Forrester SCA Wave – Mike McGuire, Synopsys Software Integrity Group
According to a recent Forrester report, 78% of codebases today are open source as organizations increasingly utilize the free code in their software. However, open source code carries inherent security risks as it is developed by third-party sources. Security leaders rely on software composition analysis (SCA) tools to help mitigate the security risks and gain insights into a company’s open source code. In this interview, we sit down with Synopsys Software Integrity Group’s Senior Software Solutions Manager Mike McGuire to discuss the findings of this year’s Forrester SCA Wave and how SCA tools can ensure code security and quality.
Transcript
This is Textron tv. Hey everyone. Welcome back to Textron tv.
Hope you're enjoying today's show. Our next guest comes to us from the good folks over at Synopsis, and he's gonna tell us a little bit about them as well as himself. I want to introduce you to Mike McGuire.
Hey, Mike, welcome to Textron tv. Thanks, Alan. It's a pleasure to be here.
Nice to have you all. Mike. So you know, before we jump into Synopsis, let's hear a little bit about Mike.
Sure. So, um, I'm just, uh, with Security Solutions here at Synopsis. Um, and what that means is I work with the market to understand, uh, some application security issues, uh, talk about any roadblocks or future problems that our customers in the markets are running into.
Take it back to synopsis and, and work with our teams to put together solutions and then turn right back around and try to put it into the hands of, uh, of those same folks. Feeling that that pain point. I've got a background in software.
I studied software in, in college, uh, cut my teeth as a developer for a few years before moving more towards the, uh, the external facing and the, the market and strategy and, and product development roles. Um, so I've got, uh, about coming up on 10 years of software experience. I've always found it, uh, to be a pretty, uh, unique and always a very dynamic field.
So, um, I'm, I'm really happy to be here, fan of, of everything you put out. So it's, um, it's a, it's an honor to be here. Thank you, Mike.
It's an honor to have you on. You know what, most of our audience has probably heard of Synopsis. They may or may not be a hundred percent sure of everything that Synopsis does.
If you wouldn't mind share with the audience a little, kind of, you know, just a synopsis background, Dick gladly. Um, so folks that are familiar with Synopsis, you might have heard of Synopsis in the context of E D A or electronic design automation, uh, automation, which is chip design or board design. Um, actually I started off as a developer in the e d space and found my way to Synopsis and way back, it's probably about 10 years back now, synopsis started to expand beyond just the silicon as aspect and into the software and application security, a aspect, uh, with a few acquisitions 10 years later.
Now, here we are with a full broad application security portfolio with static analysis, interactive analysis, dynamic analysis, and of course software composition analysis, which we're here to talk about today. Sounds a little bit about like Grease Lightning. That's right.
Not dramatic. Yeah, yeah know. Um, A little Grease lightning.
Yeah. So software composition analysis. Look, this is a term came on the scene, I'm going to guess six, seven years ago.
But really what we're talking about with SCA specifically is open source and the security of the open source components. And it's not just open source applications per se, but you know, in a world where we, I, you know, I call it kind of app by Frankenstein method, right? Where you have all of these components that you kinda stitch together to make your app, you know, 70, 80, 80 5% of the code within an application today may wind up being open source components that have been, as I said, glued in, stitched in, called via api, et cetera.
And, um, you know, keeping track of those open source components and checking those open source components for vulnerabilities and sometimes even extending into the licensing use, you know, usage under licenses of those open source components has become a real industry, hence sca, right? Yeah. Software composition analysis.
Yeah, absolutely. And I mean, you hit the nail on the head, right? I like to say that software is no longer built from scratch.
It's assembled from mm-hmm. All bunch of bits and pieces, and the glue is the proprietary code, which is fantastic, right? Organizations get to spend a lot more time focusing on innovation, right?
They get to focus less time, reinvent, venting the wheel, more time focusing on what makes their products and their offering different from all their competitors. Sure. Um, and obviously that's blown up, right?
We do a lot of research here of, uh, about open source usage at Synopsis. Outside of Synopsis. We have an audit group that looks at code bases.
So we have a really good understanding of how modern applications are using open source software. And, and you're right, we, we find that over just over three quarters of any given modern application or the average application is totally open source software, right? There's almost 600 components, open source components per average application.
So yes, I mean, the scale of open source usage makes tracking down and, and dealing with license obligations a challenge. It makes staying up to date on all your patches and, and all your vulnerabilities a challenge, right? So this is where s e A comes into play, right?
This has outpaced any manual tracking efforts, right? We Oh, yeah. All know that developers, right?
They, they have a job. It is to develop and meet a, a feature guideline and close a ticket, and they'll do it fast and, and, and do it high quality. So they really don't have that overhead time to sit down and track all these manual open source components, uh, that they're using and all the patches and all the vulnerabilities.
So s e comes in and automates that. Yep. com in addition to Security Boulevard and Cloud native now and so forth.
So, but this is a classic kind of shift left DevOps automation kind of thing where, look, I, I don't want my developer to be a security professional, but developers want to develop quality code. And so if we can enable them to develop higher quality code by, by automating, you know, s c a and then creating feedback loops to let the developer know, Hey, we got a problem here, or this is an old version of that component, or, or what have you, right? You, you're making their, you're making them do high, you know, develop higher quality code without a huge hit in their productivity and time, right?
Because at the end of the day, developers want to develop. Now, there's been sort of a, a gun to the head of this market over the last two years, or maybe it was three years now in terms of software supply chain security and the whole SBO thing, right? A lot of people say, Hey, what, I don't get the connection between open source and software supply chain security and SBUs.
But again, when you go back and say, a software is made in factories today and it's assembled rather than written, you understand that if all of your third party parts, you know, using the, the car maker analogy, if all your third party parts are open source, or most of them are, you need to have a bill of materials, you need to have that software bill of materials that's bomb, um, to understand what those open source components are, what their dependencies are, and again, another crying need for sca. And I'm, I'm wondering, you know, anything happening with synopsis around SBOs and software supply chain security? Yeah, absolutely.
So, SBOs, it's funny, SBO has always been a part of a software composition analysis product. The end goal was always scan an application, scan artifacts, uh, scan any input or output from a repo and come up with a list of dependencies, come up with a list of open source components and even exported somehow, right? Like, uh, C S C S V for, for example.
Then SBO enters the scene from a lot of these software supply chain attacks. We saw the executive order on cybersecurity, which mentioned software bill of materials. So this is now very top of mind.
So the great thing is s c A solutions and synopsis in general, we were very well positioned to flip a switch and export these findings into a classic or a compliant sbo, right? That is in compliance with, uh, and aligned with s BDX and Cyclone DX formats that does have the required fields and information that certain industries might require. For example, F D A requires specific fields like end of life for a component, right?
These aren't gonna be on every single sbo, but you do need a tool that you can configure to add these fields or not have these fields cuz maybe you have a consumer who just use that as additional noise and you want to cut that out. So we do enable teams to specify that, generate an SBO and export it. Um, for general software supply chain security, as you probably know better than anybody else, SBO is about that much of software supply chain security.
It's just the visibility aspect. Even then an open source SBO is one subset of a entire sbo. So what about software supply chain security?
Well, SCA again, puts us in a fantastic position to address those needs because like we mentioned earlier, three quarters of a software supply chain is open source software. So if you can get your hands around that, around your dependencies, and not only at what's being brought in, not only what's on a pom not XML file or a package j s n file, but what's in your container images, what's actually gonna be making it to runtime. If you can get your arms around that and then understand what's sort of vulnerabilities, uh, what sort of history or reputation those components have, then you are well on your way to securing the vast majority of your software supply chain.
Now there's other aspects, there's other challenges and areas of risk beyond known vulnerabilities and other aspects beyond open source. But again, this puts you in a really good position and this gives you a really good start software composition analysis does, and that's absolutely exactly what we're building into our products. Very cool.
So Mike, we can't go three feet today without tripping over some AI version, some story, right? Of course. What, what role here do you think?
I mean, look, ai, there's a good side of AI and there's a bad side of ai, right? It could, it all depends whose hands it's in and what their aims are, but in my mind, there's things we could use AI for to make our SCA more effective. Sure, sure.
More Automated, more, you know, smarter if you will. Um, what's synopsis, any, anything on the, and don't say anything we're not supposed to talk about yet, but any, any kind of developments there for on, on this? Sure.
Yeah. Let me, so I'll, I'll just talk about AI and, and application security in general. And, and you're right, there is a good side and there's a bad side, but that's the same for everything.
I remember when open source was getting big, there was a lot, lot of naysayers, like open source, no good SCA was a way to keep open source out of your applications, whereas the correct approach is, this is coming, this is going to be part of business, we just have to learn to live with it and harmony, right? It's just a new risk that we have to track down and learn, learn to live with. Um, and then of course we can turn around and, and use that, right?
Of course, we even use open source in our software. Uh, so it's, it's the same situation. So there's two sides of the coin when it comes to ai.
Um, I have to, I I I would be remiss if I didn't mention the, Hey, what about AI generated code? Are we addressing that? Yes, right?
There's AI generated code and there is considerations of what's the security of it look like and what are the license or the IP obligations. So if you have AI generated code that comes in and it, it does match an open source component, we're able to detect those snippets and match it back to the component and advise you on license obligations. When it comes from the security aspect, we treat it like any other open source or, I'm sorry, any other source code.
So we actually analyze it and we can tell you if there's any security weaknesses, but we do that with static analysis. Now, the heart of your question is what are we doing? How are we using AI?
Now, from what I can imagine looking forward to having a little foresight is that AI and software composition analysis, it's going to be looking at behavior of software, it's gonna be looking at behavior of dependencies, learning what historically matches up to be malicious behavior and alerting on that. Um, so if we do have a open source dependency, if it's net new, take a look at it, take a look at not just the reputation of it, its security reputation, not just the maintainer history and maintainer reputation, but also maybe ch trends and changes over time, the updates and the new versions to this component and what it's doing, what, how the behavior is changing over time and try to analyze if that matches known malicious behavior. So that's for a net new, for a component that we've been using for say, years still, right?
4 is coming out. Let's take a look at the functionality changes and the behavior differences. And if it's big than we should probably look a little bit deeper into it.
Hey, this is calling a remote IP address that's a little fishy, uh, that's been known to lead to malicious behavior. We should flag this and go through and review it. So those are just a few ideas that I can think of.
I think that's the direction that is gonna be moving in, but taking that historically just takes a lot of compute power. Even if you wanna look at it manually, it's, it's really hard to wrap your arms around because it's so much data and it's so much analysis and as we know, that's what machine learning and AI is just fantastic at. Got it.
Love it. Good stuff. Hey Mike, we're almost outta time for people who, who out here saying, you know what, I, I want to know more.
I'd like to understand more. What's their best path to engage with synopsis on this? Sure.
Uh, I would highly recommend you reaching out to our, our website. Um, we have tons of information and content there. We have prerecorded webinars, we have plenty of written literature, we have blogs, we have methods for anybody to reach out and speak with members of our technical field or product management.
com and you can find anything there. Excellent, man. Did a great job.
Mike, I want to thank you for coming on Techstrong TV today and, and talking to the last ca with us some of the newer things we, you know, we're all learning about and thinking about around SBOs and software supply chain and now of course AI and how that affects stuff. Uh, keep up the great work and come back again soon. Thanks for having me, Alan.
All righty. Mike McGuire, senior software solutions manager and Synopsis Software Integrity Group here on Techstrong tv. We're gonna take a break.
We'll be back in a moment.