The i-Technology Media!
Register | Log in
   
 
.NET  ·  AJAX  ·  CLOUD  ·  ECLIPSE  ·  FLEX  ·  OPEN WEB  ·  iPHONE  ·  JAVA  ·  LINUX  ·  OPEN SOURCE  ·  ORACLE  ·  PBDJ  ·  SEARCH  ·  SILVERLIGHT  ·  SOA  ·  VIRTUALIZATION  ·  WEB 2.0  ·  WIRELESS  ·  XML
Comments
Plone and Drupal: Different Approaches, Different Results
paul.nowak wrote: Matt, thanks for the comments. I made an error on the version of Plone. It's 2.5 Plone running on Zope 2.9x. In regards to the additional products, we have a skin installed and we have a product that we had custom developed for us that connects to a PostgreSQL database. We've looked at slow PostgreSQL queries causing problems and have not been able to find an issue. We've also tested for the case where the PostgreSQL server is down and have not been able to create an issue. We therefor...
Nov. 4, 2009 04:19 PM EST
Cloud Expo on Google News
Did you read today's front page stories & breaking news?


2009 East
PLATINUM SPONSORS:
IBM
Smarter Business Solutions Through Dynamic Infrastructure
IBM
Smarter Insights: How the CIO Becomes a Hero Again
Microsoft
Windows Azure
GOLD SPONSORS:
Appsense
Why VDI?
CA
Maximizing the Business Value of Virtualization in Enterprise and Cloud Computing Environments
ExactTarget
Messaging in the Cloud - Email, SMS and Voice
Freedom OSS
Stairway to the Cloud
Sun
Sun's Incubation Platform: Helping Startups Serve the Enterprise
POWER PANELS:
Cloud Computing & Enterprise IT: Cost & Operational Benefits
How and Why is a Flexible IT Infrastructure the Key To the Future?
Click For 2008 West
Event Webcasts

2009 East
GOLD SPONSORS:
CA
Get Your Transactions Under Control: SOA Performance Management
Software AG
Performance Driven Adoption: The Secret to Advancing SOA
Intel
The Evolving SOA Appliance: 3 Game-Changing Innovations
SILVER SPONSOR:
Denodo
Data Mashups: Deliver Your Project Faster with Virtualized Data Services Across Internal & External Sources
POWER PANELS:
The Business Value of Service Orientation
Driving Profitability Through User Experience
Click For 2008 West
Event Webcasts
Live Google News by SYS-CON!
Top Three Links You Must Click On


From the Wires
Palamida Launches Open Source Vulnerability Reporting Solution
New Solution Enhances IT Governance by Pinpointing Known Security Risks in Open Source Code

By: PR Newswire
Apr. 23, 2007 12:00 PM

SAN FRANCISCO, April 23 /PRNewswire/ -- Gartner SYMPOSIUM/ITxpo -- Palamida(TM), the leader in software intellectual property management solutions and audit services, today announced that it has extended the reach of its extensive compliance library and launched a new service, the Vulnerability Reporting Solution (VRS). VRS works seamlessly with Palamida's code audit compliance solution, IP Amplifier(TM), to identify, prioritize, and report known vulnerabilities within open source code used in customers' projects.

Access to readily available code resources, geographically distributed development teams, and increasing time-to-market pressures have given rise to the blending of homegrown, third-party and open source components. The sheer size of today's typical software projects coupled with the number of contributing developers makes it difficult and time consuming for companies to get an accurate assessment of their software assets: What do they have? Where did it come from? What are its intellectual property and security risks?

Thorough risk mitigation calls for more than just firewalls and virus scanning, it requires code level protection against legal, financial and security risks -- it requires solutions robust enough to identify software intellectual property challenges and known vulnerabilities in the code base.

Code Level Risk Mitigation

Existing vulnerability analysis solutions scan customers' proprietary code to identify potential vulnerability holes due to coding practices such as buffer overflow and similar problems. The VRS complements these tools to further enhance the IT Governance process by both pinpointing the use of open source content and reporting on known vulnerabilities based on aggregated information from many sources.

"Successful IT Governance requires risk mitigation at the code level," said Mark Tolliver, CEO of Palamida. "By combining our scanning and detection technology with the excellent content available through repositories such as the National Vulnerability Database, we are able to bring a new level of transparency and confidence to enterprise use of open source software."

Enhancing the Value of Existing Solutions

The VRS is the perfect complement to vulnerability analysis implementations and further extends the breadth and depth of Palamida's existing compliance library -- the industry's largest and most comprehensive database of its type.

"Due to the nature of our business, we are committed to both security and efficiency," notes Stephen Chen, Managing Director of SEC Ventures. "Palamida's Vulnerability Reporting Solution delivers the depth and insight necessary for us to rectify any potential security issues, if found, in a quick and efficient manner."

"As an open source technology with a huge user base, it's very important to us to spot any new security vulnerabilities immediately," said Ron Park, VP of Engineering at MuleSource. "Palamida's VRS enables our development team to track and remediate any open source vulnerabilities as they arise -- giving us the ability to proactively address them, rather than react to them. Palamida's VRS provides us with a lot of value."

Composed of 3 Terabytes worth of content, Palamida's library contains over 140,000 OSS projects, 780,000 versions, 7 billion source code snippets, 10 million Java namespaces, 500 million binary file IDs, and Java, C/C++, Perl, Python, PHP, C#, and VB signatures, among other components.

The VRS provides relevant and timely information on open source vulnerabilities by leveraging data from the National Vulnerability Database (NVD), a comprehensive cyber security database sponsored by the Department of Homeland Security, run by the National Institute of Standards and Technology, with Common Vulnerability and Exposure (CVE) data from The MITRE Corporation. The NVD integrates all publicly available US government vulnerability resources and provides references to industry resources for the purpose of assisting with remediation efforts. The NVD currently contains over 23,700 known vulnerabilities in total, 89 US-CERT issued alerts, and 1,900 US-CERT vulnerability notes. There are an average of 19 new CVEs added to the NVD each day.

About the Company

Palamida enables organizations to manage the growing complexity of multi- source development environments by answering the question, "What's in your code?" Through detailed analysis of the code base customers gain insight into their code inventory -- a critical component of quality control, risk mitigation, and vulnerability assessment.

Palamida was founded in 2003, offering market leading solutions and services that accelerate the adoption of open source within the enterprise environment by eliminating legal and vulnerability concerns associated with its use. Customers include Avaya, Cisco Systems, EMC, and Microsoft, among others. Read Palamida's blog at http://www.palamida.com/blog or for more information visit http://www.palamida.com/.

Palamida

CONTACT: Melisa Bleasdale of Palamida, +1-415-777-9400 x140, or cell,
+1-408-219-1969

Web site: http://www.palamida.com/
http://www.palamida.com/blog
http://www.gartner.com/it/sym/2007/spg9/spg9.jsp

Published Apr. 23, 2007— Reads 142
Copyright © 2007 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
About PR Newswire
Copyright © 2007 PR Newswire. All rights reserved. Republication or redistribution of PRNewswire content is expressly prohibited without the prior written consent of PRNewswire. PRNewswire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON Featured Whitepapers

ADS BY GOOGLE

Breaking Java News
BDNA Webinar Helps Businesses Prepare for and Survive a Software Audit
KACE™ Expands Dell Support With New Appliance
Biosyntrx, Inc. Appoints New CEO
WebMD Announces Drugs.com to Join the WebMD Health Network
Clear Skies Signs $4.8 Million Contract With Microdyne Plastics Inc.
Olympus Announces Merger With Zedex to Expand Gold Production and Exploration Assets in South East Asia
First National Bank Selects QuorumLabs for One-Click Business Continuity
Sportline Launches META, the Watch-Less Heart Rate Monitor MP3 Player with Audible Heart Rate Training Feedback
Exalead to Demonstrate Smart Search Solution for Travel and Leisure at PhoCusWright Conference Travel Innovation Summit
Community Health Works, Houston and Bibb County Schools, and HealthTeacher Partner to Teach Kids Health Literacy

ADVERTISE   |   MAGAZINE SUBSCRIPTIONS   |   FREE BREAKING-NEWSLETTERS!   |   SYS-CON.TV   |   BLOG-N-PLAY!   |   WEBCAST   |   EDUCATION   |   RESEARCH

.NET Developer's Journal - .NETDJ   |   ColdFusion Developer's Journal - CFDJ   |   Eclipse Developer's Journal - EDJ   |   Enterprise Open Source Magazine - EOS
Open Web Developer's Journal - OPENWEB   |   iPhone Developer's Journal - iPHONE   |   Virtualization - Virtualization   |   Java Developer's Journal - JDJ   |   Linux.SYS-CON.com
PowerBuilder Developer's Journal - PBDJ   |   SEO / SEM Journal - SJ   |   SOAWorld Magazine - SOAWM   |   IT Solutions Guide - ITSG   |   Symbian Developer's Journal - SDJ
WebLogic Developer's Journal - WLDJ   |   WebSphere Journal - WJ   |   Wireless Business & Technology - WBT   |   XML-Journal - XMLJ   |   Internet Video - iTV
Flex Developer's Journal - Flex   |   AJAXWorld Magazine - AWM   |   Silverlight Developer's Journal - SLDJ   |   PHP.SYS-CON.com   |   Web 2.0 Journal - WEB2
Apache   |   CMS   |   CRM   |   HP   |   Oracle Journal   |   Perl   |   Python   |   Red Hat   |   Ruby on Rails   |   SAP   |   SaaS

SYS-CON MEDIA:   ABOUT US   |   CONTACT US   |   COMPANY NEWS   |   CAREERS   |   SITE MAP
SYS-CON EVENTS:   |  AJAXWorld Conference & Expo  |  iPhone Developer Summit  |  Cloud Computing Conference & Expo  |  SOA World Conference & Expo  |  Virtualization Conference & Expo
INTERNATIONAL SITES:   India  |  U.K.  |  Canada  |  Germany  |  France  |  Australia  |  Italy  |  Spain  |  Netherlands  |  Brazil  |  Belgium
 Terms of Use & Our Privacy Statement     About Newsfeeds / Video Feeds
Copyright ©1994-2008 SYS-CON Publications, Inc. All Rights Reserved. All marks are trademarks of SYS-CON Media.
Reproduction in whole or in part in any form or medium without express written permission of SYS-CON Publications, Inc. is prohibited.
 
close this window