SPM (Secure Package Management) service created by Belue Creative Inc is a next-generation vulnerability assessment solution that finds vulnerabilities inside systems that cannot be detected by conventional vulnerability assessment. Our unique vulnerability collection and inspection engine enables extremely accurate vulnerability diagnosis. It is possible to diagnose vulnerabilities of packages installed on the server, application status of security patches, status of the latest packages, and misconfiguration in the OS. Even if the server is in production, it can diagnose every detail within the server in just a few minutes without putting any load on it. In addition to the severity of known vulnerabilities, the information asset value (importance) of the target server, the network connection environment, and the possibility of exploitation of the vulnerability are evaluated, and countermeasures are prioritized for each discovered vulnerability. SPM can reduce the customer's diagnostic workload and server load by more than 60%.

By implementing SPM, you can comply with the following industry standards. 
● PCIDSSv4.0:Authenticated Scans
● SBOM

Summary of the SPM Characteristics
Visualizing Vulnerabilities
SPM, a vulnerability assessment and management service, is a diagnostic tool that visualizes vulnerabilities in packages installed on servers by referring to publicly available databases and other information to streamline vulnerability management. Vulnerability information continue to updated on a daily basis, and approximately 20,000 vulnerabilities are disclosed annually. Depending on the system, there may be hundreds or thousands of packages installed, which incurs a large cost for vulnerability management.

Features of SPM

SPM is an innovative solution with the following features.

Feature 1: Attack potential

Attack potential for each individual package can be investigated. In addition to the vulnerabilities inherent in the package, the operation status of the package as a process and network service can also be visualized. This visualization enables prioritization of remediation for each package.

Feature 2: Remains a clean environment

SPM executes commands present in the system OS and collects package version information, etc. There is no modification or deletion of configuration files or installation of special tools! Therefore, we can inspect your system environment while keeping it clean! In addition, the inspection can be performed without affecting the system in operation, such as the generation of target network traffic.

Feature 3: Ease to analysis

All you need to do is run the inspection program on your server.

There is no need to build a server for analysis, no need to disarm the FW temporarily too! The inspections can be performed at any time you want.
3 Step-Scan
Inspection Process

● No need to build a system environment
● No need to adjust dates and you can inspect any time you want
● No need to change the setting for inspection
● No effect on a system overload or operational impact due to inspection

SPM minimizes the burden on the customer in the inspection process. Inspections can be performed by simply executing the information collection script on the server.

Useful function of Vulnerability Management

The system supports several functions that enable customers to more effectively manage vulnerabilities and take countermeasures.

Batch Scanning

Multiple servers can be analyzed together. This function is useful for customers with large-scale systems.

Latest Information

Our own repository of vendor-published vulnerability information allows us to inspect for the latest inherent vulnerabilities.

Vulnerability triage

Prioritize vulnerability risk based on your CVSS score. We report CVE information and installed package information, and also security patch information.

Attack potential(NEW!)
Risk assessment based on the actual environment is possible, taking into account the value of information assets and the reachability of information via the network.

※Assessment using SSVC and proprietary technologies

Visualization of process/network port information of packages with inherent vulnerabilities

SPM new function

The new SPM features provide functionality that solve the conventional issues.

Issue: frequency/ possibility of occurrence of the attacks

Even for high-risk vulnerabilities, the priority for vulnerability management varies depending on the value of the system's information assets and the degree of exposure (public/private),The priority of vulnerability management varies depending on the value of the system's information assets and the degree of exposure (public/private).In addition, the frequency and likelihood of attacks on services that are accessed by a large number of unspecified people and services that are not in operation are different in the case of actual exploitation of vulnerabilities. Conventional CVSS-based evaluation methods require a lot of additional research, including interviews, to calculate the evaluation of attack probability for various use cases.

Solution: Assessment of Attack Potential (NEW!!)

This is a new functionality implemented the conventional issues.Using our proprietary technology, we evaluate the possibility of occurrence of an attack on a system-wide/package-by-package basis.

SPM new feature
Assessment of Attack Potential (NEW!!)

Risks are assessed based on the actual environment, taking into account the value of the system's information assets and the possibility of reaching the system via the network.

In addition, by inspecting the inherent vulnerabilities together with the availability of the package, it is possible to the vulnerabilities can be prioritized for each package.

If you have any question regarding to this article, feel free to contact us for details.

Belue Creative, Inc.
TEL:(+81) 03-6206-2066
Address: Jinno Building 4F, 2-1-8 Nihonbashi Horidome-cho, Chuo-ku, Tokyo 〒103-0012
Email: info@belue-c.jp
Website: https://solution.belue-c.jp/en/