EP 276: Route Intelligence From
Contrast Security has released the first “Route Intelligence” functionality in the latest version of their next generation security platform. www.contrastsecurity.com/contrast-news
In this DevOps Chat we speak with Contrast’s CTO/co-founder, Jeff Williams, about what route intelligence is and why you should have a look at it.
Contrast continues to set the bar in DevSecOps, pushing beyond vulnerability scanning to enable more security software.
Transcript
com Security Boulevard. You're listening to another DevOps chat in this DevOps chat. We're going to catch up with Jeff Williams, CTO, co-founder at Contrast Security.
Jeff, welcome. Welcome to DevOps chat. Thanks.
Always a pleasure. Always a pleasure to have you on, my friend. I know you were originally, Jeff, trying to talk at RSA, but that seems to have gotten away from us.
But you know what? So much the better, because I think now we get to discuss something that maybe wasn't around or you couldn't talk about it, RSA and that's something Contrast is rolling out is their first round intelligence. Right.
That's right. We're super excited about it. Cool.
So if you don't mind, why don't we tell our audience a little bit about what what do we mean by first round intelligence? Yes. So when you build a Web application, you have to somehow tell the application, which you are elles go to what code?
And every every language, every framework does this differently. But it's actually really critical to security analysis to understand the roots. That is, you know, this this you are l when it comes it causes this transaction to happen in the code ends.
It's not something that any other tools can really understand. Because, you know, the frameworks are quite complicated. So, you know, using contrasts, instrumentation based approach to application security, we're able to see the rounds as they're being registered with the framework.
And we can expose those. So that's all sort of, you know, under the covers, technical mumbo jumbo. But what it means is that you can really understand how much of your application you've actually tested.
If I tell you your application has seventy two rounds. Then you can know how many of those rats have actually been analyzed for security problems. And you can see exactly which route still need to be tested to see if they're safe enough to make sense.
It makes perfect sense to me, you know, in my mind. And maybe this is an oversimplification. It's almost like the exact opposite of, you know, back in my day, we used to have sort of these attack maps, you know, companies getting cones coming down or remember what, Skynet.
Right. So they would show you the roud an attacker would take coming into your coming into your network and eventually wind up back where you're at, you know, where your application sits or where there was something vulnerable that they can, whether it be the X X-ray, the database, the Web server, etc.. This is almost coming out from the other end of the of the of the map.
Right. Saying OK, from the application on out. What is the root?
Right. That's being taken here. Would that be a that's right.
I think it's a good analogy. I mean, sort of everything has moved up the stack since those days. And so now most of the innovation is happening at the application layer.
That's what people are doing, their digital transformations and their. They turn their enterprises into into code and. They need to have this understanding to know what is the attack surface of their application layer.
And you can't do it with static analysis. It's just way too complicated. Those tools can't see what routes are exposed.
You can't do it dynamically with the dust skater kind of tool because, you know, those tools don't know what they're attacking. They're just using the, you know, the user interface as a guide to figure out what's exposed. But they don't really know what's there.
So this is very new and it'll really help folks get get really good coverage over their Web application. I'll give an example of a real success story for it. Recently, I was at a large mutual fund company and they've been using contrast for a while and we enabled this round intelligence feature and they noticed that a number of their applications had a bunch of exposed routes that they hadn't been testing.
They didn't. And in fact, when they dug into it, they didn't really know that these routes were there. These are hidden routes and many organizations have these hidden routes.
In this case, those hatch were added by the framework. So spring, spring boot has a way of adding in extra routes to applications. Unbeknownst to the developers, they're called management routes.
And they do things like they allow you to get the environment variables or just the status of the application, even capture snap heaped on top of the memory inside the application. All of which are really dangerous to expose externally. And this mutual fund company didn't know that those routes had been exposed to the public.
And we're sitting there just waiting for anybody to hit them. But contrast illuminated those rules, allow them to see them. They very quickly realized they were a security risk and they've now turned them off in a whole bunch of their applications.
But this just gives of one aspect of why it's really important to understand your out. Exactly. And, you know, and it's something else, too, Jeff.
It's it's kind of a way that I saw building. Maybe two years ago, I first saw it and I but I've seen a ton of companies. Since then, not a ton, but more than several companies in the cyber space since that, and that is trying to let people know where and what assets they have.
It within their digital domains. Right. And and, you know, and knowing that is is only half the story.
This seems to be the other half of the story. OK, so I know I have this, that and that. And when I use this application, where does it go to this?
That that. Right. Because you need that.
You need that intelligence. What would scary to me is. I guess before we had the cloud in the apps, I thought we had a handle on these things, right.
Maybe this question is simpler. Right. Have you had your app lived on a server or was projected out maybe onto a Web server?
Your data was back in the database. Yeah, I think that's right. It was a little simpler in the old days.
Things are getting very complicated with, you know, smashing up these monolithic apps into a whole bunch of API, which can then run anywhere. It makes it very difficult to understand where your code is and what it's doing. So this this round intelligence feature is part of our efforts to expose what's really going on inside the application layer.
You mentioned inventory. Very important to understand your inventory contrast helps with that by kind of letting all your code self inventory. So instead of having to run around with a clipboard and write down where all your code is.
Contrast automatically collects all that from all your apps and builds an inventory in reverse, actually, like it's the are reporting in to tell you exactly where they are. We tell you what codes in each of those things. So we analyze all the libraries and the frameworks and with custom code and tell you what's in there.
In this round intelligence feature is taking it to that next level. It says, hey, here's exactly what you know. Exposed end points connect to which code to allow you to see exactly how the app, the apps are put together.
And then the future of this round intelligence capability is to start reporting details about each of those rounds. Wouldn't it be fantastic if you could just quickly query contrasted asked, hey, show me all of my routes that have sensitive information going into them that connect to secret database on the back at. And show me maybe you want to say, hey, show me if any of those rats don't have an access control check associated with them.
Really powerful way to zoom in on what's really important and find, you know, those kinds of architecture level vulnerabilities that we're. You're paying tons of money to Penn testers and security analysts to try to figure out the hard way we can do all that much more easily. Makes sense.
Makes perfect sense. It's great. I think it's a really, really powerful tool.
Jeff, how is. I know it's part of the of the bigger contrast. Assess.
Offering. How? How do you price this, how?
You know what for people would me I have a question on it. Oh yeah. So generally, we price it per today, annual subscription per application.
And we're not real strict about how you define an application. It's generally, you know, what the code that a team of developers is working on. So it's pretty easy.
However you think of your application inventory. That's how we'll we'll track it. And then using contrast is really easy.
You just add contrast to your application and then keep doing your normal development the way you've always done it. You don't have to change anything about the way you build or test or deploy your code. Contrast just sits there in the backgrounds gathering instrumentation based, instrumentation based telemetry from your applications and building you this picture.
So you always have an up to date dashboard of everything that's going on from an application security perspective across your portfolio. Exactly. And it's a I designed it and it's really differently to say it scales really differently than scanners.
Like scanners, you kind of have to go one by one through your portfolio. But with contrast, you can deploy it across hundreds or thousands of applications. We see a lot of cloud deployments these days where people are just adding contrast to their standard server build and then it just goes out across hundreds of applications or thousands of applications all at once.
And, you know, you could sort of turn on the lights with regard to apps instead of just getting the strobe light visibility into one app at one time. Instead, you can see kind of everything all at once across, you know. And the other thing just too, is for too long, frankly, and I'm not knocking.
Right. There are a lot of companies are paying a lot of money in the app space at Saks Space. And there's been a lot of improvement in the security of our applications.
But really for too long apps, SAC was really just scanning the code, scanning your app. You know, a different kind of vulnerability skin, if you will. Right.
But you're not that different. I don't know. I'm not a huge fan of of skinning anymore because applications have gotten a lot more complicated.
And, you know, if you look at the results of what the scanning tools are producing, they missed a lot of vulnerabilities. But more and more importantly, they generate tons of false positives, which, you know, as much as a DevOps person, you know, that the speed of being able to iterate on software is paramount. And so we can't we don't have time in a 15 minute build pipeline.
You don't have time to run a scan that takes four hours and then it takes another two weeks to get the findings triaged by human experts. That'll just kill your DevOps program. And so, you know, it doesn't kill the DevOps program.
We've learned this, that I'm still not going to go out without your security. What do you think? Your security program?
I think that's fair. Right. Because people aren't going to wait for that, though.
You know what? MVP will get it out when you get me those scan results. We'll take a look.
Right. I think that's right. And that's what happens more often than not.
Right. I think that's one of the fallacies of the of the, you know, pre Copernicus security person who thinks security's the center of the universe. It.
Yeah, that's that's an excellent point. It really isn't. And what it does seem like he says he said DevOps finds a slowdown and routes around it.
So security is an example they say always comes up with some good one liners. But that's another story. But you know that that's what it is.
So, Jeff, this sounds great. Is it is it generally available at this point? Yeah, it's available to everybody.
It's actually also available as part of our contract community edition. So if you are interested in by asking rasped and using an interpretation based approach to apps that you can create yourself an account at, you know, contrast security, dot com slash community edition and. Give it a try to see what her roots can enhance your application security program.
Cool. Very good. Jeff, we have maybe we don't have too much time left, but beyond this, anything else new?
In contrast, you want to share with the audience maybe. Well, let's see. We're growing really fast.
So we've got now a team in Belfast. We've also got a team in Japan. So we're expanding internationally quite a bit.
We're almost 300 people now. And I don't know if you've got a chance to swing by our booth at RSA, but you saw, you know, we had a real big booth there. And.
And a lot of great meetings. I think it's gonna be a really exciting year for for contrast. I think it's finally time that, you know, people are viewing.
I asked as the way to start with application security. And, you know, it's been so long for Sassed and Dast and, you know, sort of scanning based approach. But we've finally got people to a point where they know they know about.
I ask, they know about Rassman. They're starting there. You start with the easy thing that covers most of your portfolio.
And then if there's still a few edge cases where you need to use static or dynamic, great. But it's got to get people off those because they're slowing down people's programs way too much. Got it.
I gotta be honest, I never made it to the show floor, it asks a joke. I was so busy at videos putting on it on our deficit jobs day's events on Monday. Ah, say we can go and eat.
So we have some work at couple. I'll tell you what it was. It was roughly the same as it's always.
I'm sure it was, you know. You know what they say. You seen one.
You've seen them all but nonmalignant. Yeah it's true. It is.
Anyway, Jeff, I want to thank you for joining us today. Good luck with this. It sounds it sounds like an exciting new frontier in in the in the abstract was right in making us all thinking all of our applications more secure and providing a better a better experience for for end users.
So good stuff. Keep up the great work and contrast. So it's a pleasure to see you guys are kind of knocking it out of the park.
John, great to talk to you as always. All right, Jeff Williams, CTO, co-founder, contrast security. This is Alan Shimel.
And you just listen to another DevOps chat. Jacqueline by Murray Clock, we were right around 18 minutes on that. Is that fair?
I'm sure that's right. I tried to keep it 15 to 20, just so I thought we get.