Taking on Security Automation

Taking on Security Automation

Increasing risk exposure in modern software

Security experts are sounding the alarm about risks in the software development process. Not only does modern software architecture create a broader attack surface area, the accelerated DevOps methodology makes it harder to detect and remediate vulnerabilities. The heart of this issue is that DevOps teams are challenged to take on new security responsibilities. This is not a role they are trained to play, but it is possible to make developers an extension of your security strategy. New tools for automated security in DevOps remove much of the security burden placed on developers—but do so in ways that make them part of the solution at the same time, while not slowing development.

DevOps as a Driver of Increasing Risk Exposure in Modern Software

DevOps teams offer much to businesses who employ it. Assuming you can pull off the tricky integration between two different and organizationally-distinct groups, the result is faster software development cycles and alignment with agile methodologies. Combined with practices such as Continuous Integration and Continuous Deployment (CI/CD), DevOps enables the release of new software features at a rapid clip.

This is great until you start to look at DevOps from the perspective of information security. The pace of development is simply too fast for traditional application security techniques to work. According to SANS Institute research, 43 percent of organizations are pushing out changes to their software either daily, weekly or continuously. Historically, software testing was intended to reveal security flaws in a new application. There is little time built for manual AppSec inspection into these processes on today’s rapid DevOps timetable.

The nature of software vulnerability is also evolving, making code developed using DevOps that much more vulnerable. Undetected at the source, hackers can plant malware into the vast open source code libraries that DevOps teams draw on for their work. This is an astonishing 79 percent of code. Now, those libraries can carry malicious code.

The Fallacy of Expecting Developers to Enforce Security Policies

Development professionals already have a full-time job: writing great code. Their skill sets revolve around code. They get paid to write code and fix bugs. Bonuses are based on writing code to deliver new products and features that popularize applications. They are used to having an arm’s-length relationship with security. Developers care about security if, and when, it helps to make their products better, faster and more reliable. However, if a vulnerability seems theoretical, or worse the issue is a security “code hygiene” practice, then developers may not give that type of security escalation much priority.

A new approach today involves continuous follow up with dynamic, run-time analysis that can uncover real security problems. Done right, automated analysis identifies critical issues with a clear path to remediation. Once a problem is uncovered, the developer can address it as a software “bug,” e.g. JIRA ticket that includes secure code samples and recommendations to make the remediation straightforward.

The need for automated security discovery without the burden of being trained as a security professional is crucial. It is possible to make DevOps more secure. Armed with this automation, developers will be able to test for vulnerabilities sooner in the development process instead of at the end or after there is a huge breach and they have to rebuild, rewrite code or find a new job anyway.

This article originally appeared in the November/December 2019 issue of Security Today.

About the Author

Felicia Haggarty is a director at Data Theorem.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West
  • Live From ISC West 2024: Post-Show Recap

    ISC West 2024 is complete. And from start to finish, the entire conference was a huge success with almost 30,000 people in attendance. Read Now

    • Industry Events
    • ISC West
  • ISC West 2024 is a Rousing Success

    The 2024 ISC West security tradeshow marked a pivotal moment in the industry, showcasing cutting-edge technology and innovative solutions to address evolving security challenges. Exhibitors left the event with a profound sense of satisfaction, as they witnessed a high level of engagement from attendees and forged valuable connections with potential clients and partners. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance. 3

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions. 3

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection. 3