|
ABSTRACT:
In the ever changing landscape of application security, how does an organization choose the right set of tools to mitigate the risks their applications pose to their environment? Equally important: how, when, and by whom are these tools used most effectively? This paper examines the most common tools found in the enterprise application security environment:
- Web Application Firewalls (WAF)
- Web Application Scanners (WAS)
- Source Code Analyzers (SCA)
Each tool is evaluated and compared in terms of how they address critical vulnerabilities, beginning with the Top Ten Vulnerabilities identified by the Open Web Application Security Project (OWASP). The paper will provide an at-a-glance "report card" to help ensure that organizations devising their application security strategy have an informed understanding of the approach of each tool, its method for addressing security flaws, and its efficiency and effectiveness in eliminating security threats to data through applications.
|
| |
 |
| |
AUTHOR:
Ryan Berg
Co-Founder and Chief Scientist, Ounce Labs
Ryan Berg is a Co-Founder and Chief Scientist for Ounce Labs. In addition to advancing the state of the art in application security technologies, Ryan is also a popular speaker, instructor, and author, in the fields of security, risk management, and secure development processes. He holds patents and has patents pending in multi-language security assessment, kernel-level security, intermediary security assessment language, and secure remote communication protocols. Prior to Ounce, Ryan co-founded Qiave Technologies, a pioneer in kernel-level security, which was later sold to WatchGuard Technologies in October of 2000. In the late 1990s, Ryan also designed and developed the infrastructure for GTE Internetworking/Genuity’s appliance-based managed firewall and security services.
|