Context-aware Checkmarx Fusion features cross-component prioritisation of application vulnerabilities

Checkmarx, the global leader in developer-centric application security testing (AST) solutions, has announced the availability of Checkmarx Fusion, a context-aware correlation engine that provides a holistic view of application security scan results across all stages of the software lifecycle to correlate and prioritise vulnerabilities, thereby guiding remediation of the most critical issues first.

“Development teams test tens of millions of lines of code monthly. With the complexity of modern applications – which include source code, open source code, infrastructure-as-code (IaC), containers, and more – developers and their AppSec leaders have a critical need for visibility into how application components interact,” said Checkmarx Chief Product Officer Razi Sharir.

“Working closely with our customers worldwide, we know that developers and AppSec teams need a holistic view of the context and prioritisation of application vulnerabilities that are lacking in AST and ASOC (application security orchestration and correlation) solutions. Checkmarx Fusion unifies, prioritises, and streamlines AppSec vulnerability remediation thereby increasing developer efficiency and organisational agility.”

Teams can now “shift left”* and bring comprehensive AppSec testing and remediation into the development cycle from creation of the first line of code to the last, the company said. Unlike ASOC solutions, Checkmarx Fusion offers multi-engine-scan correlation and context-based risk prioritisation of scan results across engines. Checkmarx Fusion, which is part of the Checkmarx One AST platform, empowers developers and AppSec teams with:

Visibility: Provides threat modelling by mapping threats in a visual, intuitive graph containing all software elements, consumed cloud resources, and relationships between them. Checkmarx Fusion extrapolates potential vulnerabilities within two or more scans that might otherwise escape detection.

Correlation: Adds context to the silo scanners by combining and correlating results from static code scans and runtime scans, effectively eliminating false positives

Prioritisation: Focuses developers and AppSec teams on solving the most critical issues by prioritising vulnerabilities based on their real impact and risk.

Cloud-nativeness: Leverages cloud-native architecture including microservices, cloud resources, containers, and APIs while correlating insights from pre-deployment to runtime

Melinda-Carol Ballou, Research Director for IDC's Application Life-Cycle Management (ALM) programme**, “The breadth of capabilities in Checkmarx's portfolio, which spans SAST, SCA, IAST, and IaC security***, delivered in a unified platform is an advantage in the highly competitive DevSecOps market space. The platform's developer focus, along with DevOps toolchain integrations and contextualised training, can increase developer performance and lighten the load of security testing, permitting the rapid delivery of more secure applications.”

*Editor's note: 'Shifting left' refers to locating problems earlier in the process of software delivery.

**IDC, IDC MarketScape: Worldwide Application Security Testing, Code Analytics, and Software Composition Analysis 2022 Vendor Assessment, by Melinda-Carol Ballou, March 2022.

**SAST: static application security testing; SCA: software composition analysis; IAST: interactive application security testing.

Comments

Popular posts from this blog

Fortinet enhances FortiRecon to align with CTEM framework

SentinelOne recognised as a 2025 Gartner Peer Insights Customers’ Choice for XDR

AWS: AI adoption grows 20% in Singapore