• Latest
  • Trending
Finite State Adds Binary Analysis to Catch Zero-Days

Finite State Adds Binary Analysis to Catch Zero-Days

January 7, 2022
ATC Ghana supports Girls-In-ICT Program

ATC Ghana supports Girls-In-ICT Program

April 25, 2023
Vice President Dr. Bawumia inaugurates  ICT Hub

Vice President Dr. Bawumia inaugurates ICT Hub

April 2, 2023
Co-Creation Hub’s edtech accelerator puts $15M towards African startups

Co-Creation Hub’s edtech accelerator puts $15M towards African startups

February 20, 2023
Data Leak Hits Thousands of NHS Workers

Data Leak Hits Thousands of NHS Workers

February 20, 2023
EU Cybersecurity Agency Warns Against Chinese APTs

EU Cybersecurity Agency Warns Against Chinese APTs

February 20, 2023
How Your Storage System Will Still Be Viable in 5 Years’ Time?

How Your Storage System Will Still Be Viable in 5 Years’ Time?

February 20, 2023
The Broken Promises From Cybersecurity Vendors

Cloud Infrastructure Used By WIP26 For Espionage Attacks on Telcos

February 20, 2023
Instagram and Facebook to get paid-for verification

Instagram and Facebook to get paid-for verification

February 20, 2023
YouTube CEO Susan Wojcicki steps down after nine years

YouTube CEO Susan Wojcicki steps down after nine years

February 20, 2023
Inaugural AfCFTA Conference on Women and Youth in Trade

Inaugural AfCFTA Conference on Women and Youth in Trade

September 6, 2022
Instagram fined €405m over children’s data privacy

Instagram fined €405m over children’s data privacy

September 6, 2022
8 Most Common Causes of a Data Breach

5.7bn data entries found exposed on Chinese VPN

August 18, 2022
  • Consumer Watch
  • Kids Page
  • Directory
  • Events
  • Reviews
Wednesday, 27 September, 2023
  • Login
itechnewsonline.com
  • Home
  • Tech
  • Africa Tech
  • InfoSEC
  • Data Science
  • Data Storage
  • Business
  • Opinion
Subscription
Advertise
No Result
View All Result
itechnewsonline.com
No Result
View All Result

Finite State Adds Binary Analysis to Catch Zero-Days

by ITECHNEWS
January 7, 2022
in Leading Stories, Opinion
0 0
0
Finite State Adds Binary Analysis to Catch Zero-Days

Finite State this week has added a binary analysis capability that enables device manufacturers to more easily identify zero-day vulnerabilities in software.

Jeff Martin, vice president of product for Finite State, said this latest addition to the company’s risk analysis platform can quickly assess third-party components for zero-day vulnerabilities and other known common vulnerabilities and exposures (CVEs).

YOU MAY ALSO LIKE

ATC Ghana supports Girls-In-ICT Program

Vice President Dr. Bawumia inaugurates ICT Hub

The Finite State risk analysis platform is primarily used by device manufacturers that typically employ on-board support packages (BSPs) and software development kits (SDKs) from third-party vendors and developers. The challenge they face is those BSPs and SDKs are essentially a black box that device manufacturers can’t see inside, added Martin.

In the absence of that visibility, Martin said device manufactures have no idea whether or not their software supply chains have been compromised by a zero-day vulnerability. As in the case of the recent Log4j vulnerability and others, these types of zero-days are being disclosed with greater frequency. In the absence of an analysis tool, IT teams can spend months manually looking for vulnerabilities in connected devices that might be deployed almost anywhere in the world.

In general, Martin noted there is too much attention being paid to inspecting source code rather than the application binaries that cybercriminals are looking to exploit in production environments. While the individual component that makes up a software package may be deemed secure, the way they interact with one another once a binary is created can often be exploited, noted Martin.

Unfortunately, Martin added, many device manufacturers are reluctant to analyze those binaries for fear of liability. It’s easier to assume liability for any vulnerability will lie with the developer of the BSP or the SDK, he said. However, it’s apparent that both end users of a device—and various regulatory bodies—are starting to hold device manufacturers more accountable. Lawsuits are sure to follow, Martin warned. Device manufacturers would be well-advised to get ahead of that scrutiny before a cyberattack causes a major disruption that impacts large numbers of end customers, said Martin.

It’s not clear whether the current focus on software supply chain security will extend to the device level. However, it’s all but inevitable that the current level of scrutiny being applied to applications will eventually extend to embedded systems deployed at the network edge. Right now, many cybersecurity teams are not even aware of the existence of those devices until an incident is reported.

Fortunately, device manufacturers have begun to adopt DevSecOps best practices to ensure the integrity of their software supply chains. In the longer term, Martin said Finite State expects to also use machine learning algorithms to help device manufacturers prioritize which vulnerabilities to address first based on potential risks.

In the meantime, Martin said the important thing to remember is not to overlook binaries. After all, while securing source code is important, it’s often the binaries that are the weakest link in a software supply chain.

Source: Security Boulevard
Tags: Cyberattack
ShareTweetShare
Plugin Install : Subscribe Push Notification need OneSignal plugin to be installed.

Search

No Result
View All Result

Recent News

ATC Ghana supports Girls-In-ICT Program

ATC Ghana supports Girls-In-ICT Program

April 25, 2023
Vice President Dr. Bawumia inaugurates  ICT Hub

Vice President Dr. Bawumia inaugurates ICT Hub

April 2, 2023
Co-Creation Hub’s edtech accelerator puts $15M towards African startups

Co-Creation Hub’s edtech accelerator puts $15M towards African startups

February 20, 2023

About What We Do

itechnewsonline.com

We bring you the best Premium Tech News.

Recent News With Image

ATC Ghana supports Girls-In-ICT Program

ATC Ghana supports Girls-In-ICT Program

April 25, 2023
Vice President Dr. Bawumia inaugurates  ICT Hub

Vice President Dr. Bawumia inaugurates ICT Hub

April 2, 2023

Recent News

  • ATC Ghana supports Girls-In-ICT Program April 25, 2023
  • Vice President Dr. Bawumia inaugurates ICT Hub April 2, 2023
  • Co-Creation Hub’s edtech accelerator puts $15M towards African startups February 20, 2023
  • Data Leak Hits Thousands of NHS Workers February 20, 2023
  • Home
  • InfoSec
  • Opinion
  • Africa Tech
  • Data Storage

© 2021-2022 iTechNewsOnline.Com - Powered by BackUPDataSystems

No Result
View All Result
  • Home
  • Tech
  • Africa Tech
  • InfoSEC
  • Data Science
  • Data Storage
  • Business
  • Opinion

© 2021-2022 iTechNewsOnline.Com - Powered by BackUPDataSystems

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Go to mobile version