for all of the network traffic. For API, there's gonna be an API approach. For email, I have an e email attachment, I have an email hook. And and then this the I said, you know what, I'll be able to go and integrate it all together. And then integrate all of the antivirus engines together. So I OEM'd all of the antivirus engines and created a multi-scanner approach. And then after we integrated all of the antiviruses together, I I still got some malware that managed to go and bypass despite my expectation to go and get ninety nine point nine nine and while while working with bunch of critical infrastructure. and then I was beating myself with a stick, why it happens? And actually I got 99.92 to 99.94. Sounds great to you, right, Joe? Why am why am I beating myself
Joe: Something's pretty good.
benny: with a stick with 99.92 and 9914? So why am I beating myself with a stick? Am I crazy? Maybe I am.
Joe: Sounds like an acceptable risk.
benny: It's not. If you pr pass a million files, a billion files, is that acceptable? You have a nuclear facility and you pass a billion files and
Joe: Okay, if if it's a nuclear facility or, you know, critical infrastructure like that, then yeah, I understand that.
benny: or water or banking or the the defen or defense or you know
Joe: Mm-hmm. Yeah.
benny: Not cool. I expected ninety nine and nine nine, so why why why th then I figure that actually the probability is actually is so we have we have we have an we have a probability issue here. so and then I came up and said, you know what, it's like what if we with dump detection, we assume that all of the five flow to a critical infrastructure, they're all infected with malware. And instead of kinda relying on detection, we'll say that all of the file flow to a critical infrastructure is infected and we'll regenerate the data flow. So so imagine you send me a table.
Joe: Sounds like a pretty arduous task. Like very resource intensive, that's what it sounds like.
benny: It's not, that's the whole beauty of it. Actually, I I I'm talking about the entire journey. Initially it was resource intensive, though we made it not. So I'm talking about the journey because it took it took took took us a couple of years to make it not resource intensive. Initially it was. And then it was a whole journey around that. Initially we we we we we we use JPEG to like another format, after that we use JPEG to another intermediate format back to JPEG, and after that we rebuilt it to a point that We identify the file format, pass through the file format, and then regenerate a new file format to a point that it's gonna be pretty quick. It's not I would say pi when people ask me about the performance, I would say it's it's pretty fast. It's not like you know, it's slightly slower than maybe an antivirus, though slightly scanning, though it's still acceptable. It's you it's nearly real time when we talk about that. And And and again the reason for that, the reason for that again, the the the antiviruses scanning, multi-scanning is conditional probability, so it's not unconditional. So we we have to take a different approach. And the and the approach is data regeneration. And and my whole approach there, that's actually makes me thinking about the entire industry, and especially now with AI, is that Why are we actually doing detection? I start asking myself. Because we can achieve a very deterministic approach to cybersecurity prevention, however, without detection, we can actually achieve it with file regeneration. And then I start applying this model not only to antiviruses, also to vulnerabilities. Think about mythos right now. Can I start applying to mythos? Mythos, what is mythos? Think about that. It's like it's taking like vulnerabilities in simple file formats. Not not only that, it's also configuration-based. Let's let's forget about configuration-based vulnerabilities. Let's just look at file-based vulnerabilities and with among those the the productivity files. So it's looking for like containers of like JPEGs in I IoT, IoT, and anything like that. Like let's talk, let's look for example, JPEG. And it's looking for like code on IoT, I IoT that is going and presenting this JPEG in whatever format on a printer, on a screen, or anything, and finding for buffer overflow within just aggravated. By regenerating this JPEG and creating a very, very clean format, it is like clean JPEG that doesn't have the buff of overflow. I eliminated the attack vector that that will pretty much I eliminated the X the the ability to create XPot.
Joe: Hmm.
benny: And bought much more time for everybody to patch. That applies for simple
Joe: Hmm.
benny: file formats like that, such as JPEG, also to complex file formats that com such as Wall document and PDF that contains all kinds of simple file formats within.
Joe: That's it that's interesting. Can you can you say that maybe one more time where you're you're rebuilding it? You're rebuilding it and then taking out like the buffer overflow attack in it. What what was that part again?
benny: So let's say that okay, let's look at for example, again, I I like JPEG because it's a great example. There have been a bunch of attacks on JPEG. Some of them have been pretty dramatic in the cybersecurity world. And and so and and in in and CDR the is is like it's it's a three-step approach. Now it's identifying the file type, passing through a file type, and regenerating a new file format. So So let's say that you have Methos is finding vulnerability. And how is it gonna go and find vulnerability? It's gonna go and find vulnerability at the container of the specific JPEG, is the the presentation layer of this JPEG. So it's gonna find vulnerability at the like the Word document or like presentation layer or the application we're using right now, right? So if I will present a JPEG within the application that we're right now using for this podcast, it will create a buff of overflow that the attacker will be able to go and use. So what I'm saying is that we take this JPEG, we'll regenerate that to a clean format to a point that all of the pointers within the JPEG will be clean, will not be exploitable. Then it doesn't matter what type of exploit Mythos will find. the file format is gonna be clean and the file base exploit is not gonna be relevant for me
Joe: Hmm. So you're essentially like putting it to a known, like good, secure state that you already know. So no matter what modifications
benny: Compliance alpha.
Joe: were put to it, you already know how that file should be formatted and whatnot.
benny: It's compliant file format. I know how file formats. So the whole thing about this technology is really cool because we we start applying it to hundreds of file formats. And also, by the way, file formats had versions. I mean, for example, PDF has already nine different versions from 1.1 to 1.8. Now we're on two point zero. So each one of these file formats have their own versions. So we know these versions of the file formats, and we're putting in a compliant file format. We know how JPEG file format looks like. And we see something that Pretend to be a JPEG, so we are we are pretty much formatting this JPEG in something that is known good. So if there was an exploit on the original JPEG, it's gone. We we just kinda we pass through it, we generate a new JPEG in a good state, good format. And then we put it back to whatever supposed to go and present this JPEG, whatever it's PC, Mac, IoT, I IoT, printer, whatever.
Joe: Yeah. That's interesting. I never thought about it like that before. Where hm. Yeah.
benny: So I'll give you another analogy for for for that. So I I put by the way, I I in the book I made I try to make the book I I know it's sometimes hard to think about it, so I try to make the book I also who reads books these days? so so I'm everybody's just listening to your podcast to podcasts. so so I I try to make it ultra visual. So there are a bunch of diagrams and visuals around that. So for example, you know Dolly the sheep. So let's say that you want you want to eat a sh are you vegetarian?
Joe: No.
benny: Okay, great. So let's say you want to eat a sheep. So however, you're not sure if this G sheep has a vac bacteria or not. So you take a DNA from the sheep, you're cloning it. I think about very, very fast cloning. And you're getting a new sheep, and you take this sheep and eat the new sheep. Huh? Well, another example, maybe for your vegetarian, vegetarian audience. Is is maybe distilling water, right? You go camping, you want to drink the water, you can either test the water for bacteria, right? That's the antivirus way. Let's test it, use AI, is there bacteria? Yes, no. And which is not really deterministic because maybe you don't have the test for bacteria. However, You have another one. You can distill the water. You can regenerate water. You can make smart smalt water and then regenerate your own water and then you know that this water you just regenerated. safe to drink.
Joe: Huh. That's interesting. And when did you
benny: That's what we're gonna
Joe: come up with this with this method?
benny: So that was two thousand and ten. However, since then we perfected that. So that's the digitalization. However, the then I start voting, however, we then we perfected it like two thousand ten to twelve two thousand and twelve, we cannot we just perfected perfected. And I'll talk about the journey of perfecting it. However, it's we're still developing it because you know, when we released it two thousand twelve we have like maybe like fifteen file types. Now we have like hundreds of file types and we'll feel more versions, and also we do it quicker and faster. And also it's not only about that, we're adding reporting there because now also we found out that we can have detection capabilities on top of the CDR for you, because if we find that there is a buffer overflow throughout our parsing, then likely somebody's trying to hack you. So
Joe: Hm.
benny: so we we start adding more and more features to the CDR, which is fine. And also we added more data channels. So if we add it, for example, just for you know email, now we have it for USBs, we edit on file downloads, file uploads, and we have more with on storage, we have it even now also, which is kinda cool. We have it for three sixty five, entire suite of three sixty five. So you integrate it to SharePoint to team team messages, external. Think about it, you have an external vendor for teams you can integrate as well. So we have it as well. So that's kinda that's that's good, effective. think about your entire file of data. So if you are looking for to protect the critical infrastructure from data flow protection, we We get you anything. We even have it on a dare diode. Dare diode is a you know it is a dare diode. It's like stronger than firewall. It's an optical firewall. It's a
Joe: Mm.
benny: one way, it's unhackable firewall. So we are not only whenever you go to like a nuclear facility, you can't really rely on a firewall. Or you go to a bank, ATM, you don't you can't really you should not rely on a firewall. You go to like a really critical network, you should not rely on the firewall because firewall is hackable. So we have a optical firewall, so we have the CDR on the stream of the of the optical firewall and then you don't only have a one way, you have a one way that is regenerated so we have a really secure data flow to
Joe: Hm.
benny: or outside your critical
Joe: Hm.
benny: So I'm in Tampa now, so well by the way manufacturing of this tea diode is just there, just
Joe: Yeah. Huh. That's interesting. I've questions I'm not sure exactly how to ask Like for that firewall, you know, use case. I understand the use case and everything, but how are you rebuilding the proprietary data that is being sent through the firewall potentially? Or encrypted data through the firewall?
benny: on encrypting, we we can do we can deal with encryption by kind of decrypting on both sides and sometimes we partner with customers like that. For that we have some some decryption keys. So typically it's like we have we have like actually it's two computers. One computer is two reverse proxies. We're taking the protocol in one way and then we're doing the CDR on one of the computers, either in the ingress or the egress. And then we're taking on a fiber optic between the two computers and then we know it's going only in one way because there is no fiber optics on the other way.
Joe: Mm.
benny: And you're taking a clean way. Sometimes we do it CDR again just for even absolute security, because then if something was hacked, then you CDR it again.
Joe: Right. Okay. That that's interesting. Yeah. So you're you're forming that trust between the sender and yourself and then the next party on, right? Like the nuclear facility or whatever it might be. And then you're you're getting the data, decrypting it, rebuilding the whole package and then sending it on the verified secure traffic to the facility.
benny: Yeah, d yeah, typically whenever we deal with that it's already kinda decrypted, so like that's not kinda we really want to make sure that that the data that we transfer is not gonna create any damage to the organization we protect.
Joe: And with the with the data, the I mean it's still relying on the file types, right? Like you're expecting this kind of file type, this is what it should be formatted. But is there an attack where the data itself is compromised? Because I I'm just thinking like we were focusing on the file type. But what if there's no file type modification to it? Or maybe that doesn't
benny: It's productivity files. Well, it's a productivity.
Joe: happen.
benny: It's the productivity files. I mean it's like we we we block executables. We can't regenerate executables. I mean we I'm not advising our critical infrastructure to accept executables anyway. so we and also we cannot regenerate executables yet. though we we we regenerate any re any Many, many, many productivity files. Not any productivity files. There are more than ten thousand productivity fil ten thousand types of productivity files. Out of them, like three hundreds are more common. That we focus on those and their versions. and so we focus on protecting this critical infrastructure and for threads within this for the PE files and so on, we're still relying on the multi-scanning, and also we have adaptive sandbox and also Ether, which is a threat Intel integrated to to sandbox and an LLM detects the IOCs and combine them together. so we have that. we also have AI, like like other things in the platform to go and predict more more more for PEs and and other file formats on that. though the ter deterministic approach we focus and we typically lead with to protect critical infrastructure is is very much the the CDR that it's very very deterministic on on on security. And also it's a concept.
Joe: It's a f it's a interesting it's an interesting way of addressing a really complex problem, right? Because like you always hear about critical infrastructure being so difficult to protect because it's you know the the systems are so cut off from from everything else, which makes it like really difficult to just maintain and manage. I I actually used to work for a company that They didn't deal with critical infrastructure and they didn't have what you would consider critical infrastructure in their environment. But, you know, they had been breached before so significantly that they decided, okay, we're gonna put all in into this security thing and now we're gonna create, you know, this super hard, hardened network. And they created, you know, this this kind of tiered architecture flow. where their their crown jewels were in like a protected walled off, you know, garden essentially, right? And it was so difficult to get into that environment that most of the time it was like two years behind on patches. And their logic was, well it doesn't matter because if no one can get to it, we don't need to keep it updated. And then when I start poking around, you know, it's like, yeah, there's this feed out to the internet that provides you know, whatever functionality or updates, and there's this other thing that does it, right? Like it's it's very difficult to protect an environment like that. And I feel like this almost provides like a way around it because you don't need necessarily that walled garden potentially, or at least not as thorough a as like you previously would, if that makes sense.
benny: I mean, yeah, we do other things by the way. We we also have offline patching right now. We that we released it like a couple of years ago to have to have that. So we do that. that also helping with the critical infrastructure with their kinda with their needs. And so what we recommend is that okay, fine, so just air gap to your entire thing. Right. Any data flow, just C DR all of the data flow. So if you have a meter type attacks and we are yeah, we're pretty much we're buying you so much more time to patch your patch your your thing. And then for everything inside we have offline patching, so you can do offline patching. So it's not only about we have that, so we we really evolved our platform to do that is what we do, no. If I go to a higher level about kind of the mission, now we have a platform that includes the technology such as CDR and other things. We have products that integrate through the data flow through your critical infrastructure. And something that we released like four years ago is the five years ago, Opsot Academy, which is training the critical infrastructure. Because what I just kind of went over with you is relatively new to you. Over put yourself in a seat of like So many IT professionals within the critical infrastructure. And the we we found out that nobody there there isn't really really a training system for them. What is CDR? What is critical, what is Air Gap, how to protect the PLC, how to protect against Mythos type attack, how to protect that. So we build a full online academy ran by IRFAN. he's he's is he's here in Tampa and he's building a really cool tool. It's obsoacademy.com. We really made it fun. We a very online we got like two hundred and eighty thousand certified students already which is almost the population of Iceland and
Joe: Huh. That's an interesting set. I didn't realize that.
benny: so I when once we pass it I'll let you know. Maybe I should try should fly to Iceland and tell them
Joe: Right. That's interesting. I always figured, you know, the admins of critical infrastructure would be like highly specialized, highly trained in operating within those environments. But I guess it kind of makes sense that they might not be because it's such a unique, you know, environment that like you're typically not trained on it or talked about it in any education format in all of, you know, cybersecurity really.
benny: I went over all of the four hundred and thirty six cybersecurity certification before we did that and neither focus on training critical infrastructure and so we before we form
Joe: Yeah. Huh. That's interesting. That's an interesting training path. I I would definitely be interested in like taking a look at it and and like going down it myself because I'm just a a nerd like that, I guess.
benny: I I'll get you the if you need more kinda the the that one we'll send you some some I'll I'll make sure to get you the the if you need the the extended versions because there is free, there is also the paid one and we'll make sure to send you whatever you need and I promise to sign the certificate pretty fast. It's automatic so anyway.
Joe: That would be awesome. Cool. Well, Benny, you know, we're we're unfortunately at the top of our time here. but I really enjoyed the conversation. It's really fascinating. It it's interesting how Just how everything changes when you start talking about critical infrastructure and how to really distill down security, you know, principles kind of like to the basics, to the bare bone, you know, root of the problem basically. Right. And so I I I think this conversation was extremely interesting.
benny: Thank you. I appreciate that. that's that's good hearing it from you. Thank you so much for your time and for your interest. It was really a pleasure and a treat to speak with you. Appreciate the opportunity.
Joe: Yeah, absolutely. Well, you know, Benny, before I let you go, how about you tell my audience, you know, where they can find you, where they can find your book, and where they can find Opswat if they want to learn more.
benny: So on Opsot, very easy, w dot Opsot dot com, find me at my website, Bennycharney dot com. Benny dotcharney dot com. So easy and some information about my book is also there as well.
Joe: Awesome. Well, thanks everyone. I hope you enjoyed this episode. It was a fantastic conversation. Go ahead and check out Benny at all of the links. They'll be in the description of this episode. Thanks everyone. Bye.
benny: Thanks, Joe.