Aqua Security strengthens software supply chain security with pipeline integrity scanning
Summary
Powered by eBPF technology, Aqua’s pipeline integrity scanner detects and blocks suspicious behaviour and malware in real time, preventing code tampering and countering threats in the software build process. The capability also takes advantage of behavioural signatures produced by the Aqua Nautilus research team to detect zero-day threats based on cloud native attacks seen in the wild. To scale safe development practices and ensure software integrity, assurance policies can be implemented to block completion of new builds that show signs of suspicious activity. These are important but have proven insufficient to detect and stop supply chain attacks of this type.” Aqua’s pipeline integrity scanner leverages Tracee, the company’s robust open source runtime security and forensics sensor for Linux. By detecting and stopping drift of the original build through eBPF-based scanning and policies, teams can protect their software from unauthorised access and prevent advanced supply chain attacks.