Security AppScan

From Wikipedia, the free encyclopedia
Jump to: navigation, search
IBM Security AppScan
Developer(s) IBM
Stable release
Version 9.3
Type Test management tools
License Proprietary
Website IBM Security AppScan web page

IBM Security AppScan, previously known as IBM Rational AppScan, is a family of web security testing and monitoring tools from the Rational Software division of IBM. AppScan is intended to test Web applications for security vulnerabilities during the development process, when it is least expensive to fix such problems. The product learns the behavior of each application, whether an off-the-shelf application or internally developed, and develops a program intended to test all of its functions for both common and application-specific vulnerabilities.


AppScan was originally developed by Israeli software company Sanctum Ltd. (which was initially named Perfecto Technologies) and was first released in 1998.[1] In 1999 Sanctum expanded its web security offering and launched one of the world's first Application firewall, named AppShield.[2]

AppScan version 2 was released in February 2001, adding policy recognition engine and knowledge database, an automatic and customizable crawler engine and attack simulator.[3] Version 3 was released in April 2002, adding collaborative testing capabilities, where different tasks can be assigned to different testers; and a number of user interface enhancements in both the scanning and reporting sections of the program.[4] By 2003 AppScan was used by over 500 enterprise customers and revenues reached $30m.[5]

In July 2004, Sanctum was acquired by Massachusetts based company Watchfire, which developed a web applications management platform named WebXM. AppScan became Watchfire's flagship product and Sanctum's R&D center in Herzliya, Israel, became Watchfire's main R&D location.[5]

In June 2007, Watchfire was acquired by IBM and incorporated into the Rational Software product line, enabling IBM to cover more of the application development lifecycle; with an addition of a tool to help developers make security intrinsic to the application.[6] Watchfire R&D center was incorporated into IBM R&D Labs in Israel.[7]

In 2009 IBM acquired Ounce Labs, adding to the AppScan line a tool that finds and corrects vulnerabilities in software source code during the development process, which was renamed AppScan Source Edition.[8]


  • AppScan Enterprise Edition - Client-server version used to scale security testing.
  • AppScan Standard Edition - Desktop software for automated Web application security testing environment for IT Security, auditors, and penetration testers
  • AppScan Source Edition - Prevent data breaches by locating security flaws in the source code
  • AppScan Dynamic Analyzer - Help secure web applications deployed on IBM Bluemix.
  • AppScan Mobile Analyzer - Help secure mobile applications by detecting dozens of pervasive, published security vulnerabilities.
  • Arxan Application Protection for IBM Solutions - Extend vulnerability analysis capabilities to mobile application hardening and runtime protection.


  • Virtual Forge CodeProfiler for IBM Security AppScan Source - Identify and remediate vulnerabilities in Advanced Business Application Programming (ABAP) code.

External links[edit]


  1. ^ "Perfecto Technologies Becomes Sanctum, Inc.; Pioneerin Automated Web Application Control and Security Changes Name". BusinessWire. 21 June 2000. 
  2. ^ Ellen Messmer (7 September 1999). "New tool blocks wily e-comm hacker tricks". CNN. Retrieved 17 November 2010. 
  3. ^ Mimoso, Michael S. (6 February 2001). "AppScan release secures Web applications". SearchSecurity. 
  4. ^ Costello, Sam (30 April 2002). "Sanctum boosts tests, reports in AppScan 3.0". Computerworld. 
  5. ^ a b "Sanctum acquired by Watchfire". Israel Venture Capital Research Center. 26 July 2004. 
  6. ^ Ogren, Eric (8 June 2007). "AppScan lives on with IBM". Computerworld. 
  7. ^ "Watchfire Israel goes to IBM". Globes. 7 June 2007. 
  8. ^ Rick, Whiting (8 June 2010). "IBM: Design Security Into New Applications During Development". CRN.