The Web applications vulnerability testing market is about to get a little more crowded, as both Core Security and Qualys are entering the space with strategies to integrate the tools into their existing products and services.
On Tuesday, Core announced that it has added Web applications penetration testing to the latest version of Impact, its automated network and internal security scanning package.
Executives with Qualys, which markets hosted network vulnerability testing services, confirmed to InfoWorld that the company plans to begin offering its own Web applications scanning capabilities sometime during the first quarter of 2008.
In both cases, company leaders cited strong synergies with their existing business models and recent industry consolidation as drivers for jumping into the Web applications security segment.
Earlier this year, two of the largest players in the niche, Watchfire and SPI Dynamics, were acquired by IBM and HP, respectively.
And while both Watchfire and SPI continue to market their Web applications scanning technologies as their new parents integrate the tools into their larger software development platforms, executives with Core and Qualys contend that they have an opportunity to cash in on pent-up demand.
In Core Impact version 7.5, the company has added the ability for customers to search for security holes in Web applications and servers, and any databases sitting behind those systems, via SQL injection and remote file inclusion attack techniques.
The company said the new functions will be tightly integrated with the product's traditional features, which are used to probe for weaknesses in customers' external network defenses or internal employee security practices and launch proof-of-concept attacks that demonstrate how network or user-based vulnerabilities might be exploited by real attackers.
Extending Impact's ability to include Web applications testing is a natural fit for number of reasons, said Core Chief Executive Paul Paget.
"When we talk to customers today, they understand the process of crawling sites and fuzzing applications for weaknesses. But we can also give them the ability to auto-generate SQL injections and remote inclusion injections on the fly," said Paget. "The capability to create an exploit as we're carrying out penetration testing is a huge differentiator compared to what is out there. Once we compromise a server, we can plant our agent in the system and go deeper inside the network to illustrate just what real attackers would do."
Qualys CEO Philippe Courtot said his company's move into Web applications testing is a similarly natural evolution, both in terms of blending the capabilities into the vendor's existing network vulnerability scanning tools and in delivering the tests via its hosted software-as-a-service (SaaS) delivery model.
While IBM and HP are integrating their newly acquired vulnerability scanning technologies into their respective software platforms -- and thereby pushing developers to carry out additional testing before moving applications into production -- Courtot contends that the network security professionals already using Qualys' vulnerability testing services are actively looking for more tools to scan Web-based programs.
Get the independent advice and expertise you need to support a virtual workforce.
The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.
Download now »Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.
Download now »A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »