4 Jan 2011

Client, Denim Group, Group Provides Guidance on Application Security Trends for 2011

Client, Denim Group, today announced its annual guidance on application security trends for 2011.  

Mobile Applications, Shifting to The Cloud, Malware on the iTunes / Droid Stores, The Smart Grid and More, Give Rise to New Forms of Application Security Threats in the New Year to Come

You may view the news release here on Yahoo News, or read / print the document below.

If you would like to interview Denim Group, CTO, Dan Cornell, please reach out to me - alan at weinkrantz dot com.

Click here to download:
2011Trends-_clean4.0.doc (41 KB)
(download)


 

17 Nov 2010

Security Media / Analysts / Bloggers - How to Guide for Software Security Vulnerability Remediation from Client, #DenimGroup

Client, Denim Group, has a compelling presentation on the subject of Software Security Vulnerability Remediation.  It's a handy and very practical "How to Guide" that can be adapted as source material for stories on the subject.

Denim Group does a lot of software security remediation projects, so they put together a how-to-guide based on their experiences.

How-To-Guide for Software Security Vulnerability Remediation

Most internal development teams are experts with coding and application development but lack the tools and methodology needed to efficiently remediate security flaws in web applications.

Denim Group's consultants are all practicing developers who track the latest software trends and methodology and have the expertise to fix vulnerabilities in the source code.

If you are a journalist, blogger or analyst looking for year-end security wrap up stories, or stories for 2011 trends, please reach out to me - alan at weinkrantz dot com and I will connect with Denim Group CTO - Dan Cornell.

View more documents from Denim Group.

 

15 Jan 2010

Client, Denim Group, Previews Release of its Vulnerability Manger - Java/Spring/Hibernate-based web application allowing organizations to automate and centrally manage administration of many of the functions of an application security program

Client, Denim Group just made the “technology preview” release of their Vulnerability Manager application available.  This is an internal Denim Group project they’ve been working on for a number of months.  It has been through a number of private and semi-public demonstrations, so they are really excited to make it available to a broader audience.

If you're an industry analyst, journalist, or blogger covering application security, reach out to me at: alan at weinkrantz dot com for a briefing.

Here's a quick overview....

Vulnerability Manager is a Java/Spring/Hibernate-based web application allowing organizations to automate and centrally manage administration of many of the functions of an application security program:

· Create and maintain a portfolio of applications

· Import and merge vulnerability results from a variety of free and commercial static and dynamic scanning tools

· Automatically generate WAF and IDS/IPS rules for identified vulnerabilities (virtual patching)

· Track attack statistics for vulnerabilities based on WAF and IDS/IPS logs

· Bundle vulnerabilities and send them to defect tracking systems

· Track team maturity practices according to standards such as OpenSAMM

There is an online screencast demo here:

Vulnerability Manager sprung from a number of conversations and engagements we had with clients discussing the problems they faced getting application security programs working in their organizations.  At Denim Group we have been fortunate to have the opportunity to work with folks across the spectrum of application security maturity and we think we have assembled some capabilities that will be compelling to many organizations.

Please remember, this is a “technology preview” release of the application.  What this means is:

· In short – it still needs serious work before I would put it in production.  Please be kind and constructive in your feedback

· It works well for our example files under controlled conditions.  Outside of those circumstances…  good luck (please let us know about any issues)

· The application has not been through a proper security review and has, in fact, been built in an ad hoc manner that we are aggressively working to correct (please do as we say, not as we’ve done thusfar)

· A number of must-have features surrounding configuration and workflow have not yet been completed.  Those are in progress

· Vulnerability Manager” is a terrible name for an application and we promise to come up with something cooler

If you explore the Vulnerability Manager site you can see a demonstration video showing how this works as well as some screenshots.  You can also download a running Tomcat-hosted version of the code.  We welcome feedback – especially constructive feedback.  Please submit feedback here.

 

6 Jan 2010

Client, Denim Group, Provides Guidance on Application Security Trends for 2010

Client, Denim Group, an IT consultancy and strong contributor to the larger application security community, has just announced that it foresees shifts in the application security landscape this year. As a trusted advisor to many Fortune 500 and large public sector organizations, the firm has just announced its guidance on the top application security trends for 2010.

eWeek broke the story earlier.  You may view the release on Yahoo Finance here.
27 Oct 2009

Journalists, Industry Analysts, Bloggers....need topical experts for Application Security? Follow client, @danielcornell and @johnbdickson / Denim Group

Members of the media, industry analysts, and bloggers - if you need topical expertise on Application Security, Software Security and issues critical to assessing and mitigating risks with their existing software  please reach out to me at alan at weinkrantz dot com.  I'll connect you with client, Denim Group.  

Follow Denim Group Principals - @danielcornell and @johnbdickson on twitter.

Screen_shot_2009-10-25_at_4

graphic done using Wordle.net
mode: space; -webkit-line-break: after-white-space; ">



1 Oct 2009

Client, Denim Group, Featured on Building43 Interview with @scobleizer

Here is client, Denim Group's @danielcornell and @johnbdickson talking about application security and broader security issues at large.

Many thanks to @scobleizer and the whole Rackspace team including @kr8tr and @rjamestaylor for helping to make this happen.

27 Aug 2009

Denim Group's Dan Cornell in Houston next week to speak to OWASP Chapter

(download)

Be sure to follow Dan on Twitter

19 Aug 2009

Client, Denim Group, Partners with Fortify Software

Denim Group Partners with Fortify Software

Denim Group Uses Fortify’s 360 Suite of Application Security Solutions on Software Development Projects

SAN ANTONIO--(BUSINESS WIRE)--Denim Group, an IT consultancy that develops secure software and helps organizations assess and mitigate risks with their existing software, announced today that it is partnering with Fortify® Software, the market leading provider of Software Security Assurance solutions. Under the agreement, Denim Group can now use Fortify 360, the market leading application for containing, removing and preventing vulnerabilities in software for Denim Group’s secure software development projects. A related video to this announcement may be viewed at: http://tinyurl.com/p3wa9k.

“Fortify’s technology brings together the critical analytic, remediation and management capabilities necessary for an effective Software Security Assurance program,” said Roger Thornton, founder and CTO of Fortify Software, Inc. “We’re pleased that a recognized leader like Denim Group has become a trusted delivery partner.”

Using both static and dynamic analysis methods, Fortify 360 identifies more than 400 types of security vulnerability across 17 different development languages. It provides line-of-code level details for vulnerabilities that are uncovered - a critical capability for organizations that are serious about reducing risk in their software.

“What makes us unique in our software development approach is that we use the Fortify solution for secure software development projects for our clients,” said John Dickson, Principal of Denim Group. “This enables us to build secure applications that our clients trust to protect their most sensitive information.”

About Denim Group

Denim Group develops secure software, helps organizations assess and mitigate risk with existing software, and provides training on best practices in software security. Denim Group has worked with a range of Fortune 500 companies and public sector organizations, bringing a focused software development approach to the world of software security. The Company provides clients with secure .NET and Java development services and remediates serious software flaws in existing application portfolios. Denim Group also identifies vulnerabilities and quantifies risks that vulnerable applications represent through assessments, code reviews, and application-focused penetration testing. Training complements Denim Group’s development and testing services by helping organizations build an internal competency in secure software development and testing through a combined classroom instruction and e-Learning approach.

Denim Group is a strong contributor to the larger application security community, and has been involved with the Open Web Application Security Project (OWASP) since shortly after its inception. Additionally, Denim Group was ranked in Inc. Magazine's 5,000 Fastest-Growing Private Companies in America in 2008 and 2009.

About Fortify Software, Inc.

Fortify's Software Security Assurance products and services protect companies from the threats posed by security flaws in business–critical software applications. Its software security suite–Fortify 360–drives down costs and security risks by automating key processes of developing and deploying secure applications. Fortify Software's customers include government agencies and FORTUNE 500 companies in a wide variety of industries, such as financial services, healthcare, e–commerce, telecommunications, publishing, insurance, systems integration and information management. The company is backed by world–class teams of software security experts and partners. More information is available at www.fortify.com or visit our blog.

Reader Contact Information:

Denim Group, 3463 Magic Drive, Suite 315; San Antonio, TX 78229, Tel: 210-572-4400, Fax: 210-572-4401, www.denimgroup.com, john@denimgroup.com.

Fortify Software, Inc., 2215 Bridgepointe Pkwy, Suite 400; San Mateo, CA 94404, Tel: 650-358-5600, Fax: 650-358-4600, www.fortify.com, contact@fortify.com.

 

12 Aug 2009

Denim Group's @danielcornell and @johnbdickson interviewed by @scobleizer today

For client, Denim Group, we just finished an interview with Robert Scoble, and his compadre Rocky Barbanica. Dan Cornell - @danielcornell and John Dickson - @johnbdickson did a great job in articulating the Denim Group story.

Dsc_0090

Thanks to the whole team over Rackspace, including Rob La Gesse - @kr8tr and Robert Taylor - rJamesTaylor for getting us connected.

 

28 Jul 2009

News From Black Hat 2009: Client, Denim Group, Teams Up with WhiteHat Security - Yahoo! Finance

businesswire

Denim Group Teams Up with WhiteHat Security

Partnership Allows Denim Group to Offer Clients a Full Portfolio of Protection and Application Risk Management Services Including Ongoing Website Vulnerability Management

SAN ANTONIO & LAS VEGAS--(BUSINESS WIRE)--Today at Black Hat USA 2009, Denim Group, an IT consultancy that develops secure software and helps organizations assess and mitigate risks with their existing software, announced today that it has teamed with WhiteHat Security, the leading provider of website risk management solutions. The partnership enables Denim Group to expand its portfolio of services by offering WhiteHat Sentinel for ongoing website vulnerability management to quickly and accurately identify security defects in Web applications. A related video to this announcement may be viewed at: http://tinyurl.com/nzkrcy.

“Today, more than 70 percent of hacker attacks worldwide are actively targeting websites, and 80% of sites have a serious vulnerability, so the importance of website security cannot be overstated,” said Jeremiah Grossman, founder and CTO of WhiteHat Security. “We’re pleased to partner with an experienced application security provider like Denim Group to ensure that companies have ongoing website vulnerability management oversight which enables them to protect critical data, ensure compliance, and narrow the window of risk.”

The WhiteHat Sentinel family of website security solutions delivers the visibility, flexibility and control that enables companies to secure their websites, regardless of company size or volume of applications. WhiteHat Sentinel delivers accurate, and verified results via an on-demand, SaaS-based subscription service, combining advanced proprietary automated scanning technology with expert analysis. Once software vulnerabilities are identified, Denim Group’s seasoned development team can prioritize risks and quickly remediate security defects found in its customers’ applications. In addition, Denim Group offers website security training, providing everything from individual courses to entire training and process improvement initiatives targeted at those building, testing, and managing custom software.

“This partnership allows Denim Group to use White Hat’s technology to provide its clients with ongoing vulnerability assessment for their Web application portfolio,” said Dan Cornell, principal of Denim Group. “In addition, we can accelerate remediation times for WhiteHat’s customers and offer targeted education services on Web application security so that the same vulnerabilities don’t get reintroduced.”

About Denim Group

Denim Group develops secure software, helps organizations assess and mitigate risk with existing software, and provides training on best practices in software security. Denim Group has worked with a range of Fortune 500 companies and public sector organizations, bringing a focused software development approach to the world of software security. The Company provides clients with secure .NET and Java development services and remediates serious software flaws in existing application portfolios. Denim Group also identifies vulnerabilities and quantifies risks that vulnerable applications represent through assessments, code reviews, and application-focused penetration testing. Training complements Denim Group’s development and testing services by helping organizations build an internal competency in secure software development and testing through a combined classroom instruction and e-Learning approach.

Denim Group is a strong contributor to the larger application security community, and has been involved with the Open Web Application Security Project (OWASP) since shortly after its inception. Additionally, Denim Group was ranked 1101 in Inc. Magazine's 5000 Fastest-Growing Private Companies in America in 2008.

For more information about Denim Group, visit www.denimgroup.com.

About WhiteHat Security, Inc.

Headquartered in Santa Clara, California, WhiteHat Security is the leading provider of website risk management solutions that protect critical data, ensure compliance and narrow the window of risk. WhiteHat Sentinel, the company’s flagship product family, is the most accurate, complete and cost-effective website vulnerability management solution available. It delivers the visibility, flexibility, and control that organizations need to prevent Web attacks. Furthermore, WhiteHat Sentinel enables automated mitigation of website vulnerabilities via integration with Web application firewalls. To learn more about WhiteHat Security, please visit our website at www.whitehatsec.com

Recommended Social Tags: Denim Group, WhiteHat Security, Vulnerability Assessment

Reader Contact Information:

Denim Group, 3463 Magic Drive, Suite 315; San Antonio, TX 78229, Tel: 210-572-4400,
Fax: 210-572-4401, www.denimgroup.com, john@denimgroup.com.

WhiteHat Security, Inc., 3003 Bunker Hill Lane, Suite 220; Santa Clara, CA 95054, Tel: 408-343-8300, Fax: 408-904-7142, www.whitehatsec.com, sales@whitehatsec.com.

Denim Group is a registered service mark of Denim Group, Ltd.

Other names and brands may be claimed as the property of others.

Contact:

Agency Contact:Alan Weinkrantz, 210.820.3070alan@weinkrantz.comorDenim Group Contact:John B. Dickson, CISSP, 210.572.4400john@denimgroup.com

 

Contributors

Alan Weinkrantz