SolidLab
SolidLab SDP

SolidLab SDP

The SolidLab intelligent secure development platform helps build DevSecOps and secure development processes. Platform modules combine automated security analysis, SAST, DAST, SCA, secret detection, and security weakness management in a single environment, while detected issues are transferred to an interface for findings management and task prioritization.

Overview of capabilities

The platform provides a programmatic interface (API) to automate application security analysis tasks.

Use cases

  • identifying security weaknesses in applications during development;
  • embedding security checks into application development processes;
  • assessing the security of information systems based on automated analysis results;
  • validating discovered issues and implementing a remediation workflow.

Deployment

The platform is hosted on the provider side and is a set of technical and software components based on infrastructure-as-a-service offerings. It is intended for SaaS and managed service delivery models.

Functional capabilities

SolidLab SDP is a set of tools, scanners, services and automation components, flexibly configurable to customer needs and designed to identify security issues in applications.

The platform consists of independent subsystems, which makes it possible to:

  • use only the subsystems required for specific tasks;
  • change the set of subsystems in production without downtime of deployed components;
  • optimize allocated compute resources.

Depending on the tasks, the platform may include:

  • a centralized subsystem for processing and storing discovered issues and displaying results of other subsystems;
  • a subsystem for identifying issues using static code analysis methods;
  • a subsystem for dynamic application vulnerability analysis;
  • a subsystem for detecting exposed secrets in source code;
  • a subsystem for infrastructure-as-code (IaC) analysis for security misconfigurations;
  • a subsystem for analyzing used software components for known vulnerabilities;
  • a subsystem for analyzing components inside container images for known vulnerabilities.

Subsystem capabilities

  • retrieving source code for analysis from repositories;
  • selecting subsystems used to analyze a particular information system;
  • parallel execution of multiple analysis jobs and a job queue;
  • exporting discovered issues to the centralized processing and storage subsystem;
  • grouping results from multiple subsystems;
  • filtering findings and verifying them with severity assessment;
  • tracking fixes for discovered issues;
  • granular access control to analysis results;
  • statistics on findings and report generation;
  • static analysis without compiling application source code;
  • static analysis for languages: C, C++, C#, Go, Java, JavaScript, Kotlin, TypeScript, Ruby, Rust, PHP, Python, Scala, Swift;
  • detecting static-analysis issues including injections (incl. XSS, SQLi, SSTI), user-data deserialization, SSRF, XXE, RCE;
  • building an attack surface during dynamic analysis by discovering entry points using static and dynamic techniques;
  • detecting dynamic-analysis issues including Reflected XSS, DOM-based XSS, SQL injections, XXE, Path Traversal;
  • detecting exposed secrets in source code and commit history;
  • infrastructure-as-code analysis (Terraform, Kubernetes, Docker, Ansible);
  • finding vulnerabilities in used components (npm, maven, gradle, pip, composer, go, etc.);
  • analyzing components inside Docker images for known vulnerabilities.

Subsystems use:

  • proprietary vulnerability databases delivered with the platform;
  • public vulnerability databases.