<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>ImperViews</title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/" />
    <link rel="self" type="application/atom+xml" href="http://blog.imperva.com/atom.xml" />
    <id>tag:,2008-02-26:/2</id>
    <updated>2008-05-14T22:42:32Z</updated>
    
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type Open Source 4.1</generator>

<entry>
    <title>Under All that Heavy Equipment there is Just an Operating System</title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/2008/05/all-that-heavy-equipment-under.html" />
    <id>tag:blog.imperva.com,2008://2.17</id>

    <published>2008-05-15T12:21:30Z</published>
    <updated>2008-05-14T22:42:32Z</updated>

    <summary><![CDATA[ Recently, a rare bug in&nbsp;a SCADA system by Invensys was&nbsp;disclosed - one&nbsp;which if exploited could cause a remote Denial of Service on the system.&nbsp;As these systems are deployed in power plants, dam control systems and other&nbsp;truly mission critical systems...]]></summary>
    <author>
        <name>Amichai Shulman</name>
        <uri>http://www.imperva.com/company/management.html#2</uri>
    </author>
    
    <category term="applicationsecurity" label="application security" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="infrastructure" label="infrastructure" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="scada" label="SCADA" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="threats" label="threats" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://blog.imperva.com/">
    	
<![CDATA[ Recently, a rare bug in&nbsp;a SCADA system by Invensys was&nbsp;disclosed - one&nbsp;which if exploited could cause a remote Denial of Service on the system.&nbsp;As these systems are deployed in power plants, dam control systems and other&nbsp;truly mission critical systems...]]>

    </content>
</entry>

<entry>
    <title>Patches Reversing into Exploits</title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/2008/05/patches-reversing-into-exploit.html" />
    <id>tag:blog.imperva.com,2008://2.12</id>

    <published>2008-05-13T15:33:22Z</published>
    <updated>2008-05-13T17:06:35Z</updated>

    <summary><![CDATA[ On May 18 security researchers&nbsp;will gather&nbsp;at the IEEE Symposium on Security and Privacy. One of the papers to be represented is "Automatic Patch-Based Exploit Generation is Possible: Techniques and Implications" by David Brumley, Pongskin Poosankam, Dawn Song and Jiang...]]></summary>
    <author>
        <name>Amichai Shulman</name>
        <uri>http://www.imperva.com/company/management.html#2</uri>
    </author>
    
    <category term="applicationsecurity" label="application security" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="virtualpatching" label="virtual patching" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://blog.imperva.com/">
    	
<![CDATA[ On May 18 security researchers&nbsp;will gather&nbsp;at the IEEE Symposium on Security and Privacy. One of the papers to be represented is "Automatic Patch-Based Exploit Generation is Possible: Techniques and Implications" by David Brumley, Pongskin Poosankam, Dawn Song and Jiang...]]>

    </content>
</entry>

<entry>
    <title>The Hunt For The Kill Switch</title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/2008/05/the-hunt-for-the-kill-switch.html" />
    <id>tag:blog.imperva.com,2008://2.16</id>

    <published>2008-05-12T14:27:54Z</published>
    <updated>2008-05-12T02:13:47Z</updated>

    <summary>I am a big fan of conspiracy theories and the business of being paranoid. This must be the reason that I&apos;m in the proactive security business for more than a decade now. I truly believe in Andrew Grove&apos;s Only the...</summary>
    <author>
        <name>Sharon Besser</name>
        <uri>http://www.imperva.com</uri>
    </author>
    
    <category term="analogy" label="analogy" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="securesphere" label="SecureSphere" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="security" label="security" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="technology" label="technology" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://blog.imperva.com/">
    	
I am a big fan of conspiracy theories and the business of being paranoid. This must be the reason that I&apos;m in the proactive security business for more than a decade now. I truly believe in Andrew Grove&apos;s Only the...

    </content>
</entry>

<entry>
    <title>How Low Can You Go?</title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/2008/05/how-low-can-you-go.html" />
    <id>tag:blog.imperva.com,2008://2.13</id>

    <published>2008-05-07T16:53:44Z</published>
    <updated>2008-05-07T16:59:05Z</updated>

    <summary>If you are wondering about the answer to this question regarding Web Application Security, you must read the following article in the Register and then get some further gory details and examples from the Daily WTF. In this story, the...</summary>
    <author>
        <name>Amichai Shulman</name>
        <uri>http://www.imperva.com/company/management.html#2</uri>
    </author>
    
    <category term="databreaches" label="data breaches" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="sqlinjection" label="SQL Injection" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="webapplicationsecurity" label="web application security" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://blog.imperva.com/">
    	
If you are wondering about the answer to this question regarding Web Application Security, you must read the following article in the Register and then get some further gory details and examples from the Daily WTF. In this story, the...

    </content>
</entry>

<entry>
    <title>WAF. Defined.</title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/2008/05/waf-defined.html" />
    <id>tag:blog.imperva.com,2008://2.14</id>

    <published>2008-05-05T13:47:05Z</published>
    <updated>2008-05-04T04:55:50Z</updated>

    <summary><![CDATA[One of the outcomes of the PCI Security Standards Council information supplement for PCI DSS requirement 6.6 that I blogged about last week,&nbsp; is providing a definition of Web Application Firewalls. The definition was made by creating 3 different set...]]></summary>
    <author>
        <name>Sharon Besser</name>
        <uri>http://www.imperva.com</uri>
    </author>
    
    <category term="pci" label="PCI" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="waf" label="WAF" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="webapplicationfirewall" label="web application firewall" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://blog.imperva.com/">
    	
<![CDATA[One of the outcomes of the PCI Security Standards Council information supplement for PCI DSS requirement 6.6 that I blogged about last week,&nbsp; is providing a definition of Web Application Firewalls. The definition was made by creating 3 different set...]]>

    </content>
</entry>

<entry>
    <title>Attacking Around the Globe Around the Clock</title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/2008/04/attacking-around-the-globe-aro.html" />
    <id>tag:blog.imperva.com,2008://2.11</id>

    <published>2008-04-30T14:52:54Z</published>
    <updated>2008-05-01T03:09:06Z</updated>

    <summary>There&apos;s been a lot of security talk recently regarding the latest massive attack where hundreds of thousands of URLs have been hacked. Add to this that many of the infected sites belong to some big-name organizations such as the UN,...</summary>
    <author>
        <name>Amichai Shulman</name>
        <uri>http://www.imperva.com/company/management.html#2</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://blog.imperva.com/">
    	
There&apos;s been a lot of security talk recently regarding the latest massive attack where hundreds of thousands of URLs have been hacked. Add to this that many of the infected sites belong to some big-name organizations such as the UN,...

    </content>
</entry>

<entry>
    <title>PCI&apos;s 6.6 Accountability Problem</title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/2008/04/pcis-66-accountability-problem.html" />
    <id>tag:blog.imperva.com,2008://2.10</id>

    <published>2008-04-28T18:33:56Z</published>
    <updated>2008-05-02T17:29:00Z</updated>

    <summary>Last week, the PCI Standards Council has issued a press release and a supplement document clarifying some of the ambiguous points in the PCI standard, including section 6.6. SecureSphere addresses 8 or 10 of the 12 PCI requirements (depends on...</summary>
    <author>
        <name>Sharon Besser</name>
        <uri>http://www.imperva.com</uri>
    </author>
    
    <category term="datasecurity" label="data security" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="pci" label="PCI" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="webapplicationfirewall" label="web application firewall" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://blog.imperva.com/">
    	
Last week, the PCI Standards Council has issued a press release and a supplement document clarifying some of the ambiguous points in the PCI standard, including section 6.6. SecureSphere addresses 8 or 10 of the 12 PCI requirements (depends on...

    </content>
</entry>

<entry>
    <title>Patch and Forget?</title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/2008/04/patch-and-forget.html" />
    <id>tag:blog.imperva.com,2008:/blog//2.23</id>

    <published>2008-04-14T22:47:48Z</published>
    <updated>2008-04-29T17:43:07Z</updated>

    <summary>This week has raised once again the question regarding the effectiveness of patching as a security countermeasure. The past Tuesday is known to Microsoft users as Patch Tuesday, where Microsoft released eight fixes as part of its monthly security update,...</summary>
    <author>
        <name>Amichai Shulman</name>
        <uri>http://www.imperva.com/company/management.html#2</uri>
    </author>
    
    <category term="applicationdatasecurity" label="application data security" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="databreaches" label="data breaches" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="patching" label="patching" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="virtualpatching" label="virtual patching" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://blog.imperva.com/">
    	
This week has raised once again the question regarding the effectiveness of patching as a security countermeasure. The past Tuesday is known to Microsoft users as Patch Tuesday, where Microsoft released eight fixes as part of its monthly security update,...

    </content>
</entry>

<entry>
    <title>RSA is Over</title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/2008/04/rsa-is-over.html" />
    <id>tag:blog.imperva.com,2008:/blog//2.22</id>

    <published>2008-04-12T01:58:45Z</published>
    <updated>2008-04-18T08:46:23Z</updated>

    <summary>So the party RSA is over. Even though most bloggers and reporters unanimously agree that this year was lacking a common theme and excitement, I did find some common theme. During my discussions with customers, prospects and peers while networking...</summary>
    <author>
        <name>Sharon Besser</name>
        <uri>http://www.imperva.com</uri>
    </author>
    
    <category term="applicationdatasecurity" label="application data security" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="beer" label="beer" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="rsa" label="RSA" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="tradeshows" label="trade shows" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://blog.imperva.com/">
    	
So the party RSA is over. Even though most bloggers and reporters unanimously agree that this year was lacking a common theme and excitement, I did find some common theme. During my discussions with customers, prospects and peers while networking...

    </content>
</entry>

<entry>
    <title>Hackers Can Cause Epilepsy </title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/2008/04/hackers-can-bring-about-epilep.html" />
    <id>tag:blog.imperva.com,2008:/blog//2.21</id>

    <published>2008-04-01T17:10:27Z</published>
    <updated>2008-04-18T08:45:17Z</updated>

    <summary>In my opinion, the report of hackers assault epilepsy patients might be the first recorded occurrence of physical, human damage due to large scale hacking. We heard about medical facilities attacks and records destruction in the past. But according to...</summary>
    <author>
        <name>Sharon Besser</name>
        <uri>http://www.imperva.com</uri>
    </author>
    
    <category term="applicationsecurity" label="application security" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="hackers" label="hackers" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://blog.imperva.com/">
    	
In my opinion, the report of hackers assault epilepsy patients might be the first recorded occurrence of physical, human damage due to large scale hacking. We heard about medical facilities attacks and records destruction in the past. But according to...

    </content>
</entry>

<entry>
    <title>Protecting The Virtual World&apos;s Economy</title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/2008/03/protecing-the-virtuals-world-e.html" />
    <id>tag:blog.imperva.com,2008:/blog//2.20</id>

    <published>2008-03-27T00:53:35Z</published>
    <updated>2008-04-30T19:14:07Z</updated>

    <summary>View Image I attended one of the most interesting customer meetings yesterday. It was interesting because the customer is asking to deploy SecureSphere in order to protect the entire universe. His universe. As you can guess, this company (let&apos;s keep...</summary>
    <author>
        <name>Sharon Besser</name>
        <uri>http://www.imperva.com</uri>
    </author>
    
    <category term="applicationdatasecurity" label="application data security" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="databaseactivitymonitoring" label="database activity monitoring" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="economy" label="economy" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="virtualworlds" label="virtual worlds" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://blog.imperva.com/">
    	
View Image I attended one of the most interesting customer meetings yesterday. It was interesting because the customer is asking to deploy SecureSphere in order to protect the entire universe. His universe. As you can guess, this company (let&apos;s keep...

    </content>
</entry>

<entry>
    <title>What makes a solution better, unique and different?</title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/2008/03/what-makes-a-solution-better-u.html" />
    <id>tag:blog.imperva.com,2008:/blog//2.15</id>

    <published>2008-03-14T04:59:41Z</published>
    <updated>2008-05-02T18:45:36Z</updated>

    <summary>What makes a solution better, unique and different? Boston, MA Today, I participated in a security panel that was (very well) organized by our partner, Netanium Network Security, Inc. Four different vendors, focusing on solving different aspects of information security,...</summary>
    <author>
        <name>Sharon Besser</name>
        <uri>http://www.imperva.com</uri>
    </author>
    
    <category term="differentiation" label="Differentiation" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://blog.imperva.com/">
    	
What makes a solution better, unique and different? Boston, MA Today, I participated in a security panel that was (very well) organized by our partner, Netanium Network Security, Inc. Four different vendors, focusing on solving different aspects of information security,...

    </content>
</entry>

<entry>
    <title>Closest Thing to a Silver Bullet for Security Managers</title>
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/2008/03/closest-thing-to-a-silver-bull.html" />
    <id>tag:blog.imperva.com,2008:/blog//2.14</id>

    <published>2008-03-14T03:46:54Z</published>
    <updated>2008-05-02T18:46:14Z</updated>

    <summary>SecureSphere Wins another WAF shoot outWhat a great start for my first blog post with our new blogging system. Information security magazine published a review of six (6) web application firewall products. Beside winning this shoot-out review and scoring top...</summary>
    <author>
        <name>Sharon Besser</name>
        <uri>http://www.imperva.com</uri>
    </author>
    
    <category term="securesphere" label="SecureSphere" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="silverbullet" label="Silver Bullet" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="waf" label="WAF" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://blog.imperva.com/">
    	
SecureSphere Wins another WAF shoot outWhat a great start for my first blog post with our new blogging system. Information security magazine published a review of six (6) web application firewall products. Beside winning this shoot-out review and scoring top...

    </content>
</entry>

</feed>
