You are here: silicon.com > Software > Security Strategy

Security Strategy

Betfair fortifies its software code

Case study: How to free up developers' time and squash the bugs

Tags: bug, betfair, fortify

By Gemma Simpson

Published: 20 November 2007 11:21 GMT

Betfair has rolled out a source code analysis tool to free up its developers' time and keep bugs at bay.

Betfair introduced the Fortify Source Code Analysis (SCA) tool at the beginning of the year to identify, manage and fix any software security flaws.

The online betting exchange expects to see a return on investment on the SCA product within the space of three years.

Security A to Z

From antivirus to zero-day, click here for silicon.com's alphabetical guide to security.

Betfair uses the tool to run nightly scans on its code and the output of those scans goes to a central reporting server (CRS).

The CRS then flags up any serious issues uncovered by the tool and also tracks trends, such as the number of potential lower-level security issues.

Matt Young, engineering partner development director at Betfair, told silicon.com: "A spike in the number of low-level potential issues found by the SCA tool usually means either that a lot of code has been checked in at once or that someone has checked in code without getting it reviewed first. It can be a good early-warning sign."

Young said the SCA tool also covers some of the review and analysis work when scanning through reams of code - in particular automating the more labour-intensive parts of manual code review - leaving developers more time to look at broader design issues.

Once a bug is found within the code, the tool also provides Betfair with custom rules to identify the bug which has been found.

The custom rules can then be used to search the rest of the code base for other existing and similar instances of the problem and to run a nightly source code regression checks to prevent any new instances of the same bug entering the code base.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Software Engineer C++ - FTC

Provide post release support in all instances, including training where necessary to internal customers, and occasionally with external ...

Alfresco CMS Administrator, London

Using design patterns for smart client development (MVC) • Employing Agile methods for software delivery • Utilisation of source ...

Senior Firmware Engineer, Embedded C, RTOS

Fault finding and bug fixing Senior Firmware Engineer This is an exciting opportunity to work for an international organisation, within a highly ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: