Palamida Launches Code Vulnerability Reporting Tool
April 28, 2007The VRS package enhances CTOs' control over their companies' software by pinpointing known security risks in open-source code, Palamida says.
SAN FRANCISCO - Software intellectual-property management services provider Palamida on April 27 introduced a new service that works to identify vulnerabilities in an enterprise's open-source code.
The announcement was made at the annual Gartner Symposium/ITxpo: Emerging Trends at the Moscone Center here.
Palamida's Vulnerability Reporting Solution works as a plug-in to the company's code audit compliance solution, IP Amplifier, to "identify, prioritize and spotlight the location of known vulnerabilities" in open-source code, a Palamida spokesperson said.
Palamida's library contains more than 3 terabytes' worth of content, including 140,000 OSS projects, 780,000 versions, 7 billion source code snippets, 10 million Java namespaces, 500 million binary file IDs, and Java, C/C++, Perl, Python, PHP, C# and VB signatures, the spokesperson said.
The VRS uses data from the National Vulnerability Database, a comprehensive cyber-security database sponsored by the Department of Homeland Security and run by the National Institute of Standards and Technology and MITRE.
The National Vulnerability Database integrates all publicly available U.S. government vulnerability resources and provides references to industry resources for the purpose of assisting with remediation efforts. It currently contains over 23,700 known vulnerabilities, 89 US-CERT issued alerts and 1,900 US-CERT vulnerability notes, and has a publication rate of approximately 18 new vulnerabilities per day.
Readily available code resources, the increase of geographically distributed development teams and ever-increasing time-to-market pressures have resulted in the blending of homegrown, third-party and open-source components, the spokesperson said.
The sheer size of a code base coupled with the number of contributing developers makes it difficult for companies to get an accurate assessment of their software assets.
"Successful IT Governance requires risk mitigation at the code level. Customers should be utilizing vulnerability analysis solutions to identify and remediate application risks," Palamida CEO Mark Tolliver said. "The VRS works together with vulnerability analysis solutions to bridge the gap between proprietary code analysis and complete code analysis."
Most companies operate without any knowledge of exactly what their software is made of and whether or not it contains security risks. The root cause of many application security vulnerabilities resides in the code base - an area that traditional security software cannot protect, Tolliver said.
Existing vulnerability analysis solutions scan customers' proprietary code to identify potential vulnerability holes such as buffer overrides and network and intrusion detection gaps. They also highlight violations in secure coding practices.
The VRS, on the other hand, augments the IT governance process by scanning the customer's code base and pinpointing the existence of open-source content, highlighting any known vulnerabilities and delivering a prioritized report to assist with remediation efforts, the spokesperson said.
Michael Cote, an analyst with RedMonk, told eWEEK that the important thing in this release is that it builds on the code auditing that's already in the Palamida platform.
"It's true that there are a handful of vendors that work in the same space, but Palamida is approaching the sector in their own way technologically: building up the database of open-source projects, and then layering on more software auditing and 'health checks,' " Cote said.
"What I like about the code auditing and code-health approach that companies in this problem space do is that it lets developers work at the fast pace they'd like to without being slowed down by manual auditing processes," Cote said. "Adding in things like venerability checking adds more value to these platforms in that the platform is further automating previously manual processes."
San Francisco-based Palamida and Black Duck Software, headquartered in Waltham, Mass., are the primary companies working in this space today, although other entrants are likely to emerge, Forrester Senior Analyst Michael Goulde told eWEEK.
"Their products and services address two of the leading concerns many companies have about software in general, not just open-source software: security and intellectual property rights," Goulde said.
The two companies have taken somewhat different directions in terms of the markets they address and their go-to-market approaches, Goulde said.
"What they're doing is more than code searching," Goulde said. "They need to identify and flag specific issues by using a wealth of data they've collected from a variety of sources. It isn't good enough to know that a particular piece of code is being used, because in one context that can be perfectly OK and in another, there can be serious licensing or IP issues. So putting all the pieces together to present a complete picture is what both companies are trying to do for their customers."
Copyright 2007 by Ziff Davis Media, Distributed by United Press International
-
Computer security firm Symantec extorted by hackers
Feb 07, 2012 |
5 / 5 (2) |
11
-
For Facebook 'Hacker Way' is way of life
Feb 05, 2012 |
3 / 5 (1) |
1
-
Symantec urges users to disable pcAnywhere
Jan 26, 2012 |
not rated yet |
0
-
Adobe confirms zero-day danger in Reader and Acrobat
Dec 07, 2011 |
5 / 5 (5) |
0
-
Iran says Duqu malware under 'control'
Nov 13, 2011 |
4 / 5 (1) |
1
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (31) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Calling function with no input argument
15 hours ago
-
Force free body diagram problem on gym equipment
16 hours ago
-
Empirical data regarding shower heads and water
23 hours ago
-
feed hold button on CNC lathe
Feb 09, 2012
-
RFAC in Fortran
Feb 09, 2012
-
dynamics 2/32
Feb 08, 2012
- More from Physics Forums - General Engineering
More news stories
Anonymous knocks CIA website offline (Update)
The website of the Central Intelligence Agency was inaccessible on Friday after the hacker group Anonymous claimed to have knocked it offline.
9 hours ago |
5 / 5 (9) |
16
Google users warned of threat to smartphone wallets
Users of Google smartphone wallets were being warned on Friday that there is a way to crack pass codes intended to thwart thieves from going on illicit shopping sprees.
8 hours ago |
5 / 5 (2) |
0
New error-correcting codes guarantee the fastest possible rate of data transmission
Error-correcting codes are one of the triumphs of the digital age. Theyre a way of encoding information so that it can be transmitted across a communication channel such as an optical fiber o ...
Technology / Computer Sciences
18 hours ago |
4.9 / 5 (8) |
6
|
New power source discovered
(PhysOrg.com) -- Researchers at the Massachusetts Institute of Technology (MIT) and RMIT University have made a breakthrough in energy storage and power generation.
Technology / Energy & Green Tech
17 hours ago |
4.8 / 5 (29) |
8
|
Small modular reactor design could be a 'SUPERSTAR'
(PhysOrg.com) -- Though most of today's nuclear reactors are cooled by water, we've long known that there are alternatives; in fact, the world's first nuclear-powered electricity in 1951 came from a reactor ...
Technology / Energy & Green Tech
17 hours ago |
4.4 / 5 (13) |
23
|
Humans may have helped the decline of African rainforests 3000 years ago
(PhysOrg.com) -- Large areas of rainforests in Central Africa mysteriously disappeared over three thousand years ago, to be replaced by savannas. The prevailing theory has been that the cause was a change ...
The power of estrogen -- male snakes attract other males
A new study has shown that boosting the estrogen levels of male garter snakes causes them to secrete the same pheromones that females use to attract suitors, and turned the males into just about the sexiest ...
Complex wiring of the nervous system may rely on a just a handful of genes and proteins
Researchers at the Salk Institute have discovered a startling feature of early brain development that helps to explain how complex neuron wiring patterns are programmed using just a handful of critical genes. ...
Could Venus be shifting gear?
(PhysOrg.com) -- ESAs Venus Express spacecraft has discovered that our cloud-covered neighbour spins a little slower than previously measured. Peering through the dense atmosphere in the infrared, the ...
Advanced power-grid model finds low-cost, low-carbon future in West
(PhysOrg.com) -- The least expensive way for the Western U.S. to reduce greenhouse gas emissions enough to help prevent the worst consequences of global warming is to replace coal with renewable and other ...
Fool's gold may prove an unlikely alternative to overexploited catalytic materials
Catalytic materials, which lower the energy barriers for chemical reactions, are used in everything from the commercial production of chemicals to catalytic converters in car engines. However, with current catalytic materials ...