Seeker 3.8 can detect known vulnerabilities in web applications' open source and third-party software components through a turnkey integration.
Synopsys has released the 3.8 version of its Seeker product, the company's runtime security analysis solution and one of the latest additions to its Software Integrity Platform.
Seeker analyses web application code and data flows at runtime using a technique known as an Interactive Application Security Testing (IAST), which detects and confirms exploitable security vulnerabilities and provides actionable guidance that enables developers to address their root causes with ease. The Seeker 3.8 release includes improvements to its security analysis, usability and technology support.
Most notably, Seeker 3.8 now has the ability to detect known vulnerabilities in web applications' open source and third-party software components through a turnkey integration with Synopsys' Protecode Supply Chain (SC) technology. Seeker 3.8 automatically scans target web application binaries and produces a list of the detected open source and third-party dependencies (also known as a software bill of materials), a list of known vulnerabilities affecting its components, and pertinent software license attributes. This feature provides coverage for "A9 – Using Components with Known Vulnerabilities," one of the OWASP Top 10 most critical web application security flaws.
"Modern web applications depend on an increasingly vast and complex supply chain of open source and third-party software components," said Andreas Kuehlmann, senior vice president and general manager of Synopsys' Software Integrity Group. "There are thousands of known vulnerabilities that affect commonly used components, and they represent low-hanging fruit for attackers. Software composition analysis is an invaluable complement to Seeker's runtime security analysis as it provides a more comprehensive view of an applications' risk posture."
Seeker 3.8 includes several updates to improve its ease of use and ease of deployment, making it more flexible and easier to adopt across a variety of enterprise development and testing environments. This release also adds support for MongoDB and PHP 7, extending its utility to a wider range of web applications and services.
Seeker and the other tools in Synopsys' Software Integrity Platform are used to facilitate "software signoff," an integrated development and testing methodology that aims to ensure software quality and security. Pioneered by Synopsys to emulate the signoff concept used in integrated circuit (IC) design, software signoff involves a series of automated testing cycles at critical points throughout the software development lifecycle and software supply chain.