CodeSentry – Vince Arneja, Grammatech
GrammaTech’s newest product, CodeSentry, is a supply chain security platform (SaaS and On-prem) which can scan production applications (binaries and beyond) to produce SBOMs, identify associated open source vulnerabilities, license information and a lot more.
Transcript
This is texturing TV. Hey everyone, welcome back to techstrug TV. I want to introduce you to a gentleman.
It's a first time here on Tech strung, but it's not the first time we've covered the company. It's gramitec. We're gonna talk about that, but let me introduce you to Vince.
Our nature Vince is a chief product officer CPO at Grandma Tech and hey, Vince, welcome to Tech strong TV. Thank you Alan. It's a pleasure to be here.
I've watched many of these and I'm excited about participating finally. where where excited to have you on here so You know Vince some people in our audience may have heard of grab attack. It kind of it's in our sweet spot right of abstract and devsecops and so forth, but not everyone.
I'm sure has or maybe they have and they're not sure would you mind if we go kind of fundamentals at first and give us a little company background? Yeah, absolutely. Absolutely.
So it's a grammatech has been around for a while 20 plus years. It really started out as a company spun out of Academia Cornell University of Wisconsin couple of professors got together and decided to formulate a company that would do a lot of research for the government, you know with DARPA o&r those kinds of research agencies. And so really that's how the company formulated and eventually as they started to do this research.
They started to create a product Division and a static analysis capability was born called code sonar and really started to lay the foundation for the uniqueness that Grandma Tech has historically brought and still brings which is around application security scanning source code binary code and we've kind of built on that the last few years since myself and a few others have come on board the management team. Actually, I'm gonna talk to you about that in a second. But before we do, why don't we tell people a little bit about your background?
Sure. Yeah, so I'm kind of a cyber geek. I've been in cyber security since 2001 been in various aspects of cyber primarily application security.
I'd say of the 20 plus years in cyber. I'd say about 14 or so. We're in application security including of course Grandma Tech previously.
I was I was at ARK sand where we did a lot of in-app protection and protection of mobile apps. As you know, the application became the new perimeter back in 2011, 2012. And so Yeah, I mean I've been in cyber a long time and my role is really to head up product.
So in summoning vendors where I've been involved with it's product management product strategy in this particular case. It's also product engineering and other facets of product. And as you might have seen with a lot of your interviews the CPO role has evolved quite a bit.
It's now not just encompassing product management. It's it's really encompassing all of aspects of product and that's kind of how we do it here at Grandma Tech. So it's been fun.
I've been here three years. We've really sort of turned the company into a product focused company versus a research only company. We still do a lot of research, but it's a good blend and and I'm glad to be part of the team doing that.
Absolutely, you know look that's one of the reasons we started the whole digital cxo website. We would you know property we started because of the changing roles of yeah, the CP are the chief product or we see a lot of organizations where the cpos the CTO as well. Yeah Chief technology officer actually runs product.
Yeah and sometimes engineering as well. Yeah. Exactly.
It's one in one head. Yeah. I've seen that over the last five or six years the CPO role.
It's kind of taking over engineering product management really looking at the capabilities that you need to build from an Outsiders perspective because the CTO historically has a very technical lens and it doesn't always lend itself to what the customer or the market needs. And so I think that's the shift. We're starting to see a little bit we'll see if it continues but that's what we're currently sensing.
No that Look, there's that then there's this whole Chief data and chief digital officer. And this is why we call it cxo. It's it's very different kind of thing.
Hey, I got a I know we want to talk about this new product coming out of Grandma Tech, but I got into a conversation the other day with a CEO of a company You know was around this whole shift left shift, right? When do you scan? What do you scan went and look?
Apex scanning and shifting that left has been sort of the bread and butter the heart of the step-secops movement, right? I also in 2001. I found it a company still secure out in Colorado and I think it was in 2003.
We launched a vulnerability scanner. But that was to scan stuff after you know in production right? I was to scan your assets out there your service your you know your footprint.
A big thing apps that came and the idea of scanning pre-deployment. Wow, really? Good mine, you know my blower.
Yeah, and now we over the years, you know, oh watch everything. We've seen absec really grow up. You've got static.
Standing or static code analysis as you mentioned, you've got software composition analysis right open source stuff. You've Dynamic scanning and then a lot of vendors have their own little initial. you know initials for the kind of scanning they do but this gentleman yesterday said that doing Dynamic scanning.
pre-deployment was just wasteful. Yeah. interested agreed disagree why well, so I mean these are subjective views, right?
We all come from a different lens. If you will we're looking at it differently. I mean to me different types of applications lend themselves to different types of scanning we primarily play in sort of the embedded Arena where you're talking about Automotive Aerospace government and those kinds of applications are more running lower level code and so static analysis and and software composition analysis.
Absolutely Paramount dynamic or interactive doesn't really apply to those types of use cases and those kinds of applications. Whereas it obviously does when you're talking about, you know, web applications and things of that nature. So I feel like in certain it really comes down to the Computing platform and the application that you're you're creating and the target audience and what which of those different types of sort of AST capabilities is primary versus secondary.
And so I think it comes down that To me is really the right answer versus. Hey, this one technology is great regardless of use case or technology or beginning plan for black or white exactly, right? Excellent.
All right. Hey, Vince, I got it turned over the rest of this interview to you. Now.
You've got some exciting news to tell us about gram attack and go ahead. Yeah, absolutely. So so, you know as somebody that's in this space, you're you're well aware of the sort of recent I'd say in the last, you know, 18 months or so supply chain security attacks, you know solar winds we had obviously a big effect there from you know with sunburst and and that whole Solar events event we had cut which occurred last year as well.
There was a different malware scanner. So all these different sort of known so supply chain and security attacks that took place in the last 18 months have led to more of an emphasis right? We've seen the government step in with the Theo 14028.
Yeah, we've seen follow-up from that that's actually actionable and and tangible now after that came out in May of 21, and so what we're seeing is In my opinion, this is just my two cents. We're seeing that zero trust mindset that has the last 10 years been applied to network security or Cloud security. We're seeing that zero trust mindset not necessarily architecture, but mindset apply to applications and so obviously to your point just now.
When you're building your applications, you've already shifted left or you're planning to in order to you know, have security take place right in the the snippet of code that the developers coding. But what about the third party applications? What about the supply chain applications that are critical part of your ecosystem that you've kind of blindly trusted.
Well, it seems like at least from the things we're seeing and you know talking to customers about that that mindset is Shifting to a zero trust as well and that I know this vendor I trust them but I'm still gonna make sure the code is very is exactly and so in some cases you trust a vendor you still want to verify in some cases, you know, you might have a smaller division using an application that you don't even trust and so you want to do verification on that. So we're seeing that that's kind of called, you know, high risk profile application. So we're seeing that mindset shift to where customers, you know large Fortune 1000.
Companies are looking at this and saying we have to do something about this not just a code that we're writing. But let's put a plan in place so that we're less susceptible to supply chain attacks. We can proactively get ahead of what the vendors are giving us and you know, take it from there.
So look this whole exponent thing. Yeah, right is blown up as a yes. It's right.
Yes, the guy out of the government Allen Friedman. Yeah. It was a Sonora says, he's like the father Yes.
Anyway father. Yeah. Yeah.
No you like Johnny Appleseed. You're right planting. That's Bob kind of stuff all over the place.
I thought this was sort of something that that's bombs are supposed to be helping with. Yeah, you're right. It's definitely becoming a key element of software supply chain attacks and the things that you can do with that.
We're seeing more and more vendors pop up that you know are doing something about either creating an s-bomb or managing an s bomb, you know, or aggregating a bunch of s-bombs and then allowing for you to you know, submit that together. So yes a software bill of materials is critical absolutely Paramount sort of foundational if you will to software Supply Chain management and security but that's just one element of it. Right?
So whether you're creating it from your own code whether you're trying to create one from third party code, that's the that's the initial process, right? And so then what do you do with it? Because it's remember as Alan's, you know echoed for over a decade and that's bombs just an inventory list, right?
It tells you what's inside just like an ingredients list, but it doesn't tell you what the next This right doesn't tell you what's vulnerable within there or what's actionable that you need to address right away. And so it's it's a multi-pronged process to really get your arms around the software supply chain security aspect of things, but I completely agree you can't act on anything until you know, what's inside which is what an s-bomb, you know helps you really do whether you're doing one yourself or you're getting one from a vendor that you can then, you know to your point verify. So, you know, there's a whole.
We could probably have a whole full day discussion on this what s bombs and how to work how they should work all of that. I want to hear more about this new grammatech platform though the world. Yeah, I think that's true.
What sorry got in that spot big deal. How are you helping me with that? Right?
Right. So so we've launched so so as I mentioned I joined here about three years ago, and we had a sort of a legacy product code sonar that's done really well in the static analysis space that investment for us continues and and you know, because the shift left that product's getting a lot of adoption as well, but we decided to expand the portfolio and launch a new capability based on some work. We had done with DOD CIO office back in 2016.
And so we really leverage the basis of that and we created code century and code century is really about creating an s-bomb identifying open source components vulnerabilities and educating the customer on what's inside. pause third party applications So obviously their source code SCA and you know, we've seen that space evolve and mature and become more mainstream, you know, black duck and many others and but that's really applicable to the source code that you're building. What about the binaries that you're getting from your vendors or your tier one tier two providers.
If you're an automotive company, what about applications you're bringing in house that you're going to deploy to a hundred thousand workstations. How are you enabling any kind of trust within those are you just looking at a spreadsheet with the B Sim, you know output from from the vendor. Are you now gonna look at their s bomb and just trust that so what code Century does is it takes various types of binaries our archive files.
Zip files exes dll shared objects. You name it? It covers desktop mobile embedded web firmware.
And so all those different type of input files can be ingested by code century and the very first thing Does as it analyzes those files individually within an archive is it tells you what open source components reside within the exe for example, and so that's step one right step two is once we've identified that we tell you what version is is part of that open source component. Then of course, we are equipped now to tell you what cve's are associated to that vulnerabilities tied to let's say open SSL, you know one one three J for example, and so all of that data that we can give you is all tied to our ability to be able to dissect, you know, different types of binaries and now you get a report at the end of this and that's bomb being an example of a type of output to where you now have visibility to what's inside, you know an application that you're whole organization is using historically you've either dependent on the vendor and Trust Them or you've had your pen testing team manually hack away at it for weeks or months using a variety of Open Source tools and things they've created but what we can do is we can actually take that application and we can go through it and tell you anything and everything that's open source. What is it?
You know, what version is it? What licenses is it Associated to GPL or GPL and then obviously, you know vulnerability data Associated to that. So that's that's really the uniqueness of this tool compared to others in the market.
But at the end they all those tools are a key part of you know, the the shift that's occurring for software supply chain security, you know capabilities. Absolutely Vince. Where where is this?
In terms of available to the public. How did they engage? Yes, we launched it last year.
We've already seen some pretty significant adoption, especially in in government and and a few other verticals that you would think, you know have to know what's inside those kinds of applications the whole notion of of trust but verify, you know, really applies to certain verticals right away. And that's really where this technology is resonating. So, yeah, it's been out for about a year.
We just launched a version last month which is why you know, we thought it was good to get in with you guys here as an example is now we cover all those different Computing platforms desktop server or mobile web embedded firmware different types. And so because you could be an embedded customer, you know, you could be a customer that just wants to scan Cox applications that you're you're acquiring before you deploy them. We have government agencies that are working with vendors and they want to scan Gods applications government off the shelf.
We have we have software vendors that are building a game or Or you know complicated system. It takes a long time. They can create an s-bomb for what they're building but it's kind of a mess because it's taken them, you know months or years to build that whereas if you use a tool like this at the tail end of your stlc now, you get the output of that right away, you know, as far as open source components versions vulnerability information license information remediation information.
We even go far as to sort of things like social risk score. So is this vulnerability being talked about in a social setting right and different types of social settings? So a lot of things that we provide visibility to that you typically don't have I love that man.
Hey for people who were running low on time, but for people want to get more information, Vince should they just go to Grandma Tech Comm or where was in the website? Yeah, I mean Grandma Tech Comm. We've got a couple products listed.
There are code century is the product that this interview is about and so that really is the product that helps you understand your risks the software supply chain perspective produces s bombs for you know, and applications production applications binaries, whatever you want to call them. And so yeah, it's this is a very Nation space. So there's a lot of Education still occurring, you know, a lot of people in your audience probably don't even know what an s bomb is but so it's it's early, you know embryonic as we you know, we know some analysts like to call it but it's it's Gonna Catch Fire and to your point.
It's it's kind of all the rage and a lot of these conferences and you know, so on and so absolutely Absolutely. Hey, I just put you on the spot spell grab a tech for me. com.
That sounds like folks. That's very rich. Good luck with this.
You know, I know it's your first time on but don't don't be shy come on back. Keep us posted this whole software supply chain. I think 2023 and we're gonna be you know, we put on a show in January every year called predict we talk about what what the big stories are coming up.
I think software supply chain is gonna be a big part of 2023 our own Tech strong research team will be talking about it. Maybe we invite you back for that. Keep us posted and best of luck with grammatech.
Absolutely. Thank you Alan and look forward to our next time together. All right, take a break.
card to be right back