Home > Software Quality All-in-One Guides > Web application security -- How to prevent attacks > Web application security tools and services > Veracode provides security audits for externally sourced code
All-in-One Guides: Web application security -- How to prevent attacks:
EMAIL THIS
 START   TYPES OF ATTACKS   SECURITY REQUIREMENTS   DEVELOPER TECHNIQUES   TESTER TECHNIQUES   TOOLS & TECHNIQUES   
Web application security tools and services

<< PREVIOUS | NEXT >>: Enhanced application protection in Dotfuscator...

Veracode provides security audits for externally sourced code

By Michelle Davidson, Site Editor
23 Apr 2008 | SearchSoftwareQuality.com

Software quality news and advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

If your company hires third parties to develop code or uses commercial off-the-shelf software (COTS), it can be difficult to ensure that the code is secure. Veracode hopes to facilitate that task with its SecurityReview, an automated, subscription-based auditing service.

More information on application security testing
Web application security testing basics

Free Web application security testing tools you need to get to know

Learning Guide: Application security testing techniques

"For the first time enterprises have the ability to test applications from any external source," said Bernd Leger, vice president of marketing at Veracode. "The reason why we can do this comes from our ability to test the binaries. We can tell them how secure the code is."

The challenge companies have faced is that it has been hard for them to tackle all the code that comes from different development teams, from outside the organization and from COTS, Leger said.

"Enterprises haven't had a way to evaluate the risks," he said. "They've done one of two things -- surveyed the vendors or had checklists for them, which means you're relying on them to tell you the truth, and manual penetration tests, which are too expensive and time-consuming."

And to test the code themselves, enterprises would have to ask for all of the code, Leger added. However, software makers won't give them the source code. When they do, testing that code is a large, time-consuming task, he said.

Aside from testing the code themselves, companies would have to rely on the software providers and third-party developers to test the code. But then testing is out of your control and you're relying on them to do it properly, Leger said.

Meets a need
Now companies have the option to use Veracode's SecurityReview on-demand service to review and test such code. Veracode uses static binary testing technology and dynamic Web scanning analysis to test the software. Companies simply contact Veracode, and "we take the work off their plate," Leger said.

"We're basically doing a security audit. The code is uploaded to our portal and we test it," he continued.

Leger further said that any information found during the tests is shared with the COTS vendors to help them improve their software.

"We never scan or test without permission from the companies. They need to opt in," he said. "And they're interested because they see the service we're providing."

Diana Kelley, partner at SecurityCurve, sees a need for this type of service. "Enterprises need effective ways to test and audit the risk associated with COTS and outsourced software when source code isn't available," she said.

The Veracode SecurityReview service portfolio, available now, comprises the following on-demand services:

  • Outsourcing SecurityReview -- Provides simple, cost-effective and automated security audits that ensure enterprises receive secure code from offshore development partners.
  • COTS SecurityReview -- Helps enterprises and government agencies quantify and manage the security risks of COTS.
  • SDLC SecurityReview -- Enables security teams to conduct security assessments on mission-critical internally developed applications before they ship.
  • PCI SecurityReview -- Automates and shortens the process for achieving compliance with the application security requirements of PCI-DSS, Visa PABP and PA-DSS.

"[With this service] enterprises can now make decisions around what outsourced vendor they should use, should they keep development in-house, etc.," Leger said.



Tags: Software security testing toolsWeb application security tools and servicesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


<< PREVIOUS | NEXT >>: Enhanced application protection in Dotfuscator...
VIEW ALL IN THIS CATEGORY


RELATED CONTENT
Software security testing tools
Why you don't need to buy a testing tool, except when you do
Old problems persist in Web 2.0 security practices
Beating software's cross-site scripting, authentication problems
Application security checklist: Finding, eliminating SQL injection flaws
Free tools for Agile testers
Put a stop to software espionage by watermarking source code
How to make your software tamperproof
How can I tell if my software security has been breached?
WebGoat: password weakness issues, basic application hacking concerns
Lesser-known free software testing tools testers should try

Web application security tools and services
Static analysis tool helps software engineers find bugs during builds
Automated security tool finds flaws in enterprise apps
Parasoft enhances its Application Security Solution
Cenzic Web application security tool targets CSRF attacks
Ruby on Rails security audit service available
Secure software measures: Their strengths and limitations
HP software security suite treats vulnerabilities as defects
Dynamic analysis tool from Coverity looks at concurrency defects
Enhanced application protection in Dotfuscator Professional 4.3
BMC uses source code analysis to improve software line

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
penetration testing  (SearchSoftwareQuality.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Software Development Methods - Extreme Programming, Agile Programming, Scrum
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts