| By Marketwire . | Article Rating: |
|
| February 4, 2013 06:01 AM EST | Reads: |
592 |
COLUMBIA, MD -- (Marketwire) -- 02/04/13 -- Aspect Security, a pioneer in application security, today announced the availability of Contrast Enterprise On-Premise (EOP) Edition. Contrast EOP passively gathers security-relevant data directly from inside an organization's portfolio of running applications, then applies a powerful combination of static, dynamic, and runtime analysis to identify vulnerabilities, security architecture, and library problems without any need for security experts.
"Automation is the only way to secure an entire application portfolio -- but today's website and code scanning tools take forever and make too many mistakes -- worst of all, they require experts, so they don't scale," explained Jeff Williams, CEO Aspect Security. "Contrast EOP empowers an enterprise with realtime application security intelligence for every application, starting with the first line of code and continuing through system test, quality assurance, and even into production."
Contrast is the first truly scalable application security solution. Organizations can enable their application servers with Contrast in just seconds, and leverage their existing development and testing teams to get security coverage. Enterprise developers will enjoy an unprecedented level of clear, actionable guidance. In fact, Contrast is so easy to use that a 14-year-old developer found and correctly fixed 6 Cross Site Scripting (XSS) and 2 SQL Injection flaws in 30 minutes.
The secret to Contrast's unparalleled coverage and accuracy is the ability to access a wealth of data about the code, the runtime environment, HTTP traffic, and even runtime data flows -- far more data than traditional application security tools. This wealth of information combined with Contrast's innovative application vulnerability fingerprinting algorithms enables Contrast to identify more vulnerabilities, cover more code, and produce less false alarms than other application security technologies.
"With Contrast, organizations can break out of the penetrate-and-patch culture, and fix problems early in the SDLC," said Williams. "Contrast is compatible with real-world software development practices, including Agile and DevOps techniques. No more out-of-date paper-based vulnerability reports, annual scans, or pre-launch security surprises."
Contrast also protects organizations against insecure and improperly used open source components. Aspect Security researchers recently announced their discovery of a new remote code execution vulnerability in the Spring Framework, an open-source web application framework. Over 22,000 organizations worldwide downloaded susceptible versions of Spring over 1.3 million times last year alone. Contrast is the only automated tool that can identify this type of expression-language injection vulnerability in addition to many other types of complex, significant vulnerabilities.
Contrast research was sponsored in part by the Air Force Research Laboratory (AFRL). Contrast Enterprise on Premise is available now, starting at $4,800 per application per year.
About Aspect Security
Founded in 2002, Aspect Security focuses exclusively on application security, ensuring that the software that drives business is protected against hackers. Aspect Security's researchers analyze, test and validate on average of 5,000,000 lines of critical application code every month and the company unearths more than 10,000 vulnerabilities every year. Aspect is a founding member of the Open Web Application Security Project (OWASP), and has made vast industry contributions including the OWASP Top Ten, Enterprise Security API (ESAPI), Application Security Verification Standard (ASVS), Risk Rating Methodology, and WebGoat. For more information, please visit www.contrastsecurity.com or follow @contrastsec.
Media Contacts:
Dan Chmielewski
Madison Alexander PR
714-832-8716
Email Contact
Or
Paula Brici
Madison Alexander PR
949-677-6527
Email Contact
Published February 4, 2013 Reads 592
Copyright © 2013 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Marketwire .
Copyright © 2009 Marketwire. All rights reserved. All the news releases provided by Market Wire are copyrighted. Any forms of copying other than an individual user's personal reference without express written permission is prohibited. Further distribution of these materials is strictly forbidden, including but not limited to, posting, emailing, faxing, archiving in a public database, redistributing via a computer network or in a printed form.
- Cloud People: A Who's Who of Cloud Computing
- CollabNet And UC4 Announce General Availability Of Joint Enterprise DevOps Platform
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- The Software Freedom Conservancy – Fundraising Campaign: Non-Profit Accounting Software
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- Remote Controlling a Car over the Web. Ingredients: Smartphone, WebSocket, and Raspberry Pi.
- Midokura Announces General Availability of Disruptive Network Virtualization Technology
- Social Business Intelligence Book Industry’s First Executive SBI Guide
- The Linux Foundation’s Collaboration – OpenDaylight Project – Open Source SDN
- Tech Trends To Watch In May 2013
- Services Orinted Architecture (SOA) Market
- Cloud People: A Who's Who of Cloud Computing
- SUSE Receives Common Criteria Security Certifications
- Basho Announces Open Source Riak CS and General Availability of Riak CS Enterprise v1.3
- CollabNet And UC4 Announce General Availability Of Joint Enterprise DevOps Platform
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- The Software Freedom Conservancy – Fundraising Campaign: Non-Profit Accounting Software
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- Project Floodlight Grows to the World’s Largest SDN Ecosystem; Global Users, Contributors and Partners Innovating Using Open Source SDN
- Mobility News Weekly – Week of March 17, 2013
- Global Information Security Products And Services Industry
- Kevin Benedict’s What’s New in HTML5 – Week of February 24, 2013
- Java Developer's Journal Exclusive: 2006 "JDJ Editors' Choice" Awards
- The i-Technology Right Stuff
- Creating Web Applications with the Eclipse Web Tools Project
- Eclipse Special: Remote Debugging Tomcat & JBoss Apps with Eclipse
- Where Are RIA Technologies Headed in 2008?
- The Next Programming Models, RIAs and Composite Applications
- SYS-CON Webcast: Eclipse IDE for Students, Useful Eclipse Tips & Tricks
- How to Bring Eclipse 3.1, J2SE 5.0, and Tomcat 5.0 Together
- Eclipse: The Story of Web Tools Platform 0.7
- The Top 250 Players in the Cloud Computing Ecosystem
- "Eclipse 3.0 is a Great Leap Forward," Says JDJ's Dudney
- Developing an Eclipse BIRT Report Item Extension



























