Microsoft announces new tool to find, fix bugs at scale


New Delhi, Sep 18 (IANS): Microsoft has introduced a new tool on its open source repository GitHub that will further help developers and security researchers find and remove critical bugs.

Called Project OneFuzz, it is an extensible fuzz testing framework for Azure Cloud.

Available through GitHub as an open-source tool, the testing framework used by Microsoft Edge, Windows, and teams across the company is now available to developers around the world.

"Fuzz testing is a highly effective method for increasing the security and reliability of native code -- it is the gold standard for finding and removing costly, exploitable security flaws," said Justin Campbell Principal Security Software Engineering Lead, Microsoft Security.

"Enabling developers to perform fuzz testing shifts the discovery of vulnerabilities to earlier in the development lifecycle and simultaneously frees security engineering teams to pursue proactive work".

Earlier this year, Microsoft announced that it would replace the existing software testing experience known as Microsoft Security and Risk Detection with an automated, open-source tool as the industry moved toward this model.

The global release of Project OneFuzz, said Microsoft, is intended to help harden the platforms and tools that "power our daily work and personal lives to make an attacker's job more difficult".

Project OneFuzz is available now on GitHub under an MIT license.

  

Top Stories


Leave a Comment

Title: Microsoft announces new tool to find, fix bugs at scale



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.