No more typing reviews! Try our Samantha, our new voice AI agent.

Defensics Protocol Fuzzing vs SonarQube comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Defensics Protocol Fuzzing
Average Rating
8.6
Number of Reviews
4
Ranking in other categories
Fuzz Testing Tools (4th)
SonarQube
Average Rating
8.0
Reviews Sentiment
7.1
Number of Reviews
135
Ranking in other categories
Application Security Tools (1st), Static Application Security Testing (SAST) (1st), Software Development Analytics (1st)
 

Mindshare comparison

While both are Quality Assurance solutions, they serve different purposes. Defensics Protocol Fuzzing is designed for Fuzz Testing Tools and holds a mindshare of 15.2%, down 23.1% compared to last year.
SonarQube, on the other hand, focuses on Application Security Tools, holds 12.7% mindshare, down 24.3% since last year.
Fuzz Testing Tools Mindshare Distribution
ProductMindshare (%)
Defensics Protocol Fuzzing15.2%
PortSwigger Burp Suite Professional33.6%
GitLab30.1%
Other21.099999999999994%
Fuzz Testing Tools
Application Security Tools Mindshare Distribution
ProductMindshare (%)
SonarQube12.7%
Checkmarx One8.3%
Snyk5.0%
Other74.0%
Application Security Tools
 

Featured Reviews

SK
Senior Technical Lead at HCL Technologies
Product security tests for switches and router sections
Codenomicon Defensics should be more advanced for the testing sector. It should be somewhat easy and flexible to install. What I see in the documentation isn't that. Even if something doesn't malfunction, sometimes it is hard to install and execute. The product needs video documentation. This would help a lot more.
Sathyamurthi Natarajan - PeerSpot reviewer
IT Officer (Solution Architect) at World Bank
We maintain high code standards with effective static code analysis and integration
SonarQube Server (formerly SonarQube) could be improved on the reporting front. Instead of grouping, I would prefer to scan the code as part of development and then generate a report on a daily basis among different units or projects, which is currently complicated. We need to change it to more of a portfolio report, where configuring or setting up things on the portfolio requires tagging at the ADO level.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Simple and straightforward GUI."
"Whatever the test suit they give, it is intelligent; it will understand the protocol and it will generate the test cases based on the protocol: protocol, message sequence, protocol, message structure, and because of that, we can eliminate a lot of unwanted test cases so we can execute the tests and complete them very quickly."
"The stability of this product is great; we tested it under multiple constraints and even on cloud services it is absolutely stable."
"ROI was 100%. Since there are no product suites available that provide the level of testing available with Codenomicon, the development, quality and security assurance departments know that the investment was correct."
"We have found multiple issues in our embedded system network protocols, related to buffer overflow. We have reduced some of these issues."
"The product is related to US usage with TLS contact fees, i.e. how more data center connections will help lower networking costs."
"I find SonarQube Cloud to be very user-friendly with an easy-to-use interface."
"I'm not implementing the solutions. However, I've talked to the people who deploy the tools, and they are happy with how easy setting up SonarCloud is."
"We have the software metrics that SonarQube gives us, which is something we did not have before. This helps us work towards aiming coding standards to empower us to move in the direction of better code quality. SonarQube provides targets and metrics for that."
"It has improved our options for offering products to our clients that can better meet their needs, lower costs, and improves code quality and basic security."
"It is a very good tool for analysis despite its limitations."
"This solution has the capability to analyze source code in almost all the languages in the market."
"When it comes to security, this solution is pretty great."
"We consider it a handy tool that helps to resolve our issues immediately."
 

Cons

"Sometimes, when we are testing embedded devices, when we trigger the test cases, the target will crash immediately. It is very difficult for us to identify the root cause of the crash because they do not provide sophisticated tools on the target side. They cover only the client-side application... They do not have diagnostic tools for the target side. Rather, they have them but they are very minimal and not very helpful."
"It requires understanding the Defensics protocol."
"Codenomicon Defensics should be more advanced for the testing sector. It should be somewhat easy and flexible to install."
"It does not support the complete protocol stack. There are some IoT protocols that are not supported and new protocols that are not supported."
"You can't implement proprietary ciphering algorithms, nor can you modify protocol models if you need to test customized public protocols."
"The solution is a bit lacking on the security side, in terms of finding and identifying vulnerabilities."
"It would be helpful if notifications could go out to an extra person."
"I have found this solution creates more noise than competitors."
"We've been using the Community Edition, which means that we get to use it at our leisure, and they're kind enough to literally give it to us. However, it takes a fair amount of effort to figure out how to get everything up and running. Since we didn't go with the professional paid version, we're not entitled to support. Of course that could be self-correcting if we were to make the step to buy into this and really use it. Then their technical support would be available to us to make strides for using it better."
"After scanning our code and generating a report, it would be helpful if SonarQube could also generate a solution to fix vulnerabilities in the report."
"The learning curve can be fairly steep at first, but then, it's not an entry-level type of application."
"There is room for improvement in the code security space which is not as extensive as it could be. There are other products on the market which are much better in terms of code security scanning."
"SonarQube needs to improve its support model. They do not work 24/7, and they do not provide weekend support in case things go wrong. They only have a standard 8:00 am to 5:00 pm support model in which you have to raise a support ticket and wait. The support model is not effective for premium customers."
 

Pricing and Cost Advice

"Licensing is a bit expensive."
"We're using the Community Edition, and we don't pay for anything."
"The price of SonarCloud could be less expensive. We are using the community version and the price should be more reasonable."
"I rate the pricing a five out of ten."
"There is both a free and licensed version. The free version has limitations on development languages and support."
"SonarQube is a fairly affordable solution for a larger scale if you have a specific role or specific department for secure code."
"I am using the free version of the solution."
"This product is open source and very convenient."
"People can try the free licenses and later can seek buying plugins/support, etc. once they started liking it."
report
Use our free recommendation engine to learn which Fuzz Testing Tools solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Financial Services Firm
10%
Manufacturing Company
10%
Comms Service Provider
7%
Financial Services Firm
13%
Manufacturing Company
13%
Computer Software Company
12%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business43
Midsize Enterprise24
Large Enterprise79
 

Questions from the Community

Ask a question
Earn 20 points
Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which tools that are the best for for Static Code Analysis, I suggest you have a look...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
 

Also Known As

Codenomicon Defensics
Sonar, SonarQube Cloud
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Coriant, CERT-FI, Next Generation Networks
Snowflake, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.