Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Fortify Software measures success of apps-testing black boxes

Tracer pinpoints flaws and counts the thoroughness of application testing.
By Tim Greene , NetworkWorld.com , 11/02/2006
  • Share/Email
  • Comment
  • Print

Fortify Software has a new tool for figuring out how well Web applications have been tested for vulnerabilities with the idea of making the applications safer.

Called Fortify Tracer, the product figures out what lines of code make an application vulnerable so the customer can patch it.

Tracer works in conjunction with automated application testers called black boxes that simulate attacks on points that take in data. WatchFire's AppScan is one such black box product, and Fortify has a partnership with WatchFire. If a black box discovers vulnerabilities, customers can take steps to patch them.

The problem with black boxes is there is no way to measure how thoroughly they do their job. So Tracer positions software sensors around all the possible points of attack in an application and records whether each has been probed by the black box.

If Tracer finds, for example, that a black box security test tried only 20% of the attack points, a business would want to improve the test. At the same time, if the black box discovers flaws, Tracer pinpoints the lines of code involved in the vulnerability.

"This gives us insights into what's happening in an application when we're doing a limited test," says Brian Holyfield, co-founder of Gotham Digital Science, a consultancy in New York City that tests application security for businesses.

Holyfield says Tracer can be used to satisfy his customers as well. "It validates you've done a comprehensive test because it documents the results," he says.

Tracer works on any Web application.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.