PBOM: Illuminating Software Supply Chain Security – Neatsun Ziv, OX Security
SBOM is a critical step for software supply chain security, but it is only the second act in a five-act play. SBOM is a static list of the name, version, license, and any vulnerabilities of open-source components used to develop and build a piece of software. It is important for quality control and a crucial step for software supply chain security, but SBOMs leave large parts of the software supply chain in the dark. OX Security’s PBOM standard shines a light on those dark places, scanning the full software supply chain, ensuring the integrity of every build, verifying the security of all apps in production, and minimizing the attack surface.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
You know, I, we were talking off camera with this gentleman, and I remember, uh, talking to Ox Security. They had recently come outta stealth, but I don't know if I've spoken to them since. I'm really happy though, to have 'em on here today and not them, him.
We have Tsin Ziv, uh, SEN is the co-founder and c e o at OX Security. Tson welcome, welcome to Techstrong tv. Hey, thank you for having me.
Pleasure being here, Alan. Absolutely. So, Nathan, let, let's jump right into it.
Give people a little bit maybe of your background and then let's talk, you know, give them more talk security about. Okay. So, uh, uh, we started OK Security about two years ago, uh, before that, 10 years as the vice President of cybersecurity at Checkpoint.
Uh, amazing journey. Um, then we decided that, uh, it's time to, uh, leave and start a new venture in the cyber supply chain area. And we started seeing more and more events like solar winds and cold cough and, and many more.
Um, since then, we raised about $40 million, uh, seed from, uh, Microsoft I b m Evolution Equity teammate. Uh, the company's about, uh, 70 people already, A few tens of customer, hopefully very soon. Good touching the 100, uh, customer mark.
And what we're doing for our customers is allowing them to secure the entire software supply chain from the code to the build to the cloud. So the entire journey, securing it from, um, code to cloud, um, in a very, very nice and graphical way. Excellent, excellent.
Um, be before I, we're gonna talk SBOs today, but before we get into SBOs, I just wanna make sure for anyone watching this, and maybe they want, you know, how people are, they'll, they multitask if they wanna look up OX security, what's the U R L? security as you and you can go into the product, play with it. Uh, always, uh, product led.
Fantastic. Alright, so let's talk SBOs. Look, our audience is a very cyber savvy audience, very technical.
We've all, we've, we've covered SBOs every way you can seven ways from Sunday, right? And, um, and we still do, but you have a unique take on SBOs. You think we're in the second act, in a five act play is, is how this was kind of presented.
Explain what you mean by that. So, uh, let's take SBO M and let's for a second, define what it is. So imagine an Excel spreadsheet saying open source version, license known vulnerability.
That's as long for you. Now, the challenge with that is if you look on all the software supply chain attacks that we had over the past, let's say five years, it is a very, very small percentage that actually goes back that this Excel spreadsheet can help you with. So you take the big cases, solar winds, cold covid, so ASBO wouldn't have helped in any other way.
So what we suggested is, let's extend asbo because it's, it's the right direction. It is saying something that the logic behind is let's record what do you have inside your software? But it doesn't count for how do you build the software?
What software vulnerabilities do you have inside of it? Did you embed passwords in it? Do you build on a safe containers?
So there are so many different things throughout the software supply chain that SBO m simply does not cover. So, uh, with the help of about 20 different companies, we formed, uh, a new startup called PBO Pipeline Bill of Material, which says everything that goes into building the pipeline itself or the software itself, we need to record and say, are we accepting the level of security that gained from that step? And the way, so it is, the analogy would be if I'm looking on the ingredients of something that I'm going to eat, it is just on looking on the amount of sugar without, I don't know, salt or, or other things.
So you're saying let's record everything and let's say that everything needs to be accounted for, everything needs to be in place, and this is how you can ensure security and just of, instead of just looking on one parameter, which is the list of open source that you're using. I hope it makes sense. Yeah, no, it makes sense.
You know, look, so my biggest fear when I first saw the SBO kind of, you know, the whole movement or coalescing around SBOs and so forth, was, God, I hope we're not going to use a spreadsheet for this, right? There's gotta be a bit, there's gonna have to be some, some way. And then, and then my second fear was what I, in my mind called the balkanization of spo, right?
Is that we would have competing standards competing, uh, FinTech and protocol that would, would create, you know, the balkanization like, like we had with Unix, right? There was so many different Unix as Linux came along and cleaned it all up. Um, and, and we see we, we've seen a few different standards around SBOs, but I, I do, I do think you're right.
You know, you spoke about when you guys came outta stuff two years ago, so it was two, two and a half years ago at R S A we were putting on the DevSecOps event, and we had a great panel on SBOs with, um, Alan Friedman from, uh, from, uh, the government. He, he was with the US government at the time, and we had, I forgot her name, but a a PhD doctor from Intel. And, and we were, you know, discussing all of these things.
Do you think we've matured enough in this evolution around SBAs where we, we are coalescing around a standard that we can all get behind? Is is that the message here? I think it's a, it's a bit more complicated than that.
Uh, meaning I'm afraid of that. Yeah. It's, uh, it, it always goes back to people.
Uh, and as you can imagine, people working at a vendor, they don't have a great incentive in actually exposing their S om because what it actually means for them is usually more work and more logistic and somebody coming from the outside and can pass judgment without them approving or not approving that. So their incentive to actually provide the SBO is very rarely. So they're actually looking for ways to say, what is the minimum that I can do with the maximum that I can gain?
Like everything that you, you would say. And if you are taking it that way, then the idea is to say, yes, I've got an sbo, but never to share it with anybody else. So if you're not sharing the sbo, so the value that the legislator thought about saying, let's have the, uh, accountability on the consumer of the software to actually enforcing, is it secure enough to use yes or no?
It, it doesn't really, uh, get into place. And this is where I'm relating to the first part of your question. So are we mature enough to do that?
So the answer is once again, no. Um, you can get the files if you ask them, but when you get the list, it's file, you, you, you consume the file, and now you've got hundreds if not thousands of vendors that you need to consume it from. And then you need to somehow orchestrate this entire operation.
And let's say that you did find something interesting, they need to go back to the vendor that already knows because they have the SBO as well, and tell 'em, you guys need to fix this, but the vendor already knows that it needs to fix this. So right now it, it's, it's a loop that, uh, nobody can actually solve. Yeah.
Well, there's a couple of reasons for it too though. And you know, and you, there, there, there was, this is saying in, in the us Ronald Reagan first started it, which is the eight scariest words in the English language is, I'm, I'm here, I'm from the government and I'm here to help. Right?
Anytime you get the government involved in these, you know, cybersecurity or technological kind of things, they mean, well, they mean well. But generally speaking, they set sort of a low bar, like a least common denominator for the standard. And the standard doesn't necessarily get to what, what the intent was, right?
The, the legislation, the rules, the governance doesn't really match the intent. Um, the, the other thing is, look, I, I agree with you. I think a lot of what I've seen from the SBOs, it's like reading your cell phone bill or your, or your cloud bill.
It, it's purposely obtuse, it seems, where you really can't necessarily get to what you want. And then the third thing I, I will tell you za, is I, the more I get into Esam, it's like one, you ever see those Russian dolls, that there's dolls within dolls within, you know, you lift it up and there's Yeah, It's called, uh, babushka. Yeah.
Ha, babushka. Correct. So that's what an esam is, right?
Because the more you peel that onion, the more you find, oh wait, but this has a dependency on that, and this one has a dependent and that has a dependency over here. And that one of course is dependent on this. And now you're going four or five dependencies out from, you know, the software that you thought you have here.
Putting all of that on the consumer, whether the consumer's a commercial entity or a true individual is, is putting it in the wrong place in my mind. Right? It's, we, I don't think the purpose of the s farm was to put the onus on the consumer to police the software, to police the dependencies, to police the third party pieces in there.
I would agree. I think it's, if I go back to the, um, food labeling analogy mm-hmm. It's not a police, the manufacturer.
It is for you as a consumer to say, you know what? I'm not going to eat that. Yeah.
Now it's more of an educational side, but I think the, the gap from meaning, I, I would go better with something that they've done in the restaurant world saying, you've got A, B and C grade. And I'm saying, okay, if I'm seeing certain level that I'm, I'm simply not going to go in because somebody simplified it to me to saying three options. Yes, we trust this.
There were some issues, we don't know. And definitely not. That should be, That would be great.
I mean, how do we get there? Okay, so imagine that you can take the sbo, you can ingest it and say, what do you think A, B, or C out of the challenge that most of the time you're going to get B or C? The amount of A is not, is not that high, right?
And even if that is the case, you're going to get an A, you're going to get a, just on the amount of sugar in the meal. It doesn't say anything about anything else in the, in the industry. So, um, even if you'll be able to simplify it, it'll mean very little in, in the reality of things.
Understood. Understood. So let, let me, you know, we we're going to go a little full circle here.
Let's bring this back now to OX security and what you're doing. How, how are you helping with this? Okay, so Asbo, think about it as one criteria that you need to pass.
I'm going back to the food analogy. So I probably want to see the ranking of the restaurant saying it's an A, and then I would go to something that ranks restaurants in terms of, uh, customer's review and saying, okay, what is it? Is it good?
How many reviews? And then I'd probably look on a few dishes, say, okay, is it my taste yes or no? So we're taking this concept of saying there are different points within the, the software, uh, supply chain that you would like to tap into.
You would like to see the developers that are actually fixing the code. You would like to see that the SBO that you're bringing is correct, that you don't leave any security holes in your code. That the C I C D itself, it's posture is secured, that you don't ship things to the cloud without integrity.
So you pick up on, on the things that might change the, uh, the security level of the software supply chain, and you want to address them one by one. Now, how do you get to that point? Um, if you know the Mitre attack attack framework, then we've done a translation from the endpoint to software supply chain.
About 20 different companies helped map, um, about 300 software supply chain attacks. We broke them down to the TTPs, the techniques, tactics and procedures, and build a map with is on the site, pbo m do dev, pbo m do dev, that you can actually see all the techniques used by threat actors. And now that we know the techniques, we can actually go and search for them throughout the entire software supply chain.
Th this is what OX is helping do. And once we do that, we help you how to remediate, who do you need to work with to fix those issues? How do you automate the process and actually close the disciple for you?
Love it. security and get their hands on the software right now, uh, use Everybody. Yep.
So how do you make money? So, uh, people usually start the projects, uh, by saying, okay, we will start at the demo project. We'll have just a few developers.
This is the community edition. As you start scaling upwards and we've got customers with thousands of developers, you pass certain threshold in the few, uh, let's say passing 10 developers at the moment, you need more functionality and more developers, then we ask you to move to the commercial tier or your, the enterprise tier over there. Uh, we charge money, sure.
But we also have, um, open source that does some of the functionality for people that need, I would say cost flexibility and have more time. Uh, you can see them on GitHub, uh, project called Megaliter that embeds a lot of scanners to one place, open source, completely free, 100%, and there's a commercial version. Excellent.
All right. And just real wrapping up, I, I don't know if this'll air before, but you guys are gonna be a black hat. Yes.
Yes. We're gonna be in Black Hat And you'll be at Oasp in December? Yes.
And in F Ss Isaac. And I think we've got, uh, two more, uh, throughout the year. What about CubeCon in Chicago?
Any plans for that one? I do not know yet. Uh, okay.
But it's something that it's definitely worth exploring. I don't think it's right now. It's on our calendar.
Alrightyy. I'll write out. I appreciate it.
Ni and Ziv, co-founder, c e o, at OK Security here with us today. Thank you for coming. Please stay in touch, come back on, keep us posted.
Love to talk about SBUs. Thank you very much. Pleasure of meeting you.
Okay, we'll be back here in a minute on Text Drug tv. We're just gonna take a break.