Microsoft releases free tools for security development

Share this article:
Microsoft on Wednesday announced the availability of two free tools designed to detect vulnerabilities in the software development process.

The tools, BinScope Binary Analyzer and MiniFuzz File Fuzzer, are the latest two technologies to emerge from the software giant's Security Development Lifecycle (SDL) initiative.

The BinScope tool lets developers run checks of binary code against SDL's list of "security flags," such as whether code would permit stack-based buffer overflows. This allows engineers to detect possible coding errors.

The MiniFuzz tool, meanwhile, runs automatic security tests on code so testers can monitor and study unexpected actions, such as a crash.

"Focused on the verification phase of the software development process, both tools offer developers and application testers responsible for the prerelease testing of software the ability to catch security risks in their code before it releases," Ladd said.

Earlier this year, Microsoft released the SDL Process Template for Visual Studio Team System, which provides a framework, including auditable requirements, for building security into applications. On Tuesday, the Redmond, Wash.-based company released a new paper, titled "Manual Integration of the SDL Process Template," which provides a step-by-step review of how to integrate the template into existing projects.

Also in the past, Microsoft has distributed other free secure development tools, including Optimization Model, Pro Network and Threat Modeling Tool.

Microsoft developed the SDL initiative in 2004 to address security vulnerabilities in its software. The program is credited with reducing in-house vulnerabilities in Vista and SQL Server.



Share this article:

Sign up to our newsletters

More in News

Instagram iOS and Android apps vulnerable to session hijacking

Two researchers wrote about the Instagram app for iOS and Android is vulnerable to session hijacking because both send unsecured information through HTTP.

Report: Hackers stole data from Israeli defense firms

A report by Brian Krebs detailed the intrusions, which occurred between Oct. 2011 and Aug. 2012.

Neverquest trojan targets regional banks in Japan

Symantec researchers found a new variant of the banking trojan.