Connect with us

Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website. .

Top Stories

Synopsys Redefines Interactive Application Security Testing with New Seeker Solution Optimised for DevSecOps

Synopsys Redefines Interactive Application Security Testing with New Seeker Solution Optimised for DevSecOps

Published : , on

Continuously detects and verifies web app vulnerabilities at the speed of DevOps, identifies and tracks sensitive data for compliance

Synopsys, Inc. (Nasdaq: SNPS) today announced the availability of the latest major Seeker® release, an interactive application security testing (IAST) solution redesigned to enable DevSecOps and continuous delivery of secure web applications.

Seeker integrates seamlessly into CI/CD pipelines and monitors web applications during preproduction testing cycles. Using patented technology, Seeker is the only application security solution that detects and automatically verifies whether vulnerabilities are exploitable, providing developers with accurate, actionable information in real time.

Click to learn more about Seeker for interactive application security testing and register for our upcoming webinar on Aug. 28, 2018.

“With 34% of developers saying they build multiple times per day or during check-in, application security testing must run in these same time frames or risk grinding the development machine to a halt,” wrote Amy DeMartine, principal analyst at Forrester Research. “Dynamic application security testing (DAST) has long been a burden for organisations trying to test security at development speeds.”1

Seeker’s unique approach continuously mitigates application security risk in a tight feedback loop, complementing DAST scans and penetration tests that occur later in the development cycle and often require dedicated, out-of-band testing cycles and manual results verification and triage. To address software dependency risk, Seeker integrates Black Duck Binary Analysis (formerly Protecode SC) to automatically detect known vulnerabilities and license conflicts in open source components. Seeker is also the only IAST solution that provides sensitive-data tracking to help achieve compliance with standards and regulations like PCI DSS and GDPR. Seeker is easy to deploy out of the box and supports large-scale, cloud-based, and microservices-based application architectures.

“Seeker is designed specifically for organisations embracing DevOps and leveraging automation to deliver continuous software improvements to their customers,” said Andreas Kuehlmann, general manager of the Synopsys Software Integrity Group. “Due to its continuous monitoring, unrivaled accuracy, and contextualised remediation guidance, Seeker removes the manual elements of security testing and enables developers to take ownership of application risk.”

Key features of Seeker 2018.07 include:

  • Active vulnerability verification for unrivaled accuracy: Seeker is the only IAST solution that provides automated active verification to confirm that detected vulnerabilities are exploitable. This verification is achieved through patented technology that replays original HTTP(S) requests with tainted parameters and monitors the resulting application dataflow. The result is a near-zero false positive rate, which is significantly lower than that of other IAST and DAST solutions and reduces the cost of manual verification.
  • Sensitive-data tracking: Seeker is the only IAST tool that enables security teams to identify and track sensitive data, such as credit card numbers, usernames, and passwords, to ensure that it is handled securely and not stored in log files or databases with weak or no encryption. Sensitive-data tracking helps organizations comply with data security regulations including PCI DSS, HIPAA, and GDPR.
  • CI/CD integration and flexible deployment: Seeker can be deployed in virtually any type of automated or manual testing environment with minimal configuration required. Seeker fits seamlessly into CI/CD pipelines with native plugins and easy-to-use web APIs for bug tracking, build, and test automation tools. Seeker supports standard, microservices-based, and cloud-based application architectures and is scalable for large enterprise requirements.

Click to learn more about Seeker for interactive application security testing and register for our upcoming webinar on Aug. 28, 2018.

  1. Amy DeMartine, Construct a Business Case for Interactive Application Security Testing, Forrester Research, Inc., Nov. 3, 2017.

Global Banking & Finance Review

 

Why waste money on news and opinions when you can access them for free?

Take advantage of our newsletter subscription and stay informed on the go!


By submitting this form, you are consenting to receive marketing emails from: . You can revoke your consent to receive emails at any time by using the SafeUnsubscribe® link, found at the bottom of every email. Emails are serviced by Constant Contact

Recent Post