NORTHPORT, NY, March 20, 2014 (Press-News.org) Secure Decisions, a division of Applied Visions and developer of visual analytic tools for cyber security, has received a Small Business Innovative Research (SBIR) Phase II award from the US Department of Homeland Security (DHS) to improve the security of software applications. Under this DHS Science & Technology (S&T) Directorate contract, Secure Decisions will continue development of the Code Ray software assurance risk management framework, to correlate the results of static and dynamic software analysis tools towards the goal of improving software vulnerability detection. The Code Ray technology will be incorporated into and extend Secure Decisions' current Code Dx static source code analysis product. At the heart of the Code Ray technology is Secure Decisions' dynamic tracing capability called Code Pulse, which was funded under a prior effort to aid penetration testing of software applications, by DHS S&T Cyber Security Division BAA 11-02.
About Code Ray
Under a 24-month Phase II software development initiative, the Code Ray technology will be developed and matured as a software assurance risk management and visualization framework to help software developers, security analysts, and quality assurance engineers better identify and remediate software vulnerabilities within developed code bases. The tool will improve the analysis speed, accuracy and confidence in detection of vulnerabilities by cross-mapping and normalizing the output of hybrid techniques - dynamic application security testing (DAST) with static application security testing (SAST).
Using the DAST-to-SAST merged results, Code Ray will map and prioritize the correlated findings to selected industry security standards, such as FISMA, HIPAA, MISRA and PCI to help consumers understand and communicate the relevance and risks of software vulnerabilities to these widely recognized compliance standards.
"Hybrid application security testing, also known as HAST, will soon become a best practice approach in finding and remediating software vulnerabilities. It combines the value of dynamic and static techniques to expose the vulnerabilities software applications that are most exposed and visible to potential attackers," said Mr. Kevin Greene, the Software Assurance program manager at DHS, S&T.
As the Code Ray technology matures, it will be added to Secure Decisions current software assurance product Code Dx to provide a more robust software assurance tool suite solution to customers seeking to improve the security and compliance posture of their existing and future code bases. . An educational version, to be offered free to qualified academic institutions, will serve as a resource to educate programmers and security analysts about the value of SAST, DAST and hybrid techniques for secure code development.
Code Ray's hybrid analysis capabilities are also targeted for incorporation into DHS's Software Assurance Marketplace (SWAMP), which is a cloud-based set of software assurance tools being developed by the Morgridge Institute for Research (http://continuousassurance.org/) for use by software developers, software assurance researchers and educators. "DHS aims to improve the security of the supply chain by offering free-of-charge a variety of software assurance technologies for evaluating the security of software applications, including hybrid techniques, through the SWAMP. We expect software developers and security analysts to use this capability to detect and remediate software vulnerabilities before they enter the supply chain."
The Secure Decisions Code Ray development team will be joined by two top notch consultants: Dr. Robin Gandhi, Assistant Professor of Information Assurance at the Nebraska University Center on Information Assurance (NUCIA) at the University of Nebraska at Omaha (UNO), and Mr. Dave Wichers, COO and Co-Founder of Aspect Security, a consulting firm focused on application security and educating organizations about the ever-changing cyber threat landscape. "We are very excited and privileged to be working with such industry experts", said Ken Prole, Principal Investigator and Lead Engineer for Code Ray. Dr. Gandhi will consult on modifying Code Ray for use in educational and training institutions that offer courses in secure coding practices. Mr. Wichers will provide subject matter expertise on improving Code Ray for use by penetration testing teams. "We expect their expertise to be invaluable in helping to drive the direction of Code Ray and mature its capability," said Ken Prole. Code Ray development gets underway in mid-March, 2014.
Code Ray builds on the results of prior research sponsored by the DHS S&T Directorate, Cyber Security Division: SBIR projects (contract #s D11PC20010 and D14PC00060) and BAA 11-02 contract # FA8750-12-C-0219.
The views and conclusions contained herein are those of the authors and should not be interpreted as necessarily representing the official policies or endorsements, either expressed or implied, of the Department of Homeland Security, the Science & Technology Directorate, or the U.S. Government.
To learn more about Secure Decisions software assurance tools go to http://www.securedecisions.com/research-development/software-assurance/ and http://www.codedx.com
About Applied Visions and Secure Decisions
Applied Visions, Inc. (AVI) provides software products, custom solutions, and advanced technology research for commercial and government customers. The company's vision and expertise in visual software solutions for complex defense, national security, and business problems have served AVI's customers in the Department of Defense, Department of Homeland Security, Federal Bureau of Investigation, and prominent technology and Fortune 500 firms. Founded in 1987, AVI is based in Northport, NY, and has secure facilities and clearances to support classified government programs.
Secure Decisions was launched by AVI in 2000 to focus on cyber security research and products. Today, Secure Decisions is a leader in security visualization, with an established track record of R&D contracts, technology transition and product development. Secure Decisions' technologies are used to enhance the situational awareness of software developers and security professionals in government and commercial organizations. SecureScope , VIAssist , MeerCAT and Code Dx are among Secure Decisions' extensive portfolio of cyber defense solutions.
For more information, please visit http://www.avi.com and http://www.securedecisions.com.
Keywords: cyber security, software assurance, software security, application security, static source code analysis tools, static analysis, static application security testing, SAST, dynamic application security testing, DAST, dynamic tracing, hybrid analysis, hybrid techniques, CWE, software risk management, Code Ray, Code Dx, Code Pulse, Secure Decisions, SBIR, DHS,
Press Contact:
Brianne O'Brien
631-759-3908
Brianne.OBrien@securedecisions.com
All trademarks, trade names, service marks, and logos referenced herein belong to their respective parties.
Secure Decisions Wins U.S. Department of Homeland Security Phase II Software Assurance Contract
Division of Applied Visions, Inc. to continue development of a software assurance risk management framework for supporting static and dynamic code analysis to help secure software developed for government, industry and academia.
2014-03-20
ELSE PRESS RELEASES FROM THIS DATE:
Brentano to Show Color, Pattern at HD Expo
2014-03-20
Brentano will show their true colors at the Hospitality Design Expo in May. The textile house will debut dramatic new fire retardant draperies from the upcoming fall Affinity collection -- in addition to the heavy duty upholstery, outdoor and novelty fabrics expected from Brentano. From geometrics and stripes to organic shapes modeled after tree bark and gingko leaves, all of the fabrics have two things in common: They're bright! And they're Brentano.
"We looked at the new Affinity patterns and colors, and these were the ones that popped," says National Sales ...
Tathata Launches Tathata Golf Certified Instructor Training Program
2014-03-20
Tathata, the creator of revolutionary new golf training designed to transform the entire mind, body and swing, today announced it has launched the innovative Tathata Golf Certified Instructor Training Program.
Tathata, in its truest sense means "suchness," a sense of complete understanding and all-knowing. The Tathata Golf Certified Training Program has been built around this principal and is designed to revolutionize golf instruction to help instructors teach, and students learn, very detailed and complicated mechanics in a simple new way and improve at a ...
Wellbe Announces Webinar on Improving Day of Surgery Efficiency for Orthopedics
2014-03-20
OrthoServiceLine.com, a free resource to the orthopedic community sponsored by Wellbe, is hosting a complimentary webinar with Sandra L Nettrour, PA-C, DFAAPA, Orthopedic and Neurosurgery Service Line Coordinator at Butler Health System, on "Total Joint Replacement- Improving Day of Surgery Efficiency and Throughput."
Organic growth of total joint replacement volume is growing at 3-4% per year as the number of physicians entering orthopedic residency programs is in decline. Cuts in Medicare reimbursement for total joints is forecast every year producing stressors ...
Career Step Programs Now Available to Graduating High School Seniors
2014-03-20
Career Step, an online school providing career-focused education, is pleased to announce that its programs are now available to graduating high school seniors. This new effort gives high school students the opportunity to start rewarding careers more quickly after graduation.
"Our mission is to provide all of our students affordable, quality education that will help them begin a rewarding career and earn a good living," said Career Step CEO Stephen Tober. "With skyrocketing tuition rates and ballooning student debt levels nationwide, traditional college ...
Fishbowl Solutions Recognizes Team Members for Achieving Google Search Appliance Qualified Deployment Specialist Certification
2014-03-20
News Facts
- Fishbowl Solutions, an Oracle WebCenter Content and Portal Specialized Gold Partner and a Google Enterprise Partner, announced today that team members Greg Bollom and Kim Negaard received the Google Search Appliance (GSA) Qualified Deployment Specialist certification. This certification is recognized as the highest level of GSA certification possible for Google partners, and further demonstrates Fishbowl's commitment to provide expertise in the areas of enterprise search and overall information management.
- Greg and Kim represent the first Fishbowl employees ...
Chris Hastings to Launch World Class Dessert Brand from Hot and Hot Fish Club
2014-03-20
Beginning today at the Famous Hot and Hot Fish Club, James Beard winner, Chris Hastings, will allow diners an opportunity to enjoy a sneak preview of 80 POPS! , the world's best frozen dessert by Birmingham, AL entrepreneur, Brian Robinson.
"I've wanted an opportunity to deliver a farm to table experience to the masses, and when Brian approached my wife and I with a vision to create a dessert like none-other, after learning about his commitment to excellence, we decided 80 POPS! is the perfect vessel to achieve our goals," said Hastings.What is 80 POPS! ?
80 ...
Precision Tune Auto Care Selects S&A Cherokee as Agency of Record
2014-03-20
The North Carolina franchise of Precision Tune Auto Care, a leader in automobile maintenance for more than 35 years, has recently selected S&A Cherokee as its agency of record. S&A Cherokee will provide communication, marketing and digital strategies for Precision Tune Auto Care of North Carolina.
Precision Tune Auto Care is an industry leader in car repair and maintenance as well as customer service. Providing brake inspections and repairs, cooling system services, car repairs, tires, fleet services and more, Precision Tune brings the best-in-class training ...
IIM Survey Indicates that Traditional Gender Roles are Outdated
2014-03-20
The question to ask today isn't just "Can women have it all?" It's "Can men have it all, too?" A new study by Insights in Marketing, LLC (www.insightsinmarketing.com), a research- based marketing consultancy in the Chicago area, reveals that the expectations and roles of both genders are shifting. While the majority of women are returning to the workplace, and more men are choosing to stay home with the family, many men are facing the same stigmas and struggles that women have faced for years.
"Our latest study has revealed some important findings ...
Final Phase of Homes To Be Released for Sale at Pardee Homes' Sorrento Heights in Coastal San Diego
2014-03-20
The final phase of homes planned for Sorrento Heights will be released for sale on March 28th. This popular neighborhood of single-family detached homes, located in Sorrento Mesa, has sold quickly, according to Pardee Homes. The final phase of three homes includes Plans 1 and 2.
Located above Sorrento Valley on the mesas and hills that overlook the natural canyons of Los Peñasquitos Canyon, Sorrento Heights is priced from the mid $700,000s. There are no Mello-Roos fees at Sorrento Heights.
Sorrento Heights features sophisticated, single-family detached homes with four ...
Special Monthly Teleclass: Writing for the Personal Story Market - Wednesday, March 19th at 5pm EST Presented by Dorit Sasson.
2014-03-20
The personal story writing market is a wide open genre focusing specifically on the "personal experience." Writers need to know these kinds of writing opportunities exist, which is why I'm offering a special teleclass called, "Writing for the Personal Story Market" for members of the Working Writers Club.
This market is a wide open genre that naturally lends itself to personal stories. Maybe you associate the Chicken Soup of the Soul series with these kinds of stories, but the personal story market is all encompassing. The basic "story premise" ...
LAST 30 PRESS RELEASES:
Elena Belova and Yevgeny Raitses recognized for groundbreaking plasma physics research
SOX9 overexpression ameliorates metabolic dysfunction-associated steatohepatitis through activation of the AMPK pathway
Florescent probes illuminate cholesterol and Alzheimer’s research
Qigong significantly decreases chronic low back pain in US military veterans
New insights into pancreatic disease and diabetes
Effectiveness and safety of tenofovir amibufenamide in the treatment of chronic hepatitis B: A real-world, multicenter study
Higher costs limit attendance for life changing cardiac rehab
Over 500 patients receive diagnosis through genetic reanalysis
Brain changes in Huntington’s disease decades before diagnosis will guide future prevention trials
U of A astronomers capture unprecedented view of supermassive black hole in action
Astrophysicists reveal structure of 74 exocomet belts orbiting nearby stars in landmark survey
Textbooks need to be rewritten: RNA, not DNA, is the main cause of acute sunburn
Brits still associate working-class accents with criminal behavior – study warns of bias in the criminal justice system
What do you think ‘guilty’ sounds like? Scientists find accent stereotypes influence beliefs about who commits crimes
University of Calgary nursing study envisions child trauma treatment through a Marvel and DC lens
Research on performance optimization of virtual data space across WAN
Researchers reveal novel mechanism for intrinsic regulation of sugar cravings
Immunological face of megakaryocytes
Calorie labelling leads to modest reductions in selection and consumption
The effectiveness of intradialytic parenteral nutrition with ENEFLUID???? infusion
New study reveals AI’s transformative impact on ICU care with smarter predictions and transparent insights
Snakes in potted olive trees ‘tip of the iceberg’ of ornamental plant trade hazards
Climate change driving ‘cost-of-living' squeeze in lizards
Stem Cell Reports seeks applications for its Early Career Scientist Editorial Board
‘Brand new physics’ for next generation spintronics
Pacific Islander teens assert identity through language
White House honors Tufts economist
Sharp drop in mortality after 41 weeks of pregnancy
Flexible electronics integrated with paper-thin structure for use in space
Immune complex shaves stem cells to protect against cancer
[Press-News.org] Secure Decisions Wins U.S. Department of Homeland Security Phase II Software Assurance ContractDivision of Applied Visions, Inc. to continue development of a software assurance risk management framework for supporting static and dynamic code analysis to help secure software developed for government, industry and academia.