Snyk’s Manoj Nair on Simplifying DevSecOps with App Telemetry Data
Manoj Nair, chief product officer for Snyk, explains how the acquisition of Helios will advance DevSecOps by making it simpler to capture application runtime telemetry data.
Transcript
This is Textron tv. Hey guys. Thanks for the throw.
We're here with Manoj Nair, chief Product Officer for sneaking. We're talking about their acquisition of a company called Helios that specializes in capturing application runtime data and how that's gonna improve our overall state of cybersecurity. Manoj, welcome to the show.
Hi, Mike. Uh, good to be back. Good to talk to you again.
So walk me through what it is exactly that Helios does, and then kind of position that as it relates to what we're gonna see in terms of improving the state of application security. Great. Excellent.
Uh, so Helios, uh, you know, it's a very interesting company. Uh, we've been, uh, tracking them, partnering with them for, for a while here. Uh, and what they did was, uh, they were really pioneering in, um, how do you capture application runtime, um, data with, um, very similar to snyk.
You see, with my background, DevOp security trusted, they were, you know, trying to be dev first in terms of getting that observability data and runtime data. So there's a whole category of companies that do observability. They're trying to do this in a way that it's really empowering developers to be able to track what's happening, you know, so a lot of times deforce build products, but they don't know once it's deployed, how is that application doing?
And it's, you know, like you got DevOps teams, platform teams. So it's really bringing that control back. Um, just like we did it for security.
Uh, that's where they started. Um, so, you know, dev first, um, and, and monitoring and looking at, you know, what's happening with that application. Um, there were standards like, uh, hotel open telemetry and other that they embraced.
And, and doing that, uh, over time they also started looking at security settings of that application and runtime. So again, standards like, uh, EBPF, which for containerized data, it's, uh, you know, the ability to filter and look what's happening, you know, underneath the container. And so that, that was what they were doing, but they're trying to bring that context back to devs.
Uh, that's Helios. And Where does that fit in the context of application security? Because it kind of sounds like we're trying to bring observability to application security, or where are we going?
Yeah, observability and, and little bit of like, uh, security context. Um, so, you know, it's been, this whole space is very interesting, right? We came at it from an ability to empower devs with context and automation so they can fix security issues before they get into production.
Um, modern apps are complex, lots of reasons, lots of ways that new, new vulnerabilities come in. And what we observed is, uh, one of the big reasons, you know, this started, um, like maybe been there going on for a while, but over the last 18 months, um, when you ask CISOs, why do you get software supply chain attacks, right? Uh, there's a Forrester data, um, recently I saw 2023, what's the number one reason for, uh, you know, a breach in an enterprise?
And the software supply chain attacks and software vulnerabilities are easier to breach and conduct a breach than, uh, you know, that phishing email that we all get all the time, that's how easy it's become. And so when you, when you talk to CISOs, um, they understand it, they understand it's a big risk. Yet backlog is a big problem.
So tools, the tech data and tools like snyk are really focused at quickly fixing it. You know, there's this old adage of quality, the sooner you fix it, the least less expensive it is. That's the same approach we take for security as soon as possible in the id in the, uh, you know, in, in the PR before it's checked in so on and continuously tested, uh, despite this, backlogs keep growing.
So one of the things we did with our A SPM, you and I talked about Enzo, and it was all about, you know, bringing a broader context on the application and bring that and, and the, you know, the risk context, not just, here's a vulnerability and you gotta fix it. It's critical. It's a high no, no, what's the risk to this app, right?
So now you're having a business dialogue between the DE or, and the security team. Uh, and that was the innovation. Now we're just taking that next step in that innovation.
What we are able to do today with sny is to say, look, here's how all the things came together in the package that got deployed, but once it's deployed, we don't have visibility, right? We sit in that production of that application, part of the environment. The clear need from a security professional's perspective is, I got all these other things in the runtime, uh, environment.
Don't build new tools for that. But can you bring that context to further prioritize? And that is the key problem that, um, we next wanted to tackle.
So Helio's ability to bring observability data to bring in what's running in the container, it allows us to further take that risk saying not only that certain issues that are super important and high risk score, make it into what you deployed, but it's actually being invoked. That function is in memory. That package is in memory.
What it does is it dials up the risk score, but it allows the security team is to take that back to the dial person saying, this is super important, and this is, it's not the 10,000 things that you need to fix. This is this one thing because of all these reasons, right? So it's all about, you know, shifting to this application centric and risk-based view.
Um, so that's, that's, you know, I, I threw a lot out there. Hopefully that helps and we can unpack it further in terms of how we're doing that. Who was taking the lead on this?
Because to your point, historically, cybersecurity people threw a bunch of vulnerabilities over the wall, developers looked at it, determined that the issue wasn't running in their application, in their production environment, or the app itself wasn't internet facing. So we've been talking about this DevSecOps thing forever and a day, but who's taking the lead and how much progress are we making That this is really, uh, uh, something that's top of the mind for that, uh, CISO and security, um, um, persona, uh, as I said, supply chain breaches, um, are becoming, you know, more and more pervasive. Uh, today, you, we go to the audit committee and explain, if you're a ciso, you know, any sized company, what are you doing about these things?
And that's really where a lot of pressure is coming into application security teams. So application security teams report into this, the chief security officers, uh, uh, uh, you know, uh, umbrella. At the same time, businesses are getting the push to move faster.
So you think about if you're the CTO, the head of engineering, the chief development officer, the push, especially with gen AI from the CEO, is increased productivity. How can you get more productivity, right? So there's this tension between risk production and productivity, and that's where the disconnect is.
So while the pressure is there from the CISOs team, um, to, to take care of risk, they have to do it in a way that they don't bring down productivity. And that's really what's going on here that's causing more of a need for solutions that are sitting in the kind of development world and solutions that are sitting purely in the security world to collaborate better. What will meet the connection between the observability data that we're starting to pull in and our efforts to apply AI to better secure these environments?
It, it, it's, uh, look, DA data is critical in, in applying ai. We have lots of layers of, uh, ai, we call it hybrid AI in detecting security issues in the applications. As software is being built, is this, you know, is there a vulnerability here?
So the ability to bring that data more and more data in allows the models to get, you know, tuned and tweaked over time too. Uh, the first step, as I said, is prioritization, right? So there, there's, uh, even in that risk goal, I mentioned the risk core.
There's a probabilistic of application of how do I, it's not just a pure, pure straight math equation. Um, so, so being able to look at these trends saying certain kinds of signals from observability or other security runtime, uh, you know, data is able to be more prevalent in, in predicting, uh, the risk patterns and certain other kinds are less, you know, less relevant. And that's something that is continuous and we've started doing that.
But, um, that's some of the, you know, uh, where, where things can go. A lot of times you hear developers complain about the cognitive load is too high. They, you know, we talk about shift left, but on a practical level, they don't have a lot of time to devote to patching and fixing vulnerabilities.
So how do we kinda address this issue ultimately without impacting developer productivity in a way that they'll resist? This is a key question, isn't it? I was just talking to, uh, you know, fortune 50, uh, platform engineering, uh, uh, CTO, uh, of the company this week.
And, uh, the number one goal for them is, uh, what are we doing, uh, to improve their productivity and the security tool landscape? Uh, and it's, you know, the answers are, it's hard to actually implement it, but the answers are very simple. Devs need context, devs need education.
Devs need the speed. So how quickly, how, you know, how soon are you telling them that this is a bad path to go? The sooner you tell them that the faster it is, right?
So it's like six times more expensive to fix something after the fact that it's in production does, it's, it's, you know, as extreme left as possible, right? Shift left is not just a buzzword. Like we're seeing that people are like, well, could you do something sooner than the id?
You know, what if, uh, while they're selecting the package, you know, today you go to a Google search for a new open source package, tomorrow you're probably gonna do it in the ai. So those are, those are the things that, you know, we're continuously, we have done a lot, but we're continuously doing that. Automation is the next part.
So how do I actually, great, I get the context. I know it needs to be fixed. Can you make it easy, right?
So we have something called a fixed pr. You automatically open a pull request, the dev can just click enter, accept it, review it. Uh, but could we, we get to a point where using AI, and you know, this is our deep code AI engine.
We call it deep code AI fix, that's something that we introduced for first party code. So whether it offers is typing it or a tool like a co-pilot or code whisperer duet, other ones that are there lots of code generating tools using ai, whether they are producing, it doesn't matter when that code is entering production, it can I get to a point where I can get a security tested fix? 'cause all these tools, you know, there's a lot of hallucination, just the nature of how, how these tools are.
So create a fix, find the issue, human or ai, and then just automate it. Could it get autonomous? Is it gonna be good enough that I don't even have to have the human in the loop?
I trust the system so much that I'm able to generate autonomous fixes that are security tested. So this is where things are going. Uh, Mike, it's really a huge focus for us, and this is where context, right?
Going back to Helios and, you know, our app risk product that we just launched, uh, that's what we are trying to do, right? We're trying to scale the shift left DevSecOps adoption, uh, by having this application centric risk-based and constant context, context exchange between the left and the right. Um, can do you get the application context if you're the developer?
No. When you're building code, you get the micro, you know, service context. If, if you are in production, you have the full context.
So that context from the right to the left, the actual dev context, back from the left to the right saying, how did this app come together in production? And it's just a matter of, you know, having these kind of, you know, production context, dev context, application context and the, and how do you make it easy? How do you make it scalable?
How do you do it in an environment that has hundreds of thousands of repositories? You know, we're deployed in some of the, you know, the largest companies in the world. These are gigantic dev houses with lots of apps.
So doing it at that kind of enterprise scale and in an enterprise trusted manner, that's, that's really what we're focused on. Um, that's what we launched our app risk, um, late last year. And, um, this is where Helios will plug in as a capability, um, to further enhance that.
What are you seeing organizations that are succeeding at this doing well? What do they kinda do for best practices or get started? Or what's something that everybody else can learn from?
Well, I think the, the, the leading organizations are using adoption of gen ai because this is something that Dev wants and the business wants to further shift left security. So they might have had tools like NY in there, but they're not shifted far enough. And some of these companies have just made it very easy.
You want this tool, you know, this new cool gen AI tool, you are going to deploy this as left as possible. This is your guardrail. Um, and this is kind of that, you know, whole carrot and stake approach.
You might think trust, but verify whatever, you know, you want to think about. Um, they're using the, um, so you know, this is the fastest shift maybe since the internet in terms of a lot of companies, right? Um, especially large companies haven't seen technology shift so fast.
That's the big trend I'm seeing is use this rather than fight it, use it as a positive to do the things that a lot of times security teams have always tried to get this adoption and interest. Now they have a reason and they have a carrot to offer. That's one of the big things I would say.
All right, folks, you heard it here. There's a big difference between just shifting accountability and responsibility left and actually making it possible for somebody to live up to those expectations. Hey, Manoj, thanks for being on the show.
Thanks, Mike. Great to talk always. All right, and back to you guys in the studio.