Home > Software Quality News > Automated security tool finds flaws in enterprise apps
Software Quality News:
EMAIL THIS

Automated security tool finds flaws in enterprise apps

By SearchSoftwareQuality.com Staff
22 Jul 2008 | SearchSoftwareQuality.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Enhancements to the Ounce source code analysis tool will help companies analyze large enterprise applications quickly for security flaws, according to Ounce Labs.

Ounce 6.0, available in early August, uses an automation server to automatically scan applications, providing prioritization and developer assignments without human intervention and delivering only confirmed vulnerabilities to the developer desktop, said Jack Danahy, CTO and founder of Ounce Labs.

"People want to do various types of triage," he said. "We've received more requests for automated triage."

To satisfy those requests, Ounce 6 includes Developer Triage and Team Triage. Developer Triage enables developers to act quickly on the most serious vulnerabilities, while Team Triage allows team members other than developers to look at the assessment data, make decisions, and merge data back into the system.

Ounce 6 also gives developers the ability to access analytic functions and give security analysts developer capabilities in the analyst framework.

"What we found out is sometimes the person doing triage is also the lead developer and would like to see the analyst functionality in the developer world. And we have security analysts who want developer tools," Danahy said. "The suite is much more flexible for the individual role players who want to take advantage of it."

For more information about Ounce 6, visit Ounce Labs' Web site.



Tags: Software security testing toolsWeb application security tools and servicesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Software security testing tools
How to make your software tamperproof
How can I tell if my software security has been breached?
Lesser-known free software testing tools testers should try
Demo: Using WebGoat, a free software testing tool
Rich Internet applications security testing checklist
Finding cross-site scripting (XSS) application flaws checklist
Webgoat Tutorial
Retaking command of your hacked software
Identifying whether or not your site or software has been hacked
Selecting the best tool for stress and load testing

Web application security tools and services
Static analysis tool helps software engineers find bugs during builds
Parasoft enhances its Application Security Solution
Cenzic Web application security tool targets CSRF attacks
Ruby on Rails security audit service available
Secure software measures: Their strengths and limitations
HP software security suite treats vulnerabilities as defects
Dynamic analysis tool from Coverity looks at concurrency defects
Veracode provides security audits for externally sourced code
Enhanced application protection in Dotfuscator Professional 4.3
BMC uses source code analysis to improve software line

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
penetration testing  (SearchSoftwareQuality.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Software Development Methods - Extreme Programming, Agile Programming, Scrum
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts