Quantcast
Search for: Search what?
Sep 5, 2008  
 Newsletters
Subscribe Free to Product News Alerts
  
Receive customized, daily news on the products you want.
Subscribe   View Sample
 Categories
Industrial Market Trends
OnSite WebReviews
Latest New Product News
Adhesives and Sealants
Agricultural and Farming Products
Architectural and Civil Engineering Products
Automatic ID
Chemical Processing and Waste Management
Cleaning Products and Equipment
Communication Systems and Equipment
Computer Hardware and Peripherals
Construction Equipment and Supplies
Controls and Controllers
Display and Presentation Equipment
Electrical Equipment and Systems
Electronic Components and Devices
Explosives, Armaments and Weaponry
Fasteners and Hardware
Fluid and Gas Flow Equipment
Food Processing and Preparation
Health, Medical and Dental Supplies and Equipment
HVAC
Labels, Tags, Signage and Equipment
Laboratory and Research Supplies and Equipment
Lubricants
Machinery and Machining Tools
Material Handling and Storage
Materials and Material Processing
Mechanical Components and Assemblies
Mechanical Power Transmission
Mining, Oil Drilling & Refining
Mounting and Attaching Products
Non-Industrial Products
Optics and Photonics
Packaging Products & Equipment
Paints and Coatings
Plant Furnishings and Accessories
Portable Tools
Printing and Duplicating Equipment
Retail and Sales Equipment
Robotics
Safety and Security Equipment
Sensors, Monitors and Transducers
Services
Software
Test and Measuring Instruments
Textile Industry Products
Thermal and Heating Equipment
Timers and Clocks
Transportation Industry Products
Vision Systems
Waste Handling Equipment
Welding Equipment and Supplies
Association News
Browse Categories
Browse Companies
 Press Releases
Products in the News
Company News
Mergers & Acquisitions
People in the News
Literature & Websites
 Resources
News Delivery Options
Mobile Edition
PR Resources
Licensing
Advertising
How to Write an effective Press Release
Trade Associations
Small Business Support
MEP


Advertisement

Story Tools
Tools for Registered Users
   Go Back |  Send Story by email E-Mail  |  Print  |  Post   
   Save Story |  Watch_Company  
Archive News Story
(Products mentioned in this Archive News Story may or may not be available from the manufacturer.)


Analysis Tools identify/resolve software security risks.


February 21, 2006 - To ensure application security, Source Code Analysis v3.5 lets users identify, prioritize, and resolve security flaws in software applications before they ship. Solution incorporates Structural Analyzer and runs automated security checks on software code bases to detect over 115 vulnerability categories via Secure Coding Rulepacks. Language support includes .NET languages, and IDE features plug-in support for Eclipse, Visual Studio, and IBM WSAD environments.


Related categories:   Software


Archive Press Release
(Products mentioned in this Archive Press Release may or may not be available from the manufacturer.)


Release date: January 9, 2006


Fortify Announces New Source Code Analysis Tools to Identify and Resolve Software Security Risks


PALO ALTO, Calif., Jan. 9 / -- Fortify Software, Inc. today announced Source Code Analysis 3.5, a powerful advancement in functionality for its award-winning Source Code Analysis suite. Designed to ensure a higher level of application security, the new enhancements improve the ability for software developers and development managers to identify, prioritize and resolve security flaws in software applications before they are shipped or deployed in order to mitigate enterprise security risk.

Fortify Source Code Analysis 3.5 include the following new and expanded components:

-- New Structural Analyzer detects potentially dangerous flaws in the structure or definition of a program.

-- Expanded language support that includes .NET languages such as C#, VB.NET and ASP.NET

-- The addition of over 48 new vulnerability categories that will be referenced by Source Code Analysis

-- Significant enhancements to Integrated Developer Environment (IDE) plug-in support for Eclipse, Visual Studio and IBM WSAD environments

"Fortify Source Code Analysis has been adopted by leading enterprises such as Wells Fargo, eBay, Oracle and Cingular as the premier solution for finding, tracking and fixing security vulnerabilities in software applications," said Barmak Meftah, Vice President of Engineering and Operations, Fortify Software. "Version 3.5 expands our feature set so companies can scale their software security efforts by auditing more code with higher confidence and in less time than they could before."

Fortify's powerful source code analyzers run comprehensive, automated security checks on software code bases to detect over 115 vulnerability categories across popular languages and platforms. In version 3.5, Fortify Source Code Analysis includes a new Structural Analyzer and expansion of its list of supported languages that includes Java, C/C++, XML, PL/SQL, and .Net C# 1.0, to include:

-- .Net 2.0 support for C# 2.0, VB.NET 2.0, ASP.NET 2.0

-- Microsoft T-SQL support

-- Expanded JSP support for BEA Weblogics and IBM Websphere

By understanding the way programs are structured, the new Structural Analyzer identifies vulnerabilities that are often difficult to detect through inspection because they encompass both the declaration and use of variables and functions. For example, the Structural Analyzer detects assignment to member variables in Java servlets, identifies the use of loggers that are not declared "static final", and flags instances of dead code that will never be executed because of a predicate that is always false. This new analyzer joins Fortify's stable of data flow, configuration, semantic and control flow analyzers to provide the most comprehensive and accurate coverage of security vulnerabilities in the industry.

Fortify's Secure Coding Rulepacks now contain thousands of rules in more than 115 vulnerability categories that provides comprehensive coverage of over 35,000 permutations which would be virtually impossible to track manually. The Rulepacks recognize sources of tainted input combined with known unsafe functions, function call sequences and application configurations. Fortify's security experts and partners continually update the rulepacks based on a rich store of security knowledge around common programming practices used in application development.

Version 3.5 also includes significant enhancements to its support for popular IDEs, including Visual Studio 2003 and Visual Studio 2005, Eclipse 3.0 and above, and IBM WSAD 5.0 and 6.0. Now developers can use powerful functionality previously only part of Fortify Audit Workbench to discover and remediate flaws in a familiar environment while they code.

About Fortify Software, Inc.

Fortify Software products protect companies from the threats posed by security flaws in business-critical software applications. Its flagship software security suites, Fortify Source Code Analysis and Fortify Security Tester, drive down costs and security risks by automating key processes of developing secure applications prior to deployment. Fortify Software is backed by leading investors, including Kleiner, Perkins, Caufield & Byers, and a world-class team of software security advisors and partners. More information is available at www.fortifysoftware.com.

CONTACT: Kim Milosevich of OutCast Communications, +1-415-392-8282, or kim@outcastpr.com, for Fortify


Contacts:

Public Relations:
OutCast Communications
Kim Milosevich
USA
Phone: 415-392-8282
Send email  E-mail this person

Company Information:
Name: Fortify Software, Inc
Address: 2215 Bridgepointe Pkwy, Suite 400
City: San Mateo
State: CA
ZIP: 94404
Country: USA
Phone: 650-358-5600
FAX: 650-358-4600
http://www.fortify.com



Story Tools
   Go Back |  Send Story by email E-Mail  |  Print  |  Post   

Click here for copyright permissions!
Copyright 2008 Thomas Publishing Company

Send email Contact company
View Company Profile at ThomasNet.com
company web site Company web site
more company news More news from this company
directory searchSearch for suppliers of:
Debugging Software
directory searchJoin the forum discussion at:
Engineers Lounge

Advertisement
Related Stories:
Aug 29, 2008Telecom Software enables complete NGN testing.
Aug 22, 2008Testing Software is compliant with DMTF management standards.
Aug 20, 2008Debugging Software analyzes HTTP/HTTPS communications.
Aug 20, 2008Software aligns product development with business goals.
Aug 18, 2008Software ensures overall application health.
Jul 29, 2008Software supports LynuxWorks flagship RTOS.
Jul 29, 2008Software monitors applications throughout lifecycle.
Jul 21, 2008Search Appliance optimizes code maintenance.
Jul 10, 2008IDE Software offers advanced run-mode and post-mortem debug.
Jul 7, 2008Source-Code Analysis Software supports Mac OS X.
Jun 25, 2008Debugging Software targets processor driven tests.
Jun 24, 2008Software has visual tools for CEP application development.
Jun 10, 2008Software enables secure remote embedded systems management.
May 22, 2008Software IDs security vulnerability, meets CERT C standard.
May 22, 2008Simulation Software aids wireless communications IC design.
May 12, 2008Dynamic Analysis Software tests multi-threaded applications.
May 5, 2008Software helps increase network productivity.
Apr 25, 2008Software offers HSPA+ test for 3GPP-compliant components.
Apr 18, 2008Software simplifies Linux Kernel profiling.
Apr 11, 2008Development Tool provides on-chip microcontroller debugging.
More New Product News from this company:
Apr 2, 2008Software Suite provides comprehensive software security.
Nov 8, 2006Software optimizes black box security testing efficiency.
Mar 3, 2006Software delivers security testing to QA professionals.
Nov 30, 2004Security Tools help resolve software vulnerabilities.
Other News from this company:
Oct 01, 2007 U.S. Air Force Bolsters itself for Cyber War by Selecting Fortify's Application Security Suite for Worldwide Development Teams
May 14, 2007 Fortify Software Extends Leadership in Detecting the Most Complete Range of Security Vulnerabilities
Mar 19, 2007 Fortify Software Offers Protection for Vulnerable Web Applications with Fortify Defender for .NET
Feb 01, 2007 Two Fortify Software Products Named as Finalists in 17th Annual Jolt Product Excellence Awards
Jan 30, 2007 Fortify Software Expands Vulnerability Detection to Combat New Security Threats against Software
Jan 17, 2007 Fortify Software Announces Definitive Agreement to Acquire Secure Software, Inc.
Jul 31, 2006 Fortify Software Contributes Software Security Research to Open Source Community
May 15, 2006 Fortify Software Sponsors FindBugs Open Source Project
Jan 23, 2006 Fortify Software to Launch Application Security Solution at DEMO 2006
Jan 16, 2006 /C O R R E C T I O N -- Fortify Software, Inc./
Jan 16, 2006 'Extra' - Fortify Software Launches Online Software Security Community Site
 
Category Advertisements

Brought to you by Thomasnet.com        Browse ThomasNet Directory

Copyright © 2008 Thomas Publishing Company
Terms of Use - Privacy Policy