Opens in a new tab
vmblog logo 2024 wht (updated)

Combating the Rising Software Supply Chain Attacks

Share: 

David Marshall | Published: October 12, 2022

By Ritesh Patel, VP of Product, Nirmata

Cloud-native applications have become increasingly complex. Composed with an infrastructure stack of mash-up code, hundreds of open-source and commercial components, services and APIs, today’s software supply chain is fraught with security risks. At the same time, the ability to manage existing application requirements while building innovation and taking on new areas of responsibility like security is stretching DevOps teams beyond their capacity. The concern for the number of connected and exploitable weaknesses across the software supply chain are now requiring organizations to take a proactive approach to protect their continuous integration and continuous delivery (CI/CD) systems as they have become a target to infiltrate multiple production systems. But meeting this requirement is no easy feat as it often requires organizations to choose between how much security to enforce in the build cycle while quantifying their risk to build and deploy quickly.

A recent survey revealed that nearly all (97%) of an organization’s assets – and security issues – are now in the cloud. And yet, only 29% of their assets are associated with cloud specific policies. Addressing this gap requires organizations to have a proactive approach to protect their technology infrastructure, especially securing the artery of their software supply chain: the CI/CI pipeline. By embracing new security and compliance strategies within their governance approach, organizations can better protect their CI/CD pipeline and cloud applications.

There is a growing shift toward programmable infrastructure and Infrastructure-as-Code (IaC) practices to build out the infrastructure and manage configuration files. But with this practice comes the increased risk of exposing application credentials, API keys, encryption keys, and digital certificates. Tools supporting CI/CD pipeline have now become the artery of cloud applications, and it’s creating challenges to store, transmit and audit data securely. To add to that, when CI/CD tools interact with other systems in the DevOps environment, it increases the risk exposure of the configuration files. A compromise in the build system, for example, can be used to get access to production systems that results in the exposure of sensitive information or the injection of malicious code, corrupting the entire CI/CD pipeline and software supply chain.

A recent Unit 42 Cloud Threat Report revealed that overly permissive credentials created added risk opportunities in the CI/CD pipeline. The study found that 63% of IaC templates contain misconfigurations, and 91% of container images contain high or critical security vulnerabilities. To address this, organizations need to catch security problems in the build before cloud workloads are provisioned. During the SolarWinds compromise, hackers used custom malware designed for the company’s build cycle to observe each step. The sophistication of the intrusion in this attack during the software build process is influencing how security needs to be approached.

One way to attack this is being able to identify CI pipeline misconfigurations, which leads to improved security in the software supply chain. Because CI pipelines are configured in the code, the same policy-as-code approach can be used to identify IaC misconfiguration or open-source vulnerabilities to surface CI/CD weaknesses. Other ways are to keep configurations accessible to just a small group who are building for production release. By establishing enforceable permissions to the pipeline, there is better control of who can commit code changes to the repositories, create containers and deploy code to the different environments.

Strong chains of trust throughout the build cycle are not commonplace today. But as organizations look at ways to strengthen their risk posture by shifting left, security and DevOps teams can work towards proactively hardening pipelines with the right tools and frameworks that make up CI/CD pipelines, and push the industry toward a more secure software supply chain.

##

To hear more about cloud native topics, join the Cloud Native Computing Foundation and the cloud native community at KubeCon + CloudNativeCon North America 2022 in Detroit (and virtual) from October 24-28.

ABOUT THE AUTHOR

Ritesh Patel, VP of Product

Ritesh Patel 

Entrepreneurial, collaborative leader with a proven track record of managing complex projects and delivering results. Leveraging extensive experience in Technology, Market Strategy, and Business Development to revolutionize the Cloud-native space.