Accessibility Statement Skip Navigation
  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing
  • Login
  • GDPR
  • Create a Free Account
Return to PRWeb homepage
  • News
  • Resources
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All News Releases
      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
  • Business & Money
      • Auto & Transportation

      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • View All Auto & Transportation

      • Business Technology

      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • View All Business Technology

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Financial Services & Investing

      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • View All Financial Services & Investing

      • General Business

      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Overseas Real Estate (non-US)
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • View All General Business

  • Science & Tech
      • Consumer Technology

      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • View All Consumer Technology

      • Energy & Natural Resources

      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • View All Energy & Natural Resources

      • Environ­ment

      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Health

      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • View All Health

      • Sports

      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • View All Sports

      • Travel

      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • Advocacy Group Opinion
      • Animal Welfare
      • Congressional & Presidential Campaigns
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • U.S. State Policy
      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • View All People & Culture

  • Hamburger menu
  • Cision PRWeb provides efficient communication tools to continuously engage with target audiences across multiple online channels
  • Create a Free Account
    • ALL CONTACT INFO
    • Contact Us


      11AM ET Sunday – 8PM ET Friday

  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • News in Focus
    • Browse All News
    • Multimedia Gallery
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR

Denim Group Announces Application Vulnerability Management Technology Breakthroughs With ThreadFix 2.0


News provided by

Lutchansky Communications

May 05, 2014, 09:00 ET

Share this article

Share toX

Share this article

Share toX


In the long-term, this gives U.S. companies the capability to identify key weaknesses throughout the software development lifecycle which will help reduce the cost of software failures. Kevin H. Greene, DHS Science & Tech Cyber Security Division

Post this

San Antonio, TX (PRWEB) May 05, 2014 -- Denim Group, the leading secure software development company, today announced the release of ThreadFix 2.0, the first application vulnerability management product in the industry which can point to the exact line of source code responsible for an application vulnerability that has been identified by a dynamic security scan. This new capability and ThreadFix’s new IDE (integrated developer environment) plug-in bridges a challenging communications gap between security and software development teams that can dramatically simplify and accelerate the time-to-fix of critical application vulnerabilities.

Originally released in 2012, ThreadFix was one of the first products in the industry to provide a comprehensive and easy-to-understand view of the state of an organization’s software security. By aggregating multiple vulnerability test results into a centralized platform, ThreadFix automates the prioritization of the application’s vulnerabilities into a unified list that application security managers can further prioritize via a centralized dashboard. As the development team resolves defects, status updates are synchronized within ThreadFix, enabling the security team to schedule follow-up testing to confirm that security holes have indeed been closed. This can transform the application remediation process by improving and simplifying the collaboration between security and development teams.

HYBRID ANALYSIS MAPPING
ThreadFix 2.0 was enhanced with the support of a Department of Homeland Security (DHS) Hybrid Analysis Mapping research contract, As a result of this new research, ThreadFix can now better combine and deduplicate the results from dynamic and static application security tests which frequently use different labels for the exact same logical problem. The new technology creates a more accurate list of vulnerabilities which can improve the overall state of software security within an organization.

PINPOINTS CODE DEFECT LOCATION FROM DYNAMIC SCANS
ThreadFix 2.0 can now take dynamic scanner reports and pinpoint exactly where vulnerabilities exist in application source code. To do this, ThreadFix leverages the application attack models that the newly created Hybrid Analysis Mapping engine is now able to create, and maps those vulnerabilities back to the source code. ThreadFix 2.0 can also export this code data into the developer’s Eclipse or IntelliJ Integrated Development Environment (IDE) which eliminates the vast amount of time previously spent manually searching for the offending line of code. ThreadFix provides the contextual relevant information as to exactly where the problem resides and what the problem is. By delivering this data when the developers are coding in their code editor, the time-to-fix for each vulnerability can be shortened dramatically.

“The ability to identify the line of code associated with dynamic testing is huge,” said Dan Cornell, Denim Group CTO. “Now security managers can provide better information to the developers who are the ones that actually fix the vulnerable code. This provides an organization with another important capability that is needed to resolve software vulnerabilities more quickly.”

MAKES DYNAMIC SCANNERS EVEN SMARTER
Another technology breakthrough that resulted from the Hybrid Analysis Mapping research improves the efficacy of dynamic scanners by identifying specific vulnerabilities which are not typically found by standard dynamic scanning crawls. The ThreadFix 2.0 platform accomplishes this by conducting a lightweight scan of an application’s source code to enumerate an application’s complete attack surface. The platform then exports the results of the scan back to the dynamic scanner, enabling that scanner to test “hidden” web pages and additional HTTP parameters that might have been missed in a typical dynamic scan. This new feature enables ThreadFix to improve the intelligence of dynamic scanners by feeding the scanner with additional threat model data, which in turn enables more comprehensive scans.

“Hybrid Analysis Mapping technology can accelerate the discovery, identification and remediation of application vulnerabilities in order to better protect the software systems that power our nation’s critical infrastructure and e-commerce industries,” said Kevin E. Greene, Department of Homeland Security Science & Technology Cyber Security Division Program Manager. “This research has made substantial progress towards its core goal of bringing together the results of static and dynamic testing technologies which will help improve the tool coverage and provide better analysis results. In the long-term, this gives U.S. companies the capability to identify key weaknesses throughout the software development lifecycle which will help reduce the cost of software failures, the number of software-related breaches and the potential loss of confidential information which continues to occur with alarming frequency.”

SCAN ORCHESTRATION
ThreadFix 2.0 also offers another substantial new feature in the Enterprise edition which provides dynamic scan orchestration capabilities. By offering a central facility that can store scan configurations for a variety of vendor scanner technologies, ThreadFix enables application security professionals to schedule software testing using multiple dynamic scanners without the need for human intervention at every step of the process. This new scan orchestration capability empowers companies to scale the dynamic testing of more web applications, making it possible to automate the inspection of a company’s entire portfolio of applications for the first time in the industry. This will also enable inspections to take place on a more frequent and recurring basis as well.

THREADFIX 2.0 ENTERPRISE EDITION
To respond to customer demand, ThreadFix 2.0 Enterprise Edition is also now available. ThreadFix Enterprise Edition offers enhanced features for multi-user deployments in large organizations such as LDAP (Lightweight Directory Access Protocol) and AD (Active Directory) integration, as well as role-based access control to enforce separation of duties within organizations. ThreadFix 2.0 Enterprise Edition also provides enhanced vulnerability reporting to address specific compliance requirements and offers additional tech support. ThreadFix Community Edition, which is typically used by companies that have just a few applications under development, will remain an open source project and can be downloaded at http://www.threadfix.org/download. To learn more, visit http://www.threadfix.org or contact Denim Group at [email protected] or at (210) 572-4400.

ABOUT DENIM GROUP
Denim Group is the leading secure software development firm. The company builds custom large-scale software development projects across multiple platforms, languages and applications. What makes Denim Group unique is that the company brings significant core competencies in software security to the table, offering an innovative blend of secure software development, testing and training capabilitie s that protect a company's biggest asset, its data. Denim Group customers span an international client base of commercial and public sector organizations across the financial services, insurance, healthcare, education, government and defense industries. Its depth of experience building large-scale software development systems in a secure fashion has made the company’s leaders recognized experts in their fields. Denim Group has been recognized as one of the 5,000 Fastest Growing Company’s by Inc. Magazine five years in a row, and has won multiple awards including its accolades as one of the best places to work in San Antonio. For more information about Denim Group visit http://www.denimgroup.com.

Denim Group is a registered service mark of Denim Group, Ltd. Other names and brands may be claimed as the property of others.

Robin Lutchansky, Lutchansky Communications, http://www.LComm.com, +1 408 607 7118, [email protected]

Modal title

Denim Group Logo
Denim Group Logo
Portraying The Power of ThreadFix to De-Duplicate Scanning Reports
Portraying The Power of ThreadFix to De-Duplicate Scanning Reports
Dan Cornell, Denim Group CTO
Dan Cornell, Denim Group CTO
Denim Group Logo Portraying The Power of ThreadFix to De-Duplicate Scanning Reports Dan Cornell, Denim Group CTO

Contact PRWeb

  • 11AM ET Sunday – 8PM ET Friday
  • Contact Us

About PRWeb

  • About PRWeb
  • Partners
  • Partnership Programs
  • Editorial Guidelines
  • Resources

Why PRWeb

  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing

Accounts

  • Create a Free Account
  • Log in
  • Contact Us

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact Cision

Products

About

My Services
  • All News Releases
  • Online Member Center
  • ProfNet
Cision Distribution Helpline
888-776-0942
  • Legal
  • Site Map
  • RSS
  • Cookie Settings
Copyright © 2025 Cision US Inc.