Help | Advanced Search
What's New?
What's Popular?


The Right Tool for the Right Job: An Application Security Tools Report Card
sponsored by Ounce Labs
Posted:  08 May 2008
Published:  08 May 2008
Format:  PDF
Length:  20   Page(s)
Type:  White Paper
Language:  English


ABSTRACT:
In the ever changing landscape of application security, how does an organization choose the right set of tools to mitigate the risks their applications pose to their environment? Equally important: how, when, and by whom are these tools used most effectively? This paper examines the most common tools found in the enterprise application security environment:

  • Web Application Firewalls (WAF)
  • Web Application Scanners (WAS)
  • Source Code Analyzers (SCA)

Each tool is evaluated and compared in terms of how they address critical vulnerabilities, beginning with the Top Ten Vulnerabilities identified by the Open Web Application Security Project (OWASP). The paper will provide an at-a-glance "report card" to help ensure that organizations devising their application security strategy have an informed understanding of the approach of each tool, its method for addressing security flaws, and its efficiency and effectiveness in eliminating security threats to data through applications.


Author

Ryan Berg
Co-Founder and Chief Scientist ,  Ounce Labs
Ryan Berg is a Co&#45;Founder and Chief Scientist for Ounce Labs. In addition to advancing the state of the art in application security technologies&#44; Ryan is also a popular speaker&#44; instructor&#44; and author&#44; in the fields of security&#44; risk management&#44; and secure development processes. He holds patents and has patents pending in multi&#45;language security assessment&#44; kernel&#45;level security&#44; intermediary security assessment language&#44; and secure remote communication protocols. Prior to Ounce&#44; Ryan co&#45;founded Qiave Technologies&#44; a pioneer in kernel&#45;level security&#44; which was later sold to WatchGuard Technologies in October of 2000. In the late 1990s&#44; Ryan also designed and developed the infrastructure for GTE Internetworking/Genuity&#8217;s appliance&#45;based managed firewall and security services.<br />



BROWSE RELATED RESOURCES
AJAX | Application Security | Security Threats | Vulnerability Management | Web Services

View All Resources sponsored by Ounce Labs

Library Home | Advertise with Us | Product Library
A Service of Bitpipe