EP 285: Shadow Code Security w/ Perimeter X
When the cloud first caught on there was a problem with Shadow IT. Developers spinning up instances in AWS without the IT team knowing they existed. Now with the ease of CI/DC automated deployments, the problem of Shadow Code has arisen. Code being added to apps that did not go through the entire team process.
In this DevOps Chat we speak with Elad Koren, VP of Product at Perimeter X about the Shadow Code issue and how his company can help.
Transcript
P. of product at PerimeterX, and Elad, Welcome to DevOps chat. Thanks, Alan.
It's a it's an honor being here. Happy to join you. I appreciate you being here.
And it's our honor to have you. So. We've never I don't believe so.
We've never interviewed or a concrete PerimeterX before on Security Boulevard or DevOps. And why don't we start with why don't you give our audience a little background. What's PerimeterX about?
Cool. I believe you're right. PerimeterX has been around for a bit more than five years, and its main goal is to secure businesses, digital businesses across the Web.
I can be e-commerce, SAS and the other online businesses essentially providing solutions to the online digital challenges they have. We started with our Bot Defenders solution about four years ago and this set target's the bot problem around the Web. I'm sure you're well aware of it being a security professional you are about a year ago.
We've also launched our code Defendor product, which looks at the client side code and highlights vulnerabilities and issues around that. And we will, of course, develop some more in the future as part of our growth plans to continue and secure businesses, digital businesses around the world. Actually, we're going to dove into that in just a second with a lot I know so what we'd like to ask people about their own personal journey.
How did you come to be BPU products, the PerimeterX? Wow. It was a long journey.
I'm actually been I've actually been in security for more than 15 years. Started with the Israeli intelligence and the IDF then moved to my own startup where I took all the security and compliance and and fraud areas from there if I moved on to our security. So you're probably familiar with RSA security now, part of Dell.
And after a short period in panniers, their head of compliance and security, I found myself in period or X leading the product group. And now the VPN products. And very proud of what we do with.
Oh, it's really sense of accomplishment with with what we've been doing so far. Well, RSA security was spun out of don't know. Right.
We didn't do a p e deal a couple months ago. I thought. Yeah, yeah.
They, they, they had a they had a discussion around that. It was actually interesting because the RSA was one of the biggest assets EMC had before Dell acquired them. And once Dell stepped in, I think RSA wasn't that interesting for them.
So it was only a matter of time. Yeah, know Dell seems to have a love hate relationship with the security companies they acquire, but that's another podcast. So client side code, inspections and security.
Talk to us a little bit about what you're doing there. And then I want to jump into this concept of shadow code that you spoke about off. Yeah, so so first of all, very important to understand, the first question that comes to mind is why are we talking about it in DevOps dot com?
So so one of PerimeterX's is top targets is to assist DevOps seems to do their job better. And the fact of the matter is that after we've had our BOB mitigation solution for quite awhile and DevOps was one of our personas, we went out and asked our customers, what's their next major problem? And one of the things that came up from many, many customers is the fact that they have a challenge around their client site.
Developers are adding libraries. Well, you know, it's a common practice. However, some of these libraries, JavaScript or others, they they're not that secure and they're not that trustworthy.
What we did at that point is kind of think of that problem and what it reminded of. And it kind of reminded of a right that reminded us of the problem of the shadow IT that we've seen about 10 years ago or so where employees would just come with their devices or do whatever they want with with their bring your own device kind of concept. And companies started fighting that.
But at the end of the day, they understood that they have no way. It's kind of similar with code. Developers will find the best way to add code, even if it's a library that they can just stake in and adjust slightly.
And even if it's a GitHub repository that no one maintains and these introduce significant trisk. Yes. Absolutely.
You know, it's interesting. I think no one in DevOps questions anymore. When we talk about adding security to the mix, I think, you know, I look a little bit at my own personal journey.
Right idea. The reason I got into DevOps is because I thought it was the greatest thing for security. I thought this is the way it came down that, you know, this whole death psych ops moving and shifting left and making gallopers more whoI aware of security.
I envision that when I first, you know, was found out about DevOps and I, I was hoping it would give us another another chance to do it right. To correct some of the mistakes that were kind of inherent in our whole model. And I'm not saying it's a panacea or it's perfect now, but certainly we we can acknowledge that developers do care about.
No one wants to develop insecure, crappy code. People have pride in what they code they develop now when they did it. No.
The more they know about security and the more tools we can give them that allow them to kind of do better, develop more secure code, the better off we are, I think. But this issue of, as you're calling it, shadow code. Right.
Kind of growing. T. when the cloud first game.
It's a problem. And the thing about it. Is again, developers don't raise their hand and say, I want to sneak around.
I want to sneak a little code in the back door of the apple. Right. Do they do it because.
They have time constraints. They want to get it done. They wanted to work faster.
Right. The exactly the reasons that we've understood and we when we looked into it and it makes sense, if you think about it, developers should be able to add whatever it is they think can help them develop faster. I mean, it's the business go.
The question is, the main question that we asked is. Well, how can you make it more streamlined? OK.
How can you. And now going one step backwards or or sideways, there is a disconnect. OK.
That the developers that as you said, they want to make it a secure code, but the business owner or the person manages the security posture of the application doesn't necessarily know that somebody introduced new vulnerability because the developer thinks that district positively is safe. I mean, it should be. It's in GitHub.
So, so, so, so the thing is, and this is where we we asked around are our customers. What are they doing to mitigate this type of risk? And what are they finding out?
And what we what we found out is interesting enough. You have a lot of performance monitoring tools, but you have zero security monitoring tools on client side in real time. You have static analysis.
You have a lot of other solutions trying to find the vulnerability before it goes out of production. But once it's out there. Nobody monitors and you have to keep in mind.
I know you are keeping in mind, but are our listeners the fact that. Well, when in runtime, you can inject dynamic code that changes. And if somebody else gets control over it, this is a problem.
Well, and there's a couple, I think other complicating factors, a lot that I'd like you to address. And that is, you know, today, where does that client site code live? Is it in.
Is it in the container somewhere? Is it was with the code goober nerd's Microsoft, which is Meche thing going on? Is it use it in the traditional hypervisor kind of environment or maybe, you know, something like that, or is it on bare metal and Cervalis or you know, it's a great time to be a developer, but it's a security birchley from guardrails there for these people to to to to, you know, do it as safely as possible, as securely as possible.
How do you do that? This is this is this is grab your spot on. You'd expect that when a new code is introduced, the company or the developers would adopt it and, you know, manage it or maintain on their servers or on their micro servers or their mesh.
However, because they want to keep it updated, because they want to keep it as as as capable as possible, they sometimes take that dynamic library from their repository. And whenever there is a CISSP process going on, it pulls the library from there. And that is where you're the shadow code becomes a problem, because unless you have the right processes around how to make sure that this library is safe, how to make sure that this is you're not introducing anything malicious.
And we have seen it happening in the past. This is where you have to address the problem. And, you know, I can share some of the things that we've seen when we had the validation of the product before we launched it.
We we had a design partner and they asked for something like this because their developers asked for four for a security team to allow them visibility into what's happening on the client side. And we actually and it's a big, big customer. I don't want to name names naturally here, but and then you'll share my surprise when we found out.
When we run on their client side, that's a very, very big vendor of theirs, is using a J query from a non trustworthy source. Now, you'd expect something like this would never happen for a well established company, but it does. It's surprising, but it does.
And they weren't the only ones. Hmm hmm, interesting. So so let let's now talk.
So I think we've defined the issue and the problem, right. How how is perimeter actual? Goodness.
So our approach when when we're looking at this issue or this problem, naturally, we are a dead first company. P. of products.
I'm a product manager at heart. And customer input is the number one thing that I am looking into when I'm building the products. They said very clearly, if they can see before moving from staging to to death to fraud, what the code itself, when it's full, when it's full dynamically is doing and have the visibility of what's happening there in real time on users.
This is something that they don't have today because death will introduce that level of visibility whenever something bad happens. I don't know if you've seen some of the major CRT attacks that have happened from third party libraries. Again, don't want to name names, but if somebody looks online, they can find out.
When we come in and we analyze in real time on the client side, on every user going into the Web site, what the scripts are doing there, whether they send information to a bad domain, whether they try to take the information stored in a cookie, and then I use it later on. We can quickly highlight the main risks and main problems and vulnerabilities. Like I mentioned earlier with Jake Wery.
So that's the DevOps or DevOps chat. Cops can quickly raise a flag and say to this developer, listen, this script you have you've added introduced this new vulnerability. You can see that in the static code analysis, but you will see that on runtime on the client side.
And that is that is something revolutionary. We don't have that today in anyone else's solution out there. Hmm hmm, interesting.
What would suit? I was asked. And you're the perfect person.
Your father. Now, you've got a conundrum. You've got a really great security product here that's going to help developers with secure code.
How do you how do you how do you sell it? How do you bring it into the organization? You talk to the security guy and say, hey, go talk to your developer team and tell them to use this.
Do you talk to your developers and say you tell your security team you want to do this, you got to talk to the security team and the developer team? Whose budget does this come out of? Who ultimately is responsible for setting the policies and processes?
This is the solution. Hard to sell maybe, though. Pat, you're correct.
So theoretically, it's hard to sell. However, the main the main key or the key differentiator is the fact that when we went into look how we want to sell this, we can before we even built it, we established the fact that it should fit into their processes. If it's not fitting into their processes, if they have to start defining things like content security policy, if they have to start maintaining this on a day to day basis, it's not going to work.
Solutions for DevOps or if Cyclopes today are one, two, three, you have to have it in and you have to do it quickly and you have to have minimal manual effort unless you definitely prove why it's needed. And so this is why we've added the fact that nobody needs to do the base lining on their own. We are doing that automatically with the machine learning capabilities, what every script does, whether it's a or not.
And the fact that they can just have a small snippet on their client side and we'll analyze whatever and flag in our portal or alerting system that they have. T. process.
It fits into their day to day process. If they can even have it as part of their regular security processes and have it fit into their SIM. And this is where it really makes the difference, because you don't have to do anything manually and you solve a problem and you fit into their processes and security.
People are very happy about it. I can tell you that one of the customers that actually already bought this product was very happy with the fact that they have visibility to this area and they don't have to make DenTek on their own because we are doing that. The product does that out of the box.
So this was a key component in our product. Excellent, excellent, excellent show. I told you, the time goes very.
Coming up on time here, we will see for people who are interested, let's let's use our time wisely. How could they find out more information? Would would would pass, do you suggest, for them?
So first of all, they can go out, go out to our Web site and check out our our solutions, both for both mitigation and as well as the codefendant and other solutions that we have. I think reaching out to our team, if you have any questions, if you have any concerns around the client site, I can tell you that even companies that thought it, everything's fine. We're completely oblivious to threats and concerns around the client side that that are out there and and many people are not aware of.
You can also reach out to me directly, Movielink Dan or what have you, and we can well we can discuss. I think in general for DevOps and deficit cops to be more aware of the dynamic nature of the code that is added to the client side and what to do. We actually have a blog post listing the things that are best to do if you want to make sure that it's secure and and you're on top of things.
So it's a good read as well. And that's about it. So we're here.
We're ready to help. Well, last question, just because you have to ask it with it's out there with all everything going on in the world with the cozied and everything else. How's it affecting?
Has it affected you guys? What are you seeing? It's actually amazing.
We've seen some trends around the e commerce landscape that we've actually had some some blog posts on. And I think, you know, one of the things that kind of symbolizes these times, a few of the e-commerce sites that we're working with said that the traffic they experienced out out outgrows the Black Friday, Cyber Monday, the level of traffic. I think I think it symbolizes are they kind of the boom of online life that we have?
I'm sure you're experiencing it as well. And I think the shift there is not going to go back to the previous levels. Definitely going to go down.
But we are seeing so many trends, very interesting trends, and we're naturally adjusting what we're doing. But luckily and happily, we're doing great. And these times and then it's it's very happy with what we have now.
I will tell you, for whatever reason, you know, you may not all be good because the Ziga is this whole with the virus pandemic, there's a Seiberg pandemic of people trying to exploit. So, for instance, even here, MediaOps,, where DevOps and Security Boulevard are security, so used to be pretty, even in terms of how many visitors they both get, 350 to 400000 visitors, unique visitors. All of a sudden.
Security Boulevard now this month is going to be at six hundred thousand. Wow. Last month was five hundred and thirty thousand.
So in the last two months since this Crovitz, you know, we've seen traffic on the Boulevard site, DevOps, stayed relatively steady, hasn't gone up necessarily, hasn't gone down. But do you think you know, one thing we've noticed and I think it can also explain, I think it's it's wider than that attacks and in general, fraud and security challenges became much more complicated because the adversaries are out there and they are targeting a whole lot of other news sites that previously didn't experience. We are seeing much higher levels of of complexity in the attacks that we've previously seen on Giants.
Now, an even medium, small, small, medium sized size sites. Agreed. Crazy.
Just crazy, right? Yeah. Because that's what you need when you have a virus pandemic.
We need to avoid cybercrime. Stop to worry. Yeah.
I want to thank you for joining us today on DevOps chat. It's been a pleasure. Thanks.
Elad Koren here on DevOps chat, this is Alan Shimel and you just listened to another DevOps chat.