惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cloudbric
Cloudbric
E
Exploit-DB.com RSS Feed
SecWiki News
SecWiki News
Forbes - Security
Forbes - Security
N
News | PayPal Newsroom
S
Security @ Cisco Blogs
Schneier on Security
Schneier on Security
V
V2EX - 技术
S
Secure Thoughts
W
WeLiveSecurity
Google DeepMind News
Google DeepMind News
C
CERT Recently Published Vulnerability Notes
NISL@THU
NISL@THU
S
Securelist
S
Security Archives - TechRepublic
Know Your Adversary
Know Your Adversary
V
Vulnerabilities – Threatpost
Security Latest
Security Latest
Recent Commits to openclaw:main
Recent Commits to openclaw:main
G
GRAHAM CLULEY
H
Hacker News: Front Page
Microsoft Azure Blog
Microsoft Azure Blog
I
Intezer
Google Online Security Blog
Google Online Security Blog
美团技术团队
阮一峰的网络日志
阮一峰的网络日志
T
The Exploit Database - CXSecurity.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Webroot Blog
Webroot Blog
Jina AI
Jina AI
Engineering at Meta
Engineering at Meta
P
Proofpoint News Feed
The Cloudflare Blog
I
InfoQ
L
LangChain Blog
U
Unit 42
P
Proofpoint News Feed
S
Schneier on Security
S
Security Affairs
Y
Y Combinator Blog
T
Tenable Blog
N
News and Events Feed by Topic
MyScale Blog
MyScale Blog
量子位
Google DeepMind News
Google DeepMind News
Cyberwarzone
Cyberwarzone
博客园 - 聂微东
D
Darknet – Hacking Tools, Hacker News & Cyber Security
GbyAI
GbyAI
AWS News Blog
AWS News Blog

RapidFort Blog

RapidFort Test Blog Blog 4 Test Test Blog 3 Test 2 Mythos Vulnerability Assessment: Eliminate Real Risk, Not Just CVEs Securing Modern AI Workloads for National Security RBOM vs SBOM: The Critical Difference Between Software Inventory and Runtime Reality The Remediation Gap: When AI-Powered Discovery Outpaces Human Defense You Only Control 15% of Your Software. Here's How to Secure the Rest. Free ATO Readiness Cohort: Shorten Your Path to Federal Market US Cyber Strategy & Software Supply Chain Security EU CRA for Containers & Kubernetes: Scope, Deadlines & Steps PyPI, npm, and the New Frontline of Software Supply Chain Attacks GitHub Actions Security Audit: CI/CD Risk & Shell Injection What Is RBOM™? Runtime Bill of Materials vs SBOM Explained EU Cyber Resilience Act & Open Source Risk RapidFort Raises $42M Series A for Software Supply Chain Security Fintech Container Security 2026: SASM & RBOM™ RF Analyzer: Precision Container CVE Intelligence Kimia: Secure Kaniko Alternative for Kubernetes Builds AI-Powered Cyberattacks: How Defenders Must Adapt RapidFort Pioneered DoD Container Hardening | Industry Standard Turn Scanner Output into Verified CVE Elimination RapidFort's Giant Washing Machine: Cleaning Open Source at Scale Why SBOMs Fail: RBOM™ & Near-Zero CVE Images Fix the Gap Defeat NPM Supply Chain Worms: Near-Zero CVE Defense Bitnami & Chainguard Alternatives: Free Near-Zero CVE Images Runtime Profiling: Eliminate up to 99.9% of Container CVEs Flow Defending: AI-Speed Container Hardening & Runtime Visibility AI in Software Supply Chain Security: Defense vs Attackers SBOM vs RBOM™: Why Runtime Bill of Materials Wins AI-Powered Container Stack: Built, Hardened & Defended AI-Generated Code Vulnerabilities: Runtime Defense for Containers Container Vulnerability Management Reimagined | RBOM™ 35,000+ Near-Zero CVE Images: FIPS, STIG & AI-Era Standard RBOM™ Runtime Intelligence: Cut CVE Noise & Improve Accuracy EU Vulnerability Database (EUVD): Impact on CVE Management Critical Infrastructure Cyber Resilience: Near-Zero CVE DoD Software Procurement: SWIFT, cATO & Container Security Stop Fixing CVEs One by One: Eliminate up to 99.9% Before Production Break the Patch-and-Pray Cycle: Proactive CVE Management Beyond FedRAMP Checklists: Continuous CVE Elimination Why RapidFort Outperforms the Competition: The Future of Secure Containers FedRAMP Fast-Track: Near-Zero CVE Images & Zero Patching Hidden Costs of Manual CVE Elimination | Automate with RapidFort PCI DSS, SOC 2, FedRAMP & HIPAA Compliance via CVE Elimination Emerging Cyber Threats 2024: Protect Containers with RapidFort Container Supply Chain Security: From Source to Deployment Build a Robust Security Stack with RapidFort's SASM Platform Securing Containerized Environments: Best Practices Identify & Eliminate Common App Vulnerabilities in 3 Steps Near-Zero CVE Blueprint: Securing Your Software Supply Chain Eliminate up to 99.9% of Container CVEs in 3 Steps | No Code Changes DoD Innovation: SpaceWERX, AFWERX & Defense Tech Firsthand Developer Security Training Do's & Don'ts Top 5 Software Security Myths Debunked AI-Generated Code Security Risks: CEO Insights Using AI in Software Development: Security Tips & Considerations RapidFort Wins Intellyx Digital Innovator Award | Runtime Security 3 Tips to Conquer CVE Alert Fatigue Mature DevSecOps Teams: Key Traits & Security Best Practices Top 3 Software Security Trends 2024: AI, Compliance & SASM Software Security Budgeting 2024: Eliminate CVEs by up to 99.9% & Measure ROI RapidFort 2023 Year in Review: Milestones & Container Security Wins OSS Vulnerability Scanning & Container Hardening RapidFort Joins Microsoft Pegasus Program | Container Security Runtime Container Protection: 90% Attack Surface Reduction Black Hat USA 2023: AI, CISO Trends & Cybersecurity Insights SOC 2 Type 2 Compliance for Container Security RapidFort Achieves SOC 2 Type 2 | Enterprise Security Validated Common Container Security Risks & How to Fix Them 6 Steps to Securing Your Software Supply Chain Harden Containers with Coverage Scripts & RBOM™ Profiling Container Vulnerability Management Best Practices Minimize Software Attack Surface | RBOM™-Powered SASM Docker Container Security Best Practices 2023 | Harden & Scan What Is Container Hardening? Reduce CVEs & Meet Compliance | Guide Securing Popular Docker Containers: Up to 80% Attack Surface Cut How RapidFort Secures Its Own Containers | Dogfooding DevSecOps Why Container Security Tools Fail: Scan vs Eliminate Hidden OSS Trade-Offs: Container Bloat, CVEs & Security Debt OSS Patch Management: Eliminate Container Bloat & CVEs OpenSSL Vulnerability: Scan, Harden & Reduce Risk in Containers Harden Hundreds of Containers Today for Free Customs Bridge Automates CVE Elimination with RapidFort SAST vs DAST vs IAST: Limitations for Container OSS Security Delete 78% of Your Redis Container - It Still Works 100% Free Tool: Copy AMIs to AWS GovCloud Fast | Open-Source Script Why CVSS Severity Alone Fails: Use Exploit Probability The Limits of Shift Left: How Software Optimization Fills the Gap Software Supply Chain Security with SCA Scanning What Is Software Supply Chain Risk? Causes & How to Mitigate It Reduce Container Bloat: Remove Unused Components & Cut CVEs What Is Software Optimization? RBOM™ vs SBOM Explained Log4j Response: Harden Containers Now Before the Next Patch
Stop Chasing CVEs: Smarter Container Test Cycles
Saty Sundarram · 2022-05-11 · via RapidFort Blog

What do you do when your security scan reveals 7,000 vulnerabilities in a single aspect of your infrastructure? Worse, what do you do when you’re using golden base images and you’re still seeing reports of thousands of vulnerabilities within those images?

These are some of the questions keeping security professionals from a good night’s sleep. At some point, you have to ask if there’s any point in remediating tens of thousands of vulnerabilities. Even if you took care of just the critical vulnerabilities, what about the high-priority ones? After all, high priority vulnerabilities can still lead to significant potential damage.

When you write code with open source components for containerized applications, you deal with mountains of problems that you didn’t create and can’t fix.

There’s a much better solution than staying up all night and worrying.

In a recent interview with Security Magazine, RapidFort CEO Mehran Farimani shared valuable insights about securing containerized workloads. Specifically, he offered some solid advice for product and security teams when facing insurmountable numbers of vulnerabilities.

You Don’t Need More Visibility or Vulnerability Testing

There are many great tools available that provide amazing visibility into your code, infrastructure, and workload performance, like SCA scanners and other vulnerability scanners. Some of them are free and provide excellent results. The real question is: What do you do with all this visibility? What are you going to do with the results?

The problem is intractable.

Infrastructure and DevOps teams today have tools to manage operations, automation (CI/CD), Kubernetes management, and so much more. Developers have an overwhelming selection of tools to scan their code, improve runtimes, and understand performance. All these tools are vital for developers to build fast, secure code. But that’s not where the security problems are.

A software development team could write rock-solid code with zero vulnerabilities and maximally-optimized performance, 100% code coverage tests, and even change the world with their work. (Sounds nice, doesn’t it?) But as soon as they need to actually deploy and run that application code, they bundle it with open source components, and their perfect code is now swimming in a sea of vulnerabilities residing in third-party code.

The code gets packaged into virtual machines and containers, pulling in thousands of lines of third party code not controlled by the developer before it’s deployed into production. Once that happens, developers have no visibility into the components that their workload is actually using. The dev team’s perfect, secure code is sitting atop layers and layers of interoperating open source libraries and frameworks in the underlying operating system, which is loaded with critical vulnerabilities the team can’t fix.

Would more visibility help these developers? No. We’re talking about emptying the ocean with a teacup - or, if we want to be generous, a really big pot. Large enterprises have millions of vulnerabilities across their infrastructure. Even in mid-size companies, we see containers in production with literally thousands of vulnerabilities. No matter how big the teacup or the pot, visibility into security issues is only so effective.

Remove Vulnerabilities for Better Container Security

Knowing where vulnerabilities exist is only helpful when you can actually treat them. Unfortunately, a vast majority can only be corrected within an organization’s custom code. Some organizations write custom patches, but contend with open source software package updates that break those custom patches, so there are significant forward compatibility challenges.

There’s no point in playing security whack-a-mole.

It’s more important to understand how a workload functions than it is to understand where vulnerabilities exist. What teams need to know is simple:

  • What software components are running in a workload
  • What components actually gets used
  • What components can be eliminated
  • What vulnerabilities exist after unused components are eliminated

Dev, security, and infrastructure teams need less noise and real solutions that reduce the noise. Huge lists of insurmountable vulnerabilities don’t help anyone. Imagine a product manager saying to a DevOps engineer, “We’re looking to push a major new release next month. Our early scans show there are 6,247 vulnerabilities. Can you get those taken care of in the meantime?”

Funny as it may sound, this is the reality many organizations face. Now, what if the product manager were to say, “Our early scans show more than 6,000 vulnerabilities, but it also looks like we can eliminate about 70% of the container’s codebase. That brings us down to about 1,800 vulnerabilities. Can you get those taken care of in the meantime?”

Certainly, 1,800 vulnerabilities is overwhelming, but at least you know they’re actual risks to your production infrastructure. Your remediation efforts can now be directed and your container isn’t just a sitting duck with a huge attack surface that can’t be treated.

Focus on Test Cycles with Container Optimization

We think organizations should spend their time improving test cycles so that their test coverage better resembles production run time behavior. With that in place, it's much easier to determine which components are used. Instead of chasing down vulnerabilities and moving to time-consuming golden base images that are quickly outdated, teams should become more nimble by using software that intelligently cuts unnecessary problems out of the system, and sets a foundation for long-term manageability and success.

Organizations that focus on golden base images are wasting their own time. It’s an outdated methodology that keeps security and infrastructure teams scrambling to keep up with the industry. In the short term, they’re constantly revising these base images because open source software changes all the time. In the long term, they’re contending with the momentum of an organization that has evolving business needs. 

Most importantly, they’re preventing the organization from being nimble and agile.

Having a complete test suite is a more effective way of staying nimble and focusing on what’s important. When software has been optimized, an engineering team can be confident in deploying a system that’s efficient and has a minimal software attack surface. It’s a waste of their time to focus on moving to Alpine base images or distroless images - both of which have plenty of built-in vulnerabilities - and spending a ton of time on security.

Developers’ time is very valuable. It’s much better spent building new features and software that addresses customer issues than spending their time aligning with security requirements that become outdated the moment they’re written down.

We believe a new deployment model is needed where developers write high-value code and automated tooling in a CI/CD pipeline eliminates a significant majority of security concerns. Security teams should have insight and input to this process, defining profiles that meet their organization’s security requirements without becoming a roadblock or adding friction to the SDLC.

Get Started with Software Optimization

Our new deployment model is not a far-fetched idea. In fact, it is available today to any forward-thinking company that wants to get away from outdated software and infrastructure security methods.

RapidFort is the only product offering an improved Software Bill of Materials (SBOM) - which we call a Real Bill of Materials (RBOM) - that provides a thorough breakdown of unused components in a workload, machine learning-driven component removal estimation, and automated optimization based on user-specified profiles. It can plug directly into any existing CI/CD pipeline and optimize containers with minimal overhead.

We want the whole world to be vulnerability testing and performing container optimization (studies show only 48% of companies scan their infrastructure whatsoever!), so we are offering our container and workload scanning capabilities for free.