Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • Development
    • Innovation
    • IT Management

    IT Science Case Study: How Chef Cooked Up Better Security

    Written by

    Chris Preimesberger
    Published December 19, 2017
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      This is the latest article in a new occasional feature series in eWEEK called IT Science, in which we look at what really happens at the intersection of new-gen IT and legacy systems.

      Unless it’s brand new and right off various assembly lines, servers, storage and networking inside every IT system can be considered “legacy.” This is because the iteration of both hardware and software products is speeding up all the time. It’s not unusual for an app-maker, for example, to update and/or patch for security purposes an application a few times a month, or even a week. Some apps are updated daily! Hardware moves a little slower, but manufacturing cycles are also speeding up.

      These articles will describe industry solutions only and won’t focus on any single product. The idea is to look at real-world examples of how new-gen IT products and services are making a difference in production each day. Most of them will be success stories, but there will also be others about projects that blew up. We’ll have IT integrators, system consultants, analysts and other experts helping us with these as needed.

      Today’s IT Science Feature: Platform-as-a-Service Provider Chef

      This article is about DevOps tool provider Chef. Chef is an innovative, fast-moving company that is driven by speed to market using a DevOps approach to engineering. Chef makes an automation platform that transforms infrastructure into code.

      Name the problem to be solved: The engineering group required a security solution that could scale with their business. Due to a high volume of requests, previous web application firewall (WAF) evaluations had shown the risk of false positives to be very high.

      As a transformation solution, Chef helps customers embed more effective security throughout their entire development cycle.

      Describe the strategy that went into finding the solution: Chef’s development and operations teams required more visibility into the changing vulnerabilities and attack vectors across their applications. They knew that in order to help other organizations achieve business transformation, they needed to embed scalable security into their own application delivery pipeline.

      Chef searched for a security solution to provide a full spectrum of security visibility and ease of use for their developers without negatively impacting performance. Chef required security at the speed of DevOps.

      Chef’s development and operations teams chose Signal Sciences because “everything just works brilliantly.” Signal Sciences allows a company with limited security bandwidth to seamlessly embed security across teams throughout its entire DevOps process.

      List the key components in the solution: In order to resolve its challenges, Chef required a technology that had:

      • minimal impact on performance. Because Chef is an organization that requires high performance to keep up with their customers’ innovation and speed, it was critical that any added security solution provide security without negatively impacting the development lifecycle;
      • no additional overhead, maintenance, and training. One of Chef’s biggest priorities is avoiding additional burden to the engineering and security teams. It was important that they find a security solution that was easy to use without adding additional security resources; and
      • eliminated false positives for legitimate traffic. Chef’s team evaluated other WAF solutions and found that they often flagged and blocked a large number of legitimate requests. Chef needed a solution that would help its customers securely access the Chef platform, without hindering their customer experience and productivity.

      Describe how the deployment went, perhaps how long it took, and if it came off as planned: With Signal Sciences installed, the Chef team has full confidence that any attacks will be automatically detected and blocked and relevant alerts will besurfaced through their existing DevOps tool chain.

      Signal Sciences Web Protection Platform is a security solution that DevOps teams actually want to use, said Ben Rockwood, Chef Director of Engineering.

      “Signal Sciences doesn’t hold us up. If anything, it actually enables us to continue forward on our larger business initiatives—without using my engineering pipeline to leverage security,” Rockwood said. “With Signal Sciences Web Protection Platform in place, I never have to worry about unnecessarily taxing my engineering Pipeline.”

      Describe the result, new efficiencies gained, and what was learned from the project.

      • No performance impact to existing Chef systems or performance. When Chef first deployed Signal Sciences WPP into its application stack, the Ops team didn’t even realize that the product had been turned on. The Signal Sciences solution added almost zero additional latency. With Signal Sciences in place, Chef didn’t have to make the tradeoff between security and high performance for their customers—they could have both.
      • Access to complex security data that is easy to comprehend. Signal Sciences gives Chef powerful visibility and remediation capabilities that are consumable by the entire organization at a wide variety of skill levels giving everyone continuous situational awareness. Signal Sciences is able to surface only the most important alerts and anomalies in consumable dashboards and immediately alert teams through ChatOps tools like Slack. Without being a security expert, any Chef team member can easily access security data and quickly understand what’s going on within the application.
      • Security automation that enables DevOps priorities. The Chef development team embraces security rather than working around it. Signal Sciences WPP has successfully increased their automation, adding even more momentum to the development and operations pipeline. Signal Sciences WPP gives Chef’s DevOps team the option to share the responsibility of security, by seamlessly scaling their security posture with their development teams.

      Other references:

      • Chef case study
      • Signal Sciences platform information

      If you have a suggestion for an IT Science article, email [email protected].

      Chris Preimesberger
      Chris Preimesberger
      https://www.eweek.com/author/cpreimesberger/
      Chris J. Preimesberger is Editor Emeritus of eWEEK. In his 16 years and more than 5,000 articles at eWEEK, he distinguished himself in reporting and analysis of the business use of new-gen IT in a variety of sectors, including cloud computing, data center systems, storage, edge systems, security and others. In February 2017 and September 2018, Chris was named among the 250 most influential business journalists in the world (https://richtopia.com/inspirational-people/top-250-business-journalists/) by Richtopia, a UK research firm that used analytics to compile the ranking. He has won several national and regional awards for his work, including a 2011 Folio Award for a profile (https://www.eweek.com/cloud/marc-benioff-trend-seer-and-business-socialist/) of Salesforce founder/CEO Marc Benioff--the only time he has entered the competition. Previously, Chris was a founding editor of both IT Manager's Journal and DevX.com and was managing editor of Software Development magazine. He has been a stringer for the Associated Press since 1983 and resides in Silicon Valley.
      Linkedin Twitter

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.