What you NEED to Know About Software Supply Chain Security | DevOps Connect: DevSecOps 2023
Software supply chain security is one of the hottest topics in security today. The problem is that depending on who you talk to, you get a different definition on what software supply chain security is. In this session, Matt Rose, field CISO at ReversingLabs, will discuss what complete software supply chain security is and what it is not. Specific areas of discussion will be malware, SBOM, comprehensive risk analysis beyond vulnerabilities, and deconstructing the most recent SSCS attacks in the press.
Transcript
Hi everyone. I'm Matt Rose Field Seso with Reversing Labs. Thank you for taking time to watch my presentation today.
So we're gonna go over a bunch of different things, but the first, uh, kind of question you're asking is, who is Reversing Labs? So, reversing Labs, uh, is my current employer, um, as you kind of figured that out already. But Reversing Labs is a company that's been around for a, a hot minute, if you will.
Um, reversing Labs came to an existence around the 2009, uh, timeframe. And you're probably like, well, maybe I've never heard of it. Well, you've probably used Reversing Labs, uh, in another security product.
So the D n A and the starting point, and I'm gonna do a little timeline on the left here, about the How Reversing Labs has become the predominant, uh, solution for software supply chain security in the market. So around 2009, the two founders of Reversing Labs came together with the goal of creating a, uh, malware analysis and threat hunting company, all powered by a large, uh, and cultivated malware database. So in 2009, they started the process of creating this, this malware reputational database.
It's currently evolved into the largest reputational database in the world that's private for malware. And this database has feeds associated with it. And I'll get to the point in a second here, but wanted to give a little history cause a lot of people are like, who are reversing labs?
Um, a lot of software supply chain, not software supply chain, but software companies, security companies, would use this as part of a feed to make their products better. So the blue chip, and I'm not gonna mention the names here, uh, use this feed to create their products. So, you know, I'll throw some out there that are pretty public knowledge, like SolarWinds and Microsoft currently use our product.
But if you have a software, uh, uh, solution for security, you probably use the feeds. Well then the time kind of moved along and we decided that we needed a user interface for the mauer analysis, threat hunting kind of, uh, swim lane. Uh, so the SOC analyst would use our product to basically, and it's currently called a 1000, uh, as a dashboard into doing this activities within their own soc.
So proactively research malware, uh, reactively, uh, respond to a threat detonate in sandbox malware to see how it works. So this was pretty much the, the foundational technology of reversing labs. Uh, then we actually fast forward to a few years ago, and there was this small, I don't know, maybe you heard about it, software supply chain attack called SolarWinds.
SolarWinds. It was probably the first, you know, really, I dunno, we, we call them superhero threats or superhero, uh, um, uh, attacks in the industry. And we basically, with our malware analysis, uh, capabilities and that reputational database, we're able to figure out what happened with the SolarWinds attack.
Well, based on that SolarWinds attack, uh, research, we came out with a blog talking about how we see this happening, which gained a ton of press and attention from industry analysts, from investors, and shockingly from SolarWinds itself. Uh, once we actually, uh, made this information public, we kind of paused for a second and thought this should be something that everybody has at their disposal. So we decided to create more recently in the past year or so, our SS c s platform and S S C S stands for software Supply Chain Security.
What we're doing is we're using that cultivated database of malware, uh, that's been, you know, growing and expanding, uh, over the last, you know, 13, 14 years. Uh, currently has over 15 billion signatures in it and, uh, good wear malware. And also we are adding around 8 million signatures or, uh, threat kind of, um, uh, surfaces a day.
So that is our s se, uh, s s e S platform. So we kind of look at it from two ways. We are a company that focuses on malware analysis and threat hunting, and SS c s software, supply chain security software, supply chain security.
I don't know if anybody, uh, was at R S A a couple weeks ago. If you're watching this video, you probably heard about it through R S A, but I really think the, there's always that theme associated with R S A one, two and three. We'll, we'll fix that.
Uh, the, uh, supply chain security was a huge one this time. SBO was a second one in AI was the third one. We're not gonna go into AI today cuz that's not really the topic, uh, that I want to talk about.
But software supply chain security and, uh, SBO m were huge. The first thing you have to do is define what software supply chain security is. There's everybody in there, brother, sister cousin, third cousin removed, talking about software supply chain security.
But there's really different lenses. There's the, you know, s c a lens, there's the tooling lens, and there's, you know, firmware. Everyone's trying to say, Hey, we do it too.
And then there's, you know, all the, uh, a s t tools are saying that they do software, supply chain security as well. But to truly be a software supply chain solution or a software supply chain security solution, you have to think about a couple things. Most of these vendors are looking at a piece of the entire software package.
SolarWinds, uh, some other, you know, interesting attacks recently, you know, circle CI and, uh, three CX are also in this, uh, mix. These are kind of the superhero, uh, issues that you're seeing out there, or the, the, uh, the superstars of software supply chain attacks. All of these things happen in different ways.
And it doesn't matter if you are just looking at the open source code or looking at the C I C D pipeline tooling, making sure your CI orchestration layer is secure, your code repos are secure, or your third party, uh, binary repositories are secure or firmware. That's something that would be embedded in a device that's not talking about software applications developed by an I S V or a bank. Um, and then the a S T solutions, a little homework assignment, I always do this to people, is look at the blue chip, uh, application security testing technologies and search their websites for malware.
They don't really look for malware. They may do a little peripheral look or a little bit of a sniff test on it, but they don't truly look for 'em. So from that standpoint, all these attacks need to have a, a final, or not a final, but a most effective way to find risk.
Um, and the risk you need to think about when you're looking at software supply chain is malware, is secrets. And a lot of people talk about secrets and just finding secrets in your application or in your ecosystem of the application. That means, you know, talking about API connections, uh, and the secrets associated with those.
It's not just finding them, but it's actually prioritizing what are the things I need to care about? Cause we don't, again, work busy. Uh, we wanna work smart.
Uh, another thing that is hugely important is seeing what has changed in an application. Ding one release to another. 2 of my application.
Hey, malware is very difficult to find. It always hides itself. It's not as simple as malware dot d l uh, in your application.
You have to grip and find it. Hey, we're good. You have to see, okay, what has changed in this application?
These applications have become very compli, uh, complicated based on aggressive C I C D pipelines in addition to new kind of, not new, but you know, modern and, and very, uh, you know, fancy technologies, if you will, that everyone likes to talk about. Like cloud native development with a microservices architecture. So diffing of releases.
Uh, you also have one of the biggest ones is what the heck is this application actually doing? Youth threat model and application. You have an intended purpose for an application.
The behaviors are what it's supposed to do. The, it's supposed to actually process credit cards. It's supposed to allow you to buy something.
It's supposed to process a, an insurance claim. What are the capabilities or what are the actions it needs to do? Those are behaviors of the application.
So malware secrets, identification, prioritization, and differing, uh, of different releases and behavior. This is in my mind a complete S S C S platform, software supply chain security. So by doing this, you have the ability to say, Hey, what's changed?
What's new? Is this potentially compromised? Because you think about, um, uh, uh, the SolarWinds attack, it was a compromise of the MS build environment.
Circle CI was a compromise of secrets within the CI orchestration level. Three CX was a, uh, manipulation of a signed package post compilation. So when you think about that, there's a ton of activities that you need to do and why.
Reversing Labs is a software supply chain solution that is holistic, complete, and effective to prevent the next or any potential software supply chain risk. Uh, the, the, the analogy I like to use kind of here is you have all these activities and this is an hourglass. Uh, I do a lot of presentations and use, uh, days of our lives like sands through the hourglass.
These are the days of our lives like sands through the hourglass. These are the days of our DevOps process or our development process. So thinking about it this way, and I'm gonna do right in the middle here, we have the ability to look at this, um, uh, whatchacallit, the hourglass on its side.
These are all the development activities on the left here, and these are all the deployment activities on the right. So on the left, you're doing application security scanning on this, uh, uh, on the un compiled source code. You're doing, uh, software composition analysis.
You're, uh, securing the pipeline, the, the code repos, all these activities. And there's a lot of different things happening. And truly with modern software, usually everybody has a responsibility, but nobody understands the whole process.
And then you get through this whole process, you come to an inflection point. That inflection point is, and I'd like to use this as an example, a package. And that package is, it's like a Christmas package here or a present, it's a compiled artifact war file, dll, iso m msi, something that is compiled cuz for people that aren't familiar with software development practices, you have raw source code and its dependencies are all compiled into an executable that is then pushed to a cloud environment, uh, you know, a data center, a container except, uh, so on and so forth.
So you could try and do a ton of activities on the left. They're all very important. Scanning the source code is important for awas top 10 issues.
Software composition analysis is important for issues with, uh, the software, um, the open source packages, licensing issues, version issues, vulnerabilities in those packages. Uh, you have, uh, dynamic testing of a compiled package at runtime. You have, uh, SM a p i scanning of an application.
You have all these things you do. And then you basically have this deployment thing where you're worried about, you know, the, the, the cloud environment, the containers, uh, what is the runtime? How is this all working, is there a compromised post-deployment?
So this inflection point is where you can actually see the full picture in one stop shop, if you will. So you basically pick up the package, integrate it into your C I C D pipeline, or just basically push it to a solution to allow for analysis of that package. For these key areas that I just discussed, is there malware in this application?
What the heck does it look like? Are there secrets or in, or are those secrets, uh, potentially risky? Prioritize, do they touch information that is sensitive?
P i i type data a diff of different releases. So you can actually see like the heartbeat of an application in terms of changes, what files were added, what files were deleted, what files were changed, the behaviors of this application. If you're looking at the behaviors and it's like, this is not supposed to make this type of connection to this a API or open this port or restrict access to 4 43, things like that.
But this also gives you something that I haven't even mentioned on, which is the second real, uh, interesting topic from R S A and, and kind of in the industry right now. When you scan at this inflection point, you are scanning the package that's deployed. That could be something that's updated through normal updates to customers.
It could be through a release, uh, update release for your SaaS platform, your banking platform, your mobile app. The SBO m you create at this level is a complete SBO of the package itself. A lot of times people talk about s bm, everybody throws SBO M out, we do sbam, we do sbam.
They're just creating a list. And what is that sbam of? Well, is it just s e looking at the open source code?
Is it an SBO m of just, uh, pieces of the application Doesn't include all the third parties, all the homegrown code, all the open source code. So, you know, the executive order recently talking about, um, self attestation with an SBO m the SBO M has to be complete and it has to be in a, a normalized format. Uh, I'm a big fan of Cyclone DX from O os as uh, um, sbam format.
But, uh, S P dx I believe and S W I D are two other formats that are very much, uh, standardized in the industry. So kind of to wrap and to have this conversation, software, supply chain security is vitally important to anybody developing either applications or software. And I kind of delineate that.
I always like to say that people hear software and they think of Microsoft or they think of, uh, someone developing a I S V, an independent software vendor developing software as their business. Yes, software supply chain is very important to those individuals cuz that's what they do. They develop software.
But pretty much in this world, every company is a technology company. So a bank, a retail shop, everybody uses software and those. So the software they create is for facilitation of their business.
The apps, the order management system, the banking app, the retail app. So thinking about software, supply chain security, it's very important to not, you know, think about just developing of software. It's developing of anything.
And every company is a technology company or a development company in some way, shape and form because they rely on the software. So again, reversing labs. We are the software supply chain in malware analysis, threat hunting company with the largest reputational database of malware that's private in the world.
And we are helping some of the largest organizations in the world solve the problem of software supply chain security. Hope you enjoyed the presentation. Thank you for taking time outta your day.





