UPDATED 09:00 EDT / NOVEMBER 14 2023

SECURITY

New Lacework features provide full visibility through the application development lifecycle

Cloud security company Lacework Inc. today announced the addition of new code security features that provide Lacework customers full visibility throughout the complete application development lifecycle.

Lacework’s new code security features have been designed to prevent security issues from being exposed in the wild by identifying them before the code is deployed. The service also assists in prioritizing and fixing problems faster, wherever they are found in the application lifecycle.

The release reflects Lacework’s belief that the best way to achieve security outcomes with speed requires continuous visibility and context, including knowing where every software package is running and the ability to capture and correlate data across the application lifecycle. The approach is claimed to empower security teams to be more efficient by eliminating the need to stitch together data and findings from different sources, consolidating them into fewer tools that deliver higher value.

The release introduces two new forms of static program analysis: Software Composition Analysis and Static Application Security Testing.

Software Composition Analysis gives customers continuous visibility into third-party software libraries and associated vulnerabilities, including direct and indirect dependencies. The approach goes beyond basic SCA functionality and gives teams constant visibility into exactly where vulnerable functions are used in the code, including how often each is referenced, who was responsible for bringing it in and who owns fixing the code. Customers gain an always-up-to-date software bill of materials for every application, continual visibility into their software supply chain and an understanding of open-source license risk, according to the company.

With SCA as part of the Lacework platform, customers can track a vulnerable package’s entire lifecycle, including its use in source code and its activity within any cloud-native workload. The active vulnerability detection is accomplished using an extension of the Lacework runtime agent known as Code Aware Agent.

Static Application Security Testing complements SCA to provide comprehensive code security capabilities to help organizations understand how first-party code could be exploited. SAST identifies source-code weaknesses in in-house code that attackers could use to bypass security controls, run malicious commands or exfiltrate sensitive data. The tool provides customers with an automated and intuitive secure code review that is easily actionable by entry-level and senior security analysts.

SAST also gives application security engineers visibility into complex vulnerabilities within their most exposed internet-facing applications. Lacework provides an in-depth model of each application, tracking the path of untrusted data to detect and remove zero-day or yet-unpatched vulnerabilities that could result in dangerous exploits such as SQL injection.

Image: Lacework

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.