Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Black Hat: Software Vulnerability Index making progress

Could the encyclopedic document be published by summer?

March 1, 2007 12:00 PM ET

InfoWorld - Security experts working on the CWE (Common Weakness Enumeration) project claim that the initiative to create a central resource of software vulnerabilities for developers is gaining momentum.

Sponsored by the Department of Homeland Security (DHS) and maintained by a team of workers at nonprofit Mitre and other security professionals, the ongoing effort is roughly four months shy of publishing a final draft of its vulnerability encyclopedia, said leaders of the project.

Presenting at the ongoing Black Hat 2007 conference, CWE initiative leaders said they are busy aggregating and organizing the mountains of vulnerability data they have gathered and said they are working more closely than ever with applications security testing companies to help compare the abilities of various software scanning tools.

Launched in Dec. 2005, CWE seeks to establish a unified, measurable set of software flaws to help developers improve the quality of their products and drive out the types of vulnerabilities that have led to the ongoing malware explosion.

By gathering input on commonly seen mistakes from developers, researchers, and security vendors, the group believes it can create a common language and standard procedures for handling the many different types of loopholes that exist in programs' source code today.

Prior to the delivery of a final draft of its encyclopedia of flaws later this year, CWE officials said they are preparing a sixth iteration of the index to likely be published some time in April.

While much of the work the group has completed thus far has revolved around the gathering of vulnerability formats and the various methods used to identify and remediate the coding problems, the project has recently involved a significant amount of testing of security scanning tools to get a better idea of the capabilities and limitations of those products.

By gaining an understanding of the vulnerabilities that popular code scanning engines can find -- and those they can't -- CWE can help developers understand the types of issues they will need to look for on their own, said Bob Martin, a CWE leader and the head of Mitre's related CVE (Common Vulnerability Exposures) Compatibility effort.

"We wanted to evaluate what the tools claim to cover and what they are most effective at finding," Martin said. "Right now, best test is to throw tools at a big pile of code and see what tools find the most vulnerabilities, but we're changing that paradigm into test cases where we now look at the answers so we can evaluate what the tools found and what kinds of complexities they can handle."

CWE's research will not list the names and performance results of the products it is testing -- provided by over 20 firms, including Cenzic, Fortify, SPI Dynamics, Veracode, and Watchfire -- but the work to compile a resource that offers developers an idea of the types of vulnerabilities missed by the tools should provide a great deal of value, Martin said.


Reprinted with permission from

For more enterprise computing news, visit Infoworld.com
Story copyright 2006 InfoWorld Media Group, Inc. All rights reserved.

Jump to comments

black hat 2007

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs