Veracode Takes Mobile Application Code Analysis to the Cloud

Veracode has added support for Windows Mobile applications to its Web-based code analysis service. Support for other platforms, including Google Android, is on the road map for later this year.

Veracode has expanded its cloud-based SecurityReview service to help businesses improve security for mobile applications.

The service, which analyzes application code for vulnerabilities, is now available for Windows Mobile applications. Support for BlackBerry and Google Android is expected to come later this year.

The new focus comes as the number of mobile applications in the market continues to rise. According to Veracode, there are already more than 100,000 mobile applications in the market and millions of mobile users accessing critical business data. Added to the mix is the fact that many mobile applications are written by third parties.

"Asking software vendors to provide source code for analysis is akin to asking Coke or Pepsi to hand over their secret formulas to conduct a taste test-it isn't going to happen," said Chris Wysopal, Veracode's CTO.

Veracode's service works by assessing the application's binary code. Customers upload binary code over the Internet to the Veracode SecurityReview platform through a standard Web browser. Veracode provides an independent assessment and security grade that allows organizations to make informed decisions about the application's security, Wysopal said.

"Typically, if the application does not meet an agreed upon security level, those who developed the application would remediate or recommend mitigation strategies before acceptance," he said. "Many of our customers, particularly in the financial services industry, have mobile applications as part of their overall application portfolios, many of which are procured from third parties. While these applications may not constitute a majority of the customer's portfolio, they are strategically important because they combine highly sensitive personal and financial data with a mobile and therefore high-risk computing platform.

"This also enables app stores to implement application security as a differentiating category for applications targeted for enterprise usage," he continued. "Further, ISVs can leverage automated independent assessments to lower the operational burdens of security testing, provide higher quality software with [fewer] 'patches,' and differentiate their product in the enterprise and government markets by demonstrating security."

Veracode competes against several companies in the market for static application tools, including Fortify Software and Ounce Labs.

Diana Kelley, an analyst with Security-Curve, noted that mobile applications are one of the fastest growing segments of the software market.

"Insecure software which processes sensitive data poses a risk to enterprises, regardless of the platform it is run on," Kelley said in a statement. "Enterprises need to apply the same risk assessment and security analysis to mobile applications as they do to those housed in data center."