SBOM Compliance with Walter Capitani and Dmitry Raidman at RSA Conference 2024
Walter Capitani, senior director of technical product management at CodeSecure, and Dmitry Raidman, CTO at Cybeat, discuss their joint initiative, the Binary Composition Analysis (BCA) Marketplace. The marketplace addresses the demand for Software Bill of Materials (SBOMs) required by regulations like FDA and CRA in Europe, enabling both software producers and consumers to access and manage SBOMs efficiently. By offering a variety of binary composition analysis tools and fostering collaboration between industry leaders, the marketplace aims to simplify compliance with regulatory requirements and enhance software security across various sectors.
Transcript
This is Textron tv. Hey everybody. Mitch Ashley here at RSAC 2024 in San Francisco Day.
I don't know what day it is, it's Wednesday. It depends on how long, many days you've been here. But we have some more great conversations.
We're gonna be talking about a really cool announcement, uh, about an organizations that's been formed and launched. Uh, while we're here, I'm joined by a couple of, uh, great gentlemen, Walter and Dimitri. I'm gonna ask you to introduce yourselves first, and then we'll talk about this announcement.
So Walter, if you would go Yeah, Nice to be here. Mitch. Uh, Walter Capi, senior Director of Technical Product Management at Code Secure.
Excellent. Fantastic. Yeah.
And I'm Dimitri Redmond. I'm CT Co-founder at sbe, and we are software supply chain security company. Okay, great.
Now we kind of know where, where we're coming from. So tell us about the announcement that, uh, this organization that you watched, Mitri, you wanna go? Of Course.
Uh, so what what's great about this announcement is that it's all ties to a lot of regulations and government activity, right? It, it goes to things like FDA and CRA in Europe, and also executive order for the 0 2 8, right? All of these regulations they demanding for software based product producers to be able to, uh, create asbo, which stands for software bill of material, and then also be able to share it with your customers, right?
And one of the challenges there is really, okay, so how do I produce the asbo if I am a software producer? But it's even a bigger challenge of how do I get that asbo If I'm software product consumer, right? I'm installing this database, I'm installing this IP surveillance camera in my offices, in my network, in my enterprise.
How do I know what inside it, right? I want eventually to understand the asset better so I can also understand my risk and mitigate them. And that's all this started.
And I think we, we partnered for already very long time ago on, on, on, on different things. But we came up with this, uh, great idea jointly actually, right? We can, we, we, we almost like design partners in this where we said, okay, there are companies that they will need these ASBOs now or tomorrow, either to be compliant with the regulation or either to get them because they want to be more secure.
They want to improve their pro security posture of their organization. So how do they get that? And today, mostly it's, uh, it's, it's quite complex because what companies are doing, and they, they, they would go to different companies and doing something called BCA binary Composition Analysis and they would start, you know, engagements and POCs and decisions and onboardings.
And sometimes it takes months, if not years to choose the right tool. And then when they're choosing the tool, also they discover, okay, it's not covers all of our use cases, right? So that's kind of where we came up is this idea of binary composition analyst marketplace because we, as a sobes, we don't create these SBOs, we just help our customers to manage them.
And there are great companies like Code Secure that they actually really good at creating these SBOs that very high quality. And that's where we found these partnership very beneficial, where we could bring a technology with very fresh approach of PLG, which stands for product led growth, right to the market, and make this technology available quickly toward the customers so they can, you know, fulfill that requirement and need. Fantastic, well, binary composition analysis that kind of says it all right?
I mean, think about software bill materials, doesn't mean that's what actually gets delivered into production or downloaded or whatever. You get that executable from things could happen during that creation or build process. Um, talk a little bit about, so the name of this is Binary Composition Analysis Marketplace.
That's right. Is that right? This a Marketplace?
Correct. Okay, very good. Tell us a little bit more about how does this work, how does it function and what can people do, um, as as, because we have this now.
Yeah. So we at Code Secure been developing our binary composition analysis technology for quite a while. So it's very mature and we've worked with a lot of customers to help them develop, you know, techniques and processes to deliver a true SBO m out of their binary package.
Let's say that they're distributing their software or even software they receive from a third party. But the challenge is, some of the ones that Demetri has mentioned is that you've got procurement processes that take a long time you're evaluating while you're trying to actually solve the problem. And so one of the nice parts about the BCA marketplace, it makes it easy and fast to start generating SBOs that you can use today.
And with a combination of accurate SBOs generated with code secures binary analysis and the side beats SBO M management that lets you manage, manipulate, and view and share your SBOs together, you have an easy to use solution that you can try with low risk and a low commitment in terms of your own organization's time and resources. Okay, excellent. Am I, am I understanding this correctly then is are you in analyzing like the executable or whatever the file format are after they've been built and packaged and delivered in whatever form, then go back and validate what's actually in it?
Is that the stage you're looking at or is it part of the build process that you're producing this? Yeah, so definitely you can do it at both stages, but we really recommend you're doing this at a packaging and release step. Okay.
And certainly if you're receiving software from a third party, you know, recently we had pretty high profile VPN breach, for example. So if you have known vulnerabilities in open source components that are part of those types of software and you're an end user of that software, you have no visibility into the source code. But this way you can actually generate a binary based software bill of materials if you're a producer of software.
This allows you to validate what you think, you know, from your built software versus what you're actually packaging and sending out the door. You know, organizations like SolarWinds for example, when they had their large, large breach, they responded by putting checks and balances in place to make sure that what is built by source code is actually what's going out the door as binary code. And that's another place where the BCA marketplace can help you validate that information, uh, Come a long way from the checks some days.
Have we not Mfi? Yeah, For sure. So talk about the marketplace.
What does that mean that the, this is a marketplace for that? Can you say a little bit, uh, Dimitri about it? So, so the MAR marketplace is a place where, where you can go and you can, uh, get yourself basically credits, right?
So you getting your buying credits and now you can use these credits against multiple engine to send your binaries and get the scan results, right? And we will have multiple vendors on the marketplace, of course. And cost secure is the first one to join us.
And, um, you know, it, the thing is that it's, it's like a toolbox eventually, right? Some tools are better for, for binary files that have been used in automotive space and they're using all these, you know, special operating systems like Autor and others. Some binary scanners are really good at Windows operating system, right?
So you really will have the variety to choose the right tool or the right mission, and that's what really strong at the marketplace. Right. Very good.
Um, is, is this intended for technology suppliers bringing their products to market or enterprises? Uh, uh, you know, practitioners can also use this? Yeah.
So capability, yeah. We're working with a lot of different types of entities, for example. So, uh, one, you know, obviously very important and exciting, um, market is for medical devices for example, because the FDA has put in lots of new legislation that essentially are requiring SBOs as part of validating new cybersecurity.
And you know, if you look even further to the EU with the Cybersecurity Resiliency Act, that affects essentially any consumer product or professional product that has a digital element to it. So, you know, it's hard to think of something that doesn't have a digital element today. Good point.
So in, in both those cases, right, if a regulatory environment that is really pushing you for the devices you produce to have a, a good understanding of the software bill of materials and the vulnerabilities that might be in that, but looking further off to the enterprise, for example, and this is where it's important to what Dimitri mentioned about multiple engines, because there will be enterprises that have everything from firmware to enterprise level software that they want to scan. And they may get different results from different tools. They might want to use multiple tools, multiple engines to scan.
And so that's all supported by the BCA marketplace and the credit system that, uh, Dmitri's talking about. Okay. May maybe a dumb question.
You mentioned devices is, um, kind of tamperproof chips and those kind of device levels part of this or pure software form software where, how far down into the hardware do you go or do you go there yet? So we go As far as the firmware. So yeah, so, um, code secure engine can analyze everything from enterprise software down to firmware, um, multiple algorithms in use that can recognize binary patterns even in code that has no obvious signature, for example.
Uh, but yes, uh, chip sets is, uh, not in our, our, uh, purview right now. Yeah. It's a whole nother chat of challenges, right?
That's right. As the delivery vehicle. So, so doing organizations, uh, collaboration, joint ventures, other things, you know, they're, they're to make them successful, my experience has been there has to be some things or a thing that's a shared goal objective, but you also, your organizations get something from that.
What would you describe as why are you doing this together? What's the reason why you're better together, it's gonna help you both. Do you wanna start Dimitri?
So that, that's a good point. And I think that one of the strongest thing that we observe by this type of collaboration is really industry leaders jointly coming together to solve a problem, a big problem in the industry, right? So actually we are an enabler for this ASBOs to come in place.
Mm-Hmm. And one of the things that are really great is that, okay, so you have the S bone, now what you do is it right? And we all know the culture of shifting left and the DevSecOps and DevOps culture, right?
That the organization are adopted already many years ago. And today it's getting to the kind of highest level. There is no easy Collection, right?
And up and down, right? So that's the point supply chain, the shifting, right? If we think about that, what is shifting right?
Shifting right, is really shifting to the consumer and the actual user of the software based product. Good Point. Does it end at the It does.
I not finished it now, I gotta exactly distributor 'cause they're gonna operate it for years, for many years. And what we don't know today, we are going to discover tomorrow, right? 'cause new vulnerabilities has been found out, new attacks, supply chain, sophisticated supply chain attacks been found out on a base daily basis like ex Z attack, right?
Yep. That was in the works for a couple years. And this is why it's so important for organization to include in their defensive mechanisms this shifting right.
Culture. Because hey, shifting right? Is not you who produce the software.
Yes. You, you would monitor your software, you make sure you're doing the best job in the world, right? To keep it up to date and to fix vulnerabilities and to release new patches.
But it's also going now into the enterprise zone at the customer because customers the one, the end user is responsible for shifting, right? And they need this transparency, they need this visibility in depth to understand what inside these software products, and they also need to tie this into their asset management systems and solutions Mm-Hmm. To understand where these products are in their enterprise.
Is it in the cafeteria or it's in the production floor of vehicle, you know, large car manufacturer. And that's what we bringing, right? So that's the value that we are both seeing here, right?
And that's what will help us to grow this business for. Interesting. Walter, it sounds too like some problems are bigger than one companies could solve along.
That's right. Right? And you need the expertise, the markets that different companies possess to come together.
Is that what's happening here? It seems like that's very much about what you guys have put together. Yeah, I think so.
At Code Secure, right? It says it all in the name of our company, right? That's our mission is to secure things everywhere there's code, right?
And what is nice about a partner like Side beats, what we found is not only does their technology complement ours in that it extends what we're doing in generating SBOs into making those SBOs more valuable and usable for the end customer and user. They've got a lot of technology that makes sure the SBO m is a hundred percent correct and is valid and takes a lot of work away, let's say from an end customer to have to do that right? Partnered with our ability to bring a really accurate sbo OM based on a binary to them, we can achieve that mission of securing code together.
And uh, and that's why I think this partnership is a really great idea and a really strong one. Great, great. What do you hope to accomplish over the next, uh, 12 to say 24 months?
What's the, when launching it, you know, you have some goals, some things that you want to have happen. What, what would you describe, I'll ask you next two Dmitri. Yeah, So I think, I mean we're very excited about the idea of enabling companies and organizations, governments that are struggling with how to get started in this SBO M world.
Mm-Hmm. That, that this solution can really lower the barrier to entry for them, right? And so everybody's talking about SBOs at the show.
I mean, it's everywhere, but Nobody's doing anything about it. That's right. It's a big, sometimes it's a really massive problem to how do I get started, right?
How Do you get started? Exactly right. And so what we wanna say to everyone is, there's an easy way to get started.
Come to the BCA marketplace, sign up for a trial, try out your most problematic or popular piece of software and see what you get out of our tools, our joint solution that we've put together here. And you can get started really quickly and easily on that road through what ultimately is compliance, right? And that's, you know, we've talked to a lot of customers that are very concerned about how they're gonna comply with legislation and we can help you.
You know, that's, that's the message. We can help you do it. It's easy to do.
And uh, it's, it's quite frankly no harder than sending an email with an attachment. That's how easy it is to use this system. So anybody can get started, they just have to come pay us a visit.
Boy, that's sometimes that's an insurmountable problem. How do we comply with the legislation, the requirements, the governance, uh, Dimitri. So what's the name of the site?
First of all, the folks can go to or send an email. How do they do this? So just to send the binary, that's How they get To it.
So they, they just can get to our, uh, website, do do do website t com and they will be able to find their under one of our product. It's a separate product. So the users of the BCA marketplace, they don't have to buy our main solution.
Mm-Hmm. They just can go in and use the BCA marketplace to produce ASBOs. And the moment they will need to create value out of these ASBOs, that's where they of course can also user SBOs studio solution for start managing these SBOs.
Great. Do they also go, can they go to your website also or is that the right, the kind of entry? Yeah, That, that's the entry point over there.
Okay. And, uh, yeah, so we, we talked a little bit about generating SBOs. We should mention like everything that we're generating is industry standard format.
So all our SBOs are shareable, exportable, importable. So you know, we've got Cyclone dx, SBDX formats, everything you need to get started. So if there's a buzzword you're concerned about, you can come to the BCA marketplace, we're gonna help you out with It.
You don't have to figure it out. That's Right. You don't need to figure it out.
We've figured it out. Excellent, excellent. We Remove the friction out of the equation.
Yeah. That's all about. Excellent.
That's great news. com, is that right? That's correct.
Good, good. Excellent. Anything else about the announcement we haven't covered yet?
Did we hit all the, all the important stuff? I think yeah, we did. I mean, you know, you have issues with compliance, you're worried about the legislation.
You need an easy way to get started producing an sbo OM that's compliant and will help you, you know, with regulatory agencies. BCA marketplace can help. One things I like about this too is you don't have to back all the way up and kind of rebuild your whole process to generate SBOs in a systematic way.
Yes, you want to do that, but you can also, whether you're starting kind of at what you're producing or you're validating what you produce with all of that up front, you can go kind of start wherever you are to help lower those barriers and reduce the friction. So yeah. Alright guys, we wish you the best.
Congratulations on the launch and the announcement and, uh, hope this, hopefully this takes off and fills a need that everybody has. So Thanks Mitch. Thank you.
Great. Appreciate it. Appreciate it Walter and Dimitri.
Great. There's great innovations that, and sometimes innovations with partnerships, bringing the right things together to solve problems in unique ways or filling gaps. You know, it's not easy to suddenly go from we aren't doing it to, we have to do it.
And how do we get started? Where do we get started? Here you go.
There's a place to do that. com to get started with the binary composition analysis marketplace. There you go.
That rolls off the tongue. Good stuff. Alright guys, thank you and have a good rest of your RSA.
Thanks for joining us. We have another great interview coming right up so it'll go away. We'll be back in a moment.