SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Integrating IT >> Tools and Languages

Oracle secures source code

Oracle secures source code

By:  Stacy Cowley and Paul Roberts  On: 19 Jan 2006 For: IT World Canada Creator
 

New technology aims to lessen software bugs By Stacy Cowley and Paul Roberts Source-code security developer Fortify Software Inc. is giving Oracle Corp.’s database and middleware software a security boost with tools that seek out source-code vulnerabilities at the development stage.

New technology aims to lessen software bugs By Stacy Cowley and Paul Roberts Source-code security developer Fortify Software Inc. is giving Oracle Corp.’s database and middleware software a security boost with tools that seek out source-code vulnerabilities at the development stage.

Fortify’s software is an integrated collection of tools that scan code for secure coding policy violations and other weaknesses. Oracle has licensed the tools for its Server Technologies group, which handles development of its database, application server, identity management and collaboration suite software.

Oracle, in Redwood Shores, Calif., has been searching for automated tools to examine its source code, and Fortify was the company to provide that, said Mary Ann Davidson, CSO at Oracle. Last year, Fortify unveiled two new product suites - one to inspect source code written in the C++ and Java programming languages, and the other to probe security holes in software applications.

Oracle has a code base of more than 30 million lines, and is the first top-tier commercial software developer to sign on as a Fortify customer. Other Fortify clients include Flash maker Macromedia Inc. and a number of financial services companies.

By eliminating vulnerabilities before code turns into shipped product, Oracle hopes to improve its customers’ security by reducing the number of patches it needs to issue.

“There are lots of band-aid products out there that protect against attacks. You wouldn’t need so many band-aids if you could actually have a vaccine,” Davidson said.

Oracle has taken a few hits on its security reputation last year after issuing a spate of critical patches.

Fortify said its tools help strengthen software applications by spotting and removing common vulnerabilities like buffer overflows, format string errors and unchecked input from the product code early in the development process.

Fortify uses technology called “extended static checking” that analyzes the properties of software code rather than the behavior of finished program, said Brian Chess, chief scientist at Fortify.

Most source code analysis products work by trying to “stimulate” finished software applications with long lists of data and produce an invalid response.

Extended static checking allows Fortify’s tools to enumerate all the paths in computer code that can take action or “execute,” quickly spot sensitive areas in the computer code, then determine the exact limits of the vulnerability, Chess said.

QuickLink 069994


Sign up for our Newsletters

 












Print |  Views: 1078   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Stacy Cowley and Paul Roberts Stacy Cowley and Paul Roberts is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Recent Canadian IT Jobs




Related Content

Oracle's patch update offers 41 fixes
Oracle's patch update offers 41 fixesOf the vulnerabilities, 15 could be exploited remotely without a user name or password. Plus, why it pays to hold off installing modules you don't need
Oracle ships critical update for database, applications
Oracle ships critical update for database, applicationsWhile it continues its pursuit of BEA, the company takes a moment to focus on its own product line, fixing 51 vulnerabilities. Find out what's wrong with the import utility
Code right and don't let the bugs bite, says Microsoft
Code right and don't let the bugs bite, says MicrosoftMicrosoft’s security development lifecycle (SDL), a methodology for secure software development, is going beyond the corporate walls of the Redmond, Wash.-based software firm and into the hands of enterprise software producers, according to company executives.
Why hack a Mac?
by joaquim p. menezes - remember charlie miller? 
blog comments powered by Disqus