Перейти к содержанию

"1C-Bitrix" Added AI to Application Testing

Classification of "findings" is carried out according to industry standards - CWE and OWASP Top 10, severity assessment - according to CVSS.

The "1C-Bitrix" Information Security Center has implemented a new level of control for third-party solutions. Now, for publication on the marketplace, which features over 2000 modules and applications, code analysis based on artificial intelligence is used.

The new AI audit complements the existing multi-level security system, which already includes static analysis, expert verification, and maintaining a public vulnerability registry. According to company representatives, this is their own initiative aimed at developing the security of the entire ecosystem.

A feature of the AI audit is its ability to identify atypical and complex vulnerabilities that may be missed by standard automated checks. All identified problems are classified according to international standards, and the module developer is responsible for their elimination.

The response process has not changed. If a threat is detected in a new solution, its publication is blocked. If a vulnerability is found in an already placed module, the developer receives a report and is obliged to release a fix within the established timeframe. Until the patch is released, information about the problem is not disclosed to protect users. In case of refusal to cooperate, the module is removed from the marketplace.