Home > Security News > Veracode launches on-demand code analysis service
Security News:
EMAIL THIS

Veracode launches on-demand code analysis service

By Dennis Fisher, Executive Editor
24 Jan 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

As software security and secure development techniques have continued to gain momentum, the demand for code-auditing tools and services has risen as well. A number of companies have sprouted up to meet that demand, but a new company called Veracode Inc., launching this week, is bringing a unique on-demand services model to a market comprising almost exclusively software offerings.
We can do code analysis at a deep binary level. The engine traverses more code paths than source code tools can.
Matt Moynahan,
CEO, Veracode Inc.

Veracode's Code Assurance Security Platform enables customers to upload code to the company's servers, where it is then analyzed using Veracode's proprietary binary-analysis tool. About a day later, the customer gets a complete report on all of the vulnerabilities found in the code. The customer can click on each vulnerability in the report and link directly to the section of the code where the problem lies. The goal is to make the arduous task of code analysis much more efficient and accurate than it is now.

Aside from the on-demand, subscription-based model, Veracode's key innovation is its tool's ability to analyze the application binary, and not simply the source code.

"We can do code analysis at a deep binary level. The engine traverses more code paths than source code tools can," said Matt Moynahan, CEO of Veracode, based in Burlington, Mass. "The binary is what's running online, not the source code."

Veracode's platform enables a closed-loop feedback system in which mistakes found in one customer's code help the company's analysts identify and correct that problem in other customers' applications. This allows for continuous improvement in both Veracode's analysis methods and its customers' development techniques.
Code analysis:
Static and dynamic code analysis: A key factor for application security success

Source code analysis tool key to absentee ballot system

Code-scanning tool automates software review at financial firm

Attackers hide malicious code using new method

Veracode's entry into the market comes at a time when on-demand services in general are becoming more and more popular in the enterprise. The success of pioneers such as Salesforce.com, Netsuite Inc., and others has convinced industry giants like Microsoft Corp. and IBM that there is plenty of appetite for subscription-based services and more flexible delivery and pricing models. However, Veracode is the first vendor to offer a code auditing service using the model. Its competitors, including Fortify, Coverity, Ounce Labs and others all sell software.

Veracode is the brainchild of co-founders Chris Wysopal and Christien Rioux, both veterans of the famed L0pht hacking collective and its eventual corporate parent, @stake Inc. Wysopal, the company's CTO, helped write the binary analysis tool that is at the heart of Veracode's offering. After Symantec Corp. bought @stake in 2004, Wysopal joined the security giant for a time, but left last year in order to get Veracode up and running. Rioux is the company's chief scientist and is well-known in the security community for his vulnerability research and other work. The company's management team boasts a number of other Symantec and @stake veterans, including Mike Pittenger, the vice president of business development, and Malcolm Lockhart, the chief architect.

Veracode plans to demonstrate its service at the RSA Conference in San Francisco next month.

Tags: Security Industry Market Trends, Predictions and ForecastsVulnerability Risk AssessmentVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Security Industry Market Trends, Predictions and Forecasts
Cybersecurity czar candidate questions clout of new position
Gartner sees better days ahead for security budgets
Sophos CEO on Symantec, McAfee after Utimaco acquisition
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Security budgets take hit in media, tech industry, survey finds
Cybersecurity Act of 2009: Power grab, or necessary step?
Opinion: Gartner gets NAC wrong, again
Cloud computing security group releases report outlining trouble areas
White House cybersecurity advisor calls for public-private cooperation
Security Industry Market Trends, Predictions and Forecasts Research

Vulnerability Risk Assessment
Are Web application penetration tests still important?
McAfee to acquire Solidcore Systems for whitelisting
The Pipe Dream of No More Free Bugs
Vulnerability test methods for application security assessments
Free HP SWFScan tool detects Adobe Flash flaws
PCI QSA assurance program penalizes assessors
Information security book excerpts and reviews
New York drafts language demanding secure code
Security experts identify 25 dangerous coding errors
Microsoft Windows XML flaw exploits test desktop antimalware
Vulnerability Risk Assessment Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
backscatter body scanning  (SearchSecurity.com)
marketecture  (SearchSecurity.com)
NCSA  (SearchSecurity.com)
Palladium  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts