Chenxi Wang, PH.D – Software Supply Chain Security: Buzzwords or A Sustainable Market?
Software supply chain risk is certainly buzzy these days, from the executive order to CISA directives, everyone is talking about supply chain risks. But what does it mean for practitioners who have to deal with the actual risks that come with the use of extensive third party software? This talk examines the supply chain risk landscape, market trends and practical solutions.
Transcript
My day job these days. is a venture capitalist I run my own Venture fund and we fund early-stage cybersecurity companies and one of the reasons I'm here is in the past. Six months also, I would say I probably got 20 pitches on s-bomb related startups.
And I'm a researcher at heart. So I have a PhD in computer science and I did a lot of academic research in my early days. So this is what I do is I just did research.
I put everybody's pitched together and what they want to do and I did a map. And then I went to so Alan talked about that. I have a actually a large network of women CISO and security practitioners and I got together with them.
I say hey, what are you doing? There? Are you doing anything who's asking you to do things?
And if you're doing anything, what are you specifically doing? And so I took that map I developed from the vendor pitches and then I did my research with the practitioners. I put them together and they're very different.
So I'm gonna talk a little bit about that difference today and also actually join the call with the the previous speaker that I think as practitioners in this space. You know, that gentleman from ADP is an example we can do a lot of things to push the state of art forward and along with folks like me. I can challenge my companies and the startups that come to pitch to me to do the right thing.
So I'm gonna start with some of this list. So first of all, are you asking your vendors? to give you s-bombs in their software products I asked my csos and you know how what the percentage of them said?
Yes any guesses? What's your guess? Yeah.
Two four four out of four out of hundreds of customers ask them. So my number I mean I asked about probably on the call of 30 people and it was single digit percentage. Right?
So it's similar and I said well, do you think your customers will ask you and some of them said Maybe next year now. Son, the single digit percentage are from people actually produce software products, right? They they release software.
There's also quite a bit of folks that coming from SAS Services, right? So ask those SAS providers just do your customers asking you no zero, right? Well, you put your data your information in SAS.
Why don't you ask them for a spawn? No, it's just not people's radar screen. So.
Yeah, another question. Yes, I'm getting into that. and we get into that so the first is At the very end of the value chain the year the receiving and you're the software consumer.
You must push this requirement up the stream. Okay, even though maybe difficult today. You may have the vendor made push back.
You must start asking them because if you don't if you the ones who control purse strings, you don't it's not gonna happen. Um, even though there are lots of startups say, oh I can generate s-bombs for you can generate a sponsory that still very difficult to do first is end users must start asking the question second is there has to be a usable interchangeable format. So we've got how many how many SBOM formats I can count three.
They're more than three. The major one three, right? So are they interchangeable today is can I do it very quickly.
No. Another thing is so one of my sister said I can ask them for a spums. then they will give me their software with response.
I don't know where it is. I don't know how to search for it. I don't know how to automatically collect them and actually use them.
Now. This is from a company that actually doesn't write its own software. They just use it.
Right but they use it for that customers. um, but if you're a software producer yourself Think about it. You have to collect all these s-bombs and metadata and put them together and generate your own.
And I know one of the large software providers here in the in the Bay Area. They have a team of 45 people 45 people all they do this team 45 people is taking everybody's s bombs process them and write them into a format that they own production team can handle right? It's 45 people full-time job, and that's just ridiculous.
Um, so we need better formats interchangeable formats. We need automated tools to process them with the software. Another thing is we talked about s-bombs with software.
Any software comes without apis these days. No, usually they come with apis, right? So what's on the back end of that piece of software that you didn't write, but your software is calling, right?
Do you have a smart for that? No. How do you get a spawned if you're using API?
We don't know. What do we do it's these are all open questions. I remember in 2010 when I was giving a talk at the cloud security conference.
the early days in Cloud There was a a CIO of a large Enterprise stood up in the room and said I want to share a stat. Statistic so they did an audit of the enterprise software and back then, you know was a lot of cloud a lot of people have like packaged software and they're running on premises. And he said they did an audit of the list of software.
They run internally 30% This is 2010. Okay, 30% of their software applications running in the data center call out to AWS 30% right? And he's like, I have no idea why they calling out to AWS.
We didn't know they were supposed to call out to AWS. Do I stop it? I don't know.
Maybe it's critical. So. Here are the problems is that we have I think of software now like a spaghetti, right?
You know, you have a ball of schedule there evolves getting here and lots of interchangeable relationships between and that ball may come with a Spam and that ball may come with a Spam guess what some of the interchange or the relationships in between either you don't know about it or it doesn't come with our spawn. So what do you do? so to try to tease that apart another critical component to a spawn is you have to have an inventory of the apis that you're using and what libraries are there on the other end that could be pulled in to your production systems and then think about how to push your SBOM requirements up the stream there.
We have to have this ecosystem and network effect. Otherwise. we nog in a collectively raise the security of our industry Another thing that is really really interesting for me.
Is that software producers? Right? So they are getting s bombs.
They're getting asked to produce s bombs if you are selling to government today. the you know what they CISO and sometime VP of engineering is deathly afraid of You write an s-bomb in your software. What are you disclosing?
Do you know what your disclosing? Yeah, your IP. Yeah, you're intellectual property right?
Do I want to tell everyone what libraries are using my software product? Maybe not. So what should I tell customers while still preserving my intellectual property?
That's a big open question. So I need way to redact things in aspan. So, how do I redact that again?
It's it's a manual effort today. So how many of you are from? software producing companies and you know everybody software consumers, but some of you are a software producing.
Okay, and are you I mean you're nodding a lot. I know you get these pain points are your customers asking you for response today? They are interesting, okay.
But let's write four four. It will be more it will be more. Are you thinking about producing ass bombs and and upfuscate certain parts of it, so that no.
He says no, so I have a lot of CISO and practitioners. Well, I work in startup. So everybody is definitely afraid of some of you taking your your intellectual property away so that everybody's talking about how do I generate s bond without giving my intellectual property away?
on one thing that I thought would be really interesting is some of the large Enterprises already doing this but it's not done in enough in all the companies Netflix and E-Trade used to do this a lot one and Etsy used to be the three companies that did a lot of this in the beginning is they package up a lot of common functionality inside the company, right? So nobody should be writing the authentication packages themselves. Nobody should be writing their password processing package itself.
So the package it up and write it in a way that it's very standard and every other applications use those services and for that service Daniel becomes one time effort or not quite one time effort, but at least a somewhat diminished effort to to control the layers of software building to that and generate as palms and then it can be used by many different applications. So that's inside the Enterprise but think about and you're you're doing things for open source, and possibly that can become a distributed effort throughout the industry so that we all use standard. Is some of the open source others is not but if all those services are tested and in attested with s-bombs and the Integrity of which are verified.
That's a good thing. one more thing that it came up in probably earlier this year, which is a new requirement that I have a Let's just say large equipment vendor that I know of and they obviously they write their software and goes into the equipment and the equipment, you know goes in lots of Telecom networks and for government and whatnot and they were doing audit of their software libraries and they found lots of open. So, I mean, they know there are lots of Open Source, but what what interesting what interested them was like they found a few open source packages that were essentially written by individuals located in Russia right and and then they start digging into it more.
And so these I'm not saying these individuals have any malicious intent, but do you know who is actually contributing to the software package? Where are they sitting? What other software package are they contributing to and if you are writing software go into a critical equipment.
That's that's on the backbone on the internet on going into government. Shouldn't you know that? And how do we know that?
Do we have a open source or third-party Library reputation system that we can trust today? What like a conference? I'm sorry, I can't.
Carfax Anyway, so we can talk later. The what I was going to say is they are some open source packages out there actually open source for open source intelligence. Some of those are really interesting to take a look at there is I can tell you a few commercial solutions that are also providing that now one of the things that I'm challenged some of my companies to do is looking at How these few building a car right the car manufacturer would be able to trace back to every single component in the car.
Right who I produce this component when this component was produced what design version it was right? Not for software today. How do we get to that level of fidelity and integrity?
We're a long ways away from that but they are little steps we can do such as every step on the way ask your provider. Give me that intelligence and tell your providers to give me that intelligence and another thing. I know you guys talked about how a stop stop getting random libraries from the internet.
Guess what? I know very few companies that can actually do that exclusively. Because you are under pressure to push out your software to your customers and then maybe millions of dollars or even more on the line.
Are you going to stop production of software? Just because you don't have the right packages your developers are very resourceful. They're gonna find the right thing.
Yeah. Well, maybe not the right thing right thing, but they're gonna find the right functionality for that purpose and they're not going to look at where it's from or is the right version and they're gonna test it works like done right and you can stop them but they'll get it from somewhere else that personal laptop. So one of the things is Understanding they are going to do that.
But give them the guidance that if they are going to do that then they have to document it. They have to let you know where it's coming from because the day they download they didn't say where to come from 30 days later. They're not going to know where you came from.
Right? So give them the right guidance and framework to do that. Another thing that I want to Basically is the industry together if we don't do this, right if we don't do this today, we are getting more and more software produced every single day and our debt is going to be exponentially increasing if we don't start control this problem.
So my last comment is that if your software consumer go Upstream ask your vendors to give you intelligence, even if it's crappy ass bomb today by start now. If you are a software producer. Start getting your hands on the different formats and look at who can help you in automating controlling and managing and aggregating those together as a first step and then do the Integrity control to say Choice back to each component that you're using and putting in your ass bomb someday.
Only then we can get to a level of software confidence and integrity that we can be comfortable of and I I don't know I predict. 10 years questions High Chancey, thank you for the presentation you brought up a very provocative topic with the idea of contributors to projects that may be under foreign influence, etc. Etc.
Can do you see an alternate? To having good enough metrics on the package itself where we don't have to care so much about that or do we really need to go down to who actually wrote the code. That's a very good question.
I asked myself that question as well. I actually got pitched a few startups that all they do is They look at contributors. So I have to tell you I go back and forth on this.
There's a privacy issue. Right? And there is also the Integrity issue now which which side of the fence do you lie on?
flop but Ultimately, I think if you're contributing to open source, right you are your names out there you are letting other people using your software there has to be a love of accountableity that all of us has to stand up and say I take that because I contribute to that piece of code. They also has to be management of that reputation, right so we can't just randomly. Put a bath stamp on someone without verification But ultimately I would like to see some level of Intelligence on the contributors so that I can take that into consideration.
If I'm going to put that damn piece of code in a machine that that controls some of these life. That's my that's my take. But it's a really good question.
other questions Hi chancy, Mitch Ashley. It's good to see you. Thank you for being here.
It seems to me that when we talked about security around apis and and security of software in general that sort of the the Star Chamber Of apis is the software creation process and if we don't automate that security as part of that creation process because we're moving to microservices and yeah, you know, it's infinitely exploding the number being guys. It's just the fact the matter so it's s bombs and and those practices but if they aren't automated any manual process will never keep up agree you disagree. What do we know this in agree?
You have to automate it right with microservices. I'm it's already becoming a way that the state of things is that you can just stand where your data is going. For instance right this week.
Not even talking about data here. We're just talking about is bombs. But if I'm processing customer day that you use a ton of Services, you know, my lots of my friends are cpos.
Chief privacy officers of large companies that have customer data and they're scared to death they because they don't know they go talk to engineers in their organization Engineers. Don't know how many microservices are there. And how would this CPO know how the Privacy organization now they don't right.
So you must automate it. So tools that allow you to do observe Ebola but up the stack a little bit not just in connections, but in content that's going across the microservices and who's consuming it on the other end and understanding chasing the data and tracing the software components. It's hard problem, but it has to be done.
Pretty sure again from 80 piece. First of all, thank you for raising the issue with your people who are pitching you of raising sort of the bar. Right?
Because honestly, I have to say that the amount of spam I get I get from Little startups that are you know, they have this tiny little idea and it's like this this is not you know, but that's the nature. It's very fragmented application security and and you know is very fragmented. So whatever can be done to persuade a vendors to understand that you know, they could win big if they go up the stack versus I'll fix your little thing and you know, we were able to figure out that this CPE was relevant, you know, half an hour ahead of the other vendor.
Okay, you know, so anyway, I appreciate that. Yeah, I agree that the only common I have for that by the way, I want to talk to you afterwards and Understand what you're doing internally that helps me a tremendous amount. It's startups have a challenge, right so they have to get to Market fast enough to survive.
They also have to give value to customers. Right? So sometimes they work on the wedge initial wedge into the company things that you will need today.
And then they expand now if they come with a platform big platform idea, it's difficult to sell right? So that's the reason but I hear you. Now, what I would like to do is, you know, if you can find me young LinkedIn send me a note and I'll find you I would like to understand what your most compelling problem is today and how you might want to solve this and then I will in my research your mind our again aggregate that and I'll go look for the right technology to solve that.
Do we have time for another question? Okay, one more. Thanks for the presentation.
I just want to ask about maybe it's a personal question or not. You you used to be a professor, I guess and you change your mind into becoming a venture capitalist and specifically you you work with security companies. What made your mind?
How did you decide to go into this path? If you want to talk a little bit about it? That would be nice.
Thanks. Oh, it's a career question. Interesting.
Yeah, I had to in fact I gave a was it yesterday. I give a talk. Yeah, and so this is my third career.
I started I could academic. I was a professor at Connie came Outland University. Then I came to Industry I just startups and and that was a VP research at Forester.
I did industry research now I'm investor so I called this my third career. I get bored doing the same thing. And that's my personal reason but another thing I thought looking back what I have done is you could call that.
I don't know what I want to do when I grow up, but another thing is the different roles that I've had gave me a very rich perspective. I think when I look at things I don't look at things just from Avengers perspective or just from users perspective. I look at technology.
I also look at how the product speaks to users also look at user experience. So I think that makes me a better technology evaluator and investor and that's my view. So if you have the opportunity to do different things in your career, I would say take it.
Because they'll make you a better technologist. I hope all right. So with that.





