- BlackBerry Storm vs. the iPhone
- Digg's Kevin Rose: "We have to do better"
- Blogger warns: "Nortel doesn't make it out alive"
- Financial quagmire bringing out the scammers
- Verizon plays with the wrong e-mail addresses
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:Application Performance Solutions | App Performance | Networking Solution | SafeGuard Enterprise Solution Center | SOA | Test your Web Filter | Value of WDS
Fortify Software has a new tool for figuring out how well Web applications have been tested for vulnerabilities with the idea of making the applications safer.
Called Fortify Tracer, the product figures out what lines of code make an application vulnerable so the customer can patch it.
Tracer works in conjunction with automated application testers called black boxes that simulate attacks on points that take in data. WatchFire's AppScan is one such black box product, and Fortify has a partnership with WatchFire. If a black box discovers vulnerabilities, customers can take steps to patch them.
The problem with black boxes is there is no way to measure how thoroughly they do their job. So Tracer positions software sensors around all the possible points of attack in an application and records whether each has been probed by the black box.
If Tracer finds, for example, that a black box security test tried only 20% of the attack points, a business would want to improve the test. At the same time, if the black box discovers flaws, Tracer pinpoints the lines of code involved in the vulnerability.
"This gives us insights into what's happening in an application when we're doing a limited test," says Brian Holyfield, co-founder of Gotham Digital Science, a consultancy in New York City that tests application security for businesses.
Holyfield says Tracer can be used to satisfy his customers as well. "It validates you've done a comprehensive test because it documents the results," he says.
Tracer works on any Web application.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment