Brian Roche, Veracode | RSA Conference 2023
Brian Roche, chief product officer at Veracode, discusses Veracode’s new AI-powered developer tool, Veracode Fix. Veracode Fix suggests remediations for security flaws found in code and open-source dependencies.
Transcript
This is techstrong tv. Welcome back to R S A C 2023 in San Francisco. Here we are, we're actually filming from the Marriott Marquia Special Studio, uh, in addition to broadcasting on, uh, broadcast alley in Moscone West.
So, lots of great conversations, great people. We're continuing that theme. And, uh, very much so with my next guest who is Brian Roche.
Welcome, Brian. Hey, how are you? Good.
Good to See you. Good to have you. Thank you for having me.
It's a privilege to be here. You bet. Brian's cpo, uh, with, uh, Veracode and I've had some really exciting news, uh, but it's a great space to talk about.
I mean, we're all interested in sort of the whole software lifecycle security and AppSec and melding that all together and how to do that well, So, and we have some time to unpack it all too, right? We do. It's great.
We do. So tell us about yourself and for folks that may not know Barcode. Yes.
I've been the Chief Product Officer at Barcode, and, uh, that means I lead cloud operations, engineering and product management, of course. And, uh, I think what's what I love most about what we do is we really focus on user feedback and AB testing. And a lot of what we've built more recently has really been focused on early access programs and feedback for users.
And it's, it's so rewarding for us as a company to, to look at our users, give us, you know, both positive and negative feedback, but be able to iterate quickly and incorporate that into the products that we're building. Mm-hmm. And, and one of those this week is our a vari code fix announcement.
Mm-hmm. Last quarter we released Cloud Native Security in the form of containers and infrastructures, code and secrets detection, which is really great and, and, you know, obviously super important, but, uh, vari Veracode Fix is really, really our big announcement. And that was, it was so important to get that right, because we talked about our, our respective roles.
And, you know, you look at the developer, it's, it's a tool and technology aimed at the developer, which produces, you know, security fixes or recommendations for common vulnerabilities that they see in their code. And, you know, as developers, right? If, if you get that wrong, right?
Mm-hmm. It's, you know, Get one shot, Right? You get one shot at that, right.
So it was really great to get feedback, and it was really great to implement some new technology, but in a responsible way, because I think there's a lot of fear around AI and ML and how it's going to either positively or negatively affect everything that we're doing. So, mm-hmm. Yeah.
Super excited to be here, and, and it's great to talk about what we're doing. It's great to see all the buzz. I mean, I've lost my voice as I'm sure you have too.
It is our third, fourth day during third, fourth day. Yeah. How long you been doing this?
This Week? It's like the Twilight Zone. You know what day you're in anymore.
It is the conference. It is the only thing that's great about Veracode, and we've been working together through techstrong and, and, uh, our companies over a number of years. You know, we, we've kind of gone from this thinking of application security as a code scanner, right?
Mm-hmm. It's sort of the SaaS part of the industry. And, and VER code's really a platform.
I mean, you've gone to the cloud too Yeah. As well, but it it really comprehensive across many parts of that, you know, infinity cycle, if you will. Yeah, Yeah.
Yeah. I mean, I think that you, you know, the whole world has changed, right? I mean, we, it's so much has changed, but yet so much has not changed, right?
Developers are now relentlessly focused on speed and, you know, you look at the DevOps movement, right? We, we've seen how that sort of transitioned over the past, you know, decade as an example. I went around the world and talked about, you know, what Eric Reese, uh, put out there and, you know, the lean startup and mm-hmm.
We're starting to see this movement now where developers are saying, I don't want to be an operator. And operators are saying, I don't wanna be developers. Right?
So I think we have to recognize that as much as organizations are striving to achieve DevOps or DevSecOps or embracing extreme programming or XP like we are, I think there's still the notion that software can change in, in any step of the sdlc, and that includes production. And we've gotta think about it. How do we make security pervasive without being invasive?
Mm-hmm. And how does it become an enabler? And you said it right up front.
So our mission has always been to be the software security platform that brings together developers and security professionals so they can deliver best in class tools to developers like static and SCA and dynamic, which are crucially important, uh, so that they can go and deliver their software quickly. But, you know, the world has changed and, and those technologies are largely focused on finding vulnerabilities. And you know, I don't know anybody in the industry that says, you know what, I'm good.
Like, I've got no more tech debt. Like, we're, you know, we're gonna go home early today, we're gonna go, it's, it's called day zero. Yeah.
Start When you start, start your project. Start. Yeah.
And so I think that the problem is that everybody has alert fatigue and everybody has this, you know, insurmountable tech back security backlog that they've gotta burn down. Mm-hmm. And so fixes is really important because we're making it easy for developers to not only identify common vulnerabilities, but proposing fixes to them that they're both intelligent, but align and conform to the standards that we set for ourselves when we released, you know, static code analysis many, many years ago.
Mm-hmm. And we drove that standard. And here we are again now transitioning from just finding to just, Hey, from your command line run Vera Veracode fix, identify the problem.
And we're gonna propose some fixes for you that have been finally tuned on our curated data set. And one of the questions I got asked a lot at the conference is, do you train on our data? Do you use customers data to inform the model?
Because, uh, ultimately we're all technologists and you get into the implementation. We talked about leveraging the transformer architecture under the cover covers, and the reality is we've really implemented it in a responsible way because we have our own curated data set. For 17 years we've been finding vulnerabilities, and when you can find them, you know, what the fix is.
So we leverage the power of, of the transformer architecture taking off the chat piece, and, you know, we're now able to present in security fixes to developers that enable 'em to just basically take that code and check it in so you don't have to worry about IP leakage and you don't have to worry about, you know, uh, all of the issues that come, come along with ipss. So I think, you know, it, it's really great to been able to trans to not only lead that many, many years ago, but to now transition to this new model and, and to build it into the way that that conforms with people's GRC expectations and, and enables 'em to do, you know, deliver code more quickly. It's interesting.
So folks of whom may not be into the AI things quite as deep yet, that transformer model is the tokenized mechanism. That's right. Yeah.
Yeah. With Chat G P T in the large Language Yeah. This is the gen pre-train, pre-trained Yeah, exactly.
Are built on, so it's, it's powering a lot of That. It is, Yeah. I, I'm curious too, because you've mentioned, um, maybe in our prior, prior conversations Yeah.
About the, the user experience, the developer experience. Yeah. So it isn't just fixing it that that's an experience the developer's gonna have as well, right?
Yeah. So tell us what that's like for the developer when Barcode Fix engages and takes care of a problem. Yeah.
I mean, look, I, I'll say this very simply, cuz it, it really is simple, right? As, as a developer, I wanna be able to, from first contact to value, achieve value in under two minutes, right? And so we, we have spent a lot of time as we talked about transforming our entire, entire, uh, platform and, and tech stack to be cloud native, but we've also looked at that developer experience.
What, what does it mean when you interact with our service and our, and our technology? How do you derive value? And I, I think that's crucially important because a lot of tech companies get lost in, oh, I've got this great architecture, and we're like, you know, we're implementing it in a really intelligent way.
And, and that's great and you should, but ultimately what is, what is the value does the u that the user sees, how can a developer grab a plugin, use it inside of their I D E and how does it bring them value? Mm-hmm. And by the way, it, it's not just about developers.
There, there has been this massive over rotation towards the developer community, which again, I, I've talked about them. I started there and it's crucially important. But you've also got the security teams who Good point.
You know, when I meet with security professionals, one of the first things they say is like, I, I, I don't know if we're good or not. Mm-hmm. I have no way of determining what's out there, whether it's an external asset or an internal asset.
Like, I just don't even know what my teams are pushing in production. And I had a customer tell me, I I don't even, we've got this service running in production, we don't know who pushed it there. And so it's, it's how do you bring about that, that comprehensive visibility or that discovery capability where you can show them this is your complete attack surface and then take that and connect that to the work that a development teams are doing.
And quite frankly, vari code is positioned to do that with the platform that we've built. We can identify those assets, we can connect the assets that have been pushed to production to wherever they are in a GitHub repo, and we can focus teams on work that matters most because nobody's sitting there saying, I've got all this bandwidth, so we'll work on security issues or burn down tech debt. Right?
So if you make it easy for developers to fix code, if you make it easy for them and you prioritize it for them in a way that they can go take action, I think that's what that, this is how it all comes together, right? The platform is so crucially important and I think you're seeing a lot of people in the, in, in the space where you, you've got a lot of startups who are, you know, coming at the problem in, in a very vibrant and different way. And it's great because it's created all this competition, but ultimately it's about how do you enable value quickly?
How do you unlock speed, enable and boost innovation? And then how do you do that in a way that's comprehensive, that pulls it all together in a platform that enables you to answer that simple question, we're good or not. Mm-hmm.
And so I think that's, that's the key to, to what we're doing really. Yeah. It seems like one, one of the promises holds is as you gain more confidence and use more verify error, code fix.
Yeah. Like you said, many of the vulnerabilities are not new things, right? Mm-hmm.
There may be things that are sprinkled, but, and, and amongst our code that we've done for years Yeah. And not managed to fix at that point. Yeah.
But if you can leverage the automation, the number of times you may have made that same or similar kind of, uh, uh, security mistake or Yeah. Or Whatever it might be, it's, it's the muscle memory, right? Yeah.
You could, you could potentially automate a good portion of that. Yeah. Or at least, at least enough to start to whittle down some more of that security debt.
Yeah. You can't, I mean, I think there's, um, and now we're kind of getting into the crossing the line into the sort of the social component and, and the responsible component of ai. And, uh, you know, a lot of, a lot of companies as we, we, we tested this early on, uh, we're, we're vve that you cannot change our code, right?
There's no automatically checking code in. And in fact, for many of them, you know, creating a pull request was even too far, right? That there's, there's still this, this, this trust hill that developers and security teams have gotta get over because, you know, again, while machine learning and AI has been around for many, many years, really the major advancements in half happened in the last year and a half.
And I think everybody really is now talking about chat G P T. And this is, you know, open AI did a great job with GT two and we're now on the third and fourth versions, but I think there's still a lot of, a lot of fear around what is this gonna mean? So, you know, ultimately I think it's, it's really producing those recommendations to them and then thinking about how do you further automate that in the future?
And we have a lot of ideas about that, right? You know, we initially implemented this as a poll request and we backed away and said, well, we're going create a patch file that still enables you to, to check that fix in if you, if you choose to do so. Mm-hmm.
But we we're also thinking about how do you auto code complete? Because our big announcement was Vera code Fix. That's kind of old news to us now, right?
Cause we've been working on this for a year. So what's coming next and what's coming next is looking at container orchestration, looking at, uh, you know, orchestrating and, and remediating vulnerabilities that are running in production. Because in the same way we brought value with our software composition analysis to show, uh, security and risk and context.
You have the same issues when you're building a container, right? You're pulling in all of these different layers and these operating systems. And so you've got all these transient dependencies that you've, you've got to interrogate and understand.
And so, um, we're, you know, the way that we think about it is how do we simply make software security a natural part of every step of the sdlc? And that looks like securing workloads through every step and when they're in production, and then identifying that risk. And then even inside of the developer's ide, how can you bring auto complete capabilities where, uh, you know, if, if, if I'm a security person, I want to be able to have a policy that states don't, don't allow developer to ingest or import this library.
So we're thinking about how do we bring auto complete capabilities based on the platform policies that have been described. Mm-hmm. And then you said it right?
As the world progresses and as trust, uh, you know, sort of, uh, we raised that bar and, and trust and, and then you start to do it in a more automated way, then we can, then it can start to become really, really powerful where you can have automated mechanisms that prevent ingestion of libraries and are not secure or, you know, don't allow you to pull in, uh, infrastructure as code or a helm chart that's not secure, uh, or a, a a container base image. Uh, so being able to do that in a more, a more automated way, I think is the big power. But yeah, the way we look at it is, let's have the market lead us, right?
Like we, we've got an opinion and we are thought leaders in this space, but let's, let's work with the community, uh, very much sort of the open source mindset. Let's, let's, let's get feedback from the community on how best to build this capability in a way that, that, that meets all of our requirements, um, but also, you know, enables you to go go faster. Okay.
Cool. Uh, so in, in many ways, the IDs the center of the universe for developers, right? Mm-hmm.
Things like auto complete and assisted, uh, code development. What, what's the center of the universe for Veracode for security professionals? Where are they spending their time?
What are they looking at? Yeah, well, you know, last year we, we got a lot of requirements around the ability to, to really customize your security program, right? So we, we obviously have a lot of experience and, and, and knowledge in this space and, and our opinionated about how vulnerabilities need to be either rated or need to be remediated as well as offering, you know, those, those suggestions.
But security teams are coming back to us saying, we, we need even more flexibility. And so that really was the impetus for us refactoring, rewriting from the ground up our policy engine. So when you think about the platform policy is really what spans everything, right?
The decisions that are made around any flaws that are found. And, uh, we completely rewrote that leveraging open source technology because like any other software company, we're looking to leverage, you know, open standards as a way to not only go faster, but but also sprinkle in our, our, our core IP and what's special about the platform. So we rearchitected the policy engine to be based on open and Rigo policies.
And so now the application security professionals can essentially describe what their policy is in code. And so there, it's, it's uber flexible, which really, when you think like a cloud native developer, that becomes a building block that you can piece together and connect with your containers or your iac. So you can have your policy that's gonna, you know, span your production environment that says, if we find this vulnerable, you know, container, or it's gonna, you know, identify at the integration time, you know, applications that are coming together and being, and being deployed, it's gonna be able to produce an SBAM and identify, you know, risk in that application.
So I think we, you know, we continue to listen to the security teams a and by the way, the C-suite to be able to provide that visibility's true and that flexibility to model their business, their business process. Because I think that's, that's crucially important. And, you know, we exist to serve them, right?
And, and so if they need that flexibility, that's what we've built because ultimately we'll still lead with our recommendation on how you should handle whatever we find. But ultimately, it should be down to you to say, you know, these are my grace periods, these are my policies. Or in our case, we, we sometimes find, you know, uh, low priority tech debt where we say, we're going to re-architect this area in the next month and it's gonna become more cloud native.
So, you know, we're gonna carry that risk because it's buried behind the cycle, many, many layers. And it's not exploitable. It seems like there is some real power in the idea of contextualizing what you are understanding about security and vulnerabilities, right?
That's the whole, you know, alert fatigue from security products in general. But if you're, if you're marrying the policy engine with, um, the ability to take action mm-hmm. With fix and, and other automation, and then of course the, the information that's coming to the developer, to the security team, now your policies can be contextualized to what the environment, this helm chart, this operating environment, this cloud provider.
Yeah. Not as a kind of checker at the end to see are you in compliance? Yeah, that's right.
Yeah, that's right. Yeah, exactly. And I think that's, that's how it's going to evolve over time.
And I think, you know, we'll have to look at, you know, how the market leads us and how customers lead us. And I, I, I spend, you know, a lot of time outside the building as you would expect as the chief product officer and you, you gotta really understand what people are trying to solve and, and, and figure out how you can bring a solution that's gonna not only bring them value, but but take care of all of those constituents because, um, yeah, this is application security problem, but it's also a software security problem where we've gotta stop dis distinguishing between first and second and third party software. And we've gotta look at everything as you've got your infrastructure, whether it's Kubernetes or you know, whatever your, whatever your orchestrator is you're deploying to, you've gotta secure all of that.
And you've gotta give them the flexibility and the policy to not only make decisions sort of in an, you know, be able to sort of sleep at night and say the Vari code platform is watching and listening and it's remediating or offering suggestions for us. Um, and I think once you can do that, then you start to get better control. And, and frankly, we, we stop losing the war that we've been fighting on, on security debt and make it easier.
Because I think ultimately, if you make the decisions easy for developers, they, they're gonna elect to choose those solutions, right? I think, I don't think we're gonna hire our way out of it. So you've gotta have some other options.
No, exactly. Yeah. Well tell folks where they can find out more, maybe get some kick the tires, uh, what, what kind of assets you have available.
Absolutely. So the last time we talked, I think we talked about containers and our cloud native expanded support and our language support. And at RSA conference 2023, we talked about Veracode fixes, which is we talked about is our AI and ML solution that produces security recommendations.
But, but look, it only matters what you're gonna do for me tomorrow, right? That, that's old news. And so you're gonna see us continue to evolve that technology to become part of every step in the sdlc.
Uh, I just put together a white paper with a couple of my closest friends and we put that out there to talk about, uh, AI and ml and we're gonna do some blog posts and podcasts and we're even gonna try to get a Boston meetup group together, where if you look at the last page in the, in the white paper, it talked about, let's come together and, and let's figure out how we, we bring AI and ML to bear to, to drive more positive and better outcomes. And so I, I think this is a really exciting time, right? Like, you know, many, many years ago we led with static.
And so here we are now again disrupting ourselves and leading with Vera Code fix. And so I'm really excited to be at the forefront of this and I think it's gonna be great to get the conversation not only started, but do that in a way that, that where everybody's voice is, is heard. And so, cuz I think the confluence of everyone's opinion here is gonna lead to the best outcome.
That's the creating tools for developers and security professionals that they'll use. That's right. Ultimately what matters.
Right? Exactly. I don't think anybody can accuse Vercotta resting on your LA so far from it.
Yeah. Well, thank you very much. Listen, thank you.
It's been a pleasure talking with you. My Pleasure too. It's always thank you so much And uh, we look forward to, you know, we had 2024 rscc, but that's what's gonna happen between Now.
We'll see you again soon. Yeah. And another quarter when we do some work.
Cool stuff. Sounds very cool. Awesome.
Be sure and check out Veracode, you know, one of the leaders in this space doing some really innovative things across the board, not just in, in a, in a single area. But I'm excited to see too where you take AI and how that's fitting into what we're doing around code security and platform as well. So stay tuned.
We'll be back with another fantastic interview, just like with Brian and, uh, we appreciate you hanging with us. We'll see you in a minute.





