Fortify Software

Fortify Software

Home Products Fortify 360 Vulnerability Detection

Vulnerability Detection

Identify Vulnerabilities in your Software
Detection of security vulnerabilities in software is an essential element of every Software Security Assurance program. Detection must be accurate and provide visibility into the source of the problem, not just report on the symptom. This helps software developers quickly identify problems early in the development lifecycle when they are far cheaper to fix.

Fortify 360 provides comprehensive, root-cause detection of more than 400 types of software security vulnerabilities across 17 development languages and 600,000 software component APIs - the most in the industry today.

Identify Vulnerabilities throughout the Development Lifecycle
With Fortify 360, organizations have greater flexibility over how they identify vulnerabilities. Using Fortify 360's three static and dynamic analyzers, vulnerabilities can be identified during the development or quality assurance phase of a project or even after the application has been deployed. To ensure that the most serious issues are addressed first, Fortify 360 correlates and prioritizes results from the analyzers to deliver an accurate, risk-ranked list of issues ready for remediation.

Capabilities
Advantages

Static Analysis of Source Code

Fortify 360's static Source Code Analyzer (SCA) provides root-cause identification of vulnerabilities in source code. SCA is guided by the largest and most comprehensive set of secure coding rules and supports a wide array of languages, platforms, build environments and integrated development environments (IDEs).

Dynamic Analysis of Programs during Testing

Fortify 360's dynamic Program Trace Analyzer (PTA) provides root-cause identification of vulnerabilities during the QA process. Because Fortify 360 PTA works in the background during the application testing process, organizations can easily use their existing test suites and processes to identify vulnerabilities.

Dynamic Analysis of Applications in Production

Fortify 360's dynamic Real-Time Analyzer (RTA) provides root-cause identification of vulnerabilities after an application has been deployed into production. RTA monitors critical software functions and application programming interfaces (APIs) from inside the application itself, provides root-cause identification of vulnerabilities in a real world context.

360 Correlated Analysis

To ensure accurate risk severity, Fortify 360 correlates the results from across its multiple analyzers. This provides an accurate picture of an application's security and ensures development is addressing the most significant issues first.

 

Sign up for a Free Trial

Contact me about products from Fortify Software

Fortify in the news

Contact Fortify Software

eNewsletter Sign Up | Software Security Blog | Contact Us | Privacy