Black Duck Binary Analysis is a software composition analysis (SCA) scanner for compiled code.
Problems Solved
Here's what it can do for you:
- Provides a clear view of risk. Black Duck Binary Analysis gives unmatched visibility into open source and third-party code in applications and containers. Black Duck Binary Analysis gives you the information you need to verify that your product has exactly the components you expect, that those components are up to date, and that no inappropriate software licenses have been used. It creates a high-level overview of the composition and overall health of software, including desktop and mobile applications, embedded system firmware, and more. Better visibility leads to better decisions regarding mergers and acquisitions, as well.
- Helps to manage the risk. Black Duck Binary Analysis provides a comprehensive solution for managing security, quality, and license compliance risk.
- Informs your decisions about software consumption. Reduce security risks and the threat of license noncompliance. Identify known open source vulnerabilities, licensing obligations, sources of sensitive data leakage, and application permission requirements. When you're acquiring a product, Black Duck Binary Analysis allows informed decisions, minimizes your risk, and maximizes the value of the product.
- Maintains security as threats evolve. The receipt of a detailed Bill of Materials for every analyzed product keeps your supply chain secure. Black Duck Binary Analysis automatically updates you when a new vulnerability applies to previously scanned software. This information allows you to make decisions, mitigate or eliminate risks, or negotiate with suppliers.
Use Cases Addressed
Black Duck Binary Analysis can be leveraged in a variety of situations, depending on who you are and what role you occupy in your organization:
- Procurement: If you are acquiring a product, Black Duck Binary Analysis provides visibility into the risk profile of the product, allowing you to make informed decisions and negotiate with your vendor to minimize your risk and maximize the value of the product.
- Mergers and Acquisitions: Black Duck Binary Analysis makes it easy to analyze existing products to understand their composition and associated risk. Better visibility leads to better decisions about product integration and security risks.
- Supply chain security: Any organization looking to minimize risk in its supply chain can put Black Duck Binary Analysis's results to good use. For each analyzed product, Black Duck Binary Analysis provides a BOM, an accurate view of vulnerabilities and risk. This information allows you to make decisions, mitigate or eliminate risks, or negotiate with suppliers.
- Development: For builder organizations, Black Duck Binary Analysis provides automation for tracking third-party software components. As a critical check on the products you are building, Black Duck Binary Analysis gives you the information you need to verify that your product has exactly the components you expect, that those components are up to date, and that no inappropriate software licenses have been used.
Why and How
Using third-party code saves time and money, but exposes your project to risks, in terms of security, code quality, and licensing. Black Duck Binary Analysis addresses that risk when you don't have access to source code. It analyzes software binaries, compiled applications, or docker images. It can scan virtually any compiled software, including desktop and mobile applications, embedded system firmware, and more. (It does not analyze source code; however, standard Black Duck can do that.)
Black Duck Binary Analysis recognizes thousands of existing libraries and open-source projects, as well as their components. If it does not recognize components because it is a proprietary or commercial component or it’s possibly a missing OSS component in the Knowledgebase, you can teach the components using the Vendor Components functionality in Black Duck Binary Analysis, and they will be recognized thereafter. (See the User Guide for more information.) You may also request adding an OSS component to the Knowledgebase by opening up a Support request.
Black Duck Binary Analysis's composition analysis helps you determine whether any of your software components are vulnerable to bugs such as Heartbleed (CVE-2014-0160), particularly in cases where you either cannot run dynamic tests against your systems or are afraid that active vulnerability scanning might have adverse consequences.
Basic Usage
When you scan your code with Black Duck Binary Analysis, it analyzes your binary files and compares the results with those stored in a common database. Components can be recognized by a number of matching methods, including the use of metadata extracted from binary files or .jar files; package manager data, manifest files, or a checksum of a .jar file. (In the user interface, you can find the matching method that was applied to any file in its component description.)
When you teach Black Duck Binary Analysis to recognize your components, you can track and manage the vulnerabilities that are found in them. These remain in your organization and are never shared in the common database (In fact, customers cannot add components or information to the common database – so your proprietary files cannot be mistakenly exposed).
After scanning your application (including third-party and proprietary code), Black Duck Binary Analysis produces a bill of materials (BOM): a comprehensive listing of the components, their known vulnerabilities, and the associated software licenses.
A comprehensive dashboard helps you manage vulnerabilities, leaks of potentially sensitive information, and licensing issues, discovered by Black Duck Binary Analysis. Additionally, you can download scanned binary files and add custom data to scan results.
Obtaining and Setting Up Black Duck Binary Analysis
Typically, licensed users can access and use Black Duck Binary Analysis in any of these ways:
- As a cloud application, in a SaaS environment that is hosted by Amazon Web Services, via https://bdba.blackduck.com/. All files are encrypted with AWS KMS using 256-bit AES-GCM encryption.
- As an on-premises software appliance (a virtual machine), accessed only through your network and using your preferred hypervisor.
- Deployed on a Kubernetes cluster. For more instructions, see https://github.com/protecode-sc/helm-chart.
Once installed, Black Duck Binary Analysis can be accessed through any modern web browser or by using a web API. When accessed by browser, the interactive dashboard displays a high-level overview of composition, overall health, and security risks of scanned software.
Black Duck Binary Analysis supports single sign-on (SSO) via SAML. With SSO, users can log in via an Identity Provider and won't need separate login credentials for different services.