JKI Security Suite 3.1: Stronger Analysis and Better Usability
As cybersecurity requirements continue to expand across the defense, aerospace, and critical infrastructure sectors, engineering teams face increasing pressure to validate software security and demonstrate compliance with evolving federal standards. While traditional programming languages benefit from mature security analysis tools, graphical programming environments like LabVIEW have historically lacked equivalent capabilities.
JKI Security Suite was built to close that gap. It is a cybersecurity compliance solution designed specifically for LabVIEW applications, helping engineering teams identify security weaknesses early in the development process while supporting compliance with industry and government cybersecurity requirements. JKI Security Suite officially launched at NI Connect in May, marking a major milestone in bringing dedicated security analysis to the LabVIEW community. Since launch, we've been actively collecting feedback from our early access users and prioritizing the capabilities that matter most to them as we shape each new release.
JKI Security Suite enables organizations to:
- Identify weaknesses in LabVIEW code through automated security analysis.
- Align development practices with standards such as NIST SP 800-53, the Cyber Resilience Act (CRA), and NASA NPR 7150.2.
- Reduce the time and effort required for manual security reviews through automation.
- Integrate security analysis into existing CI/CD workflows.
- Strengthen software security throughout the entire development lifecycle.
With the release of JKI Security Suite 3.1, we're continuing our mission of making security analysis more accessible, comprehensive, and easier to integrate into everyday development workflows. This update focuses on four key objectives:
- Expanding CWE coverage through new and enhanced security rules.
- Improving reliability and robustness by addressing reported issues and strengthening tool behavior.
- Enhancing usability with workflow improvements that help developers investigate findings more efficiently.
Expanded CWE Coverage
Expanding security coverage remains a core focus of every JKI Security Suite update. New security rules and enhancements increase coverage across the Common Weakness Enumeration (CWE) standard, helping engineering teams identify a wider range of potential weaknesses in their LabVIEW applications.
This update adds or improves detection for several important CWEs, including:
- CWE-390: Detection of Error Condition Without Action – Identifies situations where an application detects an error condition but does not take appropriate action, helping developers address cases where failures may not be properly handled.
- CWE-457: Use of Uninitialized Variable – Detects cases where variables may be used before being initialized, helping prevent unpredictable behavior and potential software defects.
- CWE-798: Use of Hard-coded Credentials – Enhances detection of insecure hard-coded strings by using the context of surrounding string labels to improve the accuracy of security findings.
The release also introduces deterministic signatures for weaknesses in the JDB file, providing more consistent identification and tracking of security findings.
Together, these enhancements strengthen automated security reviews by identifying issues that might otherwise require manual inspection. As coverage continues to expand, engineering teams gain broader visibility into recognized software weaknesses while supporting compliance efforts with standards such as NIST SP 800-53, the Cyber Resilience Act (CRA), and NASA NPR 7150.2.
Improved Reliability and Robustness
Reliability is essential for any security analysis tool. This update focuses on addressing reported issues, improving error handling, and strengthening the overall stability and behavior of the analysis workflow.
Improvements include better handling of tool errors versus security findings, improved consistency across scans, and fixes for issues affecting analysis reliability. Examples include improved handling of unloadable VIs, more consistent use of root directories between scans, improved recognition of RaceCondition:MultipleWriters bookmarks, and fixes for configuration and reporting-related issues.
These changes provide a more consistent scanning experience across a variety of LabVIEW projects and help reduce interruptions during development. Whether performing manual security reviews or running automated scans as part of a CI/CD pipeline, users benefit from a more dependable foundation for secure software development.
Usability Improvements That Make a Difference
Security analysis should fit naturally into the development workflow. This update introduces usability improvements designed to help developers investigate findings more quickly and resolve issues with less effort.
Notable enhancements include:
- Open VI functionality, allowing developers to jump directly from a security finding to the affected LabVIEW VI.
- Highlight Node, making it easy to identify the exact node associated with a reported issue.
These improvements reduce the time spent navigating large applications and help developers move from identifying a security finding to understanding and addressing it more efficiently.
Why This Release Matters
Cybersecurity is no longer something addressed only during final testing or certification. Organizations are increasingly expected to build security into every phase of the software development lifecycle, especially when developing systems for regulated industries.
By expanding automated security checks, improving analysis coverage, and making findings easier to investigate, JKI Security Suite helps engineering teams spend less time on manual reviews and more time building secure software. Whether developing applications for defense, aerospace, research, or industrial systems, teams can identify security issues earlier, improve code quality, and support compliance throughout development.
Building More Secure LabVIEW Applications
This release represents another step toward making cybersecurity analysis for LabVIEW applications more practical, comprehensive, and developer-friendly. By improving distribution, expanding CWE coverage, strengthening reliability, and refining the user experience, JKI Security Suite helps engineering teams build more secure software while supporting compliance with today's evolving cybersecurity standards.
As cybersecurity expectations continue to grow, we'll continue investing in new security rules, workflow enhancements, and capabilities driven by customer feedback and emerging industry requirements.
Ready to explore the latest improvements? Contact the JKI team to learn how JKI Security Suite can help strengthen the security of your LabVIEW applications and support your organization's compliance goals.
Enjoyed the article? Leave us a comment