소프트웨어 강화
Fortify Software![]() | |
| 유형 | 소프트웨어 벤더 |
|---|---|
| 산업 | 컴퓨터 소프트웨어 |
| 장르. | 소프트웨어 보안 보증 |
| 설립. | 2003 |
| 설립자 | 클라이너, 퍼킨스, 코필드 & 바이어스, 마이크 아미스테드, 브라이언 체스, 아서 도, 로저 손턴의 테드 슐레인 |
| 본사 | , 미국 |
주요 인물 | John M. Jack(전 CEO), Jacob West(보안연구그룹장), Brian Chess(전 수석 과학자), Arthur Do(전 수석 건축가) |
| 주인 | 마이크로 포커스 |
| 웹 사이트 | Micro Focus 보안 Micro Focus 소프트웨어 보안 센터 서버 강화 |
Fortify Software(나중에 Fortify Inc.)는 캘리포니아에 본사를 둔 소프트웨어 보안 벤더로, 2003년에 설립되어 2010년에[1] Hewlett-Packard에 인수되어 HP Enterprise Security [2][3]Products의 일부가 되었습니다.2017년 이후, Fortify의 제품은 Micro Focus가 소유하고 있다.
Fortify 제품에는 정적 애플리케이션 보안[4] 테스트 및 동적 애플리케이션 보안[5] 테스트 제품과 소프트웨어 보안 보증을 지원하는 제품 및 서비스가 포함되어 있습니다.2011년 2월 현재 Fortify는 정적 동적 애플리케이션 테스트 [6]서비스인 Fortify OnDemand를 판매하고 있습니다.
역사
Fortify Software는 [7]2003년부터 독립회사로 운영하다가 2010년에 HP에 인수되었습니다.
2016년 9월 7일 HPE의 CEO인 Meg Whitman은 Fortify를 포함한 Hewlett Packard Enterprise의 소프트웨어 자산을 Micro Focus와 합병하여 HP Enterprise 주주들이 다수의 [citation needed]소유권을 보유하는 독립 회사를 설립할 것이라고 발표했습니다.
Micro Focus의 CEO Kevin Loosemore는 이 거래를 "당사의 확립된 인수 전략 및 성숙한 인프라스트럭처 제품의 효율적인 관리에 초점을 맞춘 것"이라고 평가하면서 Micro Focus는 "거래에서 성숙한 자산의 핵심 수익률을 21%에서 80%까지 끌어올리려고 한다"고 밝혔습니다.3년 [8]안에 Micro Focus의 기존 46% 수준으로 올라갑니다."합병은 2017년 [citation needed]9월 1일에 끝났다.
테크니컬 어드바이저리 위원회
Fortify의 기술 자문 위원회는 Avi Rubin, Bill Joy, David Wagner, Fred Schneider, Gary McGraw, Greg Morrisett, Li Gong, Marcus Ranum, Matt Bishop, William Pugh 및 John Viega로 구성되었습니다.
보안 조사
Fortify는 Fortify의 분석 소프트웨어의 [10]보안 규칙과 더불어 Java Open Review[9] 프로젝트와 보안 취약성의 Vulncat 분류법을 유지하는 보안 연구 그룹을 만들었습니다.이 그룹의 멤버들은 "Secure Coding with Static Analysis"라는 책을 쓰고 JavaScript Hijacking,[11] Attacking the build: 크로스 빌드 주입,[12] 작성 내용 확인: 프로그램 출력 [13]및 동적 오염 전파를 관찰하여 사이트 간 스크립팅을 방지합니다. 공격하지 [14]않고 취약성을 찾아냅니다.
「 」를 참조해 주세요.
레퍼런스
- ^ "HP Completes Acquisition of Fortify Software, Accelerating Security Across the Application Life Cycle". September 22, 2010. Retrieved December 17, 2018.
- ^ Roberts, Paul (April 5, 2004). "Software Searches for Security Flaws". PCWorld.com. Retrieved December 17, 2018.
- ^ Wagner, Jim (April 5, 2004). "A New Approach to Fortify Your Software". Internetnews.com. Retrieved December 17, 2018.
- ^ "HP Fortify Static Code Analyzer". Retrieved December 17, 2018.
- ^ "HP Unveils Real-Time Application Security Testing Tool". DarkReading.com. July 14, 2011. Retrieved December 17, 2018.
- ^ Reitano, Victoria (February 15, 2011). "HP builds up its Security-as-a-Service". SD Times. Retrieved December 17, 2018.
- ^ "HP's Fortify Buyout Numbers Tell Lucrative Story For Software Security". Forbes. August 18, 2010. Retrieved May 4, 2020.
- ^ Sandle, Paul; Baker, Liana B. (September 7, 2016). "HP Enterprise strikes $8.8 billion deal with Micro Focus for software assets". Reuters. Retrieved December 17, 2018.
- ^ "Quality and Security for Open source Community". Archived from the original on December 16, 2006. Retrieved December 17, 2018.
- ^ "HP Fortify Taxonomy: Software Security Errors". Archived from the original on November 27, 2012. Retrieved December 17, 2018.
- ^ Chess, Brian; O'Neil, Yekaterina Tsipenyuk; West, Jacob (March 12, 2007). "JavaScript Hijacking" (PDF). Retrieved December 17, 2018.
- ^ Chess, Brian; Lee, Fredrick DeQuan; West, Jacob (October 10, 2007). "Attacking the Build through Cross-Build Injection". Retrieved December 17, 2018.
- ^ Madou, Matias; Lee, Edward; West, Jacob; Chess, Brian (2008). "Watch What You Write: Preventing Cross-Site Scripting by Observing Program Output" (PDF). Retrieved December 17, 2018.
- ^ Chess, Brian; West, Jacob (January 2008). "Dynamic taint propagation: Finding vulnerabilities without attacking". Information Security Tech. 13 (1): 33–39. doi:10.1016/j.istr.2008.02.003. Retrieved December 17, 2018.
외부 링크
- 공식 웹사이트

- 애플리케이션 보안 테스트를 위한 Gartner 2018 Magic Quadrant
- Joy, Bill (September 26, 2006). "Software Isn't Complete Unless It's Secure". BusinessWeek. Retrieved December 17, 2018.
