This page was machine-translated and may differ from the original. View original
Korea Microsystems, Open Source License and Security Vulnerability Analysis Solution 'Black Duck Hub' Domestically Available
Domestic supply of 'Black Duck Hub', an open source license and security vulnerability management solution
Integration of DevOps environment and open source management, continuous monitoring of new security vulnerabilitiesKorea Microsystems (CEO Dal-Yong Jeong, www.microsystem.kr) announced today that it will supply 'Black Duck Hub', an open source license and security vulnerability management solution from global solution company Synopsys (www.synopsys.com, (Nasdaq: SNPS)), in Korea.
As the official domestic channel for Synopsys, Korea Microsystems began supplying Black Duck's open source license and security vulnerability management solution, 'Black Duck Hub', to Korea after Synopsys acquired 'Black Duck Software' last year.
The number of companies adopting open source in software development is increasing day by day. Open source has the advantage of reducing development time and development costs. However, if you do not understand and manage the open source licenses you use, you may face legal risks of being involved in lawsuits and damages. In addition, if you fail to identify and respond to security vulnerabilities in open source in advance, there is a security risk that the developed software will be exposed to hacking.
According to a survey by Synopsys, which acquired Black Duck Software, an open source license management and security vulnerability analysis solution company, open source security vulnerabilities have been steadily increasing over the past five years along with the increase in open source usage. 96% of the software surveyed used open source, and 85% of them violated open source license policies, posing legal risks.
Additionally, there were over 4,800 newly discovered open source security vulnerabilities in 2017, and the number of open source security vulnerabilities per software increased by up to 134% compared to 2016. The discovery rate of security vulnerabilities in applications using open source was approximately 78%, and it was confirmed that there were an average of 64 security vulnerabilities per source code.
In particular, the period since the discovery of security vulnerabilities reported this year has increased by two years compared to last year to six years, indicating that more and more security vulnerabilities are accumulating in source codes and becoming targets of hacker attacks.
Synopsys' open source license management and open source security vulnerability analysis solution, 'Black Duck Hub', is the industry's No. 1 open source software (OSS) analysis solution with a database of over 2 million open source projects, and has performed analyses of over 80,000 security vulnerabilities and 2,400 open source licenses.
Black Duck Hub supports open source license identification from customer-developed source code, automatic mapping of identified open source to known security vulnerabilities, license compliance and component quality risk analysis, policy violation notification and action process tracking, open source software management policy setting and execution, integration of DevOps environment and open source software management, and continuous monitoring of identified new security vulnerabilities.
BlackDuck Hub enables development, legal, and security teams to collaborate to identify and mitigate open source license legal risks and open source security threats across the application portfolio, significantly improving work efficiency and the security of the entire IT infrastructure.
Kim Sang-mo, director of Korea Microsystems, said, “Since open source is used everywhere, there are also various routes through which self-developed source code can be accessed. “In order to protect application security from potential security vulnerabilities, it is necessary to specifically check the status of open source usage, update progress, and policy compliance,” he said. “Black Duck Hub is an industry-leading solution that can quickly respond to security vulnerabilities in open source software in real time and provide integrated management of licenses and policies.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.














