[ad_1]
These issues, he said, could disproportionately affect small and medium-sized businesses and would be nearly impossible to solve easily. sound pattern analysis About 30% of Log4j consumption was found to come from a potentially vulnerable version of the tool. “Some companies don’t get the information, they don’t have the material, they don’t even know where to start,” Fox said. Sonatype is one of the companies that offers scanning tools to identify problems, if they exist. One customer told them that if they didn’t, they would have to send an email to the 4,000 app owners they work with, asking them to individually determine if they were affected.
Part of the problem, of course, is the over-reliance of for-profit businesses on open source, free software, which is developed and maintained by an oversized team of small volunteers. The problem with Log4j is not the first – Heartbleed flaw that ravaged OpenSSL in 2014 is a striking example of a similar problem – and it won’t be the last. “We don’t buy things like cars or food from companies with very bad supply chain practices,” said Brian Fox, CTO of software supply chain management and security specialist Sonatype. “However, we’ve been doing this with software.”
Companies that know they use Log4j and are using a fairly recent version of the utility have little to worry about or do anything about. “That’s the answer to not being sexy: It’s actually pretty easy,” Fox said.
The problem arises when companies don’t know they’re using Log4j because it’s used for a fraction of the applications or tools introduced, and they don’t have oversight and no idea how to start looking for it. “It’s a bit like understanding what iron ore goes into the steel and then into the pistons of the car,” Glass said. “As a consumer, you don’t have a chance to figure that out.”
Log4j’s vulnerabilities in the software library make it difficult to fix, Moussouris said, as many organizations have to wait for software providers to patch it themselves — which can take time and testing. “Some organizations have people in-house with higher technical skills who can work out different mitigations while they wait, but basically, most organizations rely on their vendors to produce high-quality patches that include updated libraries or in these packages newer ingredients,” she said.
However, companies large and small in the United States and around the world have had to move quickly. One of them is Starling Bank, a UK challenger bank. Because its systems are mostly built and coded in-house, they were able to quickly detect that their banking system was not affected by the Log4j vulnerability. “However, we are also aware that there may be potential vulnerabilities in both the third-party platforms we use and the source code of the libraries used to integrate them,” said Mark Rampton, head of cybersecurity at the bank.
have. “We quickly discovered instances of Log4j code that existed in third-party integrations that had been replaced by other logging frameworks,” he said. Starling removes these traces and prevents them from being used in the future. Meanwhile, the bank commissioned its Security Operations Center (SOC) to analyze hundreds of thousands of events to see if Starling was being targeted for a Log4j vulnerability. They don’t, but are watching closely. The effort required is enormous, but necessary, Rampton said. “We decided to take the ‘guilty untold innocence’ approach because vulnerabilities are being exposed so fast that we can’t make any assumptions,” he said.
“I know where the FTC is trying to come from,” Thornton-Trump said. “They try to encourage people to do vulnerability management. But it absolutely falls on deaf ears as to the actual threat risk this vulnerability poses to many businesses. They basically make you press the panic button and you don’t even know if you have it now.”
More exciting connection stories
[ad_2]
Source link






