All the latest UK technology news, reviews and analysis

Comsec launches code checking service

by Phil Muncaster

14 Jul 2009

Be the first to comment

  • Tweet this
Code
Secure code is vital to get right from the start

Security firm Comsec Consulting today launched a new on-demand code review service designed to improve the security of developers' code.

Codefend allows developers to send non-compiled code to Comsec, where it is analysed for security vulnerabilities and threats by automated code analysis tools as well as human experts.

The service could reduce code rewrite costs by as much as half, according to the firm, and, being an outsourced service, is more cost efficient than purchasing in-house tools.

Codefend is able to find common vulnerabilities as detailed by the Open Web Application Security Project Top 10 and the Sans Top 25, as well as more complex vulnerabilities such as filter evasions, injections and race conditions.

The human analysis, meanwhile, can remove false positives and detect business logic flaws, according to the firm.

Stuart Okin, UK managing director at Comsec, argued that commercial pressures to release software as soon as possible often mean that security is overlooked in the development process.

"In the security profession we have been saying this for years," he said. " Don't get me wrong: firewalls and anti-virus are important but, if you have a code vulnerability such as a filter evasion, cross site scripting or whatever, malware will get straight through the firewalls as if they don't exist."

Ed Gibson, chief security advisor at Microsoft UK, agreed that firms could save significant sums of money by detecting flaws in code early on. He quoted figures from the American National Institute of Standards and Technology suggesting that eliminating flaws in the design stage can cost 30 times less than fixing them after release.

Gibson added that, because the service is outsourced, it may attract smaller firms that do not have the in-house expertise to undertake such checks.

"These capabilities will take away any reason not to have your code checked because you don't need someone in-house full time," he said.

"[Code review] has become more important given the continuing and more targeted attacks by miscreants, organised crime and state sponsored."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

25%

1%

11%

63%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Senior Infrastructure Project Manager

Our highly successful client urgently requires Senior...

Senior Infrastructure Project Manager

Our highly successful client urgently requires Senior...

Senior Infrastructure Project Manager

Our highly successful client urgently requires Senior...

east midlands

Our client, a highly successful and currently market...

To send to more than one email address, simply separate each address with a comma.