Interview : Why fortified software is a safer bet

Fortify chief John Jack explains how his firm helps developers build security into their code

Written by Dave Bailey

If you were one of the many thousands of people who placed a bet on this year’s Grand National, the chances are that the security of that transaction was being monitored by application security software developed by Fortify, a little-known firm based in San Mateo, California.

Fortify produces tools used by other software devlopers to constantly monitor security throughout a product’s lifecycle ­ a process known as business software assurance (BSA). “We’re in the business of helping enterprises to progress from developing high-quality, high-performance software to developing high-quality, high-performance software with built-in high security,” said Fortify chief executive John Jack.

The latest version of Fortify’s BSA package is Fortify 360 (F360), a software suite launched in March that is designed to analyse code development throughout the software lifecycle, including the planning, coding, testing, deployment and maintenance phases.

Fortify’s system is a natural evolution in software security, according to Jack. “Just as firms deploy anti-virus systems throughout their business to secure their employee’s systems, firms are looking for a partner to secure their business-to-business and business-to-consumer applications,” he said.

The tool works primarily by checking code at the software compilation and build stage. “Our package finds defects in software code, demonstrates why a defect is an issue and sets out what to do to fix it,” said Jack. “The package works when you’re developing code and also when that code has been signed off, deployed and is running in your datacentre ­ it’s constantly checking for online attacks.”

The company has a dedicated team of researchers checking for software vulnerabilities, and once a quarter their findings are used to update Fortify’s BSA package to ensure its accuracy when auditing code.

A roll call of Fortify’s customers includes many of the world’s largest banks, independent software vendors and industry giants such as Oracle. One area that has proved particularly lucrative for the company in recent years is online gambling, where customers include www.bwin.com and www.betfair.com. “Bwin has adopted our F360 system to secure its online betting site. It is facing attacks from organised crime syndicates, especially from eastern European countries not yet part of the EU,” Jack said.

He explained that the problem these online gambling sites had was that “it was very difficult to tell whether the person who’d just won £1m through that site did so on behalf of hackers who supplied them with information allowing them to beat the odds”.

Another problem highlighted by Jack is that developers often fail to differentiate between everyday software bugs and those that give rise to security issues. “The difference is that if customers find a bug in software, then they’ll phone up and talk to you about it; if a hacker finds a bug, he won’t phone you up,” Jack said.

Ideally, developers should focus on areas where security flaws might cause a major problem, he said. “With security, you can’t fix every issue, so you have to make business risk decisions. For example, an internal human resource tracking application that doesn’t face the web will not be as highly exposed as software dealing with online betting,” Jack added.

Another software security issue that has come to prominence in the past few years is the problem of compliance ­ making sure that software is certified as fit for purpose. Jack said there are two key areas to consider when it comes to meeting compliance mandates around software security. “The first is demonstrating that the application has been coded securely in the first place, by providing the reports and audit trails required by the regulation or statute,” he said.

The second area is the need to assure protection of these applications when they are in a live production setting. “Our Real Time Analysis system sits inside the application itself, providing thorough protection as well as the detailed attack forensics that are needed, not only for reporting purposes, but to give developers the information they need to address the underlying problem,” he said.

Tags:

reader comments

related articles

hacker

Web threats continue to rise

Latest Symantec threat report finds a big increase in site specific attacks 08 Apr 2008

 

Borland and CodeGear tout better software development

Enhanced support for distributed development teams and code re-use 01 Apr 2008

Firms being left behind by criminals

Response times are too slow to worry hackers, say experts 10 Apr 2008

related whitepapers

today's top stories

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Are you worried about your job prospects in IT over the next 12 months?

Are you worried about your job prospects in IT over the next 12 months?

Will the economic crisis affect your job prospects?

Previous poll results

Latest audio and video articles

Remote workerVideo

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Latest in-depth articles

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Comment

Broadband must be a spending priority

For the economic health of the nation, the government would do better to bankroll an optical fibre rollout rather than prop up profligate banks 09 Oct 2008

Advertisement

Primary Navigation