Home > Software Quality News > Parasoft enhances its Application Security Solution
Software Quality News:
EMAIL THIS

Parasoft enhances its Application Security Solution

By Michelle Davidson, Editor in Chief
16 Jul 2008 | SearchSoftwareQuality.com

Software quality news and advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Parasoft Corp., a provider of solutions and services that deliver quality as a continuous process throughout the Software Development Lifecycle (SDLC), has enhanced its Application Security Solution to help companies identify run-time security vulnerabilities and monitor security policy compliance.

What we've done with this release is combine our security analysis with our data analysis engine. So we have a real end-to-end security analysis solution.
Matt Love
Application security architect, Parasoft Corp.

With this enhancement, Parasoft is leveraging data flow analysis with knowledge of security artifacts to show end-to-end how a hacker's tainted data could infect code, said Matt Love, an application security architect at Parasoft.

"Originally it was a quality tool, because it could do things like identify points in code where null points were assigned and how it might flow," Love said. "What we've done with this release is combine our security analysis with our data analysis engine. So we have a real end-to-end security analysis solution that will start at a point where a hacker might enter tainted data and trace the flow of the data and show how it goes from one file to another and bypass any validation -- and might be passed to a database."

A significant part of the automated solution runs on the server. Vulnerabilities uncovered include SQL injection, cross-site scripting (XSS), and data exposure.

The latest enhancements not only draw upon a knowledge base of common attack patterns, but they also enable organizations to map the data flow logic to their own security policy. And based on the policy that's running, tasks are pushed to the developers' desktops.

"The developer is not fumbling around with an analysis tool. They're working through the prioritized issues that land in their task list. This combination gives them the ability to correct the defects," said Wayne Ariola, vice president of corporate development at Parasoft.

By showing developers how tainted data can flow through an application, it's easier to persuade developers to fix their code, Love added.

More information on application security tools
HP software security suite treats vulnerabilities as defects

Cenzic Web application security tool targets CSRF attacks

Developers get bigger role in software quality, security

"People are hesitant to fix code because think it isn't their responsibility. We can prove that it can get from point A to point B without validation. We can show how it can slip through that hole," he said.

Ariola said this is more than just bug-finding exercises. "It really fits into the policy-based approach," he said.

Neil MacDonald, vice president and Gartner Fellow, said security should be an integral part of the SDLC, not an afterthought.

"The notion of application 'quality' which has traditionally focused on functionality and performance must be expanded to include security," he said in a prepared statement. "Native integration of security testing capabilities into the SDLC environment will increase the likelihood of acceptance by the development organization."

For more information about Parasoft's Application Security Solution, visit Parasoft's Web site.



Tags: Software security testing toolsAutomated software testingWeb application security tools and servicesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Software security testing tools
Commonly-overlooked security flaws in rich Internet applications
10 steps to acing Web app security assessments
New tools target software QA, testing: Spring roundup
Hack maliciously to boost your software's security
What is fuzz testing? What are some ways to use fuzz testing?
Why the quality assurance department should be involved in testing
Using the Firefox Web Developer extension to find security flaws
Top tools for testing Web application security
Static analysis tool helps software engineers find bugs during builds
Web security: Web services an overlooked entry point for attacks

Automated software testing
Exploring mobile layout testing, emulators and goals
Liz Andrews, Marketing Manager, Altova
What are the top free and not-free automated test tools?
Creating strong QA and testing strategies in a changing world
Six software test planning tips for better QA testing ROI
Evaluating the benefits of automated software testing
Testers: Time to gear up for mobile software testing
How to choose the best software test automation tool for your team
When to use manual vs. automated software testing tools
Open source QA tool for automated Web application testing

Web application security tools and services
Static analysis tool helps software engineers find bugs during builds
Automated security tool finds flaws in enterprise apps
Cenzic Web application security tool targets CSRF attacks
Ruby on Rails security audit service available
Secure software measures: Their strengths and limitations
HP software security suite treats vulnerabilities as defects
Dynamic analysis tool from Coverity looks at concurrency defects
Veracode provides security audits for externally sourced code
Enhanced application protection in Dotfuscator Professional 4.3
BMC uses source code analysis to improve software line

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
penetration testing  (SearchSoftwareQuality.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Software Development Methods - Extreme Programming, Agile Programming, Scrum
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts