The organization relies on the successful migration, build, and operation of IT assets from existing enterprise workloads to new cloud-native applications and data platforms. A key part of this process is to minimize the risks associated with file-based threats by conducting stringent security scanning when deploying internally developed software into a client’s highly sensitive environments.
Furthermore, the Executive Order on Improving the Nation’s Cybersecurity of May 2021, requires vendors “to implement more rigorous and predictable mechanisms for ensuring that products function securely”. This directive requires organizations to adhere to a set of strict guidelines and placed a newfound emphasis on full disclosure of the solution’s Software Bill of Materials (SBOM). While this helps the US Government to reduce and control the potential for security exploits and malicious software, it caused difficulties when shipping code into their environments.
A combination of the Executive Order and the Cloud Provider’s own commitment to providing market-leading and safe software presented them with a challenge: to process entire containers at scale that include a variety of file formats.
This required the analysis of large volumes of traffic, but with bad actors creating ever more sophisticated exploits, relying on anti-virus solutions alone could not address zero-day risks or thwart sophisticated exploits that are not necessarily signature-based.