Accessibility Statement Skip Navigation
  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing
  • Login
  • GDPR
  • Create a Free Account
Return to PRWeb homepage
  • News
  • Resources
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All News Releases
      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
  • Business & Money
      • Auto & Transportation

      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • View All Auto & Transportation

      • Business Technology

      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • View All Business Technology

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Financial Services & Investing

      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • View All Financial Services & Investing

      • General Business

      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Overseas Real Estate (non-US)
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • View All General Business

  • Science & Tech
      • Consumer Technology

      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • View All Consumer Technology

      • Energy & Natural Resources

      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • View All Energy & Natural Resources

      • Environ­ment

      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Health

      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • View All Health

      • Sports

      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • View All Sports

      • Travel

      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • Advocacy Group Opinion
      • Animal Welfare
      • Congressional & Presidential Campaigns
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • U.S. State Policy
      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • View All People & Culture

  • Hamburger menu
  • Cision PRWeb provides efficient communication tools to continuously engage with target audiences across multiple online channels
  • Create a Free Account
    • ALL CONTACT INFO
    • Contact Us


      11AM ET Sunday – 8PM ET Friday

  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • News in Focus
    • Browse All News
    • Multimedia Gallery
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR

Department of Homeland Security Awards Denim Group with Research Contract to Better Protect the Critical Infrastructure by Improving Software Vulnerability Management
  • USA - English


News provided by

Lutchansky Communications

Aug 05, 2013, 09:00 ET

Share this article

Share toX

Share this article

Share toX


San Antonio, TX (PRWEB) August 05, 2013 -- Denim Group, the leading secure software development company, today announced that it was awarded a Phase 1 Small Business Innovation Research (SBIR) contract of $100,000 by the Department of Homeland Security to improve the accuracy and comprehensiveness of software vulnerability analysis activities. This will enable security analysts and software developers to fix software applications, a key exposure point into systems of all kinds, faster and more easily than ever before.

This technological innovation is a pivotal investment in protecting software systems that power our nation’s critical infrastructure and e-commerce industries.

Post this

“As software systems grow more capable and complex, they become more susceptible to flaws that prospective adversaries can exploit,” said Kevin E. Greene, Department of Homeland Security Science & Technology Cyber Security Division Program Manager. “As a result of this contract, the research by Denim Group will create a Hybrid Analysis Mapping framework that will accelerate the discovery, identification, and remediation of application vulnerabilities to help further protect software systems from sophisticated cyber-attacks. This technological innovation is a pivotal investment in protecting software systems that power our nation’s critical infrastructure and e-commerce industries.”

When software applications are being built, a key part of the software development life cycle is testing the software to validate that any given application is free from security-related flaws. Conducting multiple types of software security analysis can be valuable to both find more vulnerabilities as well as reveal more data about previously identified vulnerabilities. This process consists of running dynamic, static and manual tests on each application in order to discover the majority of the vulnerabilities. Static scans analyze an application’s source code or binary code. Dynamic scans test software at runtime and are also known as web application scanning, penetration testing, and/or black box testing. The increased data can be valuable when it provides deeper insight into vulnerabilities; however, the increased data can also create challenges if it makes the overall problem harder to manage by requiring too much manual analysis or when it highlights a large number of low value or low priority vulnerabilities.

This research contract empowers Denim Group to develop a risk management framework called Hybrid Analysis Mapping that normalizes the results between automated static and dynamic security scans of web applications. According to the Department of Homeland Security Phase One SBIR Solicitation, no framework or standard currently exists that can map and correlate the vulnerability output from open source or commercially available static analysis tools with open source or commercially available dynamic analysis tools. The Hybrid Analysis Mapping framework will be designed to correlate and merge the results of these test results. This will significantly ease the process because many times both types of scans will find the same logical issue but label those issues differently. In fact, according to vulnerability research from White Hat Security and Veracode, on average, it can take some organizations in excess of six months to resolve serious vulnerabilities. The proposed Hybrid Analysis Mapping framework will systematize matching dynamic and static results against each other, saving substantial time and money by enabling a wide variety of applications to be safely put into operation as quickly as possible.

Centralizes Application Vulnerability Data
Recognizing the severity of these problems, Denim Group has been conducting a multi-year research effort in this area. The company used this research to create ThreadFix, an open source software vulnerability management system launched last year that collects, normalizes and centralizes application vulnerability data in a single location. ThreadFix has already made it much easier to manage software security programs within organizations by aggregating vulnerability test results into a centralized, comprehensive console to reveal the security status of all applications within an organization. The aggregated static, dynamic and manual penetration testing, code review and threat modeling results are then exported into the defect trackers already being used by the company’s software developers, injecting the resolution of these security tasks into their regular work flow. ThreadFix also auto-generates web application firewall rules to protect corporate assets during the remediation process, increasing the company’s security posture.

The SBIR contract will empower Denim Group to do the research necessary to take ThreadFix to the next level. Hybrid Analysis Mapping will enable ThreadFix to more accurately correlate the results of static scans against dynamic scans to de-duplicate results, delivering another significant breakthrough for today’s industry professionals. In addition, because ThreadFix is an open source product, the results of Denim Group’s research will be available for free to spur wider adoption and make it much easier and faster to fix this serious security issue in the industry as a whole. This is important because cyber attacks against the U.S. continue to increase. In 2011 alone, the DHS US-CERT received more than 100,000 incident reports, and released more than 5,000 actionable cyber security alerts, with many of these being software-related vulnerabilities. Further illustrating the magnitude of this trend, 2012 numbers reflected a 35 percent increase in the number of cyber attacks.

SBIR Award Confirms the Importance of This Research
“ThreadFix was created to fill a perceived gap in secure application development, and it is gratifying to see the government confirm the importance of the research and the resulting product we’ve already developed,” said Dan Cornell, CTO of Denim Group. “We’ve endeavored to make ThreadFix as easy to use as possible in order to change this dynamic in the industry. Furthermore, ThreadFix will enable security analysts and developers to get more value out of the static and dynamic assessment tools they have already purchased. As a result, security analysts can get runtime-analysis-like results with an open sourced product without having to purchase all new products – in fact, this research will let ThreadFix deliver equivalent results to better secure their applications against possible attacks.”

An Investment in Vulnerability Analysis Innovation
The SBIR program was created to invest federal research funds into innovative technological research that could solve critical American priorities to help build a strong national economy. SBIR agencies award monetary grants in phases I and II of a three-phase program. Once the technical merit and feasibility of Denim Group’s initial Hybrid Analysis Mapping research is proven, the company may be awarded a Phase II grant of up to a $750,000 to expand its research into capabilities that can be incorporated into both commercial and government security operations. In fact, companies such as Symantec, Qualcomm, DaVinci and iRobot were started with R&D funding from this program.

About The Department of Homeland Security Science and Technology Directorate
The Department of Homeland Security Science and Technology Directorate mission is to strengthen America’s security and resiliency by providing knowledge products and innovative technology solutions for the 22 different federal agencies in the DHS collectively referred to as the Homeland Security Enterprise. S&T contributes to enhancing the security and resilience of the Nation’s critical information infrastructure and the Internet by (1) driving security improvements to address critical weaknesses, (2) discovering new solutions for emerging cyber security threats, and (3) delivering new, tested technologies to defend against cyber security threats. R&D activities are focused on the essential characteristics needed to achieve desired end-states of trustworthy cyber systems while also accelerating the transition of new cyber security technologies into commercial products and services. Please visit us at http://www.dhs.gov/st-directorate-organization.

About Denim Group
Denim Group, the leading secure software development firm, builds custom large-scale software development projects across multiple platforms, languages and applications. What makes Denim Group unique is that the company brings significant core competencies in software security to the table, offering an innovative blend of secure application development, security assessments, application security training and consulting capabilities that protect a company's biggest asset, its data. Denim Group customers span an international client base of commercial and public sector organizations across the financial services, banking, insurance, healthcare, and defense industries. Its depth of experience building large-scale software development systems in a secure fashion have made the company’s leaders recognized experts in their fields Denim Group has been recognized as one of the 5,000 Fastest Growing Company’s by Inc. Magazine several years in a row, and has won multiple other awards as well. For more information about Denim Group visit http://www.denimgroup.com.

Robin Lutchansky, Lutchansky Communications, http://www.lcomm.com, (408) 963-6773, [email protected]

Modal title

Dan Cornell, Denim Group CTO
Dan Cornell, Denim Group CTO
Dan Cornell, Denim Group CTO

Contact PRWeb

  • 11AM ET Sunday – 8PM ET Friday
  • Contact Us

About PRWeb

  • About PRWeb
  • Partners
  • Partnership Programs
  • Editorial Guidelines
  • Resources

Why PRWeb

  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing

Accounts

  • Create a Free Account
  • Log in
  • Contact Us

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact Cision

Products

About

My Services
  • All News Releases
  • Online Member Center
  • ProfNet
Cision Distribution Helpline
888-776-0942
  • Legal
  • Site Map
  • RSS
  • Cookie Settings
Copyright © 2025 Cision US Inc.