[0:05] Hello everyone, thank you for joining us today for this webinar on software supply chain security and a brand-new product brought to the market by HCL Software and OX Security, called HCL AppScan Supply Chain Security. My name is Adam Cave, I’m a product marketing manager for HCL AppScan. A couple of things before...
[0:05] Hello everyone, thank you for joining us today for this webinar on software supply chain security and a brand-new product brought to the market by HCL Software and OX Security, called HCL AppScan Supply Chain Security. My name is Adam Cave, I’m a product marketing manager for HCL AppScan. A couple of things before we start: this is being recorded, we’ll keep participants on mute but we encourage questions in the Q&A and chat, and we’ll have a Q&A session at the end. We have Michael Smith with us from HCL Software and Boaz Barzel from OX Security. Michael, tell us a little about yourself, and same for you, Boaz.
[1:28] Sure, my name is Michael Smith, director of technical sales for AppScan. I’ve been around AppScan for about 10 years at IBM and now at HCL, and before that I was in the commercial space working in application security for about seven or eight years, so almost 20 years of application security experience altogether.
[1:51] Fantastic. And Boaz?
[1:56] Thank you, my name is Boaz Barzel, I’m leading product enablement and many other things at OX Security, with over a decade of prior experience at Check Point in the cyber security space. Really excited to be here with the amazing folks from HCL.
[2:22] Before we get into the product and how these two companies are integrating, I want to broadly talk about software supply chain security. Could both of you give your two-minute elevator pitch on the difference between traditional application security, which many on this call are familiar with, and software supply chain security? Michael, do you mind starting?
[2:54] Sure. Historically the AppSec tools and space have really been focused on your source code, your open-source components, and live running applications deployed in dev and test, focusing on those individual areas of testing. Newer technologies have come out in the last five, six, seven years with the evolution of DevOps, and the tools and testing have evolved just like the attacks have. But from a supply chain security perspective, it’s more about looking at the entire stack, every single technology throughout the entire pipeline, and trying to validate every little piece that goes into the application, giving you full visibility into the pipeline holistically, not just from a source-code or open-source perspective. It’s a much broader view. Boaz, what do you see on the OX side?
[4:12] I agree, and I’d add that beyond taking it broader, from a supply chain perspective we’re also looking at integrity: not just testing and fixing vulnerabilities, but understanding every piece, its location, and how it was incorporated into the process, what came from my pipeline and what didn’t. So the ability to understand the different pieces, have that integrity in place, and then the traceability: not just moving everything forward to production, but the ability to go back and complete that map. I really think this is the next way of looking at software supply chain security.
[5:12] HCL Software, or AppScan, has been in the application security business a long time, but felt the need to move into software supply chain security. Michael, could you tell us why a partnership with OX was the direction, and why OX in particular?
[5:47] Sure. We’ve been seeing ever-increasing supply chain attacks, from NotPetya to the Solar Winds attack, which was the biggest driving factor that forced the US government to make some mandates. We saw OX making headlines with Gartner and some analysts, and then a very large account of ours, which uses a couple of our scanning technologies, recommended OX Security and said, “you need to take a look at this startup, they’re doing some really amazing things.” This account loved our scanning technology but needed a higher-level view and correlation of all their AppSec tools, because they had a diverse set, seven or eight different tools throughout their application security space. AppScan can correlate its own results extremely well, but OX takes it to another level and can correlate all the major AppSec tools in the market, which is extremely powerful for a large organization with many business units that has acquired scanning or testing technologies through acquisition. So bringing world-class scanning technologies together with AppScan and partnering with OX, focused on software supply chain security, we could create something amazing.
[7:43] Boaz, let me flip the question to you. Michael pointed out that OX can integrate with a lot of different tools, one of its strengths. When your team looked at this partnership, what do you feel HCL AppScan brings that makes this combination particularly powerful?
[8:12] Thank you, Adam and Michael. When we first started looking at HCL, we were really impressed by the technology and the portfolio, what AppScan can do and the different elements in it. Focusing specifically on the DAST aspect, it was amazing to see the abilities AppScan brings, and thinking about how that technology with the OX technology comes together to provide a holistic solution for the entire software supply chain, from code to cloud, validating integrity and tracing everything back and connecting it, so the results we provide together are much more accurate and reduce a lot of the manual work around analysis and triage, reducing that friction. That partnership got us excited, and that’s why we joined forces.
[9:27] You’ve both alluded to a lot of drivers in the market. This is some data we pulled on the threats and risks driving interest in software supply chain security. Is there a number here that stands out to either of you?
[10:11] Beyond the threats and risks, and Solar Winds was a big inflection point from a sophistication standpoint, I’m thinking about how organizations face the next level of risk. You look at the percentage of organizations that have faced a data breach or cyber attack, and the cost, and from a business perspective the question is how do I reduce that cost and stay below those numbers. That’s what really occupies boards on a daily basis.
[11:13] Building on that, what are the drivers today? Boaz indicated the cost factor; anything else striking a bell that you’ve been hearing about?
[11:33] One example, from one of our customers: they started from the compliance aspect, because they had a hard time meeting audits; they realized they didn’t have the necessary tools and foundations in place. When they tried to do it themselves, DIY or with specific tools, they realized there was a lot of noise and they were missing visibility. We see that journey with most customers as they build their AppSec program, facing each of these issues from different sources, and once they have a lot of tools they accumulate security debt because they have to analyze and do everything manually. So it’s a nice way to see how issues from different areas drive them to seek out the next technologies.
[12:39] Michael, anything to add?
[12:47] The biggest shift we’ve seen is how much influence development organizations now have over security teams. Historically, security teams would pick the tool and implement it for developers; that’s drastically changed. In most larger organizations, developers honestly outvote or have more influence over the decision of the security tools. You can have organizations with several thousand developers but only a handful of security analysts, or even trained security champions, so it’s still an uphill battle for security teams to find the right balance, integrate with the developer community, and have visibility into the overall pipeline. Given the landscape and the direction hackers are going, always down the path of least resistance, the more visibility we can bring to the application security team to arm developers with the help they need to fix issues, the more efficient everyone is going to be.
[14:25] With that in mind, let’s look at our new product, because I think we’ve laid the groundwork. We’re introducing HCL AppScan Supply Chain Security, which, with the partnership of HCL Software and OX Security, provides Active application security posture management. Michael, introduce the product from the HCL Software perspective, and then we’ll move into a demo.
[15:07] Sure. I could not be more thrilled to announce this partnership, which we announced a few weeks ago at RSA; it’s about a year in the making. The partnership allows HCL to resell OX Security on HCL paper. We wanted to bring a supply chain security aspect to the AppScan portfolio, giving more value to our AppScan customers. OX was really the first to create what they call the pipeline bill of materials, where you can highlight end-to-end visibility of the risk associated with the pipelines and validate the software supply chain, which could not be more timely as organizations struggle with tool sprawl, having a tool for DAST, a tool for SAST, and so on. Let me go deeper into AppScan. HCL acquired it from IBM about five years ago; it’s an entire portfolio. We have SAST supporting over 40 languages, with AI and ML capabilities since 2016, seven or eight years before ChatGPT came out. We can run both compiled and source-code scans, and about 50% of our findings have automatic fixes in a dev tool we call code fix. For DAST we have over 20 years of experience and what we think is the strongest DAST engine in the market. For API security we keep investing, supporting OpenAPI, Swagger, and Postman. We’ve significantly invested in SCA since coming to HCL, including SBOM and SCA support for every static language, and created container scanning, secret scanning, and infrastructure-as-code scanning, all since coming to HCL. From an application security management perspective, we have the full stack of integrations for source code management, defect trackers, build plugins, APIs, and SDKs. With OX and AppScan together, organizations can scan with AppScan and various technologies, then integrate in OX to secure everything across their portfolio: an integrated platform, more out of AppScan or other third-party tools, no gaps in coverage, and AppSec teams focusing on what matters most instead of connecting or de-duplicating findings.
[19:42] That’s a great rundown. Let’s take a look at what it can do.
[19:58] Sure, let me share my screen and do a quick AppScan on Cloud demo, then I’ll throw it over to Boaz. I’ve already logged into AppScan on Cloud, which we call ASoC for short. I have several applications already created. To get started you create an application, give it a name, assign an asset group, and select the AppScan presence used to scan internal websites for DAST. Then in a matter of seconds I create my DAST scan: enter a domain, choose to scan only links below a directory, and it verifies the domain. To scan a private network behind your firewall, you’d install our software-based agent called AppScan presence, which lets our DAST engine create a reverse proxy into your network to scan test or dev applications. You enter login credentials, and there are options for the explore and the test policy. We have a slider, created for pipeline integration: “fast” finds about 97% of vulnerabilities but is twice as fast, and faster settings find 85% at five times the speed, so depending on where you are in your SDLC you choose. I’ll go with fast and create the scan. While that runs, I’ll create a SAST scan on the same application, via a GitHub repo or by uploading an archive; we scan both compiled and source code, so you can zip up the source code, or connect to a GitHub repo. There’s also a client to generate what we call an IRX file, an intermediate representation of your source code that cannot be executed, is fully encrypted, and cannot be reverse engineered. I’ll create the scan. So within about a minute I’ve created both a DAST and a SAST scan.
[26:06] I’ll pop over to the issues for the completed DAST scan. This gives the HTTP request and response, why and where the vulnerability exists, and why we detected it; it looks like it threw a SQL error, so we flag it as a vulnerability. Once it’s over to the developers, there’s a very broad set of remediation guidance, over 25 languages in total. Going back, my SAST scan is already done; I’ll open one of the findings, say “validation required.” You can see the source where the data comes in, the best fixed location, and a new feature where you can click the source code to go directly to the file, or to your GitHub repo if you’ve set it up, plus how-to-fix guidance for about 15 languages. In my Juice Shop application I’ve set up the integration with OX, which I’ll show in a second; once you go into the issues and click a finding, when I go to source code I can open directly in the repository, because I scanned via the repository. So in a matter of minutes I scanned a DAST and a SAST scan. To create the integration, you come to our tools section, go to API, and generate a new key ID and secret. Then pop over to OX, go to their connectors page, look for AppScan, add your API key and secret, and that’s it. I’ll stop there, and Boaz will show more of the actual integration and results.
[31:01] Fantastic, thank you Michael, that was a great demonstration. Let me start sharing my screen. I want to connect us back to the entire software supply chain. With OX we introduced the pipeline bill of materials technology, which lets us create full asset visibility from code to cloud, plus traceability and integrity from cloud to code: the ability to connect to AppScan, collect all the information, correlate and consolidate it, let OX add prioritization, and map it to OSC&R. OSC&R is an open-source supply chain attack reference that lets you see all of your issues from an attacker’s point of view, a MITRE-like framework focused on software supply chain security. The second element is posture, looking at Git and CI/CD posture: two-factor authentication, the ability to create forks, adding more admins, and so forth, to reduce the risk by taking away elements that make it easy for attackers to infiltrate. We correlate all that information between your business, your environment, how applications are running, and the attacker standpoint, bringing in threat intelligence to help you reduce manual triage and automate the response. Continuing from where Michael left off, on the connectors page HCL is already connected; all I had to do, as Michael showed, is put in the access key and secret key and click connect. From that point on, all results from HCL AppScan are pulled into OX. On the dashboard, the main part of the screen, what we call the AppSec data fabric, is where we collect all the results; you can see the dynamic application security coming from HCL, a great way to understand how vulnerabilities progress from code to cloud, plus vulnerabilities OX discovered and the posture engines, and the prioritizations. This is a demo environment so the numbers are low, but with many customers we see about 27% or more reduction in noise, and the ability to prioritize the actual risks that are reachable, exploitable, and high business damage, correlated with what developers are currently working on.
[35:19] Let’s deep dive into an issue. On the issues screen you’ll see, as Michael created the scan, all those results are pulled into OX, letting us create different correlations, for example by URL, where multiple issues are correlated based on the same applications. We also map compliance and create visualizations to help you understand the issue and where it’s connected and came from. Let’s take this Juice Shop example Michael showed; one of the issues came from AppScan, and we add threat intelligence, correlating information from HCL AppScan into that visualization. Looking at the entire software supply chain, we build the informational aspects: reachability and damage, detection and response, the different intelligence, and the exposure and reachability aspects. This is a strong part of the integration: using AppScan’s scanning results and engines, bringing them to OX, helping you correlate and prioritize, so you can focus on the critical risks across the entire software supply chain. From the dashboard I can click the criticals and now I have six criticals to address right now, with the evidence from a reachability, exploitability, and damage perspective. We also bring the description and recommendation, including a DAST recommendation, so you understand how to use both platforms in conjunction. From a visibility perspective, API, SaaS, and ASPM information can be correlated together. From a response perspective, we can create workflows: when there’s a critical issue, the action can be sending a Slack message or opening a Jira ticket. So just to summarize, the integration is super simple, put in the API key and secret key, and everything is mapped into the AppSec data fabric, correlated and prioritized automatically, with no-code workflows to automate a response. We cover the three main aspects of software supply chain security, discovery, analysis, and response, reducing a lot of the friction and load on both development and security teams, connecting the two solutions from HCL and OX. I’ll stop sharing.
[41:19] That was great, thank you so much. I know both of you were moving fast and have done longer demos, which we can make available to participants. We have some great questions. One that’s come up a couple of times, Michael, is about the on-prem products: this is an integration with AppScan on Cloud, so if someone wants to do something with AppScan Standard or AppScan Enterprise, is there a workaround?
[42:47] Neil, a technical advisor on my team, answered it elegantly: as long as you can get results into AppScan on Cloud, we can integrate them with OX. Out of the box we chose to start with AppScan on Cloud, and we’d look at direct integrations with AppScan Enterprise down the road. As of now the direct integration is just with AppScan on Cloud, but there are workarounds if you can get the data into AppScan on Cloud.
[43:36] Another question, from Enzo Jimenez: is the “go to source code” option we saw available for GitLab?
[43:53] As Neil said, it’s pretty much repo-agnostic, based on Git, not necessarily GitHub or GitLab specifically. We have GitLab teed up on the roadmap, but there are workarounds: if you have the code locally you can point to any Git location or directory you have access to.
[44:23] Boaz, one question from the Q&A: someone is excited about the combined solution, expecting it to be more about visibility and coverage, and is trying to understand whether it’s more about faster triage and remediation. Where do you see the balance?
[44:53] From a visibility standpoint, as I showed in the data fabric, we map the entire software supply chain from code through CI/CD, registry, and cloud, giving you the mapping and the ability to understand the severity of issues by category, plus how OX enables correlation and prioritization. The second part is taking it further: the combination of HCL AppScan and OX Security lets you prioritize the relevant issues, so instead of working with long lists of vulnerabilities, you understand the critical issues, their locations, and the evidence, so you focus your attention not on figuring out whether a vulnerability is real or a false positive, but on how much risk it creates and what you need to do to remediate it. So it takes you through the entire flow, discovery, analysis, response, and the ability to understand the effectiveness of your AppSec program and its impact on the business.
[46:40] A note on the recording: a link will be supplied to all of you via email. I think that about wraps it up. To everyone who asked questions, thank you so much, we appreciate you being here. Michael and Boaz, thank you so much for great presentations; I think we learned a lot today, and I look forward to seeing where this partnership goes. Great days ahead.
[47:40] Thank you very much, Adam, thank you Michael, appreciate it. Thanks everyone.