Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cybersecurity
    • Development

    Tools Block Code-Busting Crooks

    Written by

    Darryl K. Taft
    Published December 20, 2004
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The concept of adding security to the coding phase of application development is catching on, with new companies delivering tools to help developers test for vulnerabilities early in the process.

      One company is not only delivering tools but also attempting to seed the market with the talent to create secure applications. Ounce Labs Inc., of Waltham, Mass., last week introduced its Secure Foundations Initiative, a program that puts the source code vulnerability analysis software vendor in collaboration with universities to train developers in secure software.

      The Ounce Labs Secure Foundations Initiative has committed software and research grants worth more than $500,000 to launch the program to promote security at schools such as The George Washington University, Southern Methodist Universitys High Assurance Computing and Networking Lab, the United States Military Academy at West Point, and The Center for Education and Research in Information Assurance and Security at Purdue University, said Ounce Labs CEO Jack Danahy.

      “This is a problem we need to figure out how to solve,” Danahy said. “A lot of people dont realize the problem, but there are only about 300 to 500 people worldwide who can do a competent [secure] code review,” he said.

      In May, Ounce released its Prexis tool, which automatically scans source code to analyze an applications security and pinpoint vulnerabilities during development.

      “I intend to use it to have our students run their code through the tool to show them where they may have made some security errors—without any foreknowledge or planning for security in their code—to let them see what are known pitfalls,” said Ron Dodge, director of the IT and operations center at West Point, in New York.

      Julie Ryan, professor of information security management at The George Washington University, in Washington, said, “One of the problems for information technology security is that the market demands that software be developed quick and cheap.” That means less emphasis on coding for security.

      /zimages/4/28571.gifClick here to read an in-depth story on securing applications during development.

      West Points Dodge said an influx of tools to help with security at the development phase would be welcome. “Its like somebody trying to build a fence without a level,” he said.

      Although tools for automating the detection of software vulnerabilities have existed, the space is relatively uncharted. In the next version of its Visual Studio Tools, Microsoft Corp. plans to deliver to developers the ability to check for security vulnerabilities.

      One other company following a similar path is Kenai Systems Inc., of Rocklin, Calif., which last week announced its ExamineST Web services security tool, which provides vulnerability assessment to test for problems with Web services at their development phase, said Bill Kesselring, CEO of Kenai.

      ExamineST allows developers to import WSDL (Web Services Description Language) files and test them for compliance with the Web Services-Security specification and other known vulnerabilities.

      /zimages/4/28571.gifCheck out eWEEK.coms for the latest news, reviews and analysis in programming environments and developer tools.

      Darryl K. Taft
      Darryl K. Taft
      Darryl K. Taft covers the development tools and developer-related issues beat from his office in Baltimore. He has more than 10 years of experience in the business and is always looking for the next scoop. Taft is a member of the Association for Computing Machinery (ACM) and was named 'one of the most active middleware reporters in the world' by The Middleware Co. He also has his own card in the 'Who's Who in Enterprise Java' deck.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.