State of the Software Supply Chain – Stephen Magill, Sonatype
Dr. Stephen Magill discusses the key findings from Sonatype’s 8th Annual State of the Software Supply Chain Report. Over the past year, Sonatype studied dependency update patterns for thousands of open source projects, analyzed hundreds of survey responses, and took a critical look at commonly-held beliefs about effectively managing security risk.
Transcript
This is texturing TV. Hey everyone, welcome back to techstrung TV. Our next guest this morning is Stephen McGill.
Steven is with sonatype. Well, he's gonna tell you more Stephen. Why don't you give him your background?
Welcome? Yeah. Thank you.
I'm happy to be here. Thanks for having me. So yeah, I'm with sonatype.
I'm the VP of product Innovation here, which is a great position. I love it. I get to sort of see what we're working on contribute to that next generation of products and product features.
And yeah, there's been you know, a lot of exciting new developments in software supply chain. So sonotypes Focus has a traditionally been on software supply chain open source risk management. How do you make sure that you can use open source as a foundation for your applications and be confident in the security of those applications and we'll we can talk about this more as part of our discussion today about our reason research, but there's been a huge increase in new types of software as a play chain attacks.
And so developing technology to address those new challenges that's been a big focus of ours and and then looking at first party code scanning scanning the code you're Developers. Are writing and getting the xenotype lift product out there as a web service that you can use and GitHub to scan your code and find issues both with open source, and with the code that you're writing. That's that's been another cool development.
So a lot of exciting stuff happening. Absolutely, I mean and for those out there who may or may not be familiar with this owner type. What's really interesting is the the company kind of got started right as the keepers of the of the notifications.
Nexus yeah repository which is probably the you know single largest biggest repository for job or Scratching that's right. Yeah, and we're the still the maintainers of Maven Central which is the primary Java software repository for open source, and and that's actually really interesting source of data about the open source community and how they manage risk and so I can I can get into some of that as well. Absolutely Steven.
I feel like we would be you know. Not telling the whole story if we didn't also say that you had joint Zone to type as a result of an acquisition from a company that you found it. That's right.
Yeah. I found it a company called Muse Dev that built a software analysis tooling and in particular the integration of that into the development process so that you can get feedback from tools as part of code review and just get get issues with the code fixed during development and it's sort of low very low effort way. And yeah, we were acquired by sonotype a couple years ago that's been really exciting that technology went into the sonotype lift product that I mentioned before and and then now I get to design the next the next big thing here at Center time.
Just great. Absolutely. All right, I think we've done enough setting the plate, you know, one of the Interesting.
Well sonotype is also the folks behind all day devops, which recently took place the largest kind of devops showing in terms of I think 24 hours right around the world and you met a people but in addition to all day devops sonotype has historically put out their kind of state of Security and open source security and so forth and I think that's what we're going to talk about today, right? That's right. Yeah, we recently published the eighth state of the software supply chain report.
I've been involved in that report since 2019 and it's just yeah, it's always a really interesting process. We like each year. We try and find new sources of data interesting new analyzes we can do with the goal of shedding some light on best practices.
What what works and what doesn't in terms of Open Source risk management and secure software development. And so it's it's exciting. It's always a rush, you know, trying to get everything together and out the door, but it's out there and we're super excited to be talking about it.
Absolutely. So let's jump into it what you know, I was like, yes people about reports seeming there's usually at least three big bullets. That we want people to take out of a report.
Let's hear the three big ones for this report. Yeah. Yeah.
So I think one is the huge increase in what we're we call Next Generation software supply chain attacks. So this is You know traditionally it was all about attackers finding vulnerabilities that are sort of sitting there latent, you know in open source software. No one's discovered them yet.
Someone notices them and then starts exploiting them. That's like what used to happen that still happens a lot but more and more we're seeing a hackers try and inject vulnerabilities directly into open source gain, the trust of Open Source developers submit some helpful changes and then sneak, you know, a malicious commit in there or take advantage of repository Management systems and and publish packages that have names very close to legitimate packages to take advantage of developers, you know type having typos in there in their little materials. And so those types of attacks have increased 742% year over year for the last three years.
So that's if you go back at the last three years and you look at an average it over time 742% a year, which is just a ridiculous growth rate and was really shows that this is a soft spot right in our software Supply chains and hackers have keyed in on this. It's just that's a crazy number man. Crazy, yeah, and you know what when you think about it, it's a relatively simple.
Kind of little thing to do right? I mean you don't have to be a master hacker. Right to set up, you know.
Yeah, it's in yeah, it's simple from an attack perspective and it's you know, it's difficult to defend against it's been a soft spot for a while. And you know, we've we've released some technology to help with that. We have the firewall system which sort of sits at the at the periphery of your of your software development organization and can quarantine packages they come in if it looks like there have been malicious commits, you know, there's some some AI behind that and so, you know, there are solutions out there, but it's it's something to be aware of because it's it's really a new development.
mmm Right. That's number one. What else we have?
Yeah. So number two I would say is That there's the the issue with open source vulnerability is really at this point consumption side problem. So, you know, there's this question of like it open source, you know, there's all these vulnerabilities and open source.
It sneaks into Enterprise applications. Is it because it open source developers just aren't taking security seriously or is it because there's something about our usage of Open Source that is you know, bringing vulnerability in and we looked at a lot of data this year from Maven Central, you know, so seeing how are people consuming products, you know, which which versions are they using and then and what we did is we did an analysis to say. 5 million vulnerable.
2 billion vulnerable downloads per month. So there's a huge amount of vulnerable software being consumed, but it turns out 96% of those downloads if you look at that project, there's a newer version available that fixes that vulnerability so someone downloaded a vulnerable version, but they didn't have to right so open source producers. They're putting the patches out there, right?
They're fixing these security issues. We're just not great at noticing when we have a vulnerable version and moving to something to something better. Yeah.
Yes Stephen. I remember seeing this back with the struts to And equif the Equifax hack, you know, which was based on a vulnerable version of struts too. And I you might have been involved with it at that point already was Derek and and weeks and some other folks.
And yeah, and what was interesting was six to eight months after the attack was public publicized and you know people knew about it. The amount of people who were still downloading the vulnerable version of struts too versus the new version which had been patched. Was phenomenal.
I forgot what the number was but like tens of thousands of people a month were still downloading it. Oh, yeah, and we see the same thing with log4j so log for J was the you know, huge security event of 2022 or 20. I guess it was 21, right December last year and we still see a huge amount of vulnerable downloads of log4j.
So it's over 30% of downloads of log4j from even Central are still downloads of the vulnerable version. It's just not smack. Yeah.
Yeah really is when you think like what can we do? Yeah, I mean so tooling does help so we we did an analysis to see you know people who are using at software composition analysis tooling like sonotype lifecycle. 6% better management of risk if you're using this Tooling in the right way and so like log4j, you know, you see log4j remediation rates much higher much closer to 100% for people using those tools, but there's still you know, it's still uneven right?
Let's it's remarkable how much of an impact media attention has on remediation rate. So if you look at log4j versus even spring shell which got a lot of press but not as much as log for Jay. The remediation rates are quite different.
Yeah, someone who maybe isn't a Savvy into how this all works. In our audiences sitting here saying why do they even have the vulnerable additions up there available for download? Yeah.
Yeah, we get that right why not just block it at the source. Why even you know, do you take down the vulnerable versions? You know the problem there is it well, it would break a lot of people's build pipelines.
You know, there are there are cases where maybe it's okay to be using one of these older versions. It's an internal application. It's firewalled off it, you know, you have some other mitigation in place.
There's sort of this implicit contract with repositories like Maven Central that like, we'll host the software. It'll always be available you can count on it, you know, it's not gonna break your your software development process. It certainly is reasonable at an organization level to say we're okay breaking the software development process for people using vulnerable versions.
And so, you know, there are products you can put in place. There are tools that will that will do that that will let you block a vulnerable versions and just not even not even allow them into the build process and that can be an effective management strategy. Yeah fair enough.
All right on to number three. yeah, so item three is that there's there's when you look at the Quality metrics, so we took we did sort of a deep dive on you know, how can you choose better components? Right?
Because I mentioned like there is still vulnerability creeping into Enterprise applications. There's all these vulnerable downloads and you know, that's not surprising because when you look at the challenge in staying up to date with software, there's on average 1500 updates to dependencies of an application per year, right? The average application has 15 dependencies.
There's 10 or sorry has 150 dependencies. There's 10 releases per dependency. So 1500 per year.
You have to keep track of that's just Monument a Monumental task, right? So we wondered Could you do better by choosing better components? You know, could you make it less likely that those 1500 releases?
Some of them have security issues you have to deal with and so we took a look at what's out there in terms of safety ratings and you know do those correlate with vulnerability do we actually see a connection there and we didn't see a connection between the common top level metrics and and vulnerability but we were able to train a model using machine learning based on the open ssf scorecard data. So this is a project from the Linux Foundation that really injects transparency into the development practices of the open source community. So it says, you know here these this project is doing code review their fuzz testing their software.
They are do issuing signed releases this other project, you know isn't doing that yet, but maybe they have security policy in place. So they're starting to take steps towards secure software development. And so it lets you let's see what practices these projects are using.
And it turns out that you know with a powerful enough model on top of that you can actually get a metric that corresponds very closely to vulnerability of these projects. And so we actually released that recently on Maven Central and on OSS index as the sonotype safety rating and that's out there, you know, you can check it out for for popular projects. It's a work in progress.
We're still working on improving that we want to make it a community effort. You know, how can we develop better metrics that measure project quality and so, you know welcome feedback on on that metric. Excellent.
Excellent. Stephen. I always what did what did you think is the most surprising finding in this year's report?
Yeah, I think The most surprising finding for me is related to point number two that I just mentioned of, you know, the issue with security being on the consumption side. So we did a survey of you know, how well do people think they're doing right? I mentioned what the data shows there's a whole lot of vulnerable projects being downloaded but the perception on the consumption side in terms of self-reported data is that people are actually doing great that we're really great at managing vulnerability great at managing risk.
And what was really interesting about that result was management was more likely to say that the organization could respond quickly to new vulnerabilities versus when you look at just the developer responses. They were they were much more skeptical and so that was surprising and worrisome. I would say because you know this management level that's who's security but right right.
They're making the decisions about what to invest in where to focus and yeah, you need accurate false sense of security is not good for anyone. especially in security You know what? We're almost done on time Stephen for people who want to be able to, you know, grab the report and take a look at it a little deeper at their Leisure.
How can they do? So yeah just search for sonotype state of the software supply chain report. It'll come up, you know, it's it's not behind a paywall or anything you just click through and view it it's all web-based and there's interactive graphs and stuff.
So definitely check it out. By all means Hey Stephen, let's not wait a couple years for you to come back on here. Definitely.
We'll see you soon. This is fun. Thank you.
Alrighty, say hello to all our friends. It's on the type, especially Katie. And we'll we'll be in touch Steven McGill here from sonotype on Textron TV.
We're gonna take a break. We'll be right back.