• Home
  • Advertising
    • Why Advertise
    • Create Your Campaign
  • About
    • About Security on Screen
    • Privacy Policy
  • Webinars
  • Social Wall
  • Contact Us
Tuesday, August 16, 2022
No Result
View All Result
  • Login
  • Register

No products in the basket.

Submit News
Submit video
  • Create Your Campaign
  • Product Groups
    • Access Control
    • Biometrics
    • Physical Security
    • Smart City
    • Surveillance
    • Systems Integration
  • Cyber-Security
  • Industry sectors
    • Banking
    • Casinos
    • City Surveillance
    • Data Centres
    • Government
    • Healthcare
    • Leisure
    • Manufacturing
    • Retail
    • Schools and Campus Security
    • Transport
    • Utilities
  • Business News
    • New Technology
    • Opinion
    • People
    • Education & Events
  • Create Your Campaign
  • Product Groups
    • Access Control
    • Biometrics
    • Physical Security
    • Smart City
    • Surveillance
    • Systems Integration
  • Cyber-Security
  • Industry sectors
    • Banking
    • Casinos
    • City Surveillance
    • Data Centres
    • Government
    • Healthcare
    • Leisure
    • Manufacturing
    • Retail
    • Schools and Campus Security
    • Transport
    • Utilities
  • Business News
    • New Technology
    • Opinion
    • People
    • Education & Events
No Result
View All Result
No Result
View All Result

Synopsys highlights software supply chain challenges in new OSSRA report

by Zoe Deighton Smythe
26/04/2022
in Cyber Security, PRESS RELEASE
Synopsys highlights software supply chain challenges in new OSSRA report

Synopsys, Inc has released the 2022 Open Source Security and Risk Analysis (OSSRA) report. The report, produced by the Synopsys Cybersecurity Research Center (CyRC), examines the results of more than 2,400 audits of commercial and proprietary codebases from merger and acquisition transactions, performed by the Black Duck Audit Services team.

The report highlights trends in open source usage within commercial and proprietary applications and provides insights to help developers better understand the interconnected software ecosystem. It also details the pervasive risks posed by unmanaged open source, including security vulnerabilities, outdated or abandoned components, and license compliance issues.

The 2022 OSSRA report findings underscore the fact that open source is used everywhere, in every industry, and is the foundation of every application built today.

  • Outdated open source remains the norm—including presence of vulnerable Log4j versions. From an operational risk/maintenance perspective, 85% of the 2,097 codebases contained open source that was more than four years out-of-date. 88% utilised components that were not the latest available version. 5% contained a vulnerable version of Log4j.
  • Assessed codebases show open source vulnerabilities are decreasing overall. 2,097 of the assessed codebases included security and operational risk assessments. There was a more dramatic decrease in the number of codebases containing high-risk open source vulnerabilities. 49% of this year’s audited codebases contained at least one high-risk vulnerability, compared to 60% last year. Additionally, 81% of the assessed codebases contained at least one known open source vulnerability, a minimal decrease of 3% from the findings of the 2021 OSSRA.
  • License conflicts are also decreasing overall. Over half—53%—of the codebases contained license conflicts, a substantial decrease from the 65% seen in 2020. In general, specific licence conflicts decreased across the board between 2020 and 2021.
  • 20% of assessed codebases contained open source with no licence or with a customised licence. Since a software licence governs the right to use it, software with no licence presents the dilemma of whether use of the open source component entails legal risk. Additionally, customised open source licences might place undesirable requirements on the licencee and will often require legal evaluation for possible IP issues or other implications.

“Users of SCA software have focused their attention on reducing open source licence issues and addressing high-risk vulnerabilities, and that effort is reflected in the decreases we saw this year in licence conflicts and high-risk vulnerabilities, said Tim Mackey, principal security strategist with the Synopsys Cybersecurity Research Centre. “The fact remains that over half of the codebases we audited still contained licence conflicts and nearly half still contained high-risk vulnerabilities. Even more troubling was that 88% of the codebases [with risk assessments] contained outdated versions of open source components with an available update or patch that was not applied.”

“There are justifiable reasons for not keeping software completely up-to-date,” Mackey continued. “But, unless an organisation keeps an accurate and up-to-date inventory of the open source used in their code, an outdated component can be forgotten until it becomes vulnerable to a high-risk exploit, and then the scramble to identify where it’s being used and to update it is on. This is precisely what occurred with Log4j, and why software supply chains and Software Bill of Materials (SBOM) are such hot topics.”

To learn more about the potential risks associated with open source software and how to address them, download a copy of the 2022 OSSRA report, or read the blog post.

Tags: CybersecurityCyRCOSSRAreportRisk Analysissoftware supply chainSynopsys
ShareTweetShare

Related Posts

KnowBe4 launches resource kit to help defend against surging “Human Layer” attacks
Cyber Security

KnowBe4 launches resource kit to help defend against surging “Human Layer” attacks

New UK maritime security strategy to target latest physical and cyber threats
Cyber Security

New UK maritime security strategy to target latest physical and cyber threats

barox Ethernet PoE switches approved to power Redvision X4 COMMANDER PTZ camera
New Technology

barox Ethernet PoE switches approved to power Redvision X4 COMMANDER PTZ camera

Nominations open for Security Serious Unsung Heroes Awards 2022
Cyber Security

Nominations open for Security Serious Unsung Heroes Awards 2022

Feedzai and Lloyds Banking Group recognised as a Aite-Novarica Group 2022 Fraud Impact Award Winner 
Banking

Feedzai and Lloyds Banking Group recognised as a Aite-Novarica Group 2022 Fraud Impact Award Winner 

Altronix Trove expansion
Access Control

Altronix expands Trove Access and Power Integration Solutions

Load More

The Tannery, 3a John Street, Tunbridge Wells,
Kent TN4 9RU
All enquiries: +44 (0)1892 525141

  • Home
  • Advertising
  • About
  • Webinars
  • Social Wall
  • Contact Us
No Result
View All Result
  • Login
  • Sign Up
  • Cart
  • Home
  • Why Advertise
  • Create Your Campaign
  • About Security on Screen
    • Privacy Policy
  • Webinars
  • Social Wall
  • Contact Us
  • Business News
    • New Technology
    • Opinion
    • People
    • Education & Events
  • Product Groups
    • Access Control
    • Biometrics
    • Cyber Security
    • Physical Security
    • Smart City
    • Surveillance
    • Systems Integration
  • Industry Sectors
    • Banking
    • Casinos
    • City Surveillance
    • Data Centres
    • Government
    • Healthcare
    • Leisure
    • Manufacturing
    • Retail
    • Schools and Campus Security
    • Transport
    • Utilities

© 2020 SecurityOnScreen.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.