-

Kaspersky Hybrid Cloud Security Protects Software Development Tools From Supply-Chain Attacks and Adds Integration With Google Cloud

WOBURN, Mass.--(BUSINESS WIRE)--Kaspersky today announces that the next generation of Kaspersky Hybrid Cloud Security now safeguards software development operations (DevOps) environments. The product has been enhanced to enable protection for containers, add containers, image and repository scanning capabilities for integration with continuous integration and delivery pipelines (CI/CD). Additionally, to support business use of a wide range of public cloud platforms, Kaspersky Hybrid Cloud Security now includes integration with Google Cloud.

Supply-chain attacks that affect software development, such as when a malicious piece of code is added to legitimate software, are effective tools for cybercriminals. For example, this method was used in the ShadowPad attack where a backdoor was embedded into a popular legitimate business software product’s code library. Supply-chain attacks also strike open source repositories, such as when Docker Hub found 17 backdoored container images, or when RubyGems caused users to download 725 malicious packages almost 100,000 times.

Protection from such supply-chain attacks is essential for software developers, though it can be difficult to find an effective security tool because validating the integrity of fast-changing development environments in a moment’s notice is often technically challenging. A cybersecurity solution should also not affect an application’s time to market or the overall flexible approach to IT that DevOps is accustomed to, such as being able to scale cloud workloads up and down or use different open source tools.

Kaspersky Hybrid Cloud Security reconciles the two worlds of DevOps and IT security. It helps businesses integrate security tools into the development process to minimize the risk of container compromise and supply-chain attacks without impacting development speeds.

The product now enables Docker containerization environments to be protected through granular AV scanning. Using file threat protection, it scans containers and images and all their layers to reveal threats, even those in lower layers. Scanning can be performed as objects are accessed in the namespaces of running containers (on-access scan, OAS) and within tasks with flexible scope control (on-demand scan, ODS). It also allows kernel memory scanning. Added network and web threat protection ensures safe internet traffic and the prevention of network attacks on Linux hosts and containers.

Kaspersky Hybrid Cloud Security safeguards the use of open source code repositories and prevents supply-chain poisoning. Software developers can add security steps into continuous integration and delivery (CI/CD) pipelines including TeamCity or Jenkins Pipeline, among others. Integration is available via command-line and application programming interfaces (CLI and API) that allow developers to run scripts in pipeline management tools for container and repository image scanning at different stages.

Additionally, users of public cloud platforms for software development and other business needs can choose from more options, as the product can now be integrated with Google Cloud as well as existing offerings such as AWS and Microsoft Azure. Kaspersky Hybrid Cloud Security can be seamlessly extended to a customer’s workloads in Google Cloud. Security management for cloud environments is available through a single control panel in Kaspersky Security Center.

Continuous software development is a unique environment that needs a specific cybersecurity approach. To stay nimble, DevOps may go as far as bypassing formal IT approval processes, making it a challenge to build cybersecurity into the development journey,” said Andrey Pozhogin, senior product marketing manager at Kaspersky. “However, it is important to leverage containers and open source code securely to reduce the risk of unknowingly embedding malicious code into software, as was found in the RubyGems attack and other cases. Kaspersky Hybrid Cloud Security helps businesses find a way out of this challenge through a win-win scenario where IT security and DevOps cooperate. The solution provides understandable tools for DevOps that don’t affect their processes; and it helps IT security teams to put in place a proven protection layer for the part of the infrastructure that may not yet be covered.”

More information about Kaspersky Hybrid Cloud Security and DevOps protection can be found on the product page.

About Kaspersky

Kaspersky is a global cybersecurity company founded in 1997. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection and a number of specialized security solutions and services to fight sophisticated and evolving digital threats. Over 400 million users are protected by Kaspersky technologies and we help 270,000 corporate clients protect what matters most to them. Learn more at usa.kaspersky.com.

Contacts

Media Contact:
Cassandra Faro
Cassandra.Faro@Kaspersky.com
781-503-1812

Kaspersky


Release Summary
Kaspersky Hybrid Cloud Security protects software development tools from supply-chain attacks and adds integration with Google Cloud
Release Versions

Contacts

Media Contact:
Cassandra Faro
Cassandra.Faro@Kaspersky.com
781-503-1812

More News From Kaspersky

Kaspersky North America Wins Silver for “Support Department of the Year” in the 10th Annual Best in Biz Awards

WOBURN, Mass.--(BUSINESS WIRE)--Kaspersky North America has been named a silver winner in the “Support Department of the Year” category of the Best in Biz Awards, the tenth annual business awards program judged by prominent editors and reporters from top-tier North American publications. The award was achieved by the Kaspersky North American support and services department, which delivers a wide range of premium support, professional services and training offerings. Throughout the year the team...

Kaspersky Report: Criminals Targeted Remote Work In 2020

WOBURN, Mass.--(BUSINESS WIRE)--Kaspersky researchers have analyzed the redistribution of threat activity that took place in 2020, as the COVID-19 pandemic caused a worldwide, involuntary shift to digital platforms and tools used to work and carry out other aspects of our lives from home. The new way of life resulted in organizations adjusting their corporate networks and led to the emergence of new threats to target those networks, as well as the strengthening of existing threats. Details on t...

Safe_expression: Kaspersky and KRAKATAU Present Unique Clothing Collection Customized by Your Digital Imprint

WOBURN, Mass.--(BUSINESS WIRE)--Today, self-expression is not only about showing our individuality through the clothes we wear and how we look but also by what we do online - with many of us using new media to share our views and beliefs. How can people create their digital identities and express themselves while keeping their unique personality safe online? To raise awareness about the importance of privacy and freedom of self-expression, Kaspersky and international techwear brand KRAKATAU hav...
Back to Newsroom