Business & Technology News

Business & Technology Information


Recently...
LogiSense and Trustive Form Wireless IP Roaming Alliance

LogiSense Corporation (logisense.com), a leading global provider of IP Billing and Traffic Managemen...

Discrete Wireless Announces Commercial Release of New MARCUS® 6 GPS Fleet

Announced today, Discrete Wireless has launched it’s new MARCUS® 6 GPS Fleet Management Application ...

Neutouch Revolutionary Unified Messaging System

The speed which business is conducted as technology diversifies and then consolidates revolutionizes...

Real-time Sports Betting Odds Now Free For All Web Sites.

Until recently, live lines were a luxury most everyday gamblers could not afford. These live odds pr...

Santa Says Texas is First on His List, Thanks to Free Wireless Internet

The Texas Department of Transportation and Coach Connect Corp. are bringing free wireless internet t...

PeopleSoft clients wary of Oracle

Almost two-thirds of PeopleSoft Inc. customers said they will cancel their software-support contract...

Intel Firms Up Dual-Core Plans

CEO Craig Barrett tells analysts that Intel is "firing on all cylinders" as the company offers a tim...

Intel Bullish On Technology Direction At Fall Analysts Meeting

Sounding anything other than a company that has had its share of missteps in recent months, outgoing...

AMD adds PowerNow technology to Opteron processor

The addition of the AMD PowerNow technology with OPM is expected to strengthen the performance-per-w...

Chinese Mobile Developer CYIT Chooses Java Technology-Enabled ARM9E Family Processor

Chongqing Chongyou Information Technology Co., Ltd (CYIT), a major TD-SCDMA handset developer in Chi...

AMD To Provide On-Demand Power Management For The Rack-Dense Enterprise Market

Addition of AMD PowerNow!™ technology with Optimized Power Management will further enhance the AMD O...

AMD To Present at Lehman Brothers 2004 T4

AMD (NYSE:AMD) today announced that AMD Corporate Vice President and Chief Technology Officer Fred W...

AMD Drives Future Of Formula One Technology

Using technology provided by AMD (NYSE:AMD), Formula One team Sauber Petronas today launched its new...

A New Web Site About MRAM Technology

MRAM-Info is a new web site about MRAM technology. MRAM (Magnetic RAM) is a new, promising new RAM t...

New technology finds missing persons

The developers of a new system says their technology can track missing people anywhere in the countr...


Archive
April 2005
March 2005
February 2005
January 2005
December 2004
November 2004
October 2004


Business & Technology News RSS Feed
RSS Feed


Web Resources
Online Casino News
Online Poker News


 

Watchfire Takes Control of AppScan Security Software

Watchfire Corp. last month released version 5.0 of the AppScan application security software it acquired from Sanctum Inc. in July, with new features that make the vulnerability assessments more sophisticated, the company says.

“Hackers are more advanced, so more intelligence is required behind the tests,” said Steve Orrin, former CTO at Sanctum who now is vice president of security and technology at Watchfire. “It’s like an arms race. There’s always a gap” between what hackers are doing and what companies are doing to defend against those actions, but Orrin claimed that Watchfire, compared with other application security vendors, “is a little bit ahead of the game.” Orrin estimated there is a lag of six to 12 months between what hackers are doing and when those actions become commonly known in the industry.

AppScan’s test engine has been enhanced to do multiphase scanning of applications, according to director of product marketing David Grant, so that if any tests reveal new links within an application that weren’t explored, AppScan will create tests for those new parts of the application. AppScan now also can do multistage tests that need multiple requests and responses to execute, Grant added.

Also new to AppScan is a port listener that recognizes new kinds of HTTP attacks by detecting out-of-band responses, Orrin explained, saying that the software sits as a proxy server, listening to a specified port for HTTP requests and ensuring the responses also are HTTP.

Among the new vulnerabilities Watchfire has identified is HTTP response splitting, which is an attack that splits a single response into two and allows the hacker to disrupt the order of the Web application. “You can poison the Web cache, or have your server run my Web page,” Orrin said. “You can do a lot of logic subversion.”

But knowledge of a vulnerability is not always a guarantee that it will be fixed, Orrin cautioned. “It’s been 10 years since cross-site scripting was discovered, and it’s still a problem today. But we’re seeing development managers getting it by starting to apply the right policies” in the application process, he said.

To cut down on these types of vulnerabilities, Orrin said vendors must start to bring these tools to developers. “Microsoft’s not out there promoting these solutions,” he said, noting that the drivers have been regulatory compliance and the inclusion of QA teams in compliance, an area in which auditors worked alone. Orrin said 15 different compliance reporting templates are now included in AppScan 5.0, which comes in developer, QA and auditor editions. Pricing was not available.

Grant said that an update to AppShield, the company’s firewall, is in development and should be out late this year or early next, and a port to Linux also is in the works. Grant explained that before the Sanctum acquisition, Watchfire could offer analysis of a production site and create dashboards, but now can offer visibility and testing throughout the Web development life cycle.

Source: SD Times


All trademarks and copyrighted information contained herein are the property of their respective owners.




A   B   C   D   E   F   G   H   I   J   K   L   M   N   O   P   Q   R   S   T   U   V   W   X   Y   Z