Skip to main content
Home
  • Agile
  • Manage
  • Test
Register
Log In
  • Home
    • TechWell.com
  • My Page
  • Communities
    • Agile
    • Manage
    • Test
  • Interact
    • Blogs
    • Forums
  • Resources
    • Articles
    • Better Software
    • Download Center
    • News Center
    • Podcasts
  • Events
    • Web Seminars
    • Conferences
    • Training
  • Jobs
  • Membership
  • Feedback
  • Contact Us

Coverity Plans New Tool to Help Developers Fight SQL Injections

News Article

Coverity Plans New Tool to Help Developers Fight SQL Injections

News Article by Jonathan Vanian | Comments: (0) | Mon, 06/11/2012 - 8:12pm
  • Login or register to post comments
  • Print

If you hate SQL injections and other malicious attacks, San Francisco-based Coverity has got you covered. Coverity, a developer of static code analysis tools, announced new methods for static analysis testing, which the company says “will empower development teams to effectively address security defects in Java web applications.”  

From the announcement:

Coverity has extended static analysis to deeply understand both source code and modern web application architecture, providing greater accuracy and remediation guidance to help developers find and fix security defects that can lead to the most commonly exploited vulnerabilities, including SQL injection and cross-site scripting. Designed from the ground up to analyze web applications from the developer's point of view, Coverity's new technology addresses the complexity of modern web applications and enables developer adoption of static application security testing in a way that the shallow, incomplete analysis of first-generation tools failed to achieve.

Joab Jackson of IDG News, via PC World has the details on what Coverity has up its sleeves and writes that the company is planning a September release of the new product tentatively titled “Coverity Development Testing for Web Application Security.”

From IDG News, via PC World:

Coverity's static code analyzer will tackle one of the heretofore trickiest issues of analyzing Web applications, that of dealing with frameworks. Frameworks are libraries of code from which developers often borrow to carry out common tasks in their programs. For static analysis, however, frameworks can be problematic, because the code being examined just points to a framework function, and, as a result, fails to offer the full picture of what actions are taking place when the program is executed. Coverity's approach is to design the tool in such a way that it also examines the full framework calls. The first version of the software will support the two most popular JEE frameworks, Hibernate and Spring.

The software will also include what the company calls a white box fuzzer, to check data sanitization routines. Data sanitizers are often used to check for malicious or otherwise harmful user input. Data sanitizers, however, could be incomplete or improperly configured; the fuzzer will check for weaknesses in the sanitizer.

Over at eSecurity Planet, Sean Michael Kerner talked to Andy Chou, CTO of Coverity, who explained how the new tool will deal with those pesky SQL injections.

From eSecurity Planet:

"Developers aren't security experts and they don't understand how to fix problems, even if they understand the problem," Chou said. "So we give them very actionable advice, so they know where the problem is in the code as well as how to fix the problem properly."

For example, with a SQL Injection vulnerability, fixing the problem in the source code often depends on the context. Chou noted that in general, the best practice when it comes to mitigating SQL Injection attacks is to change queries to prepared queries. With prepared queries, a SQL statement is specifically defined, which can limit the risk from random queries. Chou stressed that his company's new tool is going a step further by visually showing developers where the SQL statement is in their code and how they should actually go about changing it within the context of the application.

 

  • Test & Evaluation
  • Coverity
  • SQL injection

More like this

  • Better Software & Agile Development Conference West
  • You Can't Fight Change
  • Keeping Secrets
  • Sticky ToolLook Interview: Improving QA-Development Communication with Amit Chopra
  • A Word with the Wise: Assessment First with David Dang

Welcome to TechWell!

With an ever-expanding library of content by industry experts, TechWell is your source for software knowledge. The site is still growing, so please pardon our dust. If you see anything that requires our attention, please CONTACT us.

Not a member? REGISTER to join our community.
Already a member? Log In

Hot Topics

  • Most Read
  • Most Discussed
  • Most Shared
  • New Downloads

Management Myth #1: The Myth of 100% Utilization

Article by Johanna Rothman | Comments (17)
 A manager took me aside at a recent engagement. “You know, Johanna, there’s something I just don’t understand about this agile thing. It sure doesn’t look like everyone is being used at 100 percent... Read More

Edit Those Epics

Article by Johanna Rothman | Comments (23)
 I've been working with folks making their transition to agile. One of the hardest transitions is for the managers and technical leaders.Managers are accustomed to working in timeboxes. To them, the... Read More

Three Components of Effective Defect-management Systems

Article by Krishen Kota | Comments (3)
 From a high-level view, defect management systems are made up of a combination of some defect management tools or tool and a defect management process. These two primary components work together to... Read More

Passing the Baton

Article by Rinku Sahay | Comments (2)
 I was watching a relay race recently. A relay is where members of a team take turns to perform and complete a certain action or activity. In a relay race, one team member passes a baton to another... Read More

Three Components of Effective Defect-management Systems

Article by Krishen Kota | Comments (3)
 From a high-level view, defect management systems are made up of a combination of some defect management tools or tool and a defect management process. These two primary components work together to... Read More

The Optimists Don't Make It Out

Blog Post by Lee Copeland | Comments (2)
 There’s only one advantage to delayed flights, missed connec­tions, and extra nights stuck in hotels far away from home—you can catch up on your reading. The book at the top of my “to read” list was... Read More

Considering the Modern Technology Career

Article by Matthew Heusser
 Software development is a young field, at least compared with established professions like law and medicine. The choice to work in software is likewise a different choice. It is often made in youth... Read More

Testing Tradeoffs and Project Risk: A Case Study

Article by Payson Hall
 The project had issues. It was a two-year project intended to swap an aging legacy application for a commercial product. The vendor’s off-the-shelf software required some customization and extension... Read More

The ROI of Learning for Testers

Article by Lisa Crispin
  During my software career, I’ve spent a lot of time and effort learning new thinking and technical skills. I’ve encouraged my peers to do the same. The series that Janet Gregory and I wrote on... Read More

The Top 5 Frustrations for Project Managers

See how you can avoid management swoop-in at the eleventh hour, or creating and sending around a dreaded 200-page plan that no one has time to read once, let alone every time a change occurs. We've... Read More - Get this content

Follow Us On...

Follow us on Twitter
Twitter
Follow us on Facebook
Facebook
Follow us on LinkedIn
LinkedIn
Follow our RSS feed
RSS Feed

Sponsors

  ASTQB
  HP Software
  Microsoft
  Neustar
  SQE Training
  SmartBear Software
  Tricentis


Our Bloggers

Johanna Rothman is a management consultant and a regular StickyMinds.com and Better Software magazine columnist.

Steve Berczuk is an engineer and ScrumMaster at Humedica where he's helping to build next-generation SaaS-based clinical informatics applications.

Naomi Karten is a highly experienced speaker and seminar leader who draws from her psychology and IT backgrounds to help organizations improve customer satisfaction, manage change, and strengthen teamwork.

Lee Copeland has more than thirty years of experience in the field of software development and testing.

Lisa Crispin has worked as a tester on agile teams for the past ten years, and enjoys sharing her experiences via writing, presenting, teaching and participating in agile testing communities around the world.

Claire Moss has been testing software for 8 years. Although authoring a testing blog and articles are new for her, Claire has always had a passion for writing, which might be a strange trait for a Discrete mathematician.

Site Contents
Back To Top
  • » My Page
  • » Communities
    • - Agile
    • - Manage
    • - Test
  • » Solution Central
    • - HP Solution Center
  • » Interact
    • - Blogs
    • - Forums
  • » Resources
    • - Articles
    • - Better Software Magazine
    • - Download Center
    • - News Center
    • - Podcasts
    • - Videos
  • » Events
    • - Web Seminars
    • - Conferences
    • - Training



Techwell

  • Terms of Use
  • Privacy Policy
  • RSS
  • Site Feedback
  • Subscription Services