Keith Mokris – Why Left is the Direction to Go for Secure DevOps
Developers and DevOps Teams are at the forefront of new application architectures and deployment workflows to achieve greater release velocity and scale. As they adopt containers, Kubernetes, and serverless technologies, security is catching up to protect these architectures and applications—not only at runtime but also across the application lifecycle.
In this interactive technical session, join Keith Mokris from the Prisma Cloud by Palo Alto Networks product team for a presentation about the latest trends in cloud native security, including exploring security of IAC and applications and git repo vulnerability management.
Transcript
Hi, everyone. Thanks so much for joining me at this DevOps experience Day 2020. My name is Keith Mokris here at Palo Alto Networks with Prisma Cloud.
And I'm excited to provide my overview, presentation and demo today. Why left is the direction to go for secure DevOps. So let's dive in.
Here's a highlight of what I hope to cover today, first and foremost, I want to highlight what the trends are in cloud native security, then focus on how security can enable cloud native adoption at their organization. And then finally, I'm going to highlight a demo of Prisma Cloud, starting to look at how you can prioritize risk in a running containerized application on Kubernetes, then how you can integrate CI/CD capabilities across infrastructure as code templates and the application layer, and then finally highlight some of our newly released git repo vulnerability management capabilities here that we can highlight today. So let's dive in.
First and foremost, I want to highlight some of the trends in cloud native security that came out of our 2020 state of cloud native security report. And so what we did here at Palo Alto Networks is over the last six or so months, we interviewed DevOps practitioners, cloud platform engineers, cloud infrastructure architects and security architects and asked them about their journey to the cloud and how they're moving their workloads to the cloud securely. We focused on key industries worldwide, and I want to highlight some of the findings that really allow us to look at the data behind the state of cloud native security, which I think sets the foundation for this approach with shift less security around DevOps.
And so first and foremost, based on the research, we're definitely living in a multi compute world when it comes to running today's cloud native applications. So in our survey, 86% of companies expect their usage to increase or stay the same over the next two years. So they highlighted the fact that they're certainly using a combination of virtual machines, containers, containers as a service or managed Kubernetes, which is really become one of the dominant forces for running your cloud native applications.
And then certainly PaaS or server less offerings. And I don't think it's any surprise to anyone in the audience to see containers and containers as a service. If you were putting those two together, really leading the response from our organizations.
And so as we talk about this, as we get to secure and DevOps, we want to really look at this from a not only security perspective, but really how do these architectures impact security at scale? And at the same time, as we asked organizations what they expect from the evolution of the cloud, they expect this evolution to be continuous. And so 80% of respondents shared that their companies cloud infrastructure is constantly evolving.
And so this really brings into the notion of integrating security into the pipeline, leveraging tools that are scalable and also leveraging tools that provide you with a lot of advantages from automation because you're just not going to be able to do everything manually in this world that's constantly evolving. Next, we asked organizations what are their top challenges for moving workloads to the cloud? And I don't think that these responses will shock anyone who's watching today.
But I think it's a good reminder to understand that a lot of people in the world moving workloads to the cloud are dealing with a lot of these challenges. First and foremost, while the cloud makes some things more simple and there are certainly functions you can offload to the cloud service provider. There are still a lot of technical complexity that you need to figure out at your organization.
This involves the technology you're using, your architectures, your deployment workflows, how you manage data. And essentially this is definitely a top concern for any organization. At the same time, maintaining comprehensive security is also vital because you are essentially off sourcing some of these responsibilities to the cloud service provider.
You still have a lot of responsibilities that you need to take care of yourself. At the same time, maintaining comprehensive security is difficult because you might not have the right purpose built tooling to focus on these cloud environments. And then finally, just because you've moved your workloads to the cloud doesn't mean that your concerns around compliance go away.
So whether it's an internal framework that's a really important to you or an external compliance regime like PCI BSS or HIPAA, and obviously there are dozens of others, you need to ensure that it's the data configurations and applications themselves that meet those compliance criteria. When we ask security teams what their top issue is when it comes to cloud security, I don't think it's too surprising to see that security teams have a lot of issues they're concerned about, and many of them prioritize them all differently. And if you look at all of these different concerns.
Top concerns like data exposure or application vulnerabilities, and then you look at a delta that's not that big, you have things like credential leakage, insecure APIs or infrastructure misconfiguration. You see that everyone approaches these concerns quite evenly. And when you look at cloud resources and the applications that run on top of this cloud infrastructure, you start to see how some of these threats can really magnify one another.
So if I have an application with vulnerabilities and then I have other improper configurations or insecure APIs, now I essentially have kind of an exponential or higher level of risk based on all of these contextual metrics about each individual application or resource. And so it's something to really keep in mind that as you approach security, you're not trying to hit a single target. The target is moving.
And based on your different concerns, day in and day out, you need to make sure that you're approaching all of these at the same time. When we talk about providing it, the notion of comprehensive cloud security, a lot of these things, again, shouldn't surprise anyone who's watching today. First and foremost organization shared that they need to get visibility into security vulnerabilities.
And if you look at the application security industry, vulnerability management is a key concern that a lot of organizations need to take care of. And we'll certainly in the demo talk about how we want to make it easier to help organizations prioritize risk then. And this certainly would map to things like complexity and moving to the cloud.
Employee training on security tools and employing training on safe practices were also major concerns for comprehensive security. So here we're not talking about the tooling you're using. We're talking about how do we actually train employees to use that tooling or leverage best practices, which, again, people are a huge part of this shift.
So we need to keep in mind that everyone at the organization really contributes to your overall security posture. And then finally, organizations certainly shared that evaluating the current state of their security was difficult. And again, if we go back to kind of this notion that a high amount of respondents shared that their infrastructure is constantly evolving, it becomes really difficult to audit what you have today given all of this continual evolution.
And so, again, DevOps is certainly a contributor to this cloud, native architectures as well. And what we want to do is plot a path forward to where organizations can really improve their overall metrics for success and security. One of the things that we highlight, and this will be the last couple of slides I focus on before I really get into the exciting demo, part of today's presentation is that we brought together a new cloud security metric that we called cloud security preparedness by looking at 19 different security best practices based on organizations responses to our survey.
And what we found is that organizations, only 18% felt that they were highly prepared to keep their cloud, a state secure, and almost 30% of companies fell and self-identified into the lowest prepared category. So if you really think about this, we have a small fraction of organizations that feel really confident about their practices, their security tooling and all of their efforts and moving to the cloud. And there's a lot of people that might be out there that are looking for best practices and tools and processes that they can leverage to improve this.
And so that's really what we're going to be doing today, is learning what did the high group do that maybe we can all benefit from? And if we look and this is really kind of a jumping off point for talking about shifting security left is that a highly prepared group said that embedding security across the application lifecycle greatly improves their security outcomes. And so by embedding security into the DevOps process and embracing the notion of DevSecOps, organizations have a huge opportunity to deploy more secure applications, which is a real core requirement as you embrace cloud native architectures.
And as we move forward, I want to kind of remind us, like, why are we shifting security left and what does that mean when we look at the application lifecycle? And so a shift left approach is really important because that really gone is this day of the development or cloud infrastructure teams throwing an application over the wall to security where an application gets locked down before it gets deployed. So organizations are shipping code more rapidly and more quickly than ever before.
And ultimately, security teams really want to be able to foster collaboration with all of their DevOps leaders at their organization. So this inquires, speed and accuracy from security tooling in working with the development teams that organizations, you need to make sure that everything you're doing can plug right into native tooling. So we want to provide security teams with visibility and control without slowing out, slowing down the development and DevOps teams that are focused on releasing value with software more and more quickly and as everything changes.
There are two key things that become important with shifting security left or embracing DevSecOps. First and foremost, the idea of manually doing everything is really out the window. Automation is really an effort that's essential in order to scale security.
They're just not going to be able to do it if you have a lot of manual efforts. And because everything with DevOps is so focused around automation, security also needs to automate. And in doing this, you can ultimately hope that you're improving your overall code quality, making sure that the development and DevOps folks at your organization have embraced these best practices and ultimately you're improving the overall security posture of your applications.
So as I prepare for the demo today, here's what I'm focused on here with Prisma Cloud. We provide two core capabilities when we talk about integrating security across the application lifecycle. And as we look at these steps across build, deploy and run, we're focused on two main areas, infrastructure and applications.
And you can almost think of those as two key layers to the capabilities in our platform. So at the build phase, we want to provide vulnerability and infrastructure as code scanning integrated with all the development tools that you're using today. And I'm going to show you some of the different ways that we can plug security in here.
First and foremost, we want to provide you the easy capability to scan infrastructure as code templates as part of the IDE, SCM or CI process. And within that CI process, we also want to be able to scan your container images, functions, or even a host for vulnerabilities or compliance issues where you can create thresholds over what can progress across your development pipeline will surface these details within our native build tools as well as in our central dashboards. And then when it comes to deploy, we want to provide these same checks and control over all your automated deployments, as well as the ability to continuously monitor and control your container image registries or your serverless repositories.
So, again, as a basis, we want to provide that continuous visibility, but also allow you to set key guardrail controls over what can progress to production. And then at production, we want to combine leading cloud security posture management where you have visibility and control over all your cloud infrastructure and resources, which we support today on AWS, GCP, Azure and Alibaba Cloud. And then we want to provide runtime protection for your workloads and applications running across public and private cloud environments like the ones you see below this graphic.
And so in this in my demo today, what I'm going to be doing is showing you some of these different build controls using some of the native tools from GitHub and then also showing you how we can see that data within the Prisma Cloud dashboard. So here is what I want to start with is I want to show what we provide from a runtime telemetry standpoint. So in the demo here, I've authenticated with several different cloud providers and I've also deployed our agent to protect the actual running host and containers.
So you can see what that looks like at runtime. And so here, for example, if I were on the security operations or security architecture team, I can come in and get a single look into all of the different resources that I have running across multi or hybrid cloud environments. And I can drill down into any of these to learn how they're passing or failing my policies and implement policies to control anything that may get deployed into my running environments.
And this is really forms the basis for the cloud security posture, management capabilities that we have in the cloud. And then if I navigate down further, what I'm going to be highlighting are the cloud workload protection capabilities that we also deliver within our single solution. And here what I'm going to do is I'm going to pull up a view that we call our container radar and we provide this radar for those containers and serverless applications where if I have any applications that are communicating with one another, where my defender agent is deployed, I'll be able to see more information and telemetry about all of those individual applications.
And it's just an easy way to understand the data we're able to provide so then we can get into our shift left DevSecOps moment. So here I'm going to click on a container that I have deployed. And one of the things you'll immediately notice is that I have this crimson color connected to this container.
And so I can see that it has a high number of not only vulnerabilities, but also some compliance issues. So with a single click, I can expand this window and learn more about what vulnerabilities are impacting this running container I have in my environment. So what we're going to do is continuously monitor any application that's deployed or any host and identify any of these issues that we see and continuously monitor this based on the threat intelligence we're pulling into our platform.
So here, for example, we can see all of these issues sorted, sorted by the passenger library, the OS component, the severity and the description of exactly what details you would want to know about these vulnerabilities. So if I expand this vulnerability here, I can see more information about the package. I could go out to the initial CD source, see the vendor fix status and look at the important risk factors that impact the severity of this vulnerability.
And I can come over here and see the compliance data that accompanies this. So here, for example, we're able to do is look at things like the Linux, Docker and Kubernetes CI benchmark, as well as custom compliance checks. And we can see that, unfortunately, this image is failing one of those medium compliance checks.
So for a lot of issues, this might not be too bad, but if it's something you want to customize, you could certainly do so within our platform. We also have a lot of other powerful views into the current security intelligence of this individual container. So what I'm doing here is I can actually hop over to our layers view and go layer by layer through this image to understand exactly its vulnerability posture.
So I can see here that this base image contains a lot of critical and high vulnerabilities that I may want to remediate or pass intelligence to my development or DevOps team. We provide global rollups so you can quickly understand all of the vulnerability or compliance issues that you may have in your environment. So, for example, I can come in here and see the essentially highest ranked CVE in my environment and I can see whether it may impact an image host or function.
And if I have any vulnerabilities that span all of these components, I'll quickly identify exactly where it is in my environment by expanding the risk tree. So here we can see the name space and the exact host or cluster where this vulnerability is running with a lot more details about it. So now this really brings me to what if I wanted to essentially tell my development or DevOps team to rebuild one of these components and redeploy it to improve its vulnerability posture.
And so that brings me over here to my GitHub window. And so what I have is I have a very simple code repository where I build a container image and scan it for vulnerabilities. And if I wanted to, I could set a vulnerability threshold within my central console based on, again, a vulnerability or compliance setting to essentially alert on or fail that build based on my policy.
So what I'm going to do is to kick off a new build. I'm going to simply edit my doctor file and I'm going to essentially grab the latest version of Python in order to build this image. And so what I'm going to do is in this new part, I'm going to essentially say hi DevOps experience 2020, and I'm going to commit these changes directly to Master and what we're going to do is we have an action that's going to scan this for vulnerabilities.
So it successfully ran a couple of times as I was testing this. And so we'll hop into this build and scan step here. And if you haven't checked out GitHub actions, I highly recommend it.
It's a really cool way to set up a lot of automated workflows that will kick off as soon as you have a pull request or a check in. And so what we're doing here is we're building and tagging this container image based on a couple of workflows that I had. And after it's built and tagged, we're downloading the command line interface from the Prisma Cloud console and we're going to scan this image for vulnerabilities.
So it's really simple and it's something that anyone could for and commit with a license that they'd be able to access this themselves. And in just a couple more seconds, we're going to see those vulnerability scan results right here in our GitHub action. And so it's kind of fun to let it kick off, live and work through all these different steps.
Perfect. And what I'm going to do is the scan step is completed and then make my window a little bit smaller so you can see the settings all in one window. And we have the scan results for the image that I just built based on that Docker file.
So here we can see that I have what's essentially an image that I probably would want to deploy on to some production infrastructure based on the fact that I have a lot of high severity vulnerabilities. And there are things that you may want to dig into further. And if you had different rules governing the progression of this image, you could prevent it from being built and deployed or built and sent and stored to your container image repository.
So here you can see that we have some open vulnerabilities so they don't have a vendor fix available. And we also may have some compliance issues based on how I've configured the image. And if I go through any of these here, I can look at them in more detail.
And what's really cool is if I hop on over to the images and hit the CI tab here, I can see that exact image that was just built in my system within the Prisma Cloud console. So you can have developers and DevOps teams throughout your organization seeing results in their native tooling and within the central system here. So if I hop in, I'll see the same exact information that I just saw within GitHub, and then I can even come over and see that layer's view that I like to show earlier.
As I mentioned, I can come over here and see the how it maps to different compliance settings. So here, for example, I didn't create a user assigned to this container image, which is certainly one of the high severity recommendations from the official Docker CIS benchmark. Now, I'm going to provide visibility into a couple other scenarios that are really important.
Getting control over your container registries is also important, and that's why Prisma Cloud is going to continuously monitor your repositories for vulnerabilities. But we also have some other integrated capabilities that are really nice to highlight. So one of the things that I mentioned earlier is the ability to look at infrastructure as code templates for miss configurations or compliance issues.
And so I have an example of that here. In a GitHub repo as well. So here what I have open is the SOC shop deployment YAML.
So a Kubernetes deployment, YAML and you can go through here manually and see, several hundred lines of code. So for me to understand the compliance status of all of these different configurations manually with my own eyes would be quite difficult. So one of the things that we do is we have a set of unified DevOps plug ins.
So whether you're using VS studio code, IntelliJ, or GitHub, all of these plugins are available from the Palo Alto Networks documentation site. And I have the DevOps plugin installed for GitHub. So I've configured the Prisma Cloud IaC scan.
So if I had a pull request on any of my infrastructure as code templates or any build's or updates, we can automatically scan those templates for misconfiguration or issues. So this scan completed automatically and if I hop into the details, I can see those security issues. And so, again, these checks are mapped to not only the docker and Kubernetes benchmarks, but you can also implement custom settings as well, all configured from either the template configuration or potentially the central dashboard, depending on the check.
And so here you can see that I have some major misconfiguration in my YAML here that I would probably want to address before I deploy this on my, you know, some sort of running production stack. There's one more capability that I'll highlight that we just released. That's all part of Prisma Cloud.
And so one of the questions we get a lot from customers is, is there more data that I can gather before I've essentially compiled my infrastructure applications? And so one of the things that we've added is the ability to scan git repositories for vulnerabilities. And so what I did in order to scan another one of my git repositories is I added the directory for a public repository.
So my username is and I highly recommend if you've never seen the Docker curriculum that uses this food trucks app as an example to learn docker. It's a really great tutorial that you should check out in here. By authenticating with this repository, I can see updates and vulnerabilities along with all of the risk factors for the components that are stored in that git repository.
So this is another powerful set of capabilities for shifting security left before I've even built my application. And so I really want to say thank you to everyone who's seen this demo and was able to see all of the capabilities we're delivering across, build, deploy and run. And before I leave you today, I just want to highlight the fact that Prisma Cloud is the industry's most comprehensive cloud native security platform.
I hope you've enjoyed the capabilities I've been able to highlight today that include cloud security posture management, cloud workload protection, as well as other capabilities that are part of some of our recent announcements, like cloud network security and cloud infrastructure, entitlement management. I want to thank you so much for joining this presentation as part of the 2020 DevOps Experience. And if you have any questions, don't hesitate to navigate to our website or reach out to some of our other social handles.
Thank you so much.