AppSec Road Map – Chen Gour Arie, Enso Security
Enso Security, developers of the first Application Security Posture Management (ASPM) solution, launched the next iteration of the AppSec Map, its interactive map of the AppSec ecosystem. Embraced by the community for its ability to intuitively segment and visualize the AppSec tech stack, the map now enables users to create custom maps and generate security posture ratings. Chen Gour Arie, Enso Security Chief Architect and Co-Founder, discuss how developers are tackling application security challenges while we increase the velocity of software development.
Transcript
This is Textron TV. The great pleasure being joined by Chen guariah who is Chief Architect and co-founder of enso security. Welcome Jen.
Thank you very much. Thank you for having me pleasure to have you we're gonna talk about absec API security all kinds of good stuff before we do that tells a little bit of about yourself your background and tell us what in so security does. Yeah, so I'm planning that if I could talk about the security and I'm coming from hands on deck on the application security.
I spend a lot of time breaking many forms of applications and different layers of the stack and also spend some time helping organizations try to find ways to build Safer applications and to run away and successful application Security Programs and attenzo. We're building the Aspen the first sphere application security posture management platform and it lets team Get from all the experience that we gain through these and start leading organized systematic way of doing upsec kind of a new way of doing upsec new and improved way. Fantastic, it's it's a very hot topic but it's not an easy topic too.
Right? There's no respects to this. I know when things that you were telling me about that you've launched is this abstract map kind of a an outline almost looks like a subway map of you know, the journey that you can take where to start how to get get going and we'll we'll hand out the URL to that.
I'll put that in the description here. Tell us a little bit about that map and how people can use this. Yeah, so the object map is actually initiative that we launched the wire back and it started as a as an effort to give a clear and simple categorization of the absec came of offering in the inepsic area offering that are also the combination of services but also Solutions opens also commercial and breaking down to few main categories that are prominent and relevant in in doing absec and start with a no just a simple visually and nice engine to explore the domain.
And get a lot of information easily in fine, for example easy to find if a vendors that you're using. Also have something else to offer that maybe you don't know about. So if you search the name of the vendor, you will see all the offering that it has.
That they have in the abstract domain and we start to get a lot of positive feedback. Also the way that we've built this was with a community contribution. So vendors will submitting their information Community users was submitting information about open source projects and the database was built based on this data and the engine is actually keep feeding from that data and from all these positive feedback.
We we thought what would be more useful using this data and then we've decided to add a layer of personalization and this is a this new update and we call it a my map and it's it's to take almost the same data. And to arrange it in a way that is maybe similar to how we perceive a implication production in maybe in a devops kind of a picture. We all have a mental image of devops when we think about production environment and the software production process.
So we've arranged in a similar view when you have your right hand side shows your Dynamic environment your left hand side show more production of the code part of that is about the code in the open source dependencies and then arrange around it all the solution that that you're using. and and with this information the map can give you first of all some sort of visualization on how How much have you progressed in terms of instrumenting services Solutions or processes that you need in order to protect applications and and also shows you what would be relevant Next Step just in a very user user friendly kind of easy journey, and it is meant to to help in perceiving the fact that the challenge in absec is a journey is something that you start and you do and and in reality once you bring a solution you face. And some other problems that you need to think about and the app is about helping people engage in the same Forward Thinking kind of of the way when we talk about absec.
If it was only just an IDE extension Plugin or you know, put this in your cicd, you're all good. We wish it was that easy. I'm curious.
What what do you find people struggle the most with when it comes to application security or or API security for that? Yeah. So I think that the it all stems from the fact that they're building safe software is very very difficult.
It's not something building software is difficult building functional software is difficult and Hello tolerant software is difficult and building a safe software in large scale and secure software in our scale is very difficult into stats on this. And it was also very difficult to build the safe infrastructure. But we've done a lot of the cyber community cyber security Community than a lot of work on securing infrastructure and everybody were busy with it.
But in the meantime applications will also going up in a complexity and in features and the kind of things that they can do. And and it became of it it was and it still is a very very complex bosses to actually secure an application and what many people are actually struggling in the bottom line is not the instrumenting automated tests and sometimes not even executing manual tests and but in many cases it's in it's in taking this data back to the development organization in a way that will make sense to them and will inspire them to actually make some meaningful changes. And this is where most teams of struggling even if they are even if the instrumented the tool chain, of course the the devops a pipeline and go fully devs the cops and they have some shift left campaigns.
They'll still struggling with it because this is actually The real struggle is to help the development organization build an application that is safer from the ground up and not by just patching this this problematic dependency or maybe the specific tiny Elliot. It's a big picture kind of thing. To describe it as you don't bolt on airbags after the car leaves the factory It's gotta be built in right that's exactly capsicus the same way it's built and where it's not not to mention breaks.
Yes those brakes. You should have those too that out. We should do that right the car, you know, so API security is really hot topic as well within absec and I know in your abstract map, you know, you talk about, you know inventory your software inventorying the code and and of course that's that's one of the first steps in API security is you know, especially in API first kind of environment is removing to more API Centric microservices, all that kind of stuff.
Right? I mean, it's proliferation of apis is very very vast. It seems like that.
It can't be a static step though. It can't be like let's go inventory our stuff and then we'll leave it alone and go back and look at six months if you're doing yeah native development and devops you probably Have changed API at your own stuff more or less the things that you're using, you know, dozens maybe hundreds of times, you know in a month or two or six. So it's gotta be it's got to be a rolling process got to be built in to your your workflow pipeline, correct true and and in fact in in many places, it is built-in but by Developers for Developers for their perspective and and in application security, we're still stocking into acquire the same level of of observability on the software that that our teams make and in fact much of the that is already there and you have to continuously process it.
Soon enough. Everybody will be required to because everybody that is trading software or service based on software to Assam level will be required rightfully to present, you know bit of material of that software. And and yes, it's a it must be automatic must be instrumented the same way the same it in the logic is very basic.
If you want to protect something that is being automatically generated created and by with many many you tools you need the same level of automation into looking at it in to understanding where the problems So yeah, so and another point is that to acquire this data is not going to be as straightforward as it is for developers because developers plan and Technology stuck. They can plan those things and dedicated for that technology stuck from the get-go because they need observability. They need monitoring and they will build it inside but they would not consider the use case of security that needs this for each development stack that has in inside the company.
They need to see the white picture. They can't just very very focused on one technology stack and see it properly but not see the rest a developers have this visibility security Are going are getting this sensibility now with a platforms like like hours and because they are tapping into the same data sources, but they they're bringing this information in a more white manner that they give the visibility to everything. Very good.
Well we talked about the abstract map. We talk a little bit about sort of the journey and and building security into in from the start right into the process. Tell me a little bit about more about Enzo security what you do and how you fit into this ecosystem of app sack.
Yeah. So our mission is a is to bring the same level of Automation and days of operation that they existing engineering to application security. And the our platform is designed to be able to measure security posture of full software Factory.
If you're building software, if you operating software, you have many questions that needs to be asked about a course your entire Factory about the different assets that you building and our platform automates the process of understanding those assets Gathering the security intelligence around this asset. So security intelligence that could combines the perspective of what kind of a security effort was already deducted. So what kind of test I performed on that specific asset what kind of activity I conducted from security perspective.
What do I know about existing alerts and then also put it in a context of what is the meaning of this asset? This is a fundamental data plan that the platform provide and on top of it. There are many features to either pull more data generate more tests automate workflows like a Duration of ticket and this kind of features to take this data and start Distributing you to hand organization in the most effective way.
It sounds like you're not sort of like a point solution as part of access absec but almost kind of manager platform of mm-hmm into abstract through the whole process. Is that a good description? Yeah.
It's to bring the concept of asset management and posture management into application security basically. So the main the First Fundamental step is inventorying and creating A notion of asset inventory and then all the rest of the the actions followed on that inventory when the context of that inventory we've understanding with the understanding of which assets are more important. So it's an asset management solution for for application security domain basically.
Fantastic was doing great talking with you. It's as I said, it's a rich topic and very very yeah go hot one. Right?
com. So yeah, go there. That's the the free tool the free sort of Dramas directory kind of ecosystem and roadmap and then as you were talking about click on my map and you'll kind of build from there right great.
You're right. You're customized Guide to the process just so where do we find out more about in Social Security? Um, when do we what was the question where what's the URL for folks to go?
So yeah. Okay. So endless security so ends of security.
Okay, and so that's security ensf. That's easy. Yes.
Always remember that. Yeah. Oh Jen is very been a very very great pleasure talking with you and go to yay who is Chief Architect and co-founder with and Social Security.
Hope you're coming back soon. Thank you very much for having me. It's a pleasure you bet.