SBOM’s Role in Software Supply Chain Security with Tanium’s Vivek Bhandari
Vivek Bhandari, vice president of product marketing for Tanium, explains why, given the dynamic nature of application development, any approach to securing software supply chains needs to start with a software bill of materials (SBOM).
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Vivek Bandari, who's vice president of product marketing for Tanium, and we're talking about software supply chains and SBOs and how maybe the answer to our woes lies in these software bill of materials that folks are supposed to create.
But I'm gonna put it to him 'cause a lot of the folks I talked to are scratching their head trying to figure out how to operationalize all this stuff. Vivek, welcome to the show. Thank you, Mike.
I'm just looking forward to the conversation and sharing certain insights with, uh, listeners here today. I think the Biden administration put SBOs on everybody's radar screen. They basically told the federal agencies We need to have this.
Everybody looked up and said, what are these things? And some of them had them and never even used them before, but now they're trying to sort through them. And a lot of folks now mandate that there is an SBOs so they can hopefully figure out where vulnerabilities are.
But I put it to you this way. Um, there's so many SBOs, so many formats. How do I make sense of all of this in a way that I can operationalize it to actually make my software supply chain actually more secure?
Yeah, Mike, that's a great question. It's a very broad question, but I think you summed it up real. I mean, you said it pretty well towards the end.
The ultimate goal is to really mitigate risks coming from the software supply chain, right? So if we sort of take a step back now and look at why this thing is so important now and gaining such importance amongst all organizations globally, the reason is if you think about software today, it is a lot more dynamic. It's not only a lot more prevalent and there's just more and more software.
Everyone, no matter what industry you are shipping, retail technology, healthcare, finance, there is a significant software component to your business today. And why the software has become so dynamic, it's probably because of the cloud. Cloud has been a big catalyst in making this happen.
And if you sort of, you know, throw back days, early days of my career too, when we, you know, I used to walk into the office and I would work on a, on a machine that was plugged into the wall and there was certain software thick clients deployed on the machines and we worked on it, right? And it was once a year or periodically where the software would get updated. But today, software, the way we are consuming software as a service and cloud delivered software has really changed the game.
It's allowed a lot more innovation to come out. It's allowed businesses to really leverage this innovation to further their own businesses. But as part of that, that's made that software dynamic, right?
There's so much software we are using from the cloud, there are components of it that are on our devices, whether it's laptops, you know, tablets, mobile phones, and attackers have evolved and realized, you know what, while it is maybe getting, you know, a little bit harder to directly get onto the user's machine what, or, or, or organizations network. They're finding creative ways. And one of the ways is going through the software supply chain.
Now, again, what's a software supply chain? Modern software is primarily built using a multiple different existing components, what we call as open source software, right? Just like Lego blocks, you, you take a few things, you assemble them together with your own design and logic, you add a little bit more custom code to it, and Walla, you've got an application that at the fundamental basic level is what it is.
So as you're assembling your apps, modern software using these open source components, these open source components, there's millions of those out there. And it's really spurred this rapid development of new applications, right? But what's happened as part of that is because it's open source software, it allows attackers to inject bad code into it.
And once you get that bad code, anybody that's using that open source software becomes vulnerable, right? To that bad, that malicious code sitting in there and to exploit it. So that's the backdrop here, right?
Software has really sort of, uh, modernized using open source libraries. There are millions of these open source libraries with really smart people globally contributing to it that allows people to leverage each other's innovation. But attackers are using that medium to get in.
And when you think about it, in an environment today, in any enterprise, any organization, there's hundreds if not thousands of different pieces of software that are being used that is software both that organically developed by the organizations, but the own engineering team. And a lot of it is sourced through vendors. And each of these have these open source components.
So now, if you don't know, so SB is really what is the componentry of each of these software at the most fundamental level, right? And that's foundational and important because when you do discover that something is bad, right? What we call as a zero day vulnerability or a new vulnerability or that gets announced, sbo m's really a loved one to understand where that problematic software might be.
So to your point, it's a highly dynamic software environment. So how does the SBO m know what's out there in terms of the components? 'cause a lot of times, you know, I've seen SBOs that are so far out of date, it's not funny and it doesn't really help people.
So, um, how do we continuously update the SBO m when we're dropping new containers or whatever artifact it might be, you know, a couple of times a week? That's a challenge that frankly is the challenge. And that goes back to your original question too, around the government stepping in and asking at least all the government agencies and critical infrastructure organizations to, you know, mandate and ask like you have an SBO m in place, SBOs get out of date all the time.
Because the way SBOs a lot of times are assembled are by the development community, the developers, right? As they're assembling the software, they are basically creating the SBO m and now these mandates are requiring that you include your list of ingredients with whatever software you ship and supply to the, the government, uh, uh, side of things. But as software evolves, right?
As we know, like software is constantly being updated, new features, added fixes being done, that componentry is changing. And so the SOM is also dynamic and it may not always be, um, you know, fully sort of active and in line with what the software code is. The other challenge here with SBO M becomes is now you think about it, if you're running hundreds of pieces of software as an organization and each of these software have their own sbo, now you are required to sort of understand across all these sbo, what's my true master SOM at my organization level.
And there's nobody really sort of looking at that. And that's where an organization like Tanium, for example, what we do is, doesn't matter whether you got an SOM from a software supplier or not, we, we create a dynamic s om at the organizational level, right? It basically looks at all software, whether it's homegrown third party source, it looks at all the libraries recursively inside, and it creates this comprehensive list of your enterprise level SOM and where those componentry are sitting and which applications, which endpoints and servers.
So tomorrow, Mike, for example, right? A lot of the organizations, if as they're dealing with zero day vulnerability, so let's say God forward, like, you know, there's a major log four J kind of an incident that comes along when you think about the log four J people were scrambling for weeks, months, and even today, organizations getting nailed with that vulnerability. It takes a long time for organizations to figure out where in my entire IT estate do I have this library across all the different software?
Tanium can tell that to organizations in seconds, right? Because we are there on the end points. We can look at all the componentry across all software.
And when organizations want to find out, show me all endpoints with open SSL version three, it'll boom list everything about, you know, where it is, what version, all the details you need to be able to sort of understand where your risk is. And then you can sort of a platform like Tanium can also help you remediate if there's a patch available, patch the systems if you want to temporarily quarantine because it's too severe and it's a critical asset facing the internet that could get exploited. Let's quarantine that off.
Let's uninstall the software if it's too risky. All those things become possible. It starts with visibility, instant visibility that would take months before.
Now we have tooling and platforms like Tanium that can tell you in an instant where you have the different software components in your idea state Who's in charge of all of this? Uh, what sounds inherently chaotic because you know, there's DevOps and developers on one side and there's cybersecurity folks on the other and they don't always get along. They, Tony, you're right, I think it's an ecosystem, right?
And everyone has a pretty important role to play in this. So from a developer community, I think people need to continue to include SOM in the software that's being shipped out and shared and as it is getting updated, but from a security community, right? For, for organized, for, for teams that are looking to defend their organizations from attackers, they need, they need an ability to be able to identify in real time where a potential new identified vulnerable software is, regardless of who the supplier was and whether it was built by their own teams.
And so that's their priority because they are looking to protect the organizations and mitigate these emerging risks. And that's where I think, you know, the third uh, leg of this tool here is organizations like Tanium can really help fill that gap by providing a true platform, which can allow organizations to immediately get visibility on the componentry across the IT landscape, right across the IT estate within their environment and help identify, tell me where this thing is right and what remediation options I have. And that can really start tilting the game because I mean, a recent example Mike, right?
I think, uh, was, uh, what was it, Comcast, just not to in the recent past was a victim where there was a, you know, software and the nature of software is there will be vulnerabilities that get discovered, right? And they found, uh, vulnerability in one of their, uh, um, uh, set of servers, our application. And as soon as they found that out, they very quickly within a week assessed where it was and remediated within a week's time or so.
But even that week exposure was enough for the attackers to go after it, and they were able to steal tens of millions of sensitive records out, you know, from the environment. And that's how fast these attackers are moving. So you, we don't have the luxury as, as defenders to wait for days and weeks to assess where my componentry and what software is bad.
You need a way to identify right away and then fix it right before the attackers can get to it and exploit it. And that's the world we live in. Do you think someday that AI might save us from ourselves because, uh, the algorithms are, can at least be trained to discover components and learn what's in an environment, but you know, how smart and smart get Oh yeah.
I mean AI will certainly have a role to play in this area for sure, like in many other areas. And I think where AI can really help is providing those insights and recommendations early on. So things that humans have to do today by, show me where it is and then show me the importance of the relative, uh, endpoints where I need to patch.
So for example, if there's an internet facing server that has a, has a problematic software versus an internal server that has very limited connectivity, naturally you're going to sort of prioritize the one that's facing the internet and the attackers can get to sooner. So, you know, things like figuring out the prioritization, figuring out at a global scale where, which things are getting exploited and putting that into the priority list and then, you know, sort of maturing the models eventually where you can train them to automatically take actions, right? So as you discover these things, go ahead and identify them, triage them and fix them, right?
I think that's where we can create autonomous capabilities within the platforms that can both identify and take action. And I think that's where AI will play a role. Now, it'll be a journey, right?
And it'll be a steady journey. We'll have to earn the trust of the operations teams, whether it's security or it, um, but it'll certainly give them a much needed boost, right? In terms of operational capability, because you can't throw enough staff at this, right?
To keep solving the problem. And you look at the skills gap that we have in cybersecurity alone, right? In the US and globally, it's in millions, right?
You just don't have enough people to go, you know, take care of the basic hygiene today. And this is where AI and autonomous systems will play a role in really augmenting the stuff and giving them that scale to not only automate a lot of these mundane things, but even dynamic things like being able to find new vulnerabilities and fixing them. I dunno if you can name customers or not, but who's getting it, right?
And how did they go about doing that? Did they just throw everybody involved in a room and lock the door until reason prevailed? Or is there some smarter way to do this?
No, I mean, look, I think the most security conscious organizations are already embracing this, uh, approach. And I can tell you that from, from our perspective, from Tanium, ever since we launched this dynamic enterprise scale SOM capability, our customers are just soaking up that capability because they have realized that by using this capability, and a lot of them already had the right sort of platform capability, and it was just an enhancement to that cap feature, they realized it was saving their staff months, it was saving thousands of person hours for organizations and not only saving thousands of hours, it was helping them mitigate risk faster, right? So what we are seeing is the more forward leaning CISOs, right?
Top financials, like for example, at Tanium, we have a lot of large financials in the fortune hundred that our customers, they're already embracing this capability Departments of defense, they are leveraging this capability, right? So anybody that's in the, in the, in the highly, they have more sophisticated security teams, uh, have immediately jumped on it. And then even the more mid-size organizations where they have limited staff even and limited security expertise for them, it's even more important.
Like, what is it that the systems can provide us if we have this SBO add an enterprise level that can instantly tell us where, what is that gives them enormous stride forward in, in, uh, protecting the environment, right? From the bad, bad actors. All right, folks, you heard it here.
Well, if you're lost, you need a, a map. And the truth of the matter is, when it comes to application security, these days, more of us are lost and we care to admit. So an s bomb is a map, then you start from there.
Hey, Vivek, thanks for being on the show, Mike, thank you so much. This was really good and fun. And hopefully, you know, we, we delivered some value for our listeners here today.
Thank you. All right, back to you guys in the studio.