<iframe src="//www.googletagmanager.com/ns.html?id=GTM-KXSCJR" height="0" width="0" style="display:none;visibility:hidden">

Arpit Joshipura

Recent Posts

The Focus Has Shifted: Application Security is in the Limelight

Arpit Joshipura | May 24, 2016

I am pleased to report that after a period of calm, the media is now buzzing with great stories on application security. These stories give great insights, statistics and actionable guidance for CISO and Security executives.

Applications have taken on an important business role, acting as the heart of companies and generating millions of dollars in revenue. But, until recently application security was not a focus. But now, we are excited to see an influx in media coverage around this extremely important topic. Here are a few of our favorites:

Continue reading

Topics: Application Security, DevOps, Vulnerability remediation, DevSecOps, SQLi, SQL Injections

Hindsight is 20-15: Recent Web Attacks Prove Application Security is Broken

Arpit Joshipura | Apr 28, 2016

A look at the last 6 months of web application attacks show an interesting trend. Hackers are bypassing traditional defenses like firewalls that are based on methods like signatures, heuristics and data flow analysis. This post outlines how these recent attacks were carried out, what could have been done to prevent them, and whether runtime application security would be an appropriate solution for protecting against future attacks (as opposed to traditional perimeter solutions).

Continue reading

Topics: WAFs, Application Security, Language Security, LANGSEC, SQLi, Data Breaches, Runtime Application Security, SQL Injections

Prevoty Runtime Security Continues to Gain Momentum with Product Expansion and Industry Recognition

Arpit Joshipura | Apr 22, 2016

We are thrilled with the momentum Prevoty continues to see this year in the category of runtime application security. To start, we now offer new Web Services capabilities, which allows our customers to integrate attack protection technology into more applications easily and quickly. Additionally, we are continuing to gain industry recognition as a result of two new awards.

First, let’s take a look at our newest product expansion.

Continue reading

Topics: Company News, Prevoty Technology, Language Security, LANGSEC, Web Services

Why RASP is the Third Pillar of Application Security

Arpit Joshipura | Apr 12, 2016

According to recent research we conducted with the Ponemon Institute, one in two enterprises today admit that they need better application security — demonstrating both the scope and the reality of the problem.

Continue reading

Topics: RASP, Tech Zone, SAST, LANGSEC, DAST, Pattern matching, Runtime Application Self-Protection, Dynamic Application Security Testing, Runtime Application Security, Static Application Security Testing

Why LANGSEC for Runtime Application Security? Because Patterns Can't Keep Up

Arpit Joshipura | Mar 10, 2016

Age-old security is broken because it uses antique techniques 

Throughout the past ten years, security methods have remained relatively unchanged. These methods rely solely on signatures, heuristics and dataflow analysis and are focused on defending the networks. The problem is that hackers have learned how to work around predefined network controls. 

The majority of today's firewalls still have to run thousands of patterns to match for known attacks, and false positives and false negatives run high -- making it difficult to determine what is normal. These traditional methods rely on code that is constantly changing. The thing you’re trying to detect is changing because the application itself is always changing, causing solutions to be out of date as soon as they are created.

Continue reading

Topics: WAFs, Startups, Application Security, RASP, Prevoty Technology, Application Security Monitoring, Signatures, Language Security, Innovation, LANGSEC, Heuristics, AppSec, Pattern matching, Cross-site Scripting, Command Injection, Runtime Application Self-Protection, Data Flow Analysis, Vulnerability remediation, SQL Injections, CSRF

Six Application Security Predictions for 2016

Arpit Joshipura | Jan 22, 2016

This post originally appeared on CSO Online.

2016 is upon us and it is time to review what we think will happen in the world of application security in this fast-paced world. Security is always evolving just as attacks, hacks and vulnerabilities shift and as new technologies enter the landscape. Security must adapt in order to protect businesses, consumers and treasured data. Can today’s security practices achieve security assurances, rooted in sound computability theory? We believe so.

Continue reading

Topics: Application Security, RASP, Industry commentary, DevOps, Signatures