2008 InfoWorld CTO 25: Chris Wysopal, Veracode
An obsession with software security forms the basis for a new model to assessing apps' safety
Chris Wysopal's obsession with software security has brought him fame as a member of the L0pht hacker "think tank," led to stints as lead security researcher at @stake and director of development at Symantec, and helped produce the Organization for Internet Safety, which was founded on guidelines for the responsible disclosure of software security vulnerabilities developed by Wysopal and MITRE's Steve Christey.
![]() |
[ Discover what insights you can take advantage of from the other 2008 InfoWorld CTO 25 winners. ]
Wysopal started Veracode with fellow L0pht and @stake alum Christien Rioux, who serves as Veracode's chief scientist. The company's application security analyzer is based on work begun by Wysopal and Rioux at @stake on automating security testing, as well as efforts on binary code analysis that Wysopal spearheaded at Symantec. Veracode has produced an offering that differs from other static security analyzers in two important respects. First, it analyzes the application binary, not the source code, allowing security testing to be done as part of the development process or even when source code is not provided or available. Second, it's provided as outsourced service: customers send Veracode the binary, then Veracode sends back a report.
So far, Veracode serves primarily software vendors and financial services companies that both build and buy software. Because Veracode is gaining visibility into code being written by hundreds of development groups across the globe, it's in a position to measure the quality of an application against others of the same type. A financial services company outsourcing a Web app to India, for example, could learn from Veracode how the quality of the product it's getting compares to similar Web apps outsourced to India or elsewhere. Wysopal hopes to gather enough of this data to eventually issue quarterly or annual reports on the state of the software industry.
In the meantime, Wysopal is counting on the magic formula of binary analysis, automated security ratings, and SaaS (software as a service) to make Veracode the Moody's of the software industry. "The thing that makes Veracode truly special is the fact that we can do the security analysis of an application as a trusted third party," Wysopal notes. "It's not so much that Veracode has incrementally more accurate analysis results than a source code analysis-type tool; it's that we have created a model where software security testing is workable for the whole software vendor-purchaser ecosystem."
-

- COMMENTS
Technology White Papers
- An AT&T White Paper: Enterprise IPTV Solution - Discover two components of a solution that allows you to produce and broadcast video to internal and external audiences:...
- HP Architect Planning Tools for MS Office Communications Server 2007 - This user guide provides details on the HP Arch. Planning Tool for OCS 2007: - Detail on various input parameters and ...
- When Content is King: Content Delivery Networks (CDNs) & You - Consumers now expect to see rich media on corporate websites. Learn how and why some businesses are turning to outside vendors...
- HP ProLiant BL480c Server Blade Microsoft Exchange Server 2007 - The Exchange deployments can incorporate different server, storage and application availability features to support tiered...
- Best practices for Microsoft Exchange 2007 with HP Servers - After extensive testing, we present you with configuration and performance data, best practices, and recommendations to ...
- Performance and Scalability on HP ProLiant Multi-Processor Server Blades - This performance brief summarizes scalability testing of Microsof(R) Exchange Server 2007 on HP ProLiant blade servers. ...
-
-
- Technology White Papers
- Technology White Papers E-mail Alert
-
TOP STORIES
ADDITIONAL RESOURCES

- Virtual Machines: Sun's xVM Virtualization Portfolio
- Migrating to Vista
- Turning Information Into A Competitive Advantage

- Speeding Business Innovation with Data Center Transformation
- Security and Trust: The Backbone of Doing Business over the Internet
- Forrester Data Center Automation
- InfoClipz: Unified Communications
-
The concept "presence" and an impending flood of new voice/data applications...
more
- [+] Watch the Video
- SOA Success with Oracle WebLogic Server
-
SOA Success with Oracle WebLogic Server
Sponsored by Oracle
more
- [+] Watch the Video













