当前位置:网站首页>Software component analysis: 5 major capabilities to protect software supply chain security
Software component analysis: 5 major capabilities to protect software supply chain security
2022-08-02 12:19:00 【InfoQ】
This article is shared from HUAWEI CLOUD Community "
HUAWEI CLOUD Releases Open Source Software Governance Services - Software Component Analysis
", author: HuaweiCloud PaaS service Xiaozhi.
Software component analysis, which refers to the static analysis of software source code, binary software packages, etc., to discover security compliance risks such as open source compliance and known vulnerabilities.A common security testing method; recently, HUAWEI CLOUD, with its leading edge in software component analysis products and technologies, passed the evaluation of the Institute of Information and Communications Technology and won the evaluation certification of open source governance tools.

Forge open source governance tools and protectYour software supply chain security
- No need to rely on source code
Users only need to upload binary packages/Firmware, the service will use static detection technology to quickly analyze the security risk issues in binary software packages/firmware without building a running environment or running a program, and output a professional analysis report.
- Independent of the architecture platform of the object under test
Supports desktop (Windows and Linux) applications, mobile applications (APK, IPA, Hap, etc.), embedded system firmware (u-boot, Android sparse, etc.), etc.
- Mainstream programming languages are fully supported
Support C/C++, Java, Go, Python,JavaScript, Rust, etc., the coverage of languages continues to increaseVulnerability library capability to actively manage newly discovered vulnerability alerts in the BOM of the historical scanning software.

- Strong risk detection capabilities, and rules continue to increase
Provide comprehensive and rapid investigation capabilities for risks in user release packages/firmware packages, covering open source softwareThere are 3 major categories of 26 sub-categories of risk, information leakage risk, and configuration risk, and the detection rules continue to increase.

Passed the evaluation of CITIC and won theOpen source governance tool evaluation certification
Trusted open source governance tool (SCA), as the most important detection tool in trusted open source, provides enterprises and evaluation agencies to use open source software to determine whether software products are safe or not.Provides an automated detection capability and quantifiable, visual detection results.
At the "OSCAR Open Source Pioneer Day" meeting in May this year,
Huawei Cloud Computing Technology Co., Ltd.'s R&D security service (component analysis) (SaaS version) passed theCertification of the Trusted Open Source Governance Tool of the China Academy of Information and Communications Technology
, and has provided commercial services on Huawei's public cloud.

HUAWEI CLOUD DevCloudWe have been committed to providing customers with an R&D environment that improves end-to-end efficiency and provides full-link security. Huawei's R&D tool capabilities continue to spill over. Currently, HUAWEI CLOUD software component analysis provides binary component analysis capabilities. Source code analysis will be officially released in the future, so stay tuned.
Click to follow and learn about HUAWEI CLOUD's new technologies for the first time~
边栏推荐
猜你喜欢
随机推荐
Create your own app applet ecosystem with applet containers
力扣35-搜索插入位置——二分查找
MD5详解(校验文件完整性)
SQL函数 TRIM
darknet训练yolov4模型
1.3快速生成树协议RSTP
Metaverse "Drummer" Unity: Crazy expansion, suspense still exists
【第六届强网杯CTF-Wp】
numpy&pands 中的unique
基础协议讲解
MyCat2的介绍与安装以及基本使用
SQL Server 数据库之导入导出数据
excel 批量翻译-excel 批量函数公司翻译大全免费
How to connect TDengine through DBeaver?
Seneor Exposure Basics
手撸架构,Redis面试41问
np.nan, np.isnan, None, pd.isnull, pd.isna 整理与小结
WPF 实现窗体抖动效果
企业级数据治理工作怎么开展?Datahub这样做
Free Chinese-English Translation Software - Automatic Batch Chinese-English Translation Software Recommended Daquan