Uploaded by 0Oooo0oO0ooOoo0 on May 4, 2011
OWASP Israel 2008 Conference
Ivan Ristic
No More Signatures: Defending Web Applications from 0-Day Attacks with ModProfiler Using Traffic Profiling
Web application security is a big problem, yet there is never enough time to dedicate to solving the issue or, at least, making it smaller. To help with this, we embarked on a project that would enable you to tighten the security of your web applications with little effort. The project, called ModProfiler, aims to provide best-possible protection for web applications by analysing web application traffic passing by. This new open source tool builds on the success of ModSecurity (also open source), which is generally considered to be the most widely deployed web application firewall.
The premise is simple: ModProfiler works by observing what's valid and what's not, resulting with a tight application shield designed around the positive security model concept. The process of shield construction is not as simple, but the complexity is hidden away. This talk, presented by Ivan Ristic, the author of the tool, will give you an insight into the technology behind the scenes, and enable you to get the most out of it.
About Ivan Ristic
Ivan Ristic is the Vice President of Security Research for Breach Security, Inc. as a result of the recent acquisition of Thinking Stone Ltd. and its ModSecurity open source web application firewall. At Breach Security, Ristic will focus primarily on educating the market about the security risks associated with conducting business on the web. He will also continue to improve the open source ModSecurity project as well as incorporate ModSecurity technology into Breach Security’s WebDefend architecture. Prior to moving to the computer security field, Ristic spent a number of years working as a developer, system architect, and technical director in the software development industry. He authored Apache Security for O’Reilly, a concise yet comprehensive web security guide for administrators, system architects, and programmers. Ristic earned a BSc with honors in Information Technology and Computing from the Open University. He also completed coursework at the Faculty of Electrical Engineering, University of Belgrade.
http://www.owasp.org/index.php/OWASP_Israel_2008_Conference_at_the_Interdisci...
-
0 likes, 0 dislikes
5:31
Micro Drone V2 FPVby rctestflight7,287 views
48:48
Theory and Practice of Cryptographyby GoogleTechTalks32,371 views
9:00
Owasp5023 Part2 -WAF MODSECURITY, with Ivan Ristic.by mediarchives267 views
54:00
Protection from Latest Network and Application Attacksby f5networksinc780 views
4:30
Owasp5023 Part6 -WAF MODSECURITY, with Ivan Ristic.by mediarchives142 views
15:01
OWASP Mantra Security Framework, An introduction at Clubhack 2010-part 2.flvby Getmantra397 views
3:45
Subhanallah - Ustaz Asri Ibrahimby nyem6960,382 views
10:17
Ivan Risticby rileta91872 views
5:13
Semantic based Web Application Firewallby ranafaisal342247 views
42:55
ApacheCon 2011: Security Problems (And Solutions) For Service Oriented Applicationsby TalendChannel154 views
45:11
SCS3: Antonio Fontes - Open Web Application Security Projectby swisscyberstorm103 views
8:26
Imperva SecureSphere Web Application Firewall Vulnerability Assessment Integrationby ImpervaChannel3,160 views
5:19
The state of SSL on the web: Qualys' Ivan Ristic discusses the good and the badby SCMagazineUS64 views
9:59
CERIAS Security: Automatic Signature Generation for Unknown Vulnerabilities 1/5by ChRiStIaAn00862 views
1:22
Nashville's Home Inspector Revals Most Common Firewall Breachby homeinspectnashville32 views
59:18
Blackhat 2010 - State of SSL on the internet - Ivan Ristic - Part.movby killab66661130 views
34:58
DEFCON 16: Playing with Web Application Firewallsby ChRiStIaAn008390 views
1:48:11
War Games 1983 Full Movie (Brought To You By Kevin Nicholson)by LacoVideos75,323 views
5:37
Log Analysis Helps Tackle Multiple Attack Typesby biztech262 views
50:31
RSA Conference 2011 - How to Recruit Spies on the Internet - Ira Winklerby RSAConference601 views
- Loading more suggestions...
Link to this comment:
All Comments (0)