October 16, 2007

Core, Qualys to enter Web apps scanning market

Core Security and Qualys say their entrance into the Web apps vulnerability testing market is a natural evolution of their products, expertise

The Web applications vulnerability testing market is about to get a little more crowded, as both Core Security and Qualys are entering the space with strategies to integrate the tools into their existing products and services.

On Tuesday, Core announced that it has added Web applications penetration testing to the latest version of Impact, its automated network and internal security scanning package.

Executives with Qualys, which markets hosted network vulnerability testing services, confirmed to InfoWorld that the company plans to begin offering its own Web applications scanning capabilities sometime during the first quarter of 2008.

In both cases, company leaders cited strong synergies with their existing business models and recent industry consolidation as drivers for jumping into the Web applications security segment.

Earlier this year, two of the largest players in the niche, Watchfire and SPI Dynamics, were acquired by IBM and HP, respectively.

And while both Watchfire and SPI continue to market their Web applications scanning technologies as their new parents integrate the tools into their larger software development platforms, executives with Core and Qualys contend that they have an opportunity to cash in on pent-up demand.

In Core Impact version 7.5, the company has added the ability for customers to search for security holes in Web applications and servers, and any databases sitting behind those systems, via SQL injection and remote file inclusion attack techniques.

The company said the new functions will be tightly integrated with the product's traditional features, which are used to probe for weaknesses in customers' external network defenses or internal employee security practices and launch proof-of-concept attacks that demonstrate how network or user-based vulnerabilities might be exploited by real attackers.

Extending Impact's ability to include Web applications testing is a natural fit for number of reasons, said Core Chief Executive Paul Paget.

"When we talk to customers today, they understand the process of crawling sites and fuzzing applications for weaknesses. But we can also give them the ability to auto-generate SQL injections and remote inclusion injections on the fly," said Paget. "The capability to create an exploit as we're carrying out penetration testing is a huge differentiator compared to what is out there. Once we compromise a server, we can plant our agent in the system and go deeper inside the network to illustrate just what real attackers would do."

Qualys CEO Philippe Courtot said his company's move into Web applications testing is a similarly natural evolution, both in terms of blending the capabilities into the vendor's existing network vulnerability scanning tools and in delivering the tests via its hosted software-as-a-service (SaaS) delivery model.

While IBM and HP are integrating their newly acquired vulnerability scanning technologies into their respective software platforms -- and thereby pushing developers to carry out additional testing before moving applications into production -- Courtot contends that the network security professionals already using Qualys' vulnerability testing services are actively looking for more tools to scan Web-based programs.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

additional resources
White Paper - How to Improve Delivery of Advanced Web Applications

White Paper

Virtual Workforce: The Key to Expanding The Business While Cutting Costs

Get the independent advice and expertise you need to support a virtual workforce.

Go inside:
The three-step approach to making a virtual workforce a reality.
The four flavors of client virtualization technologies.
The three key initiatives that solve IT challenges.
Download now »
White Paper: Successfully Secure Your Wireless LAN With Wi-Fi firewalls.

White Paper

Addressing Linux Threats Leveraging Fewer Resources

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now »
White Paper - The 2009 Handbook of Application Delivery

White Paper

The 2009 Handbook of Application Delivery

Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.

Download now »
White Paper - Is Your Backup System Outdated?

White Paper

Mid-range Storage Considerations

A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2010 Infoworld, Inc.