|
Project Title: Testing Security in E-Commerce
(Certifying Security in Electronic Commerce Components)
Project: To design a rigorous process
and core testing technologies for assuring the security of software
components, a key enabling technology for Internet-based electronic
commerce.
Duration: 1/2/1998 - 1/1/2001
ATP
Number:
97-06-0005
Funding
(in thousands):
ATP Final Cost
$1,978 83.9%
Participant Final Cost 380 16.1%
Total $2,358
Accomplishments: With ATP funding, Reliable
Software Technologies (RST), which was renamed Cigital in 2000,
accomplished the following:
·
Developed a rigorous process and tools to diagnose vulnerabilities
in web-based software applications
·
Wrote a program that scans source code for vulnerabilities, issues
a report, and suggests solutions
·
Received widespread media coverage for discovering flaws in a
gambling website and for confirming flaws in Java and Netscape Navigator
·
Was named by Deloitte and Touche and the Virginia Chamber of
Commerce as one of the 50 fastest growing companies in Virginia and was twice named by Inc.
magazine among the 500 top-performing firms
Commercialization
Status: The
ATP-funded technology was the basis for two products. One was developed
by a former RST colleague who is now a competitor. Cigital uses the
second product, SourceScope, in its work with its own clients and also
licenses it to Fortify Software, in which it owns a percentage and with
which it maintains a consulting relationship.
Outlook: The outlook for this
technology is strong. Because security is a critical concern with online
transactions, the market for tools to spot flaws and prevent their
exploitation is robust.
Composite Performance Score: * *
* *
|
Number of Employees: 35 at start of project; 100 as
of January 2006
Focused Program: Component-Based Software, 1997
Company:
Cigital, Inc.
21351 Ridgetop Circle
Suite 400
Dulles, VA 20166
Contact:
Jeffery Payne
Phone: (703) 404-9293
Publications:
·
Ghosh, A.K. “Securing E-commerce: A
Systematic Approach.” Journal
of Electronic Commerce, 2, September 1997.
·
Ghosh, Anup K. E-Commerce Security: Weak Links, Best Defenses. New York: John
Wiley and Sons, 1998.
·
Ghosh, A.K. "E-commerce Security: No
Silver Bullet." Database
Security XII: Status and Prospects. IFIP International Federation for
Information Processing , Vol. 14 Heidelberg:
Springer Verlag, 1999.
·
McGraw, Gary and Ed Felten. Securing Java: Getting Down to
Business with Mobile Code. New York: John
Wiley and Sons, 1999.
·
Voas, Jeffrey. “Developing a Usage-Based
Software Certification Process.” IEEE Computer Society 33, pp. 27-32 August 2000.
·
Walls, T.J., V. Shah, and A.K. Ghosh.
“Towards Certifying Software for Security.” International
Security Assurance Certification Conference (ISACC) 2000, September 2000.
Presentations:
·
Ghosh, A.K. “Certifying Security of Components Used in
Electronic Commerce.” Workshop on Compositional Software
Architectures, Monterey,
CA, January 6-9, 1998.
·
Ghosh, A.K. “E-Commerce Security: Protecting Your Clients,
Your Reputation, and Your Profit.” NetExpo Washington, Washington,
D.C., September 9, 1998.
|