logo

NJP

Set your innovation free, mitigating risk with Aqua Security & ServiceNow

Import · Apr 24, 2023 · video

be like you're able to see everything okay yes awesome perfect so let's get started so as Aaron said my name is minhal gardezi I'm one of the solutions Architects here at Aqua security super excited about talking about this topic with you so we're going to be talking about setting your Innovation free mitigating risk with aqua security and servicenow with both myself and Aquila from servicenow as well so a little bit of an agenda here we're going to start with the challenges of cloud adoption we're going to talk a little bit about the aqua platform as well as servicenow and then go through the winning combination and how we come together to help with that vulnerability management so starting with Cloud adoption so as we know Enterprises are moving to Cloud native for a reason very easy to experiment with very fast Innovation we capture new business and it allows you to adapt and grow and scale at a in a way that we haven't seen before so Cloud adoption is going up and up and as we know from Gartner through the statistic that cloud native support will be 95 of new digital initiatives by 2025. but as we're adopting the cloud there's a lot of barriers to the cloud adoption so you can see some of them outlined here on this slide security and compliance concerns cost complexity lack of skills and Personnel so as Enterprises are adopting these new technologies they're also increasing the threat of their cyber security attacks and especially with this lack of skills and Personnel we know security teams currently are understaffed and required to do more with less so the whole move to Cloud integration has introduced a lot more noise due to the amount of assets and the increased use of Open Source as well so we have a need here now to detect and track all the vulnerabilities and making sure they're being handled for the next zero day Cyber attack so we can see some here again some of the barriers to Cloud adoption as well some of the share responsibilities that we have we don't want to only have Security in the cloud but we also want to control all those administrative controls and policies as well and another great statistic here from Gartner is through 2025 99 of cloud security failures will be the customer's fault our own aqua's team Nautilus they pick up 80 000 attacks a month as well as 18 unique attacks when it comes to uh Cloud security and that's definitely something you would want to get on top of especially if you're adopting this technology moving on when it comes to actually securing it it's not a unique issue so if we look at the 2022 security maturity report that went out we can see that 96 of people uh security compliance and observe observability those are their biggest Inhibitors through uh for cloud security for adopting it 98 of those actually experienced at least one cloud data breach in the past 18 months and then finally there was another survey done by IDC themselves and um basically over half of a cloud cloud users rank themselves at the lowest level of Cloud Security in terms of the maturity of their Cloud security some information regarding the costs of uh not having Cloud security as well cyber attacks and the breach costs are up so year over year there's been a 300 increase in Cloud native attacks there's also been a 245 increase in the cost of a data breach between 2020 and 2022 and the average cost of a database we're looking at here is 9.4 million obviously a significant cost something that we do want to avoid if we can and that's where we leverage our own Aqua products so on my side we're here to talk about the aqua Cloud native security platform we are a cnap solution so what that means is we're a cloud native application security platform we're going to be securing your environment both on the devsec side and the cloud sex side so that includes software supply chain security for your code vulnerability and risk scanning when it comes to all your workloads Advanced malware detection and DTA just for extra layers of protection and then on the cloud sex side we do have cspm Cloud security posture management Cloud workload protection as well as kubernetes security posture management so basically we like to see that the aqua platform is a single platform for multiple use cases kind of gives you one source of security Truth for holistically protecting your Cloud native applications and it connects from runtime to your code so we can pinpoint exactly where vulnerabilities start and stop them as quickly as possible moving ahead from here we're going to see some information about our Cloud uh Aqua Cloud native Security application platform so one thing we do here is pull in all your inventory to our platform once we connect to your Cloud accounts so we'd like to consider ourselves pretty Cloud agnostic we integrate with multiple types of cloud accounts multiple types of deployments and we secure all kinds of workloads from VMS to managed kubernetes containers as a service as well as serverless functions we don't want to miss anything we want to have to have this entire visibility within our environment and understand all the vulnerabilities we're going to be seeing also on that side we do have insights so we want to with all the noise we're creating in our platform we're going to have a misconfiguration from here vulnerability from there we want to provide you insights onto what's most important and Urgent to fix so when it comes to these insights we'll have a lot of compounded vulnerabilities that combine with different uh misconfigurations like having excessive privileges and we'll surface those top insights into your account as well and this we'll talk about later this will also integrate with one of our service style Integrations as well and finally out of the box we do have analytics of our own we do have an analytics page within our Aqua Hub within the console of the UI so this analytics page it's going to give us great reporting uh capabilities from VM vulnerability reports to container vulnerability reports and we will lay out all the information you need right here including unique vulnerabilities unique repos Etc but these interactive reports are really helpful but at the same time don't solve the complete issue of doing complete vulnerability management and that's where we like to tie in with service now um hi everyone I'm very excited to give you a quick overview of service talk uh continue vulnerability response application as as we all walked us through you know once you scan vulnerabilities across your applications there's a need to have a unified view of all the vulnerabilities across Enterprise and service now limited response application helps us get a single pane of class view of all the vulnerabilities across the Enterprise and as you see the vulnerability response application it helped you to integrate with scanners like Aqua from which you can import the vulnerabilities and once you import it you can automate the prioritization using the auto assignment rules or the risk or calculators that get shipped out of the box with the product and using that information it becomes really easy for the security Champions or the devops team or the security teams to triage and remediate the vulnerabilities quickly which is where most of the time spent by these teams going through what do I triage first what do I remediate first what is my priority at the given moment so that really is you know this is applications give them that's unified and View and also a single pin of view of all the vulnerabilities in in one page and once remediated you can use a downstream workflows like change management to record the production changes and close the loop So based on the need to track different vulnerabilities service now vulnerability response application got evolved into different modules like application vulnerability and container vulnerabilities for today I'll be deep diving into the Container availability response application excise peace so um the contender availability response module as I said you know is is designed to bring in the container vulnerabilities from a scanner like Aqua once you bring in that it also creates you know the data model that is required to store the docker image and the image repository all that is built into this module so I would like to quickly walk through the key features of the consider availability response first one being you know um containers are ephemeral in nature meaning they're short-lived right uh once once the once you build a new image the older one gets dropped out the service now creates vulnerable items pointing to image repository all specific Docker image records in the in the configuration management database that way you're not distracting the container running container instances you have the the link back to the source image which you can go and mitigate the vulnerability next slide and servicenow allows customer to decide the granularity so just to take a step back a vulnerable item is a combination of vulnerability which is a cve existing on a container image for the speed of Simplicity right so that can be the customers can draw the granularity of how they want to create each vulnerable item they can choose to create a vulnerable item one per repository and CV combination or using the image tag all the namespace they can use this configuration to drive the granularity and service now automatically tracks any vulnerabilities fixed in old versions and all the closes closes those vulnerable items automatically sometimes scanners might not provide this intelligence but since we have that information already on the server platform it the the application provides you the snapshot of vulnerabilities found and you don't need to remember the history of that and you can track the available items in base image that's highlighted on the screen here so many times what happens is the base image might be handled by different team versus the actual emotional image that's already running in the production environment so if you select That Base image option that creates a separate record to be tracked and gets assigned to a different team like uh devops so that way both the the vulnerability is getting mitigated at both the places at the base Image level as well as at the running container level next one please so that before I give it to mihal back the remediation owners can also raise exception requests or false positive requisite or their workforter already built into the Container vulnerability response module and it also has the multiple level of approval system built into it that way you know when the exception is raised uh it goes to a appropriate approver and gets approved and then you know it gets flat as um acceptable requested for this vulnerability so now I'll give it back to minhal to tie these two products together and how we have integrated and what value we are driving from that thank you so yeah wonderful so that's what I'm here to do I want to tie everything together how aqua and servicenow can work together hand in hand so basically our unified scanner is going to provide accurate and consistent results across the application lifecycle saving time and resources we're going to get all these vulnerabilities for you and lay them out as clearly as possible but obviously we want to integrate with the vulnerability management tool get all of our vulnerabilities pulled into those containing vulnerability items so firstly I would like to talk about our initial service now integration with our response policies so this is not going to necessarily fully help with vulnerability management but we are able to send uh different triggers and actions to servicenow based on things that are happening in our environment including those insights I talked about earlier different scan results that we might have such as assets with critical vulnerabilities or incidents that are going on with uh in our console whether it be behavioral malware any sort of incident that we are finding out we can set off a trigger and then set it off with our servicenow integration with the Json template that we have integrated within our response policies as well but the big thing we're here to talk about is the aqua app within servicenow So within service style we'll have our own Opera Aqua security app uh within the integration configuration all you'll need to enter is basically your Cloud URL which at this point if you're using SAS would just be cloud.aquisec.com along with your username and password and with that we'll be able to set off our integration as well as our schedule and basically pull in all the vulnerabilities within the servicenow so automating this vulnerability uh management and incident response within servicenow provides a lot of value as opposed to just seeing the vulnerabilities in the list we're going to reduce the amount of false positives and will allow the vulnerabilities to land in the hands of where they need to be fixed as well so you can see here on the container vulnerability items page we do have uh the cvit number as well as the summary information about the image repository the risk store the risk rating and the severity and state we'll also be pulling in things from Aqua such as R Aqua Scopes as well as our Aqua remediation options if we go deeper into the view I apologize if this is a bit small but as I said we're going to have the source here that's going to be Aqua security a lot of the same things Aquila was showing us earlier including the cve docker image info image repository info as well as the discovered container image and then from here we will have a summary of the vulnerability that is pulled in from our Aqua vulnerability database as well as under notes any notes we have in servicenow and then in the aqua security tab that's where we'll be labeling our different application scopes yeah I just tried a couple of more points here minhal um you know if the customer is running the kubernetes ideas and Discovery in their environment it also correlates based on the docker image it brings in all the image clusters and the namespaces that's already available in the cmtp and gets highlighted on the seawit which is the cultural vulnerability item record so you think that that makes it really easy to drive the assignment Auto assignment rules to send these um see which 12 appropriate assignment groups to for the remediation to happen so that makes it a very neat transition and then also automated workflow awesome thank you for that point and just as a final slide just uh basically what we're doing here is we're gaining visibility we're saving time we're reducing risk we're going to be able to prove our compliance and finally consolidate and optimize so with the power of aqua's uh scanning ability as well as the vulnerabilities with the combined with servicenows vulnerability management you'll be able to take care of those vulnerabilities as quickly and as efficiently as possible and one plug I just want to really quickly do before we end the presentation is come see us at RSA I myself won't be there but Aquila will be driving this presentation so driving value from confusion transforming alert fatigue into business efficiency using aqua and servicenow that'll be on Wednesday April 26th at 10 30 a.m PST so thank you from both aqua and service now so uh any questions there in terms of when the integration will be available so that is uh I would say very soon uh Eli I'm not sure if you have a specific uh date on that but we will we do plan to bring this integration uh to BGA very soon and we will likely try to align that with RSA as well I can answer some of these questions live can I give you the next question what slow components are required to integrate Aqua to snow so uh for the integration purposes we need entitlement for the container vulnerable response but if you have the itsm kubernetes discovery running it you can leverage the value of the integration with added um data points as I was talking about you know if you can have the kubernetes cluster information namespace information that really helps you to drive the assignment rules much better but that's not limited you know you can still do the assignment rules based on the data that's getting populated on the discovered items you can still use that to try the assignment rules yeah one question about demonstration so um there was a technical issue with the demo for today so one thing we wanted to make sure that we uh highlight is that we there is there is a demo environment available and if you do have um you know if you're curious about that we I believe we have video resources we can also do a follow-up so while we answer these other questions I'm going to launch this poll and um if you want to see a more in-depth demo or you want some help actually installing and configuring say you have both aqua and servicenow VR and you didn't realize that this integration was out there and you want some you know some guided support in installing that uh we'd definitely be um you know I think Eli and team would be all about [Music] um you know following up with you and and and and helping with uh something some of those activities so it could be could be demo could be more of like a you know like a Live support on that all right so see that's answered and then um do we want to address you know when the uh when the integration is available is the next question in my list so this integration is currently still in beta is that right yeah that's right right so one of the follow-ups if you do indicate yes in the follow-up you can be included in that beta as well so there are customers who are already testing this on an ongoing so as soon as those those feedbacks are finished um the beta will be you know finalized and this will go ga but obviously the aqua team wants to fold those feedbacks into the integration before you know releasing it to releasing It generally so that you know everyone gets the benefit of those changes um so again like if you can indicate yes in the survey then we'd definitely be interested in um in getting you a preview of that I see a question Aqua will be integrated with module vulnerability response and config compliance or containers so it's integrated with vulnerability response containers specifically not for config compliance foreign container and not container VR and not container CC just yet um a question from uh Gail how to tie Aqua vulnerable items into our cmdb or if they create CIS do you want to go back into any of the um demo screenshots and show how those are created or show where those you would expect to see those yeah just to I mean weekly walk uh get through here so as I was showing on my on my um it I mean how do you have the screen back when I was yeah I couldn't reshare the slides one second thank you just let me know what slide you wanna just first slide you can go back to after the web yeah next group yeah as you see here once the data comes into the services platform let's say if there was no Discovery running and you don't have the data in cmdb already the Discover container image gets created from which a CI is created as you see the docker image and that builds a relationship already and you can use that um so basically that's how the the CIA gets tied to and also the Dockside service.com has a lot more information on how this is currently working so you can refer to that for more details yeah revenue from Eli saying that um actually already gone to betas or to GA certification so um integration ETA is actually just a couple of weeks so that's a sort of fresh off the presses for everyone who's attending the webinar today um we expect this you know by probably early May um you know would be uh the sort of approximate timeline at this point right so again we have about um two-thirds participating in the poll if you're interested in you know obviously you know getting an announce like say you want to get an announcement of that integration availability as soon as it's done um we will reach out directly the aqua team will reach out directly and um and get in contact with you so if you're if there's any interest in getting on that list as well um I'll just indicate so in the um in the poll question any other uh technical questions um regarding the integration how it works um Louis Vuitton Hall Eli any closing thoughts oh question in ah one second there's a chat question as well one second ah okay how does service now stay up to date with the CBE landscape across containers and images uh because containers you know are ephemeral basically so how do we understand you know you know uh when a CV is detected by aqua and when it's when it's actually remediated and what does that look like so you know Aquila do you want to take this yeah feel free to add I don't know if you have any other thoughts there the one thing they continue vulnerability response module has offered is um Auto close configuration which is set to by default one day given the nature of the continuous is really familiar you know they just disappear or they are they're trashed within a day also so you bring in and you we create the record for that particular image and the CVA combination and then in the next run they get updated as closed if that's not found so that's and then uh it the same the vulnerability might have been remediated and there's a new image created so it creates a new record that way you know you know that the old image is gone and then you can still tie it back to the base image so you if if the base image is still existing at different location or it's if you want to go fix the vulnerability on the base image you can still do that yeah because it's more there's sort of more like a snapshot Behavior versus you know patching an application that's like you know constantly running or you know continuous in runtime so it's a little bit different than your VR VR infrastructure model all right we have another question is there a list of snow or service now modules required for the aqua integration and are there any additional that are optional so I guess if there's anything that can be used to enhance the behavior of Aqua that's not necessarily a prerequisite and um Aqua response policies are required to send data from Aqua to servicenow that I think um let me know I'll let you take that third one so uh for servicenow modules it's a application vulnerability response check me on that Aquila is that right um container vulnerability yeah container vulnerability sorry yeah so part of our um I believe it's part of our pro package and um additional modules I don't believe at this time we have like an intelligence offering along with that you know we do have Integrations that bring in additional data you know over and above what's in you know the cve like nvd database so it's possible that we could relate that data to um you know vulnerabilities based on keying on that CBE field I don't think there's anything out of the box for that just yet but that's a good thought as to things that you could do if you already have that data coming into service now through another integration and then I mean Hall um can you address the question on Aqua response policies absolutely so response policies is actually a feature that's already enabled right now within Aqua Hub so that is more of a notification system integration so that's going to be set off by certain triggers in the aqua console like I said it could be scan results it could be specific incidents within your environment as well as those insights we surface so that's separate from the actual uh new integration we were showing today so um that integration is still able to be used uh that requires just a simple servicenow integration that you would do within the aqua console but in order to configure the container vulnerability response and all those container vulnerabilities coming into service now we would configure the actual plug-in and module Within servicenow so I'm sorry if I didn't separate those two items a little bit but uh just for a little bit of clarification the response policies that's a separate side all right then another question how does aqua and servicenow for container vulnerabilities differentiate between sast and dast like the you know the code versus the runtime yeah so at the moment uh this is uh the data that's been brought up or imported is is dynamic which is runtime vulnerabilities on the containers um not the static ones but definitely the application vulnerity response does have uh support for static and dynamic but for container it's more of runtime because you know uh runtime is those are important the base image or the static versus the runtime but in container case you really want to know where the container is running to go ahead and address that so the current support for the container is more on the runtime possibilities all right great well um we've made a note of those who like to be contacted afterwards and I look forward to working with you in the future on this you know disintegration um any final comments mean hall or Aquila well I'm excited to see where this integration goes I do think it's going to be very useful for both aqua and servicenow users and I appreciate everyone for the time as well and uh see whoever comes to RSA as well yeah okay another question Dale wants to know um are you saying only runtime events or input in search now right now and not image scans so probably uh Gail we can confirm back to you on that um but runtime definitely we are supporting yep yeah that probably needs a little bit of clarification yeah cool yeah and indeed like we are um yeah we'll be we'll be um at a few different events at Aqua we have service now folks there um so obviously look forward to uh seeing you and I think we um we may also have a session at the aqua the aqua Booth we're not mistaken so what you do when that is off the top of your head I mean I'll just share that it's on Wednesday 27th at if you want to see that bag all that out Wednesday I have a slide for it there we go all right okay oh no it comes to us at RSA that'll be Wednesday April 26th at 10 30 a.m PST and obviously you don't have to come just at that point to uh ask any questions about the integration more than welcome to visit the um the aqua booth and uh let us let them know if you want to have sort of a you know joint um follow-up we're more than happy to assist the aqua team as they uh as they launch this integration um you know this for the rest of this year and we'll have some incredible Technical Resources at that Booth so feel free to stop by any questions you have awesome all right well um I think that wraps it up and thank everybody for your attention staying with us a little bit past the half hour Mark um you know if we have an update on the content with the integration obviously there's some interest in you know other use cases and so as those um you know as those activate and launch we will we'll probably follow up in the same Forum so look for those announcements in the future and um hopefully join us for those updates and we look forward to seeing you soon

View original source

https://www.youtube.com/watch?v=wM9ATa7ceQU