home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers

Home > Security


S T R A T E G Y



Analysis: Automated Code Scanners

False Sense of Security?

Vendors claim that adopting source-code security analyzers will fortify your business and protect your precious data. But should they be your only line of defense, or will they simply lull the IT staff while criminals still prowl?
- By Justin Schuh

   

The Latest Videos
Watch demos of Intel's webpad-based Health Guide for seniors, at the New York City launch of Intel's $250-million alliance with GE. In this special "ReviewCam" edition of Interop Insider, InformationWeek editor-at-large David Berlind sits down with Splunk co-founder Michael Baum to get a demonstration of the company's namesake product. Intel chief sales and marketing officer Sean Maloney sits down with InformationWeek's Alex Wolfe, on the occasion of the launch of the Xeon 5500 Nehalem server processor, for a wide-ranging discussion.
Watch demos of Intel's webpad-based Health Guide for seniors, at the New York City launch of Intel's $250-million alliance with GE.
Remember when attackers were just out for fame and glory, and application security was someone else's problem? Big targets like Microsoft and Oracle drew the fire. All enterprise IT had to do was apply patches regularly and keep a properly configured firewall.

Those days are gone. Cracking corporate networks is no longer a kid's game, it's a lucrative criminal growth industry. The attackers who stole 45.6 million credit- and debit-card numbers from TJX Companies were professional enough to remain undetected for at least 10 months. Meanwhile, major software vendors, including Microsoft, have improved their security practices, which puts niche and in-house-developed software and Web applications squarely in the bad guys' sights.

Data Privacy
Immersion Center

NEWS | REVIEWS | BLOGS | FORUMS TUTORIALS | STRATEGY | MORE

It seems enterprise IT is finally grasping the liability insecure coding practices represent. Data protection and application-software security were chosen as the most critical issues through 2008 in the 2006 CSI/FBI Computer Crime and Security Survey, above policy and regulatory compliance, and identity theft/data-leakage prevention.

If you think your network's not at risk, consider that most software isn't built for commercial distribution; it's developed in-house or on contract for specific requirements. Purpose-built apps provide the framework for a huge range of business processes, from dynamic Web sites, SOA (service-oriented architecture) and e-commerce to business process automation and administration. They also provide a target-rich environment for would be attackers.

In response to this escalating threat, major compliance standards like HIPAA and PCI DSS (Payment Card Industry Data Security Standard) are incorporating--or at least implying the necessity of--application security processes.

Of course, where there's a regulation, there's a marketing op. In this case, makers of automated source-code analysis tools are shifting their focus from commercial software vendors to enterprises. They say adopting their tools will let your developers build more secure software and meet the compliance burden.

But are they up to the job?

To find out, we brought three popular static source-code analyzers into our Chicago Neohapsis partner lab: Fortify SCA (Source Code Analysis) 4.0, Klocwork K7.5 and Ounce Labs' Ounce 4.1. We also asked Coverity to send its Prevent analyzer, but the company declined, citing insufficient resources.

Each product has strengths and weaknesses, but any would be a useful addition to a mature security process. And therein lies our most important point: A code scanner, no matter how effective, is only part of the answer. Without adequate developer training and an SDLC (software development lifecycle) that makes security a priority, no tool will protect your network. Sound familiar?

We've long advocated a defense-in-depth strategy that recognizes that there is no perimeter. Security groups have implemented technologies like host intrusion prevention, NAC and database-extrusion prevention that seek to thwart attackers who have infiltrated outer lines of defense before they gain access to sensitive information.

But that's no longer enough. It's time for enterprise IT to partner with in-house and contract developers to make security Job 1. The application development group and the security group all sit under the CIO, so even though security pros typically have had a different world view from developers, who are mainly concerned with providing the functionality requested by the business, political issues can be overcome.

Continue Reading This Story...

IMAGEs
Click image to view image

NWC REPORTS
bullet Analysis: Automated Code Scanners
Get the full PDF of this article at NWC Reports.
NWCANALYTICS.COM
bullet Host Intrusion Prevention Systems
We examine host IPS in this Network Computing Analytics Tech Report based on an exclusive survey of enterprise users and in-depth lab analysis.




Page 2: A Child Can Use It
1 | 2 | 3 | 4 | 5 | 6 Next Page














Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Aneesh Chopra is looking to other CIOs to advise him on fleshing out a more detailed agenda to best serve the president's IT agenda.

IT spending is expected to decline by 3.8 percent in 2009 according to Gartner.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips

 


Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service