Enterprises are increasingly reliant on software engineering to help orchestrate mission-critical tasks.
While this shift has had positive impacts, it has also reshaped the attack surface and created new opportunities for adversaries who consider the engineering ecosystem as the new path of least resistance.
The complexity associated with building and deploying applications and the speed at which the process is conducted leads to “countless vulnerabilities and misconfigurations,” said Daniel Krivelevich, AppSec CTO for Prisma Cloud at Palo Alto Networks.
To address this, the cybersecurity giant today added an 11th module to its industry cloud-native application protection platform (CNAPP) Prisma Cloud.
This will provide protection for continuous integration/continuous delivery (CI/CD), the software development practice of making incremental code changes. The new capability builds on the integration of Cider Security, which was acquired in December 2022.
Coming together on pipeline securityAccording to Gartner, securing the software delivery pipeline is as important as securing the software that it delivers. In fact, the consulting firm predicts that by 2025, 45% of organizations worldwide will have experienced attacks on their software supply chains, representing a three-fold increase from 2021.
The U.S. government is also raising the alarm on securing the CI/CD pipeline. Just in June, the cybersecurity and infrastructure security agency (CISA) and the national security agency (NSA) released a comprehensive guide to help organizations secure their pipelines.
“CI/CD environments are attractive targets for malicious cyber actors (MCAs) whose goals are to compromise information by introducing malicious code into CI/CD applications, gaining access to intellectual property/trade secrets through code theft, or causing denial of service effects against applications,” the agencies cautioned.
Organizations and government agencies alike are waking up to the profound impact of an insecure CI/CD, Krivelevich noted. He pointed to the now-infamous 2020 attack on the software supply chain of SolarWinds and other large entities.
Earlier this year, cybercriminals also successfully infiltrated and disrupted leading CI/CD platform CircleCI through a customer’s GitHub OAuth token.
Ultimately, the Open Worldwide Application Security Project (OWASP) identifies 10 CI/CD security risks:
- Insufficient flow-control mechanisms
- Inadequate identity and access management (IAM)
- Dependency chain abuse
- Poisoned pipeline execution
- Insufficient pipeline-based access controls
- Insufficient credential hygiene
- Insecure system configuration
- Ungoverned usage of third-party services
- Improper artifact integrity validation
- Insufficient logging and visibility
A “paradigm shift” in recent years has changed the relationship between engineering systems and processes, Krivelevich said. There is a rise in the diversity of development languages and frameworks; increased use of third-party tools and frameworks; growth in codification (infrastructure as code, policy as code); and automation and usage of CI/CD processes.
Increased investment in engineering has resulted in organizations being “heavily outnumbered” by engineers (typically one AppSec engineer for every 100 to 200 developers), he said.
Facing all this, defenders are changing their approach, with more enterprises turning to CNAPP, whose market is expected to grow from an estimated $7.8 billion in 2022 to $19.3 billion in 2027, representing a compound annual growth rate (CAGR) of nearly 20%. PANW competes in the space with security powerhouses including Sysdig, Orca, CrowdStrike, Wiz and Trend Micro, among others.
But PANW says the integration of CI/CD security into Prisma Cloud makes it the “most complete” security platform for protecting “the entire engineering ecosystem from code-to-cloud.”
Protection across the software delivery pipelinePrisma Cloud’s CI/CD Security module enables DevOps and security teams to better collaborate and improve security outcomes throughout the application life cycle, Krivelevich said. Customers can analyze individual tools, visualize how they interact with applications and each other and identify and remediate risk.
The tool provides the following features:
- A single view into the engineering ecosystem (across repositories, contributors, coding languages/ frameworks, risks)
- Pipeline posture management with protection against the OWASP Top 10 CI/CD risks
- Controls to block insecure code from reaching production
- Graph-based mapping of the engineering ecosystem to uncover attack paths
- Actionable fix guidance
The new capability augments the Prisma Cloud platform’s Secrets Scanning, Software Composition Analysis and Infrastructure as Code Security, Krivelevich said.
Thinking differently about securitySimply put, organizations must think differently about application security, Krivelevich said.
He described an effective AppSec program as consisting of three primary domains: security in the pipeline to address insecure code; security of the pipeline to optimize CI/CD posture; and security around the pipeline to implement flow control mechanisms and prevent unauthorized access.
The future of cloud application security requires a focus on hardening CI/CD systems and processes, he said, as attackers increasingly target engineering workstations to gain access to sensitive information. Organizations should prioritize the building of cloud AppSec workflows and conduct analyses against realistic attack scenarios, he advised.
“As software engineering becomes more fast-paced, dynamic and influential, application security teams must evolve to keep up,” he said. “Recent attacks have shown that a single unsecure step in a CI/CD pipeline can have significant consequences, leading to compromised infrastructure, leaked secrets and malware spread.”
Comments