Speaker
Abstract
You have a vulnerability problem. You run a scanner. Now you have two problems - vulnerabilities and a mess of scanner results to process.
Keeping up with vulnerability scanners is a struggle. Modern software services can have vulnerabilities in each of their layers. Scanners at each of these layers can produce results that require time to understand and process. False positives and overblown risk ratings can exhaust engineering team capacities.
Vulnerability management pipelines help us trend away from chaos. At LaunchDarkly, we built a vulnerability management system to support our organizational objectives. It incorporates our requirements for FedRAMP and uses a variety of serverless AWS Cloud Services to reduce operational overhead. We combine AWS Inspector, AWS Security Hub, AWS Lambdas, and other tooling to support a vulnerability management pipeline where all of our cloud production workloads are scanned at each layer. Vulnerabilities from a variety of sources can be not only combined, but processed by code. This allows us to define exceptions as configuration in code and keep our vulnerability alert actionable.
This talk will discuss the lessons learned creating our vulnerability management pipeline, where we’re headed in the future, and design considerations for other teams facing similar challenges.
Topics
QCon San Francisco 2022 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.
Part of the track
Practical Security Hosted by Julia Knecht Manager, Security Platforms Engineering @NetflixFrom the same track
Wednesday 26 October
10:35 Seacliff ABC Session Security A Big Dashboard of Problems Travis McPeak Founder and CEO @ResourcelyInc, previously @Netflix & @Databricks We have all heard "an ounce of prevention is worth a pound of cure" in medicine, but the security industry isn't so sure. This talk explores the forefront of simple and effective preventative strategies. 11:50 Seacliff ABC Session Security Scaling Defenses Amidst Evolving Threat Landscape Aditi Gupta Staff Security Software Engineer @Netflix Security services that defend against malicious or fraudulent traffic operate in an unpredictable and constantly evolving threat landscape. The dynamic nature of attack traffic means that as attacks evolve, our defenses must evolve too. 13:40 Bayview Session Security Vulnerability Inbox Zero Alex Smolen Director of Security @LaunchDarkly, previously Engineering Manager @Clever, Engineer @Twitter, Security Consultant @Foundstone You have a vulnerability problem. You run a scanner. Now you have two problems - vulnerabilities and a mess of scanner results to process. 14:55 Seacliff ABC Session Panel: Practical Security Aditi Gupta, Travis McPeak, Nimisha Asthagiri, Alex Smolen Join us to continue the conversation around the track theme of practical security, the panel discusses current and future challenges and security issues facing security engineers, practitioners and organizations. 16:10 Ballroom BC Session Security Privacy-First Re-Architecture Nimisha Asthagiri Principal Consultant @Thoughtworks, Previously Chief Architect & Senior Director of Engineering @edX The tech industry grew organically the last few decades. We built new innovations on top of old. We evolved systems and technologies to meet new challenges. Decisions of the past became assumptions of today.