Klocwork Broadens Security Vulnerability Analysis

Share |

Klocwork Broadens Security Vulnerability Analysis to Align with Industry and Government Best Practices. Integrated support for CWE, CERT and SAMATE initiatives helps developers eliminate exploitable security issues

(I-Newswire) April 7, 2010 - Klocwork, Inc., the global leader in automated source code analysis solutions for improving developer productivity, today announced the enhancement of its security vulnerability analysis capabilities with support for the Common Weakness Enumeration™ (CWE), the CERT Secure Coding Initiative, and the Software Assurance Metrics and Tool Evaluation (SAMATE) project. Integrated support for these initiatives ensures Klocwork's security reporting features align with industry and government best practices for identifying, understanding, and remediating security coding issues.

Common Weakness Enumeration (CWE)

As a community-developed list of software weakness types coordinated by MITRE, the CWE is helping to define and categorize the most common weaknesses affecting software security, including buffer overflows, format string vulnerabilities and un-validated user inputs.

Having declared Phase II compliance for the CWE standard, Klocwork Insight analysis results can now be reported using CWE identifiers and Klocwork's vulnerability documentation has been updated to include CWE identifiers. CWE categorization as part of Klocwork's products enables customers to report on any CWE violations in their code.

CERT Secure Coding Standards

The CERT Secure Coding initiative at the Carnegie Mellon Software Engineering Institute (SEI) is supporting the development of secure code by identifying common coding errors that produce vulnerabilities and establishing a set of secure coding standards for commonly used programming languages, including C, C++ and Java.

"The CERT standard was created to help developers build code that is robust and resistant to security attacks," says Robert C. Seacord, Secure Coding Team Lead, Software Engineering Institute. "An effective way to ensure adherence to the standard is through the use of source code analysis tools because they allow you to check for rule violations."

To help software developers take advantage of the guidelines and direction provided by the CERT initiative, Klocwork Insight analysis results and documentation reference the corresponding CERT standard violation.

Software Assurance Metrics and Tool Evaluation (SAMATE)

An inter-agency project between the U.S. Department of Homeland Security and the National Institute of Standards and Technology (NIST), the SAMATE project has developed a set of metrics to measure the effectiveness of software security assessment tools like source code analysis technology, and assesses those tools to help identify weaknesses that lead to software failure and security vulnerabilities.

Klocwork runs the SAMATE test suite as part of its standard benchmarking practices and maintains a pass rate of 90%.

"These latest product enhancements extend Klocwork's commitment to helping professional software developers produce the most secure software possible," says Alen Zukich, director of product management, Klocwork. "In collaboration with industry- and government-lead initiatives, Klocwork offers development organizations the ability to establish a single, consistent security policy across their software development lifecycle."

For a summary of Klocwork's support for these initiatives, visit Klocwork's code security web page.

About Klocwork

Klocwork® source code analysis solutions boost the productivity of software development teams while helping to ensure code security, quality and stability of complex code bases. Through proven static analysis techniques, Klocwork removes bottlenecks at the earliest stages of the software development process and enables software developers to find critical security vulnerabilities, quality defects and architectural issues quickly and accurately. More than 650 organizations have achieved higher code security and quality with Klocwork.

http://www.klocwork.com/solutions/
http://www.klocwork.com/products/product-comparison-matrix/

Media Contact:
Meranda Powers
1.866.556.2967
press@klocwork.com





About Klocwork:
Klocwork is an enterprise software company providing automated source code analysis software products that automate security vulnerability and quality risk assessment, remediation, measurement for C, C++ and Java software and java static analysis. More than 300 organizations have integrated Klocwork's automated source code analysis tools into their software development process in order to ensure their code is free of mission-critical flaws while freeing their developers to focus on what they do best – innovate.

Company Contact Information
Klocwork
Todd Landry
15 New England Executive Park
01803
Phone : 1.866.556.2967




Computer > Software

code   automated   source code analysis   analysis   software quality   Source   code analysis   static code analysis   Source code   Static   FDA software   software validation   peer code review  

April 7, 2010

Content Disclaimer: If you have questions regarding information in this press release contact the company listed above. I-Newswire.com is a press release service company and not the author of this press release.The information that is on or available through this site is for informational purposes only and speaks only as of the particular date or dates of that information. As some companies and PR Agencies submit their press releases once per week,month or quarter,make sure to check the official company website for accurate release dates as our site displays the date only.We do not guarantee the accuracy or completeness of information on or available through this site, and we are not responsible for inaccuracies or omissions in that information or for actions taken in reliance on that information.


Related Releases

Newly TS To IMovie Converter Released By ILifeSoft
ILifeSoft update TS to iMovie Converter to convert .ts file to mp4 for import imovie for editing.

Newly Panasonic HDC-TM700K 1080/60p MTS To QuickTime MOV Converter Mac From ILifeSoft
Mac Panasonic HDC-TM700K 1080/60p MTS to QuickTime MOV Converter is a wonderful conversion software which will convert convert Panasonic HDC-TM700K to MOV for QuickTime player on Mac with your several clicks.

the Greatest On-Line Treasure Hunt of All-Time! Find King Arthur’s Lost Gold Crown and Win Almost U.S. $50,000.00
The Treasure of Camelot is a New Online Treasure Hunt Competition to find King Arthur's Lost Gold Crown. There is an amazing prize worth almost $50,000.00 for the first person to locate the treasure!

GoldKey Announces Soft-Token App For IPhone, IPad, And Android
New App from GoldKey Provides Two-Factor Authentication for iOS and Android Devices

Euro 2012: The Best One — Android Application Devoted to UEFA Euro 2012 Championship
UEFA Euro 2012 Poland and Ukraine is coming, the endless football joy will begin at the June 8th. BigWhitePlanet s.r.o. has proudly announced the worldwide release of they stunning football application: Euro 2012: The Best One.


© Copyright 2012 I-Newswire.com - press release distribution service. All rights reserved