Secure Software Supply Chain Platform | DevOps Connect: DevSecOps 2023
Bill Manning discusses the challenges and risks associated with software supply chain attacks and highlights JFrog’s solutions for mitigating those risks and enhancing software security.
Transcript
Hi everybody, and uh, welcome to, uh, the j Frogg platform, securing your software supply chain. Um, the idea today is we're gonna be discussing the best way for you as an organization to make sure that you're not endangering your company and also endangering your users by potentially introducing things that are malicious and nefarious. So my name is, uh, bill Manning.
Um, I'm a solution architect and also solution to engineering manager at, uh, JRO. Um, we are the, uh, number one platform in terms of binary management. You probably know us.
We've been around since 2008, uh, when public in 2020, we're on our way to over, uh, 8,000 customers, 89% of the Fortune 100, top 10 auto manufacturers, top 10 banks in the world. And the thing is, is today, why am I here? Well, the jro platform is actually designed to be an end-to-end DevSecOps solution providing sta, you know, security and safety for your organization from your developer, all the way to the deployment.
So we read these headlines all the time. They're constantly inundating us about the amount of potential threats and risks that happen to our organization in terms of how we manage the actual third party trends of dependencies we use and the things that we produce. And just so you're aware, JRO is a C N A, we are a CV number authority.
So we're always bringing new information to the forefront in terms of security on how to best protect your organization. And the thing is, is that we see also too, the numbers rising constantly. The number of zero day exploits that have been happening over time, the amount of money that companies have to spend to go ahead and actually address these potential threat issues is on the rise too.
And the thing is, is that software supply chain attacks is nothing new. But the thing is, is that it takes a long time to identify. And the thing is, the longer it takes to identify, the longer you're at risk, and then also understanding that also the actual cycle for these actual vulnerabilities and these malicious intents that are happening through the, or, you know, the industry is actually decreasing.
So it's actually, you know, frequency is going on and on and on. And the thing is, is that even if you even address them, if you identify them, the average meantime for remediation on these is about 60 days. Now, they weren't an industry of, of milliseconds.
And when we start talking about days to do this and the amount of exploits that could happen in the meantime, it's in, it's almost criminal actually. It is criminal, uh, when you think about it, right? The thing is, is that we need to be able to go out there and address these.
And the thing is, most of these exploits are, are in the process. If you're, you know, the way a CBA is actually created, which is just basically it's the amount of exposure and and vulnerabilities of your organization. The thing is, is that there's a process to it, right?
It just doesn't happen overnight. Of course there's the, you know, you got the discovery, you got the validation, you have the peer review, you have the, you submit it, and then it becomes the cve, right? It's an entire process that's involved.
And the thing is that 80% of theses are, are, are out there before a CVE even happens. And in 2022, 21,000 CVEs were registered, as I mentioned, we are A C N A. We see this, we produced a tremendous amount of these actually, just so you're aware.
We even have things like our JRO research page that's available for anybody to look at. And just recently, we actually brought up some exploits actually, um, a around, uh, MPM packages, um, sorry, out newk packages, my bad. Uh, but you know, these are new exploits that came out in an industry where people are like, ah, MPM isn't in Newgate isn't really that affected that much.
And the thing is, is that as we go through this and everybody think about how, and you know, the CVEs are actually happening, and my favorite quote I have is right here. Every time you do a PIP install, go get Maven fetch. It's the equivalent of finding a thumb drive, basically on the street and plugging production server.
And why am I saying this? Because you gotta remember, you know, when it comes to anything around c you know, around third party transit dependencies, which we're talking about here, which is is the biggest threat, 85 to 90% of the stuff you make is from people you don't know. These are the, all these, you know, third party transit dependencies are the implicit and the non implicit, right?
So the stuff you directly, uh, request for what you're doing and then of course all the things that come along for the ride, right? Look at mpm, you put three things near Pakistan, Jason, and then 500 show up. And the thing is, is that there was a 650% increase in software supply chain and tax in 2021.
And then in 2022 it went 40% from there. Think about that. That's absolutely insane in an industry that we're part of that we're constantly inundated with the attacks and most companies, not that they have a lez fair kind of attitude around it, it's just that how do you, how do you address an insurmountable force of all these exploits happening constantly?
So with JF Frogg, we have our end-to-end solution. We have artifacty, which is our, our binary manager, is it manages the third party transitive dependencies that you have and they get proxy through artifacty and also the build you produce, the things you do. We have over 32 package types that we support natively out of the box.
Everything from low level code as such as CNC plus plus with Conan all the way up to orchestrated environments with things like Helm and Docker and even infrastructures code such as Terraform. And how do you protect them? So we have our X-ray product.
Now our X-ray product is a security vulnerability, license compliance and operational risk tool. And some of the things I'm gonna talk about today, and I'm gonna do a quick demonstration of is our advanced features where we have a thing called contextual analysis. And to me it's an absolutely amazing piece of kit that you could add into your organization so that you're constantly on top of things.
But the thing is, why is our X-ray product and our artifacty product from so others in the industries? Cause most products out there, there are a lot out there that can tell you that there is a potential threat with the stuff that you're doing. Difference is, is because of the way we store the binaries in artifacty.
We represent them as a check, as a check sum, and then we have a metadata construct that represents the context behind it. Our X-ray product uses that actual metadata construct as its evaluation. Thus we have continuous security, meaning that if new zero data exploit happens, you're immediately notified.
Of course we have distribution to get your software down to the end. We have Connect, which is our I O T platform, allows you to do remote updates, remote diagnostics and that. And we have our C I C D and C orchestration tool pipelines.
But for today's discussion we're gonna talk about Artifacty and x-ray. Cause the first thing we need to do is discuss the curation portion, the software that you're bringing in, those third party transit of libraries that you've used to build your software. And how do you protect them?
Because when you've used them, you're actually part of the creation process. And the thing is, our artifacty and X-ray product allows you also to have auditability and traceability of all those components. Not just letting you know that there's some something potentially nefarious and wrong with it.
And we also provide a series of other things that you can do to give you some sort of action based thing, such as blocking the binaries, setting up notifications of something like Slack or MS teams, uh, creating Jira tickets so that they're actionable. But the thing is, we also offer tools such as our ID plugin, which I'm gonna show you today. You also can integrate into your CI environment.
Any of them, you know, uh, you know, M P m, I mean, sorry, M P M, my god, uh, Jenkins and Azure DevOps and our C I C tool. We have integrations into all these major CI environments and it allows you to also integrate security into that as part of the trust. In addition, any build you produce that are published, you can go ahead and have its own sdlc.
So you can have a promotion model where you can go from dev to QA and staging a production, moving the atomic unit from its its conception all the way down to its deployment. We also have software bill of materials, S P DX and Cyclo DX formats so that if you have regulatory purposes, you have the ability to go in there. And I should also mention the fact that this entire system can be also air gapped.
Uh, we are Iron Bank and Platform one certified. So you can go ahead and use this in those highly, uh, you know, basically secure situations where you're worried about compromise. And lastly, we even bring the X-ray product all the way down to the point where you're about to deploy.
And in the future we'll have runtime analysis too. But let's go ahead and I'm gonna show you a couple of things just to kind of give you an idea of where we really excel in this space. So the first thing I'm gonna do is I wanna address something, uh, very precisely in this case.
I wanna talk about something very near to my heart, which is actually Docker. When we talk about Docker, the reason why I like to talk about Docker and security is very simply the thing is, is it has a lot of complex parts. It's got an os, it's got a run time, it's got an application layer.
And each one of these has its own level of complexity. So when I go in here and I take a look, I'm gonna go show you a particular build in this case. And in my case, the one that I'm going to go ahead and show you is this build right here.
Now the build that I have right here is, it says Docker app, which is the name of my docker. Cause we are a docker registry and I think we're the best docker registry in the market. It has 355 violations, it's got 298 security risks.
And it also has six exposures. Cause one of the other things we find is secrets application and also service exposures, which can be compromised your organization. But let's take a look inside.
And the thing is, is that the first piece I'm gonna show you is the most obvious, which is also vulnerabilities, right? Vulnerabilities is the biggest threat to every organization that's out there. It it could cost you time, effort, and money.
And the question I have to ask you is I have 298 vulnerabilities in this kid's particular container and its own right? And the thing is, is I ask every organization, how many people, time, effort, and money is it going to take you just to investigate, not even fix them, but to investigate them. And that every organization usually has the same response.
We'll either ignore it, it's gonna take us a long time, we're gonna have to split it up and do it over months, whatever you say. But what if I was able to tell you that we could go in and actually delineate through these and let you know that 74% of these issues are not applicable to you, we're saving you time, effort, and money. What our contextual analysis does is it breaks down the CVEs that are being detected because we can detect the libraries with their particular issues.
And then we actually do a contextual analysis. We actually look at what the CVE is. So if you look here, here's the P public source information, we bring it into our architectural analysis tool.
We even tell you how and what we're looking for. And we include also things since we are A C N A. Like I said, if you wanna remediate, you can remediate and also a whole level of detail on what the reasoning is, why this is an issue.
But we're letting you know this one is not applicable to you. But we can also tell you as part of this, which ones are, and this allows you to go in and now precisely the ones that are, if you look here, I have a C V E, it's a medium risk. Of course we had, you know, tell you what version is.
I also could tell you, you know, we, you can go ahead and upgrade to another version, but we show you directly inside of our product where you need to go ahead and go forward and address. We provide the information to you and we also provide you with the level of detail on why this is such a threat and also to all our research materials behind it. Now the last thing on this too is how do we address the ones that are undetermined?
And that's simple. We offer contextual analysis also too in our ID plugin. So this is VS code.
I'm running our JFR plugin here. This happens to be an M P M project. Uh, this is the package on J S O, right?
This is the definition of those third party transitive dependencies that I need to do my job. We actually go ahead and we highlight the potential threats and issues that you have here. If you hover over any of them, we actually show you the CBEs that are associated to them.
But that's not all. Uh, as I stated, we actually do bring the contextual analysis with us. So if I click on any one of these CVEs, cuz we actually show you all the CVEs that are at are right there.
And just so you know, the r o ROI for any security tool in this space, the greatest r o ROI is at the developer level. And as you can see here, we're actually letting you know that this actual piece of code is applicable. This C V E is applying to this particular project.
And if I look at the public source information, by the way, it's, it's garbage. There's really not a lot of information here. But with architectural analysis we show you how we found it.
And also too in our research we've tried you all the details on why and how to fix it yourself. We even show you the file that's being affected. And if I hover over this, we give you the information on what you could do to protect yourself as an organization.
Now going back to our product, I wanna show one more thing around this too because we also go ahead and we expose things such as secrets where we could go ahead and tell you, you know, like here it is an example, you need to go ahead and look at the service. Actually this a service level exposure. But you know, I'm not enforcing t l s or in, you know, in this case I've got a secret in here that maybe one of my passwords is well known or undefined.
But the other big value that we offer as an organization is I'm gonna show you one more thing and then we can always, you know, you can contact us and talk to us, uh, if you want. Uh, but I recommend looking at some of the things like this. Here's another example because like I said, just identifying and being able to fix those issues is one thing.
Here's another example of our docker registry. Once again I'd like to show it cuz it's complex. Every other docker registry looks like this.
The thing is, if I were to ask you, I'm running a node front end of the Java backend in this container and I asked you what version, everybody has the same reaction. I have to do a docker pull. A docker run, I've gotta go in.
Well one of the things that we do is we help companies trace this through. So if I look here, here's my note front end and here's my Java at backend, I know exactly what versions I'm running. What if we have user complaints or performances isn't as good as the one we deployed previously?
Well one of the things that we also offer is you can actually diff docker images even at the actual application level, being able to see quickly in most cases. I had a guy last year tell me his root cause analysis used to take his days and weeks cuz he had to try to figure out every place it touched, everywhere it was used. And he goes, the the shot that we showed him actually knocked it down to minutes and hours and they'll show you.
So let's go take a look at this previous version of this node front end that I was having here, right? I'm gonna go click in here. Here's the actual, if I take a look, you can see here's the actual component that I'm hosting.
I can show you how it was built when it was built. I can show you what it is and it's transitive dependencies. I can go ahead and do other things.
I can create more metadata. Here's all the metadata behind this actual component. I can add more metadata to make it more relevant.
But the thing is, if I go in here, I can show you here's the build that produced it. We just went from the docker application layer to the application. Here's the build that produced it.
And I can show you every single container that's ever used it. Think about that. I just told you every place that a component has been used.
But let's go one step further. Let's go take a look at the build that produced it itself. Well if you look here, you can see there's a tar gz that I just showed you and I can also show you here's all 453 transitive dependencies.
And what if you read an article or you get a notification that one of these dependencies is bad nefarious, it's the worst thing known to man. Um, well I can click on it cause I know it was used here. I can go over to the builds area and I can show you all 100 projects that use this.
Now as stated, we also provide this information as not just a, you know, a way to block and, and stop the consumption. We actually could pre evaluate actual binaries. So these third party transit dependencies before they get into the developer's hands where they say they do an M P M installer or a PIP installer or a docker pole, it goes through artifacty out to the internet, grabs down those three for third party transits, both paid free prior proprietary, whatever, pulls them in.
They get evaluated by our X-ray product. If they meet your criteria, they are delivered to you. And if they don't, those users receive an error message saying that the component that they requested has a potentially nefarious thing.
Go ahead and please take a look, but the idea is protection, right? Front level detection, the ability for you to address and attack the situation at the developer level as part of the CI process. We're also continuously monitoring and ma maintaining all the information.
You can hook us up even tiered monitoring tools such as like Datadog and Splunk and others. Like I said, we even have ID plug-ins and we also have plug-ins for things like x-ray, you know, for um, uh, slack and MS teams. And you can even create things such as, uh, violations and apply them into Jira.
We even extend this all the way out. Uh, so you can even do it. We have a thing called Fraud bot, which allows you to go ahead and do one last validation on poll requests.
And we also provide the same level of information. Um, while you're doing this also to, to our C L I tool, where you can do audits and also into tools, uh, where you can do, you can do on-demand scanning using our c l I also. And the thing is, is that what we bring really to the, to the market is, is just this end-to-end compatibility and find out the reasons why over 7,000 global corporations utilize us.
So please feel free to contact Jay Frogg. My name is Bill Manning. Thank you for your time and I really appreciate it.
Have a wonderful day. Be safe, be wonderful, and be well.





