Microsoft coders get a bug-catcher

By Robert Lemos, CNET News.com
Monday, February 10, 2003 09:31 AM
Microsoft developers now have a new tool to help them catch security bugs in their own code.

The software giant plans to announce later today that a plug-in created by security firm Sanctum, scheduled for release in March, will be the first to easily integrate with Microsoft's development platform Visual Studio .Net. The tool, AppScan Developer Edition 1.5, can be run on Web applications in real time to catch common programming flaws.

"The cool thing with the integration with Visual Studio is that, because it's there in your face, you run it early and you run it often," said Michael Howard, senior program manager for Microsoft and the author of the company's textbook on secure programming. "You can find issues before they get far down the development path, before they become expensive to remove."

The announcement comes as Microsoft moves into the second year of its "Trustworthy Computing" initiative, the most visible part of which is its push to heighten product security. Last year, the company spent more than two months and US$200 million dollars training its own developers in secure programming.

Tools like Sanctum's go a long way toward moving that training outside Microsoft to the independent developer community, said Michael Kass, product manager for Microsoft's .Net Framework.

"There are two sides to Trustworthy Computing," Kass said. "First, training our developers and making sure that we ship more secure applications. The other side is evangelizing best practices."

Until now, Sanctum had primarily been providing products to security consultants and network auditors, which would use AppScan 3.5 to test Web sites and applications for commons security flaws. With AppScan DE 1.5, Sanctum is moving its product up the development chain to catch bugs early, said Ben Straley, the company's product marketing manager.

"The way that we look at the application lifecycle is that there is a role for (testing) at every stage," he said. "Moreover, (AppScan DE 1.5 is) not just a useful testing tool, it is an educational tool as well."

AppScan DE 1.5 goes on sale in March. No price has yet been announced.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Keep IMAP e-mail messages locally using OfflineIMAP

Open Source

Vincent Danen discusses the uses of OfflineIMAP for synchronizing local and remote IMAP mailboxes and providing a good method for backing up e-mail.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except..... by Lee Lup Yuen

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web