JFrog Runtime Security with Eyal Dyment at JFrog swampUP 2024
Eyal Dyment, VP of product for JFrog Security, about the company’s latest product announcement—JFrog Runtime Security. Dyment explains how this product integrates with the JFrog platform, particularly Artifactory, to provide unique bidirectional lineage and image integrity verification, helping track and secure containerized applications from development through production. He also highlights upcoming features and the role of AI and MLOps in improving security and automation.
Transcript
This is Techstrong tv. Hi everyone, it's Alan Shimmel for Techstrong tv. We are back here in, uh, Barton Creek in Austin, Texas for the 10th annual Jfr Swamp Up.
And we're, we're interviewing and talking with some of the frogs, some of the attendees, some of the partners, analysts. Having a great time. I want to introduce you to our next guest.
His name is Al Demon, right? Yeah. Deon What?
Demon. But Al, first of all, welcome, welcome back. You've been on our show before.
Oh yeah. Y for those not familiar at home, tell them a little bit about your role at Jfr and maybe a little bit about your background. Cool.
Awesome. So, um, so yeah, yal Deman, uh, I've been with Jfr for the past, uh, couple years now, and I'm the VP of product for JO Security. So in jfo we have multiple product lines, very commonly known as Audi Factory.
Uh, but within jfo we have the jfo security, uh, organization, and I lead product for that team. So, uh, uh, for the past couple of years. So everything has to do with security within jfo and the jfo platform is within my organization.
Uh, my background is obviously I'm a techie, so I used to be a developer, uh, I dunno, 15 or 16 years ago. I was a developer and then a team leader and group manager. And then, uh, I had enough of the tech side and I really loved working with customers and I made that transition into product management.
And I've been doing product management for the past eight years now with different leadership roles, and I've been doing, uh, this role for the past couple of years now. Yeah. Excellent.
Um, some big announcements. Oh, yeah. Today here at Swamp Bubble, you know, there was an Nvidia partnership, a GitHub integration, but from a product point of view, I think the biggest story was the announcement of a jfr runtime security.
Right? But module, is it a separate product or a module? How do you refer to It?
So it's separate product, uh, has all the value sets among it, but obviously it's connected with the platform, which we can Right. Which is what I want to talk about, right? Because, you know, one could look around in the market and say, oh, just what the world needs, another runtime security product.
I can Imagine there's no shortage of them and some are better than others, but the fact is this onetime security product has a little special sauce, right? And that is its integration to the Jfr platform, right. But I, you are the product guy.
Explain to our audience, if you would, a little bit about Jfr runtime security and what the special source there and how it kinda cool makes itself known. So Jane speaking, as you mentioned, there's a lot of, uh, what you can call like pulling solutions for one time. Uh, and what's special about the jfo onetime security solution is its connection with the jfo platform in general, and most specifically with j jfo Art Refactory solution.
So, number one, like any other onetime security product, you need to have realtime visibility to your onetime environments. So you can monitor for vulnerabilities and exposures. And that's, you can say is like the basic capability of a onetime solution.
But the special aspect of it in connection with the platform is in two ways. First of all is what we refer to as the bidirectional lineage. So most of times or most of the cases, there's a disconnect between your, uh, coding, uh, development life cycle all the way to the pipeline.
And then there's a disconnect with the runtime environment. So whereas images or as containers applications are being shipped into production, there's a disconnect between those solutions and therefore you lose the lineage. So when you are shipping images, containers, applications from your, uh, uh, development lifecycle, you don't know where they are going in production and you lose track of that.
Mm-Hmm. And on the other way around, uh, you lose track of traceability capabilities back into, to the development teams directly through the platform. So what J four Guam is specialized in is to have a, a bidirectional lineage between the development lifecycle and production.
And when something goes wrong, being able to monitor that in one time, detect that and trace it back to the development team in a matter of, of an instant. And the second aspect, which is specialized in the connection with the platform is what we refer to as image integrity or verification of image integrity. So a lot of times what you really are concerned about when it comes to security is what we refer to as image tampering.
So you build an image in your factory and you store it, uh, in Audi factory, and then you ship it to production. But maybe sometime during the process there's a man in the middle kind of an attack and somebody is stamping with your image, and you end up with a situation where the image that's running in production, it's not the one that you build in your C pipeline and you don't know about that because you have a disconnect across your lineage. And that's where J four heim comes into play and gives you that capability.
Now, this is different than like, for instance, the solar flare right? Kind of breach where they were actually able to interject a backdoor malware right into the CICD pipeline, right? Uh, you know, so before the product was uploaded mm-Hmm.
To a repo or deployment repo, like an artifactory or a Docker hub or something. This is if, if something happened after it was deployed to the repo. So after it was deployed and then you find out about it and you wanna be able to, uh, understand that this, this happened as there's a mismatch.
This, this was is what you do now. And it's unique in that sense. Only the JO security solution together with that facto gives you that benefit of connecting between those two.
Uh, there's a chasm between the, between your, uh, development lifecycle and one time. And only by connecting that without a factory can you cross that chasm and have that lineage. Yeah.
Got it. Now, and this is available now, red type Security. Yeah.
What about plans going forward with it? So in terms of, uh, so we have a lot of, uh, Four functionality. So Obviously, uh, one, uh, important aspect that everybody cares about is automation.
Yeah. Uh, so think about a situation where you have that complete lineage between your development lifecycle and production, and you detect those issues automatically using alerting systems or whatnot. And then you want to be able to detect that, know about it and automatically remediate that.
So, so take that to the next level through detection and remediation with the recommendations. So that's something that we are, uh, planning on introducing, uh, and that's coming up from our customers. That's, that's feedback, yeah.
One on one feedback that we're getting from customers. And then, uh, another thing I can share is, uh, you mentioned, uh, our announcement today with the GitHub, uh, and J four integration Yeah. Uh, partnership.
So think about a situation where you can form the development lifecycle from the development perspective, understand which of your images are running in production and have vulnerabilities that are, for example, applicable in the context of runtime. So being able to connect between the developers all the way to runtime, uh, by joining forces with our Gear Up partners. Uh, so that's also something that's really, really, uh, important and is coming up again from, from the field, from customers that we are planning to, uh, to go into.
I, I think that was a big theme here too, that many of these features and products Yeah. Really their genesis is in the field, right? Oh, Absolutely.
I mean, everything you hear about here today, including one time, uh, it's not like J Fog is, has decided, Hey, we have this great idea and now we're gonna push this down to your throats. Uh, uh, I give you that example of, uh, about image, uh, integrity. This came from our customers around, I would say probably about a year and a half or two years ago.
They, they were saying, you guys are the single source of truth. You guys are holding all of our images, storing all of them. Why can't you tell me, oh, can you build a product that tells us where these images are running?
Sure. Uh, so this was conversations about two years ago, and now it came full circle with the introduction of that singles with the GitHub integration, singles with ML ops. Um, and those, uh, and those are, uh, things that are coming up.
All of them are very much rooted, uh, in discussions we have with customers here. Yeah. So you mentioned ML ops.
Look, AI ops Yeah. A excuse me, AI in general, right? Is is all over it, right?
Right. Just can't, it sucks the oxygen out of every roof. Where do you see this coming in with, um, with the run time?
Right. So we look at ml, uh, specifically ML ops or Ms. SecOps.
We look with ml uh, models the same way we look at open source packages. So it's another type of a package. It has risks attached to it from threat actors like, uh, trying to inject malicious models or other types of attacks.
And the same way where you want to detect vulnerable images that have CVS in production and you wanna trace it back to the development team as quick as possible. You wanna do the same with ml SecOps, uh, relevant operations. So those two, you know, separate lines of DevSecOps and ML ops have to come together, the different personas we have the DevOps engineers, the the developers, the security practitioner practitioners, and now the data scientists all have to be using the same platform so that we can, whatever it is that's going through our pipelines and through our development life cycle, we can detect those in run time and get back to the development teams or the data centers as quick as possible.
Get it. Excellent. com.
com. We have a website, uh, we have a dedicated section in the website up and running with all the information, uh, both on the deployment and technology, uh, and all the values. Yeah, absolutely.
Go, go out, go ahead and check that out. Uh, and like always with J Fog, customer feedback, feedback from the field is what we are looking for. Uh, so if you, anybody here is, uh, checking this out and want, want to provide feedback to us, we welcome that with Open Up.
Absolutely. You know, and, and again, the real special sauce here is especially if you're a Jfr customer, yes. You're already using Artifactory or X-Ray or the ML ops or any of the, you know, the platform, right?
'cause at the end of the day, that's where people seem to be going to towards platforms. Oh, absolutely. Absolutely.
Yeah. Thank you so much. My pleasure.
It was a quick 15 minutes, but, uh, very good. Alright, check it out. Jfr Runtime Security and announcement here at Swamp Up.
We're gonna continue our, uh, coverage at day one at Swamp Up. In just a moment, we'll be back. Yes.