Vous êtes sur la page 1sur 4

DATA S HE E T

Palamida Enterprise Edition


The First Application Security Solution for Open Source

Palamida Enterprise Edition is an end-to-end solution that identifies, assesses, and


Palamida Enterprise manages open source vulnerabilities, compliance issues, and license concerns within
Edition At A Glance custom-built software applications. By creating visibility into software content, Palamida
Targeted towards organizations Enterprise Edition helps engineering, security, and legal teams manage and secure their
concerned with managing both use of open source software:
vulnerabilities and IP issues • Document Your Open Source Usage: Ensure rapid and accurate analysis of
that can arise from using custom-built applications, provide an inventory of open source components and their
undocumented open source location within your code base, and report on associated vulnerabilities, license and
copyright information.
• Facilitates sharing of relevant
data across teams: engineering, • Assess Your Exposure to Risk: Provide a reliable framework for security and
security, legal and management IP stakeholders to receive alerts of issues as they arise, assess violations against
established policies, and document the decisions around remediation.
• Includes comprehensive
• Manage Compliance and Collaboration: Assist in establishing procedures,
detection techniques to protect
implementing policy and enabling collaboration for approval and/or registry of open
against security vulnerabilities
source use prior to inclusion within applications.
and IP violations due to false
negatives Document Your Open Source Usage
• Sends vulnerability and IP alerts Vulnerability and IP Detection Engines
to appropriate stakeholders for Software developers have almost one million popular open source project versions (and counting) to choose

remediation from when building custom applications, an enormous benefit in terms of cost and time savings. However, most
open source use remains undocumented – without formal record of its existence within your mission critical
• Provides centralized dashboard applications and products. Identifying which components, versions and even partial components have been
for 360° view of risks that actually adopted, after the fact, is time consuming and difficult. Without this level of documentation, it is difficult
could impact mission critical for development, security, and legal teams to fully assess the risk level of mission critical applications.
application Palamida’s specialized vulnerability and IP detection engines leverage patent-pending technology to detect
• Establishes registry of the components, versions and even partial component code that have been used. Detection capability spans
binary files, source code, Java name spaces, copyright, license and user-specified search terms across multiple
authorized open source
languages including Java, JavaScript, C#, C/C++, Perl, Python, PHP and Visual Basic. The ability to analyze
components, licenses and
binary files and archives means that the detection engines can find open source use, even when source code is
secure versions for standardized not available – something not possible with manual analysis or simple in-house tools.
use across the organization
The vulnerability engine leverages data derived from multiple sources including the National Vulnerability
Database, sponsored by the Department of Homeland Security, to identify and report on vulnerable versions
of components found in your code base. Users receive an open source inventory, descriptions of projects, and
relevant Common Vulnerability Enumerations and severity. In addition, the software pinpoints the exact location of
the open source inside the code base for remediation.
Concise reporting on known vulnerabilities for all detected open source
The vulnerability and IP detection engines
leverage the industry’s largest index
of open source components. The index Vulnerability and IP Analyzers
is continuously growing and currently
The nature of code reuse in the open source development model makes accurate identification and the review of
includes:
false positive matches tedious.
• 884,000 versions of open source
projects and associated licenses Palamida’s technology includes identification algorithms that provide automated analysis ranging from source
• 8 billion source code fingerprints code snippet matches to component and version level usage. Java™ Auto-inventory, based on a patent-pending

• 500 million binary files Java analysis algorithm and specialized database of millions of Java namespace names, provides accurate,
automated identification of Java projects – virtually eliminating the need for manual analysis of source code.
• 13 million Java namespace names
Additional detectors are specifically tuned for the highest levels of automated identification across all languages.
• Over 4,500 popular open source
project versions and associated
vulnerability alerts
Assess Your Exposure to Risk
Dashboard
Providing relevant information appropriate to individual stakeholders across a cross-functional team is
challenging. Palamida Enterprise Edition turns data into actionable and measurable information with an alert-
Palamida Enterprise Edition is capable based reporting system that provides pertinent information based on each person’s functional role.
of scanning source files of all kinds:
.c .h .cpp .hpp .cxx, .java, .js, .pl, .pm, The dashboard provides a centralized view of the documentation, assessment and monitoring of open source
.php, .py, and .vb. If source code is use. It provides vulnerability and IP alerts, and allows users to drill down on details and assign issues for
not available, the software can detect remediation. For executive managers, the dashboard provides the ability to track security and IP violations across
licenses, java namespaces, binary files, the enterprise.
copyright text, and even text files as
part of its identification of open source For security teams, Palamida reports on known vulnerabilities for detected open source components. With one-
usage. click, you will know exactly where vulnerabilities may impact deployed applications. This level of detail allows you
to focus on remediation with precision and speed.
At the same time, legal stakeholders see a summary of the inventory of open source components, compliance
CodeRank™ is a patented system for status, and license and copyright information, to address intellectual property problems before they arise.
classifying open source code snippet Since one size does not fit all, you can customize reports to tailor information for specific roles in your
matches. By evaluating snippets on organization. Reports can be easily and securely distributed to select people when you need to share data.
multiple levels – uniqueness, coverage,
and clustering – CodeRank lists the
most relevant matches first.
At-a-glance view of enterprise vulnerability and IP exposure

Key Benefits:
• Make open source use decisions
visible, documented part of
Manage Compliance and Collaboration development process
Policy Manager • Provide audit trail regarding open
Preventing undocumented code from entering a code base is more cost-effective than remediating associated source use
problems after application deployment. Palamida Enterprise Edition allows managers to establish both security • Enable “conditions of use” as part of
and IP policies based on the business requirements of their organizations. Final inventory of open source open source security and IP policy rules
software and associated vulnerability and IP intelligence can be included as part of release readiness criteria
before application deployment.
Legal and security teams can create open source policies and compliance can be checked during the
development process. Lawyers can set license policies, such as blacklisting specific license types and versions,
while security managers can set usage policies such as whitelisting specific open source component versions
that have been reviewed and approved.
Engineering teams can shorten the development time by ensuring compliance with established policy early in the
process. They can easily determine what components are approved so that they use the correct versions in their
work, reducing rework from late detection. When a new module is needed, the system triggers a request process
to ensure that all the appropriate information regarding version, use, license, and vulnerabilities are documented.

Adapts to Existing Processes and IT Environments


The software is designed for integration with existing development tools and processes. The Palamida API,
based on the Groovy scripting language, facilitates the integration of the Palamida Enterprise Edition with other
applications, including existing build environments such as IBM BuildForge, IBM Clearcase, Subversion, Borland
Gauntlet, etc. Through such integration, incremental scans can be automatically triggered for specific builds,
ensuring that any new issues are found promptly and can be acted on appropriately.
Palamida Products Portfolio
In addition to the Enterprise Edition, Palamida also provides the Standard Edition and Compliance Edition.
Standard Edition is designed for organizations whose primary concerns are managing vulnerability alerts and
version updates. Compliance Edition is designed for organizations whose primary concerns are intellectual
property issues regarding license compliance and conflicts.

Enterprise Edition Standard Edition Compliance Edition


Vulnerability Detection Engine • •
Vulnerability Analyzer • •
IP Detection Engine • •
IP Analyzer • •
Dashboard • • •
Policy Manager • • •
Integration Framework • • •

Technical Specifications
Server Recommendations:
Hardware 16 GB Memory (32 GB recommended)
2.4 Ghz or higher CPU
64 bit CPU - Intel/Opteron
300 GB disk space
Operating Systems Windows XP (64-bit) - SP2
Windows Vista (64-bit)
Fedora Core 7 (64-bit)
Red Hat Enterprise 4 (64-bit)
Software Java JDK 1.5.0

About Palamida, Inc.


Palamida is the industry’s first application security solution exclusively for Open Source Software that uses
component-level analysis to quickly identify and track undocumented code and associated security vulnerabilities
as well as intellectual property and compliance issues, enabling organizations to cost-effectively manage and
secure mission critical applications and products.

Contact Us
For more information on how Palamida can help your organization mitigate risk and meet both corporate
standards and security and regulatory compliance, contact us at sales@palamida.com or (415) 777-9400 x 123.

215 Second Street


1st Floor
San Francisco, CA 94105
P: 415.777.9400
F: 415.777.5800
www.palamida.com

© 2008 Palamida, Inc. All rights reserved. Palamida


and the Palamida logo are trademarks of Palamida, Inc.
All other trademarks and registered trademarks are the
property of their respective holders.

Vous aimerez peut-être aussi