Identity, Security, Payments, Biometrics, Smart Cards and Authentication News

Parasoft enhances application security solution; helps IT organizations deliver secure applications

Tuesday, July 15, 2008

Parasoft, a Monrovia, Calif. company that helps track possible software vulnerabilities, has released an enhanced data flow analysis system that can help organizations identify high-risk security problems as well as monitor security policy compliance.

This new capability is available in Parasoft’s Application Security Solution, which expands traditional data flow analysis from software quality to application security. This server-based technology statically simulates application execution paths to help teams find vulnerabilities that might otherwise take weeks to locate, or remain unnoticed until exploited.


Vulnerabilities detected include SQL injection, cross-site scripting, exposure of sensitive data, and other potential issues. Since tests are performed completely automatically (there are no test cases to design, implement, execute, or maintain), teams significantly increase the scope of their security testing without slowing project progress. The latest enhancements not only draw upon an extensive knowledge base of common attack patterns, but also enable organizations to map the data flow logic to their own security policy.

“Security should be an integral part” of software development, “not an afterthought,” said Parasoft Vice President Neil MacDonald. “The notion of application ‘quality’ which has traditionally focused on functionality and performance must be expanded to include security. Native integration of security testing capabilities…will increase the likelihood of acceptance by the development organization.”

Parasoft solutions have supported application security verification for years through rule-based static analysis, data flow static analysis, security metrics, and peer code review process automation. [end] 

Multimodal biometric security provider ImageWare Systems Inc. has released version 2.0 of its Biometric Engine (BE) physical security identification product.

This product is designed for airports, seaports and other critical points-of-access for government and private enterprises. This update takes into account the SAFE Port Act, which requires foreign shippers to secure cargo being shipped to the U.S. and ensure the identity of those loading it. Shippers must manage this by 2013.

read more »

BT and Hitachi Europe Ltd. announced that they are jointly designing an identity management solution for the financial services market. In this move, BT is introducing BT Unified Trading federation, a cloud-based trust utility for secure identity exchange and will incorporate Hitachi’s Finger Vein Authentication Engine and technology to offer biometric security capabilities.

read more »

Identive Group has released a cloud-based NFC tag management platform that enables advertisers, retailers and organizations to deliver targeted content and services to customers’ NFC-enabled mobile devices.

read more »

NXP Semiconductors announced a new SWP-SIM secure element platform that combines passport level security, flash memory, smart card performance and multi-application support.

Designed to boost security in mobile transactions, the new secure element incorporates SmartMX2 technology, NXP’s next generation of secure elements, which have been deployed almost 1.5 billion times in eGovernment, banking and transport applications, according to the company.

read more »

GlobalPlatform and SIMalliance have signed a Memorandum of Understanding to improve application security on mobile devices.

Through the formal partnership, the associations say they will work together to develop an end-to-end solution that will enable a mobile device application to communicate with an application loaded in a secure element.

read more »

The Smart Card Alliance has announced the formation of the Mobile and NFC Council, a new industry body tasked with accelerating the adoption of NFC and raising awareness of the technology’s various capabilities.

read more »