Ounce Labs and Aspect Security Publish Report on Open Source Vulnerability Analysis
Wednesday, 15 February 2006 Ounce Labs, the leader insoftware security assurance solutions, and Aspect Security, the applicationsecurity specialists, today released "Opening the Black Box: A Source CodeSecurity Analysis Case Study." The report describes a detailed source codesecurity review of a popular open source application, ways specific flawsmay affect users, security trends of open source development, andguidelines that professionals should use for verifying the security ofapplications within their organization. Primary authors of the publication are Jack Danahy, founder and CTO ofOunce Labs, and Jeff Williams, founder and CEO of Aspect Security as wellas Chairman of the Open Web Application Security Project (OWASP)Foundation. They document a detailed security verification of Azureus, thepopular open source BitTorrent client, by Aspect's team of applicationsecurity experts supported by Ounce Labs' advanced source code securityanalysis technology. The Ounce Labs' analysis engine took under an hour to scan Azureus' 200,000lines of source code and identify vulnerabilities and potential designflaws in the application. Aspect's team used these results as part of itsunique application security verification process and documented details ofthe most critical vulnerabilities. This process is explained step-by-stepin Opening the Black Box to give organizations guidance on how to implementa software security assurance initiative for their own applications. "Our security verification of Azureus found it to be resilient to attacksfor the most part, and security mechanisms have been well-implementedwithin the code," said Williams. "Verification is not simply findingvulnerabilities. We used Azureus as a test case to demonstrate acost-effective process for ensuring that applications are secure enough totrust with your business. These efforts also provide tremendous insightinto your organization's capability to produce secure code." "This report demonstrates a process proven to successfully reduceenterprise risk caused by insecure software, although the vast majority ofcompanies have almost no insight into how secure their applications are,"said Danahy. "Layers and layers of network security are worthless ifapplication flaws and policy violations expose critical data to attack. Weare presenting a way to remove software risks that companies can beginimplementing immediately." Jeff Williams will join Ounce Labs every hour during the RSA Conference inbooth number 215 to present findings from the Opening the Black Box report.Aspect will also be exhibiting in Ounce Labs' booth as a featured partner. "Opening the Black Box: A Source Code Security Analysis Case Study" isavailable free to the public at Ounce Labs' booth or atwww.ouncelabs.com/openbox. The Azureus Team volunteered their application as a test subject for thisproject. Their support during the process and permission to publish resultsof this study are greatly appreciated. More information about Azureus canbe found at http://azureus.sourceforge.net/. About Ounce Labs, Inc. Ounce Labs™, the leader in software security assurance, deliversproducts that allow customers to verify that software meets their definedsecurity requirements. Ounce Labs' enterprise-level automated source codeanalysis provides reliable vulnerability metrics necessary to managesoftware risk, enforce security policies, enhance audit capabilities, andtrack compliance efforts. Based on patents-pending Contextual Analysis™technology, Ounce Labs' products also pinpoint specific software designerrors and coding flaws to simplify remediation during any phase of thedevelopment lifecycle. Founded in 2002, Ounce Labs is located in Waltham,Massachusetts. For more information, please visit www.ouncelabs.com. About Aspect Security, Inc. Aspect Security specializes in web application and web services security.Aspect's expert staff is responsible for the security of financial,healthcare, biotechnology, e-commerce, Fortune 500, and government webapplications. Aspect provides code review, penetration testing, policydevelopment, and developer security training services to find, diagnose,and eliminate vulnerabilities in custom web application code. Aspect isprivately held and headquartered in Columbia, Maryland. To contact AspectSecurity call 301-604-4882, visit us on the Web at www.aspectsecurity.com,or write to info@aspectsecurity.com. OUNCE LABS CONTACT:Chris McCleanOunce Labs781.547.7031 (o)617.571.8945 (m)Email Contact ASPECT CONTACT:Bill HustedAspect Security, Inc.301-604-4882301-775-5545Email Contact SOURCE: Ounce Labs
Source: marketwire
All trademarks and copyrighted information contained herein are the property of their respective owners.
Related Articles
- Novell Delivers Cross-Platform Compliance Solution for the Open Enterprise
Wednesday, 15 February 2006
- New Encryption Solution From Sun Microsystems Sets Bar for Online Application and Transaction Security
Wednesday, 15 February 2006
- Smart Style Selects Continuent Clustering for MySQL
Wednesday, 15 February 2006
- Sun Microsystems' Top Executives Share Security and Open Source Vision to Empower the Participation Age
Wednesday, 15 February 2006
- Nokia and MySQL Collaborate on Next Generation Telecommunication Subscriber Registers
Wednesday, 15 February 2006
- BEA Expands Its Blended Development Model by Making Valuable Code Donation to Open Source Java Community
Wednesday, 15 February 2006
- Philippines' Largest Carrier Adopts Funambol's Mobile Open Source Platform
Wednesday, 15 February 2006
- MicroStrategy Announces Certification to Access Open Source Databases
Wednesday, 15 February 2006
- OpenLogic to Present at Open Source Business Conference
Sunday, 12 February 2006
- Open Source Storage(R) Unveils Patent-Pending Vertical Patch Panel and Vertical Panel Switch for Datacenter Racks
Sunday, 12 February 2006
- DataForceOne, an Open Source On Demand CRM and Sales Channel Optimization Software Company is Offering a Free How To Guide: Maximize Your Sales From Y
Sunday, 12 February 2006
- Sun Microsystems Top Executives to Address Security and Open Source in the Participation Age
Saturday, 11 February 2006
- New Report From The Diffusion Group: Windows and Linux to Displace Symbian as Dominant Force in Advanced Mobile Operating Systems
Friday, 10 February 2006
- SourceLabs Raises the Bar on Open Source Dependability With New SASH Stack 1.1 for Java
Friday, 10 February 2006
- Funambol Releases First Open Source Push Email Product for Deployment With Carriers and Enterprises
Wednesday, 8 February 2006
|