LabradorLabs Develops Malicious Open Source Package Verification Engine
IT DAILY ·
✦ AI Summary
LabradorLabs announced on the 9th that it developed an open source package risk analysis engine and applied it to an update of its integrated vulnerability analysis system, "IVAS."
With this update, it is now possible to identify and verify risk factors in advance before using open source, and a repository management framework has also been implemented.
The analysis targets open source packages before they are brought into an organization, and external open source can be pre-screened and checked before it is brought into the development environment.
LabradorLabs announced on the 9th that it developed an open source package risk analysis engine and applied it to an update of its integrated vulnerability analysis system, "IVAS." The analysis targets open source packages before they are brought into an organization. The company also released a photo of the open source intake management screen in its integrated vulnerability analysis system, "IVAS."
With this update, it is now possible to identify and verify risk factors in advance before using open source, and a repository management framework has also been implemented. The update expands beyond the system's existing SW vulnerability analysis capabilities.
Today, SW development is largely built by assembling multiple open source components. Developers use open source packages from public repositories, and examples of the functions they provide include login, data processing, screen composition, and date calculations.
This kind of open source environment has become a target for attackers. Attackers strike by using malicious packages in which malware has been inserted into legitimate open source software.
These malicious packages are difficult to distinguish from ordinary open source at first glance. They have plausible names and descriptions, and they may appear to function normally.
Problems begin as soon as the malicious package is installed, and when a specific command is executed, the hidden code runs automatically. This creates the possibility that cloud access keys stored on the computer and login information stored on the computer could be leaked externally.
Accordingly, companies need measures to verify the safety of SW components before open source is brought into the development environment. LabradorLabs' IVAS analysis engine is equipped with a function that identifies whether a package is malicious before open source is brought into a company's internal network and provides the basis for its determination. It also analyzes intake records for external open source, identifies whether the package is malicious, and provides detection grounds and source listings. Through this process, external open source packages can be pre-screened, and if any risk factors are found, they can be checked before they are brought into the development environment.
Through this process, companies can check for risks and respond before malicious packages enter developers' PCs. They can also check for risks and respond before malicious packages enter build servers.
Kim Jin-seok, CEO of LabradorLabs, explained that once a software developer installs a malicious package, simply running a basic command can lead to the external leakage of account information, cloud keys, and key information from the development environment. Based on that, he said that in open source security, a post-development vulnerability detection approach alone is not sufficient.
Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241512
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.