Download PDF
Amazon Web Services > Case Studies > Veracode Helps Developers Find Security Flaws Faster Using AWS
Amazon Web Services Logo

Veracode Helps Developers Find Security Flaws Faster Using AWS

Technology Category
  • Infrastructure as a Service (IaaS) - Cloud Computing
  • Application Infrastructure & Middleware - API Integration & Management
  • Infrastructure as a Service (IaaS) - Cloud Middleware & Microservices
Applicable Functions
  • Discrete Manufacturing
  • Product Research & Development
Use Cases
  • Cybersecurity
  • Intrusion Detection Systems
  • Computer Vision
Services
  • Cloud Planning, Design & Implementation Services
  • Software Design & Engineering Services
The Challenge
Veracode, a CA Technologies company, is on a mission to secure software applications so developers don’t release software that could be susceptible to breaches. As part of this mission, the company created Greenlight, a tool that helps developers discover and fix security-related defects while they are writing code. Because Greenlight is designed to find security flaws quickly, Veracode must ensure strong performance. “We need to deliver security vulnerability results in under a minute,” says Patrick Day, principal cloud engineer for Veracode. “If developers wait too long for the data, they’ll move on to a different product.” Veracode also needs to scale its solution to accommodate growth. “As we were building the application, we needed to plan for increases in code-scan volume,” Day says. As an application-development company, Veracode also strives to reduce the amount of time employees spend managing the IT environment. Day says, “We’re focused on developing and deploying products, so we don’t want to put our resources and energy into managing and provisioning.”
About The Customer
Veracode, a CA Technologies company based in Burlington, Massachusetts, is a growing application-security company. Founded in 2006, the company provides an automated cloud-based service for securing web, mobile, and third-party enterprise applications. The company has around 100 employees and operates in the United States. Veracode's main product is Greenlight, a tool that helps developers discover and fix security-related defects while they are writing code. The company's mission is to secure software applications so developers don’t release software that could be susceptible to breaches.
The Solution
Veracode chose to meet its needs for speed, scalability, and time savings by building Greenlight on the Amazon Web Services (AWS) Cloud. “I had used AWS in previous jobs, and I was very confident in its ability to provide reliability and scalability,” Day says. “At Veracode, we were also excited because we saw that AWS would enable rapid prototyping without a lot of backend management.” Veracode initially ran its Greenlight application on numerous Amazon Elastic Compute Cloud (Amazon EC2) instances. Recently, the company started using AWS Lambda, a managed service that gives Veracode the ability to run code without provisioning and managing servers. Veracode also uses Amazon API Gateway to access data and functionality for Greenlight. Additionally, the company uses Auto Scaling to automatically scale Greenlight up or down based on scan-volume growth. To enhance application security, Veracode takes advantage of AWS Key Management Service (AWS KMS), a managed service that helps the company create and control encryption keys to encrypt Greenlight data.
Operational Impact
  • Veracode can reliably deliver fast vulnerability scans by relying on AWS.
  • Veracode was able to support a jump in vulnerability-scan volume from 100 scans to 55,000 scans in a very short time frame due to the scalability provided by AWS.
  • Veracode developers can focus on building new features instead of spending time managing the application’s backend systems.
Quantitative Benefit
  • Veracode saves about one day of testing time each week due to the automation, reliability, and scalability of the AWS Cloud.
  • Veracode can deploy new features every 15 minutes, compared to a few times a day previously.

Related Case Studies.

Contact us

Let's talk!

* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.