FREE MEMBERSHIP - Create your personalized Bitpipe Service!  Members: Sign in 
Search Bitpipe: 
  Search Help
The Right Tool for the Right Job: An Application Security Tools Report Card
sponsored by Ounce Labs
Posted:  08 May 2008
Published:  08 May 2008
Format:  PDF
Length:  20  Page(s)
Type:  White Paper

ABSTRACT:

In the ever changing landscape of application security, how does an organization choose the right set of tools to mitigate the risks their applications pose to their environment? Equally important: how, when, and by whom are these tools used most effectively? This paper examines the most common tools found in the enterprise application security environment:

  • Web Application Firewalls (WAF)
  • Web Application Scanners (WAS)
  • Source Code Analyzers (SCA)

Each tool is evaluated and compared in terms of how they address critical vulnerabilities, beginning with the Top Ten Vulnerabilities identified by the Open Web Application Security Project (OWASP). The paper will provide an at-a-glance "report card" to help ensure that organizations devising their application security strategy have an informed understanding of the approach of each tool, its method for addressing security flaws, and its efficiency and effectiveness in eliminating security threats to data through applications.
 
View This Now
 
AUTHOR: 

Ryan Berg
Co-Founder and Chief Scientist, Ounce Labs
Ryan Berg is a Co-Founder and Chief Scientist for Ounce Labs. In addition to advancing the state of the art in application security technologies, Ryan is also a popular speaker, instructor, and author, in the fields of security, risk management, and secure development processes. He holds patents and has patents pending in multi-language security assessment, kernel-level security, intermediary security assessment language, and secure remote communication protocols. Prior to Ounce, Ryan co-founded Qiave Technologies, a pioneer in kernel-level security, which was later sold to WatchGuard Technologies in October of 2000. In the late 1990s, Ryan also designed and developed the infrastructure for GTE Internetworking/Genuity’s appliance-based managed firewall and security services.


BROWSE RELATED RESOURCES:
AJAX | Application Security | Security Threats | Vulnerability Management | Web Services
View All Resources sponsored by Ounce Labs

Home | About Us | Contact Us | Advertise with Us | Partner with Us | Site Index
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines

Definitions: A B C D E F G H I J K L M N O P Q R S T U V W X Y Z Other   TechTarget - The Most Targeted IT Media
TechTarget Corporate Web Site  |   Media Kits  |   Site Map




All Rights Reserved, Copyright 2000 - 2007, TechTarget | Read our Privacy Statement