Home > Microsoft .Net Development News > Compuware updates ASP.NET security tool
Microsoft .Net Development News:
EMAIL THIS

Compuware updates ASP.NET security tool

By George Lawton, Contributor
30 Jan 2006 | SearchVB.com

ASP.NET Channel
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Compuware Corp. has announced the general availability of Compuware DevPartner SecurityChecker 2.0, which is a suite of tools for analyzing and repairing security problems in ASP.NET Web applications. The tool consists of components for integrity analysis, compile-time analysis and run-time analysis. The product will make its debut at VSLive! 2006 in San Francisco.

Run-time analysis includes the ability to find things like excessive account privileges. Compile-time analysis, meanwhile, finds things like debugging being left enabled by the developer or inheritance threats. The integrity analysis, sometimes called penetration testing, is good at finding holes for cross-site scripting attacks, SQL injection attacks, parameter tampering, and buffer overflow.

While a number of companies offer tools for integrity and compile-time analysis, Compuware says this is the only tool that does run-time analysis. Being able to run the analyses simultaneously also provides tighter security, said Ken Cowan, DevPartner Product Line Manager, Compuware.

"The interesting thing about the two white box modes [run-time and compile-time analysis] is we can find bugs specific to using .NET framework technologies and bugs in how you are using Windows features," Cowan said. "For example, if you are opening a file for read/write access and only reading, you can change the mode so someone cannot change the file. Those two technologies minimize the attack surface. If someone does get in somehow, they will not be able to do as much damage."

Tight integration with the Visual Studio development interface makes it easy to check code while programming. When the SecurityChecker finds a vulnerability, the user can double click on it, and the checker takes a user to the line of source code where the vulnerability was found. The user does not have to search the application to find the problem.

The white box tools also make it possible to find security bugs sooner in the development process, where they are far cheaper to fix. "In particular with security bugs, when you find something early, the developer learns not to make the same mistake again," Cowan noted.

Other important enhancements in SecurityChecker 2.0 include the following:

  • Full integration with Visual Studio 2005 and .NET Framework 2.0.
  • Thirty new integrity analysis rules. Some of the most significant include a rule that searches for Google hacks, in which an attacker can look for pages like login.asp that could be easy to penetrate. Another rule looks at the ability to force an application into debug mode, which would reveal information about it. There is also a rule for finding cross-site scripting attack vulnerabilities that circumvent the ASP.NET validation procedure.
  • Improvements to the discovery map, which uses a new view with simplified lists of pages discovered during the process.
  • A security assessment service based around SecurityChecker, in which Compuware consultants will analyze your applications for you.

    Initially, the license does not include access to security updates, although Compuware plans to do so in the future. "The thing about application security is that it is not like the virus world, where there are new vulnerabilities popping up every day. The urgency is not as great," said John Carpenter, DevPartner SecurityChecker Product Manager, Compuware.

    The list price for SecurityChecker 2.0 is $12,000 per concurrent user. Cowan said this is generally sufficient for the average software development team.

    Return to the VSLive 2006 home page

    Tags: .NET Framework Web application securityASP.NET development toolsVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    .NET Framework Web application security
    Security interoperability with .NET/WSE and WebLogic Workshop 8.1
    On ASP.NET AJAX testing and debugging tools
    Ajax security holes and how to fill them
    Need Web services security? Dig into WSE 3.0 for Microsoft .NET
    DevPartner SecurityChecker 2.5 does just that for ASP.NET sites
    VSLive: Membership and security in ASP.NET apps
    Test and debug an ASP.NET app: Chp. 4 of Murach's ASP.NET 2.0 Web Programming with C# 2005
    Learning Guide: Top 10 most critical Web application security vulnerabilities
    How to build secure ASP.NET applications
    How to build secure ASP.NET applications

    ASP.NET development tools
    How to use jQuery to solve Javascript browser compatibility problems
    Microsoft webcast series previews new Visual Studio 2010 features
    Visual Studio's IntelliSense for jQuery doesn't autocomplete correctly
    Dundas Map for .NET kicks up geographic visualization
    Use PHP with Visual Studio to create Web sites
    VB code: Internet application downloads
    Set of ASP.NET controls addresses data entry
    Spring.NET 1.1 brings AOP to .NET development
    ComponentArt adds editor, spell checker to ASP.NET UI tool
    ComponentOne adds rich-text editor to Studio Enterprise

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    ASP.NET  (SearchWinDevelopment.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • Development Solutions - Silverlight, WinForms, ASP.NET
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts