Vendors touting wares for source code management at an industry event Wednesday cited different business strategies for this market. But all made solid points about critical issues such as intellectual property and security.
Appearing at the IBDNetwork's Under the Radar event, executives from four companies gave brief presentations to a panel of three venture capitalists, whereupon the vendors were judged by both the panel and the audience. The companies included: Black Duck Software, which focuses on code analysis and intellectual property; Coverity, which addresses code quality and bugs; Fortify Software, which cites security as its forte, and Metallect, which locates interdependencies in software so the applications can be managed as a portfolio.
The event was held at Microsoft offices. In the end Coverity got the audience's nod as the vendor of choice while Fortify won over the venture capitalists. Each vendor had only five minutes to state its case, followed by a short question-and-answer period.
In making his pitch, Black Duck President and CEO Douglas Levin said software now is being assembled as components, with the Internet serving as a collaboration medium. But this assembly process carries with it risks in areas such as intellectual property obligations, Levin said.
Black Duck offers a subscription service for code analysis based on a knowledge base of 8 million files and 600 licenses, including the SourceForge knowledge base, Levin said. Users of the service are able to track software projects.
"Ultimately, this covers the entire lifecycle of software development." Levin said. Black Duck also will monitor development done via outsourcing, to make sure that code respects intellectual property obligations, he said.A‚Â
"The primary driver of the phenomenon of looking at source code and trying to understand binaries and source code that's in it is the Internet," Levin said. "Sarbanes-Oxley is certainly a driver, too."
Coverity stressed quality in software and how failures in the field can result in recalls or other calamites. "There's an increasing cost of achieving software quality," said Seth Hallem, CEO at Coverity.
The company analyzes code for a broad range of security and quality flaws, selling services based on lines of code.
Hallem boasted that unlike other participants in the event, Coverity has not needed any venture capital. "We don't have any funding. Why? Because we have a product that delivers clear and immediate value," Hallem said.
Fortify CEO John Jack noted his company's security focus. "We're addressing a problem at Fortify that we have found to be globally applicable and that problem is security," he said. Developers have primarily focused on application features, leaving others to concentrate on security, Jack said. Thusly, applications have not been developed with security in mind.
Fortify addresses software security by looking at the software lifecycle, performing source code analysis, and eyeing security flaws for large-grade commercial applications used in fields such as financial services and telecommunications, said Jack. The company also simulates attacks and traces the IP addresses of persons attacking an application.
"At Fortify, we have a vision and our vision is safe computing for everyone and the way to get to that vision is to look at your software," Jack said.
Metallect's software creates a visual map of each application, scanning source code, metadata, unstructured data, and text files. "The job of our software is to read all that and understand how all these applications are interrelating," said Tom Hite, co-founder and CTO at Metallect.
Locating interdependencies enables software to be managed as a portfolio, according to Metallect. "When I make a change in software, how far-reaching will the effects be?" Hite asked, in explaining Metallect. The company, for example, will gauge the effects of exposing a service in an SOA.
Although Black Duck was the top choice of neither the audience nor the venture capitalists, the company is receiving funding from two of the venture capitalists represented on the panel: Apollo Strategy Group and Intel Capital. Fortify receives funding from the third venture capital firm represented on the panel, Kleiner Perkins Caufield & Byers.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Controlling storage costs with Oracle database 11g
Discover the advantages of an open architecture multi-vendor network solution
Gaining Competitive Advantage Through Enterprise Planning
How to improve employee productivity in small and medium businesses
The state of Middleware
Email Archiving Implementation: Five Costly Mistakes to Avoid
Solve Exchange Mailbox Storage Issues Once and for All
Delivering the Power of Choice with Microsoft Dynamics CRM
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
AOC Launches 18.5” Widescreen Green 16:9 LCD Monitor in Australia and New Zealand 2008-12-03 15:30:00+11
FrontRange Solutions eases software license management with new License Manager 3.0 2008-12-03 14:56:00+11
Progress Software's Cure for Managing Services-based Applications 2008-12-03 14:42:00+11
S3 Graphics Unleashes Full OpenGL® 3.0 API Support with Beta Driver for Chrome 500 Series GPUs 2008-12-03 14:08:00+11
Informatica Powercenter added to Nec Infoframe Solution Suite 2008-12-03 11:36:00+11
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Your organisation may well have devised and implemented an Acceptable Use Policy (AUP) some time ago in order to guard against the risks of inappropriate use of computer systems by your workers, but are you confident that your AUP remains 'fit for purpose'? Read on to discover how you can enhance the effectiveness of your AUP.












