Benchmarking Dependency Analysis Tools

OWASP Top 10 2017 lists A9: “using components with known vulnerabilities” as a major security issue facing companies. The recent Equifax data breach was actually caused by a known security issue in the Apache Struts library; it was an instance of the OWASP A9. There are several vendors in the market with products that claim to address this problem. However, it is often very difficult to compare and contrast the results from the tools that do dependency analysis. We recently released an open-source Evaluation Framework for Dependency Analysis (EFDA) to help address this challenge.

