Vulnerability Inbox Zero

QCon San Francisco 2022

Session Security

Vulnerability Inbox Zero

Wednesday Oct 26 / 01:40PM PDT, Bayview

Abstract

You have a vulnerability problem. You run a scanner. Now you have two problems - vulnerabilities and a mess of scanner results to process.

Keeping up with vulnerability scanners is a struggle. Modern software services can have vulnerabilities in each of their layers. Scanners at each of these layers can produce results that require time to understand and process. False positives and overblown risk ratings can exhaust engineering team capacities.

Vulnerability management pipelines help us trend away from chaos. At LaunchDarkly, we built a vulnerability management system to support our organizational objectives. It incorporates our requirements for FedRAMP and uses a variety of serverless AWS Cloud Services to reduce operational overhead. We combine AWS Inspector, AWS Security Hub, AWS Lambdas, and other tooling to support a vulnerability management pipeline where all of our cloud production workloads are scanned at each layer. Vulnerabilities from a variety of sources can be not only combined, but processed by code. This allows us to define exceptions as configuration in code and keep our vulnerability alert actionable.

This talk will discuss the lessons learned creating our vulnerability management pipeline, where we’re headed in the future, and design considerations for other teams facing similar challenges.

 

Topics

Security Vulnerability Vulnerability Management System Pipeline
76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon San Francisco 2022 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Wednesday 26 October

10:35 Seacliff ABC Session Security A Big Dashboard of Problems Travis McPeak Founder and CEO @ResourcelyInc, previously @Netflix & @Databricks 11:50 Seacliff ABC Session Security Scaling Defenses Amidst Evolving Threat Landscape Aditi Gupta Staff Security Software Engineer @Netflix 13:40 Bayview Session Security Vulnerability Inbox Zero Alex Smolen Director of Security @LaunchDarkly, previously Engineering Manager @Clever, Engineer @Twitter, Security Consultant @Foundstone 14:55 Seacliff ABC Session Panel: Practical Security Aditi Gupta, Travis McPeak, Nimisha Asthagiri, Alex Smolen 16:10 Ballroom BC Session Security Privacy-First Re-Architecture Nimisha Asthagiri Principal Consultant @Thoughtworks, Previously Chief Architect & Senior Director of Engineering @edX