Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Veracode debuts system to test binary code

Standards-based method would allow enterprises to scan programs' binary code for problems before they are put into production


By allowing such ISVs and internal software development shops to assess where they may have problems earlier in the design process, or before applications have been installed, Veracode can dramatically cut the amount of time and effort necessary to find and fix subsequent security problems, he said.

The Software Security Ratings Service promises to chart both the severity and potential exploitability of any flaws it locates in a particular program, along with the types of business information which could be exposed by an attack on the applications being tested.

"This isn't necessarily a development problem as people have been making it out to be; secure coders simply don't grow on trees, and developers have not been trained in the security testing process," Moynahan said. "This also helps tackle the development outsourcing problem when it comes to security, instead of forcing companies to reconsider the approach altogether based on fears of insecure code."

One roadblock that has made it difficult for such an independent software rating system to have been developed in the past is that companies have been reluctant to release their source code to outsiders for testing, mainly out of fear of handing over their most valuable intellectual property to others, the CEO said.

Since the ratings system is delivered via a software-as-a-service (SaaS) model whereby users aren't forced to distribute their code externally for testing, Moynahan expects that more development shops will be open to testing their code in such a manner.

Beyond the ratings service, Veracode similarly offers its flagship SecurityReview application -- which promises to automate applications security auditing -- as an on-demand subscription service.

In the last month alone, two of the best-known providers of source code and Web applications security testing, Watchfire and SPI Dynamics, have been acquired by IBM and HP respectively, illustrating a major push among providers of software development tools to further integrate security monitoring features into their products.

While those acquisitions should prove useful in helping businesses improve the security of their applications development process, at least one expert said that technologies provided by companies such as Veracode -- those that can look directly at binary code for vulnerabilities -- could see increased demand as developers seek even more tools for driving mistakes and incompatibilities out of their programs.

"Developers should be trying to find all possible ways to break their applications, not just looking at source code for mistakes; they need to have a more hacker-like mentality, and to do that you have to test throughout the whole development process," said Joseph Feiman, analyst with Gartner, based in Stamford, Conn.

"To that end, no one today is testing binary code, which could be a significant benefit to improving security, so there will be a growing market for those tools that can handle that type of work," Feiman said. "Especially with the rise of SOA, and with people buying packages and services that offer them no access to the source code, we should see growth in this evolving market for binary testing tools."

Matt Hines is a senior writer at InfoWorld.
« PREVIOUS PAGE | 1 | 2 


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





Application Grid: Oracle's Vision for Next-Generation Application Servers and Infrastructure
View this live Webcast to hear senior Oracle executives Hasan Rizvi and Steve Harris discuss the application grid. Learn how Oracle is combining cutting-edge technologies from its recent acquisition of BEA with the Fusion Middleware portfolio. Discover a new level of reliability, performance, and "scale-agility" in your data center, with emphasis on efficiency for today's challenging economic environment. Sponsored by Oracle

»  Click here to view this Webcast
  Virtualization Solutions Guide
This comprehensive IT Strategy Guide covers Virtualization and puts you at the forefront of the discussion. You'll learn all you need to know from the cost of virtualization, how to implement it for your business, how to back it up safely and which products are best. Sponsored by Riverbed

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 09/05/2008

Sun to craft software stack into NAS appliances, former CA CEO Sanjay...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist