Software Security Analysis
While today most security analysis tools look for "technical" attacks based on code weaknesses, Hatha Systems' Knowledge Refinery™ allows the analyst to see the big picture and detect vulnerabilities based on architectural/design, functional defects, as well as, business rule vs. software implementation disconnects. True security analysis isn't just about the vulnerability, but the context in which that vulnerability exists in the system.
With Hatha Systems' Knowledge Refinery™ the analyst can explore the whole system. We provide the capabilities that allow a system engineer to analyze the security vulnerabilities of an application, or conversely, allow a security expert to understand and explore the technical make-up of the application. Once a series of security aspects and their intersections to the functional components of the systems they support are revealed, the Knowledge Refinery™ enables the analyst to run periodic application security checks or audits. These can be run, on-demand, as often as is necessary, in a minimum time frame and without additional investment. The security or regulatory compliance becomes a permanent reality, not just something to be confirmed at discrete time intervals.
Hatha Systems' Knowledge Refinery™ along with its powerful querying capabilities can be employed to answer some very sophisticated application level security questions. We bring an unprecedented magnitude of speed and accuracy to this process.
The following are just a few examples of the types of questions that can be answered:
- Is there the possibility of confidential data inadvertently flowing to unauthorized users?
- Is confidential data, which is the aggregation of non-confidential data, displayed on an unauthorized application interface?
- Are there secret doors allowing a user of the application to get access to an unauthorized area?
- Is there some malicious or non-compliant code introduced during normal maintenance activities?
- Have the security functions within the applications been implemented to meet compliance requirements?
- Have the application's security function(s) (e.g. IdAM) been integrated into the relevant enterprise infrastructural components to meet compliance requirements?
Hatha Systems' Knowledge Refinery™ kPath Query Language










