Taking on Security Automation

Taking on Security Automation

Increasing risk exposure in modern software

Security experts are sounding the alarm about risks in the software development process. Not only does modern software architecture create a broader attack surface area, the accelerated DevOps methodology makes it harder to detect and remediate vulnerabilities. The heart of this issue is that DevOps teams are challenged to take on new security responsibilities. This is not a role they are trained to play, but it is possible to make developers an extension of your security strategy. New tools for automated security in DevOps remove much of the security burden placed on developers—but do so in ways that make them part of the solution at the same time, while not slowing development.

DevOps as a Driver of Increasing Risk Exposure in Modern Software

DevOps teams offer much to businesses who employ it. Assuming you can pull off the tricky integration between two different and organizationally-distinct groups, the result is faster software development cycles and alignment with agile methodologies. Combined with practices such as Continuous Integration and Continuous Deployment (CI/CD), DevOps enables the release of new software features at a rapid clip.

This is great until you start to look at DevOps from the perspective of information security. The pace of development is simply too fast for traditional application security techniques to work. According to SANS Institute research, 43 percent of organizations are pushing out changes to their software either daily, weekly or continuously. Historically, software testing was intended to reveal security flaws in a new application. There is little time built for manual AppSec inspection into these processes on today’s rapid DevOps timetable.

The nature of software vulnerability is also evolving, making code developed using DevOps that much more vulnerable. Undetected at the source, hackers can plant malware into the vast open source code libraries that DevOps teams draw on for their work. This is an astonishing 79 percent of code. Now, those libraries can carry malicious code.

The Fallacy of Expecting Developers to Enforce Security Policies

Development professionals already have a full-time job: writing great code. Their skill sets revolve around code. They get paid to write code and fix bugs. Bonuses are based on writing code to deliver new products and features that popularize applications. They are used to having an arm’s-length relationship with security. Developers care about security if, and when, it helps to make their products better, faster and more reliable. However, if a vulnerability seems theoretical, or worse the issue is a security “code hygiene” practice, then developers may not give that type of security escalation much priority.

A new approach today involves continuous follow up with dynamic, run-time analysis that can uncover real security problems. Done right, automated analysis identifies critical issues with a clear path to remediation. Once a problem is uncovered, the developer can address it as a software “bug,” e.g. JIRA ticket that includes secure code samples and recommendations to make the remediation straightforward.

The need for automated security discovery without the burden of being trained as a security professional is crucial. It is possible to make DevOps more secure. Armed with this automation, developers will be able to test for vulnerabilities sooner in the development process instead of at the end or after there is a huge breach and they have to rebuild, rewrite code or find a new job anyway.

This article originally appeared in the November/December 2019 issue of Security Today.

About the Author

Felicia Haggarty is a director at Data Theorem.

Featured

  • An Inside Look From Napco at ISC West

    Get a look into the excitement at ISC West 2025 from Napco. Hear from some of their top-tech executives live from the show floor. Read Now

    • Industry Events
    • ISC West
  • Upping the Ante

    I am not a betting man in terms of cards, dice, blackjack or that wheel with the black marble racing around the circumference of a spinning wheel, but I would bet on the success of ISC West this year. Read Now

    • Industry Events
    • ISC West
  • It's Show Time

    I am one of those people that likes to see things get bigger and better. As advertised, ISC West is going to be bigger (more exhibitors) and better (more attendees). It’s show time in Las Vegas. Read Now

    • Industry Events
    • ISC West
  • SIA Releases New Report on Operational Security Technology

    The Security Industry Association (SIA) has released an impactful new resource – Operational Security Technology: Principles, Challenges and Achieving Mission-Critical Outcomes Leveraging OST. Read Now

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.