Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix weak hash false positive in oracle.security.o5logon.O5Logon #8608

Merged
merged 8 commits into from
Mar 25, 2025

Conversation

jandro996
Copy link
Member

@jandro996 jandro996 commented Mar 24, 2025

What Does This Do

Exclude oracle.security.o5logon.O5Logon in IAST

Motivation

Additional Notes

Contributor Checklist

Jira ticket: APPSEC-57044

@jandro996 jandro996 added type: enhancement comp: asm iast Application Security Management (IAST) labels Mar 24, 2025
@jandro996 jandro996 marked this pull request as ready for review March 24, 2025 08:18
@jandro996 jandro996 requested a review from a team as a code owner March 24, 2025 08:18
@pr-commenter
Copy link

pr-commenter bot commented Mar 24, 2025

Benchmarks

Startup

Parameters

Baseline Candidate
baseline_or_candidate baseline candidate
git_branch master alejandro.gonzalez/APPSEC-57044
git_commit_date 1742825749 1742890817
git_commit_sha 51813bd ab7b08c
release_version 1.48.0-SNAPSHOT~51813bdfcb 1.48.0-SNAPSHOT~ab7b08c058
See matching parameters
Baseline Candidate
application insecure-bank insecure-bank
ci_job_date 1742893655 1742893655
ci_job_id 862832235 862832235
ci_pipeline_id 59860106 59860106
cpu_model Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
kernel_version Linux runner-kj59svlh-project-304-concurrent-0-y1d6cxxz 6.8.0-1024-aws #26~22.04.1-Ubuntu SMP Wed Feb 19 06:54:57 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux Linux runner-kj59svlh-project-304-concurrent-0-y1d6cxxz 6.8.0-1024-aws #26~22.04.1-Ubuntu SMP Wed Feb 19 06:54:57 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux
module Agent Agent
parent None None
variant iast iast

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 65 metrics, 6 unstable metrics.

Startup time reports for insecure-bank
gantt
    title insecure-bank - global startup overhead: candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb

    dateFormat X
    axisFormat %s
section tracing
Agent [baseline] (1.046 s) : 0, 1046427
Total [baseline] (8.698 s) : 0, 8698078
Agent [candidate] (1.05 s) : 0, 1050396
Total [candidate] (8.662 s) : 0, 8661992
section iast
Agent [baseline] (1.177 s) : 0, 1176529
Total [baseline] (9.222 s) : 0, 9221947
Agent [candidate] (1.176 s) : 0, 1176106
Total [candidate] (9.235 s) : 0, 9235197
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.186 s) : 0, 1185965
Total [baseline] (9.241 s) : 0, 9241174
Agent [candidate] (1.186 s) : 0, 1186213
Total [candidate] (9.253 s) : 0, 9253018
section iast_TELEMETRY_OFF
Agent [baseline] (1.178 s) : 0, 1178467
Total [baseline] (9.271 s) : 0, 9270706
Agent [candidate] (1.179 s) : 0, 1179020
Total [candidate] (9.24 s) : 0, 9239679
Loading
  • baseline results
Module Variant Duration Δ tracing
Agent tracing 1.046 s -
Agent iast 1.177 s 130.102 ms (12.4%)
Agent iast_HARDCODED_SECRET_DISABLED 1.186 s 139.538 ms (13.3%)
Agent iast_TELEMETRY_OFF 1.178 s 132.04 ms (12.6%)
Total tracing 8.698 s -
Total iast 9.222 s 523.868 ms (6.0%)
Total iast_HARDCODED_SECRET_DISABLED 9.241 s 543.095 ms (6.2%)
Total iast_TELEMETRY_OFF 9.271 s 572.628 ms (6.6%)
  • candidate results
Module Variant Duration Δ tracing
Agent tracing 1.05 s -
Agent iast 1.176 s 125.71 ms (12.0%)
Agent iast_HARDCODED_SECRET_DISABLED 1.186 s 135.817 ms (12.9%)
Agent iast_TELEMETRY_OFF 1.179 s 128.624 ms (12.2%)
Total tracing 8.662 s -
Total iast 9.235 s 573.206 ms (6.6%)
Total iast_HARDCODED_SECRET_DISABLED 9.253 s 591.027 ms (6.8%)
Total iast_TELEMETRY_OFF 9.24 s 577.687 ms (6.7%)
gantt
    title insecure-bank - break down per module: candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb

    dateFormat X
    axisFormat %s
section tracing
BytebuddyAgent [baseline] (718.017 ms) : 0, 718017
BytebuddyAgent [candidate] (719.31 ms) : 0, 719310
GlobalTracer [baseline] (239.959 ms) : 0, 239959
GlobalTracer [candidate] (240.001 ms) : 0, 240001
AppSec [baseline] (54.611 ms) : 0, 54611
AppSec [candidate] (55.028 ms) : 0, 55028
Debugger [baseline] (4.398 ms) : 0, 4398
Debugger [candidate] (4.432 ms) : 0, 4432
Remote Config [baseline] (701.713 µs) : 0, 702
Remote Config [candidate] (721.376 µs) : 0, 721
Telemetry [baseline] (12.733 ms) : 0, 12733
Telemetry [candidate] (14.889 ms) : 0, 14889
section iast
BytebuddyAgent [baseline] (838.522 ms) : 0, 838522
BytebuddyAgent [candidate] (837.885 ms) : 0, 837885
GlobalTracer [baseline] (229.916 ms) : 0, 229916
GlobalTracer [candidate] (229.985 ms) : 0, 229985
IAST [baseline] (22.696 ms) : 0, 22696
IAST [candidate] (22.835 ms) : 0, 22835
AppSec [baseline] (55.991 ms) : 0, 55991
AppSec [candidate] (55.802 ms) : 0, 55802
Debugger [baseline] (4.141 ms) : 0, 4141
Debugger [candidate] (4.175 ms) : 0, 4175
Remote Config [baseline] (595.984 µs) : 0, 596
Remote Config [candidate] (598.238 µs) : 0, 598
Telemetry [baseline] (8.736 ms) : 0, 8736
Telemetry [candidate] (8.746 ms) : 0, 8746
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (844.816 ms) : 0, 844816
BytebuddyAgent [candidate] (845.497 ms) : 0, 845497
GlobalTracer [baseline] (231.493 ms) : 0, 231493
GlobalTracer [candidate] (231.568 ms) : 0, 231568
IAST [baseline] (23.09 ms) : 0, 23090
IAST [candidate] (23.12 ms) : 0, 23120
AppSec [baseline] (56.741 ms) : 0, 56741
AppSec [candidate] (56.284 ms) : 0, 56284
Debugger [baseline] (4.214 ms) : 0, 4214
Debugger [candidate] (4.18 ms) : 0, 4180
Remote Config [baseline] (615.35 µs) : 0, 615
Remote Config [candidate] (602.351 µs) : 0, 602
Telemetry [baseline] (8.883 ms) : 0, 8883
Telemetry [candidate] (8.878 ms) : 0, 8878
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (840.463 ms) : 0, 840463
BytebuddyAgent [candidate] (839.645 ms) : 0, 839645
GlobalTracer [baseline] (230.224 ms) : 0, 230224
GlobalTracer [candidate] (231.5 ms) : 0, 231500
IAST [baseline] (22.398 ms) : 0, 22398
IAST [candidate] (23.272 ms) : 0, 23272
AppSec [baseline] (55.971 ms) : 0, 55971
AppSec [candidate] (55.272 ms) : 0, 55272
Debugger [baseline] (4.141 ms) : 0, 4141
Debugger [candidate] (4.141 ms) : 0, 4141
Remote Config [baseline] (605.883 µs) : 0, 606
Remote Config [candidate] (590.636 µs) : 0, 591
Telemetry [baseline] (8.578 ms) : 0, 8578
Telemetry [candidate] (8.588 ms) : 0, 8588
Loading
Startup time reports for petclinic
gantt
    title petclinic - global startup overhead: candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb

    dateFormat X
    axisFormat %s
section tracing
Agent [baseline] (1.048 s) : 0, 1048214
Total [baseline] (10.463 s) : 0, 10462912
Agent [candidate] (1.047 s) : 0, 1046732
Total [candidate] (10.478 s) : 0, 10477706
section appsec
Agent [baseline] (1.188 s) : 0, 1188123
Total [baseline] (10.796 s) : 0, 10795792
Agent [candidate] (1.196 s) : 0, 1195689
Total [candidate] (10.793 s) : 0, 10793059
section iast
Agent [baseline] (1.177 s) : 0, 1176611
Total [baseline] (11.012 s) : 0, 11012027
Agent [candidate] (1.189 s) : 0, 1189390
Total [candidate] (11.032 s) : 0, 11032147
section profiling
Agent [baseline] (1.282 s) : 0, 1282410
Total [baseline] (10.928 s) : 0, 10927500
Agent [candidate] (1.27 s) : 0, 1270343
Total [candidate] (10.816 s) : 0, 10815893
Loading
  • baseline results
Module Variant Duration Δ tracing
Agent tracing 1.048 s -
Agent appsec 1.188 s 139.91 ms (13.3%)
Agent iast 1.177 s 128.397 ms (12.2%)
Agent profiling 1.282 s 234.196 ms (22.3%)
Total tracing 10.463 s -
Total appsec 10.796 s 332.881 ms (3.2%)
Total iast 11.012 s 549.116 ms (5.2%)
Total profiling 10.928 s 464.588 ms (4.4%)
  • candidate results
Module Variant Duration Δ tracing
Agent tracing 1.047 s -
Agent appsec 1.196 s 148.957 ms (14.2%)
Agent iast 1.189 s 142.658 ms (13.6%)
Agent profiling 1.27 s 223.612 ms (21.4%)
Total tracing 10.478 s -
Total appsec 10.793 s 315.353 ms (3.0%)
Total iast 11.032 s 554.441 ms (5.3%)
Total profiling 10.816 s 338.187 ms (3.2%)
gantt
    title petclinic - break down per module: candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb

    dateFormat X
    axisFormat %s
section tracing
BytebuddyAgent [baseline] (718.222 ms) : 0, 718222
BytebuddyAgent [candidate] (718.238 ms) : 0, 718238
GlobalTracer [baseline] (239.693 ms) : 0, 239693
GlobalTracer [candidate] (239.623 ms) : 0, 239623
AppSec [baseline] (54.863 ms) : 0, 54863
AppSec [candidate] (54.689 ms) : 0, 54689
Debugger [baseline] (5.859 ms) : 0, 5859
Debugger [candidate] (5.155 ms) : 0, 5155
Remote Config [baseline] (712.222 µs) : 0, 712
Remote Config [candidate] (708.45 µs) : 0, 708
Telemetry [baseline] (12.841 ms) : 0, 12841
Telemetry [candidate] (12.314 ms) : 0, 12314
section appsec
BytebuddyAgent [baseline] (736.019 ms) : 0, 736019
BytebuddyAgent [candidate] (741.219 ms) : 0, 741219
GlobalTracer [baseline] (236.094 ms) : 0, 236094
GlobalTracer [candidate] (237.728 ms) : 0, 237728
IAST [baseline] (21.537 ms) : 0, 21537
IAST [candidate] (21.459 ms) : 0, 21459
AppSec [baseline] (175.725 ms) : 0, 175725
AppSec [candidate] (176.279 ms) : 0, 176279
Debugger [baseline] (4.298 ms) : 0, 4298
Debugger [candidate] (4.328 ms) : 0, 4328
Remote Config [baseline] (652.95 µs) : 0, 653
Remote Config [candidate] (651.781 µs) : 0, 652
Telemetry [baseline] (8.532 ms) : 0, 8532
Telemetry [candidate] (8.649 ms) : 0, 8649
section iast
BytebuddyAgent [baseline] (838.133 ms) : 0, 838133
BytebuddyAgent [candidate] (846.985 ms) : 0, 846985
GlobalTracer [baseline] (230.172 ms) : 0, 230172
GlobalTracer [candidate] (232.853 ms) : 0, 232853
IAST [baseline] (22.764 ms) : 0, 22764
IAST [candidate] (23.418 ms) : 0, 23418
AppSec [baseline] (56.182 ms) : 0, 56182
AppSec [candidate] (56.372 ms) : 0, 56372
Debugger [baseline] (4.123 ms) : 0, 4123
Debugger [candidate] (4.179 ms) : 0, 4179
Remote Config [baseline] (588.482 µs) : 0, 588
Remote Config [candidate] (607.725 µs) : 0, 608
Telemetry [baseline] (8.684 ms) : 0, 8684
Telemetry [candidate] (8.797 ms) : 0, 8797
section profiling
BytebuddyAgent [baseline] (714.074 ms) : 0, 714074
BytebuddyAgent [candidate] (708.957 ms) : 0, 708957
GlobalTracer [baseline] (353.625 ms) : 0, 353625
GlobalTracer [candidate] (349.97 ms) : 0, 349970
AppSec [baseline] (54.898 ms) : 0, 54898
AppSec [candidate] (53.451 ms) : 0, 53451
Debugger [baseline] (4.368 ms) : 0, 4368
Debugger [candidate] (4.254 ms) : 0, 4254
Remote Config [baseline] (713.936 µs) : 0, 714
Remote Config [candidate] (703.543 µs) : 0, 704
Telemetry [baseline] (9.172 ms) : 0, 9172
Telemetry [candidate] (8.926 ms) : 0, 8926
ProfilingAgent [baseline] (103.473 ms) : 0, 103473
ProfilingAgent [candidate] (102.503 ms) : 0, 102503
Profiling [baseline] (103.631 ms) : 0, 103631
Profiling [candidate] (102.53 ms) : 0, 102530
Loading

Load

Parameters

Baseline Candidate
baseline_or_candidate baseline candidate
end_time 2025-03-25T08:35:49 2025-03-25T08:43:36
git_branch master alejandro.gonzalez/APPSEC-57044
git_commit_date 1742825749 1742890817
git_commit_sha 51813bd ab7b08c
release_version 1.48.0-SNAPSHOT~51813bdfcb 1.48.0-SNAPSHOT~ab7b08c058
start_time 2025-03-25T08:35:35 2025-03-25T08:43:22
See matching parameters
Baseline Candidate
application insecure-bank insecure-bank
ci_job_date 1742892615 1742892615
ci_job_id 862832236 862832236
ci_pipeline_id 59860106 59860106
cpu_model Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
kernel_version Linux runner-vapngg-f-project-304-concurrent-0-dugngi4u 6.8.0-1024-aws #26~22.04.1-Ubuntu SMP Wed Feb 19 06:54:57 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux Linux runner-vapngg-f-project-304-concurrent-0-dugngi4u 6.8.0-1024-aws #26~22.04.1-Ubuntu SMP Wed Feb 19 06:54:57 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux
variant iast iast

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 13 metrics, 17 unstable metrics.

Request duration reports for insecure-bank
gantt
    title insecure-bank - request duration [CI 0.99] : candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
    dateFormat X
    axisFormat %s
section baseline
no_agent (387.414 µs) : 367, 408
.   : milestone, 387,
iast (523.618 µs) : 502, 545
.   : milestone, 524,
iast_FULL (737.228 µs) : 715, 759
.   : milestone, 737,
iast_GLOBAL (569.741 µs) : 548, 592
.   : milestone, 570,
iast_HARDCODED_SECRET_DISABLED (513.573 µs) : 492, 535
.   : milestone, 514,
iast_INACTIVE (466.618 µs) : 445, 488
.   : milestone, 467,
iast_TELEMETRY_OFF (508.999 µs) : 487, 531
.   : milestone, 509,
tracing (461.4 µs) : 440, 483
.   : milestone, 461,
section candidate
no_agent (394.125 µs) : 374, 414
.   : milestone, 394,
iast (521.509 µs) : 500, 543
.   : milestone, 522,
iast_FULL (732.422 µs) : 710, 754
.   : milestone, 732,
iast_GLOBAL (564.385 µs) : 542, 587
.   : milestone, 564,
iast_HARDCODED_SECRET_DISABLED (519.527 µs) : 498, 541
.   : milestone, 520,
iast_INACTIVE (471.714 µs) : 449, 494
.   : milestone, 472,
iast_TELEMETRY_OFF (504.235 µs) : 482, 526
.   : milestone, 504,
tracing (462.592 µs) : 442, 483
.   : milestone, 463,
Loading
  • baseline results
Variant Request duration [CI 0.99] Δ no_agent
no_agent 387.414 µs [367.231 µs, 407.596 µs] -
iast 523.618 µs [501.827 µs, 545.408 µs] 136.204 µs (35.2%)
iast_FULL 737.228 µs [715.211 µs, 759.246 µs] 349.815 µs (90.3%)
iast_GLOBAL 569.741 µs [547.535 µs, 591.946 µs] 182.327 µs (47.1%)
iast_HARDCODED_SECRET_DISABLED 513.573 µs [492.083 µs, 535.063 µs] 126.159 µs (32.6%)
iast_INACTIVE 466.618 µs [445.191 µs, 488.046 µs] 79.205 µs (20.4%)
iast_TELEMETRY_OFF 508.999 µs [487.047 µs, 530.951 µs] 121.586 µs (31.4%)
tracing 461.4 µs [440.245 µs, 482.554 µs] 73.986 µs (19.1%)
  • candidate results
Variant Request duration [CI 0.99] Δ no_agent
no_agent 394.125 µs [374.095 µs, 414.156 µs] -
iast 521.509 µs [499.599 µs, 543.42 µs] 127.384 µs (32.3%)
iast_FULL 732.422 µs [710.403 µs, 754.442 µs] 338.297 µs (85.8%)
iast_GLOBAL 564.385 µs [542.193 µs, 586.578 µs] 170.26 µs (43.2%)
iast_HARDCODED_SECRET_DISABLED 519.527 µs [497.774 µs, 541.28 µs] 125.401 µs (31.8%)
iast_INACTIVE 471.714 µs [449.37 µs, 494.058 µs] 77.588 µs (19.7%)
iast_TELEMETRY_OFF 504.235 µs [482.151 µs, 526.318 µs] 110.109 µs (27.9%)
tracing 462.592 µs [442.016 µs, 483.167 µs] 68.466 µs (17.4%)
Request duration reports for petclinic
gantt
    title petclinic - request duration [CI 0.99] : candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
    dateFormat X
    axisFormat %s
section baseline
no_agent (1.373 ms) : 1352, 1393
.   : milestone, 1373,
appsec (1.734 ms) : 1710, 1758
.   : milestone, 1734,
appsec_no_iast (1.739 ms) : 1715, 1762
.   : milestone, 1739,
code_origins (1.688 ms) : 1661, 1716
.   : milestone, 1688,
iast (1.518 ms) : 1493, 1542
.   : milestone, 1518,
profiling (1.577 ms) : 1552, 1602
.   : milestone, 1577,
tracing (1.496 ms) : 1471, 1521
.   : milestone, 1496,
section candidate
no_agent (1.37 ms) : 1351, 1390
.   : milestone, 1370,
appsec (1.747 ms) : 1723, 1770
.   : milestone, 1747,
appsec_no_iast (1.742 ms) : 1719, 1765
.   : milestone, 1742,
code_origins (1.67 ms) : 1642, 1697
.   : milestone, 1670,
iast (1.516 ms) : 1491, 1541
.   : milestone, 1516,
profiling (1.529 ms) : 1504, 1555
.   : milestone, 1529,
tracing (1.511 ms) : 1486, 1535
.   : milestone, 1511,
Loading
  • baseline results
Variant Request duration [CI 0.99] Δ no_agent
no_agent 1.373 ms [1.352 ms, 1.393 ms] -
appsec 1.734 ms [1.71 ms, 1.758 ms] 361.507 µs (26.3%)
appsec_no_iast 1.739 ms [1.715 ms, 1.762 ms] 365.914 µs (26.7%)
code_origins 1.688 ms [1.661 ms, 1.716 ms] 315.889 µs (23.0%)
iast 1.518 ms [1.493 ms, 1.542 ms] 145.305 µs (10.6%)
profiling 1.577 ms [1.552 ms, 1.602 ms] 204.724 µs (14.9%)
tracing 1.496 ms [1.471 ms, 1.521 ms] 123.77 µs (9.0%)
  • candidate results
Variant Request duration [CI 0.99] Δ no_agent
no_agent 1.37 ms [1.351 ms, 1.39 ms] -
appsec 1.747 ms [1.723 ms, 1.77 ms] 376.322 µs (27.5%)
appsec_no_iast 1.742 ms [1.719 ms, 1.765 ms] 371.872 µs (27.1%)
code_origins 1.67 ms [1.642 ms, 1.697 ms] 299.548 µs (21.9%)
iast 1.516 ms [1.491 ms, 1.541 ms] 145.847 µs (10.6%)
profiling 1.529 ms [1.504 ms, 1.555 ms] 159.282 µs (11.6%)
tracing 1.511 ms [1.486 ms, 1.535 ms] 140.479 µs (10.3%)

Dacapo

Parameters

Baseline Candidate
baseline_or_candidate baseline candidate
git_branch master alejandro.gonzalez/APPSEC-57044
git_commit_date 1742825749 1742890817
git_commit_sha 51813bd ab7b08c
release_version 1.48.0-SNAPSHOT~51813bdfcb 1.48.0-SNAPSHOT~ab7b08c058
See matching parameters
Baseline Candidate
application biojava biojava
ci_job_date 1742893183 1742893183
ci_job_id 862832237 862832237
ci_pipeline_id 59860106 59860106
cpu_model Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
kernel_version Linux runner-kj59svlh-project-304-concurrent-1-t7nevrbc 6.8.0-1024-aws #26~22.04.1-Ubuntu SMP Wed Feb 19 06:54:57 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux Linux runner-kj59svlh-project-304-concurrent-1-t7nevrbc 6.8.0-1024-aws #26~22.04.1-Ubuntu SMP Wed Feb 19 06:54:57 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux
variant appsec appsec

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 11 metrics, 1 unstable metrics.

Execution time for tomcat
gantt
    title tomcat - execution time [CI 0.99] : candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
    dateFormat X
    axisFormat %s
section baseline
no_agent (1.475 ms) : 1463, 1486
.   : milestone, 1475,
appsec (2.331 ms) : 2288, 2375
.   : milestone, 2331,
iast (2.12 ms) : 2065, 2175
.   : milestone, 2120,
iast_GLOBAL (2.172 ms) : 2116, 2228
.   : milestone, 2172,
profiling (2.439 ms) : 2258, 2621
.   : milestone, 2439,
tracing (1.956 ms) : 1913, 1999
.   : milestone, 1956,
section candidate
no_agent (1.473 ms) : 1461, 1484
.   : milestone, 1473,
appsec (2.351 ms) : 2307, 2395
.   : milestone, 2351,
iast (2.123 ms) : 2068, 2179
.   : milestone, 2123,
iast_GLOBAL (2.163 ms) : 2107, 2219
.   : milestone, 2163,
profiling (1.968 ms) : 1924, 2012
.   : milestone, 1968,
tracing (1.952 ms) : 1910, 1995
.   : milestone, 1952,
Loading
  • baseline results
Variant Execution Time [CI 0.99] Δ no_agent
no_agent 1.475 ms [1.463 ms, 1.486 ms] -
appsec 2.331 ms [2.288 ms, 2.375 ms] 856.53 µs (58.1%)
iast 2.12 ms [2.065 ms, 2.175 ms] 645.233 µs (43.8%)
iast_GLOBAL 2.172 ms [2.116 ms, 2.228 ms] 697.05 µs (47.3%)
profiling 2.439 ms [2.258 ms, 2.621 ms] 964.699 µs (65.4%)
tracing 1.956 ms [1.913 ms, 1.999 ms] 481.151 µs (32.6%)
  • candidate results
Variant Execution Time [CI 0.99] Δ no_agent
no_agent 1.473 ms [1.461 ms, 1.484 ms] -
appsec 2.351 ms [2.307 ms, 2.395 ms] 878.539 µs (59.6%)
iast 2.123 ms [2.068 ms, 2.179 ms] 650.611 µs (44.2%)
iast_GLOBAL 2.163 ms [2.107 ms, 2.219 ms] 690.102 µs (46.9%)
profiling 1.968 ms [1.924 ms, 2.012 ms] 494.801 µs (33.6%)
tracing 1.952 ms [1.91 ms, 1.995 ms] 479.423 µs (32.6%)
Execution time for biojava
gantt
    title biojava - execution time [CI 0.99] : candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
    dateFormat X
    axisFormat %s
section baseline
no_agent (14.835 s) : 14835000, 14835000
.   : milestone, 14835000,
appsec (15.096 s) : 15096000, 15096000
.   : milestone, 15096000,
iast (19.106 s) : 19106000, 19106000
.   : milestone, 19106000,
iast_GLOBAL (18.107 s) : 18107000, 18107000
.   : milestone, 18107000,
profiling (15.145 s) : 15145000, 15145000
.   : milestone, 15145000,
tracing (15.086 s) : 15086000, 15086000
.   : milestone, 15086000,
section candidate
no_agent (15.597 s) : 15597000, 15597000
.   : milestone, 15597000,
appsec (15.379 s) : 15379000, 15379000
.   : milestone, 15379000,
iast (19.126 s) : 19126000, 19126000
.   : milestone, 19126000,
iast_GLOBAL (17.671 s) : 17671000, 17671000
.   : milestone, 17671000,
profiling (15.038 s) : 15038000, 15038000
.   : milestone, 15038000,
tracing (15.136 s) : 15136000, 15136000
.   : milestone, 15136000,
Loading
  • baseline results
Variant Execution Time [CI 0.99] Δ no_agent
no_agent 14.835 s [14.835 s, 14.835 s] -
appsec 15.096 s [15.096 s, 15.096 s] 261.0 ms (1.8%)
iast 19.106 s [19.106 s, 19.106 s] 4.271 s (28.8%)
iast_GLOBAL 18.107 s [18.107 s, 18.107 s] 3.272 s (22.1%)
profiling 15.145 s [15.145 s, 15.145 s] 310.0 ms (2.1%)
tracing 15.086 s [15.086 s, 15.086 s] 251.0 ms (1.7%)
  • candidate results
Variant Execution Time [CI 0.99] Δ no_agent
no_agent 15.597 s [15.597 s, 15.597 s] -
appsec 15.379 s [15.379 s, 15.379 s] -218.0 ms (-1.4%)
iast 19.126 s [19.126 s, 19.126 s] 3.529 s (22.6%)
iast_GLOBAL 17.671 s [17.671 s, 17.671 s] 2.074 s (13.3%)
profiling 15.038 s [15.038 s, 15.038 s] -559.0 ms (-3.6%)
tracing 15.136 s [15.136 s, 15.136 s] -461.0 ms (-3.0%)

@jandro996 jandro996 added this to the 1.48.0 milestone Mar 25, 2025
@jandro996 jandro996 merged commit eb44168 into master Mar 25, 2025
267 of 269 checks passed
@jandro996 jandro996 deleted the alejandro.gonzalez/APPSEC-57044 branch March 25, 2025 11:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
comp: asm iast Application Security Management (IAST) type: enhancement
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants