Identity, Security, Payments, Biometrics, Smart Cards and Authentication News

Parasoft enhances application security solution; helps IT organizations deliver secure applications

Tuesday, July 15, 2008

Parasoft, a Monrovia, Calif. company that helps track possible software vulnerabilities, has released an enhanced data flow analysis system that can help organizations identify high-risk security problems as well as monitor security policy compliance.

This new capability is available in Parasoft’s Application Security Solution, which expands traditional data flow analysis from software quality to application security. This server-based technology statically simulates application execution paths to help teams find vulnerabilities that might otherwise take weeks to locate, or remain unnoticed until exploited.


Vulnerabilities detected include SQL injection, cross-site scripting, exposure of sensitive data, and other potential issues. Since tests are performed completely automatically (there are no test cases to design, implement, execute, or maintain), teams significantly increase the scope of their security testing without slowing project progress. The latest enhancements not only draw upon an extensive knowledge base of common attack patterns, but also enable organizations to map the data flow logic to their own security policy.

“Security should be an integral part” of software development, “not an afterthought,” said Parasoft Vice President Neil MacDonald. “The notion of application ‘quality’ which has traditionally focused on functionality and performance must be expanded to include security. Native integration of security testing capabilities…will increase the likelihood of acceptance by the development organization.”

Parasoft solutions have supported application security verification for years through rule-based static analysis, data flow static analysis, security metrics, and peer code review process automation. [end] 

Human Recognition Systems (HRS) has added features and enhancements to its MForce latent fingerprint processing product.

In an effort to reduce operation times and costs, HRS has developed MForce as a mobile biometric product that enables law enforcement officers and military to obtain and process latent and livescan fingerprints in the field. By processing prints onsite, users are able to quickly provide investigators with intelligence.

read more »

Clarity Services, a provider of thin-file and underbanked consumer data reporting, has called on Experian to provide identity verification and fraud detection services for its subprime market product.

read more »

Collis has announced the launch of its Visa Mobile Payment Specification (VMCPS) Test Suite, enabling the functional testing of UICC or secure element-based contactless mobile payments applications.

read more »

GlobalPlatform and SIMalliance have signed a Memorandum of Understanding to improve application security on mobile devices.

Through the formal partnership, the associations say they will work together to develop an end-to-end solution that will enable a mobile device application to communicate with an application loaded in a secure element.

read more »

Codebench Inc. and Hirsch Identive announced the integration of Codebench’s PIVCheck Plus software with Hirsch Identive’s Velocity Management Software, which aims to provide federal government and commercial customers with a solution for identity validation, authentication and PACS registration using mobile handheld devices.

read more »

The NFC Forum and WIMA, a global conference and exhibition for NFC applications, have issued a call for entries for the 2012 Tap Into Innovation: NFC Global Competition.

read more »