Developed jointly by both companies, Hybrid 2.0 brings together static and dynamic applications vulnerability testing of source code under a common framework. According to Russell Spitler, a Fortify product manager, Hybrid 2.0 will for the first time allow developers to see how an attack is exploiting vulnerabilities in their applications in real time.
As developers take increasing responsibility for the security of their applications, IT organizations need to provide developers with the appropriate sets of tools that will allow them to be proactive about fixing security flaws, said Spitler.

In addition to reducing the amount of time it takes to perform vulnerability testing, Spitler noted that integrating static and dynamic testing under one offering will also substantially reduce the number of false positive results in the overall testing process.
Hybrid 2.0 combines elements of HP’s Assessment Management Platform for vulnerability testing with Fortify’s Source Code Analyzer and Program Trace Analyzer products.
The two companies plan to demonstrate Hybrid 2.0, which is scheduled to be available before the end of June, at the RSA Conference 2010 conference in San Francisco next week.
Comments
Post new comment