Microsoft and Google together invested $5 million in a new project to improve software supply chain security for 10,000 open source projects.

The Alpha-Omega Project, which is the Open Source Security Foundation’s (OpenSSF’s) newest initiative, aims to improve supply chain security by looking for new, undiscovered vulnerabilities in open source code and then working with project maintainers to fix them.

It comes on the heels of a massive attack that exploited a vulnerability in Log4j and a subsequent White House summit to discuss open source software security attended by several software companies including Microsoft and Google, both of which are OpenSSF members.

How to best identify and secure critical open source code that is widely used across government and private organizations came up at the White House meeting, according to OpenSSF Executive Director Brian Behlendorf. “And we have a working group on identifying critical projects,” he added.

This OpenSSF working group uses a combination of expert opinions and data, including the OpenSSF Criticality Score and Harvard’s “Census” analysis, to identify critical open source software.

Software Supply Chain Security: ‘High Impact, High ROI’

In addition to updating federal cybersecurity officials about what groups like OpenSSF are already doing in this space, the meeting participants also did “a bit of creative brainstorming” about how public and private investment, both funding and human capital, could have a measurable impact on improving open source security, Behlendorf said.

“If you take an average-sized project, and Log4j is larger than average, but if you take an average-sized software project and you spitball: what’s the cost of a third-party audit and some basic remediation of the most important factors? You probably come up with a number about $100,000,” he said. “That’s very large when you’re talking about talking about developers working on things in their spare time or as an adjunct to their day jobs. But given the criticality of things like Log4j, it’s pretty high impact and high return on investment.”

Performing this type of review once a year on major open source projects would “have a tremendously positive impact on the security of open source code,” Behlendorf said.

And this is where the new Alpha-Omega Project comes into play.

Alpha-Omega Project

It works like this: First, Alpha will work with the maintainers of the most critical open source projects to help them identify and fix security vulnerabilities and improve their security posture.

For these selected projects, Alpha team members will provide tailored help such as threat modeling, automated security testing, source code audits, and vulnerability remediation support. It can also include help implementing best practices from criteria outlined by the OpenSSF Scorecard and Best Practices Badge projects.

And then Omega will focus on the long tail of open source software projects. It will use automation and other tools to identify critical security vulnerabilities across at least 10,000 widely deployed open source projects. This will involve a combination of technology (cloud-scale analysis), people (security analysts triaging findings), and process (confidentially reporting critical vulnerabilities to the right project stakeholders).

Omega will also have a dedicated team of software engineers tuning the analysis pipeline to reduce false positive rates and identify new vulnerabilities.

$5M Jumpstart, But ‘Considerable Funding’ Needed

While Microsoft and Google’s $5 million investment will jump start the Alpha-Omega Project, it’s going to take additional funding and engineers to fulfill the initiative’s goals.

“The long tail of important open source software, the ‘Omega’ of this endeavor, is always the hardest part — it will require not only considerable funding and perseverance, but its scale will also drive extensive automation for tracking and ideally fixing vulnerabilities,” said Eric Brewer, VP of Infrastructure and Fellow at Google in a statement. “Enabling automation will be one of the greatest improvements for open source security.”

It’s also worth noting that both cloud providers previously pledged to spend billions of dollars on cybersecurity in upcoming years.

After an earlier White House meeting last August that also focused on cybersecurity, Microsoft CEO Satya Nadella tweeted that his company will spend $20 billion over the next five years to advance its own security products and services. He also pledged $150 million to improve U.S. government agencies’ security posture and expand cybersecurity training partnerships.

Additionally, Google announced a five-year, $10 billion cybersecurity investment. This will include “expanding zero-trust programs, helping secure the software supply chain, and enhancing open-source security,” Google SVP of Global Affairs Kent Walker wrote in a blog post.