Cimdata Logo

Industry Summary Articles

Monday, February 12, 2024

OpenText Takes Code Security to the Next Level with Innovative use of Machine Learning

OpenText™ announced the second generation of its advanced cybersecurity auditing technology debuting at the inaugural OpenText Security Summit 2024 on February 6. Today’s developers are dealing with more complexity and threats in multi-cloud environments. Security teams feel increasing pressure to tackle application security with more sophisticated tools and practices. Fortify Audit Assistant is OpenText’s solution for incorporating security at the very beginning of the software development lifecycle—at code inception—and building robust, secure, and reliable software systems.

Fortify Audit Assistant levels up the accuracy and performance, increasing developer efficiency by reducing noise and false positives. In doing so, security teams can focus on the vulnerabilities that matter most. Triaging and validating raw static analysis results is one of the most time-intensive, manual processes within application security testing. Companies can’t afford to hire a team of human examiner experts in software engineering, computer science, and software vulnerabilities. Fortify Audit Assistant was created to automate security and address these issues by utilizing machine learning to learn from Fortify’s human auditors.

“The first generation of Fortify Audit Assistant was well ahead of its time with its use of predictive analytics and machine learning,” said Prentiss Donohue, Cybersecurity Executive Vice President. “Those pioneering efforts paved the way for us to derive 10 years of data from human experts and turn them into predictive models that are significantly more accurate compared to the previous generation’s models, improving efficacy in auditing by reducing false positives up to 90%. Enterprises can now leverage this depth of information—something no one else in the industry can provide—within their own software assurance programs.”

Major updates to the next generation of Fortify Audit Assistant include:

  • Account for model drift. The new Audit Assistant models take a proactive approach to the ever-changing threat environment by automating the processes that measure and report how models are doing and refresh them as necessary to address any model drift. Updated models will be delivered each quarter.
  • Flexibility to learn from a company’s unique environment. The next generation Audit Assistant addresses the unique data privacy needs of each company. In generation one, a single model was used for both SaaS and on-prem environments. The new Audit Assistant on-prem model pipeline was designed to learn the unique behaviors of a company’s projects. This learning gets better and better over time as more vulnerabilities are audited, the models continually learn what’s appropriate for a company’s project—all while remaining sensitive to its IP.
  • Expansive model expertise via language specification. No single model can effectively cover every programming language. To provide greater insight and expertise into vulnerabilities in both on-prem and cloud environments, the next generation of Fortify Audit Assistant now includes 30+ language-specific models. Having a single model for C++, another model for JavaScript, etc. greatly improves model performance by enabling a “team of experts” (AKA the models) to go narrower and deeper thus increasing the likelihood of finding the true vulnerabilities in software.
  • Additional data and context. Fortify Audit Assistant scans and identifies true positive or false positive amongst millions of lines of code. Sometimes a scan result is a vulnerability, but might not be exploitable because the code in question is test code, not code that is deployed. In this next generation, Fortify Audit Assistant considers the nuances of scan results. In doing so, speed and efficacy of audits are greatly improved.

Attendees of the OpenText Security Summit will be shown a demo of Fortify Audit Assistant; the demo will also be available for replay. Additional summit demonstrations to include Voltage Fusion + Content Services, a unique integration that solves the challenges of managing sensitive data, and NetIQ Identity Manager in the OpenText Private Cloud, a compliance offering that extends across hybrid environments.

To view the original press release, please click here.

Search for OpenText on CIMdata.com

r
ipad background image

Featured Cimdata Reports

ipadcontent
PLM-Enabled Digital Transformation Benefits Appraisal Guide

The Guide is designed to help potential PLM users evaluate the applicability and payoffs of PLM in their enterprise, and to help existing users of PLM monitor the impact it is having on their product programs.

ipadcontent
PLM Market Analysis Reports

The PLM MAR Series provides detailed information and in-depth analysis on the worldwide PLM market. It contains analyses of major trends and issues, leading PLM providers, revenue analyses for geographical regions and industry sectors, and historical and projected data on market growth.

ipadcontent
PLM Market Analysis Country Reports

These reports offer country-specific analyses of the PLM market. Their focus is on PLM investment and use in industrial markets. Reports cover Brazil, France, Germany, India, Italy, Japan, Russia, South Korea, the United Kingdom, and the United States.

ipadcontent
Simulation & Analysis Market Analysis Report

This report presents CIMdata’s overview of the global simulation and analysis market, one of the fastest growing segments of the overall product lifecycle management market, including profiles of the leading S&A firms.

ipadcontent
CAM Market Analysis Report

This report presents CIMdata’s overview of the worldwide CAM software and services market. It also includes a discussion on the trends in the CAM industry and updates on the top CAM solution providers.