Home
Products
Fortify 360
Vulnerability Detection
Identify Vulnerabilities in your Software
Detection of security vulnerabilities in software is an essential element of every Software Security Assurance program. Detection must be accurate and provide visibility into the source of the problem, not just report on the symptom. This helps software developers quickly identify problems early in the development lifecycle when they are far cheaper to fix.
Fortify 360 provides comprehensive, root-cause detection of more than 400 types of software security vulnerabilities across 17 development languages and 600,000 software component APIs - the most in the industry today.
Identify Vulnerabilities throughout the Development Lifecycle
With Fortify 360, organizations have greater flexibility over how they identify vulnerabilities. Using Fortify 360's three static and dynamic analyzers, vulnerabilities can be identified during the development or quality assurance phase of a project or even after the application has been deployed. To ensure that the most serious issues are addressed first, Fortify 360 correlates and prioritizes results from the analyzers to deliver an accurate, risk-ranked list of issues ready for remediation.
Static Analysis of Source Code
Fortify 360's static Source Code Analyzer (SCA) provides root-cause identification of vulnerabilities in source code. SCA is guided by the largest and most comprehensive set of secure coding rules and supports a wide array of languages, platforms, build environments and integrated development environments (IDEs).
Dynamic Analysis of Programs during Testing
Fortify 360's dynamic Program Trace Analyzer (PTA) provides root-cause identification of vulnerabilities during the QA process. Because Fortify 360 PTA works in the background during the application testing process, organizations can easily use their existing test suites and processes to identify vulnerabilities.
Dynamic Analysis of Applications in Production
Fortify 360's dynamic Real-Time Analyzer (RTA) provides root-cause identification of vulnerabilities after an application has been deployed into production. RTA monitors critical software functions and application programming interfaces (APIs) from inside the application itself, provides root-cause identification of vulnerabilities in a real world context.
360 Correlated Analysis
To ensure accurate risk severity, Fortify 360 correlates the results from across its multiple analyzers. This provides an accurate picture of an application's security and ensures development is addressing the most significant issues first.
Contact me about products from Fortify Software
"We strongly believe that Fortify's holistic approach to application security - implementing security during all stages of development, rather than after the fact - proactively helps eliminate business risk and truly safeguards our enterprise against today's ever-changing security threats."
Craig Shumard, CISO, CIGNA
"We looked into a number of tools and tested them against our source base. The vast majority of them could not handle the size, scope and nature of our applications. Of all the products we tested, Fortify came closest to our technical requirements."
Oracle
"Fortify is one of the largest SAST vendors, with strong innovation as well as execution capabilities. It has expanded its technologies beyond SAST into a broader spectrum of application security disciplines that supplement its core SAST capabilities."
Gartner MQ
"Auditing at the source code level is the best way to protect applications early in the SDL. Fortify SCA will give us the opportunity to fix vulnerabilities before we push out new versions of our applications. In our view, the alternative is a security breach, and that is simply unacceptable."
Mark Crockett, Vice President of Technology and CTO of Informa Investment Scorecard
"Fortify is one of the largest SAST vendors, with strong innovation as well as execution capabilities. It has expanded its technologies beyond SAST into a broader spectrum of application security disciplines that supplement its core SAST capabilities."
Gartner MQ
"We are very pleased with our decision to integrate Fortify products into our source code review and applications security audit processes"
Rick Dakin, QSA and Cofounder of Coalfire