Login|Japanese
July 14, 2009
 Video of Eldad Chai, Imperva talking at OWASP in Poland about Business Logic Attacks

Business Logic Attacks

Here is a link to Eladad's video.

Here is a link to the presentation in PDF.

BAT

 

July 13, 2009
 SecureSphere Visio Stencil

SecureSphere visio template image

One of the benefits of gathering together for training (beyond the obvious education) is the knowledge, utilities and tools that are being shared. 

One tool that is often requested by our partners and customers is a Microsoft Visio stencil for SecureSphere.

Enjoy!


 

 Imperva Podcast - SQL Injection Attacks & Mitigation Techniques w/ Amichai Shulman

On this episode of the Imperva Security Podcast Amichai Shulman – CTO and Co-founder of Imperva talks about SQL Injection. He discusses how these attacks are preformed, why they are so pervasive, why signature detection doesn't work, and how to mitigate these attacks.

To see various SQL Injection Attacks in action, check out our educational video demonstrations on YouTube.

For more information on SQL Injection Attacks - visit the Imperva Glossary. 

 

July 09, 2009
 Covering The Blind Spots: Auditing and Securing Oracle’s Encrypted Communication

Visability needed

Almost 18 months I wrote this white paper and then forgot all about until today when I found out that it is actually used internally. It uses some marketing lingo but nothing exceptional or unaccepted. 

So, here it is, enjoy.


Full Visibility into Database Usage for Robust Data Governance 
Meeting compliance Mandates requires visibility and control over business applications and databases – including monitoring the actions of privileged database users. Imperva delivers comprehensive database auditing and visibility into database changes that helps organizations ensure and demonstrate the integrity of applications and databases. This is a critical component of regulatory compliance for not only Sarbanes-Oxley, but also similar legislation outside of the US such as “J-SOX” (Japan), “K-SOX” (Korea), and PIPEDA (Canada).

Continue reading "Covering The Blind Spots: Auditing and Securing Oracle’s Encrypted Communication" »

 

 Imperva Podcast Transcript - Dr. Anton Chuvakin Talks PCI, VA & Security Trends

On this episode of the Imperva Security Podcast Dr. Anton Chuvakin shares his perspectives on PCI, vulnerability scanning, compliance, and general security trends.

  • The podcast can be found here.
  • The transcript can be found here.


Dr. Anton Chuvakin (http://www.chuvakin.org) is the Director of PCI Compliance Solutions at Qualys and is a recognized security expert and book author. He is an author of the book "Security Warrior" and a contributor to books such as "Know Your Enemy II", "Information Security Management Handbook", "Hacker's Challenge 3", "PCI Compliance", "OSSEC HIDS" and others. Anton also published numerous papers on a broad range of security subjects. In his spare time he blogs at http://www.securitywarrior.org. Anton has presented at many security conferences across the world; his recent speaking engagements include presenting in the United States, UK, Singapore, Spain, Canada, Poland, Czech Republic, Russia and other countries. Anton holds a Ph.D. degree from Stony Brook University.

 

July 08, 2009
 Targeted Cyber Attacks Against U.S Web Sites

Verisign iDefense reports that the web sites of The White House, the Department of Homeland Security, the Department of Defense and the Federal Aviation Administration as well as The New York Stock Exchange, NASDAQ, and The Washington Post were under attack for few days. InformationWeek reports that the attack attempts to flood  the web servers with initial requests to connect managed to temporarily take down some  web sites. 

So there's nothing new about one nation attacking another one.(Not to mention that N. Korea was always the bad guy and part of the axle of evil). What's interesting about this story is that the attack does not use of the known malware.  According to the news reports, the malware used was likely developed for this specific attack. In military terms, the attacker is exposing secret technology that was developed for a command day. The attack is probably not known and therefore can't be stopped with a signature of signature-based solution. 

Hum, time for some dynamic profiling?

 

 Cenzic and Imperva Integrate VA and WAF

Using Cenzic's Cloud Computing Product you can forward reports to developers or even give them dashboard access to help address vulnerabilities found by Cenzic. However, there may be business, political, and/or technical reasons why a vulnerability can not be addressed as soon as discovered. Until that vulnerability is fixed, Imperva integration allows a seamless export of Cenzic data into the Imperva Web Application Firewall (WAF) and will immediately begin monitoring, alerting and/or blocking attacks aimed at exploiting those vulnerabilities. 

Here are some screen shots of this process in action

This is another great example of the unification of WAF & VA and helps to illustrate the evolution and maturity of the application and data security industry by bringing together solutions (WAF & VA) that were once seen as competitive rather than complementary.

 

July 07, 2009
 Script Injection Demonstration Video from Imperva

This is a continuation of multiple educational video demonstrations related to Web application attacks. This video is focused on Script Injection and touches on session hijacking; it should be viewed as a prerequisite to the Cross-site Scripting (XSS) demonstration video which will drop soon.

 

July 01, 2009
 This Ain't Your Grandfather's Blog

Starting next week Imperva will be featuring a new blog with lots of new capabilities that we simply didn't know we needed, we wanted, were relevant a year ago. Our new blog will have greater integration with our Web 2.0 program and leverage services such as Twitter, Facebook, YouTube, iTunes and many others in a more streamlined and symbiotic format.

From an organizational perspective - this is an interesting time for those in marketing. What services should be used, how do you know if they are successful, how do they promote each other without becoming repetitive, how does this tie into more traditional tasks like lead generation, press releases, product marketing, etc, etc.

Each of the Web 2.0 services mentioned above has its strengths, and it's clear - at least right now, that the blog still acts as the focus point, but with plenty of other interesting services out there, and the dynamic nature of 2.0, blogs of tomorrow may be as far from blogs of today, as blogs of today are from the "olden days" when people actually got their news with a 24-hour delay, printed on paper, and delivered by your neighbor's kids on a bicycle.

 

June 30, 2009
 The Road To Data Intelligence
ClearPoint Metrics and Imperva announced today a collaborative effort to deliver strategic intelligence on organizations data security and compliance initiatives. This partnership allows us to  integrate SecureSphere Data Security Suite with ClearPoint Metrics' Security Performance Manager. This will create a new class of security performance and risk metrics that will provide visibility into the state, quality and effectiveness of data security investments for chief information security officers, auditors as well as business managers concerned about security.

According to Rohit Gupta, "Imperva's mission is to help organizations secure critical data and achieve regulatory compliance for their Web and database applications. Combining the visibility and control of database activity provided by SecureSphere with ClearPoint's Security Performance Manager's customers get a powerful, global view of the state of their security infrastructure."

In the future we will release more information about this integration. Stay tuned.