信息安全研究 ›› 2021, Vol. 7 ›› Issue (E1): 78-.

• 优秀论文 • 上一篇    下一篇

悬镜源鉴OSS开源威胁管控平台

刘一赫;子芽;董毅   

  1. (北京安普诺信息技术有限公司北京100089)
  • 出版日期:2022-04-20 发布日期:2022-04-20
  • 通讯作者: 刘一赫 工程师.主要研究方向为DevSecOps落地实践与技术. liuyh@anprotech.com
  • 作者简介:刘一赫 工程师.主要研究方向为DevSecOps落地实践与技术. liuyh@anprotech.com 子芽 硕士,高级工程师.主要研究方向为智能攻防技术. ziya@anprotech.com 董毅 硕士,高级工程师.主要研究方向为DevSecOps落地实践方案. dongyi@anprotech.com

Xcheck Open Source Security Platform

  • Online:2022-04-20 Published:2022-04-20

摘要: 悬镜源鉴OSS开源威胁管控平台是基于多源SCA的开源应用安全缺陷检测技术,结合悬镜独有应用探针,精准识别应用开发过程中软件开发人员有意或违规引用的开源第三方组件,并通过应用组成分析引擎,多维度提取开源组件特征,计算组件指纹信息,深度挖掘组件中潜藏的各类安全漏洞及开源协议风险.相较传统SCA检测平台,源鉴OSS更加侧重应用系统实际运行过程中动态加载的第三方组件及依赖关系,在此基础上进行深度和更加有效的威胁分析.同时,源鉴OSS通过智能化数据收集引擎在全球范围内及时获取开源组件及其相关漏洞信息,降低由开源组件带来的安全风险,保障软件安全.


关键词: SCA, OSS, 开源威胁治理, 开源组件扫描, 许可证合规分析

Abstract: Xcheck open source security platform is an open source application security defect detection technology based on multisource SCA. Combined with the unique application probe of Xmirror Security, it accurately identifies the open source thirdparty components intentionally or illegally referenced by software developers in the process of application development, extracts the characteristics of open source components and calculates the component fingerprint information through the application composition analysis engine, and deeply tap various security vulnerabilities and open source protocol risks hidden in components. Compared with the traditional SCA detection platform, Xcheck OSS focuses more on the thirdparty components and dependencies dynamically loaded during the actual operation of the application system, and carries out indepth and more effective threat analysis on this basis. At the same time, Xcheck OSS timely obtains open source component information and related vulnerability information worldwide through the intelligent data collection engine, reduces the security risks brought by open source components and ensures software security.


Key words: SCA, OSS, open source threat governance, open source component scanning, license compliance analysis