October 29, 2009

Checkmarx touts innovation in secure coding

Virtual Compiler scans code in real time, providing capabilities for fixing flaws at the earliest stages of development

Checkmarx announced technology this week that the company describes as an innovation in secure coding.

The Checkmarx Virtual Compiler lets source code be scanned in real time without using a compiler, giving developers, auditors, and security professionals capabilities for secure coding and fixing flaws at the earliest stages of development, the company said.

[ Microsoft also has focused on security for application development. | Keep up with app dev issues and trends with InfoWorld's Fatal Exception blog. ]

Most security issues can be traced to code vulnerabilities, Checkmarx said. Static code analysis tools have been used to fight software vulnerabilities but they require that a project be almost completed before scanning can take place, according to the company. This makes security repairs to code costly and nullifies the benefits of static analysis.

Checkmarx Virtual Compiler lets developers scan un-built code so static analysis can be performed earlier in the development lifecycle, Checkmarx said. Security auditors, meanwhile, can conduct audits any time on the code base without having to emulate a developer's environment.

"The Checkmarx Virtual Compiler means developers can finally fix code on the assembly line instead of having to wait until the software is almost out the door," said Checkmarx CTO and founder Maty Siman in a statement released by the company.

Usable in any stage of development, the product supports Linux, Windows and Solaris and languages such as Java, C/C++ and Salesforce.com Apex. Checkmarx is offering a free trial of its code analysis, accessible.

This story, "Checkmarx touts innovation in secure coding," was originally published at InfoWorld.com. Follow the latest in developer trends at InfoWorld.com.

Read more about developer world in InfoWorld's Developer World Channel.

Paul Krill is an editor at large at InfoWorld.
Close

On Twitter now

Application development

Powered by Twitter
additional resources
White Paper - How to Improve Delivery of Advanced Web Applications

White Paper

Virtual Workforce: The Key to Expanding The Business While Cutting Costs

Get the independent advice and expertise you need to support a virtual workforce.

Go inside:
The three-step approach to making a virtual workforce a reality.
The four flavors of client virtualization technologies.
The three key initiatives that solve IT challenges.
Download now »
White Paper: Successfully Secure Your Wireless LAN With Wi-Fi firewalls.

White Paper

Addressing Linux Threats Leveraging Fewer Resources

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now »
White Paper - The 2009 Handbook of Application Delivery

White Paper

The 2009 Handbook of Application Delivery

Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.

Download now »
White Paper - Is Your Backup System Outdated?

White Paper

Mid-range Storage Considerations

A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.

Download now »

Sign up to receive InfoWorld Resource Alerts

Subscribe to the Developer World Newsletter

Receive a weekly roundup about the art and science of software development.

©1994-2010 Infoworld, Inc.