* Breach Security’s approach to security
endif; ?>The evolution of Web-based enterprise application technologies has been one of the hotter topics in IT this year. For security managers, however, this enthusiasm strikes a familiar and disturbing chord. To them, the rush to place exciting new features and functions into production has also had an unfortunate history of exposing serious security issues before their implications are well understood.
Their fears remain well justified. Application attacks are on the rise, in part because their defense is a moving target. By definition, custom code differs from application to application. Input and output can be specific to each individual transaction. The challenges are great: defenses must have deep knowledge of application structure, yet must also be broad enough to embrace a wide range of exploits.
Today’s approaches to application defense largely revolve around two domains: code analysis and operational protection. That these two camps have become distinct is unfortunate, because what goes into application code has a direct impact on the effectiveness of operational defense.
We are beginning to see this gap being bridged, however, and one of the first vendors to do so is the aptly named Breach Security.
While other approaches to operational defense employ inline firewalling, Breach represents an evolution of the field with a more distributed, multilayered approach. The readily deployed appliance form factor of Breach’s BreachGate WebDefend does not sit directly in the application data path, which would potentially affect application availability – something which has required application firewalls to become application acceleration and delivery platforms as well. Instead, BreachGate WebDefend listens to traffic and deploys countermeasures through multilayered techniques such as blocking at a perimeter firewall or dropping a connection at a server.
The BreachGate WebDefend appliance can devote its resources to analytics that give operational administrators as well as application developers and managers a more detailed view into the actual state of application security than many alternatives. Aided by what Breach terms BreachMarks that apply pattern recognition to potentially sensitive outbound information, a broad range of out-of-the-box application security policies can be deployed as-is or modified as needed. This policy-based threat recognition is combined with behavior-based analysis in a technology Breach calls Adaption, which correlates normal HTTP request-response pairs that allow it to “fingerprint” normal application behavior and recognize variations that may indicate a security event.
BreachGate WebDefend’s event viewer allows substantial drilldown on these events, providing the context in which an event is detected, as well as substantial background information. This helps bridge yet another critical gap in application security management: the differences in understanding between developers and operational security managers. Defenses leverage the existing application and security architecture, through the distributed, multilayered blocking techniques that can be applied at key control points.
For application developers and managers, BreachGate WebDefend offers substantial visibility into application security as it really is in operation, providing real-world visibility into the practical application of secure development. For operational security specialists, the product enables them to communicate more effectively with application teams, helping to facilitate more realistic security enforcement.
For the enterprise, it represents a substantial step toward closing the many breaches that continue to aggravate the challenge of application security. Give Breach a visit – they’re definitely worth a look.




