Xantra Tech

Smartvid Strategy for Runtime Application Protection

Project Information Completion Date: 21 March 2024 Client: Josh.K Location: Boston, Massachusetts, USA Category: IT Construction Software   About Smartvid Smartvid.io uses machine learning to improve safety, productivity, and quality in the AEC industry. Its SmartTag Engine analyzes video and photo content, tags it, and syncs it with BIM 360™—saving time and reducing risk. The […]

Project Information

Completion Date: 21 March 2024
Client: Josh.K
Location: Boston, Massachusetts, USA
Category: IT Construction Software

 

About Smartvid

Smartvid.io uses machine learning to improve safety, productivity, and quality in the AEC industry. Its SmartTag Engine analyzes video and photo content, tags it, and syncs it with BIM 360™—saving time and reducing risk.

The Challenge

Understanding Active Vulnerabilities smartvid, a full-stack construction software has engaged Xantra’s security solutions to bolster its runtime security defenses. Since 2022, smartvid’s security team faced a burdensome challenge as it worked through large numbers of security alerts in its expansive cloud environment. Amidst the noise, smartvid spent more effort than it wanted to separating exploitable vulnerabilities from theoretical ones. Once the exploitable vulnerabilities were panned, the security team still had to identify which had fixes. All of this had to be done to allow smartvid to prioritize which vulnerabilities to fix. The effort involved in this process was significant. Despite the importance, smartvid had trouble identifying an effective runtime solution to streamline this process. The security team did not want to add multiple additional tools to its security stack, but rather include an encompassing cloud solution that could identify multiple runtime gaps at once.


From Managing Vulnerabilities to Managing Risks

Upon integrating with xantra, smartvid further improved its ability to manage vulnerabilities by focusing on exploitable runtime risks. Jaffe emphasizes “xantra provides awareness of package vulnerabilities that are exploitable in a much more useful way than a lot of other products do. It narrows down exploits to what can actually be exploitable.” Identifying and prioritizing exploitable—and fixable—vulnerabilities helps smartvid avoid bombardment by irrelevant alerts. This precision enhances security effectiveness, and strengthens collaboration with the development team, by presenting actionable insights rather than overwhelming team members with non-critical issues.

100% Visibility into smartvid’s Cloud Applications

In addition to leveraging runtime insights to manage vulnerabilities, xantra addressed gaps in Kubernetes security, offering important capabilities in detection and response generally not available in standard Kubernetes deployments. Jonathan Jaffe notes “xantra fills typical Kubernetes security gaps. Few, if any products out there, provide reliable Kubernetes detection and response.” xantra extends its functionality beyond detection and response to include other areas such as non-human identities management and providing a comprehensive graphical views of smartvid s environment topology. This visibility is helpful to smartvids DevOps team, offering insights into resource relationships and aiding in task prioritization. “It’s the first time we’ve been able to point to graphs that show where resources are in relation to other resources. That helps us understand the context of a problem and how to prioritize what to work on.” Detection & response for kubernetes Non human identities management Topology view of entire environment

Real time Detection and Response of Sophisticated Attacks With xantra

smartvid is able to maintain robust protection against advanced threats that could circumvent other defensive layers. “Having something at runtime is yet another layer of defense above other standard defenses such as network defenses and protocol defense.” An example of an advanced threat is code injection. This occurs when malicious code is inserted into a dependency or a component of the application. Despite best efforts in securing coding and vulnerability management, dependencies can be compromised or inadvertently introduce vulnerabilities. xantra Security monitors the execution of code at runtime and can detect whether theres an attempt to inject malicious code into the application s codebase.