Currux Vision LLC Announces Industry Leading Accuracy of Artificial Intelligence Smart City Traffic Platform Testing with the City of San Jos – PR Web

HOUSTON (PRWEB) December 17, 2020

Currux Vision LLC (Currux Vision), the innovative, infra-tech AI and machine learning solutions company today released test results with the Department of Transportation of the City of San Jos, California. San Jos, recently named the Most Innovative City in the U.S., utilized the fully integrated, AI-based SmartCity ITS for city intersections and roadways. This innovative, cost-effective platform accurately monitors traffic, and provides information that can potentially prevent or reduce congestion and accidents, creating safer roads for drivers, cyclists, and pedestrians around the clock.

Comprehensive AI Traffic and Safety Solutions for Municipalities, DOTs, Toll Road Operators or Private Communities & Commercial Properties

The San Jos Department of Transportation and Currux Vision are focused on creating a safer and smarter city. Currux Visions SmartCity ITS continues to deliver one of the most comprehensive autonomous traffic management platforms including basic and advanced traffic management, big data collection, and analytics, and real-time alerts. SmartCity ITS includes a wide range of Vision Zero initiatives including vehicular (roadway and intersection), pedestrian, and bicycle associated near miss detection, and autonomous real-time prediction of hazardous traffic conditions, such as wrong way driver, stopped vehicles, speeding, running red lights and stop signs, parking infringements, etc. The combination of these capabilities provides cities with a single, accurate solution to improve residents quality of life and optimally allocate increasingly scarce resources.

The extensive tests with the San Jos Department of Transportation at key intersections confirmed that Currux Vision can operate with an up to 99% accuracy averaged under various conditions including day and night, rain, camera vibrations and even partial camera view obstruction. Moreover, Currux Vision can achieve high resolution results with older legacy digital and analog camera systems that offer lower resolution. Testing included but was not limited to vehicle detection and classification, turning movement counts, pedestrian counts, bicycle discrimination, stopped vehicles, and speeding.

Focused on Wide-Scale Adoption of Autonomous AI Systems at the Edge

Increasing urbanization, traffic, mode shift, and increasing focus on safety drive the urgent need for a next-generation traffic management solution like our SmartCity ITS. We believe that efficient mobility and being able to do more with less creates economic opportunities, enables trade, improves quality of life, and facilitates access to markets and services effectively leveraging resources. We designed our SmartCity ITS to significantly accelerate wide-scale adoption of autonomous AI capabilities by cities, DOTs and private infrastructure developers both in the U.S. and internationally. We are happy to have worked with a great partner like San Joss Department of Transportation to prove these transportation solutions. Alex Colosivschi, Founder and CEO of Currux Vision

Testing this leading-edge technology is a step in implementing the City of San Jos Smart City Vision - using game-changing technologies and data-driven decision-making which will drive continuous improvement in how we serve our community, and to promote concrete benefits in safety, sustainability, economic opportunity, and quality of life for our residents. We look forward to seeing reduced traffic congestion and accidents with connected infrastructure, real time big data analytics and alerts, and machine learning that can power next-generation traffic systems, reduce emissions, identify high-accident intersections, and allow us to better target mitigation efforts. Ho Nguyen, ITS Manager, City of San Jos

About Currux Vision LLCCurrux Vision (https://currux.vision) uses the latest in AI, machine learning, and computer vision technologies to develop and deploy edge-based autonomous AI systems for smart infrastructure. Currux Vision SmartCity ITS is used by DOTs and municipalities throughout the U.S. and has processed billions of traffic data points. Designed from the ground up, our fully integrated platform works with any camera, high and low resolution, and securely and rapidly operates within an agencys network. Additionally, the ease of installation and operation, powerful and flexible back-end capabilities, and attractive price point are key differentiators.

About the City of San JosWith more than one million residents, San Jos is one of the most diverse large cities in the United States and is Northern Californias largest city and the 10th largest city in the nation. San Joss transformation into a global innovation center has resulted in one of the largest concentrations of technology companies and expertise in the world. In 2011, the City adopted Envision San Jos 2040, a long-term growth plan that sets forth a vision and a comprehensive road map to guide the Citys anticipated growth through the year 2040. It was named Most Innovative City in the U.S by the Center for Digital Government in November, 2020.

Share article on social media or email:

View post:
Currux Vision LLC Announces Industry Leading Accuracy of Artificial Intelligence Smart City Traffic Platform Testing with the City of San Jos - PR Web

How artificial intelligence helped me overcome my dyslexia – The Guardian

Im 10 years old. Minutes into a maths lesson and my palms have already begun to sweat. Ive positioned myself in the back row, but the teacher walks up and down the aisles of the classroom, peering over our shoulders. I dont understand the rules. The teachers voice becomes a blur, and I stare at the numbers on the board, willing them to make sense. I wasnt a shy child, if anything I was bold and kind of brash, but I couldnt ask for help. I didnt have the language to explain what the numbers were doing to my brain.

Soon Id have a name for what I was experiencing dyslexia and Id begin to find ways to accommodate my learning style. As with everything, there are scales here. Dyslexia presents and impacts people in different ways, and I was lucky to be at a great school. But I had to learn to overcome my fear of numbers and words. I had to do battle with my confidence. Its only now I realise that this was the cause of me honing my greatest skill: learning to learn. Discovering more about different learning styles was a gamechanger and where my love of artificial intelligence technology was born.

Flash forward and now Im a tech entrepreneur and co-founder of CognitionX, a market intelligence platform for AI. Two years ago I was appointed by government ministers Matt Hancock and Greg Clark, to assemble a team of experts in AI to form a council responsible for supporting the government and its office for artificial intelligence. Ive been fortunate enough to have a front-row seat as the world is transformed by new technology but on a personal level Im drawn to AI because I want more support too. My dyslexia means I need more help, like spotting simple mistakes in my writing.

I rely on apps such as SwiftKey and Grammarly as one might an old friend. SwiftKey in particular is a huge help in my day-to-day life. Its an app for your smartphone keyboard that uses AI to make much better recommendations than the inbuilt spelling and grammar check. Even better is its new feature that turns my voice to text so I dont have to type or leave a voice note when Im struggling to find exactly the right way to say something. Grammarly is my go-to for my laptop. It combines rules, patterns, and AI deep learning techniques to help you improve your writing.

The drawback is that if something goes wrong with either of these apps, I feel as Im back in the classroom again, freefalling, my brain foggy, letters and numbers jumbled up. I worry Im over reliant on these technologies, but Im also thankful for their existence. Because they use machine learning, which operates by learning how I use the apps each time, we grow together. Its a conundrum but one Im conscious of and take into account every day.

And this is why its important to note that not only am I looking for AI support, Im looking for human support. The need for a conversation at the back of the class hasnt been replaced by technology its been augmented by it. Technology and people need to work in tandem.

I think it was my dyslexia and my need to see things from a different angle that enabled me to be open to the rewards of AI. But this doesnt mean that there arent risks. I grapple with the potential pitfalls of AI, particularly its bias against people underrepresented in tech across society. We are hurtling towards AI, machine learning and robotics at breakneck speed and people are being left behind. This means a risk of job loss in an already struggling climate.

One and a half million people in England are at high risk of losing their jobs to automation in the coming years, and a 2019 Office for National Statistics report revealed that 70% of them are women. Covid will no doubt increase these risks the shift to online working has only made it easier for companies to increase automation. This is why I want to urge women to get ahead of the game. Now more than ever is a good time to become the person in your company who has learned to master the newest software. Even for those who are proudly the least techie, it is time to change tune. Im not suggesting that everyone should retrain to become data scientists or AI experts. Its more about having an understanding of how to work with products that have AI built in.

I only ever advocate for AI systems in the workplace if they have a Human in the Loop approach. HITL is a way to build AI systems that makes sure there is always a person with a key role somewhere in the decision-making process. This guarantees that whatever the outcome happens to be, its arrived at through a combination of steps taken by a machine and the person, together. Its this sort of system I want to encourage women to become the best at navigating.

Throughout history a set of qualities traditionally associated with women compassion, care, empathy and nurturing have been dismissed or sidelined by the market. Today, care work is either among the lowest paid of jobs, or its done for free (mainly by women) in the home. But these qualities, which have always been vital, are about to become ever more necessary and much harder to undermine.

Many aspects of jobs are going to be assigned to machines, but they can never do everything that humans can. A machine may be able to predict and detect diseases invisible to the human eye, but the one thing it cant do is connect on a human level and offer genuine care.

Human empathy is something machines cant offer and so, together with an AI system, a doctor could present an accurate diagnosis in a caring way. This can only happen, however, if the doctor in question decides to embrace and fully understand how to get the best out of the AI system, which will take training and an appetite to learn.

Women have also developed another skill that will become vital in the coming years: staying on their toes. For centuries women have faced all kinds of discrimination and prejudice. Women have had to know how to be vigilant and resilient, to anticipate change and to read subtle cues and analyse the world for risks. In the world of AI, this means staying one step ahead of the machine.

The way I see it, this new wave of technology could be a tsunami that knocks you down, or it could be the wave that we ride together to a brighter future. The moment I began to truly understand this, I knew I had to share what Id learned about its possible risks as well as its rewards and why it is that women were more likely to suffer the negative effects.

Its really crucial for women to challenge the tendency to sometimes see tech as boring, scary or for someone else. Im not a scientist, engineer, developer or techie. It takes me a long time to understand technological ideas because theyre mostly founded in complex mathematics. It was a really liberating moment when I realised that I didnt need to understand the precise inner workings of AI machines in order to understand the ramifications of this technology.

All you need is to get a good grasp on how to adapt and thrive in this new world and what you can do to support others to do the same.

There are simple ways of achieving this and one of them is learning how to talk to technologies which use AI. You dont need to rush out to the shops there is AI you can talk to in products you may already have. If youre an Apple user, talk to Siri, or Cortana if you use Microsoft and Google has an assistant too. Set your alarm to be voice-activated or use a voice assistant to add appointments to your calendar, or to search the internet for you. My friends tell me that theyve given up on their home system, or that they cant bear that their car is trying to talk to them. My response is always to tell them: this technology isnt going anywhere. So instead of avoiding it, find ways to make the technology work for you before you end up working for it.

How to Talk to Robots by Tabitha Goldstaub is published by 4th Estate at 12.99. Buy it for 11.30 from guardianbookshop.com

See more here:
How artificial intelligence helped me overcome my dyslexia - The Guardian

Are AI and job automation good for society? Globally, views are mixed – Pew Research Center

As artificial intelligence (AI) plays a growing role in the everyday lives of people around the world, views on AIs impact on society are mixed across 20 global publics, according to a recent Pew Research Center survey.

This analysis is based on a survey conducted across 20 publics from October 2019 to March 2020 across Europe, Russia, the Americas and the Asia-Pacific region. The surveys were conducted by face-to-face interviews in Russia, Poland, the Czech Republic, India and Brazil. In all other places, the surveys were conducted by telephone. All surveys were conducted with representative samples of adults ages 18 and older in each survey public.

Here are the questions used for the report, along with responses, and its methodology.

A median of about half (53%) say the development of artificial intelligence, or the use of computer systems designed to imitate human behaviors, has been a good thing for society, while 33% say it has been a bad thing.

Opinions are also divided on another major technological development: using robots to automate many jobs humans have done in the past. A median of 48% say job automation has been a good thing, while 42% say its had a negative impact on society.

The survey conducted in late 2019 and early 2020 in 20 places across Europe, the Asia-Pacific region, and in the United States, Canada, Brazil and Russia comes as automation has remade workplaces around the world and AI increasingly powers things from social media algorithms to technology in cars and everyday appliances.

Views of AI are generally positive among the Asian publics surveyed: About two-thirds or more in Singapore (72%), South Korea (69%), India (67%), Taiwan (66%) and Japan (65%) say AI has been a good thing for society. Many places in Asia have emerged as world leaders in AI.

Most other places surveyed fall short of a majority saying AI has been good for society. In France, for example, views are particularly negative: Just 37% say AI has been good for society, compared with 47% who say it has been bad for society. In the U.S. and UK, about as many say it has been a good thing for society as a bad thing. By contrast, Sweden and Spain are among a handful of places outside of the Asia-Pacific region where a majority (60%) views AI in a positive light.

As with AI, Asian publics surveyed stand out for their relatively positive views of the impact of job automation. Many Asian publics have made major strides in the development of robotics and AI. The South Korean and Singaporean manufacturing industries, for instance, have the highest and second highest robot density of anywhere in the world. Singapore is also pursuing its goal of becoming the worlds first smart nation, and the government has identified AI as one of many key development areas necessary to reach that goal. Japan has also long been a world leader in robotics manufacturing and development, and robots and AI are increasingly integrated into everyday life there to help with tasks ranging from household chores to elder care.

Men are significantly more likely than women to say artificial intelligence has been a good thing for society in 15 of the 20 places surveyed. In Japan, for example, nearly three-quarters of men (73%) have positive views of AI, compared with 56% of women. In the U.S., 53% of men say AI has been a positive thing, compared with 40% of women.

People with more education are also more likely to have a positive view of AI. This gap is largest in the Netherlands, where a majority of those with a college education or higher (61%) see AI favorably, compared with 43% of those with less education. In the 11 publics where age is a significant factor in views of AI, younger people usually have a more positive view of the technology than older people.

There are similar patterns by gender and education in views of job automation. The educational differences are particularly large in some places: In Italy, for instance, about two-thirds of people with at least a college education (65%) say job automation has been a good thing for society, compared with just 38% of people with less education. Among adults with more education, those who took three or more science courses tend to see job automation more positively than people who took fewer science classes.

Note: Here are the questions used for the report, along with responses, and its methodology.

Read more from the original source:
Are AI and job automation good for society? Globally, views are mixed - Pew Research Center

Global Artificial Intelligence in Supply Chain Management Market was Valued at US$ 1549.5 Mn in 2019 Growing at a CAGR of 25.12% over the Forecast…

Request for Sample Copy of This [emailprotected] https://www.absolutemarketsinsights.com/request_sample.php?id=747

Enquiry Before Buying @ https://www.absolutemarketsinsights.com/enquiry_before_buying.php?id=747

Get Full Information of this premium [emailprotected] https://www.absolutemarketsinsights.com/reports/Artificial-Intelligence-In-Supply-Chain-Management-2020---2028-747

About Us:

Absolute Markets Insights strives to be your main man in your business resolve by giving you insight into your products, market, marketing, competitors, and customers. Visit

Contact Us:

Email id:[emailprotected] Contact Name:Shreyas TannaPhone:+91-740-024-2424

Photo: https://mma.prnewswire.com/media/1384957/Artificial_Intelligence_in_Supply_Chain_Management_Market.jpg Logo: https://mma.prnewswire.com/media/831667/Absolute_Market_Insights_Logo.jpg

SOURCE Absolute Markets Insights

More here:
Global Artificial Intelligence in Supply Chain Management Market was Valued at US$ 1549.5 Mn in 2019 Growing at a CAGR of 25.12% over the Forecast...

LinearB offers A-line to kill off bad code – ComputerWeekly.com

Question: whats better than project management?

Answer: Invisible real-time data-driven project management, thats what.

Holy Land and US-based LinearB plays in this arena and the company insists that its not focused on intelligence software delivery, as such, its core gambit is Software Delivery Intelligence.

The companys cheeky usage of CAPS to brand a discipline that we already know is meant to tell us that its tools help ship software in a different way.

Correlating Git and project management data, LinearB delivers dashboards, reports and real-time alerts the details how teams actually work this is meant to predict and eliminate project delays caused by all the bad (code) stuff.

What constitutes bad code stuff then?

The company says that traditional project management tools are good for planning, but they dont add value once dev teams start building.

Why is LinearB so keen to diss traditional tools?

Because, says LinearB, those older tools are unable to understand progress without manual status updates and fail when it comes to developer-specific work happening in branches, pull requests and releases.

Something is broken with how software projects are delivered. While Git and CI/CD tools have adopted a dev-first approach, project management and engineering efficiency tools have a top-down mindset and actually make life harder for developers, said Ori Keren, co-founder and CEO of LinearB.

Dev teams need tools that live in their workflow, reduce manual work and help them focus on building and improving. Think of Software Delivery Intelligence as Git correlation and reconstruction technology that makes project management updates redundant, with team metrics and operational insights built-in, he added.

Keren and team insist that traditional efficiency & value stream tools miss the target of opening the engineering black box because the metrics are not actionable.

They also fail to gain adoption within the team because of their Big Brother cultural impact effect and the temptation to use executive dashboards to micromanage dev team activities.

LinearB automatically constructs and visualises detailed progress timelines for open project issues with zero manual inputs and synchronises updates to project systems eliminating developer interruptions.

The platform automates the collection and display of team and project performance data that typically takes data engineers hours to compile manually.

Developers get insight about their work where they live in Slack and Git, dev team leads get clear visibility from the first-ever project board with a full Git activity timeline for every issue and engineering VPs get actionable team-based metrics that help daily improvement.

LinearB flags which teams and projects need help so dev leaders know where their time and attention can do the most good each day. Teams are alerted in real-time to project risks, delays and dependencies so they can course-correct and deliver more features faster, notes Keren.

As a closing assertion, LinearB claims that metrics are now the language of business leaders.

As such, LinearB visualises the most important team-based metrics like Cycle Time to help translate engineering to non-technical executives.

The company also provides data-driven dashboards for stand-up, retro, sprint planning and release planning meetings ensuring conversations are fact-based and time is used efficiently.

This is real-time visibility into projects without the need for manual updates, interruptions or status meetings, empowering hybrid remote teams to work asynchronously and that reality (if nothing else in 2020) is pretty real.

Go here to read the rest:

LinearB offers A-line to kill off bad code - ComputerWeekly.com

The SolarWinds and US government breach is not a marketing opportunity – ZDNet

The size and scope of SolarWinds as an IT software provider and the nature of the breach announced on December 13 rocked the IT and security world rightfully so. While security leaders guide their companies to respond, there's some generalized advice for the vendor world about this.

Attackers Continue To Exploit Product Security Weaknesses

Throughout 2020, product security failures have happened month after month, but most focused on consumer-facing products and services. Enterprise B2B vendors didn't get quite as much attention, but the scale balanced out with the SolarWinds breach.

Companies competing with SolarWinds on providing important infrastructure, monitoring, and security products and security vendors should focus on the following:

Poor product security efforts risk market share for B2B firms. Forrester has a body of research around product security, which provides extensive guidance on how to establish or improve your product security initiatives. Expect this to become a major focus of procurement and legal teams as a result of this breach.

Vendors should NOT use the SolarWinds breach as a marketing opportunity. Attempting to exploit the misfortune of others never makes a company look good, and in the cybersecurity industry, everyone knows that today it might be them, but tomorrow it could be you. Ambulance chasing, dunking on, or victim shaming is not just in poor taste. It's deplorable and won't win clients over. FireEye exhibited tremendous transparency as a result of its breach and was able to also provide one of the first detailed technical write-ups on the SolarWinds incident.

Even a security-mature software supplier could have missed this. To identify security flaws in their supply chain, top software organizations regularly run software composition analysis to identify vulnerabilities in open source components, and they use code-signing certificates to assure the integrity of supplied code. Neither approach would have discovered this attack the malicious code was not in an open source library, and the compromised DLL (dynamic-link library) was signed by a valid (albeit compromised) certificate. Don't equate susceptibility with a lack of security maturity.

SolarWinds' degree of transparency with its customer list might need to change. SolarWinds was large and prominent enough that it was an attractive target for attackers without mentioning customer names. But the customer page on its website went as far as listing all five branches of the US military, all 10 large US telecoms, and the top five accounting firms as clients. That doesn't mean any of those organizations are caught in the breach, but it does mean attackers have some idea of the value of SolarWinds as a target if they are successful. Third-party risk management, legal, and procurement will likely force CISOs to reevaluate if they want to be listed in the future.

To understand the business and technology trends critical to 2021, download Forrester's complimentary 2021Predictions Guidehere.

This post was written by Principal Analyst Jeff Pollard, and it originally appearedhere.

Read more from the original source:

The SolarWinds and US government breach is not a marketing opportunity - ZDNet

Itoco and World Health Access launch biometric IDs for vaccination verification – Biometric Update

Itoco Inc., a Bio Tech development, production and distribution company, announced that its patent-pending, biometric Immutable Virus Test Result Verification System is now available as an open-source repository on GitHub. The system was recently deployed via blockchain Smart Contract.

Through the open-source code, users can view the code and verify the exact functionality. Potential partners or customers will have transparency of how their data is being used, for example, what is being retrieved from the blockchain. Mobile application users can verify that the only data used is a hashed public key combination of the blockchain wallet and user biometric, but not the patients raw biometric or any personally identifiable information (PII).

The publicly available Smart Contract, written in the Solidity smart contract programming language for Ethereum, allows Itocos partners and customers to verify exactly how the blockchain is being leveraged as part of the overall system.

The Smart Contract is made up of several functions; users may be added to the blockchain as a combination of their hashed biometric public key and blockchain wallet address. This means they can have immutable test results associated with them. However, a user must first be added before they can have immutable test results recorded for them. The combination hash is first submitted by the user using the mobile application and then processed by the administrative application.

Another function is adding verified test machines to the blockchain using their blockchain wallet address. A test machine must first be added by the administrative application to the blockchain before it can write test results to the blockchain.

Immutable test results are also able to be added to the blockchain. An immutable test result consists of the test results and associated details, along with updated user details with testing status and the latest test results, the company says.

Other components of the Immutable Virus Test Result Verification System are the administrative application and the integrated virus test machines, which can communicate with this Smart Contract.

World Health Access launches digital vaccination record

The release of a patented technology service to provide COVID-19 vaccine verification booklets and cards was announced this week by World Health Access, a subsidiary of International Health and Wellness LLC.

The VAX Passbook and VAX Passcard will utilize Reel Code Media (RCM) patented technologies, including biometrics, and have been designed to ultimately include all vaccination records of the user. This record will show the chronological history of testing whilst confirming the tests and vaccinations the owner has obtained.

VAX Passbook is a vaccination record booklet that consists of a document confirming all received vaccinations. VAX Passcard provides a similar document but in the form of a credit card-like tool. The Passbook utilizes patented technology to maintain security and privacy of the user and the RCM Frame is programmed to only be accessed by assigned administrators including educators, employers, government agencies, travel authorities and medical/healthcare/insurance providers. The Passcard enables user authentication with embedded fingerprint biometric technology.

The development of these technologies follows some reports that a proof of COVID-19 vaccination may be required for future international travel, company Daon is among those that have already developed an app with this in mind.

access management | biometric cards | biometrics | digital identity | fingerprints | identity verification | Itoco | World Health Access

Originally posted here:

Itoco and World Health Access launch biometric IDs for vaccination verification - Biometric Update

World Quality Report: 3 ways to build more resilient code – TechBeacon

As theymove into DevOps, teams often get advice on how to integrate security and quality-assurance (QA) testing into the development process. The advice is sound; surveys have measured which development processes and security habits are shared byelite, mature DevOps teams.

However, what is often missed in application security is how companies can push their programs after the initial forays into more mature territory to build a resilient software and development pipeline.

Successfully growing security and QA programs continues to be difficult. While a well-executed DevOps program can reduce the complexity of software-security and QA processes, orchestrating agile approaches has grown more complex overall. That's one of the top-level takeaways fromthe World Quality Report 2020-21.

Here are recommendations for transitioning from the simple security and QA tests produced by siloed experts to a more resilient integrated approach that will give your development teams a smoother path to maturity.

Companies should focus on people first, and then process and tools. Getting developers and security teams on board with integrating testing into the development and deployment pipeline is critical.

A significant factor in growing security maturity in any software development environment is sharing responsibility between the developers and the security team. Moving more security and quality tests into the development processthat is, "shifting left"and automating those tests are the two most significant ways that companies are speeding up their agile software pipelines, with 52% and 51% of companies almost always taking these approaches respectively, according to the 2020-21 World Quality Report.

Working together is important, because most organizations tend to have only one or two application security professionalsworkers who often have other responsibilities. Yettwo-thirds of respondents focused on the technology stack as essential or very importantthe top aspect, according to the World Quality Reportwhile culture and talent were the least important factors.

A security champion programcan help these companies focus on the people and build bridges between security and development. When the people work together and are knowledgeable, other considerations such as the technology stack and executive support will often take care of themselves.

Organizations that are starting out often just have simple test suitesread lintersthat conduct static checks during development or at code check-in. With most mature application security programs, the teams work with developers to push more testing into the process, yet with the realization that too much testing can slow down development.

The more complex tools used by mature organizations, however, can overwhelm less mature developers and security teams. Rather than lure developers to code more securely, more complex tools often deter security.

For that reason, once a company has integrated simple quality and security tests, the development teams should try to tackle specific classes of vulnerabilities, such as SQL injection and cross-site scripting. The most common vulnerability classes, such as the OWASP Top 10, can be detected by manytools out there, many of which are open source.

In the end, the way to move forward is to not bite off more than you can chew. Your team should not try to solve every vulnerability, but pick one or two classes and start there.

Companies believe that they have enough automation, with about two-thirds of respondents to the World Quality Report answering that they had the required automation tools and enough time to build automation tests. However, an average of only 15% of tests were automated, and only 3% of companies automated more than 20% of tests, according to respondents.

Well-implemented automation leads to more secure and resilient code, since testing takes less time, can cover more software, and can lead to better detection of defects. Despite recognizing this, companies continue to underfund testing, according to the survey.

Given the importance in automated testing to prevent avoidable defects from creeping into code, automationmore than any other factorwill help your development and security teams become more mature and produce more resilient code.

Just like your first car should not be a Lamborghini, trying to move too quickly to high-performance and complex testing environments will result in problems. With these best practices you can scale up your development with a more resilient, longer-term approach.

See the rest here:

World Quality Report: 3 ways to build more resilient code - TechBeacon

Defense in Depth: Why You Need DAST, SAST, SCA, and Pen Testing – Security Boulevard

When it comes to?application?security (AppSec),?most experts recommend using?Dynamic Application Security Testing?(DAST)?and?Static Application Security Testing?(SAST)?as ???complementary??? approaches for robust AppSec. However, these experts rarely specify?how?to run them in a complementary fashion.?

At Veracode, we use SAST, DAST,?SCA,?and?pen?testing as the?four?pillars of our?defense?in-depth?strategy to deliver a ???secure-by-design??? AppSec methodology across the entire?software?development?life?cycle.??

Most organizations start their AppSec journey by running?manual?penetration?tests?(MPT).?Penetration testing is necessary to catch vulnerability classes,?such as authorization issues and business logic flaws,?that cannot be found through automated assessments alone. Expertly trained pen testers?can?review?an entire?environment,?rather than just the application,?and can?follow or break the workflows in a way that is difficult for?automation to replicate.?Additionally, pen testing is required?to comply with regulations such as?PCI DSS, HIPAA, GLBA, FISMA, and NERC CIP.?

However,?pen?testing is only one assessment type and can bottleneck development?velocity?because it is a manual process.??

Dynamic?application?security?testing?(DAST)?is?an AppSec assessment that?scans all applications and interconnected structures in a running environment without looking deeply into source code. The results of ???outside-in????dynamic?scanning?help prioritize?the remediation of?exploitable vulnerabilities?and immediately reduce AppSec risk as they are fixed. However, it can be challenging to pinpoint the?exact?line of code to?work on?using only DAST.?This assessment on its own is limited by the configuration of your scanner and what you choose to test. If you don???t properly configure your scans,?you may miss vulnerabilities and have a false sense of security.?

Additionally, since the?application?is?scanned?towards the end of the?SDLC,?there???s more pressure on development teams to remediate the difficult-to-find vulnerabilities quickly.?This is usually?where?friction?between development and security increases,?often resulting in unmitigated risk.??

Static?application?security?testing?(SAST)?is an AppSec assessment?that tests applications from the inside-out,?by scanning applications,?but not running them. It usually targets source code, byte code,?and?binary?code, and ???sits??? in an earlier stage of the SDLC so developers can look for security issues?before?the application is complete. SAST also provides real-time security feedback during coding, making it a more?proactive method?for fixing flaws quickly. This ???inside-out approach??? can help reduce?security?technical debt?for the lowest cost.?

On the flip side, fixing all the flaws found after a SAST scan may be an inefficient use of resources that may not reduce your risk in a meaningful way.?And since the scan doesnt execute in a running environment, it can be hard to determine which flaws are immediately exploitable, or to understand how the exploit might happen without appropriate training.?

Getting features to market faster than the competition almost always requires development teams to?use at least one open-source library in?their codebase. Third-party code is a necessity in modern software development and so is securing it.?According to?Veracode???s?State of Software Security:?Open-Source?Edition,?97.4?percent?of the 85,000 apps scanned had?an unfixed?security?flaw in an external library.?The good news is that?nearly 75?percent?of the known flaws can be fixed with a?version?update.?Veracode Software Composition Analysis?(SCA) and other similar solutions?automatically?scan your?libraries?and their dependencies?to find vulnerabilities and?help you fix them.???

If you?conduct only?SCA you???re not protecting your entire codebase. If you conduct just?SAST, you may introduce resource-related inefficiencies into the SDLC during remediation.?If you?conduct only?MPT or DAST, you???re finding flaws at a later, more expensive stage and putting increased pressure on development teams to find the flaw in the source code and remediate it quickly.??

To ensure that you get the most value out of your AppSec program, you should use DAST findings to configure SAST policies, and to inform SAST activities. A quick defense against something like an input/output validation problem found during a?Veracode Dynamic Analysis?scan is to implement a WAF rule that prevents unauthorized data from leaving the application. Once the vulnerability has been secured at that level, use?Veracode Static Analysis?to go deep into the source code to find and patch the flaw.?Once the first-party code has been secured, integrate Veracode SCA into your development workflows?to secure your third-party code.?This ensures that you are not just relying on one control to prevent an attack.??

On top of this, it is critical to continue running?MPT?assessments?to secure the flaws that automation?can???t?find. You want to look at the hierarchies of the architecture to be sure that you are doing everything you can to secure each level. This?complementary approach makes it easier to find exploitable flaws, remediate them quickly, and even learn secure coding to prevent them in future.?According to the 11th?edition of the?State of Software Security?report,?organizations that scan with both SAST and DAST are likely to remediate?50 percent of?their flaws 24.5 days quicker than if they only scanned with one technology.?It???s not hard to understand why: by seeing how an attack may be exploited at runtime, developers get an education in how to think like an attacker and may even be more motivated to fix?other?findings.?

In today???s expanding threat landscape, DAST, SAST,?SCA,?and MPT provide a means for?DevSecOps?teams to secure their code and strengthen their AppSec programs before it???s too late.?To learn more about?the strengths and weaknesses of the different types of application security technologies, check out?our?Guide?to?AppSec Solutions.?

Recent Articles By Author

*** This is a Security Bloggers Network syndicated blog from Application Security Research, News, and Education Blog authored by lpaine@veracode.com (lpaine). Read the original post at: https://www.veracode.com/blog/managing-appsec/defense-depth-why-you-need-dast-sast-sca-and-pen-testing

View original post here:

Defense in Depth: Why You Need DAST, SAST, SCA, and Pen Testing - Security Boulevard

Linux Foundation Public Health Expands Technology and Public Health Community, Accelerates the Fight Against COVID-19 – PRNewswire

SAN FRANCISCO, Dec. 16, 2020 /PRNewswire/ --Linux Foundation Public Health (LFPH), the organization that builds, secures and sustains open source software to help Public Health Authorities (PHAs) around the world combat COVID-19 and future epidemics, today announced it will host the COVID-19 Credentials Initiative, a privacy-preserving Verifiable Credentials (VCs) effort focused on interoperability. It is also announcing new Executive Director Brian Behlendorf, new public health commitments and membership investments and a new set of open source guidelines for exposure risk notifications.

Since launching in Julyof this year, LFPH has gained new commitments across industries and disciplines and is adding new initiatives to collaboratively address privacy, efficacy and integrity in the software that is helping to prevent and slow the spread of infectious disease.

COVID-19 Credentials Initiative becomes part of LFPH

The COVID-19 Credentials Initiativeis a global community of more than 300 technologists, academics and healthcare professionals from more than 100 organizations working on projects that use privacy-driven verifiable credentials to mitigate the spread of COVID-19. Its guiding principles include interoperability, privacy, data protection and inclusion. The community will bring together new open standards work with existing health data standards to ensure vaccine credentials are interoperable and digitally verifiable.

"LFPH is a natural home for CCI. There is strong alignment on the most urgent matters to address, such as interoperability, privacy and ethics as they related to vaccine credentials. Most importantly, LFPH strives to respect the community-driven and open nature of CCI, which is essential to true collaboration and wide adoption. We look forward to working with LFPH and stakeholders across communities, sectors and industries, especially PHAs, on vaccine credentials for COVID-19 and other public health credentials," said Lucy Yang, co-lead, COVID-19 Credentials Initiative.

Open source and digital identity visionary Brian Behlendorf becomes LFPH executive director

Brian Behlendorf will assume the role of Executive Director of LFPH, while carrying on his duties as Executive Director of the Linux Foundation's Hyperledger Project and overseeing a variety of initiatives in blockchain, healthcare and digital identity. Behlendorf was a founding member of the Apache Software Foundation, was the CTO of the World Economic Forum 2011-2012 and worked at the White House's Office of Science and Technology Policy in 2009 and the Department of Health and Human Services in 2010 on advancing the use of open standards through the use of open source software.

"Thanks to the passionate leadership of the late Dan Kohn, LFPH is mobilized to use open source software to accelerate work on combating COVID-19, with an early emphasis on exposure notifications. That work is well underway and already having a very real impact," said Jim Zemlin, executive director of the Linux Foundation. "LFPH is now looking toward the future, one where we can help bring diverse constituents together to build, secure and sustain technologies that fight COVID-19 today and other epidemics tomorrow. There is no one more suited to enable this kind of collaboration and to carry on Dan's legacy with LFPH than Brian Behlendorf."

"It is an honor to be able to advance the LFPH work that was initiated by the open source hero Dan Kohn," said Brian Behlendorf, general manager, LFPH and the Linux Foundation's Hyperledger. "There is both a requirement and tremendous opportunity to bring together the world's leading technologists, scientists, doctors and academics on public health to seek the right balance in privacy and efficacy in preventing and slowing the spread of infectious disease. This is work we know how to do and work we must do."

New collaboration and investments

The Health Service Executive Ireland, New Jersey Office of Innovation, North Carolina Department of Human and Health Services and Boston Public Health Commission are the latest PHAs to join LFPH They are the ultimate consumers of the technologies being built by LFPH and so their contributions will dramatically accelerate adoption and innovation. LFPH is also announcing new member MotionMob and that WeHealth, the company that implements Covid Watch, is upgrading its membership and is now a Founding General Member. Other founding members include Cisco, doc.ai, Geometer, IBM, NearForm, Tencent and VMware.

"HSE contributed the source code for COVID Green in the summer of 2020. Our goal was to try and help other public health authorities in the fight against COVID." said Gar Mac Criosta from the Health Service Executive of Ireland. "Membership has brought with it a number of benefits, first and foremost an active and open community all aligned in a fight against COVID-19. I think the engagement so far has opened people's eyes across government to the benefits of open source, in particular for situations where public trust and confidence is paramount,"

"My choices before LFPH were McKinsey or vendor pitches. LFPH has provided something without financial skin in the game that I can use as a Public Health Authority," said Mike Flowers, NJ Office of Innovation.

Open source guidelines for risk notifications

LFPH launched with two hosted exposure notifications projects, COVID Shield and COVID Green, to advance phone-based alerts that people can receive to inform them that they've been exposed to someone diagnosed with COVID-19. The Exposure Notification System (ENS) provided by Apple and Google has a configurable component, a risk score, which allows health authorities to specify which types or levels of exposures should trigger a notification.

In a series of meetings in November 2020, LFPH and Apple, the CDC, Google and MIT hosted the Risk Score Symposium Invitational to inform the decision-making process for health authorities who are using, or plan to use, ENS in their region. The resultingguidelines are available now.

To join LFPH or contribute, please visit: https://www.lfph.io/

About Linux Foundation Public Health

Linux Foundation Public Health (LFPH) uses open source software to help public health authorities (PHAs) around the world combat COVID-19 and future epidemics. LFPH projects include COVID Shield being deployed in Canada and Mongolia and COVID Green, which has been deployed in five countries and four US states. As more projects are contributed, LFPH will expand its scope into software support for all phases of PHA's testing, tracing, and isolation activities. LFPH is part of the nonprofit Linux Foundation. For more information, please visit lfph.io.

The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see its trademark usage page. Linux is a registered trademark of Linus Torvalds.

Media ContactJennifer CloerStory Changes Culture503-867-2304[emailprotected]

SOURCE LF Public Health

View post:

Linux Foundation Public Health Expands Technology and Public Health Community, Accelerates the Fight Against COVID-19 - PRNewswire