Advanced Security Announcement – Nati Davidi, JFrog
Nati Davidi, JFrog SVP Security, discusses the launch of JFrog Advanced Security. This new offering focuses on binary security, whether binaries are created internally or from external sources. JFrog Advanced Security builds up JFrog’s DevOps Platform with Artifactory binary repository and Xray for decomposition analysis.
Transcript
This is Textron TV. I welcome I have the great pleasure of being joined by Naughty devadi Nadi is spp of jfrog security. Welcome glad to be talking with you today.
Hi, Mr. Pleasure to be here. Pleasure, so tell us a little bit about yourself for folks that may not know you a little bit about Jay product.
Hopefully many folks know that we J frog is but if not, well introduce them here. Yes, I'm not either VB and heading the product line of security by Jay frog we call something. The roll itself is a SVP Jay folk security.
I came to the company a bit more than a year ago through the acquisition of we do which is a company that was focused on a binary analysis from security point of view. And you know from our perspective. It's a perfect match because jfrog is all about binaries.
Starting from the earlier stage of binary is all the way to production and it's time goes by it is being spreaded more to the left and motor to the right in terms of how to cover the entire end to end journey of the software from the moment. It is being coded all the way. It is being pushing to production and we are actually coming.
I mean our division is to create the layer of security across this entire end-to-end story not focusing only on shift left or only on production shift, right but throughout the entire journey of the software on the liquid software story to make sure that in all of the great critical Junction security is being implied properly. I think that's a super important point, which is it isn't just about any individual point in the process. It's about the whole process because all of that of course can introduce security issues intended or unintended depending up here in the hacker.
So to you have some great news some exciting news. Tell us about what you're asking. Yeah, so we are known seeing the new offering of jfrog.
We call it the advanced Security package. This is a new package that we provide on top of the X-ray capabilities. And this is not the last package that we are about to to announce in the sooner future.
And when the idea to gradually expand from the software composition analysis focused and software bill of materials Focus to what we preserve as a perceived story as the true end-to-end supply chain security mechanisms because it's not only about middle of material. It's not only about cve and non vulnerability. There are so many other things that are not fairly defined by Regulators.
They implied directly regulator the calling they call them for example in the new 7900 building called an effect of treaty not vulnerability and there are so many defects. I mean, you know secrets that are being kept in the binaries and can be utilized by the attacker bet configuration that can lead to exploitation remotely or locally even just the way the container is being sorry is running on a given system so many attributes of artifacts that are not Fairly cve or zero day or the other very known terms. And what we come with in advanced security is exactly the aggregation of engines and scanners.
That should cover these these many unknown these many not so well defined categories now, we clearly gave them names. One of them is more common and known one is infrastructures code security issues. This is an engine.
There's a look for your terraform issue. We have secret detection. This is an engine that we look into the binary and look for keys and credentials of many many kinds whether you have kids.
They're related to AWS or gcp or any other service. We will find them automatically and the nice thing again in close binary. It's not in the form of source, but we look at it into the binary.
And I was also mention here that that that's the magic of binary. I mean source code will not necessarily or necessarily not include many of these things. It will include code.
It will not include the secrets and the configuration in many cases and binary will include them and they impose the risk the real risk because it's much closer to production that the form of the software. So I mentioned infrastructure is called secret detection. And then we do also configuration analysis for common services and applications like flask or like jungle or Engineers.
So we really try to aggregate all of these things can be found with the binary with clearly look for malicious packages, which we are pioneering. And more to come I mean this is not the end. There are many many small capabilities.
I left the last one for the end the most important one. So we're in an engine that we call the binary based contextual analysis. Which is also tied into the this new building is coming in.
So the contextual analysis allows for the first time to really look into a given binary and tells you and it tells you if a given cve. Is truly exploitable or not now, why is it so important first? Because if you take you know, the very common look for jstories an example everybody everybody respond with a panic.
Everybody across the entire Globe try to identify their local jpackages in the development environment in production and then to gradually replace them with a secured one just because that was the common approach, but I can tell you that more than 70% at least based on the customer that we worked with more than 70% of the look for Jay Warner bill libraries vulnerable by definition are not truly vulnerable because they're prerequisite for exploitation. Isn't that and it rendered the cve useless? So this contextual analysis allows for the first time to really tell the developer and the security Persona and the devastation you do have you do have this package 1300 times in the organization.
But only in these four cases you use the vulnerable function or you truly configuring a way that an attacker can remotely expert it. And if you are exploitable indeed the system then give you a contextual mediation plan, which is not just about upgrade your packages to the next version. It's about change this time configuration and you are safe.
Even if you have the CV you are then safe. And the reason I mentioned the the bill because there are so many Publications and articles and criticism about the new bill, but it does say that you can also introduce mitigation plan. And it does say that you need to have zero zero CVS that have an impact on the product.
But what if these are CVS that does not have impact on the product? So it's a lot of you know, a tactic language issues there that can be interpreted in many ways. But I think the regulator did actually a good job understanding that there are alternative to just make sure that you don't have TVs.
If you come from the security world that network security world, you're very familiar with her mediation not just patching right patching is one former remediation. And there are lots of ways. Sometimes you can't upgrade software right that to do that is a much bigger effort.
Not everything is built in microservices initially patchable. So I think security Engineers are probably very comfortable familiar with that approach in the software world. We don't talk about remediation very often other than patching and kind of fixing vulnerabilities in our code.
You're right more than defects right security vulnerabilities. Um as you're introducing this product and as you've worked with customers that have been I'm sure working with them before the launch. How did they Embrace and accept this idea of remediation that some things aren't aren't accessible aren't actually vulnerable even though that does have security issues.
Yeah. So it takes time to digest. I mean it's a matter of you know, building a trust and the product that they use and see the effectiveness of it the way the way we help the customer understand they can trust their recommendation.
Is is by providing the digital evidence? Actually, I mean if we prove to all three personas. To the security leader to the devops leader and to the developer that something have to be fixed or shouldn't be fixed because just take time and have zero impact on security and we direct him or hair to the specific evidence showing a specific pattern specific configuration file or a specific function, which is vulnerable this this makes the special developers very happy because now they can go back to the security Persona said listen, I really don't need to fix it here.
I have the proof all the security Persona saying to them here. I have the perfect you have to fix it and it's like kind of reduce the friction there are verticals and industries in which it becomes even more important like in the automotive and medical spaces. I mean, you know having a vulnerability and insulin pump It just means you need to recall all of the pumps if they are not the new generation that you can upgrade remotely and most of them are not you just need to recall them to upgrade the software.
It's not feasible. It doesn't make anything. You know that yeah, it's a huge deal and The Regulators are so much.
I mean looking into it and find a way to alter alternative way to deal with that and that's where mediation and mitigation comes in. Okay. Yeah Remediation in many cases is indeed more from the network Vector.
Let's call it. When you do some external actions to reduce the chance that the given vulnerability will be exploited mitigation are I mean in our point of view are more tactical things you can do even on the device or in the container on your software. It does not make require a meaningful architectural change.
But again, just a small configuration change. That will will make it we'll put it in a position where the vulnerability is there. But no one can really utilize it and in this critical verticals and indices when we come with this story, they're really really like it in the automotive.
Especially I mean, they really like the story. Let me connect a couple of dots and I'm curious you talked about contextualizing being able to understand, you know contacts and how something is used. As part of what you're saying is you really need that bill that built software.
You need to runtime software the binary to be able to have that contextual because in a microservices world just in the in the repository, you're not going to know who's calling what all the time they may not always be in one repository one location one code base. So when it's assembled into a set of services or code base that you can examine is that part of what you get additional contextual information from exactly and we discovered the accurately and we're doing it in several different Gates. We are doing it as soon as someone is developer compile code into a binary and then the context will be not that big.
Okay, and then we're being pushed to a big service or container and then the context is suddenly bigger than that and then in the context of the full product just before being released. To the production and then you have tons of context almost everything and the next thing to come which is not part of advanced Security is to do it also on runtime meaning I'm just gonna ask about runtime. It sounds like the next thing.
Yeah that definitely that the obvious required next step to make sure that also the thing that we saw just before just before pushing sync to production to make sure that they are just the same on the runtime that we are not finding or identifying new things that cause the manipulation of the software or duration of the software and this is not about it typical runtime security or infant security. By the way. I came from this space before this company.
I work in Palo Alto networks. They required my previous company say Vera which build endpoint security that they were focus on protecting production laptop servers and so on here it's about the specific perspective of the software integrity. And to see that this your software being bill of material is not being changed.
To see that things on production are not under threat. Just the one nice example. you might have a look for jail like on your product.
Okay the package. and even in the less Point analysis the system will analyze it and will tell you it's there. Okay, you don't know it's vulnerable yet, of course and then it goes to production and then suddenly a researcher find out that there is a big deal with book for Jay.
When we will be on runtime, we will be able to tell you you do have the look for J. But you don't even use it. It's just dormant on your system.
So it's another big aspect. I mean, it means that that then the the parallel packages in insulin pump. No one will need to upgrade it because the software doesn't even use it doesn't even call it.
And this is again. This is a big news to the developers because it reduced dramatically the overhead of upgrading and fixing things it shortening cycle of delivery of software. It's much more modern and all automated.
So it reduce so for the need for for manual and testing and similar at that. Not am curious your perspective on this app security is a hot space Right Now API security a lot of aspects of software, but I don't know that we've really kind of crack the nut if you will for how to really effectively create a secure software. How does this the advanced Security package?
I was a differentiated in Market to other solution. Yeah, so I would say there are the two biggest things. First of all, we clearly claim that our engines our are the best.
Okay, which is an obvious argument. This is to our customer to test against other Solutions, but more importantly At first it's about the aggregation of the capabilities. I mean having having many spot, you know Niche Solutions again create a lot of over it for the security team or the developer to Aggregate and to prioritize them to decide what the fits and what not to fix.
Second and even more importantly and that's the the really big news about security with jfrog is okay. You have an issue what then what what the next thing that you can do in order to fix this. Or to mitigate across your entire development environment and with artifactory.
It's almost the only way to say, okay, I have spring Shell. Let's find in with a click of a button across my entire repositories. Let's update it and to a send it to the filter distribution therefore distribution or to devices through j4 connect.
And then not, you know saving these cycle of two three seven weeks of just identifying your software and started to pushing it to the field. This is only one use case. I mean this this ability to First prevent things from even coming in using artifactory.
As a Gateway, you cannot do that. If you don't have artefactory, I mean you can have a great scanners, but you need someone to attempt something to aggregate all of your software assets to be the the Bible of your organization the soft survival of your organization. So this is before things coming in and then after things are going through the Journey of software to the field if something is something that happens and you want to respectively respond to any event again with one bottle of a click you look through this information, you can take an action.
So first aggregation of the security capabilities in one place and second, of course being part of a platform a devops platform, which also allows you to take the action. Perfect. And that's one of the advantage of kind of a platform starting with artifactory for you know, keeping your artifacts in a place where you can start that process at the beginning.
So I assume you have a place that folks can go check this out. Maybe some Hands-On working with it and that maybe sandbox environment something like that. Yeah.
com, you can easily subscribe to the send books and get immediately on the spot and your credential and start playing with it and they're understand how does it work. We also have a better program from for players that would like to start give us a feedback before we officially launch it. And then other than that, you can also use the free trial and the story I'll stop here because I'm not sure what will be by then, you know only for free or not.
Okay. com. Which is the real enabler for everything?
I just described because everything that we build is being supported by tens of vulnerability researchers the biggest team group here in Israel of researchers. And one of the best out there that all day long analyzing cities to build these applicability scanners to know if your city is applicable or not all day long. They are scanning repositories public wants to find malicious packages.
They found more than 2000 so far and all of these information is being pushed to the platform. So our customers can enjoy on the spot. So everything is achievable sorry accessible to our website and I welcome everyone to check.
Fantasical congratulations on the launch and excited to see folks get their hands on this and get some use of it. I'm sure the security teams will be happy too when the developers bringing information to them about the CVS that they've either mitigated or resolved in it's nice to kind of bring that together. So again, congratulations that naughty TV who's SVP research security with jfrog.
Thanks for joining us today. Thank you so much.