Continuous Software Security Platform – Brian Roche, Veracode
Veracode announced the enhancement of its Continuous Software Security Platform with substantial improvements to its integrated developer experience. New features include extended integrations to support software composition analysis (SCA), a software bill of materials (SBOM) Application Programming Interface (API), and additional language and framework support for static analysis, further enhancing developers’ ability to secure software in the environments where they work.
Transcript
This is Textron TV. Hi everyone. We're back on textjunk TV.
We've got our next guest lined up here for you. He is Brian roach. She's with roach.
She's with varicode and Brian welcome to Textron TV challenge. Thank you so much for having me. That's our pleasure.
So Brian, I guess we should start a little bit about you know, what's your role and of your background? Address I I code for about a couple of years now and I'm very coach Chief product officer. So that means I lead our product management organization engineering Cloud operations function and you know a little bit about me I guess Alan, you know, I've been deeply immersed in the whole Lean Startup pivotal software space for you know, the last 10 15 years.
And so I come at security very much from a cloud native perspective and have this perspective that you know what my focus is on delivering security software, but doing it quickly and so I sort of a unique approach Absolutely, and of course look our audience is really familiar with varico. They're one of the Pioneers in the absec space. You know coming back from the a lot of the founders come from the at stake and then semantic and then you know, very coats had a storied Journey Through the security world.
I You know probably 20 years at least when you add all that up, that's very coach 20 years ago anyway. they recently announced sort of a A new frontier a new front in there ever ongoing battle to secure applications and software and that is around container security. You mentioned the cloud native word right and Cloud native.
I just we just had a conversation here in the office with some of the analyst team right when you say cloud native is that code word for kubernetes and containers is a code word for stuff coming out of hands. Yeah, or is it really just mean stuff that's natively built for the cloud right? But it could be on hypervisors and everything else.
Yeah. Yeah. You're right.
It's an overloaded term. Right and I think the way that I think about it is if already give you the sweet length description for varicode and who we've been over the past 16 years is look developers are trying to deliver quickly and application Security Professionals are trying to reduce risk. And so the varicote platform brings them together in a way that they they don't have to choose between delivering software quickly or delivering to yourself where and so when I say cloud native, you know, I look at what's going on in the market today and for many of Customers and many organizations.
They're taking all of this Legacy value and their transforming it into running in the cloud basically. So they're going from monolithic architectures to you know, microservices and containers and they're using kubernetes for orchestration. And what they're doing is is that they're they're composing these new applications that are 12 factor or Cloud native, right?
But ultimately that can run inside of containers and they're all being hosted in a runtime or an orchestrator and what they're doing is they're they're blindly composing instead of writing applications like that. You know, if you look at if you look back 15 years ago developers wrote applications, right? Like I was a developer, we wrote applications.
Now you're grabbing open source, you're pulling some matters or some functions and you're putting your application together because speed is critical right time to Market is critical and so the question is, how do you enable? You know that the vertical Stacks. So how do you enable all of that open source to be secure that container to be secure that infrastructure to be secure and do that then horizontally through every step of the secure development life cycle and and bring security to life and have it be pervasive in a way that's not invasive and I think very simply on like that's the challenge right?
I'm taking Legacy value. I'm running it in the cloud and how do I know? It's secure and how do we do that quickly?
I think that's a great definition of it. Right and that's that therein lies the problem as they say. So Brian, let let's talk about what veracodes come up with here now.
But really nuts and boats are our audiences technical Don't Be Afraid. Yeah, you're right to dive in here. Got it.
Well, I mean, you know, look just maybe an introduction to the varicode platform, right? So we deliver a core application security capabilities and so the platform enables the you know static analysis where you're very much shifted left and securing your code as you're riding it your software composition analysis, which as we all know with the with the executive order and the Mandate around providing visibility into your supply chain our software composition analysis, tools become crucially important in that endeavor Dynamic analysis, which is the assessment of the Run of a runtime of an application, etc. Etc.
But what we announce more recently Alan is the Early Access of our container and infrastructure is code solution and what we essentially did was, you know, like any other organization the world we are lean we practice lean which means we deliver and minimally viable valuable product and We seek to get feedback and what's different is our our container security security solution is deeply embedded in our platform, but it's delivered as part of the developers and CLI. And so ultimately what we wanted to do with this solution is, you know in the past we've delivered sort of solutions first as part of the platform. We wanted to deliver this first as part of the command line interface because we believe strongly that when you take soft or security and you shifted further left in the process you you get better results and you reduce your cost and you reduce your risk.
So ultimately we are Early Access for our container and infrastructure as code solution delivered first as a developer with a developer focus and embedded in our platform. So, okay got it. kind of standard stuff there, but let's talk about all right, so developer runs it from his CLI, hopefully while Is it before he commits his code to get is it while it's in get it can be anywhere can be any one of those steps?
Yeah, I mean ultimately if you look at what we've done with the varicose platform in the past 12 months is that we are looking at ways to make our platform more tweakable more configurable and one of the ways in which we we've done that is we've completely Rewritten our policy engine from the ground up and ultimately our perspective is you know, it's it's your security program. Obviously, we are thought leaders and we are opinionated about how you ought to lead and and run your program or govern your developers But ultimately we wanted to provide that flexibility and the same is true with our container solution. We're making it available as part of the CLI developers can call it at any step in the process and we're seeking to provide them immediate results, you know, whether it's you know, we're hashing the prior results that we scans that we've done and we're doing dips and we're but goal is how do you enable that speed directly inside of the tools that they're using today to enable them to go fast?
So but are you actually scanning the container of payloads? Are you contain expanding the container configuration? Are you not scanning at all?
What exactly is this container security? Yeah great question. So I mean look if if I were to say to you what is a what is a what is good look like for container for container solution or container scanning?
Well, first of all, it's the images right? You got to make sure that you're starting with the right base images second of all, it's your Registries. So where you storing your images, you know, how do you know who has access to that?
Are they private? Are you monitoring them? Is that register?
Does that register reside and a server that secure at runtime? This is where your application security comes in. But are you monitoring your network protocols and payloads and all interactions with the host when you think about orchestration are you setting limits on privileged users and what they can access and then you're looking at the host operating system and so when you look Are our container solution we're not only we're scanning all layers off the container.
We're also scanning for miscon misconfiguration, you know Secrets management and look Alan I would say to you, you know containers virtual machines. They were they used to be an operations problem. Right?
The goal is to bring development and operations together in a way that they can all deliver results and containers have fast become a developer problem and and we need to have developer Solutions. And so the way that we think about application security or you know, the application developers writing. It's that you've got your your core IP.
You've got your open source software. You've got your containers, you've got your infrastructure as code and you're deploying all this and every step of your sdlc and so our solution should come to life in every step whether you're free post commit whether we're doing drift detection when it's in production, you know, essentially enable. To work or operate in whatever capacity you look everybody has is at a different level of maturity in their security program.
Right? And so we need to meet organizations and developers where they are in their maturity. Yeah, you know, it's I don't disagree with you Brian to me contain a good container security program.
It can't be one of these things, but we're just throwing it at the developers right developers have a lot on their plate. You want them to develop good software? but we want we want the entire organizations including devops including srees and platform engineering and developers.
It'd be nice to have them use one tool, right? Yeah the old they have a common tool with a common framework reference whatever right so that we're talking the same language and the security guy. Let's not forget the security people, right?
Yeah. We all kind of, you know talking the same thing. because you and I look at container Cloud native today.
It's the news compute stack. It's the new stack. It's the way everything is.
develop cicd integrated deployed and then operated and and so you want I mean in Nirvana, you know being If I Were King for the day I'd want one tool. Yeah, I could play it all of those, you know phases and all of those waypoints on my train here and is that it sounds like you're saying the varicode tool can be that? Yeah, I think look I think you just described the challenge that I hear when I talk to customers and in my in my position at the opportunity to speak to a lot of customers every week and one of the challenges is there there, you know moving away from monolithic virtually deployed architectures to more Cloud native 12 Factor ephemeral environments and in doing this a gloss across multi-cloud infrastructures, they're developers are trying to pick the right open source to enable that speed in velocity.
They're trying to learn containers. They're trying to learn microservices, right? They're trying to learn new patterns of work rather.
They're trying to get their heads around. What is lean and Lean Startup mean to me and what's an MVP and ultimately you're trying to put all this together and they're saying oh man, like this is you know, it's just compounding that it's hard the risk for them. It is hard right and you know the days of you know development would bring their coach the wall of confusion and toss it over and Cloud operations would figure out how to deploy it in production.
Those days are gone, right everybody's integrated to everybody shifting left and everybody's working more closely together to identify flaws and issues early on the process. And so the reason why a platform solution matters is that it look vendor consolidation we've seen this year is is a pattern for sure but the second theme and pattern that we're seeing is that you know, organizations are saying just just give me the Easy Button. Just give me one solution where I've got my static dynamic Composition analysis where I can provide my supply chain visibility, but also give me a container solution.
And by the way, when you've deployed that container to production enable me to identify whether or not there's there's drift in that production environment or determine for me in the event of the equivalent log for J situation that I know what's running. I know where I'm vulnerable and enable me to redeploy because look, you know, we've another area where we're announcing Early Access is in our Auto remediation capability, which is not only do we find flaws but we enable you to automatically fix them and there's a different mentality when it comes to coding fixes right developers need to establish trust in the machine and in the engine that's recommending those changes, but it's a lot different when you look at Auto remediating flaws in a base image or in a container in production. It's it's just not that controversial right blow away the container Spin it back up again.
That's the whole point of containers. They contain our applications or pieces of our applications and they should just be redeployed. Right?
We're all moving towards, you know immutable architectures. So I don't want to think to change just redeploy it for me. So, you know, we're seeing a whole whole lot of mileage where we are reducing that complexity by providing that single pane of glass where you can see all of your continuous integration delivery pipelines running.
You can see all of your risk in one place and you see that risk in context. So, you know, do I need to go action this flaw or this vulnerability is it buried behind five layers VPC and it doesn't matter or is it something that can be exploited? These are the ways that you bring velocity and simplicity to development team so that you reduce the cognitive load on them.
I love it, excuse me prior and we only have a minute or two left because I told you it goes we're probably over 15 minutes truth be told but you mentioned it was early access. What exactly does that mean are people watching out here? Can they go sign up for this now?
What if not when what what's the deal they can and in fact what you know, the program is still open and we're actively receiving feedback Alan. You know, I got to tell you I think every engineering leader out there will test to this when you release something in Early Access, right you get a lot of positive feedback often I have to say the opposite has been true here. We've gotten a lot of great feedback and we've learned what we delivered as foundational capabilities right was was on Target and I think that's a testament to the fact that we've been using this we've been, you know, as we develop software we've been we've been running this tool internally, so it's been super positive the reaction but that having been said Alan, you know, look we operate with no pride and authorship.
We want to get feedback. So if you are a customer out there you want to get access to our Early Access program we welcome you we want to get Like we want to when we go ga with a solution that you know, really Delights all of the users and all of the developers. And so the feedback has been great.
We've delivered something that's on target. That's terrific. But we want to continue to evolve it during the Early Access program.
com. com or reach out to me. Yeah.
Yeah, so They'll be able to find it there early access for the container security product. Hey, Brian, not to put you on the spot last question. When do you think not an exact date with a range when you think this might be in GA?
I think it's definitely going to be early next year and we're considering do we open this up sooner? It's really a question of what you know, what features what functionality is missing. And like I said Allen we're not getting a ton of hey like you you really miss this boat, right?
Yeah, it's more, you know, it's more about who we have more flexibility in the policy or could we render the results in a different way but, you know, nothing that's really preventing us from releasing it. So that's why we kind of want to open it up to even you know more than the customers that we have today. We've got about the 40 plus customers in there today, which is a reasonable sampling and But ultimately yeah definitely early next year and our other mediation functionalities Early Access now, Excellent.
All right. Hey Brian. Thanks for joining us.
Keep up the great work. Come back maybe around GA Time come back and key and let us know. Okay, we'd love to Alan.
Thanks and and safe travels this week. Thank you. Thank you.
Brian roach product the Russian product over Chief product officer CPO. That's actually our digital cxl. CPO.
Advert code here are Textron. We're gonna take a break. We'll be back in a minute.