Skip to content
AppSec PodcastThe Application Security Podcast — home
29 min

Patrick Dwyer -- CycloneDX and SBOMs

With Patrick Dwyer

OWASP ProjectsSoftware Supply Chain

Patrick is a Senior Product Security Engineer in the Application Security team at ServiceNow. He is also Co-Leader of the OWASP CycloneDX project.

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 10 chapters
  1. 00:00Meet Patrick Dwyer: CycloneDX and SBOMsAudioVideo ↗
  2. 05:07Awesome. So I want to, I want to transition into talkingAudioVideo ↗
  3. 07:36I guess what was the need when this project was startedAudioVideo ↗
  4. 10:01So, so they have kind of different functions then. So IAudioVideo ↗
  5. 12:12Cool. So let's back up for a second. I probably gotAudioVideo ↗

About this episode

Patrick is a Senior Product Security Engineer in the Application Security team at ServiceNow. He is also Co-Leader of the OWASP CycloneDX project. A lightweight Software Bill of Materials (SBOM) standard designed for use in application security contexts and supply chain component analysis. Patrick Dwyer is a senior product security engineer in the application security team at ServiceNow. He’s also co-leader of the OWASP CycloneDX project, a lightweight software bill of materials standard designed for use in application security contexts and supply chain component analysis. Patrick joins us to help us understand how CycloneDX fits into the world of protecting your software supply chain. He explains why they started the project and what is the depth and breadth of it, how many people are using it, and what is the future for CycloneDX and software supply chain.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Patrick Dwyer is a senior product security engineer in the application security team at ServiceNow.
Learn more about Security Journey

Connect with Patrick Dwyer:
CycloneDX
ServiceNow

Resources
CycloneDX
ServiceNow
CycloneDX
OWASP Dependency-Track
SPDX
Docker
JC Herz and Steve Springett – SBOMs and software supply chain assurance

Actionable

From this conversation

  1. Use SBOMs to understand supply-chain components

    A lightweight software bill of materials standard designed for use in application security contexts and supply chain component analysis.

    0:00
  2. Generate accurate SBOMs from build metadata

    Go's got good inbuilt metadata capture that enables a accurate SBOM.

    20:25
  3. Start examining your dependencies

    People need to get out and start looking at those dependencies.

    27:28
Transcript · 29 min conversation

0:00Chris RomeoPatrick Dwyer is a senior product security engineer in the application security team at ServiceNow. He's also co-leader of the OWASP CycloneDX project, a lightweight software bill of materials standard designed for use in application security contexts and supply chain component analysis. Patrick joins us to help us understand how CycloneDX fits into the world of protecting your software supply chain. He explains why they started the project and what is the depth and breadth of it, how many people are using it, and what is the future for CycloneDX and software supply chain. So if you want to gain an understanding for how you can apply SBOM into the applications and products that you're building today, check out this interview with Patrick Dwyer.

0:49Robert HurlbutYou're about to listen to AppSec Podcast.

0:53Patrick DwyerWhen you're done with this, be sure to check out our other show, High Five.

0:59Robert HurlbutHey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo, CEO of Security Journey, and today I am flying solo because Robert is traveling this great United States that we both happen to live in. Today we're going to talk about SBOMs, but we're going to talk about SBOMs in the context of an OWASP project called CycloneDX. And so I'm joined by Patrick Dwyer, who is one of the team members on the CycloneDX project. But before we get to that, we're going to ask Patrick about your security origin story because our listeners literally sit on the edge of their seats waiting to understand where people are coming from in this great big world of application security. So Patrick, I'd love to hear your security origin story.

1:50Patrick DwyerYeah. Hi, Chris. Thanks for having me. I guess really it started when I was a child, started getting into computers, started messing around with them. Probably one of the key sort of moments was in high school. Our computer teacher at the time thought his stuff was pretty secure, and he even made a joke, oh, you can't hack the server, you know, give it a go, there's nothing you can do. So of course, by the following day, the server was offline.

2:22Robert HurlbutWow.

2:24Patrick DwyerHe wasn't too happy about it. He threatened, you know, the entire class with, you know, expulsion or whatever. And so I put my hand up and said, hey, no, no, it was me. It was just me. But you said give it a go. And he sort of stopped right there. And yeah, after that, we had a great relationship, a lot of respect for each other, but it just sort of started really making me think with that sort of mindset of where things can go wrong. And that continued throughout my career. Started off as basically a one-man IT department for a small company, uh, so had to look after everything— network security, servers, all that sort of stuff as well. Then went to became a software developer by contract. So doing odd 3-month, 6-month, multi-year projects, things like that. That was more just come in and cut some code. But then my next job, I was leading the dev team for a small government organization and had a lot of stuff we were looking after. And that included our cloud environment, basically everything from woe to go. And at that point I was like, oh, the stuff that I've been interested in all this time, I really need to get up to speed on it because I'm now responsible for this stuff. And if it gets popped, it's my fault or my problem. Uh, so that's where I really got into AppSec.

4:03Robert HurlbutVery cool. So now I'm curious, was your, was your handle in high school Little Bobby Tables.

4:10Patrick DwyerNo, it wasn't that.

4:13Robert HurlbutEverybody's got to have seen that. Yeah, it's an XKCD. We'll put the link in the show notes.

4:20Patrick DwyerI love it. But the—

4:20Robert Hurlbutit's, it's a classic one too. And I always— I still laugh whenever I see it. It's like— and someone will kick it out on social media every, every 6 months or so and bring it back into the forefront. Yeah. So, so you basically So you kind of started in IT, had it, did some development, and then made your way to security. So kind of a— had a chance to experience a little bit of everything. So from the IT side, I'm guessing you were doing some administration and then your coding, and then you're making your transition into security. So having that strong foundation of, you know, the things that you're going to be discussing with people from a security perspective, you've got some, some background in all those things.

5:01Patrick DwyerYeah, yeah. Pretty good breadth of knowledge. It's been quite good.

5:07Robert HurlbutAwesome. So I want to, I want to transition into talking about CycloneDX, but I'm going to ask a really simple question first because I'm not going to assume that our audience all knows what Cyclone, what a CycloneDX even is or what it is. And so I'm going to go really simple with the first question and just say, can you just, just give us some details and some explanation about what is CycloneDX?

5:31Patrick DwyerSo CycloneDX is a bill of materials standard and associated tooling. The way we build software has changed. We grab all these third-party components and bundle them into our software. The traditional IT asset management of these are the applications we have doesn't really go deep enough anymore. because we've got all these other third-party components in them. So it's just a way of understanding what's inside the box, a bit like the food label that lists the ingredients of what goes into your food. It's a pretty basic analogy, and we don't build software the way we put together food, but it's similar to that.

6:16Robert HurlbutOkay. And so where did the name come from then of CycloneDX? It's an interesting name, one of the most interesting names, I think, in all the OWASP projects. I mean, you've got Top 10, ASVS, you got things like that, but CycloneDX sounds like a pretty powerful name.

6:33Patrick DwyerYeah, it's— so the Cyclone part of it is a reference to circular dependencies and the problems they can cause you when you're building software. And the DX part is a bit of a nod to another format called SPDX.

6:51Robert HurlbutSo it's kind of like a— so it's like a hybrid or— so SPDX and CycloneDX are not the same standard, are they?

7:02Patrick DwyerNo, they're different.

7:03Robert HurlbutDifferent in some way. So are they— are these— so we've got basically 2 competing standards in SBOM right now, or is there more than 2 that I'm not even— are there more that I'm not aware of?

7:12Patrick DwyerThere's certainly more than 2 formats, but there's 2 main ones that have seen sort of widespread adoption. SPDX traditionally has come at it from the open source software license compliance sort of perspective, whereas CycloneDX come in from the security perspective. Okay.

7:35Chris RomeoSo I guess what was the need when this project was started?

7:39Robert HurlbutLike, why did CycloneDX come into existence?

7:44Patrick DwyerYeah, so there's a guy, Steve Springett. He had a project called Dependency Track, and he was basically trying to come at the same sort of problems that you use SCA for, but a slightly different way. You know, SCA tools traditionally, they'll, you know, they're about identifying risk in software, and they look at evidence and things like that to try and figure out what could be in there and what vulnerabilities could be in there. But if you're building software, you should know exactly what is going into it. And so he was tackling it from the, all right, well, these are the actual components we've got in our software, and we'll go from there. And at the time, there wasn't really anything useful for feeding that information into a tool like Dependency Track. And so he sort of started the dependency tracks stage and then realized, no, hang on, we need a bill of materials format to collect this information and feed in.

8:47Robert HurlbutSo when I think about all these pieces working together, this has really got my brain kind of spinning around a little bit. So I have software composition analysis. This is a tool that will, you know, I can run it in a build pipeline. It tells me and and even sometimes breaks the build if there's some type of high-risk vulnerability that exists inside of my application. I have CycloneDX, which is going to create a software bill of materials and then perhaps be imported into some other system that's going to aggregate all those things together for me. I guess the million-dollar question is, is CycloneDX a replacement for SCA, or is it complementary to SCA in some way?

9:34Patrick DwyerI think it's complementary. You know, it's particularly useful because it's a standard format. You can generate them for different ecosystems, like different package ecosystems, share that information between different tools and automation. And yeah, that's really where the value comes from, where you're sharing this information between different processes.

10:01Robert HurlbutAnd so, so they have kind of different functions then. So I wouldn't use CycloneDX in a build pipeline then, or would I use it?

10:07Patrick DwyerYeah, you would. You would. So you, you build your, you create your bill of materials as part of the build process, and then you can do analysis on what's inside your software, similar to what SCA tools do, you know, known vulnerabilities, things like that. But it gives you a much bigger picture of your supply chain.

10:28Robert HurlbutOkay, so do I still run my SCA tool in that same pipeline then, or do I just run my CycloneDX?

10:34Patrick DwyerWell, it depends on what you want to do.

10:37Robert HurlbutSo is there a— it's a duplicate. So there is potentially some duplication of effort though if I'm running both of them, or I guess they could be a check and balance to each other. Yeah, of multiple layers of tooling.

10:49Patrick DwyerI know there's, you know, SCA tools generally are pretty good, but sometimes the accuracy of what the components are isn't quite 100%. And so there's certainly some value in doing both.

11:04Robert HurlbutI mean, one of the things you hear people complaining about with software supply chain-related tooling is like SCA tools are not as good at determining if you're using a piece of code, like, are you actually using a vulnerable piece of that library? And so SBOM is not going to help me from that perspective though, right? It's not going to know. It's just, it's just a manifest of everything that's in there. It's not helping me laser focus. I don't really know if that piece of code is being called like in a vulnerable way, for example.

11:36Patrick DwyerWell, there are, there is some tooling there, um, which generates a runtime BOM. So what's the components that we're using? Like not just what's actually packaged in the software, but what's actually being invoked as well.

11:50Robert HurlbutOh, so that's part of CycloneDX?

11:53Patrick DwyerThat's a third-party product that uses CycloneDX format.

12:00Robert HurlbutOkay, uses CycloneDX format to get to that level. Okay. But it still relies on the standard format that the project, the OWASP project has put forth to the industry.

12:10Patrick DwyerYeah.

12:11Robert HurlbutOkay, cool. So let's back up for a second. I probably got too excited about CycloneDX and dove in too quickly here. Let's kind of pull back up to the 10,000-foot view and let's just think about— everybody's thinking about software supply chain, whether you're a CISO, whether you're an AppSec person, or even just a developer who maybe doesn't have security in their title or security as their primary focus. I feel like everybody has heard, you know, everybody's heard about the news stories about, you know, SolarWinds and CodeCov and all the things that have the big— and it seems like there's an npm supply chain-related issue once every week now, you know, that hits the news. So I feel like people know, they know about, they're hearing about it, but I'm just curious to get your take on, you know, what is the value that CycloneDX provides to the bigger software supply chain problem?

13:04Patrick DwyerI see it as an enabler. So by itself, it doesn't actually do very much. We're really— what we're talking about is asset inventory. But if you've got that across all of your software portfolio, that lets you do some pretty cool stuff, especially at the organization level. You know, when there's a big vulnerability that comes out, and it's a case of, oh, are we affected by this somewhere? Having that accurate asset inventory across your entire fleet of servers, your cloud environment, being able to quickly go, oh yeah, we've got this component and it's sitting on this App Service in Azure, or maybe it's on this server on-prem. Especially because the things that software, you know, some people do continuous delivery, but most people don't really do it. And so you'll have, here's the state of the software in our source code repository, current build says everything's cool, but we haven't deployed that yet. We're actually running an older version of that component in production.

14:10Robert HurlbutYeah, I'm also seeing the value then of retrieving SBOMs in the CycloneDX format from the companies you're working, you know, the services that are being provided to you as well. Because when you think about, you know, when a big vulnerability hits the internet, you know, Security Journey, we provide our platform to our customers, right? And we'll get a bunch of emails from people going, hey, are you using this particular library? And, you know, there'll be a list of them and we have a canned response because normally we're not using whatever library, you know, was in question there. But I guess if you have an SBOM in the CycloneDX format, if I export that and provide that to you as a component of delivering my service, you can ingest that into your management system. You don't even have to ask me. You can just— you're just doing a query of, you know, wherever you're ingesting all the information to be able to say, oh, I know that Security Journey, for example, doesn't use that component because I've— we've searched the— it's, you know, the SBOMs have been searched or the assets that are coming out of it.

15:16Patrick DwyerYeah, there's a number of good use cases in that respect in terms of sharing it between supplier and consumer, especially, you know, open-source software. Often companies might do an internal fork, and so that component might appear to be an old outdated component, but they could be backporting security fixes for it, things like that. So being able to say to your consumer, hey, we use this component, but we applied this security patch to remediate this vulnerability. Or it could be a case of, yes, we do use this vulnerable component, but we don't call the method that's vulnerable. So yep, the vulnerability exists, but don't freak out, it's not exploitable. So you can communicate all that sort of information.

16:06Robert HurlbutSo what are people using to collect all that? Like, where are they putting the output of all these SBOMs? Is there like a management system? Are they building custom tooling to represent all of, like, import all of the CycloneDX SBOMs from all of my apps? Do they build like a custom dashboard or how do I— is there like an open source project that lets me wrap all this stuff together?

16:31Patrick DwyerYeah. So the OWASP Dependency Track project is probably the leading SBOM platform out there, but then there's a bunch of different security vendors as well. that are integrating this capability in their product.

16:46Robert HurlbutOkay, cool. So Dependency Track, which we've had Steve on before to talk about, Steve Springett, to talk about the project and kind of where it came from. So it ingests the output of CycloneDX running for my JavaScript app, for example, and my Python app, and it ingests all that together and then lets me do queries and and determine, search for certain things then across my whole fleet.

17:13Patrick DwyerYeah, it also lets you export it. So if we're talking about that vulnerability sort of assessment workflow where, all right, we've got a vulnerable component, is it exploitable or not? So Dependency Track can then generate output to give to your consumers as to the outcome of that, like whether yes, we are exploitable or no, we're not.

17:35Robert HurlbutVery cool. Yeah, I'm always so thankful when I think about projects like Dependency Track and the CycloneDX work that's been done here, because you look in the industry, and you're like, you know, people are starting companies and selling products that are doing these same things that folks such as yourself are just, you know, sacrificing and putting your time and effort into making these things available. And so, it just— I'm always so impressed with folks like yourself and Steve that are You know, operating behind the scenes, you're doing all this stuff and you're making these things available just to make the world a more secure place. And so I wish I could— I wish I could say thank you on behalf of the whole community. I'm going to do it anyway. You know, thank you on behalf of the whole community for doing stuff like that, because I know I haven't experienced it, but I know I just have an idea how much time actually goes on behind the scenes into making this happen. And it's not an hour per week.

18:31Chris Romeofolks.

18:32Robert HurlbutThese guys are spending a lot more time to make these things possible and make the world a more secure place. So that's a really, really awesome thing that y'all are doing.

18:39Patrick DwyerThanks.

18:40Robert HurlbutSo how'd you get involved with this then, with the CycloneDX project?

18:47Patrick DwyerYeah, so it was that job where I became dev lead at an organization, and I was sort of freaking out a bit because I had a look, and we had a lot of different custom-developed apps and services and integrations, and no visibility across all of those things of the state of them. So I went looking for solutions to this problem, came across Dependency Track, thought, oh, this looks exactly like what I need. And then, of course, you feed it with CycloneDX. So then started using CycloneDX myself. And there was a, you know, a couple of features missing that I wanted. So I contributed them, kept contributing. Because I'd recently gone from a development-heavy role to a role where I wasn't on the tools anymore, it was sort of a bit of a fun thing to do in the evenings to stay sharp. coding. And yeah, went from there.

19:52Robert HurlbutVery cool. Very cool. So I mentioned kind of at the— towards the top of our conversation that, you know, I, I got to— I got to CycloneDX because I was trying to generate some SBOMs. And I, I got into it and I was like, wow, there's support for a lot of different frameworks and libraries and things here. And so tell us, tell us about the depth and breadth of this CycloneDX tool, like the tooling that goes behind it, like what languages are we supporting? What, you know, how wide is this thing?

20:25Patrick DwyerI can't even remember how many ecosystems we support now. There's heaps like Go, .NET, Python, Java, Node, There's just, yeah, pretty much any modern popular environment ecosystem is supported. There's containers. Yeah, like actually starting to see this stuff be integrated into the native tooling. So Docker's now shipping a command that'll build an SBOM for the Docker images. Go's got really good inbuilt sort of metadata capture that enables a really accurate SBOM. So yeah, it's pretty interesting. Hmm.

21:20Robert HurlbutYeah, that's when I picked it up. I used the, I think it was the Node, Go, and Java and Ruby versions just to, and I was, I was like really impressed because I'm like, there's support for all these different things. Like all these modern frameworks and stuff have support in this, in this tool. So. Any idea how many people actually use CycloneDX today?

21:41Patrick DwyerWe've estimated it at over 100,000 organizations. Yeah, that's just based on downloads of the different implementations, the different Docker images, things like Dependency Track, because that takes CycloneDX. If you're using Dependency Track, you'll be using CycloneDX. But yeah, it is a bit hard to estimate because we're an open-source project, you know, we don't have a customer list or anything like that. So yeah, that's a reasonably conservative estimate.

22:18Robert HurlbutWow. So it's having a big impact across the industry then. I mean, that's a lot of organizations that are using this. And, you know, we know at the end of the day, adoption of SBOM is the answer that we've been working towards. And it's, you know, from a vulnerability management perspective, from a, you know, dependency and tracking and management and vulnerabilities from that side, like it is, it is ultimately the answer. And so it needs— people need to be incorporating it into whatever that they're doing.

22:49Patrick DwyerYeah, it's been quite interesting actually, because yeah, there's been a lot of work in the US federal government Making this happen, executive order a little while ago. But there's a lot of interest around the world. You know, I'm from Australia. The Australian Cybersecurity Center recently added it to their ISMS. Yeah, like it's, yeah, something which I thought was a bit of a niche thing is really widespread now.

23:20Robert HurlbutYeah, that's, that's great to hear. What do you see as the, what's next for CycloneDX? Like, do y'all have a roadmap that you're working from and you're trying to, you know, you've got future releases and stuff, or, you know, what is the future of CycloneDX?

23:37Patrick DwyerYeah, so probably the 2 main features that we'll be working on for the next release will be support for AI and machine learning and low-code platforms. Yeah, we've got an industry working group, so we meet with them, talk about, you know, the challenges different folks are having in different spaces, and yeah, use that to help prioritize what we do next.

24:03Robert HurlbutSo, you're somebody who's paying a lot of attention to the software supply chain. How long is it going to take us to get to the point where we get this under control?

24:17Patrick DwyerUm, that's a really hard, hard question because if you have a look at any of this stuff, it's a lot of it's inherently broken and it's easy to shoot yourself in the foot. So I think it could take quite a while.

24:34Robert HurlbutSo you think a decade? Is it— are we that far away from solving this problem? I hate to declare that and then it'll end up coming true and people say he's the person that set us off on the wrong path here, but—

24:46Patrick DwyerI don't think it'll be that long. But yeah, it's not going to happen overnight.

24:54Robert HurlbutOkay. So some less than 10 years though, we should have this thing under control. And I don't know, they've been saying we're going to solve SQL injection for 20+ years at this point, and somehow it's still out there.

25:06Patrick DwyerYeah, I think it'll be better. I don't think it'll necessarily be gone.

25:11Robert HurlbutYeah, I guess as the tooling continues to improve and the solutions for managing these things will— people that are serious about it will adopt it. And at least you'll have more differentiation between those who are taking it seriously and those who are not doing anything to manage their dependencies and stuff that they have. So if somebody's listening here and let's say they're a developer, They're a Python developer, that's what they spend their day working on, and they're wondering how to get started. What would you recommend for somebody who's hearing this, they're like, this CycloneDX thing sounds awesome, I want to use it, I want to learn about it. What advice would you give them here as somebody who's really close to the project?

25:57Patrick DwyerPretty simple, just pick a project that you're working on and download the tool for that ecosystem and generate an SBOM. spin up a local instance of Dependency Track. It runs in Docker, so it's really easy to just quickly run and try out. And yeah, load your BOM in there and actually have a look at what's in there. You might be surprised. Maybe less surprised if it's an ecosystem like npm where you're expecting to have a bazillion dependencies come in, even though you've only got a couple of direct dependencies. But...

26:29Robert HurlbutThe npm, like, you're like, but wait, I only added 3 packages. How can I have 25,000 dependencies? How's that possible? And we're only quite— we're only partially joking.

26:40Patrick DwyerYeah.

26:41Robert HurlbutThat level of dependencies that get unlocked depending on what packages you add. And it starts to— hey, the cyclone, I get that now. You know, it's the circular kind of— it continues on almost forever and ever too. So what would you, I guess, Give us a single call to action here. Give us a single key takeaway, something that you want to leave with our audience here.

27:04Patrick DwyerStart looking at the dependencies you're using. Like, even if you don't use CycloneDX, like, start looking at what you're actually shipping in your software because, you know, it might be a third-party component, but it's become part of your software that you're responsible for. You know, you have to pay attention to all of it. You can't ignore what is often the majority of your code.

27:28Robert HurlbutYeah, that's great advice and is a great place to end this conversation is people need to get out and start looking at those dependencies. And so Patrick, once again, thank you to you for all that you do behind the scenes here to make CycloneDX. I mean, once again, I took it, I used it. All the efforts that y'all put into this, I had a chance to use it firsthand in the last couple of weeks and I was really impressed with how it works and how clean it was to interact with. So thanks for sharing the knowledge about it. about this thing, and I'm hoping a lot of our listeners will go check out CycloneDX and put it into use. You'll find it at the place where you get all your good OWASP stuff.

28:06Patrick DwyerThanks, Chris.

28:09Chris RomeoThanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast and on the web at www.securityjourney.com/resources/podcast. You can also find Chris on Twitter @edgeroute, and Robert @roberthurlbut. Remember, with application security, there are many paths, but only one destination.

4,512 words · transcript by assemblyai

More on OWASP Projects

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.