From Finding to Fixing Vulnerabilities


Latest release of AppScan offers recommendations for remediation


Email    print   
December 15, 2005 —  What Watchfire calls a fundamental shift in the application security market has led to a fundamental shift in its flagship AppScan testing tool.

“The original focus of AppScan was how bad a Web site was. The success [of AppScan] was measured in the volume of issues” it uncovered, explained Michael Weider, chief technology officer at Watchfire. “In 2005, the market began to understand application security. Now the biggest issue was struggling to digest the output of the product.”

AppScan 6.0, released on Dec. 5, helps organizations do just that with the addition of an automated fix recommendation feature that studies the vulnerabilities found by the tool and generates recommendations to help remediate the problems, Weider said. “This is a huge productivity savings for our customers,” he said.

The testing tool has been given an interface lift, with new views and trees to help ease the process of working through security issues, he added. The new remediation view provides a list of recommended tasks for fixing the problems, either for the entire application or for specific pages or folders. That, Weider said, makes it easier for project managers to assign issues to the developers responsible for that work.

Other enhancements include increased scanning speed, which helps organizations get through numerous, large applications, and template-based scan configuration, which enables users to save scan items for reuse. Also, users now can prioritize changes based on the severity of the vulnerability.

Reporting is one of the most important functions of a security testing tool, and Watchfire claims that AppScan 6.0 provides reporting on more than 30 regulatory compliance requirements, such as Sarbanes-Oxley, Gramm-Leach Bliley Act and Visa Cardholder Information Security Program.

With hackers finding ever newer ways to penetrate an application, the new version provides vulnerability updates daily. AppScan 6.0 costs US$15,000 per year on a subscription basis; AppScan Developer Edition costs $1,500 per seat. AppScan DE integrates with Visual Studio and Eclipse; support for VS 2005 will be added soon, Weider said.





Share this link: http://sdt.bz/29048
 
Most Read Latest News Blog Resources

Add comment


Name*
Email*  
Country     


  • Comment
Loading




close
NEXT ARTICLE
Finding the right tool for the agile job
Experts emphasize that tools should bolster the agile process above all else Read More...
 
 
 
 
News on Monday
more>>
SharePoint Tech Report
more>>


   

 
 

Download Current Issue
FEBRUARY 2012 PDF ISSUE

Need Back Issues?
DOWNLOAD HERE

Want to subscribe?


 
blogs tab
Are you at risk for burnout?
Burnout is a severe problem and it can strike at any time. Here's how to tell if you are nearing the edge.
02/09/2012 02:16 PM EST

Agility, mom, and apple pie
If we're to evaluate the state-of-the-art in software development, we should start with the values espoused in the Agile Manifesto.
02/07/2012 11:57 AM EST

RIM woos developers with free tablet
How do you get more apps ported to the BlackBerry PlayBook? By giving every developer a free tablet, of course!
02/04/2012 01:57 PM EST

GitHire: Use Headhunters to Find Your Perfect Programmer
Are you a hiring manager tired of scouring the job boards? Check out this new service that will find 5 people interested in your jobs.
02/03/2012 12:17 PM EST

Facebook claims hacker cred
Facebook's SEC S-1 filing form includes a short essay on the Hacker Way by Mark Zuckerberg himself.
02/02/2012 08:26 AM EST

Ryan Dahl steps down
Ryan Dahl, creator of Node.js, steps back from his position as gatekeeper for the project.
02/01/2012 04:58 PM EST

 
Events calendar tab
2/13/2012 to 2/16/2012
Santa Clara
TechWeb

2/26/2012 to 2/29/2012
San Francisco
BZ Media

2/27/2012 to 3/2/2012
San Francisco
RSA

3/4/2012 to 3/7/2012
Las Vegas
IBM Tivoli

3/5/2012 to 3/9/2012
San Francisco
TechWeb