
- An SCA solution supporting the government’s SW supply chain roadmap to protect public institutions
- Applies proprietary AI model and risk-based LPP to support response based on actual threat levels
Labrador Labs (CEO Jinseok Kim and CEO Heejo Lee) announced on the 7th that it has registered its open-source software composition analysis solution, ‘Labrador SCA’, on the Public Procurement Service (Korea ON-Line E-Procurement System).
Now, public institutions can more quickly review and adopt Labrador SCA through KONEPS procurement procedures.
Labrador SCA is a solution that automatically identifies open-source components in source code, binaries, and containers, and inspects vulnerabilities and license risks. Based on its patented CENTRIS and VUDDY algorithms, it analyzes software code down to the component, file, and function levels to detect open-source components, vulnerabilities, and potential license violations.
By applying its proprietary AI model, it increases the accuracy of detection results and does not merely list vulnerabilities but filters out high-priority ones. In addition, it presents patch priorities based on its own risk criteria, LPP (Labrador Patch Priorities), and supports selecting and modifying only the vulnerable code. Security managers can respond quickly starting from the parts with actual high risk without having to make unreasonable changes to the entire system.
It automatically generates SBOMs in international standard formats such as SPDX and CycloneDX, and provides a license notice generation feature, which can be used for audits, regulatory compliance, and delivering documents. Public institutions can transparently manage software components and respond to supply chain security requirements.
“Open source is convenient, but if you don’t know what is inside, you are bringing in the risk as well,” said Jinseok Kim, Representative of Labrador Labs. “With the procurement registration of Labrador SCA, we have laid the foundation for public institutions to systematically manage open-source vulnerabilities and license risks without separate procedures.”
Meanwhile, the government announced the ‘Software Supply Chain Security Roadmap’ last month, specifying the expansion of supply chain security management models using SBOMs, and stated that it is also initiating research to automate the supply chain security system by applying AI. Labrador Labs plans to continuously provide supply chain security solutions that satisfy these requirements.
[Source] https://www.datanet.co.kr/news/articleView.html?idxno=212888