Kiran Kamity, DeepFactor | KubeCon + CloudNativeCon NA 2022
DeepFactor CEO Kiran Kamity joins Alan Shimel at KubeCon to discuss the company’s goal of incorporating security into software development life cycles.
Transcript
This is Textron TV. Hey everyone. We're back here live in Detroit at cubecon continativecon.
Continuing our days coverage and this event. It's pretty crowded. Correct reintroduce you to current committee from Deep Factor.
I'm welcome. Yeah. What do you think?
It's pretty crowded? It is super crowded much better than last year much. Yeah, you don't realize it because the boots are so spread apart.
Yeah, so it's not as dense. Yeah. I don't know how many people here.
I'll find out but there's a lot of people here, you know, I think our marketing team was telling us that the 7,000 people here physically and 7,000 online approximately. So yeah. It's more than I think three times the number of physical attendees this time then La yeah last year.
Yeah, so I'm trying to remember when we were in Valencia in a yeah, I was cute on Europe right? There was maybe six somewhere between five six thousand people there as well. Right?
So it's probably around that same size still not as big as San Diego was pre pre-covid. Yeah. Anyway getting there getting there.
It's getting there. Come on down. You're on you with deep Factor.
Yes, and let's let's start off with a little bit about you. What what tell us a little about your story. Yeah.
I'm the founder CEO of the factor. And before the factor. I was I've been in Silicon Valley for two decades now.
I've been I've done three companies as a Founder sold one to Citrix old went to Cisco. My last company was a quiet container X was acquired by Cisco and I was the head of product for Cisco's Cloud after the acquisition. So it's responsible for openstack container container networking kubernetes and a few other initiative there and it was very clear that the next Frontier of innovation has to happen around Security in the sdlc and that's what led me to leave Cisco and start deep-factor.
I I don't disagree with that at all. I think you want to know the truth from everything. I've seen this year.
It's reinforced that right, I think. Security has really it's having its moment. I hope it's more than a moment, but it's having you know, it's day in the sun here.
Let's talk a little bit about deep Factor. Let's start Basics, right? Well, yeah.
Tell us about deep Factor. Yeah, we're a developer security company. Our goal is to make sure that you incorporate security into your software-defined life cycle software development life cycle.
So that your engineering teams are empowered to create secure and compliance software. Just out of habit. incorporate that integrated Yeah, I mean if you think about the first generation of tooling around developer security, it has been very disjointed like you've had sased and SCA and you know dust and runtime analysis and all of that and they don't necessarily talk to each other.
So what we have created is an integrated solution that combines artifacts scanning which is SCA and s-bomb Etc. runtime analysis of your kubernetes environments and correlation between runtime and artifact scanning so that you can tell the developers which of the vulnerabilities in your containers are actually used by your application during Dev test and fraud so that you can prioritize and fix the ones that are important first so that whole cycle offered in an integrated manner is essentially what the factor does. I love it.
Excellent. All right. You know what?
Let's get it out of the way. So people know right now for people want to get more information about deep factor. It's deep-factor not I know.
Yeah. Okay check that out of Defector audio. All right.
I think we've laid our foundation. But yeah build a little bit right as I mentioned security is top of Mind here this this year and I'm happy for it. You guys recently have put out some new news our new release.
Yes, and you are well, I don't want to steal your straight. Tell them what's going on. Yeah.
0 which is a an exciting new release with lots of new capabilities. That further is our vision of Combining artifact scanning runtime analysis correlation in an integrated solution and we're also taking sign-ups for our data for a SAS at the booth. So for those that want to stop by the booth and interested in a SAS version of our product they can they can sign up for the for the beta you combine two things there.
Let's take one at a time. 0 that they should care about. Yeah.
I mean one of the biggest things that we're seeing out there is bill of materials and why that's important. That's bombs. Yeah.
0 you can download your s-bomb the s-bomb that D Factor gives is quite comprehensive and Superior to some of the static s-bomb tools in the sense that we not only give you a static list of vulnerable static list of you know, dependencies and images in your container. We overlay them with vulnerabilities. We group the applications into versions tag them, you know based on which components belong to an application all of that good stuff that needs to happen for you to get a full s bomb and combine that with how your applications behaving at runtime to give you both static and dynamic.
They live materials. 0 we've also made Made a tremendous amount of improvements to our user interface. So the new improved defactor is is much more easy to use.
We announced a new customer that is a case study of one of our recent customers inspired that is making a geospatial software for car traffic analysis in Spain. They recently put out, you know, we recently put out a press release with, you know, showcasing the case study of how they have used the factor to gain benefit around Security in there as DLC pipelines. Got it actually now.
I don't I know enough about Esperance to be you know, semi-dangers one of the things we're seeing with Esperance. That was the different formats. That every vendor is using.
I believe you know, I sit in a good seat here I get to see though. Oh picture. I think we need to standardize on that's bomb format.
Right? What do you think about that? Yeah.
I know absolutely and I think there's efforts underway already with Cyclone DX and spdx and and both of them are important. I don't know if we'll have one standard and I think even too would be nice that 100 exactly. What do you where is deep-factor on this?
What do you support? Yeah. I know we recognize that both need to be supported and we'll be supporting you know, both of them in English actually really good stuff.
Yeah like to hear that. Let's turn now and talk a little bit about a hosted version Look. I know enough about open source business models, right?
Yeah, right where training and support isn't enough to make a great business. And and one of the easiest ways for you know, an open source model is to take that open source supported kind of project right and offer. It is a hosted version.
It's it's great, but it's not just great for you in this case. It's great for the end user. takes the infrastructure maintenance off their hands make sure that you always have the latest and greatest, you know version.
Yeah, you have support really built into it, right? I mean Talk to us about the hosted. Right and we should mention right?
I think you did. You just accepting public beta right now. It's not out General availability Yeah in our boot people are just scanning to get into our beta just to get.
Yeah, but what do you envision is gonna be without getting too much out of the bag. Yeah. I know.
I mean defect is not an open source product, right? You know, we do contribute to open source. We do detect vulnerabilities open source, all of that.
Our product is currently, you know installed in the customers and vinements. So but right and I apologize but that's the model that we see with open source, right what you say, but still it's running at a customer. They've got to install it maintain it updated supported.
you know level one or whatever so What's in this hosted version or what that you can talk about? What would you know beyond the obvious? Yeah, I mean it all the things that you said, you know, the fundamental difference between, you know, hosting things that customers host themselves versus you know, any product that is not hosted by the customers as managed by the vendors is the fact that they don't have to deal with all of the headache of the management of the infrastructure.
So now another event so of that whole kind of SAS models generally look one traditionally when I buy software, I gotta buy the software I buy a license Annually updates. Maybe I buy the license once and it's You know some percentage every year for for maintenance and updates but in a SAS model, I don't have that big capex. And I do it monthly is that the case here or we haven't worked that out yet?
No, it's always been a annual subscription for us. So we charge case for the number of contributing developers and it's however many developers are contributing to your your containers and and software in the last 90 days those count towards contributing Developers for us. So from a user perspective price would not be an incentive to go from posted to on-prem.
No, that's not but price is a great incentive for users to go from other products to defactor because because there's instead of buying five different tools SCA and s-bomb and runtime and dash and all of that they could use an integrated solution for getting comprehensive insights into their suffer to find life cycle with prioritization with the things that developers care about so that it reduces friction for them. So, you know offering all of those things. What do you see in the Pacific?
So as Farm is all the rager everybody's talking at Sports and so forth supply chain security and what have you Yeah, a year ago. Everybody was talking about zero trust and all you know, it's always it's always it's I own a boat. This is saying when you own boats, there's always a bigger boat right?
No matter how big your boat is how much you like your butt. There's always a bigger boat. There's always another hot security.
Yes. Thank What do you see in deep Factor? Does it just keep adding the new hot security things or is it?
Hey, this is what we do. Yeah. No, we're the the core.
Strength and power of the factor is in the in the way. We do runtime analysis designed for kubernetes and Cloud native workloads. How we drop in to your kubernetes.
You can simply install a web hook you can configure which pods you want to Monitor and you don't need to install any host space agents unlike the first generation of container security tooling the approach that we took was you know, we wanted to work in even managed container deployments such as far gate. So we made that happen and the way that's that's the course strength of the product you simply install the deep-factor webhook and the containers that are being observed are deeply inspected every process within that containers. We take all of that Telemetry and do an assessment detect anomalies and tell you these are the risks but that alone doesn't make a complete solution to customers that want comprehensive Security in the sdlc.
so we've added the artifact scanning to that which is SCA and and of course bill of materials because that's an important piece that every customer of hours is asking We combine that with the runtime analysis we make we make run time analysis. So easy that you can now do runtime analysis even in Dev test not just fraud as well. So you can bring that early and shift that left, too.
And then correlation between runtime and static artifacts. If done in an integrative fashion gives you the benefit of prioritizing which of the vulnerabilities that you're seeing in your artifacts show up at runtime in Dev in test and in fraud therefore telling your developers. Hey, there are 200 things to worry about but don't worry.
We only notice 20 things in your runtime. So fix them first that way developers are happy and security people are happy that your priorities in the right. You know, we we were talking off camera before we started running and we were talking about you know.
things that deep Factor does and what you did with deep Factor, but also just let's call it the Primacy of devs devops whatever you want to call it security and that is a big issue right that we need to make it easier. We can't expect our developers. Yeah to put the time in security that security Pros too.
Yeah, and that's I think that's part of the deep fact of value prop. That's exactly the heart. Yeah.
Anyway, we mentioned deep-factor that IO yes. Okay. I want to make sure we got that check it out.
When can people sign up on the web for the public theater, maybe or there's no plan yet. There's no way I mean, I put you on the spot. I'm sorry.
They give you if you watching this live you can stop at the booth. Yes, but otherwise you may just have to wait till it's available, you know. Yeah, I can stop by the booth.
We have a sign of sheet for beta. All right, Karan. Thank you so much deep Factor.
It deep-factor died IO here in kubecon. We're gonna take a break. We'll be back in really less than a minute with our next guest.
