Pete Morgan, Phylum | RSA Conference 2023
Pete shares the latest research from Phylum covering software supply chain security attack trends.
Transcript
This is texturing TV. Well here we're back at rsac in San Francisco 2023 talking to great people about interesting and cool things that are happening in technology. You know, there's a real theme that's happening this year.
I think is very different than other years that we're talking about supply chain application security. And of course, you know traditional networking Cloud security kind of topics So to that end, I'm joined by Pete Morgan who is CSO and cofounder of final get that right? Yes, sir.
Okay, just this lady in the afternoon string a complete thought together there. So tell us a little bit about yourself and then tell us a little bit about what's Finland sure. So I've been a career security researchers as I was a child.
I got my start hacking video games against my friends and kind of got that by the bug there. and got really lucky that that turned into jobs in the career and they've got to do that ever since and my co-founders and I kind of came together. Three years ago and looked at the kind of this attack surface of the software supply chain and realized that we were a lot of the products were.
A little too focused on vulnerabilities and you know the elements of the software supply chain. That's interesting. Is this kind of more like a watering hole?
In that all software developers go to get their packages from the same handful of places and attackers are figuring that out. So we wanted to figure out a way to defend developers from the attacks that are hitting the open source software supply chain, and that's a sort of final. It's a it's makes sense.
It seems amazing. It's pretty interesting. Amazing how software developers become an attack Vector?
Yeah. It's it I think back to earlier days when I was like a pen tester back, you know early 20s and you know the targets then where they what had keys the kingdom to get me the next step and you know, getting domain admin in a Windows network was kind of the could get into the directory. We're all good.
Well now that's kind of same thing is shifted, especially with everyone working from home and Cloud. AWS Keys SSH Keys, these are the things that you really need to move around and you can get those off developer workstations. Pretty pretty easily especially given the fact that software developers.
The amount of them has gone up and sometimes some of the security tooling that runs on most workstations might be tuned down on the software developers or stations to improve build times Etc. So it's created a ripe Target for attackers to to infiltrate through the supply chain. We don't always train people or necessarily, you know, let developers know especially folks kind of entering into the career like these are keys.
This is a private key, which means doesn't go anywhere, you know, all right, or we have a lot of work to do to start over. There's there's I would say lack of awareness. I think there's just a growing awareness of software security development environment security, you know packages things that we're putting into our software and I think everybody's kind of learning bringing up their game at the same time.
Yeah. It's kind of it was something surprising to me because I looked away for a little bit doing some other work and kind of look back at software development and so many things have changed. I mean microservices exploded and we were now writing software at a normal organization in not one or two languages.
We were writing them in six eight ten because whatever fit the microservice. So you had developers following a lot of different disciplines or from a lot of different backgrounds. And they all need access to the assets to do the things they need to do.
but if you look at not just thinking about the open source supply chain from more traditional package manager like Pipi or npm but then extend that same problem out to things like vs code which has a plug-in system which references GitHub repositories then as a plug-in system which references GitHub repositories. and the security control there is the bet that the plugins you rely on are not compromised by someone and that you're getting authentic good code, but this problem is replicated all over the place now and The ways to get code onto a developer workstation are in the hundreds or thousands now. Rather than tens, and that's just a it's magnified the problem dramatically interesting.
So how did you have the foresight three years ago decide. This is a problem to go after. So my two co-founders came from the intelligence community.
And at the time they had been working on a government contract and there was some concern around taking in code from a bunch of different government contractors. And you know, there can be five or a hundred in that chain. And saying is there malware in the source code?
And there wasn't a really good way to identify that so they kind of extended that problem. We got together thinking about this saying What is open source? It's?
Untrusted code written by strangers that we use in automation. It's a perfectly ripe Target for attack and you know endpoint products don't read source code for malicious elements. So it's just one of those areas where attackers You know, I think we were a little bit early but not early enough attackers are hitting hitting it pretty hard.
I figured out pretty quick. Yeah, they're going after it. No doubt.
Well, tell us a little bit about you've had you there's announcement that finally recently made what's happening there. Yes, so we're excited to roll the open policy agent engine into our into our products to enable policy driven decision making and this really enables us to kind of Step a bit away from the traditional critical high medium low subjective rating system. Where We as phylum have to kind of pick what is the severity of an issue and know that it's never going to map perfectly to all the organizations that our customers.
But instead a lot of the customer to Define what the policy is for the things they want to use in the open source ecosystem. What do we allow? What do we reject?
And kind of iteratively build that policy so instead of saying. Kind of the way it is for most organizations right now. I think of a developer running through a Toys R Us pulling anything off the shelves and like a shopping spree because there's really no restrictions on what you can and can't use into making some decisions about these are the types of properties.
We're going to look for in open source software and be a little bit more educated a little bit more cautious on what we can choose but also let them Define that and build it up over time. It seems like it also kind of customized it to your environment. Also, there's contexts that's missing right from a rating system.
Yes, they're useful but you know, even the Simplicity of we've got that vulnerability mitigated through other rights, right right fixing it and software just as simple example. So what does it mean to bring the policy engine into your product? Does that mean you're doing more automation?
For that as well as declarative kind of actions. Yeah, so the goal so our our product is fully automated. So as new packages are released into a given package registry like npm or Pipi or cargo we run an automated analysis that looks for you know hundreds of indicators to try to identify risk and then expose that risk to customers and with the policy engine instead of saying this is a critical high medium low, they can tune that policy to what they feel is the right elements and we often start them with a kind of you know, template but that gets tuned over time as they make decisions saying this is how we see type of squatted packages.
This is how we see You know, maybe license licenses that are of this type of class. We want to handle those as this type of issue. So it really allows us to have better signal noise ratio because we can expose more data to them and then they can filter and select on the things that are most important to them.
interesting, very cool There's a picture size of organization kind of development environment teams that are the best fit for a phylum can solution. We've definitely seen Trends in organizations that are more interested in that type of solution tend to be a little bit bigger tend to be a little bit more mature on the software security side simply because I think they've crossed off a lot of the low-hanging fruit. Maybe maybe easier more easily.
But we've had organizations, you know all the way from five. To five thousand deploy us and there's not a lot of differences because the automation between those organizations often pretty similar, right? They're using some sort of source control manager like GitHub gitlab bit buckets and like that and they have some security tooling plugged into cicd.
And they have some process for how code flows from developer through pull request and you know Etc and you just map into that. Doesn't make too much of a difference the organization size when you have that automation, which is one of the cool Parts automation. Yeah, if you have that that tool chain that workflow pipeline built.
Definitely. I'm so I think I'm curious. Have you been to RSA?
Very many years. Yeah for a while now, but if you're doing security, okay, it's interesting to me, you know kind of going back you can go back last year, but it's really pretty pandemic. I remember doing interviews and talking about you know, I think one of the big things is security people need to learn something about software architecture, but maybe more important even more how software is made devops, you know workflows pipelines.
Yeah this year. That's at least give me there's a lot of other security things happening, but three four conversations are about supply chain security, whether it's what you're doing or s bomb element of it or you know, kind of her medically sealed environments where all that is controlled from me from package managers. There's a lot of approaches, but it seems to be In the conversation, maybe even on the tip of the tongues of many folks.
Yeah, I think there's a especially when it comes to software security. We're I personally see it as the spots where the Venn diagram doesn't overlap where security software security and development. Understanding don't coincide or getting smaller.
It's kind of one of those things where the most successful security teams. I've seen. Are often have developers on their staff from their organization?
They understand the development practices organization. They work with those developers the closer those two groups interoperate. there's a pretty strong trend of how they operate better, right and that's that's something I think that I think most organizations see now, but it's still a challenge to You know, there's a lot of developers comparatively not as many software security people and there used to be a little bit of maybe contention between those groups.
I've read about it never seen anything, but it's just one of those places where They don't success means working together there, right and it's becoming more and more clear. Well, I think I think there's no better way to gain respect from a software developer to speaking to another software developer that had no security or at least knows enough about software development network. If you can bring internally people then they know your environment.
It also seems like the thing that helps is security teams hiring their own developers oftentimes, you know, doing python or scripting kind of things for their sock for their security as well and see those learning about, you know, software managing it and how to use secured it so there's a little bit of kind of either I'm someone like you or if someone walking in similar shoes and okay, we can we can talk the language now. Yeah, it's a having come up from a kind of software security discipline from most of the time. There's definitely a lot more on the technical side.
And took a little bit to have some more appreciation some of the sides I wasn't as familiar with like maybe more risk based or some of the more kind of business-oriented practices that I weren't interesting to me when I was younger and then as I grew up, I you know learn to appreciate those it kind of look at them equally right saying you got to have a little bit of everything if you're going to be really good at this or maybe a lot of everything. and I think it's not that dissimilar in this case and you know we're seeing As we watch how attackers operate. There they've they're really getting good at identifying gaps wherever they are.
And if you kind of approach things from an overly technical perspective, like they'll do you see attacks where they notice this and move out of the way. It's like water right? It flows the lowest lowest spot on the container.
So, you know as a defensive practice we have to kind of be pretty open about trying to learn everything, you know and Beat them at that part of it is even kind of going back to not kind of beating up solar winds again, but just looking at that in in the supply chain the dev cycle doing some smart things to Don't Be Active when other activities are happening, right and you know codes being compiled or or integrated together. You know just sort of don't be there. Don't be in the way.
So people are gonna notice it sort of be off to the side where people won't this is a and this is something that speaks a lot to what we see. You know, one of the things that happens a lot is someone goes to install a package. And they're like, I'm installing one package.
It'll probably have some dependencies. Well, you know, I'll see them scroll by. But that average dependency length has like skyrocketed and so depending on the language you're writing in.
You know those numbers get pretty crazy to where one package that gets a hundred or a thousand or 4,000. Pardon me and it's all the things that come along with that. where that installation takes, you know milliseconds and that's where the attack happens and it's kind of something where I remember getting thinking like how would I ever check I use requests in Python all the time.
I love it. I know the API and it's great. Very happy.
Yeah. I'm not gonna go back and reread that code regularly as it changes, but they're in lies. You know part of the difficulty is we can't expect developers to do this.
That's why we want to have an automation platform or multiple automation platforms that are looking at this constantly and you know open source has been amazing. I've learned so much from using open source reading the code learning learning how things are done and then improving my own skill set. To think that like, you know, it's getting polluted.
This way is frustrating personally, but then you know Kind of being a good Steward and helping identify that stuff and get it kicked out as as also fun. What do you think the the package managers need to do? I mean obviously they're Whether it's a VMware a image or it's you know in the Red Hat World or Docker container, there's ways their processes for saying, you know, you have to go through the security checks and scan and things like that, but still things things still happen.
You think there's improvements that need to be made by the people that are kind of curating that content. It's it's a tough question on one hand. I think yes, of course, but it's also very easy for me to say that inside a point to think it's easy to point the finger but I have to think about like how difficult is that to actually Implement and also think about a lot of these package registry maintainers are open source contributors.
They're not getting paid for this. They're doing it out of the goodness of their heart and the fact that they want to contribute and improve something and then kind of pointing the fingers saying you're not doing enough might not be, you know, seems like it seems unfair bit of vinegar. Yeah.
Yeah and especially in a time when to be you know, I think the world needs to reconsider how we use open source in a way that can be a little bit more fortuitous for the developer as well. Or the individuals I should say other than the organizations on top of it, but I think there are some design changes. That would be really helpful.
It's also tough to go. to a number of disparate groups and say make all these changes on and then apply them to all of your users and deal with all the backlash of that. You know, there's a I'm hopeful there are some some positive changes in a couple ways that are I think would knock off some of the big, you know a big swath of issues, but It's the open source world, like it kind of scaffolds off of.
What people like and you know, I'll take their own path right right control over right reminds, you kind of way early of Internet protocols and a security wasn't built into them and then gradually over time, you know as soon P2 or third version three things come out and they finally kind of catch up not to say that's that's the equivalent of Open Source, but it doesn't happen overnight, right? We're still dealing with SMTP, right? Yes.
Yes and put in you know. But it's beef it or whatever the records are that we put in. Yeah, but they're kind of a pain in them in and of themselves, but so I know there's been a research report that you all issued recently tell me about yeah, we're pretty excited.
It's been kind of a collection of all the finding or the statistics we've seen in the open source supply chain, you know, we look at I think I think it says we look at around. 40 plus thousand packages a day that are just because it's too many released. So the automation system consumes those and analyzes those and you know, we've seen some stats on how many packages are malicious the type of squats like organizations that are targeted the types of attacks that are happening the frequency of those and then Trends in like where attackers are moving, which is a pretty interesting.
And yeah, we're excited to show some of that data also because we've been you know, running this analytic system monitoring the open source supply chain for for a while now. and now collecting this and kind of showing those Trends and where it's moving has been well received so far, but also just interesting to watch right like watch with these actors are doing and Other changing their game and how to stay in front of them. We're gonna reminds me how I can buy a release date about what they see in the network right friends exactly right or whatever's happening super interesting data.
io, that'll be I'm sure posted right on right on top there, but And we'd love to hear from anyone that wants to has any questions about software supply chain or wants to learn how to defend their developers from from these attacks. All right. Great Morgan, who is CSO and co-founder with final welcome.
Thanks for coming. Thanks so much. We'll be back with more.
Yes. So keep stay tuned with us here.





