This website collects cookies to deliver better user experience. Cookie Policy
Accept
Sign In
The Wall Street Publication
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Reading: Push to Explain What Software Contains Gains Steam After Log4j Flaw
Share
The Wall Street PublicationThe Wall Street Publication
Font ResizerAa
Search
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Have an existing account? Sign In
Follow US
© 2024 The Wall Street Publication. All Rights Reserved.
The Wall Street Publication > Blog > Tech > Push to Explain What Software Contains Gains Steam After Log4j Flaw
Tech

Push to Explain What Software Contains Gains Steam After Log4j Flaw

Editorial Board Published January 24, 2022
Share
Push to Explain What Software Contains Gains Steam After Log4j Flaw
SHARE

Companies must know what is inside their technology to secure it against hackers and prevent the type of upheaval seen at the end of 2021 due to a flaw in the free, widely used Log4j software, officials and analysts say.

Contents
Newsletter Sign-upWSJ Pro CybersecurityCISA chief Jen Easterly.More From WSJ Pro Cybersecurity

Disclosure of the vulnerability, which allows hackers to breach systems with relative ease, in early December prompted companies to rush to update their systems and prevent cyberattacks. Many security teams first had to find out if their software included Log4j, an open-source tool used to keep records of users’ activities so they can be reviewed later. Some companies are still combing their software for the flaw.


Newsletter Sign-up

WSJ Pro Cybersecurity

Cybersecurity news, analysis and insights from WSJ’s global team of reporters and editors.


“It’s often hard to spot because it’s not as simple as just running a vulnerability scanner, or checking a product version number,” said Jeff Macko, a senior director in consulting firm Kroll Holdings Inc.’s cyber risk business. Special tools for analyzing software are often required to find out whether Log4j or other vulnerable open-source parts are present.

Mr. Macko said he expects to be dealing with Log4j vulnerabilities for the next three to five years.

This lack of visibility into the guts of corporate software has given new urgency to an old idea—a complete inventory of what is inside software packages, including which open-source components programmers used during development. While such components are commonly used, open-source projects are sometimes maintained only by a handful of volunteers and often aren’t vetted by security teams, opening a company’s systems to attack.

Making such an inventory, known as a software bill of materials, or SBOM, has been promoted by the U.S. Cybersecurity and Infrastructure Security Agency as a way to shorten the time it takes to respond to new vulnerabilities. The Commerce Department is also an advocate, developing guidance on how to construct such an inventory in line with President Biden’s May 2021 executive order on cybersecurity.

CISA chief Jen Easterly.

Photo: Michael Brochstein/Zuma Press

CISA Director Jen Easterly said in a statement last month that the Log4j vulnerability “underscores the urgency of building software securely from the start and more widespread use of Software Bill of Materials.”

Building an SBOM that covers all technology at a company could be difficult. Large organizations such as major banks might run thousands of legacy applications, meaning that going through every piece to find open-source components is a daunting task.

“Frankly, legacy software without an SBOM is like a can of food from the 1920s without an ingredient label. Consume at your own risk,” said Sounil Yu, chief information security officer at Morrisville, N.C.-based cybersecurity company JupiterOne Inc.

Companies that can provide SBOMs demonstrate a mature software-development process, said Mr. Yu, who was previously chief security scientist at Bank of America Corp.

Software providers, in particular, are likely to come under significant pressure to produce SBOMs, he said, as client security teams are unlikely to endure long waits for vulnerability notifications from their suppliers while they figure out what is inside their products. In the Log4j case, tech providers rushed to develop patches to fix the flaw in their own products and to notify customers.

More From WSJ Pro Cybersecurity

Companies have two basic options for discovering whether the software they use contains open-source components, said Tim Mackey, principal security strategist at Synopsys Inc., a Mountain View, Calif.-based software-testing company. If the source code is available, it can be compared with open-source libraries for common components. Alternatively, the program itself can be run through a binary analysis process, where it is dissected to determine its parts, although the results might not be as clear as using the source code.

Still, Mr. Mackey said, bespoke software projects developed by teams outside a company’s technology division can complicate efforts to build comprehensive SBOMs, as they might not go through the usual checks and balances or even be known to technology staff.

Kroll’s Mr. Macko warned that component inventories won’t counteract inherently weak security. Implementing network security that watches for odd behavior from applications and following basic cybersecurity hygiene will help to mitigate the impact of attacks.

“It’s painful that we have to learn our lessons by getting a bloody nose first,” he said.

Write to James Rundle at james.rundle@wsj.com

Copyright ©2022 Dow Jones & Company, Inc. All Rights Reserved. 87990cbe856818d5eddac44c7b1cdeb8

TAGGED:Tech NewsWall Street Publication
Share This Article
Twitter Email Copy Link Print
Previous Article Noncitizens shy to vote even when it’s legal Noncitizens shy to vote even when it’s legal
Next Article CBS retools streaming service to better resemble TV network CBS retools streaming service to better resemble TV network

Editor's Pick

TLI Ranked Highest-Rated 3PL on Google Reviews

TLI Ranked Highest-Rated 3PL on Google Reviews

EXTON, PA — Translogistics, Inc. (TLI), a trailblazer in the 3PL and managed logistics space since its founding in 1994,…

By Editorial Board 12 Min Read
Justin Baldoni Shares Emotional Message Amid Blake Vigorous Lawsuit
Justin Baldoni Shares Emotional Message Amid Blake Vigorous Lawsuit

Studying Time: 3 minutes Justin Baldoni has damaged his silence. In a…

5 Min Read
McDonald’s to rent as much as 375,000 staff this summer time
McDonald’s to rent as much as 375,000 staff this summer time

Brian Vendig, MJP Wealth Advisors President, and Ryan Payne, 'Payne Factors of…

6 Min Read

Oponion

Albertans rally for separation, saying issues will not change underneath Liberals

Albertans rally for separation, saying issues will not change underneath Liberals

Katheryn Speck mentioned she was a Canadian nationalist, travelled the…

May 4, 2025

Letters: Toll hikes | Don’t flee | Reflecting poorly | Unsuitable elites | Youth’s voice

Toll hikes restrictresidents’ mobilityRe: “Toll hikes…

November 29, 2024

Tribunal da Coreia do Sul resolve permitir apresentação do Shen Yun depois que teatro cedeu à pressão do PCCh | Coréia do Sul | liberdade artística | censura

Matéria traduzida e adaptada do inglês,…

May 9, 2025

Retailer Trend Nova suppressed detrimental on-line opinions, $2.4M going to clients

FTC director of public affairs Douglas…

February 5, 2025

Missed alternatives hang-out San Jose Sharks, who stay winless

SAN JOSE – The San Jose…

October 21, 2024

You Might Also Like

The Finest LED Face Masks and Pink-Gentle Remedy for At-Dwelling Therapies
Tech

The Finest LED Face Masks and Pink-Gentle Remedy for At-Dwelling Therapies

Finest Cooling LED Face Masks{Photograph}: SHARKShark CryoGlow Pink Blue & Infrared iQLED Face Masks & Underneath Eye CoolingThe Shark CryoGlow…

4 Min Read
Which Google Pixel Telephone Ought to You Purchase?
Tech

Which Google Pixel Telephone Ought to You Purchase?

Google Pixel telephones are our favourite Android telephones right here at WIRED and have been for a number of years.…

6 Min Read
The Finest Cat Toys for Your Furry Buddy
Tech

The Finest Cat Toys for Your Furry Buddy

Cats are stunning, attention-grabbing, bizarre creatures. They're additionally very choosy. Discovering toys that they're going to truly play with is…

16 Min Read
KLN GROUP INC. Revolutionizes Auto Transport with Technology-Driven Logistics Solutions Driving Innovation and Efficiency in High-End and Classic Car Shipping
TechTrending

KLN GROUP INC. Revolutionizes Auto Transport with Technology-Driven Logistics Solutions Driving Innovation and Efficiency in High-End and Classic Car Shipping

Chicago, IL – 03.11.2025 – KLN GROUP INC., a leader in high-end and classic vehicle transportation, is transforming the car…

3 Min Read
The Wall Street Publication

About Us

The Wall Street Publication, a distinguished part of the Enspirers News Group, stands as a beacon of excellence in journalism. Committed to delivering unfiltered global news, we pride ourselves on our trusted coverage of Politics, Business, Technology, and more.

Company

  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • WP Creative Group
  • Accessibility Statement

Contact

  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability

Term of Use

  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices

© 2024 The Wall Street Publication. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?