{"id":52780,"date":"2022-11-28T12:05:06","date_gmt":"2022-11-28T04:05:06","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=52780"},"modified":"2022-11-28T12:05:09","modified_gmt":"2022-11-28T04:05:09","slug":"how-ph-businesses-can-tighten-up-software-supply-chain-against-cyber-attacks","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2022\/11\/28\/how-ph-businesses-can-tighten-up-software-supply-chain-against-cyber-attacks\/","title":{"rendered":"How PH businesses can tighten up software supply chain against cyber attacks"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em><strong>By Dean Vaughan<br>Vice President of Asia Pacific,\u00a0Azul<\/strong><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>In September 2022,\u00a0Philippines\u00a0Airlines lost the personal data of frequent flyers when its IT provider was hacked, adding yet another example of\u00a0supply\u00a0chain\u00a0attacks\u00a0that have bedeviled\u00a0businesses\u00a0globally in the past year.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The cyberattack on a third-party IT provider for the airline caused the names, birth dates, nationality, gender and points balance, among&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/streaklinks.com\/BSq6BRVKipW22ktg6ghY3PUC\/https%3A%2F%2Fwww.cnnphilippines.com%2Fbusiness%2F2022%2F9%2F11%2FPAL-Mabuhay-Miles-suffers-data-breach.html\">other details<\/a>&nbsp;to be stolen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although it is unclear how the malicious actors managed to get into the victim\u2019s systems, the incident once again reinforces the need to tighten up security against supply chain attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For many of today\u2019s IT systems, using third-party&nbsp;software&nbsp;in one form or another is inevitable, such is the interconnectedness of the Internet and the complexity of digital infrastructure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An estimated 40% to 80%&nbsp;of the lines of code in&nbsp;software&nbsp;come from third parties such as libraries, components and&nbsp;software&nbsp;development kits. Unfortunately, they are one reason for the increased vulnerability of third-party production code that goes into digital services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By 2025, 45% of organizations worldwide will have experienced attacks on their software supply chains, a three-fold increase from 2021, according to research firm Gartner.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A lack of visibility hampers defense<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is a problem facing any digital economy and the&nbsp;Philippines&nbsp;is no different as it delivers more services over digital channels in the years ahead. The way forward has to involve better detection of such vulnerabilities without impacting performance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To begin, you&nbsp;can&nbsp;only defend&nbsp;against&nbsp;something if you know what you are&nbsp;up&nbsp;against. Since many organizations do not peer into the nuts and bolts of the many third-party programs they use, they often are working on the hope that the code is free from vulnerabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even with a vulnerability detection tool in place, many organizations fail to act on a threat, because alerts are often too general or unable to differentiate between production and non-production code. This means the work required to clean&nbsp;up&nbsp;an infected or vulnerable system is too broad to be undertaken by already beleaguered security and application teams.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Today, organizations continue to grapple with Log4Shell, a critical vulnerability found in a widely used Java-based logging component (Log4j). This loophole enables threat actors to run code on a victim\u2019s system and take control. It has impacted countless servers and applications that used Java software because Java software is used widely in today\u2019s modern IT infrastructure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Yet, when the threat first emerged last year, few organizations had the ability to quickly find the exact location of the vulnerability in their IT systems because Java was used so extensively. The challenge was knowing where to look even when the dashboard lit&nbsp;up&nbsp;with a warning.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>More precision needed<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What is needed is greater precision, which&nbsp;can&nbsp;only be possible with improved visibility over existing solutions.&nbsp;Application scans in CI\/CD, application agents, or application inventories (SBOMs) are valuable approaches as part of a comprehensive security strategy. However, these approaches also have drawbacks, including false positives which waste time via alert fatigue as well as a performance impact which adds burden to Java teams and their applications.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Take&nbsp;Azul&nbsp;Vulnerability Detection, a new&nbsp;Software-as-a-Service (SaaS) product that continuously detects known security vulnerabilities that exist in Java applications. By eliminating false positives and with no performance impact, it is ideal for in-production use and addresses the rapidly increasing enterprise risk around&nbsp;software&nbsp;supply&nbsp;chain&nbsp;attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Azul&nbsp;Vulnerability Detection uniquely identifies code run using sophisticated, highly granular techniques inside&nbsp;Azul&nbsp;JVMs (Java virtual machines) and maps&nbsp;against&nbsp;a curated Java-specific database of common vulnerabilities and exposures (CVEs). This produces more accurate results, even for custom code and shaded components, so IT teams&nbsp;can&nbsp;get to a vulnerability and remediate the issue quickly and efficiently.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Gaining agility while beefing&nbsp;up&nbsp;security<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To be sure, vulnerability detection tools are not new. Unfortunately, some end\u00a0up\u00a0providing the added security at the expense of performance. This means business agility suffers, because one\u2019s security tool is slowing down transactions and requiring more computing resources and cost to run.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations need to find a way to overcome the&nbsp;software&nbsp;supply&nbsp;chain&nbsp;problem. They need smarter tools that&nbsp;can&nbsp;beef&nbsp;up&nbsp;the security without adding overheads and dragging back performance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When it comes to security in Java applications, what\u2019s different with&nbsp;Azul&nbsp;Vulnerability Detection is its use of&nbsp;Azul&nbsp;Java virtual machines (JVM), which provide highly accurate runtime-level visibility into what code is actually running and whether it is vulnerable. This enables faster remediation of vulnerabilities with significantly less operational overhead.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Additionally, because the tool is agentless, it avoids the performance penalty commonly associated with other security tools that require teams to install and maintain a separate piece of&nbsp;software. Taken together,&nbsp;Azul&nbsp;Vulnerability Detection makes security a byproduct of simply running Java&nbsp;software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Fighting a winnable battle<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security has to be baked in from the start instead of an add-on feature in a connected world. In other words, it has to be built into a piece of\u00a0software\u00a0or part of a technology stack that is then used to build other digital services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately,&nbsp;supply&nbsp;chain&nbsp;attacks&nbsp;against&nbsp;trusted vendors and third-party code pose substantial enterprise risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The key to winning battles&nbsp;against&nbsp;increasingly sophisticated threats is to be armed with the right tools that deliver a solid defense while retaining the agility that organizations need today. Even as&nbsp;cyber&nbsp;threats evolve, they have to believe they&nbsp;can&nbsp;keep out the bad guys over time and continue delivering the trusted digital services and experiences to their users.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security has to be baked in from the start instead of an add-on feature in a connected world. In other words, it has to be built into a piece of software or part of a technology stack that is then used to build other digital services.<\/p>\n","protected":false},"author":7,"featured_media":52014,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[7440,286,54,2103],"class_list":["post-52780","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions","tag-azul","tag-it-security","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/52780","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=52780"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/52780\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/52014"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=52780"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=52780"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=52780"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}