Software Bill of Materials API – Chris Wysopal, Veracode
Chris and Alan discuss Veracode’s Software Bill of Materials (SBOM) API that makes it easier to provide visibility for developers when using third party components.
Transcript
This is Textron TV. Hey everyone, welcome back to techstrong TV really happy to be joined by my friend Chris suisopel here. Chris doesn't need an introduction to our audiences.
He's probably been on here at least a dozen times, but beyond Tech shark TV. Chris's one of the original kind of rock stars and security dating back to his well his early early days, but he's really not that old. Oh, I'm pretty old lady.
Go there. Yeah, we're all getting older Chris. We're going to tell you.
But anyway, hey, man, welcome. I hope all is well with you things are good. It's a great to be here talking with you again.
Yeah, and you know, I neglected one of the co-founders of varicote again, one of the Pioneers in appsac and and what would they do and even before varicode? Well, I'm during a bike. I've got truly getting.
Oh, that's good. Yes from there and a bunch of other stuff. So Chris.
Before we jump into what we wanted you talk about today. Wanted to just kind of ask, you know, what's happening in varicode if there's any kind of updates or anything you want to share with the audience. Yeah, sure.
So I mean some of the recent stuff is, you know, we have you know enhanced our SBOM apis. So, you know, you can you can query all the s bombs you've generated across all your applications with an easy easy to use API call makes it nice and easy to manage and integrated into other s-bomb Solutions and and I think just just yesterday. We we announced our container security.
Scanning support, you know, we've scanned containers for open source components from the application that would be in the container which is a partial solution. But now we've we've rounded it out and we scan all the different layers of the container for open source. We scan for continued configuration issues, like kubernetes configuration and other other infrastructures code configuration, and we look for secrets that you may not want to have exposed in your container.
So we're pretty excited about that because it's key part of you know, Cloud native app SEC you have to be able to scan containers. So we're doing that. Look Cloud native.
I was telling someone on our team today. You know, I I managed as a figurehead our webinar program and so I tend to look at a list of all the webinars and all the registrations. And it's it really kind of jumped out at me that all of the cloud native Cloud native security.
kubernetes related webinars are some of our biggest Drugs great in terms of registrations. It's because it's new right? So everyone has to learn about it.
Like the developers are always, you know, a couple years ahead of the security people like they figure this stuff out. They start building they start deploying and the security teams like what's going on here. You're deploying containers.
How do I even I don't know what's in there. How do I secure that thing that you're using? So we're always playing catch up.
I feel in in the security space the developers are always ahead. But you know that makes sense. Right not.
All Technologies are gonna get traction, right? Not every not every technology. Someone events is gonna be used in a widespread way.
So people are gonna build solutions for every single way. Someone actually build AppSec. I don't know how many different languages of come and gone like you don't really hear about Ruby AppSec anymore right for a while.
They would grow it was the new rails. Yeah. I mean the is Is and it goes to the nature of the security business is we can't afford to get too far out ahead of our skis without wasting cycles and we don't have the Cycles to waste.
Right on something that's not going to pan out. Frankly. I mean that's what I have to do managing, you know, an engineering capability at varicote is like we have so many Engineers.
What what are we going to build? Right? What is what is gonna make the most impact for for the you know, the widest range of our customers and you know, there's a there's a million little Frameworks out there little languages out there different apis, but you have to pick the ones that are the most widespread.
Absolutely, you know look even taking it up a level to the whole opsec Space, you know for a long time last year the year before Chris a common thing I heard was yeah. Oh watch top 10 doesn't change. It's the same stuff over and over again and AppSec is stale and Abstract, you know is not but you know what?
Moms, you mentioned containers security you mentioned API security you mentioned. Yeah. These are all kind of New Frontiers within AppSec that the same old.
Same old isn't going to cut it. Right. No and absolutely some yeah.
No the way that AppSec are being built is constantly changing, you know, the language has changed slowly but the way the architecture of the AppSec changes more quickly because someone invents a new technology people want to take advantage of it. So, you know microservices is another one we have to secure microservices based applications. So you got a lot of different pieces a lot of different processes communicating with each other each over api's each one needs authenticate and and encrypt its connections and essentially protect itself, right and that that's that's a new paradigm, too.
So I feel like there's a lot of exciting things happening in AppSec. They're both certainly is but let's let's Circle back to ass pumps. So I I got to admit I'm a little surprised to hear that you're this far along with with being able to do this because my fear was that like everyone was gonna go out and build their own ass bomb format their own that'SBOM language their own that'SBOM.
You know syntax and that we would have a NetSpend Tower of Babel from Babel for a while where my SBOM is not compatible with your ass bomb and you know, how many SBOM readers do I need? It? Sounds like we've made progress here though.
Yes, so it it happened actually over a long period of time I think maybe going back like four years with the ntia which is part of the Department of Commerce having a project to standardize about how people are going to communicate bills of materials for software and you know that that kind of went along puttered along for a slow pace and people thought it was you know, it is eventually going to get here and then it came on us really quickly with Biden's executive order from you know, about little over a year ago with the cybersecurity executive order saying, you know Government, you know software customers should be requesting s bombs from there from from their suppliers and suppliers need to be able to deliver an s-bomb and that that's sort of like making it a requirement kicked everything into high gear and we had customers coming to us that sold into the federal government saying, you know, you need to support this, you know, we know you're scanning or open source, you're finding vulnerabilities and open source, but we have to be able to communicate to our customers now. What what we're doing so we want s-bomb support so we came out with s-bomb support earlier this year, you know, as far as the Tower of Babel goes, you know, we picked one format to start with we figured we're going to support all the ways that you know, people are going to be using it but we picked the one that our customers said that they wanted and made the most sense for them, which was the Cyclone DX format. There is another format that is acceptable that nist has decided is an acceptable format for the government to receive this information.
And then that's the spdx format. So we we have two Um, you know two is better than a lot. It's it's kind of painful that it's not a single standard but I think most products that are dealing with s-bombs will be able to create both formats and receive both formats.
And you know, even though they're not 100% you can't convert perfectly 100% from one to the other. They're pretty close and it's a lot better than sort of VHS and betamax, right where you have a physical difference in format. It's software so you can convert easily.
It's not, you know converting betamax stuff to VHS would require a lot of hardware. So Chris, I don't want to make you feel a little bit. A lot of people out here probably don't even know what I'm talking about.
Yes. Those are video tape form, but I do I do don't worry. I was this thing called video tape before the DVD and people are like what's a DVD?
Yeah, my son my son found found the whole concept of this optical disc and a CD and he's 14. He's not he's not that young. He found this fascinating.
He's like, wow, you can actually put data on to a physical device. Yeah. Yeah.
He's like I want to burn CDs So we when we moved about a year ago we moved and I actually found two DVD burners like portable DVD burners. I forgot I had them and I showed them to my son as well. And I was like, you know, we could record stuff on here and he's like, yeah, but Dad, where are we gonna play it?
Yeah, like well, yeah, that is a problem. That's a problem, but it's good to exactly capability. Crazy, but yes, but it we're talking.
You know, we say datamax VHS talking about incompatible formats. And of course Sony had the betamax format. It was probably a superior.
That's a form. That's what people say. Yes.
But it lost because the VHS Consortium had better marketing much like Windows and os2 to show you how old I am exactly. It's about marketing. Really.
Yeah, I loved os2. Anyway, let's talk more about ant farms, though. Can I be real with you for second, Chris?
Here's my fear. That that's bombs become. Our equivalent of the tags on mattresses and pillows that they say Do not remove it's a federal offense or whatever but no one pays attention to that.
Get people to kind of use them and pay attention to them. Yeah, so, um, I think this sort of a whole hierarchy of different usages of s-bombs. I mean, I think the way it was envisioned was a very sophisticated customer like say like a healthcare chain or something like that which has a big security team and it's sophisticated can can manage Um, you know, when new vulnerabilities and open source come out, they can really manage and understand where they're where they have products at risk where they need to talk to vendors about those products at risk and it allows the, you know, the consumer of Technology a sophisticated consumer to better to better manage their the risk coming from vendors.
And this is something that is, you know, been growing over the last several years, you know back, you know, 20 years ago. There was no open source risk problem. Right?
Like Harley any open source was used so it wasn't a big problem. Now we see that 97% of a Java application is open source libraries. If you count by lines of code not by code executed and we can talk a little bit about that but by lines of code, it's it's it's the vast majority of code today is open source, and there's a lot of risk in there that that is personally changing as new vulnerabilities are found in this new known vulnerabilities and you know consumers should should be able to manage that they should be able to demand that against their vendors, but the reality is You know a lot of consumers, you know, you know even even a small Bank maybe or a small Enterprise, you know, they don't have the capability to really manage.
Their the s-bombs that that vendors may give them if they asked for it. So I think on the low end though, there is some benefit if a vendor has an s-bomb and can deliver an s-bomb to you that says something about their development process that they know what's in their code. They're likely managing the vulnerabilities in that if they're willing to expose you to you what versions they're using just like a manual penetration test.
No one hands a manual penetration test to a customer that has high in critical vulnerabilities in it, right? They fix the problems that that that the testing company found and get them to retest and show a clean bill of health. That's a good thing because it shows that they fix things that were found and they're looking for things with manual testing I think on so on the low end I think SBOM can serve the same purpose.
It just shows evidence that the vendor has control of the open source, they're using and they're managing the risk in it. actually, let's talk specifically about Other code as far more free now, you know, I think we've done a good job with sort of laying at that farm landscape if you will. What exactly are you guys doing here?
Yeah, so what we're doing is we're able to package up in the s-bomb the Cyclone DX format the list of components and the versions that that that is in an application, right? So in an application, you know a Java War file or something something that you would deliver to a customer. You you can also deliver alongside that and s-bomb in a file format that you know, they can then consume we can talk a little bit about how they're going to consume this but we can do that.
The other thing we can do is we we have this API and policies so that the software, you know Creator whether it's an Enterprise creating software for themselves or a vendor that's going to ship software can manage all the open source across all the different applications. They're creating. So let's take a You know take a bank.
For example, they have you say let's say they have 500 applications that they build for internal use if when a new vulnerability comes out and something for log4j. They need to understand where they have log4j where they have the vulnerable version. And then manage the process of fixing it.
So if you if you if you have s-bombs, then you can look across your whole portfolio and understand where where you have that where you have that risk. So, you know part of the SBOM idea is transparency to you know to a customer but the other part of it is managing your own internal, you know, open source risk and it can also be licensed risk, too you could you could say hey wait a minute this this license isn't acceptable to the way we're deploying this software or we're using this software. So I need to understand what licenses are used.
So that's another part. Of how s-bombs can be used. Absolutely.
Chris it the rare code that's from Solutions are available today. Yes, they're available today all of our software composition analysis customers, which is you know, the technology used to understand what open source you're using. All those customers can generate an s-bomb file.
So they can generate an s-bomb on the command line. They can call an API and and they can call an API to get it as long as we've Analyzed that application with with our sea product that SBOM it is available. Another interesting thing that we actually launched I should have mentioned.
This is we've really been beefing up our IDE. So our IDE plugins allow the developer to actually just point at a an open source package a library that they want to use and we can do software composition analysis on we can identify what it is what version it is. Tell them what vulnerabilities are in that version perhaps recommend a different version if there are vulnerabilities and generate an SBOM all from within the IDE so you can think of this as the security team managing risk across, you know, the Enterprise across a you know, an application security platform, but the other way Think about it is, you know, and you want the developer to make good choices because the developer is selecting what open source they're using and you know, it'd be nice if the developer was, you know empowered.
To understand the risk in there and select other libraries rather than it show up in you know, a dashboard for you know, the security team at a later date and they have to say hey, wait a minute you need to fix this. So we're trying to shift, you know, the management of what open source you're using to the left. So developers can be empowered to understand the risk in their open source.
Absolutely, excellent stuff. Hey Chris, I want to thank you for coming on. We're we're overtime.
Anyway, I want to mention that you know, we recorded this by the time you're watching this out there the Xbox talks available. Now the container security functionality that Chris mentioned it'll be available at varicode and probably in the next day or two. We'll have a follow-up with varicote.
On the container Security Solutions as well. So stay tuned for that Chris. I don't know.
Well, I'll definitely see it RSA but that's next April. But we'll be at Cube card. I don't know if you guys are heading up that way.
Around I don't even know I'm not going to kubecon. I am going to AWS re:invent we invite so right after if you're there maybe there in Vegas, but that's still done that great seeing you be well be safe and thanks so much. Thanks Alice great talking with you.
com v e r a c o d e To go check out all of the stuff Chris told us about we're going to take a break here on texture. We'll be right back.