Jayesh Ahire

speaker
67 appearances 1 recordings 1 series first heard Oct 2024 last heard Oct 2024

Jayesh Ahire’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
No recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.

Appearances

newest first · ▶ plays the moment
There's a study which says that a defect which is fixed before things go into production can save you 100 times the cost of fixing that in production. To save that money is just one part of it, but to save yourself and your organization from the impact of
some of these things, having everything native to your development lifecycle and making sure that you catch these things very early in the development lifecycle improves reliability, improves the security by a large extent. But when we talk about framework or the pipeline, how can we get there? A few things I'll point out are
Make sure you have the whole SAST, DAST tooling in place along with your container scanning, ISEs. When we talk about APIs broadly or development life cycles broadly, there are three stages before it goes to distribution. Design, develop, deploy, and then last phase is distribution, which is running it in production, making sure it's publicly accessible.
When we talk about design, develop, deploy, and distribute, first three things, design, develop, and deploy has a lot of nuances in it. I will say very first thing is security is always an afterthought. And to address that problem, make sure that when you design your APIs, you consider all of the security practices into that design.
Let's say you're building an API, make sure it has the strongest authentication in place. Make sure it is not susceptible to
the bolas and baflas of the world make sure it is not exposing any sensitive information to public so having all of these considerations while you design the apis saves a lot of pain then as you go forward there's a development phase and then development phase while you are building the apis enabling your development teams think security first definitely helps and that's where having the right queues in place when they are pushing things when they are creating the builds
Testing those builds with various tools, having the SaaS tools in place gives them a path towards a better and secure development. Then when you deploy and create the containers, you actually create this infrastructure as code pipelines, the Terraform server.
having the security layer there as well helps you with another gate so all of these gates coming together relatively help you create a secure system overall and the security testing plays a great role when it comes to level between develop and deploy
So before you go and distribute it to production, you actually should run automated security testing, which will catch things like OWASP API top 10s, any of the PCI DSS vulnerabilities, anything that can help you or your organization to meet the compliance standards, as well as make sure you have a better security posture overall.
All of those vulnerabilities should be continuously and automatically running on your staging environment If any of those vulnerabilities are found, we should be able to mitigate them before things go into production. That framework helps us to visualize and propagate it to our customers as well.
I think that lays out a great foundation of how organizations can approach that, especially the mindset point that you called out, where people are taking cues and really thinking differently about how they're going about doing their testing and making sure the APIs don't have those vulnerabilities. I'm curious about what sort of tools and methods that you would recommend.
Obviously, you know this space quite a bit. So what tools or methods would you recommend for continuously testing APIs and ensuring they remain secure as they evolve? And I think you may have touched on a couple there in your last answer, but I'm curious of what you would say.
It categorizes organizations into two types. One is organizations which are very early, just got started trying to get things out of the door and at least start building something. And the second, the series B, series C, post that enterprises which are mature, which are trying to build rigid pipelines, making sure everything goes as expected and as smoothly as possible.
So when we deal with early stage organizations, the problem is everybody is an engineer. There's no security when we are dealing with early stage companies. Everybody just wants to get things done. That's where we make a lot of mistakes when it comes to security. We take a lot of things for granted.
And I will say one of the things which we can do there is at least make sure the developers understand the security and making right choices.
second thing to do that like to help them make the right choices just having any sass tool in place can be a good start it doesn't take much you can go with the open source sonar queue kind of a setup which will help you get started and that becomes the first entry point then second thing is having the right set of dash tool in place which
Again, as I stated earlier, these things can produce false positives, but they can at least help you get started on your journey towards the better security posture. And as you mature, things become more complicated.
Now, instead of dealing with one API, which was running in your AWS account, like one EC2 instance, now we are dealing with thousands of APIs, a large Kubernetes cluster, maybe in multiple regions, and At a maturity stage, you want to get the inventory management in place where you know all of your APIs, what the problems are, how they are designed.
You need controls on your design stage as well because you want to make sure that your API design adheres to some standard your organization has set. So that's different tools at different levels. But PI security testing plays a great role in the mature organizations for inventory management, for posture management, for security testing, for contextual security testing, for lack of better words.
We are not just running things against the black box. But you're actually running the security testing with all the API context in place, all the understanding of an API in place. So that way you produce very pinpointed results, tell users what are the exact vulnerabilities, how to fix them, help them fix it.
Showing 41–60 of 67 · page 3 of 4 ← Previous Next →