Security Scan Checks Binary Open Source

Release time:2017-08-09
author:Ameya360
source:Rick Merritt
reading:1170

  A Korean startup launched an online service that uses a novel approach to scan open source code for known security flaws. Insignary, Inc. let’s users scan files of up to 5 Mbytes for free on its Web site but charges for larger files and more detailed reports.

  The code looks for function and variable names and other constants that don’t vary among different compilations of a program. After identifying programs it checks open source repositories for known security flaws.

  The company maintains a database compiled from hundreds of thousands of open source repositories its searches. It uses a free U.S. Homeland Security database and a licensed repository to check for published security flaws.

  A variety of tools help OEMs manage open source licenses and check security, but only work on source code, not binary files. Others have tools that identify binary programs using checksums but they can fail to detect programs created using different compilers. Synopsys supplies a tool that uses hashing algorithms, supporting more accurate binary scans.

  “Our customers say we do better on the benchmarks,” said Taejin Kang, CEO of Insignary.

  The startup was founded in 2016 and released in April its software to its first two paying customers, large hardware OEMs in Korea and Japan. It has two dozen other OEMs in China, Korea and Japan evaluating the software.

  “We are trying to get people to know about this capability and how well it performs,” Kang said explaining the free online service.

  The company charges a base price of $100,000 per server per year for customers to run its Insignary Clarity program on their systems. Alternatively it lets users access a complete Web service the startup hosts for $3,000 per scan.

  The company is venture backed and seeking a Series A round to help fund operations in the U.S. including in Silicon Valley. Kang joined the company six months ago after a varied career leading startups in Korea and spending the last nine years working for Samsung and a Korean carrier.

("Note: The information presented in this article is gathered from the internet and is provided as a reference for educational purposes. It does not signify the endorsement or standpoint of our website. If you find any content that violates copyright or intellectual property rights, please inform us for prompt removal.")

Online messageinquiry

reading
  • Week of hot material
  • Material in short supply seckilling
model brand Quote
BD71847AMWV-E2 ROHM Semiconductor
MC33074DR2G onsemi
TL431ACLPR Texas Instruments
CDZVT2R20B ROHM Semiconductor
RB751G-40T2R ROHM Semiconductor
model brand To snap up
BP3621 ROHM Semiconductor
TPS63050YFFR Texas Instruments
IPZ40N04S5L4R8ATMA1 Infineon Technologies
STM32F429IGT6 STMicroelectronics
BU33JA2MNVX-CTL ROHM Semiconductor
ESR03EZPJ151 ROHM Semiconductor
Hot labels
ROHM
IC
Averlogic
Intel
Samsung
IoT
AI
Sensor
Chip
About us

Qr code of ameya360 official account

Identify TWO-DIMENSIONAL code, you can pay attention to

AMEYA360 weixin Service Account AMEYA360 weixin Service Account
AMEYA360 mall (www.ameya360.com) was launched in 2011. Now there are more than 3,500 high-quality suppliers, including 6 million product model data, and more than 1 million component stocks for purchase. Products cover MCU+ memory + power chip +IGBT+MOS tube + op amp + RF Bluetooth + sensor + resistor capacitance inductor + connector and other fields. main business of platform covers spot sales of electronic components, BOM distribution and product supporting materials, providing one-stop purchasing and sales services for our customers.

Please enter the verification code in the image below:

verification code