Sign up to save tools and stay up to date with the latest in AI
bg
bg
1

How Black Duck is using AI for at-risk software

Nov 20, 2024 - businessinsider.com
Black Duck Software, a security products and services provider, is using artificial intelligence (AI) to speed up the delivery of security advisories to its customers. The company has started using generative AI to send Black Duck Security Advisories (BDSAs) faster, enabling customers to quickly address potential software risks. The move came after the National Vulnerability Database began publishing fewer vulnerability reports due to a backlog, while the Linux kernel started flagging more risks.

The company's engineering and research teams integrated gen AI with BDSAs, using commercially available large language models. The AI system has allowed the company to send out about five times its usual number of notifications a month. Black Duck has also unveiled Polaris Assist, an AI-powered security assistant that combines existing application security tools with large language models to provide automated summaries of detected vulnerabilities and suggestions for code fixes.

Key takeaways:

  • Black Duck Software uses AI to speed up the process of sending security advisories to its customers, increasing its output by about five times.
  • The company developed this solution in response to a decrease in vulnerability reports from the National Vulnerability Database and an increase in flagged risks from the Linux kernel.
  • Black Duck's new AI-powered security assistant, Polaris Assist, is currently in beta testing and aims to help security and development teams work more efficiently.
  • The company continues to invest in AI to make application security testing and remediation easier, faster, and more scalable.
View Full Article

Comments (0)

Be the first to comment!