Download [This article belongs to Volume - 58, Issue - 4]
Gongcheng Kexue Yu Jishu/Advanced Engineering Science
Journal ID : AES_1727_26-3532-3543

Title : CENTRALIZED APPLICATION INTELLIGENCE SYSTEM FOR DEPENDENCY ANALYSIS, VULNERABILITY DETECTION, AND LIFECYCLE MANAGEMENT
Anil Kumar Chitiprolu

Abstract : Modern organizations have hundreds of applications, each based on different technology stacks, and each of those potentially depends on third-party and open-source libraries. The situation has become more complicated with libraries reaching end of life and vulnerabilities becoming unpatched. The Centralized Application Intelligence System (CAIS) brings all application metadata into one place to create an intelligence-based application cybersecurity platform. This system also automates dependency discovery, vulnerability detection and lifecycle tracking, leveraging various open-source tools, including the OWASP Dependency-Check Project and Snyk. The paper develops three application security quantitative measurements and analyzes them on ten representative enterprise applications: the Vulnerability Risk Score (VRS), the Dependency Freshness Index (DFI), and the Remediation Impact Score (RIS). In the sample, six in ten applications had a DFI greater than 50 percent, indicating an important amount of technical debt in their dependency portfolios. The VRS analysis also identified mission-critical systems with composite risk scores at the maximum level, which need immediate attention. The RIS has two of the ten proposed upgrades as major coordination efforts due to their potential blast radius. CAIS is the enterprise-scale software governance, following the practices of the DevSecOps era.

Keywords : Application Inventory, Dependency Management, Vulnerability Analysis, Software Lifecycle, Risk Assessment, DevSecOps