Home
Products
Detect Vulnerabilities
PTA in Testing
The Program Trace Analyzer (PTA) finds vulnerabilities that can be identified more easily while an application is running. It integrates into a QA test to find vulnerabilities while a functional test is being conducted on an application.
PTA enables a QA group to find security vulnerabilities and leaks while conducting a functional test. Working on the application server, PTA takes a QA test and analyzes what could happen if each input was malicious. This new approach enables QA testers to uncover security vulnerabilities in the application with no additional work.
When results from Fortify PTA are integrated with those from the Source Code Analyzer, the user gets a more prioritized list of vulnerabilities. By integrated static and dynamic analysis, the user can generate a more accurate and prioritized list of vulnerabilities
PTA sits on the application server and watches the application from the inside, analyzing how and where information flows. With this unobstructed view into the application, while it’s being exercised, PTA is able to accurately identify vulnerabilities.
Unlike traditional security testing solutions, which were designed for security experts and require configuration and extensive customization, PTA works on its own to uncover security vulnerabilities while a QA tester conducts a functional test. The results are sent to a central console that allows for triage and remediation, or can be sent to developers via bug tracking systems
PTA provides the exact line of code for each vulnerability and makes it easy to reproduce the issue. Most solutions provide the URL and force testers or developers to search the code for the location of the vulnerability. PTA’s unique position on the application server gives it the ability to report the lowest level of detail.
PTA works with any QA test, whether it’s an automated tool, such as those from Mercury and Borland, or any manual test, and is easily installed on an application server in minutes.
PTA Helps Prevent
PTA Identifies the Following Vulnerabilities
Contact me about products from Fortify Software
"We strongly believe that Fortify's holistic approach to application security - implementing security during all stages of development, rather than after the fact - proactively helps eliminate business risk and truly safeguards our enterprise against today's ever-changing security threats."
Craig Shumard, CISO, CIGNA
"We looked into a number of tools and tested them against our source base. The vast majority of them could not handle the size, scope and nature of our applications. Of all the products we tested, Fortify came closest to our technical requirements."
Oracle
"Fortify is one of the largest SAST vendors, with strong innovation as well as execution capabilities. It has expanded its technologies beyond SAST into a broader spectrum of application security disciplines that supplement its core SAST capabilities."
Gartner MQ
"Auditing at the source code level is the best way to protect applications early in the SDL. Fortify SCA will give us the opportunity to fix vulnerabilities before we push out new versions of our applications. In our view, the alternative is a security breach, and that is simply unacceptable."
Mark Crockett, Vice President of Technology and CTO of Informa Investment Scorecard
"Fortify is one of the largest SAST vendors, with strong innovation as well as execution capabilities. It has expanded its technologies beyond SAST into a broader spectrum of application security disciplines that supplement its core SAST capabilities."
Gartner MQ
"We are very pleased with our decision to integrate Fortify products into our source code review and applications security audit processes"
Rick Dakin, QSA and Cofounder of Coalfire