Friday, December 2, 2022

Open Source Software Code Validation

Overview

Open Source Software (OSS) is integral to modern software applications and can be a real-time-saver for organizations. However, due to its widespread use, OSS is also a major target of cybercriminals. Supply chain attacks are becoming increasingly common as criminals exploit the weakest link in an organization's security systems. Such attacks involve injecting malicious code or manipulating existing code to gain access and control over systems.

For Sleep Number to manage the risks associated with using OSS, we need to:

  1. Ensure that all software stack components are regularly updated and patched with the latest security fixes. This includes the operating system, application framework, libraries, and dependencies.

  2. Monitor our open-source components for vulnerabilities with a security scanning tool. These tools can help identify potential weaknesses and take action to mitigate them.

  3. Perform regular code reviews to ensure no unauthorized changes are introduced to the software stack. This is especially important if third-party developers are involved in the development or maintenance of the system.

  4. Use secure coding practices when developing custom applications to reduce the risk of introducing vulnerabilities into the codebase.

  5. Exception management processes should be in place to help identify and manage potential issues that may arise from changes in features or capabilities between versions. A well-defined process ensures our organization remains agile while successfully managing any risks associated with open-source software.

Approach

At the heart of an open-source software code validation program is its development environment. This consists of tools, languages, and libraries to develop and test code. The development environment also includes a suite of automated testing frameworks to quickly validate code changes before committing them to the main repository.

The ecosystem around this development environment comprises stakeholders such as developers, testers, users, organizations, and customers who are using or supporting the software. These stakeholders have different roles in the process, each contributing their skillsets and expertise towards improving the quality of the software through a constant feedback loop.

Part of the quality controls is enabling collaboration across all stakeholders. This includes sharing information on bugs, best practices, and processes. Documentation is also very important in this process, as it helps developers understand the code and ensure every change is tested before committing them to the main repository.

Ultimately, open-source software code validation programs rely on strong communication between stakeholders and a well-defined development process for success. This involves having clear documentation, testing frameworks, and collaboration tools (i.e., Confluence, Jira, Teams, Slack, Service Now) in place to ensure consistent quality across all aspects of the program. Organizations can build confidence in their open-source projects by providing these resources, helping them attract more users and customers.

Monitoring tools allow the stakeholders to ensure the quality and track uptime performance metrics such as availability rate, response time, and errors per minute to ensure further. These metrics help to identify any problems quickly, allowing the development team to take immediate action and ensure minimal service disruption.

An Open-source software code validation program is essential to ensuring that code is secure and reliable. By providing a well-defined development environment and strong collaboration between stakeholders, organizations can ensure their projects are running smoothly and efficiently. By implementing monitoring tools, they can also track performance data which helps them identify potential issues before they become serious problems. With the right resources and processes in place, open-source software code validation programs can ensure quality across all aspects of the program.

Reference

https://support.snyk.io/hc/en-us/articles/360004002398-Azure-Functions-overview

https://support.snyk.io/hc/en-us/articles/360004127677-Azure-Pipelines-integration

https://snyk.io/blog/snyk-support-for-azure-repos-server/

https://snyk.io/advisor/npm-package/azure-arm-apimanagement

https://snyk.io/advisor/npm-package/dynamics-imix

https://snyk.io/advisor/npm-package/confluent-kafka-wrapper

 

 


Data Mining

Overview

It is important to take the time to analyze the data gathered as a part of the Vulnerability Management Program. This time spent will help to identify patterns and enable better prioritization of remediations. For example, if all systems have the same software versions or patch levels then it suggests that these should be updated in order to address multiple vulnerabilities at once. Alternatively, a single misconfiguration in a Linux system could be resolved to address multiple vulnerabilities. Taking the time to analyze Vulnerability Management Assessment data can help stakeholders with the business intelligence (ergo - epic, stories and sprints) they will need to quickly identify and prioritize remediations, thus improving overall cybersecurity posture.

It is also important to keep in mind that vulnerability assessment reports tend to be large and complex documents. It can be difficult for stakeholders to navigate these documents if they are not familiar with the underlying technologies or lack technical knowledge. Thus, it is essential to ensure that stakeholders have access to the necessary resources and training in order to understand the report and take the necessary steps to address the vulnerabilities.

By taking the time to analyze Vulnerability Management Assessment data and regularly review them, the analysis and stakeholders can identify patterns, prioritize remediations and stay up-to-date on potential vulnerabilities. In turn, this will help to improve overall cybersecurity posture by reducing the risk of exploitation from known threats.

More than just a scan

Vulnerability scans can help gain insight into an organization's approach to its information and operational technology (IT/OT) and security posture. They provide valuable information on how organizations operate from a technical and cultural perspective. By analyzing the results of a vulnerability scan, organizations can gain insights into their security posture and identify areas for improvement.

By analyzing the information in the scan results, a security analyst can determine the organization's patch management program. Is there a testing cycle, the frequency patches are applied, and what resources haven't been patch measured in months, perhaps even years?

The scan results can also help provide insight into the organization's configuration management program. Are the machines configured following security best practices? Which best practices? Are they up to date? How quickly are new configurations pushed out?

In addition, data mining vulnerability scans can provide an additional layer of security by identifying non-compliant machines that may have been missed during the audit process. Are there any rogue, unknown systems connected to the network? If so, are they secure and compliant with company policies?

These insights also help the organization prepare to meet applicable standards for their industry or market segment, such as PCI-DSS, HIPAA, Sarbanes Oxley, or GDPR. 

Vulnerability scans can also be used to support refreshing the CMDB and ensuring the accuracy of its data. Are all systems up to date in the CMDB? Does it contain any stale or irrelevant information?

In the case of a breach, vulnerability scans can provide pieces of the puzzle when attempting to determine the origin of an attack and the scope of systems susceptible to a particular vulnerability.

Vulnerability scans can provide evidence to support insurance claims by helping to determine the level of risk posed by an organization's IT/OT systems and in its ability in preventing a mishap (i.e., breach) from occurring.

Security Metrics

Security metrics provide valuable insights into the security posture of an IT/OT environment. By measuring various aspects of the IT/OT environment, organizations can identify potential weaknesses and address them before they become serious problems.

The three core security metrics of a vulnerability management program (VMP) are the Asset Risk Score (ARS), Vulnerability Severity Score (VSS), and Incident Response Time (IRT). ARS assesses the risk level associated with an asset, while VSS evaluates the severity of a software vulnerability. IRT measures how quickly an organization can respond to a vulnerability and mitigate its effects. Each of these metrics is important for measuring the effectiveness of an organization's vulnerability management program.

The first metric is asset risk score or ARS. This score measures the potential risks associated with each asset within your network. It considers factors such as the time an asset has been exposed, its criticality, and any vulnerabilities discovered during scan results. Knowing these levels helps identify which assets need additional attention when patching or hardening systems against potential threats.

Another key metric is the vulnerability severity score or VSS. This score indicates how severely a vulnerability impacts your system based on the type of exploit and the risk it poses. For example, a remote code execution vulnerability would likely be considered more severe than an information disclosure bug. The VSS score helps prioritize which vulnerabilities should be addressed first when remediating systems.

Finally, incident response time, or IRT, measures how quickly an organization can respond to incidents or threats. It considers the time it takes for security teams to detect and respond to any suspicious activity and the amount of time needed for remediation. Knowing your IRT helps you identify areas of improvement regarding detection and response processes.

Collecting and analyzing data from these three core metrics can be used to understand our security posture and take appropriate action to strengthen it. For example, if ARS and VSS scores are increasing, but IRT is decreasing, this could indicate that we need to improve its incident response capabilities. Tracking and monitoring these metrics can help us better manage our cyber security risk and ensure the safety of our systems.

ARS, VSS, and IRT can be essential measurements of a successful vulnerability management program. We should use these metrics to measure the effectiveness of our security posture and take appropriate action to ensure our systems are safe and secure from cyber threats.

Decision Metric

Based on the tread of the each of these scores (ARS, VSS, IRT) you can then measure how well the IT/OT is protected against attacks and other threats compared to industry standards and best practices. As the following table demonstrates, these scores can give you an overall picture of our organization's security health, highlighting areas where improvements could be made to increase protection.

Indication

ARS

VSS

IRT

Could suggest that threats are being identified but not effectively addressed, which could mean the vulnerability management program is not working as intended.

:arrow_up:

:arrow_up:

:arrow_up:

Could mean that security teams are able to identify and address threats on time, but the vulnerability management program is not adequately addressing potential risks.

:arrow_down:

:arrow_up:

:arrow_up:

Could suggest that threats are being identified but not adequately addressed, which could indicate that the vulnerability management program is not working as intended.

:arrow_down:

:arrow_down:

:arrow_up:

Could mean that security teams are not taking appropriate steps to identify and mitigate potential threats promptly, and the vulnerability management program is not adequately addressing potential risks.

:arrow_down:

:arrow_down:

:arrow_down:

Could indicate that security teams are responding to identified threats in a timely manner, but the vulnerability management program is not adequately addressing potential risks.

:arrow_up:

:arrow_down:

:arrow_up:

Could signify that the vulnerability management program is working as intended, and security teams are taking appropriate steps to identify and mitigate potential threats promptly.

:arrow_up:

:arrow_down:

:arrow_down:

Could indicate that the vulnerability management program is working effectively, as security teams are able to identify and address threats promptly.

:arrow_up:

:arrow_up:

:left_right_arrow:

Could suggest that security teams are responding to identified threats in a timely manner and the vulnerability management program is working as intended.

:arrow_up:

:left_right_arrow:

:left_right_arrow:

Signify that the vulnerability management program is working as expected

:left_right_arrow:

:left_right_arrow:

:left_right_arrow:

Could mean that security teams are not taking appropriate steps to identify and mitigate potential threats promptly, indicating that the vulnerability management program is not adequately addressing potential risks.

:arrow_down:

:left_right_arrow:

:arrow_up:

Could indicate that security teams are able to identify threats but not adequately addressing them, suggesting that the vulnerability management program is not working as intended.

:left_right_arrow:

:arrow_up:

:left_right_arrow:

Could suggest that security teams are taking appropriate steps to identify and mitigate potential threats promptly, indicating that the vulnerability management program is working effectively.

:arrow_down:

:left_right_arrow:

:left_right_arrow:

 

Saturday, September 22, 2018

Resizing a virtual image in VMware or Parallels

Made the mistake of not allocating enough virtual drive space for OS X image I had setup to work from.  First i had to get rid of all of my snapshots.  This must had corrupted the catalog and disk utility first aid wasn't doing anything to fix it.  Plus when I created the image it was done with HFS instead of APFS.  
But after reading through a few sites on the ways it could be fixed.  As you might have guessed, didn't help.
Before resorting to a commercial product, I was able to come up with a working solution in both VMware Fusion and Parallels Desktop.
Prerequisite
A vm os x image on a dedicated volume
Approach
HFS and VMware – while booting:
command+s
At single mode prompt: fsck -fy
Repeat until there’s no more errors
At prompt: reboot
From terminal as root execute:
/usr/sbin/diskutil resizeVolume / R
Done
HFS and Parallels – Do before booting
In VMConfiguration-> Hardware -> Boot Order > Advance enter the following
devices.mac.boot_args=”-s”
Then boot image
At single mode prompt: fsck -fy
Repeat until there’s no more errors
At prompt: shutdown -h now
In VMConfiguration-> Hardware -> Boot Order > Advance remove the entry
devices.mac.boot_args=”-s”
Boot into vm image
From terminal as root execute:
/usr/sbin/diskutil resizeVolume / R
Done

Sunday, June 17, 2018

Dr. No


The meaning of security has different viewpoints depending on whom you ask in the organization.  Compliance to meet certifications requirements, meeting legislative, regulatory (or industry) requirement, safeguard the visibility and accessibility of personal information, a set of non-functional requirements for implementing the appropriate controls.  I have witnessed the differing definitions in many of the businesses I have consulted for over the years.  I describe it as an incohesive mess devolved into twisted competitiveness for funding, headcount, and the fighting for the position of prestige within the organization.  

This negatively impacts and splinters the focus and purpose of Security as a business partner and a positive change agent.  The difficulty lies in the consensus of how to fuse vying priorities and approaches to support the organization's vision and goals.

It seems evident that Security should be about advising the business on what path to take to improve its capability and performance in delivering the organization's goods and services.  Informing and providing business intelligence that draws on compliance, privacy, and tactics, techniques, and process for safeguarding the essence of the business so that it can continue to be innovative with the freedom to diversify its capabilities.  

It is time to squash the tendency of being seen as nothing but neighs sayers and roadblocks.  To do this, we need to know what we're up against and the significance it can have on the business.