_____ __ _____ ___ _____ ___ _____ _____ _____ _____ _____ _____ _____ _____ ____ _____ _ _ _ _____ | __|| | | | ||_ | | | || | | | __|| __|| __ || | || __|| __ | | || __| | \ | || | | || | | | __|| |__ | | | _| |_ | | | ||_ | |__ || __|| -|| | || __|| -| |- -||__ | | | || | || | | || | | | |_____||_____| \___/ |_____||_|___| |_| |_____||_____||__|__| \___/ |_____||__|__| |_____||_____| |____/ |_____||_____||_|___| I DONT WANT TO BE FAME , I DONT WANT TO BE ANY EZINE , I JUST WANT TO SHARE KNOWLEDGE
, ----. ~ Fuck full-disclosure - - ` ~ Fuck the security industry ,__.,' \ ~ Keep 0days private .' *` ~ Hack everyone you can and then hack some more / | | / **\ ~ Blend in. . / ****. ~ Get trusted. | mm | ****| ~ Trust no one. \ | ****| ~ Own everyone. ` ._______ \ ****/ ~ Disclose nothing. \ /`---' ~ Destroy everything. \___( ~ Take back the scene /~~~~\ ~ Never sell out, never surrender. / \ ~ Get in as anonymous, Leave with no trace. / | \ ~ This your Fucking IP | | \ ~ This your Fucking ISP , ~~ . |, ~~ . | |\ ~ FUCK OFF I've got enough friends !!!! ( |||| ) ( |||| )(,,,)` ( |||||| )-( |||||| ) | ^ ( |||||| ) ( |||||| ) |'/ ( |||||| )-( |||||| )___,'- ( |||| ) ( |||| ) ` ~~ ' ` ~~ '

[ Blog ]

[ History ]


Fortify Software as a Service have Launches

SAN MATEO, Calif., December 9, 2009Fortify® Software, the market leader

in Software Security Assurance (SSA) solutions, announced today the availability

of Fortify on Demand, its comprehensive software security suite delivered

via Software-as-a-Service. Fortify on Demand integrates Fortify's

market-leading static analysis technology with dynamic application security

testing powered by WhiteHat Security, allowing organizations to assess and

remediate security vulnerabilities in applications without installing software

on-premise."As the number of data breaches resulting from attacks against enterprise

applications continues to grow, there is a real need for software security

technology that is quick and easy to implement while still providing a

thorough assessment of your code," said Barmak Meftah, Senior Vice

President of Products and Technology at Fortify Software.

"For many organizations, the task of deploying an enterprise-wide

software security program can be daunting.

Fortify on Demand offers an easy first step for companies that need to

quickly assess their overall risk exposure, from both internal and third

party software, and then begin to implement a software security program to remediate and prevent vulnerabilities in their code."

Fortify on

Demand integrates source and binary code analysis with web application scanning, focusing on a core set of 90+ vulnerabilities in the most popular applications. Delivered through two solution sets, Enterprise Assessment Management and Vendor Security Management, Fortify on Demand provides enterprises with quick and accurate assessments of both internal and third party software.

Needless to say we are very excited! This technology combination and delivery model addresses a number of under-served customer use-cases, such as third-party validation and testing of COTS. As i've blogged, it’s time to move beyond the nonsensical adversarial debates about which testing methodology (black or white) is best and instead focus on the synergies. We’re putting our R&D money where are mouths are and have grand plans to directly benefit our customers.

Today’s integration is already yielding a solid level of vulnerability correlation, right down to a line or code block, which helps prioritize findings into actionable results -- such as what vulnerabilities are confidently exploitable. Looking ahead, consider that static analysis can measure exactly how code coverage is being realized during the dynamic analysis -- furthermore pointing out the gaps in unlinked URLs, back doors, extra form parameters, etc. This will lead to way better and measurable comprehensiveness for both static and dynamic analysis. And don’t even get me started on the metrics we’ll be able to gather. We’re just at the beginning of understanding what is possible!



On 12/10/09 at 1:44 PM



My Profile:


Biography:

short story:

[ Friends Link ]

[ chat with me ]


[ archives ]

[ Notices ]

By title

Fortify Software as a Service have Launches

By month

2002.03 2002.12 2005.12 2008.11 2009.02 2009.03 2009.04 2009.05 2009.06 2009.07 2009.08 2009.09 2009.10 2009.11 2009.12 2010.01 2010.03



 


elv1n4 Themes v2.0.0 © 2009 by elv1n4

www[dot]elv1n4.anti-sec[dot]org