| By Open Source News | Article Rating: |
|
| July 31, 2006 09:00 AM EDT | Reads: |
5,003 |
"OWASP is assembling the most comprehensive guide to application security principles, threats, attacks, vulnerabilities, and countermeasures ever attempted," said Jeff Williams, chairman of OWASP. "Integrated with the rest of our materials, Fortify Software's vulnerability research will help anyone acquiring, designing, building, testing, or deploying critical applications make informed decisions about application security."
The classification of software security errors entitled the "Seven Pernicious Kingdoms" organizes security vulnerabilities into seven top level sets of security problems that can be used to help software developers understand the types of coding errors that can increase security risk. By better understanding how systems fail, developers will better analyze the software they create, more readily identify and address security problems when they see them, and generally avoid repeating the same mistakes in the future.
"When put to work in an analysis tool, a set of security rules organized according to this classification is a powerful mechanism for reducing security risk," said Dr. Brian Chess, Chief Scientist at Fortify Software. "Software development practices have only just begun to look at the myriad of ways security problems factor into coding -- making a classification like this available should provide tangible benefits to the software security community."
Together with a research team that included Katrina Tsipenyuk of the Fortify Security Research Group and Gary McGraw, the chief technology officer of Cigital, Dr. Chess identified 115 security vulnerability categories present in today's software and organized them in top-level "kingdoms" which include: Input Validation and Representation, API Abuse, Security Features, Time and State, Errors, Code Quality, Encapsulation
Published July 31, 2006 Reads 5,003
Copyright © 2006 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Open Source News
Enterprise Open Source News Desk trawls the fast-growing world of Professional Open Source for business-relevant items of news, opinion, and insight.
![]() |
enterprise open source news desk 07/31/06 09:47:43 AM EDT | |||
Fortify Software announced that it has contributed an extensive classification of software security errors to the non-profit Open Web Application Security Project (OWASP). The classification of 115 security vulnerability categories will help software developers and security practitioners understand the common coding mistakes that affect software security and more readily identify security problems. |
||||
- Microsoft Tries Hadoop on Azure
- Asynchronous Logging Using Spring
- StorSimple Supports OpenStack
- What to Expect in 2012: Cloud Computing and Open Source Software
- Will PaaS Finally Bring Open Source Love to the Enterprise?
- AT&T Joins OpenStack, Floats Cloud Architect
- Linux Virtualization and Tired Open Source Myths
- Red Hat Sets Up GlusterFS Advisory Board
- OpenOffice.com Lives
- Selecting a Business Intelligence Solution
- Cloud Computing: A Platform-First Approach
- Forrester Wave: Open Source Business Intelligence
- Adobe Sends Flex to the Apache Foundation
- i-Technology in 2012: Five Industry Predictions
- Microsoft Tries Hadoop on Azure
- OpenXava 4.3: Rapid Java Web Development
- Asynchronous Logging Using Spring
- StorSimple Supports OpenStack
- What to Expect in 2012: Cloud Computing and Open Source Software
- Will PaaS Finally Bring Open Source Love to the Enterprise?
- AT&T Joins OpenStack, Floats Cloud Architect
- More Use Cases for Big Data Analytics
- Linux Virtualization and Tired Open Source Myths
- Red Hat Sets Up GlusterFS Advisory Board
- After Ubuntu, Windows Looks Increasingly Bad, Increasingly Archaic, Increasingly Unfriendly
- SCO CEO Posts Open Letter to the Open Source Community
- Simula Labs Launches Hosted Delivery Platform To Enable Enterprise Open Source Adoption
- Where Are RIA Technologies Headed in 2008?
- Source Claims SCO Will Sue Google
- How Open Is "Open"? – Industry Luminaries Join the Debate
- Latest SCO News is Plain Weird
- SCO Claims Linux Lifted ELF
- IBM Tells SCO Court It Can't Find AIX-on-Power Code
- Flashback: Investing in 'Professional Open Source' - Exclusive 2004 Interview with David Skok, Matrix Partners
- Developing an Application Using the Eclipse BIRT Report Engine API
- HP Starts Pushing Desktop Linux

















