Cybersecurity professionals are quick to see the risks associated with open source — a developer may unknowingly insert buggy open source code into an enterprise application, which could make the company, its partners, and customers vulnerable to attacks.
But with cyberattacks skyrocketing to all-time highs and threats from COVID-19 to quantum computing putting intense pressure on the industry, a growing number of cybersecurity vendors are realizing that open source can be a powerful tool for protecting customers and staying ahead of attackers. As open source becomes even more mainstream in enterprise environments, security vendors need to collaborate more on efforts including threat intelligence and product integrations, said Doug Cahill, a VP and group director at Enterprise Strategy Group (ESG) who covers cybersecurity.
“It’s a collective defense, all-boats-rise proposition,” he said. “We should be sharing threat intelligence because adversaries are putting all customers at risk.”
Open Source Code: Cybersecurity Friend or Foe?ESG recently surveyed 378 cybersecurity professionals and developers across the U.S. and Canada and asked them about open source and securing the application development process. It found that 80% of organizations report significant use of open source code. And of those organization that say more than a quarter of their codebase is open source, 49% currently use security controls to scan the open source software for vulnerabilities. “That’s not enough — that’s the bad news,” Cahill said. “The glass half full is that 44% of those organizations plan to invest in those kind of controls over the next 12 months.”
This shows both sides of the security coin when it comes to using open source code. On one hand, the community of developers and security professionals using pieces of this code numbers in the hundreds or thousands, “and there is advantages in numbers,” Zeus Kerravala, principal analyst at ZK Research said. “The code is continually being tested, it should be more reliable and have fewer bugs.”
Plus, this massive community working with open source code makes it more likely that security issues will be found — and patched — very quickly.
However, the downside of this open code is that it’s open. “Threat actors also have access to the code, and are working to breach the code,” Kerravala said, adding that there’s also the potential for hackers to create malicious open source code.
Static and Dynamic Code ScanningThis also further illustrates the importance of static and dynamic code scanning to keep applications secure. And to this end, some cloud native security vendors have developed tools to detect and block malicious open source code. This includes Aqua Security, which earlier this year launched a product that protects containerized applications from image-based malware by automatically running the images in a sandboxed environment. It’s especially important because Docker Hub is the world’s largest container image repository and hackers can easily embed malware in container images and then use it for credential theft, data exfiltration, cryptocurrency mining, and distributed denial of service (DDoS) attacks.
Also this year, Trend Micro integrated its cloud security platform with Snyk’s developer-focused open source vulnerability detection service in a bid to mitigate open source code risks.
Linux Foundation’s OpenSSFIn fact, one of the Linux Foundation’s newest initiatives aims to smash open source software security bugs before they make it into production environments. GitHub, Google, IBM, Red Hat, Microsoft, and VMware are just a few founding members of the new Open Source Security Foundation (OpenSSF), which brings together open source security initiatives including the Linux Foundation’s Core Infrastructure Initiative (CII) and GitHub’s Open Source Security Coalition. The Linux Foundation founded CII in response to the 2014 Heartbleed bug. And the Open Source Security Coalition, founded by the GitHub Security Lab, is developing a unified format and API for vulnerability reporting to improve open source security.
While some efforts like the Linux Foundation’s OpenSSF focus on securing open source software and reducing time to fix any flaws, there’s also been an increased push to advance open source standards and protocols for security, which can help address a couple other problems in the market around complexity and interoperability.
Open Cybersecurity AllianceMcAfee and IBM are two of the vendors leading this charge, and late last year the two companies co-founded the Open Cybersecurity Alliance, which aims to make security products interoperable using open source code, standards, and protocols. This becomes more important as enterprises use an increasing number of security tools — ESG puts the number at between 25 and 59 — from up to 10 different vendors on average.
At launch, IBM Security contributed STIX Shifter, an open source library that can identify information about potential threats within a variety of data repositories and translate it into a format that can be digested and analyzed by any security tool that has this standard enabled.
And in February, the group also made available OpenDXL Ontology, an open source language for connecting security tools that McAfee developed. It’s a messaging format for use with the OpenDXL messaging bus.
“It’s encouraging that we’ve had a couple of major brands partner around standards, but we need more of this,” Cahill said. “We need a critical mass. One of the impediments in cybersecurity is a lack of standards, especially when you think about how fragmented the market is and how many different controls and different vendors that cybersecurity and project teams need to already manage and develop a competency around. We do need more standards for integration and interoperability.”
Comments