More critical flaws similar to Log4Shell found in open source are almost inevitable, but Open Source Security Foundation’s (OpenSSF’s) goal is to make those incidents rare and continually make the attackers’ job harder, a Linux Foundation executive noted.
Founded in 2020, OpenSSF is a cross-industry organization hosted by the Linux Foundation that brings together individuals and companies including Cisco, GitHub, Google, and VMware, to develop better security tools and practices for open source application development without bias toward a specific ecosystem or vendor.
The organization offers automation tools, educational materials, and courses and develops various projects and frameworks — including Supply Chain Levels for Software Artifacts (SLSA), Secure Supply Chain Consumption Framework (S2C2F), Software Bill of Materials (SBOM) Everywhere, and Alpha-Omega — to improve security for the open source community, David Wheeler, Director of open source supply chain security at Linux Foundation, told SDxCentral.
“Certainly nobody wants another Log4j, [but] a major vulnerability in software that beats open source or closed source is probably inevitable,” he said. “So the goal is to make these kinds of problems rare. And so we are working towards that end.”
Wheeler noted OpenSSF offers open source security courses that specifically educate students not to make the mistake that happened in Apache Log4j 2 Java library.
“Unfortunately, LogShell was not, as far as anyone can tell, intentional maliciousness. It was an honest mistake, in part due to the complexity of code, and in part, frankly due to people who are doing the development not knowing how to do certain kinds of secure software development, and the tools that really support them either,” he said.
Making a Log4j ListOpenSSF has created a list of critical open source projects that include Log4j and its working group is in the process of revising that list. “Basically the goal is we're trying to get community input on one of the more important projects and then we use that to feed other sources” such as its Alpha-Omega project, Wheeler noted.
The project was established in February last year. The Alpha part provides funding to improve security in five critical open source projects: Node.js, the Eclipse Foundation, the Rust Foundation, jQuery, and the Python Software Foundation. While through Omega, OpenSSF uses a combination of tools and expert analysis to identify security vulnerabilities across the 10,000 most-critical open source projects.
“Something I think that's going to be unique for OpenSSF coming ahead is working to identify common patterns” and proposing solutions and automated tools, Wheeler explained.
Additionally, the organization encourages security audits that check the code in the most important part of an open source project or tool and look for problems and vulnerabilities.
“We're around to create tools and guidance and documents and processes and other kinds of resources that will help make it much easier to make software secure,” Wheeler said.
OpenSSF Welcomes New MembersThis week, OpenSSF announced eight new members including Amesto Fortytwo, Code Intelligence, Kusari, Privado, Scotiabank, Technology Innovation Institute (TII), Open Source Business Alliance - Bundesverband für digitale Souveränität e.V,. and Python Software Foundation.
“Today, our society and the global economy heavily rely on open-source software. Security incidents such as Heartbleed and Log4Shell show significant weaknesses in the software supply chain,” Khaled Yakdan, Co-founder and Chief Scientist at Code Intelligence, said in a statement. “We are thrilled to join OpenSSF to share our knowledge, experience, and learnings with the community and collaborate on accelerating the advances of open-source security.”
The organization now has over 100 members with a 88% increase in 2022.
“First of all, that means there's more money to apply. And it also means that there are more people with more different backgrounds and resources, not just money, but people's knowledge, and everything else,” Wheeler said. “And the good news is the more people get involved, each contributing a little bit, the result is quite an acceleration.”
Comments