Securing the Integrity of Software Supply Chains – Danny Nebenzahl, Scribe Security
Scribe Security CTO Danny Nebenzahl discusses in-toto, a framework for securing the integrity of the software supply chain. It uses an evidence-driven concept to demonstrate and justify trust in supply chain artifacts. Daniel describes how this framework can be expanded and implemented to provide evidence-based security, visibility, transparency and control over the software supply chain.
Transcript
This is texturing TV. Hi, that's a great pleasure. Being joined by Daniel nebenzal.
Who is CTO with scribe security. Welcome Daniel. Thank you very much.
Great being here. Great to have you. Hey, tell us a little bit about yourself and then tell us about scribe security and we'll get into the whole soccer supply chain security topic, which I know is near and dear to your heart.
yeah, so I started my engineering career in the academic reserve of the idea and my military career was divided into two distinctive Parts first was developing cybersecurity appliances. And the second was researching them and finding their flaws, but it was a lot of finding my own bugs years later. and I had the opportunity to grow along with the growth of the cyber security Arena like from the days that cyber security was encryption or a firewall to the incident response and organizational parts and policies and I had the chance to be involved in many initiatives in this area.
And a few years ago left the Army. I had a opened a consulting company and got involved in some. Like a physic and interesting like tough problems that needed to be solved and and from there emerged also a scrap security where I'm dedicated today.
Excellent, very nice. Interesting. You got to vulnerability test or pen test your own product.
That's gonna be a lot of fun. You learn a lot of what you did and maybe things you can improve going forward, right? Yeah.
Sure sure. So let's talk about satara supply chain security. You know, it's a very hot topic you see a lot of you know people talking about it articles about it companies like yourself tech companies up and coming and existing as well a little bit about What you see happening in Market?
Why why do you see it's such an important topic for whether it's software teams or secure teams or both? yeah, so I see like two main reasons that the software supply chain is getting focused. Basically, it's because it's a it's more attractive attack vector.
And the reason it is more attractive. The two-fold first is that many organizations are much more secure than they were in the past. So attackers need to get to find new ways to get in and in many cases of attention is given to production and to the services that accompany exposes and much less to the programmers.
The programmers is a developers, they need to deliver as fast as they can and and in many cases the security skips them and is the security focus is on the in the services and the second aspect is, you know, poisoning the well So if you know if an attacker wants to attack all the customers of I don't know some Bank you can do it one by one, but that's not fun. But if you attack the app developer and whoever downloaded the app is infected. Okay, that's also fun.
It's also very effective. Mm-hmm. Okay.
Well, yeah, absolutely. It's I think we've all come. I mean you can talk about whatever vulnerability from open source or third party libraries or packages or containers and you know so many, you know, so many attackers now that we didn't necessarily put as much emphasis on as well as our own court code as well too little bit about the approach that scribe uses.
How do you how do you make yourself part of the development software development process? They'll start with that kind of concept. So the concept is like suppose suppose you are.
Newly born repo to be a product someday. So we tell you, you know. We don't really trust you and we assume you're not stress worthy unless you can prove otherwise, but we are generous enough to give you an empty folder.
Please fill it up with evidence to your trustworthiness and in the checkpoints on the way be ready to demonstrate your trust and these evidence can be the softer the security posture of your repo or if you get type of account, it can be the s bomb of the sources of Islam of the build process of the final artifact. It can be data collected from your image registry from developer workstations, and so forth and given enough evidence one can is approve or demonstrate why and justify why the final artifact can be Be trusted. No, it went through the right processes.
It hasn't been modified. In an unplanned way on the way. Yeah.
So that's the approach the way people are contributing to the repository. That's where the here's the folder you need to drop in a certain list of things that provide whatever Providence about the software that's being contributed. Is that correct?
I'll think yeah, the repo is evidence Source, okay that we can take at the stations that from and we store at the station either in our fast platforms. Are we have in a solutions for on-prem and an immature or some of the system? We have a few solutions for that?
That's like more deployment issue. Okay. Yes, we have your own artifactor directory or a store.
or that information Yeah, and to collect this these evidence essentially there are two ways that that we support either by accessing apis of platforms of Jenkins API or the circle CIA Pi or whatever platform. It could be and also in in pipeline tools that are deployed, you know the same way you would apply any tool in the pipeline either get up actions or CLI tools that are combined in the in the pipelines and in some cases we can also make it easier through automatic pull requests that make life easier to whoever is going to deploy these sensors. Okay, very good.
So what you've collected this information, then you're producing an s-bomb from it. What all are you doing with that information? So we are doing a we're providing a few values as so first and Islam is both saying that to station and both an artifact we can either.
Just collect s bombs and then makes them accessible through our platform and and do some analysis of them vulnerability other open source intelligence and that we that we add on to the s-bomb. And there's a policy aspect. Okay calculating evaluating policies over the data collected as bomb is not enough to evaluate ssdf as a software that you need other data points, which can be collected from if he takes the South example, you need pieces of security posture of the GitHub account.
You need a provenance and object which could binds and artifact with the sources and the build the script and so dependent depending on the data that can be collected. We can evaluate various policies and then user can get either notification that some build did not pass the policy test or a the user can decide What is the bar that artifacts needs to need to pass in order that he will use these artifacts? We also have an admission controller.
So this can also be a a breaker, you know something that will nothing not to enable deployment of products that have not passed through the desired process. In addition to that we we support sharing so as bombs and and a sense all of attestations and the policy results can be shared Downstream the software supply chain. So as a consumer of software, I can also gain trust in.
After artifacts that we are being provided to me from subcontractors. And I also demonstrate to my prime contractor that I complied to his requirements. Mm-hmm.
Very good. So the policies that you're talking about are those predefined in scribe or or maybe a set of templates to use or do you define those from scratch? Each organization does something different?
The currently we support a predefined set of policies. But the underlying technology is based on a Opa and Rigo. So it's very flexible.
And in our roadmap, we are planning to open it up to customers so they can also modify to find their own policies that can imagine that I mean having something to start from is great. Right because you're not like what do I do starting from scratch, but also I would imagine some organizations do have the need to customize that a bit. So tell me I'm interested in as you've worked with customers and and had product and Market are there particularly industries that are adopting as moms and some software supply chain more quickly, maybe government or Finance or or is everybody kind of all going to it at about the same pace?
So as we see it, whoever is more regulated is a is more active either. They already got requirements or their hearing about their friends that Dr. Requirements.
So they're starting to get ready and smaller companies or companies that there are hardly regulated are naturally. Let's interested in the state. It seems in the in the US where I'm based.
There's sort of two drivers we talked about regulation. There are industries that are more heavily regulated like healthcare and medicine and and medical equipment Finance. But also the president did in an order or a plan of what you have to do to provide or sell software to the government, which is both Prime and then all the people who Supply to them, right?
So there's a whole supply chain if you will of companies that now are putting that process together in the attestation. So just because you aren't the prime doesn't mean this doesn't affect you right you're if you're a downstream player you you have to provide that information to the folks who are required to do it directly through regulation. You see the same kind of thing.
Sure. Sure, exactly. Yeah.
Great. Well, you know development environments the the number of tools that you could potentially sport are very broad right and not to tell you that I'm curious about the tools that you selected so far. I noticed your supporting bit by good and get and and Jenkins and Travis CI and circle CI that there are others.
what's what's kind of your roadmap thinking about are you planting on more cicd tools down the road or you're looking at other tools in the tool chain, like maybe deployment for Docker or Spinnaker or something else You're currently we are focused on the cicd and environments and basically. I'm putting our efforts towards the demand that we get. Well cicd is the starting place for devops.
I guess it should be for software supply chain to as well. But Daniel has been a fantastic talking with you. Wish you all the best.
Hope you'll come back and tell us more about what's happening at scribe is things evolve and you know, you're continually work with customers for folks who want to check out your stuff. Do you have a free account or download or something developers love to interact with right tools and check them out themselves. How can they do that?
com and through our site. There is a free tier anyone can try it out and we would appreciate any feedback. Great.
All right. Definitely. Check it out.
Thank you. Again Daniel Daniel nebenzal. Who's CTO with scribe security.
We'll see you again soon.