<iframe src="//www.googletagmanager.com/ns.html?id=GTM-KXSCJR" height="0" width="0" style="display:none;visibility:hidden">

Using Runtime Visibility to Align Application Security with DevOps

Kunal Anand | Apr 5, 2017

 

Download Prevoty's Guide to RASP now!

Continue reading

Topics: Application Security, RASP, Signatures, Language Security, LANGSEC, Runtime Application Self-Protection, Runtime Application Security, information security, signatureless, no signatures, prevoty

Signatures Are Dead, Now What?

Kunal Anand | Sep 20, 2016


(Image source: InfoSecurity Magazine)

Continue reading

Topics: Signatures, Language Security, LANGSEC, Data Flow Analysis

The Future of Application Security Depends On Our Infrastructure

Julien Bellanger | Jun 13, 2016

To say that the future of application security depends on our infrastructure may sound controversial -- especially coming from a runtime application security startup founder.

Don’t get me wrong. Our vision is still the same: application security has to be done at the application layer, and more so than ever, that security must be embedded in the application.

Continue reading

Topics: Application Security, RASP, Language Security, LANGSEC, AppSec, Runtime Application Self-Protection, Vulnerability remediation, Runtime Application Security, Infrastructure

Prevoty Turns Three Years Old and Gets a Web Lift

Julien Bellanger | May 9, 2016

Over the last three years, we went from brainstorming crazy ideas at a kitchen table to creating a new category for securing enterprises applications at runtime. We've captured our top 3 learnings in this blog post and have made some exciting new additions to our website. 

Continue reading

Topics: Company News, RASP, Prevoty Technology, DevOps, Language Security, LANGSEC, Runtime Application Self-Protection, Vulnerability remediation, DevSecOps, Runtime Application Security

Hindsight is 20-15: Recent Web Attacks Prove Application Security is Broken

Arpit Joshipura | Apr 28, 2016

A look at the last 6 months of web application attacks show an interesting trend. Hackers are bypassing traditional defenses like firewalls that are based on methods like signatures, heuristics and data flow analysis. This post outlines how these recent attacks were carried out, what could have been done to prevent them, and whether runtime application security would be an appropriate solution for protecting against future attacks (as opposed to traditional perimeter solutions).

Continue reading

Topics: WAFs, Application Security, Language Security, LANGSEC, SQLi, Data Breaches, Runtime Application Security, SQL Injections

Prevoty Runtime Security Continues to Gain Momentum with Product Expansion and Industry Recognition

Arpit Joshipura | Apr 22, 2016

We are thrilled with the momentum Prevoty continues to see this year in the category of runtime application security. To start, we now offer new Web Services capabilities, which allows our customers to integrate attack protection technology into more applications easily and quickly. Additionally, we are continuing to gain industry recognition as a result of two new awards.

First, let’s take a look at our newest product expansion.

Continue reading

Topics: Company News, Prevoty Technology, Language Security, LANGSEC, Web Services

Why RASP is the Third Pillar of Application Security

Arpit Joshipura | Apr 12, 2016

According to recent research we conducted with the Ponemon Institute, one in two enterprises today admit that they need better application security — demonstrating both the scope and the reality of the problem.

Continue reading

Topics: RASP, Tech Zone, SAST, LANGSEC, DAST, Pattern matching, Runtime Application Self-Protection, Dynamic Application Security Testing, Runtime Application Security, Static Application Security Testing

Why Security & DevOps Can’t Be Friends (Or Can They?)

Kunal Anand | Mar 16, 2016

football.jpegLegacy applications are a brush fire waiting to happen. But retrofitting custom code built in the early 2000's is just a small part of the application security problem.

Security hasn’t changed much in the last 10 years. Companies still use pattern matching and pattern-based defenses which aren’t enough to protect websites and company data from the bad guys. Hackers continuously find unique ways to create fuzzing techniques or to perform fuzzing to create new exploits, and a lot of companies can’t run regular expressions, and most can’t use pattern matching to defeat that. 

In order to protect against cross-site scripting (XSS) or SQL injection (SQLi), why not look at application security through the lens of a web browser or a database engine? What if there was a unique way to solve these problems instead of just solving it at the perimeter? Why don't companies protect from within the application where they have access to contacts and important contextual information? Most say it's lag time, or performance issues that inhibit this kind of solution. But I’m not so sure.

Continue reading

Topics: Application Security, Legacy Apps, DevOps, Language Security, xss, LANGSEC, Pattern matching, Cross-site Scripting, Runtime Application Self-Protection, Vulnerability remediation, Agile Security, fuzzing, DevSecOps, CVE Vulnerabilities, Runtime Application Security, SQL Injections, CSRF

Why LANGSEC for Runtime Application Security? Because Patterns Can't Keep Up

Arpit Joshipura | Mar 10, 2016

Age-old security is broken because it uses antique techniques 

Throughout the past ten years, security methods have remained relatively unchanged. These methods rely solely on signatures, heuristics and dataflow analysis and are focused on defending the networks. The problem is that hackers have learned how to work around predefined network controls. 

The majority of today's firewalls still have to run thousands of patterns to match for known attacks, and false positives and false negatives run high -- making it difficult to determine what is normal. These traditional methods rely on code that is constantly changing. The thing you’re trying to detect is changing because the application itself is always changing, causing solutions to be out of date as soon as they are created.

Continue reading

Topics: WAFs, Startups, Application Security, RASP, Prevoty Technology, Application Security Monitoring, Signatures, Language Security, Innovation, LANGSEC, Heuristics, AppSec, Pattern matching, Cross-site Scripting, Command Injection, Runtime Application Self-Protection, Data Flow Analysis, Vulnerability remediation, SQL Injections, CSRF

Subscribe to Email Updates