State of Application Security – Jeff Williams, Contrast Security
Alan and Jeff discuss the current state and trends of application security as well as the latest news from Contrast Security.
Transcript
This is texturing TV. Hey everyone, welcome back here on techstroke TV. I'm really happy to be joined by my friend Jeff Williams.
We haven't had Jeff on in way too long probably because you know what at one time Jeff was the single voice for contrast security, but as they've grown so have there voices and they you know, we've had Larry, of course Larry marcher only on many times and several of the other contests folks, but it's great to have Jeff back Jeff. How are you? I'm good Ellen.
Good to see you again. Good to see you. You know, Jeff I I guess.
I mean I take you for granted people know who Jeff Williams are they may not why don't we why don't we start that Jeff? We're give them a little bit of the Jeff Williams story. Yes, sir.
So, I'm I'm the CTO and co-founder at contrast security. We offer a app set platform that will support a whole apps that program from development all the way through production. I've been in absec for over 20 years now, I hope to start oh wasp.
I was the global chair there for the first 10 years. I wrote the US top 10 and led a bunch of other open source projects that are pretty popular and I worked as a consultant in abstract for many years. So I had the privilege of working on some of the world's most critical applications and doing the security doing both architecture as well as testing and Pen testing and code review.
So I've It's interesting to have that perspective. I've seen so many apps and so many different companies that I just feel like I really understand, you know the problems in our software. Absolutely, and that's great Jeff.
You know while we're out of people may not be familiar with contract security. We might as well give them a little of that too before we jump into what we want to talk about. Yes, so, you know look most of the tools and application security came out in the early 2000s.
There's static analysis tools Dynamic analysis tools web app firewalls. They're all kind of what I call outside in tools. They operate without the full context of what's going on inside the running application.
So we had a simple Insight eight years ago, when we founded contrast we said if we could get inside the running application like an APM tool like a New Relic or an app Dynamics for performance, but we'll do that same thing for security. We said we could be way more accurate. We could be a much more natural part of the software development process so we can we can work at devops speed in context and provide really accurate data about whether you have vulnerabilities whether you have Library problems or whether you're being attacked in production, we can do all of that with this this one approach instead.
So instead of having to buy, you know, four or five different apps that tools and build a team around each. Of them we can help you add asset to your whole program with the you know, sort of one simple integration. Absolutely and been very successful at it.
So for folks out here if you haven't guessed it yet or you having surmised from what Jeff's told you look you got one of the guy through really helps start to Modern app SEC movement and and contrast which company he co-founded that's quickly become a leader in in the in the app sax Space by not only offering as Jeff says the outside in kind of use stuff the typical stuff that a lot of folks and have sex are doing but by also being Innovative and creative and giving different views and different insights and different Technologies to help you with, you know, all faces of application security. So Jeff with all that kind of background. Yeah.
You know as we sit here now at black cat was I guess a week or two ago and was of course a lot of announcements and news coming out of that. But if you went on my share with our readers a little bit of the state of the market a little bit of the state of the industry the state of the technology. Yeah around apps like from your Vantage Point.
Yes, so I've been doing this a long time and you know, the everyone always thinks apps like is really important. They're like, yeah, we want to get the code security we get the library secure but frankly for you know, many years. It seemed a little stagnant in absec because it wasn't a lot of innovation but I'm actually super excited right now because of what's going on in knapsack market.
So I think the executive order the Cyber Security executive order that came out was really exciting. You should everyone should read it. It's only three pages long and it's a really good summary of kind of the problems and the software Market that are leading to security problems.
And so they they squarely put it on a market problem and economic problem in the market and they did something about it. They said hey, We've got a problem in the market that's based on people not understanding what security is in software. It's difficult to know I bet you Bank online, right?
Well, what's in that software that you're trusting your finances to what do you know about it? Do you know who wrote it or who tested it or what tools they used or whether it has known vulnerabilities. Do you know that it's better than some other bank?
Probably none of that. Right? Right, but I believe it's a fundamental right?
You should have the right to know about the security the software that you're trusting everything important in your life to and so that's the problem that the EO focuses on and most people the first thing they'll see in the EO is ask bombs, right? They're like everybody's got to produce an estimate if you want to sell to the federal government. Okay, that's cool.
That's a little bit of transparency. I think it's like a baby step but it's actually really driven some change in the market. Yeah, I think before our call you said open sources the Beating Heart of the suffering industry and I think you're right.
It's really important. And so what it's done is it's it's shyness Spotlight on open source, and people are starting to realize. Wow.
I got a lot of open source and a lot of vulnerable open source and What's really interesting I think is that they're starting to pull back the covers a little bit. They're starting to realize. Hey, you know what only 38% of the open source in my apps is ever even loaded into memory.
It's not a tackle at all. And with the right tools like contrast you can see that and so you can focus on pieces that are that are truly attackable and then I Studies have been said only of only 15% is actually exploitable. So a tiny percentage is actually exploitable.
So the trick is like zooming in on that. So that's s bombs. Very exciting.
I think it's me put a lot of interest in the market. So that's all good, but it's kind of just the first step the ego goes further. It says hey, we're gonna direct missed to create a minimum standard for application security tendon testing.
That seems like a good thing, right? Yeah, and it's pretty good. It says you got to do a little threat model.
You got to test what defenses your threat model says you need to have you got to produce evidence that you tested on and you got to fix vulnerabilities that you found in the software. That's a big step and you know, I know hundreds of companies that they run abstract testing tools, they generate a big pile of vulnerabilities. They stick them in vulnerability management system and they sit there.
The average time to fix abstract vulnerability if you're using static analysis tools is 290 dates. Wow, that's just crazy long. We need that to be a week or less.
And we can do it with better tools that fit better with modern devops. We can do that for sure. You know and I'm super excited about this because I've been talking about this since the early 2000s is the idea of software security labels.
It's a way of intervening in the software Market. Just like the way that you have labels on restaurants in New York City. You know, you don't want to go into something.
That's a c or a d right you go to restaurants that have an A on the window. Well, that's what we can do for software if you you know, and they're there is already a labeling program in Singapore and Finland for Internet of Things devices. Mm-hmm.
We're doing something similar here for iot as well as for Consumer software, including websites and things like that. So think that could be really really powerful. It could absolutely change the market because you know the apps that industry has been kind of fighting against the market, right?
And you'll never win the market always wins. So we got to fix the market. So that's what the EO does and I'm super excited about it.
I was too and I I still continue to be you know, Jeff. I I think of it this way the s-bomb stuff to me is sort of like the ingredients. Panel mandated for food right?
I want to know what what what's in this what what do the ingredients in this processed food? I bought or food. But then I just want to know how many calories it has and I want to know, you know, the analysis of carbs to protein to what have you right?
I want to know more about that quality if you will. And and to me that's what the EOS really about is it's giving me that same sort of insight into my software if I want it. I mean Well before I get into that one second, look, we always b**** about the government being bloated and not knowing what end is up and being the last to find out and and just not conducive to Private Industry.
This is the case where they really came out and threw down the gauntlet. Yeah and say hey this is this is it and I haven't met many security people who say. Oh that's Ridiculous or that's wrong.
No, I think we all agree. It's right. I think the question is though.
We're consumers love the idea of the ingredients list on their food. They love being able to say how much carbs and protein and so forth. They love that Insight.
They love that transparency. Are people going to embrace their software the same way? So here's the interesting thing about that and I went back and studied a whole bunch of different labeling regimes over the years.
Including the fda's nutrition facts label and people did not like it when it came out. It was very poorly adopted and it took 20 years for people to really start reading those labels. But here's a cool thing is it doesn't really matter because almost instantly when they produced that producers of food.
It's the initial impact of these labels is not on consumers, even though it looks like it's for consumers. The initial impact is actually on software producers who their lawyers are not going to let them go to market with something that says like you have critical vulnerabilities and you know, actually this is going to kill you. Yeah doesn't start people from buying them but another story but the problem with ingredients labels.
Another problem is that with software the same list of ingredients could be used to make something that's fantastic software and it could be a complete disaster from a security perspective. So just because you have the ass mom doesn't really tell you anything about it has to be more than the ant farm so that's right. It has to be more and that's what we're pushing for.
So we'll get there. Cool talk to us a little without what else from where you sitting in in way of absec. Well, so I think that's going to affect everybody.
I think everybody's going to be pushed towards more transparency around their appset programs. I think companies should start now they should start you know thinking about how they would tell the world about their appset program and if they're ashamed of it, then they should take steps to fix it because pretty soon they're gonna be forced to disclose a lot more about how they build software so they kind of got to get ready. Okay.
I'd like to talk about API security a little bit. There's some new companies in the market related to API security. It's something that we do really well at contrast and it's interesting because I think the traditional approach is to appsec don't work that well on apis like SAS desk and Waf They're not great at it because apis are more complicated.
The protocols are more complicated. The Frameworks are more complicated. And so the outside in approach doesn't really work as well.
So I encourage folks to kind of look under the covers at the API security tools and if they're just repackaging like a desk and a laugh which is a what a bunch of them do right? They're like a Gateway and they package in sort of a laugh and a dashed in a Gateway and they say, hey, we'll test your apis. If you give us your open api's back or whatever.
It's it's pretty weak approach. And I really think what you want is you want to make sure that you've got great API testing you want to make sure it can test the libraries in your apis. You want to make sure that it can protect your apis from being attacked.
And kind of those those capabilities are something that you know the contrast technology that we work inside out on really really help with. Absolutely a lot of action in that space for a while because almost I mean more than half of the applications that we Monitor and protect that's you know hundreds of thousands of apps and apis more than half of them are apis. Most modern apps are like apis on the server side and Rich client stuff in the browser.
And so you really got to get your game straight on apis. I think there's a lot of work needs to be done there Jeff because I I think most organizations haven't even hit the threshold of knowing what it is. They have before they can even talk about is it secure protected whatever they don't even they don't even have A list of AP that the shadow apis there's all kinds of stuff.
I've been thinking about that recently because a lot of people really they they want to focus on inventory and Discovery and it is important but my concern is that if you if you order things like well first I got to get an inventory and then I'm gonna go start worrying about securing things. You'll never finish the inventory, right? It's constantly changing.
So I really think of it as as more like you really need three parallel threads and you should start them all running one is inventory and you should be continuously like, you know deploying technology to make sure that when new things get pushed out you bring them into the inventory and they become part of the program even Code and no code stuff like you want to make sure you absolutely there's so much of that out there not to anymore. So that's one thread. But at the same time you have to have a thread going that says hey for everything that I know about in my inventory.
I'm going to do security testing on it. And you can't wait or else you'll never get there. And then the last leg of the stool is runtime protection.
If you're deploying apps and apis without runtime protection these days you're nuts. There's yes. There's too many zero days.
There's too many new vulnerabilities in your your custom code. You need to have that runtime protection to help make that stuff unexploitable. And I'll give you a quick straight.
The only that's really like the only way that the security industry has ever really made progress is by strengthening platforms, you know, you talk about training developers and you know doing testing and all that like it's that's treating the symptoms. But if you want to really eliminate whole classes of vulnerabilities, then you need to make the platform stronger so that those vulnerabilities are impossible to create or impossible to exploit and that's what runtime protection does and it's very much like what happened in buffer overflows and kernel exploits back in the early 2000s. We had Colonel exploits all the time.
You remember that's yeah I do. Well, we introduced new technologies particularly aslr and debt. Yeah, I did execution prevention and those Technologies change the game made it much harder to exploit those those vulnerabilities and the colonel explains went down, you know, we don't hear about them very much anymore because of that that's what runtime protection does for the application layer.
That's what it does for the you know, your web apps and your web apis. It makes those vulnerable those vulnerabilities which are kind of be there. There's gonna be another one probably tomorrow.
in some library that everybody uses but you know our customers through log4 shell and spring for Shell. They were all safe. Yeah, we didn't we didn't have to deploy a new rule.
We protected against the fundamental classes of vulnerabilities expression language injection. Unsafety shieldization. Those are the flaws that those attacks and we make those very difficult to exploit if not impossible.
And so it's just cover so you can go back and fix those libraries, you know just gives you time to breathe and not have to have a fire drill. A great Jeff. I know we had one or two other things I wanted to hit but we're already overtime.
I'm afraid so I'm gonna need you to come back on. I mean we try to keep these to 15 minutes. I I think we're closer to 25 already.
It's okay what you know what talking shop? Yeah, do me a favor. Maybe I'll have our people talk to your folks.
Let's get you on in the next week or so it because I want to continue this conversation. Way of blatant plugging the you know, this is really important to me we have I think it's September 13th apsec API sect virtual event Larry Larry Montreal from contracts. We one of our keynote speakers.
I think he's first thing in the morning actually the first Speaker addition. She's a great speaker. You got to listen.
Yeah. He's fantastic check it out Jeff, but I'd like to have you before then to do another interview we can continue what's going on in the abstract world. I think that's very offering our code SEC tool, you know doing quick ahead.
No, I was gonna say next time we can talk about. All right, we'll come check out code SEC it's free and awesome for everybody static analysis sea and serverless Analysis. if another website Hey, this is only part one.
Jeff will be back for part two. We're going to start with code second free analysis though, but you don't have to wait for part two. You could go to contract security and fight.
Check it out right now, Jeff. We'll see you in about a week. Thanks, Alan.
Have a great day. All right, Jeff Williams contract security. We're going to take a break here on Tech strong.
We'll be right back.