MM148635 (Community Member) asked a question.

Sandbox Static scan report is not consistent

When I re scan the same source code now which was uploaded 2 months back giving inconsistent report. (source code as well as number of modules selected were same)

Now the number of reported flaws are many as compared to prev scan.

ie,Increased Medium flaw from 37 to 450 .

Again i re scanned, but it still gives 450 flaws

I use sandbox scan. (.Net Project)

Shall we get the reason for this?


  • Hi @MM148635 (Community Member)​ ,

     

    When investigating a difference in results from Veracode Static Analysis we typically recommend the following:

     

    1. Ensure you are packaging and compiling per our Compilation Guide: https://help.veracode.com/reader/4EKhlLSMHm5jC8P8j3XccQ/UXI5sR0ayWfLm6ifmd4zWw .
    2. Ensure you are compiling with the same compiler version and configuration, as we analyse the binaries a compiler change may mean different binary output and while we try to normalize the binary at times this may result in result differences.
    3. Ensure you are consistently packaging the upload, a difference in upload naming along with a difference in upload may cause us to miss that it is the same application and not apply flaw matching.
    4. Ensure you are consistently selecting the appropriate modules and have reviewed all warnings: https://help.veracode.com/reader/wySvh2U7LWNYqeVS7PQm_g/zhoQxu~cq3U0n3XoPofxQw .
    5. Review how the code is used and whether all paths to the areas where flaws are reported are similar. Note that Veracode Static Analysis checks whether something is used ( https://en.wikipedia.org/wiki/Control_flow_analysis ) as well as how data flows through the application to the exit point ( https://en.wikipedia.org/wiki/Data-flow_analysis ). This means that small upstream changes can have a large effect how we model your application.
    6. If all of this has been verified and is correct (compiled and packaged correctly) and the same between scans (module selection) then please contact Veracode Support by clicking your avatar in the upper right corner and then clicking "Contact Support" in the resulting menu. In the support case please provide Veracode Platform URLs (starting with https://analysiscenter.veracode.com/) to 2 separate scans of the application.

     

    If you have any questions on this please feel free to contact the Veracode Application Security Consulting service either through Veracode Support or through scheduling a consultation: https://community.veracode.com/s/article/How-to-schedule-a-consultation-call.

     

    Thank you,

    Boy Baukema

    Expand Post

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.