Code Security Summary provides a comprehensive high level overview of your application security, allowing you to have a complete security dashboard of your application at your fingertips.

 Code Security Summary provides:

 

Security Rating

Kiuwan Security Rating is a discrete 5-star grade that tells you how secure your application is in terms of the likelihood and impact of the found vulnerabilities.

This rating concentrates all the security evidences found in the source.

Applications with 5 stars are considered to be secure, whereas those with 1 star are considered to be very insecure

Security Vulnerabilities

Security vulnerabilities are grouped in a quadrant according to two major axes:

These two axes produce 4 quadrants. Kiuwan summarizes found vulnerabilities for each quadrant.

 

In this image, you can see that Kiuwan found 271 vulnerabilities and how kiuwan distributes them in the 4 quadrants:

 

Security rating is based on following:

Based on analysis results, Kiuwan also calculates the Effort you need to invest to reach the different rating levels according to the remediation effort associated to fix each vulnerability.

 

Please note that Very Low vulnerabilites are discarded in Security Rating algorithm and are not included in 4-quadrant image.

That's the reason you could find that total number of vulnerabilties in the 4-quadrant image is lower than the total vulnerabilities figure.

To view detailed info on all the vulnerabilites, please go to Vulnerabilities page.

 

Top 10 Vulnerabilities and Worst Files

Code Security Summary also provides a Top-10 ranking of vulnerability types and worst files.

This way, you can easily concentrate on major contributors to current security rating.

Vulnerability Types

Kiuwan Code Security considers a vulnerability any defect that could produce a potential security issue, regardless that defect could belong to a software characteristic other than Seccurity.

Moreover, any vulnerability found by Kiuwan is categorized according to its type:

 

The Top-10 Vulnerabilities By Type graphic lets you to view which ones are the most frequent in your application, showing the total number of vulnerabilities for every type.

Clicking on the vulnerability type you will be able to see associated defects (that link will forward you to Vulnerabilities page with the defects filtered by the selected type).

If you want to see which vulnerabilities are checked by Kiuwan for every type, you should go to Model Management, select your model and click on Security Rules.  

 

The Top-10 Worst Files graphic displays a ranking of worst (low-rated) files of your application, showing the security rating and the number of vulnerabilities found.

Timeline

The Timeline section displays a historical evolution of your Security Rating and Total Effort (to reach 5-star rating) as well as the total LOC size of your application.

This section also displays information on: