HomeMalware & ThreatsHow JPMorgan Chase Achieved Scalable Secure Software Delivery

How JPMorgan Chase Achieved Scalable Secure Software Delivery

Published on

spot_img

Agentic AI,
Application Security,
Next-Generation Technologies & Secure Development

Centralized Controls Help the Bank Secure Thousands of Daily Software Builds

How JPMorgan Chase Achieved Scalable Secure Software Delivery
JPMorgan Chase centralized its container pipeline to support thousands of daily builds while detecting vulnerabilities before deployment. (Image: Shutterstock)

In a rapidly evolving financial landscape, JPMorgan Chase faces the ongoing challenge of balancing software delivery speed with robust security measures. The bank processes thousands of software builds each day, necessitating efficient scalability, meticulous traceability, and stringent security controls, as highlighted by Seetaram Rayarao, vice president and senior lead engineer at JPMorgan Chase. These factors are critical for the tools supporting the institution’s container pipeline.

To address these challenges effectively, JPMorgan Chase transitioned to JFrog Artifactory after previous artifact-management tools failed to meet its extensive scaling requirements. This advanced tool provides developers with a central repository designed for storing and managing software artifacts along with container images as they navigate through development and deployment workflows.

Rayarao emphasized the scale of operations at JPMorgan Chase, stating, “We run thousands of builds in a day.” The JFrog platform is capable of managing this enormous volume while ensuring the persistent storage of resulting container images in its repositories. This transition is part of an evolution that the bank has undergone over approximately 13 years, adapting its software architecture and delivery practices to meet the demands of an increasingly complex environment.

Tracking Components Behind Each Build

The JFrog platform plays a significant role in enhancing the organization’s capacity to document the components that contribute to its software. Rayarao likened this enhanced visibility to the bills of materials used by manufacturers for tracking components contained in physical products. He remarked, “In the software world, we need a similar kind of setup.” This involves maintaining a comprehensive software bill of materials that catalogs all libraries, dependencies, and other elements included in an application. This documentation is invaluable for security teams when evaluating whether newly identified vulnerabilities impact software that is still in development or has already been deployed in production.

Moreover, the platform significantly boosts build performance by implementing caching for dependencies and container layers, which speeds up the development process. Rayarao explained, “You don’t have to fetch the dependencies every time. It will be cached, and it will be so fast.” This efficiency not only addresses the operational demands of the bank but also enhances the development team’s workflow.

While scale and performance were pivotal factors in the migration to JFrog Artifactory, JPMorgan Chase also prioritized maintaining its security protocols. Rayarao noted that the chosen solution operates within the bank’s infrastructure, ensuring that sensitive information remains within the network, stating, “It does not have to go out of the network. Security is the main constraint now, so it is in our boundaries.” This security foundation facilitates a standardized progression from development to production.

In this context, developers are empowered to build and store container images, which are subsequently subjected to rigorous security checks before deployment. Scanners meticulously examine the containers for vulnerabilities or potential malicious code that could compromise the security of the bank’s production environment. Rayarao stated, “You can run the scan and find out the vulnerabilities before you even put something into production.”

Any identified security findings generate tickets that must be resolved prior to advancing with a release. He emphasized, “Until and unless you solve the tickets, you cannot put that code into production.” Then, a specialized security review team evaluates the vulnerability reports to decide on the product’s deployment readiness.

Automating the Path to Production

Amid the increasing complexity of software development, JPMorgan Chase has integrated various advanced processes into its delivery workflow, such as dependency caching, vulnerability scanning, and policy enforcement. This integration allows the institution to minimize manual efforts while maintaining comprehensive visibility in the deployment process.

Rayarao noted that shifting security checks to earlier stages of the development cycle not only enhances security but also streamlines operations. As the landscape shifts, security scans are conducted post-deployment with continuous vigilance since a scanner may miss issues that become apparent later due to evolving vulnerabilities. The bank has developed protocols to track any such issues, ensuring they are remediated within a defined timeline, with Rayarao asserting, “Everything will be tracked.”

The pipeline also acts as a springboard for newer automation methods. He reported that agent-based development practices have notably accelerated the time required to deploy features, citing an example where a feature that previously took three months to reach production can now be completed within a single week. This dramatic acceleration is attributed not only to the JFrog platform itself but also to the integration of artificial intelligence into development processes.

Governing the Next Generation of Development

However, these advances come with associated challenges, particularly concerning governance in the face of increasing use of coding agents. Rayarao indicated that repetitive tasks could be encapsulated as reusable skills within agentic frameworks, prompting an interest in whether the bill-of-materials principles used for managing conventional software components could be similarly beneficial for managing these skills.

This exploration presents both exciting opportunities and unsettling uncertainties. Rayarao acknowledged, “We don’t know how it is going to look in the future. That excites us, and also it is scary.” A notable concern is that while developers can identify what they asked an agent to produce, understanding the resulting code may pose challenges. “We are relying on the agents to generate,” he stated, adding that there are risks involved, especially if an agent incorrectly identifies the source of a problem.

Consequently, the implementation of access restrictions, comprehensive security policies, and diligent human oversight becomes indispensable. “If you don’t have the guardrails around it, then it can do anything,” Rayarao remarked. Additionally, the rise of agent-generated code accentuates the need for precise specifications. In the absence of thorough instructions, an agent may misinterpret the task, leading to divergent outcomes from organizational intent. To counteract this, Rayarao advocates for “specification-driven development,” emphasizing that teams should detail their specifications meticulously to satisfy product requirements before instructing agents.

“Security is one thing we cannot compromise,” Rayarao concluded, underscoring the central mission of safeguarding both the integrity of the software and the security of the bank’s operations as it navigates a complex technological landscape.

Source link

Latest articles

TRM Labs Achieves $2B Valuation Amid AI-Driven Investigations

TRM Platform Leverages AI to Enhance Blockchain Data Analysis Amidst Rising Cyber Threats In a...

SAP Patches Maximum Severity Overpass Flaw

Critical Vulnerability Threatens Over 10,000 SAP Systems A significant security alert has been raised by...

FBI Releases Initial Cyber Strategy

On September 9, the FBI made a notable advancement in its approach to combating...

OFAC Sanctions Chinese Scam Platform Xinbi Guarantee

US Government Sanctions Chinese-Language Marketplace Linked to Fraud and Criminal Activity In a significant move...

More like this

TRM Labs Achieves $2B Valuation Amid AI-Driven Investigations

TRM Platform Leverages AI to Enhance Blockchain Data Analysis Amidst Rising Cyber Threats In a...

SAP Patches Maximum Severity Overpass Flaw

Critical Vulnerability Threatens Over 10,000 SAP Systems A significant security alert has been raised by...

FBI Releases Initial Cyber Strategy

On September 9, the FBI made a notable advancement in its approach to combating...