As the first anniversary of the discovery of Log4Shell (Log4j) vulnerabilities approaches, AT&T AVP of Security Jennifer Morovitz discussed the broad impact of this zero-day threat and how it brought more attention to software bill of materials (SBOM) in an interview with SDxCentral.
SDxCentral: Is zero-day exploitation at a heightened level?
Morovitz: The number of vulnerabilities just increases. They have tripled over the past decade. So last year, we had 20,000 new vulnerabilities and then I think we're gonna be on track to surpass 25,000 new vulnerabilities this year. Last year, in particular, we had like 80 zero days, which was like an all-time record. And to put things in perspective, this year, we have eight zero days so far, and last year, we had 80.
So zero days are concerning because there are flaws that have been publicly disclosed, but most often there's not a patch or fix available. So, when that kind of a condition occurs, you have this race by malicious actors to exploit them and the zero days have a tendency to be pretty significant types of vulnerabilities. So you have to mobilize quickly to triage the vulnerabilities and understand the impact on your environment, just because you don't have a lot of time before attacks start occurring.
SDxCentral: What’s an example of a recent zero-day vulnerability that was a big challenge?
Morovitz: A fairly recent example that I can think of is Log4j. That was something that hit the industry about a year ago in December, and it was a vulnerability in logging software. And that software was broadly used. And I think the big issue with that one was it's embedded in proprietary code as well as open-source code. And because it was embedded, it was very difficult to find or detect it.
So, you might have some circumstances where you could see: okay, here are some obvious implementations of the Apache vulnerability, but it wasn't obvious, and what coupled with the fact that it was ubiquitous and hard to detect. It allowed this remote exploit capability, so you didn't have to be local, you didn't have to have special privileges, you could be remote and exploit the vulnerability, so that really upped the game.
So it was just a big event. And I think that events itself pushed a lot of focus on areas of improvement, for example, the software bill of materials. So that's the NTIA- (National Telecommunications and Information Administration) sponsored concept for software transparency in the supply chain. But [the concept of] software bill of materials has been around for a while, but when you have these broad zero-day events that impact many industries and you're dealing with a hard-to-detect scenario, that's where things like SBOM really come into play.
And it's still an area that is being developed, but it kind of shone a light on that: hey, this capability is really needed because the industry was scrambling because of a lack of detection here. So I think the positive that came out of that very broad event was we need to improve toolsets to be able to discover zero days that detect or can create software bill of materials, and have inventories of software bill of materials. So those are good outcomes that come from sometimes broad events that impact multiple industries.
SDxCentral: What should organizations do to address zero-day threats?
Morovitz: We just recently did this talk as part of our cybersecurity conference a few weeks ago, and the key takeaway is to just have basically a pre-wired plan. You don't want to wait, and you should have a triage process that incorporates how you consult the inventory that you have, hopefully starting with SBOM inventory if you haven't already, and then be able to have a crisis communication plan.
So how do we triage the issue? How do we consult our inventory, how do we look at the vulnerability and decide what the risk is to our company? So that's one piece of it, and then what's the communications? How do we quickly communicate with our business partners or asset owners? Here's the risk, and here's how you remediate in the most expedited, again, stress-free way.
So I think that having these predefined triage processes and communications protocols, like tabletop exercises with your business partners frequently a few times a year is helpful. So that would be the focus that I think people should have coming out knowing how you start with zero days because you really start with a good inventory and good processes because if you don't have those, it's gonna be chaos to deal with downstream.
Comments