Posts Tagged ‘applications’

Security apps full of common software flaws, report finds

April 20th, 2011

Security developers are one of the two software sectors most likely to write insecure code, an analysis of applications submitted to code-testing outfit Veracode has found.

According to the company’s State of Software Security (SOSS) Report volume three, 72 per cent of security software and services applications seen by the company were deemed ‘unacceptable’ on the first analysis of their code, a result that was ahead of only one sector, customer support, which failed 82 per cent of the time.

For comparison, the financial sector failed only 52 per cent of the time, with the score across all development sectors, including internal, bespoke and commercial developers, being a mediocre 58 per cent.

Veracode first published the SOSS in mid-2009, since when it has updated the analysis every six months based on the accumulated number of applications submitted by its customers. That total now stands at 4,385, of which 13 per cent are security-related.

On a positive note, security vendors were the best sector at fixing the flaws, with an average remediation time of only three days.

The findings might count as surprising if it weren’t for a recent spate of security woes suffered by companies in the sector, including RSA Security, HBGary Federal, Comodo, and Barracuda Networks, the report’s authors note.

Two security flaws that can commonly afflict web applications remain about as common as they were in the two previous SOSS reports, which suggests a deeper complacency in the developer community.

60 per cent of web applications are affected by easily-fixed cross-site scripting (XSS) flaws, a number that has remained static since Q1 2009. SQL injection flaws have improved somewhat over time, but are still currently around the 30 per cent mark.

“When you consider these statistics in the context of the ever strengthening threat environment these application security weaknesses translate into real and present danger for the risk-free operation of your software infrastructure,” say the authors.

Where the services offered by Veracode and companies like it first into this environment is interesting. The company sells its ability to detect security problems in code, mainly using an automated mixture of ’static’ and ‘dynamic’ analysis. It is clear, however, that many of the problems it detects would not be there at all were developers to adopt better security review during the stage applications are planned and written.

Source:http://www.pcworld.idg.com.au/article/383816/security_apps_full_common_software_flaws_report_finds/

SaaS inappropriate for major software applications: Forrester

February 7th, 2011

SaaS (Software-as-a-Service) will have problems getting traction from the lower-level software enterprise. It faces obstacles in major spheres of software like operating system, database, software for internal IT management, data management and securities transaction processing system.

Software-as-a-service (SaaS) is a set of capabilities and engagement models in the IT industry,particularly in the emerging world of cloud computing. Question has been raised earlier, “Is SaaS a truly disruptive technology?” Moreover, some new and emerging software products like blog and wiki platforms began as SaaS products with no disruption of existing vendors. Speculations were made that SaaS will only be a disruptive force in software products that make up about 25 percent of the total global software market, especially in customer relationship management, human resource management, IT management, and security software, Forrester said.

SaaS is raiding in mature application areas such as SCM (supply change management), particularly when the customer hasn’t already purchased such functionality from an on-premises vendor. Products where SaaS has taken hold of at least 50 percent of revenue amount to only 3 percent of the total software market. In other categories, SaaS is now “the majority model for software sales and delivery,” the report states. Those include e-purchasing, expense reporting tools, and blogging and wiki platforms. The emergence of new product variants has also given SaaS vendors who sell them a chance to mature while legacy players catch up.

SaaS is typically billed on a subscription basis and is generally considered easier for a customer to migrate away from than an on-premises product, a situation compounded by the fact that many SaaS contracts are year-to-year.

On the contrary, the likes of SAP and Oracle are now moving quickly to bring more SaaS products to market, particularly for their largest customers. SAP is planning to deliver a series of add-on SaaS extensions for its Business Suite software, while Oracle has said its upcoming Fusion Applications will be available in SaaS form according to the taste of customers.

Source:http://www.siliconindia.com/shownews/SaaS_inappropriate_for_major_software_applications_Forrester-nid-78469.html

Diamond Sierra Releases Paul Bunyan™ 3.0 Software, A Comprehensive Applications/Development Monitoring Tool

February 2nd, 2011

Diamond Sierra Software, a developer of application monitoring and diagnostics software, announced today the immediate release of their Paul Bunyan 3.0 software product. The core benefit of version 3.0 is support for Windows 7 and Server 2008 64 bit. Additional support for .NET 3.5 Framework is also included in this release. Paul Bunyan 3.0 is designed to help businesses (1) increase the performance of their mission critical applications and systems and (2) improve the software development process by providing real-time performance monitoring and notification of errors or slow-downs.

“Our current customers have saved considerable time and money with Paul Bunyan” says Teo Leonard, VP of Sales and Marketing. “Using real-time analysis and notification enables them to identify and correct problems immediately, rather than by customer complaints hours later. One customer was able to detect a performance glitch and double performance in less than an hour”.

Software providers can improve service to their customers through the use of Paul Bunyan 3.0. Real-time monitoring and analysis of systems enables businesses with custom Windows applications to decrease downtime and optimize technical personnel by quickly identifying and correcting performance problems. Performance problems can jeopardize the customer relationship by leading to slow-downs, down-time, and incomplete business transactions.

Paul Bunyan 3.0 is available immediately via download on the company’s Web site at www.diamondsierra.com. Paul Bunyan 3.0 runs on Microsoft Windows 2000 and above including support for windows 7 x64 and Windows Server 2008 x64. It provides for easy integration into: C, C++, C#, .NET, VB, Java, SQL, batch files, shell scripts, and more.

Source:http://www.openpr.com/news/160715/Diamond-Sierra-Releases-Paul-Bunyan-3-0-Software-A-Comprehensive-Applications-Development-Monitoring-Tool.html

Windows 7 Applications Keep Rockin’

January 2nd, 2011

Industry observers have found that applications for Android smartphones had increased significantly since October last year. According AndroidLib site, as quoted by Yahoo News, on Saturday (01/01/2011), more than 100 thousand applications are already available in Android Market. Even sites that track such statistics Android found that in November, Google’s platform has reached approximately 24 thousand new applications in November, while this month there are approximately 26 thousand new applications.

Compared to the number of applications on Apple’s AppStore is now a total of 300 thousand, this figure is still too small. Even 40 thousand between applications in the AppStore this can only be opened on the iPad. But the growth of Android apps is quite rapid recall in March and July, the successive application only has a row of 30 thousand to 70 thousand applications. In addition to the store application, the Windows Phone 7 also showed significant growth. In the past two months since Windows 7 Phone application store launched, of 5,000 applications have been crowded into the store. Well this is a very good news for them.

“In other words, Windows 7 Phone gets faster than Android. Windows only took two months to have approximately 5000 applications from 10 devices across 30 countries in the world,” said director of applications development software firm IDC, Al Hilwa.

Source:-http://homedailynews.com/windows-7-applications-keep-rockin/2015/

Orsyp participates as silver sponsor at hp software universe 2010

November 30th, 2010

ORSYP, a provider of IT Operations Management solutions and services, announced it will be attending the HP Software Universe 2010 in Barcelona this month as a member of the HP ISV Marketplace Referral Program.

According to ORSYP, HP Software Universe Barcelona 2010 will provide the opportunity to meet and hear from HP executives and keynote speakers, focusing on business and technical industry topics.

ORSYP, a Silver Sponsor of the event, will be exhibiting their solutions to conference attendees. Jordi Serras Marques, Director of Presales will be hosting a technical session on December 2 at 9 a.m.

The session, titled “On Earth or in the Cloud: HP’s recommended solution for Job Scheduling and Workload Automation with ORSYP”, will demonstrate how IT Operations can widen the supervision scope of HP Operations Manager (OM) to include workload automation and ensure that service levels are met through advanced job scheduling features under the control of HP Operations Manager. ORSYP’s Smart Plug-In for HP OM provides deep visibility into operational enterprise job scheduling across all applications and platforms.

Source:http://cable.tmcnet.com/news/2010/11/30/5164110.htm

Quest software rolls out vfoglight

November 27th, 2010

Delivering extended hypervisor support for both VMware ESX and Microsoft Hyper-V, as well as application infrastructure management for Microsoft Active Directory and Microsoft Exchange, the Company said vFoglight 6.5 provides increased automation of virtual infrastructures, delivering on the promise of virtualization: simplifying VMware management to increase efficiency to drive lower costs. Download a free 30-day trial of vFoglight.

As our infrastructures become increasingly complex and we move critical applications to virtual infrastructures, it was becoming a challenge for us to keep control and understand performance and capacity-related metrics,” said Chadd Warwick, a systems architect with CSS Hosted Systems. “vFoglight answered those critical needs for me. In a single tool, I can manage the virtual layer and get visibility “up the stack” into our infrastructure and applications. It’s much simpler and has been a quick ROI for us.”

Mary Johnston Turner, research director, system management software for IDC, said, “As the number of production applications and workloads running on virtual servers increases, IT teams reach a point where traditional configuration, provisioning, monitoring and optimization tools can’t scale to keep up with the dynamic needs of these environments. Our research indicates that effective virtualized data center operations require more integrated and automated workflows plus real time end-to-end performance visibility to adequately manage these resources. vFoglight 6.5 directly targets these requirements.”

Source:http://www.tradingmarkets.com/news/stock-alert/qsft_quest-software-rolls-out-vfoglight-1332667.html

Sap trains students in software application

November 12th, 2010

A software application firm has teamed up with the University of Duisburg-Essen, Germany to extend an ancillary course in the enterprise resource planning application to students in emerging market countries in Europe, the Middle East and Africa, EMEA, allowing them to obtain an official SAP certification.

The students are expected to be trained in several courses for 10 days. The courses will offer up to 300 participants the chance to acquire valuable SAP competencies during the period in Germany. This will enable the students to enhance their career opportunities in emerging markets with strong demand for qualified SAP professionals.

The Learning materials and tutorial support will be provided completely online via e-learning through the University while the final certificate examination will be held by SAP Education on site at local SAP training centers.

The training is designed to provide participants with broad, well-founded knowledge of SAP ERP, its core business processes and their operational interrelations.

Heimo Adelsberger, head of the department, Production and Operations Management, Institute for Computer Science and Business Information Systems at the University, explained that theoretical knowledge is put into practice and further deepened by means of case studies on integrated business process scenarios that participants carry out independently in the SAP system, which according to him, enables them to use and reinforce their training and fundamentally understand the system’s integration within complex business processes.

“After the successful completion of all case studies, participants receive a course certificate from the University of Duisburg-Essen. It emphasizes the practical application of know-how in addition to theoretical and methodical knowledge,” said Adelsberger.

Source:http://www.tmcnet.com/usubmit/2010/11/12/5134201.htm

Get Adobe Flash playerPlugin by wpburn.com wordpress themes