Join us to explore the evolving landscape of data center security and why your current defenses may be missing the most critical threat surface: the invisible airspace layer.
Dr. Brett Walkenhorst, CTO at Bastille, is joined by Christopher Hills, author of Data Center Security: A Blueprint for Resilient Infrastructure, to move beyond standard physical and logical controls and discuss a mature, continuous monitoring program that provides the missing audit layer for your facility. Learn how to apply the Concentric Ring Model to close security gaps from the perimeter all the way down to the rack.
What’s Covered
- Why the wireless airspace is the third layer of data center defense, sitting between physical controls and network controls
- Bastille’s analysis of the public CVE database, showing wireless vulnerability disclosures growing 20 times faster than CVEs overall
- How smartphones permitted inside data halls expose screens, credentials, and access tokens
- A real customer scenario: a hotspot entering a data hall and connecting to a device planted in a rack, creating a Wi-Fi-to-cellular exfiltration path
- Chris Hills’ multi-ring model of concentric protection, from site perimeter and campus through building security, internal operations, data hall, and rack access
- CPTED site design, guard operations, and device exclusion zones — and how visibility puts teeth behind policy
- Contractor access that bypasses the primary security gauntlet, and why zero trust has to extend to trusted parties
- Tailgating, social engineering, and staffing turnover as sources of insider risk
- Rack-level dongles, Raspberry Pi and LTE implants, and other commercial off-the-shelf devices used for wireless attacks
- Baselining normal RF activity, whitelisting known devices, and flagging rogue transmitters
- Localization accuracy of roughly one to three meters indoors, and DVR-style replay for after-action review
- The dark data center concept and the risk of compromising wireless command and control
- Integrating with SOC platforms, floor plan overlays, and cueing cameras via webhooks
- AI data centers, nation-state interest in wireless attack chains, and Bastille’s partnership with Oracle
- Audience Q&A on drone detection, wireless monitoring in new builds, and elevated RF requirements
Key Topics
The Third Layer of Data Center Security
Physical controls guard the perimeter and network controls guard the wire, but the wireless airspace sits between them largely unwatched. Learn why the middle ground — the space where insiders, contractors, and colocation customers actually operate — is where the greatest opportunity exists to catch nefarious activity inside a data center.
Wireless CVEs Growing 20x Faster
See the results of Bastille’s analysis of the public CVE database, which found that wireless-related vulnerability disclosures are growing at a rate 20 times faster than CVEs overall. The offensive research community is investing heavily in Wi-Fi, Bluetooth, cellular, and IoT protocols — and defenders have not kept pace.
Smartphones, Hotspots, and Exfiltration Paths
Understand why cell phones are still routinely permitted inside data halls, and walk through a real customer scenario in which a hotspot periodically entered a data hall and connected to a device planted in a rack — creating a clean path from server to phone over Wi-Fi, then to the cloud over cellular.
Tailgating, Turnover, and the Insider Threat
Social engineers exploit ordinary courtesy to slip through access control behind a badged employee, and data center staffing turnover compounds the risk. Learn how wireless signatures let investigators separate the badge holder from the people who followed them in, and reconstruct where each of them went.
Contractor Access and Zero Trust
Contractors frequently hold access no one else has, enter through routes that bypass the primary security gauntlet, and become background noise in facilities they visit constantly. Learn why a zero trust posture has to extend to the wireless behavior of trusted parties, not just their badge credentials.
The Dark Data Center Problem
As operators move toward fully automated facilities with almost no personnel on site, that automation is increasingly facilitated by wireless command and control. Discover why compromising those wireless interfaces — potentially from outside the perimeter — is one of the most concerning gaps in the push toward lights-out operations.
Rack-Level Location and After-Action Review
Bastille localizes emissions to roughly one to three meters indoors — close enough to identify an aisle and a small group of racks. Learn how DVR-style replay gives investigators an auditable record of which devices were present, where they moved, and what they connected to, since most of this work happens after the fact.
AI Data Centers and the Oracle Partnership
Hear how Bastille’s partnership with Oracle is rolling out wireless monitoring across Oracle’s global footprint of AI data centers, and why operators hosting extremely valuable AI workloads are treating wireless as part of the nation-state attack chain they need to defend against.
Featured Speakers
Brett Walkenhorst
Dr. Walkenhorst is the CTO of Bastille with over 20 years of experience in RF systems and signal processing, previously leading R&D at Lucent Bell Labs, GTRI, NSI-MI Technologies, Silvus Technologies, and Raytheon. He has authored over 70 publications, is a senior member of IEEE, and has served as Chair of the Atlanta Chapter of the IEEE Communications Society.
Chris Hills
Chris is a career security professional whose work bridges physical security, cybersecurity, and critical infrastructure, and the author of Data Center Security: A Blueprint for Resilient Infrastructure. He has led security initiatives across hyperscale data centers and mission-critical environments, with leadership roles at Bosch Security, Motorola Solutions, Microsoft, and Rack Controls, a data center consulting firm he owned specializing in physical and cyber integration. A former U.S. Army Military Police officer, he brings a disciplined, risk-informed approach to security design and operations. See full bio
Transcript
Welcome and Introductions
Justin: Thank you so much for joining our webinar today, The Third Layer to Data Center Security. We’re very lucky to be joined by Chris Hills, who is an author on a book about data center security and has over thirty years of experience in data center security in a variety of roles. We also have Dr. Brett Walkenhorst, our CTO at Bastille.
During the course of the webinar, please feel free to ask questions using the Q&A button in the middle of the Zoom interface. We’ll have a Q&A session at the end, where we’ll answer any of the questions people submitted before the webinar and also during the course of it. If you have any technical problems, please use the Q&A button to communicate back with us and we’ll do our very best to resolve them. As always, a recording of the event will be made available later this week. Over to you, Brett.
Wireless CVEs Are Outpacing Everything Else
Brett: Thank you, Justin. I’m excited to talk with Chris today. Chris has an interesting insight on data center security generally, and he’s going to provide a framework to us in a few moments. But before we get into that, I want to set the foundation for the discussion related to wireless security generally.
To do that, I want to highlight a study we did here at Bastille recently, looking at the CVE database — those publicly available vulnerabilities that have been published and vetted. We looked at those CVEs and compared the wireless-related CVEs to the total. We came up with a lot of interesting insights, but one of the most interesting punchlines is that wireless CVEs have been growing at a rate twenty times faster than that of overall CVEs.
There’s a lot of interest in this area from the offensive research community. A lot of people are looking at Wi-Fi, Bluetooth, cellular, and IoT protocols and trying to figure out how they can be broken so that we can shore up our security as defenders. We’re finding more and more interest and exponential growth in the rate of publication of these vulnerabilities. This points to the need for additional visibility, and I think it underlies the whole discussion we’re going to have today.
Smartphones as a Compromise Vector
To put a finer point on that, there have been a number of incidents publicized in the news. Many of these have gone to court with convictions that followed, where people were discovered compromising classified or proprietary information using just their smartphones. One way this comes about is that someone simply takes a photograph of what’s on their screen. That can be used to compromise information, but also to relay credentials and tokens.
As far as data center security goes, it’s worth pointing out that cell phones are often allowed inside data centers and data halls. I think that’s probably because they’re not as well understood as they should be. They represent not only a conduit to the information — someone could just take a picture of a screen — but they also store credentials that allow access to protected networks. Whether you have a malicious insider or someone carrying a phone that has been compromised and who becomes an unwitting insider working on behalf of someone else, these represent a very real risk.
Hotspot Data Exfiltration in the Data Hall
Another way a phone can be used to compromise information is something we discovered in one of our customers’ facilities. We were monitoring the wireless emissions of all the devices and found a hotspot coming into a data hall periodically and connecting with a client inside a rack. What’s happening here is that someone operating a smartphone is probably legitimately allowed to be inside that facility, but had previously plugged something into a server somewhere.
That offers them a path from the data on the server to their phone over Wi-Fi, and then, using the cellular protocol, they can upload that information to the cloud. Now they have a clear data exfiltration path — and the complexity of implementing this is very low. It’s really pretty simple for anyone to implement this kind of threat to the information in a data hall.
Most of our tools aren’t looking for hotspots. They’re not looking for the other activity happening in the Wi-Fi domain that isn’t directly touching the networks they’re trying to protect. This is not the only kind of threat — there are many more, and we could talk at length about it. I just want to highlight the fact that wireless does present risk. It presents threats we aren’t often thinking about. That’s the foundation for understanding the risks from a data center perspective, so I’m going to turn this over to Chris to help us frame that a little better.
Defense in Depth: Concentric Circles
Chris: Thanks, Brett. As this image shows, when you start talking about defense in depth and concentric circles of protection, we want multiple overlapping layers of defense. As you just pointed out, one of the layers we haven’t done a good job of taking care of in the past is both the insider threat and the outside threat of third parties and the folks who are just walking the data center.
You really have three different groups that work within the data center ecosystem: the insider, the contractor, and the folks coming in as customers of that facility, whether it’s a colo or a large data center. When we think about those concentric circles as practitioners, we’re thinking from the perimeter into the interior — and that middle area is where I see a huge possibility to catch folks doing nefarious things within that ecosystem. So you have the exterior, the interior, and then the core, which is where those high-value assets live. That’s where people can use RF devices or even just take pictures of the facility and how it’s designed. Some of these areas in a data center are proprietary to that organization, and they don’t want that information released to their competition or to the internet in general.
Intervention Zones: Hot Aisles, Cages, and the Core
Intervention zones are a huge topic within the data center world. The hot aisles and the cages are pretty important to both the large data center group — those people who build hyperscale and colocation facilities — and in some cases even more important when we’re talking about RF signals being sent out, because those are companies that want to keep their proprietary information in that area.
Your ability to continuously record activity within the facility, detect RF signals coming out of the data center, and correlate and alert through a SOC environment is invaluable to both those companies and to the practitioners who advise them on how to secure their facilities.
Walking the Multi-Layer Rings
Brett: Thanks, Chris. One thing that came up for me when we were talking earlier is your notion of a multi-layered approach to security in a data center — something I hadn’t seen before. The example I highlighted of a hotspot coming into the data hall sits in Ring 6, right? Let’s talk through these layers. Help us understand what they are and how wireless visibility applies across them.
Chris: Most of the people listening understand their home and how you have a perimeter, which is your property line. The same thing goes in a data center environment. You have that outside ring — rings one and two — where your perimeter is, where people are going to stop and not come into the data center if they don’t need to be there. However, if you have nefarious folks who want to get in, there are a lot of ways to infiltrate: social engineering to get into the facility, or using contractor information to get in when their intent isn’t good.
Then you’ve got building security, which normally is a layer where you have a guard or an interim control that won’t allow people in unless they have the correct credentials — a physical access control point, plus cameras and those audit pieces at the locations where you enter that critical building security phase.
Then you’ve got internal operations. Hopefully, if somebody looks like they’re taking pictures, somebody is going to stop them. But cameras are so small now, and devices are so small, that people are able to get in there and take pictures without anyone’s knowledge. Being able to show where somebody is doing something nefarious during that period of time matters, but ninety percent of this is after-action review. It’s being able to go back and have that auditable information for investigators to see what took place, when, and how.
And if they get into the rack access portion of your data center, of course we want to be able to go back and see that it happened. The only way I can see that you get a full audit picture is to use these products across the whole multi-layer set of rings and be able to see where somebody’s moving. Brett, when we talked about this earlier, we discussed the ability to really understand where people have been and where they’ve worked within the data center. Some of these data centers are ten football fields — I’ve even heard as large as thirty football fields. That’s a lot of ground to cover.
Why Wireless Applies at Every Layer
Brett: It is. Let me highlight something that may not be obvious to everyone on the webinar as to why Chris is saying wireless visibility applies across all these layers. The wireless domain is notorious for penetrating physical objects. These waves travel at the speed of light and walk right through what you and I would look at and call opaque. They look at it and say it’s transparent — they just sail right through. So when we’re talking about wireless from outside of the perimeter itself, there is still the potential for wireless to impact operations inside of the data hall.
Because of the way these things travel, there’s risk at every layer. So when you ask, Chris, whether one product can be applied to provide auditability across all of the domains, I think the answer is yes. Of course, what Bastille does is not anything and everything that would apply to data center security, but it is an important layer that is often neglected — and it does apply across all of these concentric rings you’ve highlighted.
Real-Time Visibility Inside High-Security Cages
Chris: Some of these cages are really high-security locations. Being able to be in the data halls and actually view where people are moving around in a specific cage in real time — Brett, isn’t that a huge piece for the security world to take notice of?
Brett: A hundred percent. We haven’t really set the stage for discussing that, but if you’ve seen any of our previous Bastille webinars, you know part of the product is about real-time visibility. We can literally watch a device migrate through the facility over time as we’re constantly monitoring it. And this is across all the wireless protocols — cellular, Bluetooth, Wi-Fi, and so on.
The Site Perimeter and Guard Operations
Chris: When we talk about the site perimeter and CPTED design, we’re trying to make sure we’re giving the security group the most accessible view for physical access control and visual access control into the facility. Then you’re making sure people can’t just come in and ram the gates, or go through your security using a drone. Guard operations are important on the interior as well, as I said earlier, but certainly on the exterior, being able to deal with an issue physically is important.
Where we get into some of the products I’ve seen, Brett — you can actually put sensors out here and see when your contractors are bringing phones in. In a lot of cases, as you pointed out earlier, there are no phone set-asides at a data center. That, I think, is a critical issue. Probably even at this point of entry we should be considering it and trying to deter RF devices, video, and cameras being used in the facility.
Exclusion Zones and Putting Teeth in Policy
Brett: That’s a policy question. I tend to agree with you, but each operator is going to have to determine their own rules. If you do decide you’re going to have exclusion zones for certain devices like smartphones — which is probably a good idea — then you need a way to adjudicate that. That’s where visibility can really help you make sure whatever policy you’ve put in place is actually being followed. You can put some teeth behind it with the right kinds of tools that bring visibility to the wireless domain.
Chris: Policy and procedure certainly take precedence over pretty much anything we’re talking about today. If we don’t have teeth in it, it’s never going to get done and nobody’s going to do it. But from a concentric circle standpoint, this is that first layer.
Open Campus or Closed Campus?
When we’re talking about campuses, large companies always have that push and pull — having worked for Microsoft, we always had it. Are we an open campus or a closed campus? How critical is the information we have? Is it so critical that our location starts looking like Fort Knox, or do we open it up and make it look like a college where people feel comfortable coming in and out with no impedance?
In a data center, from my standpoint, we should always fall on the side of caution and try to make our campuses as friendly as possible while making sure we can go back and do that audit process. We can check to see if somebody moved around in places they shouldn’t or entered the building in places they shouldn’t. You can have that campus environment with auditable information available after the fact, where you can see somebody’s movement on the campus and inside the facility itself. This is probably where the rubber hits the road — where the physical space we’re trying to protect starts.
Pairing Wireless Visibility with Access Control and Video
Brett: When you apply wireless visibility, you can look at what the wireless devices are doing at any given time. You can see where they are, because the system does localization. If we’re talking about the layer of building security, then we’re looking at the physical perimeter of the data center itself.
You can see where all the devices are. You can see who they’re talking to. You can see, to some extent, what kind of data they’re sending. We don’t get access to the payload, but we have a lot of information from the headers that tells us about capability, connectivity, and sometimes form factor. There’s a lot of data we get from the metadata we’re extracting that can tell us about behavior and intent, and sometimes things will show up as obviously malicious based on their behavior.
You can pair this with other kinds of physical security mechanisms like access control and video surveillance. When you detect a certain type of signal in an exclusion zone — you have a geofence around an area that shouldn’t have certain devices — and that policy gets violated, you can cue actions associated with access control and video surveillance to capture additional information, lock things down, or whatever your policy dictates. You can make those connections through an integration between the Bastille system and your physical security systems to bring about whatever action needs to happen.
Contractor Risk and the Bypassed First Layer
Chris: I’d caveat that with something I mentioned earlier: contractor security. When you start looking at contractor breaches, they’re huge — last year, $4.8 million in contractor-focused theft. Now we’re talking about really critical information. Contractors in a lot of cases tend to have access nobody else has, and being able to put a device into a rack system takes seconds. Hardly anybody sees it, because it becomes kind of white noise in the background. But your product actually sees that, and can identify what it is, where it is, and how it’s being utilized to a degree.
Rack-Level Dongles and Beaconing Devices
Brett: That is one hundred percent true. This could be a small, tiny dongle that just gets inserted somewhere. People generally wouldn’t even notice it, but it gets powered up by maybe a USB port on a server, and then it starts beaconing — Wi-Fi, Bluetooth, cellular, whatever is embedded in that dongle. If you’re not looking for the wireless, you won’t see it.
When we say wireless, people often just think Wi-Fi, but it’s bigger than that. And when we talk about wireless monitoring, there are tools in existing enterprise Wi-Fi networks that let you monitor Wi-Fi a little bit — but they’re really just focused on protecting their own network. They don’t pay attention to other Wi-Fi signals, and they’re blind to pretty much every other protocol. This is pretty easy to do, and unfortunately with typical security suites we don’t have good visibility into it.
Zero Trust for Trusted Contractors
Chris: A lot of times they completely bypass this first layer. That’s what I was moving toward — a contractor bypasses it because they already have a valid physical ID badge. They’re coming in through the back, through an area most people don’t have to go through this gauntlet. That presents a huge problem, because they’re granted access a lot of people aren’t.
Now, certainly, Brett, you and I have talked about this: a lot of these contractors are trusted, and they’re not having issues like this. But we want a zero trust architecture when we’re talking about our facility. This is really where the rubber hits the road, because these people are in these facilities on a consistent basis. I talked about white noise in the background — they’re going through the facility, but a lot of times they’re seeing the same thing over and over again and not really looking for small details, like a dongle.
DVR Replay, Localization, and Camera Integration
Chris: When you’re looking back at this information and trying to figure out where someone has been, you can actually get it down to the rack level. Do you heat map that to the location? How would somebody bring that up on their screen and correlate a camera with where someone’s been, so we can use all these assets together?
Brett: One of the UIs Bastille comes with we call the DVR UI, because you can replay events, go back in time, and see things over again. In its real-time view, it displays the location of everything as an icon overlaid on the floor plan.
For localization, we’ve typically seen accuracy on the order of one to three meters indoors — rack level to some extent, but certainly close enough that you could start to winnow it down. Over time, you’ll see it migrate toward the correct location, so you can use that to get a view of where things are at any given time. As far as integrating, you could simply see where something is, and if someone has the knowledge, they know what camera might be useful. But you can also send a webhook to the camera system to cause it to focus in on the area of interest, so you can automate that to some extent if that’s of interest.
Tailgating and Social Engineering
Chris: When I was with one of those large organizations that have data centers and we were working through some of these issues, one of the big problems we had was tailgating. To give your listeners a quick understanding — some of the folks listening today may not have run into it or heard the expression — it’s when somebody logs in through their physical access control and then allows other people to go through, having used that one access to open the door. A lot of times people are just being friendly: let me hold that door open for you.
A social engineer understands that very well. Social engineering is where someone is doing something nefarious to get into your facility, and one of the easiest ways is through tailgating. It’s very difficult, because they’re socially getting through the outside perimeter of the building via somebody else’s kindness. Typically people are just letting other employees through — but because social engineers understand this and will utilize it, now you’ve got somebody in your facility for nefarious purposes. Usually they know exactly what they want, exactly where it is, and exactly how to get there. They probably understand your facility fairly well. How do you deal with an attack like that, Brett? Can we catch this person either during or after? I think in an audit environment after the fact, we’re going to be able to track that person through the facility. Is that correct?
Brett: With the caveat that from the Bastille tools perspective, we can detect anything they have on their person that is emitting wireless signals — which for most of us is a lot. I have a phone I carry with me all the time, and it emits cellular, Bluetooth, and Wi-Fi pretty much constantly. A lot of people have smart watches, sometimes medical devices. There’s just a lot of stuff we carry on us all the time. So if someone is penetrating the facility and they shouldn’t be there, we’ll see that wireless signature. But it should be paired with other physical security mechanisms too — the most robust way to do that is with your standard video surveillance tools.
Correlating Wireless Signatures with Badge Audits
Chris: The great thing here is that when we’re reviewing this, we can use those tools together. We can look at the audit of the physical access — who was presenting their card at the time. They can see that three people went in, and of those three, we know one had a card. Now we can start zeroing in on who was there and where they went, and pair that up with those physical access controls.
Turnover and Risk to Critical Infrastructure
So there’s social engineering, there’s insider threat, there’s contractor security management that should be taken into consideration. But one of the things that is also prevalent is hiring when you have large turnover — and surprisingly, data centers have fairly large turnover of people. The larger part of your employees are going to do a great job and do the right thing. But sometimes you get nefarious people who are either being incentivized or want to cause issues.
Sometimes you don’t know who or what, because there isn’t a camera in every place and there isn’t a device covering every area. This critical infrastructure space is extremely important because everything there costs a lot of money. It’s easy to damage if somebody has nefarious intentions, or if they’re being let go but aren’t gone yet and they cause internal issues. Again — there’s not a camera everywhere.
The Dark Data Center and Wireless Command and Control
Brett: Let me chime in on this one. You mentioned that these systems are relatively easy to break. I think that’s true in some respects, and hopefully not as true as I’m afraid it might be. One thing that’s come up in discussions with customers is that these kinds of tools, if they go down, can cause a huge impact to operations — they could potentially shut down your data center. They’re also increasingly equipped with wireless interfaces to facilitate communication and automation.
I’m thinking in particular of a movement I’ve heard about toward going dark in data centers — the dark data center concept, where personnel aren’t needed on site almost ever and everything is automated. But that automation is often facilitated by wireless command and control. The idea that you could compromise those wireless interfaces, possibly even from outside the perimeter, is highly concerning. The fact that we’re moving toward greater automation without necessarily having the controls in place to mitigate the wireless aspect of that risk is very concerning.
That’s one area where we’ve had a lot of interesting conversations with customers who recognize the problem and want to bring that additional layer of visibility into their security suite, to make sure people can’t tamper with these highly critical systems.
Chris: That’s an area I didn’t even think about, Brett. That makes total sense. What a great concept, that dark data center — but I do see a few issues with it, especially from a physical security standpoint.
Protecting the Data Hall
Chris: The data hall, of course, is the lifeblood of the data center, and this is where we want very few people — contractors, employees, and customers. These halls are extremely important not only to the data center facility but to the overall company. So how can we put a layer over this that really enforces our policies and procedures in this space?
Brett: The good news is there’s nothing special needed for this layer as opposed to the others. If you implement wireless monitoring throughout your facility, you can cover just the data halls, but we recommend covering the larger footprint to make sure you have continuity of visibility across all data halls within your data center and adjacent facilities — hallways, offices, whatever there might be.
By implementing this across that entire domain, you get visibility of wireless devices as they come into data halls. Before they ever get inside, you can track them. You can see where they’ve been, what they’ve been doing, and who they’ve been talking to. If a device were to penetrate a data hall, you see it before that even happens, and then you see it as it’s happening. You watch that behavior and can take action when the analytics part of the monitoring tool highlights a concerning event. That might be policy specific — maybe you should never have an unauthorized wireless device inside your data hall. That’s a reasonable policy to consider.
How Granular Is Rack-Level Location?
Chris: I love that. Brett, you said earlier that you can put this on an overlay, and a person reviewing with the DVR function can view exactly the number of the rack that somebody went to. They can get that granular with the mapping?
Brett: I’m going to walk that back slightly, because the accuracy we have may not be rack specific. A line of racks is what I’m imagining — if you’re walking down an aisle, we can be pretty sure which aisle you’re on and within a couple of racks.
It really comes down to the accuracy we can obtain from wireless signals over the air. It gets complicated because these signals bounce off everything, especially metal. When you have a ton of metal in here, you get a multipath effect. As the sensors see those signals, they multilaterate the incoming signal and locate it somewhere, but multipath will skew that a little. Over time we get a pretty good sense of where things are, but in any given snapshot you’ll have some error. That’s the nature of it — you can’t get it perfectly, but we do pretty well. We’ve finessed these algorithms over a long time, and we find we get good resolution on the order of one to three meters.
Chris: That’s pretty granular. So we can really protect our information in these areas, which is the end goal — either showing nefarious intent using those analytics, or, ninety percent of the time in an organization, supporting the after-action audit during an investigation of what happened, why, where, when, and how. You see how granular we’re getting. We came from the outside and looked at each ring as we moved into the facility, into what I’d call the most important information there — that core information belonging to multiple customers in a colo, or in a hyperscale environment, large AI-type information flows that they do not want slowed in any way.
Beyond Dongles: COTS Devices as Attack Tools
Chris: So now we’re talking about cabinet doors and asset visibility tracking. You mentioned dongles — are there other devices they could port into the servers, or in some cases into those large energy interfaces?
Brett: Dongle is a pretty generic term — anything that has a wireless chip embedded in it. And that could be a really, really small form factor. There are lots of devices available for doing wireless attacks, and any of those are potentially useful.
We had an example published in the news just a few months ago of an attacker who plugged in a Raspberry Pi device with an LTE modem embedded in it. They plugged it into a switch on a bank’s ATM network. It wasn’t noticed for a long time — it was in some cabinet somewhere, not a data center, just a cabinet with network equipment. They plugged it in, walked away, and then did command and control over the LTE cellular connection. They began to penetrate the network, did some clever living-off-the-land work, and were able to operate with impunity for quite some time.
So that’s an example: any COTS device with a wireless interface can be used to create that wireless link, which often serves as the initial command and control function but can also serve as a data exfiltration path.
Baselining, Whitelisting, and Rogue Devices
Chris: I would imagine there are other RF or cellular devices in the facility that your system learns as normal, and then you’re looking for abnormal events?
Brett: That’s part of it. We do some amount of baselining, and then understanding what has changed over time is a useful metric for seeing what has been introduced that maybe shouldn’t be there. We can also tag devices as authorized when we know they exist. For example, we’ll often whitelist all of the access points in a facility — we know they’re supposed to be there. We’re still going to pay attention to them and flag anything weird, but those aren’t the devices we care most about. We’re interested in rogue devices that maybe shouldn’t be inside the facility.
Chris: So when somebody is talking about that dark facility, you probably have a really good understanding of what it looks like on a day-to-day basis, and when there’s an anomaly you’re able to catch it right then and there.
Brett: That is the idea. I can’t claim it’s foolproof, but it’s pretty good in the fact that we have continuous visibility, plus an analytics layer that uses both heuristics and AI/ML tools to highlight issues. It’s as robust as I think we know how to make technology like that. But I wouldn’t claim it’s going to see absolutely everything.
The thing is, though, it will see every signal. It will see every device that’s transmitting. We’re working continuously to improve the analytics, but the fact that something new appears — you’ll see that. That should be your clue to go look harder, especially if you have exclusion policies, which is probably the most robust way to do this. Say things shouldn’t be in here unless I’ve authorized them, and you will see anything new that shouldn’t be there. That part is foolproof. I just wanted to walk it back a little, because I can’t guarantee we’ll catch absolutely everything that shouldn’t have happened — but we’ll see all the devices.
No Single Technology Is the Solution
Chris: Of course. And again, you’re talking about having multiple types of controls in place, of which yours is pivotal and sits over the top for the purpose of your piece of that security pie.
Brett: A hundred percent, Chris. No single device and no single technology is the solution when it comes to security. They need to work together to create that protective layer. What we’re offering is something unique and something really needed, because there’s this whole wireless attack surface that by and large we haven’t historically paid a lot of attention to.
And we need to. Issues like the CVE database analysis I described and the report we put together to highlight the growth in vulnerabilities, issues like the news releases of different wireless attacks — whether they’re malicious insiders or a compromised device — there are so many things out there that cause concern. As an industry, we need to shift our attention more toward that end and be aware that it’s an attack surface that needs monitoring. That’s what we offer. We can integrate with other systems to make the whole security posture better, but our focus is on anything and everything wireless.
AI Data Centers and Nation-State Attention
Chris: That’s amazing. I think it’s just a huge piece of that security pie that nobody has really looked at.
Brett: The good news, Chris, is that we are seeing people sit up and pay attention. When it comes to AI, we have operators, owners, and customers of these facilities who are highly concerned about regular attackers but also about nation-state actors and their ability to use wireless as part of an overall attack chain to compromise the extremely valuable data hosted inside these facilities.
Bastille recently announced a partnership with Oracle where we’re rolling out wireless monitoring to Oracle’s global footprint of AI data centers. There’s a huge amount of work there, and we’re working with a lot of Oracle’s peer organizations and customers to do similar things for their ecosystems. So this is getting noticed as an area of risk that deserves attention. It’s been a journey to educate people about the risks, but people are seeing it — they’re seeing the threats, and they’re working to mitigate those risks when it comes to the high-value IP they’re trying to protect.
Inside a Bastille Deployment
Chris, you’ve talked about auditing needs and how this applies across the layers of a layered approach to data centers, and I appreciate that perspective. When it comes to putting this all together, I want to make it a little clearer from these pictures. On the left you see one of our sensors hanging from a downrod from the ceiling. There are lots of ways of mounting these — they can go above ceiling tiles in facilities that have them, so they’re hidden — but basically we deploy these throughout a facility we’re monitoring.
Those sensors scan the RF spectrum to detect and identify wireless emissions: cellular, Wi-Fi, Bluetooth Classic, Bluetooth Low Energy, Zigbee, and the related IoT protocols. They work together, because each sensor knows its location, and they use the information gathered from scanning the over-the-air spectrum to localize those emissions in space.
In the partially hidden UI just behind that picture of the sensor, you see colored icons overlaying a floor plan. That’s similar to what we have in the DVR UI — in a data hall, for example, you’d see lines of racks and an icon sitting somewhere that identifies its emissions as probably coming from one specific rack. As I say, there’s a little error you have to accommodate, so it could be the rack next to it or the one across the aisle, but it’s going to be really close. You get that visibility both in real time and historically, and we have analytics tools running in the background that help you slice and dice the world these sensors are seeing.
Floor Plans, Blueprints, and SOC Integration
Chris: I love the fact that we can use those blueprints — or in some cases just an environment where we know where different rooms are. They’ve probably already figured out what’s important to them and handed you that mapping to overlay with those icons, which is really important. Almost all practitioners and end users, being the data center companies, already have that information in PDF from Bluebeam or one of the other products they use to show where all their rooms are and how everything is coordinated throughout the building. So it’s great to see that you can pull that in, and presumably export that information into SOC environments so they can view it as part of the overall picture.
Brett: A hundred percent. In addition to auditing at every layer, you can push this data to any endpoint you want. It could be a SOC — you send a webhook with filters, or you open up the pipe and everything Bastille sees goes straight to the SOC. There are lots of ways to configure this, but basically you send the webhooks, the SOC receives that JSON information, interprets it, and incorporates it into the larger picture of facility security. That kind of integration is critical for making this useful for people.
Resilience Begins Before the First Alarm
Brett: I think that brings us almost to the end. Chris, you’ve got a quote here about critical infrastructure resilience beginning long before the first alarm. Do you want to add to that?
Chris: I would just say that if I had to make a tagline for our presentation today and point it at what I’d want people to take away, it’s that mesh we saw earlier over all of the layers — so important, and such a critical piece that I had never looked at.
Brett: Thank you, Chris. I appreciate your insights on all this. I think that brings us to a close. Justin, back to you.
Q&A: The Drone Threat
Justin: Brett, Chris, thank you so much for a fantastic presentation. We’ll go over now to a few questions. Brett, how is data center security evolving to combat the explosive drone threat?
Brett: From my perspective, the ability to see wireless emissions is one way to detect drones and identify that there’s a drone nearby. That isn’t foolproof, and there are obviously drones that mask their emissions or make it difficult for us to make sense of what’s on the air. Perhaps the most robust solution you could employ theoretically would be an active radar solution, and there are a number of those on the market for that specific use case.
Q&A: What to Include in New Builds
Justin: Thanks so much. What can be included in new builds to help monitor and deter these types of threats?
Brett: Obviously we’ve been talking about wireless monitoring solutions, and that’s a simple and straightforward thing to implement, especially in new construction. But it’s also possible to outfit existing facilities, and we do that all the time. I highly recommend at least looking into and understanding the threat surface better, and understanding the capabilities of such monitoring solutions. This is getting increasing attention within the data center community, and a lot of people are beginning to implement this kind of capability.
Q&A: Meeting Elevated RF Requirements
Justin: Brett, as it pertains to data centers, is it possible to meet elevated RF requirements? And if so, what’s recommended?
Brett: I’m not sure what the questioner intended by elevated RF requirements. If they’re online, I’d be happy to look at that. But if it’s simply understanding what’s on the air, then the solutions we’ve been talking about today would fit the bill. There may be other questions this person has in mind that I’d be happy to discuss with them, so I’m happy to go into that further.
Closing
Justin: Thank you so much, Brett. Thank you, Chris. To learn more about Bastille, please visit bastille.net. We’ll send out a recording of this later in the week. Thanks so much.