Welcome!

News Feed Item

Synopsys Enhances Its Software Integrity Platform to Address Evolving Needs of Organizations Building Security and Quality into their Software

Latest Product Updates Expand Coverage for New Programming Languages and MISRA Compliance, Improve Integration Capabilities and Increase Flexibility

MOUNTAIN VIEW, Calif., July 13, 2017 /PRNewswire/ -- Synopsys, Inc. (Nasdaq: SNPS) today announced key updates to its Software Integrity Platform that are designed to help companies build security and quality into their software while reducing time-to-market. In the era of digital transformation, building secure and reliable software is challenged by the rapid, complex and diverse nature of development cycles. The latest updates to the Synopsys Software Integrity Platform address these challenges with expanded support for new programming languages, full coverage for the Motor Industry Software Reliability Association (MISRA) guidelines, improved automation and integration capabilities, and increased flexibility.

According to a recent Forrester Research report, "Applications are increasingly the face of interaction between companies and their customers; this includes customer-facing applications, differentiating mobile apps, Internet-of-things (IoT) device interfaces, and streamlined back-end processes. Meanwhile, application security technologies continue to evolve based on new developer methodologies, new attack vectors, new application types, and new business needs."1

"The latest enhancements to the Synopsys Software Integrity Platform help organizations address the rapid pace of change when developing and securing their software," said Andreas Kuehlmann, senior vice president and general manager for the Synopsys Software Integrity Group. "By expanding our coverage to include new programming languages and standards compliance, and ensuring our solutions integrate with a diverse ecosystem of development tools, we enable our platform to be adaptable to a wide range of customer needs. Synopsys is positioned to guide organizations along their software integrity journey as the industry landscape evolves."

The new updates to the Synopsys Software Integrity Platform include a wide range of enhancements and features: 

Expanded coverage: Organizations are expanding their software portfolios, resulting in the adoption of new programming languages, frameworks, and open source software components, while they are simultaneously navigating security, quality and compliance requirements. Empowering organizations to improve the security and quality of their broadening software portfolios, Synopsys continues to expand the coverage of its Software Integrity Platform.

  • Programming languages and analysis checkers –  The latest platform updates introduce Coverity® Static Analysis support for the Swift programming language, improved Protecode™ Software Composition Analysis support for open-source components written in Ruby programming language, and new eLearning courses for secure programming techniques in Android, iOS, and JavaScript. Synopsys has also expanded its static analysis offerings to detect a wider range of security and quality defects across all supported programming languages including Java and JavaScript.
  • Industry standards – Synopsys' Static Analysis tool now provides full coverage for MISRA, a series of software development guidelines used by the automotive and other safety-critical industries to promote the safety and security of embedded systems. With this update, the Synopsys' Software Integrity Platform now supports all statically verifiable rules in MISRA C 2004, MISRA C++ 2008, and MISRA C 2012.

Integration and automation: With the emergence of trends such as DevOps and continuous integration/continuous deployment (CI/CD), organizations are shifting toward more rapid and iterative development methodologies. To keep pace, software security testing efforts need to leverage automation and integrate with development tool chains and workflows. Synopsys continues to introduce news ways to automate the security and quality testing process, integrating it seamlessly with other development tools and workflows.

  • Synopsys updated its static analysis integration with CI/CD tools like Jenkins, as well as current versions of popular integrated development environments (IDEs), including Eclipse 4.7, Microsoft Visual Studio 2017, and IntelliJ IDEA. Integrating static analysis into development tools allows organizations to test early and often without disrupting their workflows or leaving their development environments.
  • Synopsys updated its software composition analysis solution to automate the confirmation of identified open-source software components, which accelerates adoption and time-to-value.
  • For its Managed Services for application security testing (AST), Synopsys added additional API enhancements to assist clients with automation of assessments. Organizations can manage their applications via the API, as well as export results and schedule assessments.

Flexibility: When it comes to making software secure, every organization has unique requirements and challenges that go beyond the confines of traditional out-of-the-box security solutions. Synopsys is committed to making its Software Integrity Platform flexible and customizable, giving companies the freedom to tailor the existing solutions to address new or special needs.

  • In this latest update, Synopsys introduced a Defensics® Fuzz Testing Software Development Kit (SDK) for building custom fuzz testing tools that detect critical security vulnerabilities in software applications and embedded devices. The SDK is built on the underlying technology of the industry leading Defensics Fuzz Testing tool, which was used to discover the infamous Heartbleed vulnerability. The Synopsys Fuzz Testing SDK is a powerful framework that provides companies the flexibility to test proprietary, niche or previously unsupported communication protocols and file formats.
  • Synopsys also added more flexibility to its eLearning solution, the self-paced security training component of its Software Integrity Platform. It has modularized the courses into bite-sized, consumable and mobile responsive modules, providing developers with focused training around a wide array of evolving technology stacks.
  • Synopsys added workflow enhancements to its Managed Services for application security testing to increase customer self-service and flexibility. Tests can now be removed from the queue and rescheduled quickly and easily. A new commenting feature was also introduced to the Managed Services workflow, providing a single location for customers and Synopsys consultants to communicate, ask questions, and provide updates. These updates enable Synopsys' Managed Services offering to be more responsive to organizations' changing needs, ultimately improving service utilization and value delivered.

About the Synopsys Software Integrity Platform

Synopsys offers the most comprehensive solution for building integrity —security and quality— into the software development lifecycle and supply chain. The Software Integrity Platform unites leading testing technologies, automated analysis, and experts to create a robust portfolio of products and services. This portfolio enables companies to develop personalized programs for detecting and remediating defects and vulnerabilities early in the development process, minimizing risk and maximizing productivity. Synopsys, a recognized leader in Application Security Testing (AST), is uniquely positioned to adapt and apply best practices to new technologies and trends such as IoT, DevOps, CI/CD, and the Cloud. For more information, go to www.synopsys.com/software.

About Synopsys

Synopsys, Inc. (Nasdaq: SNPS) is the Silicon to Software partner for innovative companies developing the electronic products and software applications we rely on every day. As the world's 15th largest software company, Synopsys has a long history of being a global leader in electronic design automation (EDA) and semiconductor IP and is also growing its leadership in software security and quality solutions. Whether you're a system-on-chip (SoC) designer creating advanced semiconductors, or a software developer writing applications that require the highest security and quality, Synopsys has the solutions needed to deliver innovative, high-quality, secure products. Learn more at www.synopsys.com.

1. "TechRadar: Application Security, Q3 2017", Forrester Research, Inc., July 6, 2017

Editorial Contacts:
Mark Van Elderen                                                           
Synopsys, Inc.
650-793-7450
[email protected]

Simone Souza
Synopsys, Inc.
650-584-6454
[email protected]

 

View original content:http://www.prnewswire.com/news-releases/synopsys-enhances-its-software-integrity-platform-to-address-evolving-needs-of-organizations-building-security-and-quality-into-their-software-300487552.html

SOURCE Synopsys, Inc.

More Stories By PR Newswire

Copyright © 2007 PR Newswire. All rights reserved. Republication or redistribution of PRNewswire content is expressly prohibited without the prior written consent of PRNewswire. PRNewswire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

Latest Stories
IoT is at the core or many Digital Transformation initiatives with the goal of re-inventing a company's business model. We all agree that collecting relevant IoT data will result in massive amounts of data needing to be stored. However, with the rapid development of IoT devices and ongoing business model transformation, we are not able to predict the volume and growth of IoT data. And with the lack of IoT history, traditional methods of IT and infrastructure planning based on the past do not app...
Internet-of-Things discussions can end up either going down the consumer gadget rabbit hole or focused on the sort of data logging that industrial manufacturers have been doing forever. However, in fact, companies today are already using IoT data both to optimize their operational technology and to improve the experience of customer interactions in novel ways. In his session at @ThingsExpo, Gordon Haff, Red Hat Technology Evangelist, shared examples from a wide range of industries – including en...
To get the most out of their data, successful companies are not focusing on queries and data lakes, they are actively integrating analytics into their operations with a data-first application development approach. Real-time adjustments to improve revenues, reduce costs, or mitigate risk rely on applications that minimize latency on a variety of data sources. Jack Norris reviews best practices to show how companies develop, deploy, and dynamically update these applications and how this data-first...
In IT, we sometimes coin terms for things before we know exactly what they are and how they’ll be used. The resulting terms may capture a common set of aspirations and goals – as “cloud” did broadly for on-demand, self-service, and flexible computing. But such a term can also lump together diverse and even competing practices, technologies, and priorities to the point where important distinctions are glossed over and lost.
Intelligent Automation is now one of the key business imperatives for CIOs and CISOs impacting all areas of business today. In his session at 21st Cloud Expo, Brian Boeggeman, VP Alliances & Partnerships at Ayehu, will talk about how business value is created and delivered through intelligent automation to today’s enterprises. The open ecosystem platform approach toward Intelligent Automation that Ayehu delivers to the market is core to enabling the creation of the self-driving enterprise.
"At the keynote this morning we spoke about the value proposition of Nutanix, of having a DevOps culture and a mindset, and the business outcomes of achieving agility and scale, which everybody here is trying to accomplish," noted Mark Lavi, DevOps Solution Architect at Nutanix, in this SYS-CON.tv interview at @DevOpsSummit at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
"We're here to tell the world about our cloud-scale infrastructure that we have at Juniper combined with the world-class security that we put into the cloud," explained Lisa Guess, VP of Systems Engineering at Juniper Networks, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
Enterprise architects are increasingly adopting multi-cloud strategies as they seek to utilize existing data center assets, leverage the advantages of cloud computing and avoid cloud vendor lock-in. This requires a globally aware traffic management strategy that can monitor infrastructure health across data centers and end-user experience globally, while responding to control changes and system specification at the speed of today’s DevOps teams. In his session at 20th Cloud Expo, Josh Gray, Chie...
"We're a cybersecurity firm that specializes in engineering security solutions both at the software and hardware level. Security cannot be an after-the-fact afterthought, which is what it's become," stated Richard Blech, Chief Executive Officer at Secure Channels, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Consumers increasingly expect their electronic "things" to be connected to smart phones, tablets and the Internet. When that thing happens to be a medical device, the risks and benefits of connectivity must be carefully weighed. Once the decision is made that connecting the device is beneficial, medical device manufacturers must design their products to maintain patient safety and prevent compromised personal health information in the face of cybersecurity threats. In his session at @ThingsExpo...
In his session at 20th Cloud Expo, Mike Johnston, an infrastructure engineer at Supergiant.io, discussed how to use Kubernetes to set up a SaaS infrastructure for your business. Mike Johnston is an infrastructure engineer at Supergiant.io with over 12 years of experience designing, deploying, and maintaining server and workstation infrastructure at all scales. He has experience with brick and mortar data centers as well as cloud providers like Digital Ocean, Amazon Web Services, and Rackspace. H...
You know you need the cloud, but you’re hesitant to simply dump everything at Amazon since you know that not all workloads are suitable for cloud. You know that you want the kind of ease of use and scalability that you get with public cloud, but your applications are architected in a way that makes the public cloud a non-starter. You’re looking at private cloud solutions based on hyperconverged infrastructure, but you’re concerned with the limits inherent in those technologies.
SYS-CON Events announced today that Grape Up will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct. 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Grape Up is a software company specializing in cloud native application development and professional services related to Cloud Foundry PaaS. With five expert teams that operate in various sectors of the market across the U.S. and Europe, Grape Up works with a variety of customers from emergi...
DevOps is under attack because developers don’t want to mess with infrastructure. They will happily own their code into production, but want to use platforms instead of raw automation. That’s changing the landscape that we understand as DevOps with both architecture concepts (CloudNative) and process redefinition (SRE). Rob Hirschfeld’s recent work in Kubernetes operations has led to the conclusion that containers and related platforms have changed the way we should be thinking about DevOps and...
SYS-CON Events announced today that SkyScale will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. SkyScale is a world-class provider of cloud-based, ultra-fast multi-GPU hardware platforms for lease to customers desiring the fastest performance available as a service anywhere in the world. SkyScale builds, configures, and manages dedicated systems strategically located in maximum-security...