BYTE.com
RSS feed

Newsletter
Free E-mail Newsletter from BYTE.com
Email Address
First Name
Last Name




 
    
             
BYTE.com > Mr. Computer Language Person > 2005

DevPartner Security Checker and Fault Simulator

By Martin Heller

March 21, 2005

(DevPartner Security Checker and Fault Simulator :  Page 1 of 1 )



There's something of a glut of good advice about application security for developers these days, from web sites like the MSDN Security Developer Center and OWASP, and from books like Keith Brown's .NET Developer's Guide to Windows Security (Addison-Wesley, 2005; ISBN 0321228359) or Howard and LeBlanc's Writing Secure Code, Second Edition (Microsoft Press, 2002; ISBN 0735617228). You can also get useful information from e-mail newsletters like @RISK from SANS, which tells you about the current security vulnerabilities of major products, which in turn tells you what not to do in your own applications. The hard part is applying all that good advice.

It takes knowledge, discipline, will, and time to secure your applications. The applications that are most vulnerable to attack are the ones most exposed to attackers: in other words, applications hosted on the public Internet.

There are hundreds of ways that a web application can be compromised, from buffer overruns to cross-site scripting to SQL injection. All it takes is one little mistake, and hundreds of thousands of customers can lose their credit card and other personal information to attackers. I only wish I were exaggerating.

Security Checker

DevPartner Security Checker from Compuware ($12,000 per concurrent user) is, in Compuware's own words, a "powerful security analysis tool that helps quickly scan, locate, and fix known and potential security vulnerabilities in ASP.NET applications written in either C# or Visual Basic .NET. DevPartner SecurityChecker automates detection processes through a combination of runtime, compile-time, and integrity analyses that pinpoint the exact location of vulnerable source code and hard-to-find security problems."

Security Checker integrates with Visual Studio .NET and tests an ASP.N

 Page 1 of 1 


BYTE.com > Mr. Computer Language Person > 2005
Dr. Dobb's Media Center

Finding Runtime Concurrency Errors in Multithreaded Java Applications
Join Coverity on June 3 at 2:00 PM ET / 11:00 AM PT for a web seminar "Finding Runtime Concurrency Errors in Multi-threaded Applications." In this session Thomas Schultz of Coverity's Advanced Technology Group will offer a presentation and demonstration of Coverity Thread Analyzer for Java, a new dynamic analysis solution for multithreaded Java applications that automatically and predictably detects existing and potential race conditions and deadlocks that can cause deadly application behavior. Register today and find out how to: <ul><li> Automatically and rapidly detect serious concurrency errors</li> <li> Avoid data corruption and application failures <li> Sharply reduce the problem of testing billions of unpredictable thread interleavings </li> <li>Reduce risk of migration to multicore systems</li> <li>Combine dynamic and static analysis to improve overall code quality</li></ul>

Solving the Multicore Programming Problem
Processor raw speed gains are hitting a brick wall of power consumption. The voracious appetite for performance now must be sated through the use of multiple CPUs. The problem: multicores are hard to program. Chuck Moore of AMD said "To make effective use of multicore hardware today, you need a PhD in computer science." Learn how Gedae expands the pool of multicore developers while offering unrivaled performance and productivity. Event Date: Wednesday, June 11, 2008.

BYTE.com Store

BYTE CD-ROM
NOW, on one CD-ROM, you can instantly access more than 8 years of BYTE.
 
The Best of BYTE: Volume 2 - Heuristic Algorithms
The Best of BYTE: Volume 2 - Heuristic Algorithms
In this volume of Best of BYTE, we explore the emergence of some heuristic algorithms. Although we have only scratched the surface of this intriguing subject, we hope we've suggested the potential of the synthesis of heuristics and algorithms.

© 2008 Think Services, Privacy Policy, Terms of Service, United Business Media
Site comments: webmaster@byte.com
Web Sites: BYTE.com, dotnetjunkies.com, Dr. Dobb's Journal, SD Expo, Sys Admin, sqljunkies.com, Unixreview



MarketPlace
Add complete SSH and SFTP support to your .NET framework application
Create your own file systems in Windows and .NET applications
100% Online programs in Six Sigma, IS Security, CISSP Prep, Business Analysis, Proj. Mgmt. and more!
DELIVER SUPPORT MORE EFFICIENTLY. Remotely Control Applications. Leap Securely through Firewalls!
WebEx lets you remotely control, configure and install applications and updates more efficiently.
Wanna see your ad here?
 

web2