posted on Tuesday, January 25, 2005 9:28 PM by davidboschmans

SecurityChecker complaints

Tim Weaver is definitely not happy with DevPartner SecurityChecker 1.0, Compuware's new product designed to detect security issues in ASP.NET applications. Me too, I had some issues, though not the ones Tim is complaining about. Anyone listening from Compuware technical support?

Here are some tips if you're struggling with the performance of SecurityChecker.

SecurityChecker takes a long time to complete analysis. How can I reduce the Analysis time?

Several factors contribute to the analysis time:

Application Size – How many projects are there in the Solution
The size of your application is a determining factor in how long the analysis will take. If you have many projects within your solution, consider analyzing each project separately. You can do this by manually navigating the application using Manual discovery, or by modifying a discovery map to only analyze certain pages within the application.

Number of ASP.NET pages being analyzed
If your application contains many pages, consider using Manual discovery and limiting the session to specific pages.

Number of functions on each page being analyzed
If there are data grids on the pages of your application, integrity analysis (specifically) will take a long time to run. To effectively analyze the application it is important to test for vulnerabilities in the grid. Be advised that this will take time.

Automatic or Manual discovery
Because Automatic discovery is designed to test all aspects of your application, it will take a long time on large applications. Consider using Manual discovery to limit the parts of the application analyzed, or consider running each type of analysis (Compile-time, Run-time, and Integrity) individually.

Automatic Discovery Session Settings
If running with the default settings is producing long analysis times, you can reconfigure the Automatic discovery settings. These settings may have an affect on the analysis time.
Use the SecurityChecker Settings dialog to reconfigure the settings. Open the settings dialog from the SecurityChecker menu:SecurityChecker -> Settings -> Discovery Map.In the “Automatic Discovery Map” section there are “Link Visitation Limit”, “Crawl Depth” and “Maximum Links per Page” settings.

By default, the values are:

Link Visitation Limit – 2 visits
Crawl Depth – 10 levels
Maximum Links per Page - 25

By decreasing the values of these settings, analysis time will be shortened. Most often, it is the Crawl Depth setting that has the most affect.

Type of Analysis being run
There are 3 types of analysis that can be run in SecurityChecker; Compile Time analysis, Run Time analysis, and Integrity analysis.

Compile time analysis is the quickest to complete.
Run time analysis generally does not take long to complete.
However, because SecurityChecker Integrity analysis simulates extensive attacks on your application, this type of analysis can take a while to complete.

If all 3 analysis types are selected, the session will take longer to complete. If the application being analyzed is large, running only 1 session type at a time will reduce the time to complete the analysis.

The total number of Vulnerabilities / Rules being analyzed
By default, all of the Rules are selected to be checked during a SecurityChecker session. If you are reusing a discovery map you can select only certain Vulnerability categories and Severities to be used in the next session. Selecting one severity or category per session will reduce the analysis time.

Comments

# re: SecurityChecker complaints

Tuesday, May 22, 2007 8:19 AM by Marios
Nice...

# re: SecurityChecker complaints

Tuesday, May 22, 2007 4:10 PM by Sebastianos
Cool.

# re: SecurityChecker complaints

Tuesday, May 22, 2007 6:21 PM by Kristion
Nice!

# re: SecurityChecker complaints

Tuesday, May 22, 2007 10:22 PM by Pericles
Cool.

# re: SecurityChecker complaints

Wednesday, May 23, 2007 12:18 AM by Alexandros
Cool!

# re: SecurityChecker complaints

Wednesday, May 23, 2007 12:44 AM by Sotirios
Nice...

# re: SecurityChecker complaints

Wednesday, May 23, 2007 2:11 AM by Mamadshah
Nice!

# re: SecurityChecker complaints

Wednesday, May 23, 2007 5:24 PM by Petros
Interesting...

# re: SecurityChecker complaints

Thursday, June 07, 2007 4:23 PM by Aniketos
Nice...

# re: SecurityChecker complaints

Thursday, June 07, 2007 5:28 PM by Emmanouil
Nice!

# re: SecurityChecker complaints

Thursday, June 07, 2007 8:53 PM by Panicos
Interesting...

# re: SecurityChecker complaints

Friday, June 08, 2007 12:03 PM by Photios
Nice!

# re: SecurityChecker complaints

Friday, June 08, 2007 3:54 PM by Drymiotes
Nice

# re: SecurityChecker complaints

Saturday, June 09, 2007 12:06 AM by Nikodemos
Cool!

# re: SecurityChecker complaints

Saturday, June 09, 2007 1:04 AM by Makarios
Nice!

# re: SecurityChecker complaints

Saturday, June 09, 2007 10:34 AM by Sotiris
interesting

# re: SecurityChecker complaints

Saturday, June 09, 2007 7:48 PM by Drymiotes
interesting

# re: SecurityChecker complaints

Sunday, June 10, 2007 6:14 PM by Milos
Nice

# re: SecurityChecker complaints

Monday, June 11, 2007 3:06 PM by Stylianos
Nice...

# re: SecurityChecker complaints

Monday, June 11, 2007 3:54 PM by Sophocles
Cool...

# re: SecurityChecker complaints

Tuesday, June 12, 2007 8:08 AM by Nico
Interesting...

# re: SecurityChecker complaints

Tuesday, June 12, 2007 12:47 PM by Chrysostomos
Sorry :(

# re: SecurityChecker complaints

Tuesday, June 12, 2007 3:45 PM by Theofanis
Cool...

# re: SecurityChecker complaints

Tuesday, June 12, 2007 6:10 PM by Ignatios
Nice...

# re: SecurityChecker complaints

Wednesday, June 13, 2007 12:54 AM by Pantelis
Nice...

# re: SecurityChecker complaints

Wednesday, June 13, 2007 10:08 AM by Photios
Cool.

# re: SecurityChecker complaints

Thursday, June 14, 2007 2:00 AM by Apostolos
Nice

# re: SecurityChecker complaints

Thursday, June 14, 2007 3:20 AM by Panagiotis
Interesting...

# re: SecurityChecker complaints

Thursday, June 14, 2007 5:29 AM by Panayotis
Interesting...

# re: SecurityChecker complaints

Thursday, June 14, 2007 5:38 PM by Nico
Cool!

# re: SecurityChecker complaints

Thursday, June 14, 2007 5:58 PM by Vassilis
Cool.

# re: SecurityChecker complaints

Friday, June 15, 2007 12:19 AM by Metrophanes
Interesting...

# re: SecurityChecker complaints

Friday, June 15, 2007 4:16 AM by Zaharias
interesting

# re: SecurityChecker complaints

Friday, June 15, 2007 12:37 PM by Crist
Cool...

# re: SecurityChecker complaints

Friday, June 15, 2007 2:33 PM by Epaminondas
Nice...

# re: SecurityChecker complaints

Friday, June 15, 2007 4:31 PM by Mamadshah
Nice...

# re: SecurityChecker complaints

Saturday, June 16, 2007 5:40 AM by Adamantios
Cool!

# re: SecurityChecker complaints

Saturday, June 16, 2007 6:14 AM by Themestoclis
interesting

# re: SecurityChecker complaints

Saturday, June 16, 2007 3:15 PM by Evenios
Nice

# re: SecurityChecker complaints

Sunday, June 17, 2007 7:43 AM by Alexis
Interesting...

# re: SecurityChecker complaints

Sunday, June 17, 2007 3:00 PM by Arion
Nice...

# re: SecurityChecker complaints

Sunday, June 17, 2007 9:52 PM by Ilias
Sorry :(

# re: SecurityChecker complaints

Monday, June 18, 2007 1:21 AM by Pericles
Nice

# re: SecurityChecker complaints

Tuesday, June 19, 2007 8:52 AM by Dimitrios
Interesting...

# re: SecurityChecker complaints

Tuesday, June 19, 2007 9:41 PM by Manos
Nice

# re: SecurityChecker complaints

Wednesday, June 20, 2007 9:31 AM by Simos
Interesting...

# re: SecurityChecker complaints

Wednesday, June 20, 2007 7:50 PM by Athan
Interesting...

# re: SecurityChecker complaints

Thursday, June 21, 2007 9:57 AM by Vangelis
Sorry :(

# re: SecurityChecker complaints

Thursday, June 21, 2007 7:13 PM by Constantinos
Interesting...

# re: SecurityChecker complaints

Thursday, June 21, 2007 10:40 PM by Gondikas
Nice

# re: SecurityChecker complaints

Friday, June 22, 2007 8:51 AM by Iakovos
Sorry :(

# re: SecurityChecker complaints

Friday, June 22, 2007 10:43 PM by Eleni
Nice...

# re: SecurityChecker complaints

Sunday, June 24, 2007 10:46 AM by Thrasyvoulos
Sorry :(

# re: SecurityChecker complaints

Sunday, June 24, 2007 10:45 PM by Costas
interesting

# re: SecurityChecker complaints

Monday, June 25, 2007 12:30 AM by Neophytos
Cool!

# re: SecurityChecker complaints

Monday, June 25, 2007 10:21 AM by Arsenios
Nice...

# re: SecurityChecker complaints

Monday, June 25, 2007 12:53 PM by Laurentios
Cool!

# re: SecurityChecker complaints

Monday, June 25, 2007 1:23 PM by Savvas
Nice!

# re: SecurityChecker complaints

Tuesday, June 26, 2007 1:37 AM by Simos
Cool.

# re: SecurityChecker complaints

Tuesday, June 26, 2007 10:57 AM by Vassilis
Interesting...

# re: SecurityChecker complaints

Tuesday, June 26, 2007 4:10 PM by Thanos
Nice!

# re: SecurityChecker complaints

Wednesday, June 27, 2007 2:35 AM by Doxiadis
Sorry :(

# re: SecurityChecker complaints

Friday, June 29, 2007 9:21 PM by Stamatis
Nice!

# re: SecurityChecker complaints

Saturday, June 30, 2007 4:31 AM by Argyros
Interesting...

# re: SecurityChecker complaints

Saturday, June 30, 2007 10:43 AM by Leontios
Cool...

# re: SecurityChecker complaints

Saturday, June 30, 2007 7:32 PM by Kalinikos
Cool.

# re: SecurityChecker complaints

Sunday, July 01, 2007 3:05 AM by Philippos
Cool...

# re: SecurityChecker complaints

Sunday, July 01, 2007 3:40 AM by Ambrosios
interesting

# re: SecurityChecker complaints

Sunday, July 01, 2007 10:08 AM by Koinos
Interesting...

# re: SecurityChecker complaints

Sunday, July 01, 2007 10:56 AM by Costas
Sorry :(

# re: SecurityChecker complaints

Sunday, July 01, 2007 4:41 PM by Costa
Nice!

# re: SecurityChecker complaints

Sunday, July 01, 2007 9:23 PM by Gregorios
Cool!

# re: SecurityChecker complaints

Sunday, July 01, 2007 10:55 PM by Giatas
Nice...

# re: SecurityChecker complaints

Tuesday, July 03, 2007 2:40 PM by Yanni
Sorry :(

# re: SecurityChecker complaints

Tuesday, July 03, 2007 8:49 PM by Stelios
Cool!

# re: SecurityChecker complaints

Wednesday, July 04, 2007 12:24 AM by Thanasios
Nice...

# re: SecurityChecker complaints

Wednesday, July 04, 2007 3:24 PM by Matthaios
Nice

# re: SecurityChecker complaints

Wednesday, July 04, 2007 6:53 PM by Sotiris
Sorry :(

# re: SecurityChecker complaints

Thursday, July 05, 2007 12:46 AM by Leo
Cool...

# re: SecurityChecker complaints

Thursday, July 05, 2007 4:58 AM by Adamantios
Cool!

# re: SecurityChecker complaints

Thursday, July 05, 2007 11:13 AM by Thanasios
Cool!

# re: SecurityChecker complaints

Monday, July 09, 2007 10:28 AM by Argyros
Nice!

# re: SecurityChecker complaints

Monday, July 09, 2007 3:16 PM by Nikodemos
Cool.

# re: SecurityChecker complaints

Monday, July 09, 2007 3:16 PM by Theofanis
Cool...

# re: SecurityChecker complaints

Tuesday, July 10, 2007 1:28 AM by Costas
Cool...

# re: SecurityChecker complaints

Tuesday, July 10, 2007 9:04 AM by Stefanos
Nice

# re: SecurityChecker complaints

Tuesday, July 10, 2007 11:04 AM by Kristion
Nice!

# re: SecurityChecker complaints

Tuesday, July 10, 2007 12:19 PM by Augustinos
Nice...

# re: SecurityChecker complaints

Tuesday, July 10, 2007 7:12 PM by Giatas
Cool!

# re: SecurityChecker complaints

Wednesday, July 11, 2007 12:38 AM by Aristotelis
interesting

# re: SecurityChecker complaints

Wednesday, July 11, 2007 1:13 AM by Evangelos
Nice!

# re: SecurityChecker complaints

Wednesday, July 11, 2007 3:11 AM by Arion
Nice...

# re: SecurityChecker complaints

Wednesday, July 11, 2007 8:58 PM by Paulos
interesting

# re: SecurityChecker complaints

Wednesday, July 11, 2007 10:58 PM by Othon
Cool!

# re: SecurityChecker complaints

Wednesday, July 11, 2007 11:31 PM by Vasileios
interesting

# re: SecurityChecker complaints

Thursday, July 12, 2007 4:59 AM by Harrys
Sorry :(

# re: SecurityChecker complaints

Thursday, July 12, 2007 10:46 AM by Sophocles