Automated security tool finds flaws in enterprise apps

Article

Automated security tool finds flaws in enterprise apps

SearchSoftwareQuality.com Staff

Enhancements to the Ounce source code analysis tool will help companies analyze large enterprise applications quickly for security flaws, according to Ounce Labs.

Ounce 6.0, available in early August, uses an automation server to automatically scan applications, providing prioritization and developer assignments without human intervention and delivering only confirmed vulnerabilities to the developer desktop, said Jack Danahy, CTO and founder of Ounce Labs.

"People want to do various types of triage," he said. "We've received more requests for automated triage."

To satisfy those requests, Ounce 6 includes Developer Triage and Team Triage. Developer Triage enables developers to act quickly on the most serious vulnerabilities, while Team Triage allows team members other than developers to look at the assessment data, make decisions, and merge data back into the system.

Ounce 6 also gives developers the ability to access analytic functions and give security analysts developer capabilities in the analyst framework.

"What we found out is sometimes the person doing triage is also the lead developer and would like to see the analyst functionality in the developer world. And we have security analysts who want developer tools," Danahy said. "The suite is much more flexible for the individual role players who want to take advantage of it."

For more information about Ounce 6, visit

    Requires Free Membership to View

    When you register, you'll receive targeted emails designed to keep you informed of the most relevant information on Agile development, application security, testing & QA, software requirements, and more.

    Hannah Smalltree, Editorial Director

    By submitting your registration information to SearchSoftwareQuality.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSoftwareQuality.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Ounce Labs' Web site.