Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Microsoft releases Attack Surface Analyzer for secure development

Software giant introduces technology and consulting for application security

Article comments

Microsoft is expanding its roster of SDL (security development lifecycle) tools and services with the beta release of an attack surface analyser tool as well as the introduction of consulting services on secure development.

Microsoft's Attack Surface Analyzer is an SDL verification tool for developers and IT professionals to identify whether newly developed or installed applications inadvertently change the attack surface of a Microsoft OS. The free tool is downloadable from Microsoft's website and is the same tool used by internal Microsoft product development teams.

"Microsoft has required attack surface validation of applications prior to release for years, however, assessing the attack surface of an application or software platform can be an intimidating process at first glance," said David Ladd, principal security manager at Microsoft.

"To help ease the process, we are releasing a tool called Attack Surface Analyzer to assist both testers and IT pros in assessing the security of an application. The Attack Surface Analyzer is being released as a beta to allow us time to gather feedback and real-world usage data from our customers."

Microsoft also is updating its existing Threat Modeling and BinScope Binary Analyzer tools to enhance developer usability. These tools also are free and are accessible at Microsoft's security website. The threat modelling tool offers guidance on building and analysing threat models, while the binary analyser checks binaries to ensure they were built based on SDL requirements and recommendations.

"Consistent with the previous release of the tool, version 3.1.6 [of Threat Modeling] allows for early and structured analysis and proactive mitigation of potential security and privacy issues in new and existing applications," sad Ladd. "The Microsoft SDL Threat Modeling Tool beta is enhanced to support Microsoft Visio 2010 for diagram design, and also contains bug fixes reported to Microsoft by members of the security developer community." Version 3.1.6 is currently in a beta release stage.

"BinScope Binary Analyzer now supports Visual Studio 2010, making validation tasks readily available in the development environment. In addition, it integrates with Microsoft Team Foundation Server 2008 and Microsoft Team Foundation Server 2010 to output results into work items," Ladd said.

A Microsoft consulting services option pertaining to SDL is being offered beginning in February 11. The goal is to improve software security and reduce both customer risk and costs of development. Services are being offered by the Microsoft Services group.

Also, Microsoft is releasing a report it commissioned from Forrester Consulting, entitled "State of Application Security," studying the current state of application development practices. "There are a lot of interesting findings in the report that help validate the notion that addressing security early makes good business sense," Ladd said.



Share:

More from Techworld

More relevant IT news

Comments



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *