Streamlining Vulnerability Management With SBOMs – Chris Hughes, Endor Labs
CISA published a new White Paper on software identification ecosystems to help facilitate better vulnerability management and broader, more effective use of software bills of materials (SBOMs). It’s requesting public comment through Dec 11. Chris Hughes with Endor Labs says it represents an ambitious goal to harmonize software identification and naming, but the requirements are complex to meet. He talks with Alan Shimel about how organizations can gain value from the paper, the top issues in vulnerability management, especially as it relates to OSS, and how to gain value from SBOMs.
Transcript
This is Textron tv. Hey everyone. Welcome back here to Textron tv.
Oh, we got our next guest here to, so talk to you about, it's actually, he, he, we were talking off camera. It's the first time he's appeared on Textron tv on the regular show, though we've met at RSA, he's a regular there. Let me introduce you to Chris Hughes.
He's the Chief Security Advisor at Indoor Labs. Hey Chris, welcome to Tech Truck tv. It's great to have you here.
Yeah, likewise. I'm excited to be here and chat and, uh, get a chance to join the show. Very cool.
So, you know what, Chris, I, we don't all, we don't interview a lot of chief security advisors, right. And, uh, we, we, we interview a lot of security people, but not a lot of chief security advisors, CSA, uh, why don't we, if, if you don't mind, let's start with kind. What, what, what's that role like, you know, how do you describe your role there and, and maybe a little bit of your background and journey that kind of prepared you for, for becoming a Chief Security advisor?
Yeah, I'll start with the background front. Uh, I've been in the cybersecurity community, uh, a little bit under 20 years. I started off active duty Air Force and then a federal government employee after that with the Navy doing cloud and DevSecOps, uh, with the Navy and their environments, and then also worked at the FedRAMP team.
If anyone heard of FedRAMP, I was, you know, one of those people who kind of criticized all the services coming through and critiqued them to ensure the Fed, you know, the government is, uh, comfortable using them from a security perspective. Uh, and then worked around different, you know, department of defense intelligence community and commercial entities around cloud and DevSecOps and software supply chain security. Uh, ended up co-founding a company of my own called Acquia, which is a cybersecurity, uh, services consulting company where I service the president and co-founder.
And then yeah, on the, uh, chief Security Advisor front. Uh, you know, I've been doing a lot of work around software supply chain security. I published a book with Wiley called Software Transparency, uh, last year, uh, which is kind of like one of the leading books out there in terms of sales on software supply chain, security, you know, digging into all aspects of the topic.
And, you know, came across a team of indoor labs here and really interested in the work that they were doing and the innovative approaches they were taking and joined them as a chief security advisor. Like you mentioned, I advise several companies, uh, but the key security advisor role is a bit more of an active participant. So, you know, obviously advising like a traditional advisor, but being a more involved, you know, participating in, in, in events like this, right.
Outreach with the industry, uh, product feedback, you know, in introducing to potential customers and prospects, uh, contributing to blogs, you know, being out in the community, engaging and so on. Uh, so definitely more of a, an active participant advisory role, I guess is a good way to put it. Excellent.
And look, you know, our audience, there's nothing to be ashamed of, but our audience probably hasn't heard, or is not many people are familiar with Indoor Labs. How, how would you describe kind of like what Indoors mission is and what they're about? Yeah.
You know, so this company, indoor Labs, plays in the software supply chain security space. You know, if you've been to RSA in the last year or two, you, you know, and, and Black Hat and so on, you inevitably saw many software supply chain companies, you know, sprouting up looking to tackle this challenge. Uh, but Indoor Labs comes at it from a unique perspective of integrating with developer workflows, uh, helping organizations get a handle around, you know, uh, how handle around how they're using open source software.
For example, we know open source software is being used tremendously. You know, 60 to 80% of modern code bases are open source software. Uh, but organizations don't have a lot of tools to make good selections around what open source software components to use.
Uh, so that helps facilitate that. And as well as, you know, we have a lot of noise when it comes to vulnerabilities. For example, uh, last year, you know, we saw over 20,000 CVEs in the national vulnerability database, but less than 5% of those are ever actually exploited or ever actually pose any risk to an organization.
Uh, so Indoor Labs helps on that front by, you know, providing context rich analysis and information in terms of is it known to be exploited? Is it likely to be exploited? Uh, using capabilities like reachability, uh, analysis to show you, you know, within your code, within your application, is this component or library, is it even reachable?
Is it something you need to be concerned with being exploited by a malicious actor? So kind of driving down, uh, that toil that we often, you know, we kind of throw a massive list onto a developer engineering team and tell 'em, Hey, uh, have at it. You can't go to production until you address this list.
Uh, you know, trying to help pro provide context around those findings and help maximize efficient use of resources basically, and help, you know, developers focus on what actually poses the most risk. Got it. And, and before we jump into today's kind of topic, Chris, um, people may be wanting to get more information on Indoor Labs.
Where can they go? Yeah, definitely check it out. ai.
You can go check it out the website there and get a lot of information. We have a lot of, uh, you know, blogs out there on various topics around software composition analysis, software supply chain security, sbo m uh, we also have a Lean AppSec, uh, event that we do that, you know, is done every quarter or so with a lot of great, you know, people both from the organization as well as industry speakers coming to participate in panels and discussions and, you know, so definitely give that a look. We have one coming up here early in the new year.
Uh, you'll find a lot of great information and discussions on there too. Excellent, man. Alright, now that we've got that outta the way, let, let's turn into, you know, kind of the topic we wanted to hit on today.
And, you know, I've been at security a long time myself, right? I don't know, 25 years, something like that, maybe more 28, whatever, long time. And, um, it's rare that the federal government, that the feds lead on a particular security time, unless we're talking like nerc, FERC or, you know, something that's very, you know, government specific or quasi government specific like that.
But when it comes to software, supply chain security and SBOs, you know, the federal government, I mean, current administration, you know, we're not getting into politics, but they, they've, they really planted a flag, right? And, and really csar is the, you know, the, the, the csar office is the, is the flag holder of that flag. They planted around, you know, taking software supply chain, serious software, supply chain security, seriously, you know, standardizing on SBOs and requiring SBOs with, with all the software you get, even, you know, beyond cso, even the recent SolarWinds kinda lawsuit with their CSO being named and everything, uh, it was from the SSEC shows that, you know, the current administration of Washington seems to be taking cyber pretty seriously, and they're, and they're willing to, you know, like Lee Iko used to say, right, lead follow or get out of the way they're willing to lead and they're willing to, you know, plant that flag out there.
In that vein, Cesar recently put out a, uh, a call for input. I forget what the official government term, it's been a long time since I sold to the fed space, but there's a, there's a word for it, a term they use, but they put out a, a, a, a call for input on software identification ecosystems. They even published a white paper, um, you know, saying that, Hey, this can help facilitate better vulnerability management, broader, more effective use of SBOs, et cetera.
Chris, you are an expert on it though, right? This is kinda your world, you know, help us here. What, what, what, what's this about?
Yeah, definitely. And I did wanna mention, you know, one thing I didn't mention in my introduction is I also serve as a cyber innovation fellow at cisa, uh, dealing with the okay. And, uh, software supply chain team.
So I don't speak on their behalf, but you know, I am involved there basically. Um, and, you know, so this, thank You for that. Yeah, absolutely.
This is, this was put out, you know, to kind of address the fact that, you know, software, uh, use, as you mentioned, has become, uh, massive. It's pervasive across every aspect of society. Everything from our consumer goods to our critical infrastructure.
National security systems are now powered by software. And as you said, the government's looking to lead in a lot of capacity capacities around, you know, software, supply chain security. Uh, so this paper looks at, you know, kind of the current state of the ecosystem around software identification, and I forget the exact quote, but there's a longstanding quote about, you know, software naming or software identification being one of the hardest things, right?
In computer science. Uh, so the paper takes a look, kind of the current ecosystem it touches on some of the existing identifiers, you know, things like, uh, common platform enumeration, CPE looks at SWD software identification tags, and then also package URL, for example. And it kind of points out the strengths and merits of each of those, as well as the drawbacks and challenges associated with each of them as well.
Uh, and it talks about, you know, how do we move forward as an ecosystem? Is it, you know, do we have kind of one identifier to rule them, rule them all? What would that look like?
Do we have a centralized model, a decentralized model? Do we keep using this kind of mix of different identifiers and how do we reconcile some of the challenges with doing that? And that's kinda the intent.
And they, they put it out as, as kind of an what's called an RFI, uh, a request for information. They take information from public and private sector entities, you know, commentary, looking for feedback, you know, from industry expertise, academia, you know, public sector expertise, et cetera. Uh, so that's what this is.
They put this out there, kind of laid out the, the landscape of the software naming ecosystem and, and talk about some of the challenges and, you know, what the future might look like. Absolutely. And now where, where are we on this kind of, kind of input cycle?
Um, yeah, would, go ahead. I'll say we're a bit ways through it now. I, you know, I forget the exact date of when the comments are due, but it's, uh, you know, coming in this coming weeks, uh, you know, I wanna say month or so roughly, if I, if I remember correctly.
Uh, but it's been out for a little bit here now. And, you know, we're starting to get some feedback from folks and, uh, you know, there's no silver bullet, you know, like, like Muchin, uh, the cybersecurity landscape. There's no single bullet or easy solution in many cases, but they are looking for, you know, some suggestions on how to reconcile some of the different naming and identification schemes we have in place, or how to address some of the challenges we have.
Uh, and you know, as we look at things like you talked about gas bomb software, build materials, uh, we're now seeing greater transparency around the components of software that we're using and where they exist in the environment and what the impacts are in terms of vulnerabilities and things like that. And without kind of a comprehensive naming scheme that's universally used, uh, it can pose a lot of problems of understanding like, is this, you know, piece of software I have, is it malicious? Is it vulnerable?
Is this even the same piece of software that someone else has that's identified with a different name, uh, you know, from a different entity? So it's a lot. It's very complicated ecosystem we have at the moment.
Yes, it is. Yes, it is. You know, I, I wanna make, so Chris, our audience, you know, they're DevOps, cyber cloud native digital transformation folks.
Not everyone out here I'm going to guess really understands what we mean when we say software identification ecosystem. Some of them may be ashamed to say, some of them may think they know, some of them may be ashamed to say they don't know. Some of them may think they know and they don't, and then, you know, some people do.
But if you wouldn't mind, how would you define software identification ecosystem? Yeah, like, you know, so we talked about, you know, the use and, and growth of software, you know, all over the place and needing to identify these, these software artifacts that we use in our enterprise, whether it's a product or a library or a component of some sort. Uh, you think about when you think about your vehicle, for example, it has a unique identifier, a vin, right?
A vehicle identification number. So, you know, this is this vehicle, right? When it comes to software, we need an approach that has a unique way to identify a software artifact.
And, you know, understanding like, well, what, what is this piece of software? Where did it originate from? You know, how do I kind of map it to external, uh, databases and, and identifiers around like vulnerabilities, for example.
Uh, you know, and, and it's trying to have a comprehensive approach to that if understanding from a software perspective, you know, each, uh, piece of software, each artifact being uniquely identified. And so that's what they're talking about is, you know, how do we uniquely identify these artifacts and ensure that we're talking about the same things, things if we're mapping to things like nist, national Vulnerability database, for example, how do we ensure we're talking the same language or about the same piece of software, uh, that way when it comes to asset inventory or vulnerability management or SBOs and things of that nature, how do we ensure we're actually talking about the same artifact, basically? Got it.
And you know, you, you, you mentioned it, so let, let's go there with it. So how did you know, this seems like it's hand in hand in lockstep with what we want to do in SBOs. How does software identification ecosystems play into the SBO kind of requirements that we're seeing or, you know, suggested requirements, whatever you wanna call it.
Yeah, I say two are definitely closely related. You know, SBO m uh, for folks that aren't familiar, I'm sure many folks are by now, but it's a nested inventory of, you know, software components within an application or piece of software. Uh, and so the naming, uh, you know, ecosystem is critical for that so that when you have that identified list of components, you have, you know, a unique identifier for each of those components.
And if someone else has an SBO m they are also speaking about the same components, using the same identifiers, for example. Uh, so as we see the industry kind of, uh, embrace, you know, this software transparency, uh, is, you know, are we talking about the same components within a piece of software within an SBO m for example, and then the SBO M is gonna show you, you know, potentially known vulnerabilities as well as we talked about with, uh, vulnerability databases like NVD or OSS Index and you know, OSV, et cetera. Uh, so our, you know, as we talk about the nested inventory of components, those components need to be identified uniquely.
Uh, so that's how this interlaces with the whole software naming ecosystem, Get it. Got it. Um, and then, you know, so one of the, and I don't mean to be negative Nelly here or anything, but one of the drawbacks of what we're seeing CISA and, and the White House directives and all of even the executive orders is a lot of what they're putting out there is recommendations.
But some people are saying, well, there's not really a lot of teeth behind it, and, um, maybe we don't need a lot of teeth. I don't know what, what's your opinion? I mean, you know, so great.
They're gonna in, they're going to, they, we put all this input in, we'll put out, C will come out with a recommendation. Is it, does it matter? Are people gonna feel obligated?
Yeah, I think, uh, you know, honestly, and like I said, I don't speak on behalf of CSA or the government, you know, despite being involved there, but you know, they've released, for example, the Secure by Design document recently that has gone on track Mm-Hmm. And a second edition of that in that document. It uses the word should tens of times, you know, tens of times.
Like there's a lot of things you should be doing, but it doesn't mean you have to do these things. It doesn't mean you must do these things. Uh, and I think what we're seeing the government try to do is use their purchasing power.
You know, they spend tens of billions of dollars every year on it. Uh, software services, et cetera, use their purchasing power to kind of drive systemic change across the ecosystem. Uh, they, they use a lot of language in the national cyber strategy, for example, about pushing the burden instead of on consumers and customers onto software suppliers and vendors, those best positioned to do something about it.
Uh, so they're trying to push those requirements into their contracts, into their federal acquisition regulations, et cetera, uh, to have organizations start to self attest, uh, to using secure software development practices, to providing artifacts like an SBO m in some cases. Uh, so trying to use that purchasing power to drive, you know, a should to a must or a will, uh, and hoping that it has kind of a, a caca impact across the ecosystem, given that they have so much purchasing power and so much sway. Uh, but the ultimate reality is, you know, there's, as it stands from the commercial perspective, you don't have to do some of these things, but as we see, see more regulat regulators get involved, like SEC for example, FCC, uh, cisa and others start to try to get involved in terms of, you know, pushing their, their sway and influence where they can, uh, things could change.
For example, we've seen efforts like NIST has their national cybersecurity, uh, labeling program, right? For IOT devices. If I'm a consumer and I see a device that's labeled AC versus a, maybe I make a decision with my wallet.
And I think voting with your wallet from a consumer per perspective can drive some of these, you know, make some of these suppliers, some of these vendors make these changes. Now it's hitting the bottom line. Now it's hitting, having a financial impact.
They can, they can, you know, be concerned and care about and that can drive some outcomes, I think. I hope so. I think we all hope so.
Hey, Chris, we're running low on time here, but I wanted to, uh, for people who maybe want to get more information or, or maybe even give their input into csar on this, is there a an easy URL they can go to? Or how would you recommend? Yeah, so if you go over to SSA's website, lemme try to grab, uh, it has a lengthy URL to be honest with you, to get to the, uh, the know, the, the publication itself, I would imagine they, it is the government after all.
Um, Yeah. But if you go to a, they have a secure by design landing page, and if you go there, you'll see not only the Secure By Design publication, but you'll see the, the document we're talking about, the software naming ecosystem. You can check it out, you know, provide some feedback and commentary with the instructions they provide.
And you know, honestly, they're looking for communication and collaboration with industry. So weigh in, give your perspective, is what they're looking for. Absolutely.
So if you, probably, if you just Google SSA software by design and go there, you could get there off there. Hey, Chris, I want to thank you for coming on Techstrong TV today and, and giving us a little bit of an education here. And you know what, quite frankly, thank you for everything you do, man, working with csar and advising these companies.
You know, it, it takes a village to do security, right? And, and we don't have enough hands, right? So I appreciate your efforts and appreciate you coming on today.
Yeah, definitely. I'm excited to be here, like I said, and, uh, I'm thankful to be here as part of the Cyber Stream community. We have an awesome group of people in this community and I'm excited to be a part of it.
Fantastic man. Thank you. Come back again soon.
Keep us posted. Chris Hughes here in his role as Chief Security Advisor at Indoor Labs. We're gonna take a break here on Tech Trunk tv.
We'll be right back.