Secure Package Management

Security Management Solution

Manage your security Faster and Easier with our SPM

What is SPM?

SPM is a next-generation vulnerability assessment solution that finds vulnerabilities that traditional platform diagnostics cannot detect. With its unique vulnerability collection engine and vulnerability analysis engine, SPM performs highly accurate vulnerability scans in just a few minutes.

Furthermore, in addition to the severity of known vulnerabilities, the solution can also be used for system vulnerability management by evaluating the information asset value (importance) of the target server, the network connection environment, and the exploitability of the vulnerability, and visualizing the order of priority of countermeasures.

3 Features

Accuracy & Speed​

Accuracy & Speed

High-speed scanning for vulnerabilities inherent in installation packages. High detection accuracy is achieved by aggregating globally scattered vulnerability information and using a proprietary analysis engine.

Clean environment

Clean environment

Scanning does not overload the server.
There is no need to install any special tools or build any environment in the system.

Priority on measures

Priority on measures

In addition to the severity of known vulnerabilities (CVSS Score), we evaluate the information asset value (criticality) of the system, the network connection environment, and the exploitability of the vulnerability, and prioritize countermeasures for each customer.

Flow

Step 1
Inspection

Run the script you receive from us to collect information from packages and other configurations

Step 2
Analysis

Upload the script on to SPM portal website. SPM will detect and analyze vulnerabilities.

Step 3
Report

SPM will generate a report on the detected vulnerabilities along with risk rating (CVSSv2/CVSSv3).

Diagnosis

Existing vulnerabilities in package

Investigate known vulnerabilities inherent in the installation package

Risk assessment by CVSS

Quantitatively assess the risk of inherent vulnerabilities using CVSS scores

Unapplied security Patch Information

Check for the existence of unapplied security patches and and the latest security patch information.

Process open ports in the package

Investigate the packages running as a process
(SPM Pro)

Assessment of potential attacks

Investigate actual potential attacks and priority in vulnerability countermeasures based on CVSS score/operating processes/system criticality, etc.
(SPM Pro)

Analysis for password strength(Optional)

Investigate the strength of the passwords set for your accounts
(SPM Pro)

Choose the plan that best suits your needs

Support multiple functions to enable more effective operations and countermeasures for customers

Scan all at once

Multiple servers can be analyzed together.This function is useful for customers with large systems.

Latest information

Our own repository of vendor-published vulnerability information allows us to inspect for the latest inherent vulnerabilities.

Vulnerability triage

Prioritize vulnerability risk based on your CVSS score. We report CVE information and installed package information, plus security patch information.

Possible Attacks

Risk assessment can be performed in accordance with the actual environment, taking into account the value of information assets and the possibility of reaching the target through the network.
Visualization of process/network port information of packages with inherent vulnerabilities using SSVC and proprietary technology.

Available OS

*1 Exclude kernel aside from standard kernel(e.x. kernel-*.el7.elrepo.x86_64 etc.)
*2 Only available for CPU architecture x86_64.
*3 Exclude Server Core/Windows Server Azure Edition
※Feel free to ask us about other OS availability.

Enables targeted and comprehensive diagnosis

SPM can find vulnerabilities that are difficult to find with other diagnostics. SPM can also be combined with other diagnostics to create a more secure environment according to the customer’s needs. For more information about our other services, please visit our website.

Inquiry

Please feel free to ask us. We will look forward to work with you.