Mitigating Application Security Gaps – Jens Eckels, JFrog
According to IDC’s DevSecOps Adoption, Techniques, and Tools Survey 2023, the top two application security gaps at their organizations were the growing use of open source software among development teams (30.9%) and a vulnerable software supply chain (28.9%). JFrog Curation offers a seamless way of blocking malicious or risky open-source packages before they get into the software development pipeline. Automated policies keep undesirable components out, saving time and money fixing or replacing suspect packages later in the SDLC. JFrog Curation offers a seamless way of blocking malicious or risky open-source packages before they get into the software development pipeline. Automated policies keep undesirable components out, saving time and money fixing or replacing suspect packages later in the SDLC.
Transcript
This is Techstrong tv. Hey everyone. Welcome back here to Techstrong tv.
You know, we haven't had a frog on the show, in, in, it might be weeks if not months. Part of it was my fault. I've been traveling and doing my thing, but I'm happy to, uh, it looks like we have Iron Frog on today here.
Jen Eckles. Uh, Jens, it's good to see you, man. How are you?
Great to see Alan. Doing well. Doing well.
It's a, it's a beautiful day. Summer's in full swing, and we're ready to roll. Yeah, we were talking off camera.
It's so funny. And, and this is the, the thing of summer. One day, it's July 4th and it's the beginning of summer, and then, you know, boom, you turn around and you're looking at August.
And August is just, especially down here where we live, right? August schools open, back up, everybody goes back like summer's over by August 15th. Right.
Happy Thanksgiving, Alan. Exactly. Well Halloween, we'll see.
But, um, and, and you know, I no kidding around. I went to some store and they already had Halloween stuff off. I'm like, what are they?
Outta their minds. But, um, anyway, Jens, it's good to see you. For people who don't know Jen, so why don't you give 'em a little bit about your background?
Sure. Um, Jen Zol, I'm the VP of, uh, product marketing here at Jfr, have the privilege of, uh, manning a lot of those marketing go-to-market functions, uh, for Jfr. I've been with them for about five years, been in tech for years, um, longer than we would like to, uh, longer than we would like to remember.
Um, but, uh, been in this, uh, DevOps space almost before it was, uh, was a phrase. And I've been along the ride with you, Alan, and others, for, uh, the evolution of this for quite some time. So happy to join you and, uh, glad to represent the frogs today.
Cool. It's good to have you here. It's a pleasure.
Always nice to have the frogs on us with, with us. Um, so Gens, JFR is a company that needs no, um, introduction to our audience. But what I do want to kind of mention is, you know, we, we, as you said, we've covered the DevOps space for a long time.
I got into DevOps from security because I thought it DevOps was a great thing for security. And, you know, over the last 18 months, certainly we've really seen DevSecOps become DevOps or DevOps become DevSecOps. And it's not just with Jfr.
I, you know, quite frankly, we see it with all of the, all of the, you know, big DevOps players really focusing in on DevSecOps. But certainly at j Rog, it really has become the mantra, right? And, and, and frankly, shlomi and teams put money where their mouth is.
They've acquired a number of, of cyber related companies and, and incorporated this into the offering there. Um, and, and so Jfr is a security first company in many, many ways, um, helping developers still true to their mission, right? True.
'cause Jfr has been around, I don't know, 16 years, 17 years, something like that. Um, but security is, is Job one. Um, along that line, you guys recently released something called j Rog Curation, right?
Correct. Tell us, and, you know, educate us. Sure.
Well, as you say, it's, it's kind of part of an evolution, not just of J Rog, but definitely what we see from the community and customers. You know, you know us best probably for j Rog Artifactory, which, uh mm-hmm. We would argue still kind of the gold standard in artifact management.
And that's, that's the core of a lot of, uh, what J Rog does. That's the database of DevOps for a lot of companies. But as we introduced, uh, just a few years ago, J Rog x-Ray, which is a software composition analysis solution, um, it was from our customers telling us, Hey, now that we've got all of this, uh, all of this binary management under control, help me secure those binaries.
Tell me what's inside all of those containers. Classic software composition analysis use case, but didn't really go far enough, uh, for a lot of customers. And now we're moving into, um, some more advanced security features.
And we talked to you, Alan, and, and your audience and the community about those over the past many months on the context of vulnerabilities and the ability to detect, uh, infrastructure as code secrets, man, uh, secrets detection, et cetera. Um, so some of more of these advanced pipeline solutions. But as we've moved into this software supply chain security idea, these little point solutions to scan this, to manage that doesn't really scale well anymore.
Um, just in the way that DevOps tools kind of promised us to bring some efficiency. Now, these DevSecOps tools are creating this spaghetti infrastructure of results and reporting and everything. And so our customers came back to us and said, Hey, security in the pipeline is great.
Security scanning in production is great. What we need though, help us guard as early as possible. And so, with jfr curation, which we just announced recently, we're kind of proud to go, shall we say, left or than left in this process, before something even comes into the organization, we're going to be able to help you curate those, uh, software packages and open source and third party software much more effectively.
Um, and the reason that we believe that this is, uh, something that our customers are really gonna latch onto is we're doing it in an automated fashion. Uh, right now, there are some solutions in the market, great companies, great solutions, but still involve a little bit of manual work, some manual research, but backed by the j research team, public data and other sources, we're able to automatically into an organization or curate what's allowed to come in in the first place. Almost like putting a fence around your, uh, around your yard, right?
Does that mean you don't lock your door? No, of course not. But you're gonna do as much as you can at the perimeter to make sure that nothing nefarious gets in.
It's pretty simple. Keep the bad guys out to begin with, and there's less for everything else to discover after the fact, right? Absolutely.
You know, Jen, I, I, I sit here, right? I talk to everyone. I see what goes on.
com, you know, I was in the security, I started a few security companies and, you know, venture backed companies. And in my mind, I never understood why Jfr, for instance, right? You, you control the artifactory, you control this whole repo of, of, of stuff.
And there are other companies that control repos. To me, that was always the logical choke point of why wouldn't we put a firewall right? At that point where, where I access my repo so that if I'm downloading an old version of an artifact or a known vulnerable version of an artifact, why isn't it blocked right then and there, right?
Like the same way when I go to a website on, on Chrome and it says, hold on, the certificate's expired, or this could be a dangerous site. Why? Why wouldn't, why wasn't that it, like even x-ray for as good as X-ray was, it wasn't, it wasn't a choke point, right?
Because to me, that was always the logical choke point. So is, is this what curation is kind of, is it, is it a, a, a repo firewall where, you know, wherever you're bringing third party stuff in, I'm, I'm checking it first In, so in so many words, I think you're, I think you're accurate, Alan, and, and the difference maybe between what we traditionally did with x-ray and some of the advanced security solutions we have now, to use your phrase as a, as a choke point, is you were able to build policies around things that were already existing within Artifactory, right? So I wanna say what's in my repo, um, x-ray was gonna tell us Yeah.
Of, of current. And yesterday year x-Ray was gonna tell us, here's what's in there, and maybe you wanna build a business policy around that. I don't wanna use a package for my developers that has a bad C V S S score or something, right?
But that's, that's something that's already in Artifactory. Now, this curation solution, as you say, is a choke point. While that, that could have maybe a negative connotation, it's, it's the same reason you put the deadbolt on your door, um, door at night, right?
It's, Hey, what's that point of entry? I don't want that stuff inside in the first place, and I want to build my business value and my business policies around that, for example, um, I could want for many reasons to not bring something into, into the organization. It could be a security risk score from a public source.
It could be based off data like jfr, security research data. It could be that I don't want to use certain technologies at all in my organization for a reason. It could even be, I don't wanna bring anything in that an open source maintainer hasn't touched or updated for 18 months or more, or 24 months or more.
In fact, we saw recently, um, and I, I won't get uh, too specific on the examples 'cause I don't wanna throw anybody under a bus or, or, or cause any, uh, any strife. But we saw some examples where maintainers themselves were accidentally, not nefariously, but accidentally introducing vulnerable code into their open source libraries. We wanna stop this kind of behavior at that gate as much as we can from something ever coming in the organization.
So as you say, it's a logical point to say, my artifactory is secured, my repo is secured. Now I wanna make sure that anything that's coming in from the public source is also secured, or that I've, at least I know I've got eyeballs on it. I'm watching those guys coming in, and I've set my business policies to know that I'm not gonna invite any strangers into my house.
Agreed. Agreed. And you know what, maybe choke points the wrong word, right?
Because, but you know, in security we talk about attack surface. Mm-hmm. Right?
And, and unfortunately for most organizations, our attack surfaces are so large, we don't even realize how big our attack surface is. There are very few places, or very few points where we can control that ingress and egress of potentially harmful traffic, of harmful code, of harmful, you know, attack points. And this was what, you know, when I was coming up, we had the Moton castle kind of defense, uh, uh, model to, to, you know, defend offices because basically all your traffic came in through some Cisco router, right?
And so that was the logical place to put a Cisco firewall, had a pretty good business back then, right? You put your Cisco firewall there, and so as all your traffic came through there, I was able, you were able to say, okay, this good, this bad, this may be good, whatever. Yep.
It's that same concept that I'm talking about here. If this is the point where third party packages or third party software is coming into my development, uh, supply chain, that's the logical place to be checking for it and potentially filtering it out. I think one of the issues though, and it has been an issue in security all along Jens, is some people say, wait, I'm afraid to just filter it out automatically.
I want a human to, okay, right? I want a human to say, yeah, no, that, that is bad. We don't want it in here.
Be I, and I never, quite frankly, I never understood that about security, right? Um, when we were talking about I d s to I p Ss and, and, and, and patching vulnerable software, I never understood why the reluctance to automation, but it's there. I wonder if, if this is something like how does curation deal with that?
Yeah. So there's a couple, a couple of things that we're gonna help a, a company do, um, from this point of view. Now.
Now, what you said is absolutely correct, Alan, in that this is a, this is a logical place for the organization to apply some of these things, but it is not necessarily a fun thing for developers. If security's saying, ah, you're blocked, right? If that's where I'm getting everything, I still, my, my business requirements have not changed.
My deliverables have not changed. My necessity of utilizing trusted tools has not changed. So don't get in my way.
And if you put humans in the way, humans don't scale real well. Um, and the security team doesn't want to spend all of their days researching every little package and seeing if it's allowed. Like nobody wants to do this.
You're doing it because you want to keep the business secure, and everyone's kind of grumbly about it. Um, so what we're able to do is allow that security team to say, how about I apply some global policies? How about I make some rules that still give you the freedom in the sandbox development teams that you need to go automatically do what you need to do.
So I'm not in your way, I'm not slowing you down. I don't wanna look at it. I just want to know that it works, and I want to trust that it's working and be able to apply all those things at a global level and centralize that automated process, and then go knock yourself out with the stuff that's available to you.
Um, because, so I don't think that download and scan and research every package, nobody's got time for it. Nobody's got time for it on the security side or the development side. So we're trying to eliminate that friction in the same way.
And if people say, Hey, I need a person to look at this, or Maybe I was blocked from doing this, you're gonna get notifications, you're gonna get emails, you're gonna say, here's here, you know, you tried to utilize something, this is why it was blocked, and you can go chat with your security team if you need to. But I want to e I wanna remove that, uh, that necessity for the human in the middle to be able to get your work done. Love it.
Jens, we're running low, low, little low on time. I gotta move this along for people who are liking what they hear here and say, Hey man, I wanna check this out. What, what's the, uh, what's the, uh, path to, you know, the on-ramp to using Duration?
Well, I could give you, I could give you the email address direct for a po Alan, but that's probably jumping the go. Yeah, probably a little bit. Probably jumping the go.
You mean it cost money? I guess that means how, but okay, go ahead. Absolutely.
So very, very simple. com homepage. There's a easy to find little product link right there at the top, and there's a landing page for j Rog curation there.
That will give you all the details about the curation solution, yes, but also how you can trial it. Wanna make sure this is gonna work for your org. Obviously we're talking about the security of the supply chain.
Uh, you need to put it through its paces and make sure this is gonna work for your business. Um, one great thing is, you know, it's already backed by, we had some wonderful beta testers, some of the biggest companies in the world that walked through this development process with us, household names across verticals. So this is a tried and trusted solution for some companies already.
Happy to do that. Also, we are gonna be at Black Hat. I know you're gonna be there as well, Alan.
So shout out to the, uh, the Black Hat attendees, so you can come visit the Jfr booth at, uh, at Black Hat, get some more details, see the frogs, get some cool swag, and also we'll be talking about this more and doing live demos and, uh, more details on curation at our annual conference. com/swamp Up. I know you've been to Swamp Up before, Alan.
Um, so it's one of my, my, I'm biased, but one of my very favorite shows because it's real stuff and, um, not not fluffy things, it's just real people doing real work in this DevOps and DevSecOps space. So looking forward to it. But we invite everybody to try curation.
Absolutely. If I'm not mistaken, John Willis is gonna be at Swamp Up. John Willis is one of our featured speakers at Swamp Up, a good friend of Tech, strong tv, good friend of Jfr, and, uh, one of the, John John works here with us now.
Oh my goodness. You know what? I knew, I knew that this was going downhill, Alan.
Yeah. Well, look, truth be told, not only does John, John's not full-time here, but he works with us here at Techstrong, but his two sons work with us too. Well, one's just a summer intern, the other's full-time.
So yeah, we've gotten all the Willis is here. Um, everybody, Everybody's here. Everybody's here's, it's A fun place.
I tried to get 'em all to come. Thankfully, we're all pulling on the same end of the rope around here. We want people to be fast, we want people to be secure.
We want to co protect companies and developers and, um, you know, all these community events, security events, we're all zeroing in on it. We'll get there all. Um, but, uh, always appreciate your support, Alan, and thank you for having me.
Pleasure gens. com. Go there, go into products, go to curation, check it out.
This could be the, the third party package firewall I've been looking for for 10 years. So I'm looking, I'm looking forward to seeing how it plays out. Jens, thank you very much.
Say hello to all the frogs for us. Hopefully we'll see you in Vegas during Black hat. Um, but we're gonna take a break here on Textron.
We'll be back in a minute.