Skip to main content

Survey: Lack of Confidence in Software Supply Chain Security Runs High

A survey of 400 platform and security engineers in the U.S and United Kingdom (UK), finds nearly three quarters (73%) are either only moderately confident (58%) or not confident (15%) in the ability of their existing tools for managing software artifacts to prevent attacks against their organization’s software supply chain.

Conducted by Cloudsmith, a provider of a platform for managing software artifacts, the survey also finds nearly half of respondents (48%) can identify an intrusion in their software supply chain but need to rely on manual efforts to enforce some type of quarantine or resolve the issue. Only 37% said they can automatically identify, block, and trace an intrusion within minutes.

As a result, nearly two thirds (65%) are either investigating a different approach to compliance (45%) or are evaluating some type of security framework (25%), the survey finds.

Cloudsmith CEO Glenn Weinstein said that as it becomes more apparent in the AI era that changes will be made to how software supply chains will need to be secured, there will be more focus on securing binaries after applications are deployed. Cybercriminals will increasingly target those binaries using cyberattacks that will be launched at machine speed. As such, more resources will need to be allocated to automating DevSecOps workflows within a curated repository that limits the number of potential vulnerabilities that might find their way into a software supply chain, noted Weinstein.

The challenge is that securing binaries is a much more complicated challenge than simply trying to fix issues at the source code level, he added.

Overall, the top three concerns are attacks exploiting AI-generated code to introduce malicious dependencies, followed by supply chain attacks blending into normal DevOps activities and automated systems modifying software at scale.

More challenging still, only 27% said they are very confident their organization could pass an unexpected audit of their software supply chain. On the plus side, however, 61% are at least moderately confident that AI coding tools are not introducing additional vulnerabilities into their software supply chains. However, only 32% said they are scanning the AI models they employ for specialized threats, compared to 41% that are scanning for basic integrity to, for example, verify checksums/provenance. Another 22% are relying on general security tools such as runtime monitoring. Half of respondents (50%) are relying on provenance or attestation data to validate software builds.

Additionally, a full 95% said they generate software bill of materials (SBOM) data but only 25% integrate and automate SBOM verification into security gatekeeping. Instead, three quarters (75%) said they use that data for ad hoc compliance only.

Finally, nearly half (49%) of respondents said their organizations will occasionally skip implementing a new security/developer feature, compared to 28% that admitted they do so regularly.

Ultimately, it’s not clear which teams have responsibility for securing software supply chains. More than three quarters of respondents said security is the function most concerned with dependency-led attacks. However, when asked where the decision to trust an open-source dependency should sit, nearly two in five (39%) put it with a centralized security, platform, or governance team. Another 37% said it is a shared responsibility with developers.

Regardless of who is ultimately held accountable for securing the software supply chain, the one thing that is certain is more cybercriminals than ever are discovering just how soft the underbelly of organizations that build and deploy software really is.



from DevOps.com https://ift.tt/KdBniFR

Comments

Popular posts from this blog

Rochelle Walensky on the Rocky Road to Normal

Rochelle Walensky on the Rocky Road to Normal By David Wallace-Wells from NYT Opinion https://ift.tt/0A5Wx6r internal-sub-only-nl, Coronavirus (2019-nCoV), Vaccination and Immunization, Rumors and Misinformation, Centers for Disease Control and Prevention, Walensky, Rochelle

LocalStack Acquires WonderTwin AI to Gain SaaS App Emulation Platform

LocalStack this week revealed it has acquired WonderTwin AI , a provider of an emulator of software-as-a-service (SaaS) applications that is used to build custom applications for those platforms. Colin Neagle, vice president of marketing for LocalStack, said the emulators WonderTwin AI has developed will be integrated into the company’s namesake emulation platform that application development teams currently rely on to emulate cloud services provided by Amazon Web Services (AWS). LocalStack and WonderTwin AI make it possible for application developers working on a local machine to build applications that are designed to be deployed on some type of external cloud platform using a local sandbox to test and validate integrations without having to connect to a service or build against a live application programming interface (API). That issue has been especially critical in an era where more code will soon be generated by AI coding agents that may for one reason or another circumvent the...

Mystery Fuels Unease in Maine Woods: Who Bought Burnt Jacket Mountain?

Mystery Fuels Unease in Maine Woods: Who Bought Burnt Jacket Mountain? By Jenna Russell, Heather Knight and Sophie Park from NYT U.S. https://ift.tt/a6Ye2Gp Land Use Policies, High Net Worth Individuals, Forests and Forestry, Logging Industry, Real Estate and Housing (Residential), Facebook Inc, Thomas Associates, Zuckerberg, Mark E, Chan, Priscilla, Appalachian Trail, Bangor (Me), Maine, Palo Alto (Calif), Mount Katahdin (Me), Millinocket (Me)