STATE OF WEB FRAMEWORK SECURITY Remote Os Command Execution - No
4
APPLICATION SECURITY RULE OF THUMB
5
RUNTIME APPLICATION SELF DEFENCE
6
TYPES OF RASP
7
FOCUS OF RESEARCH
8
MONKEY PATCHING
9
LEXICAL ANALYSIS AND TOKEN GENERATION
10
PREVENTING CODE INJECTION VULNERABILITIES
11
REMOTE OS COMMAND INJECTION HOOK
12
REMOTE OS COMMAND INJECTION PROTECT
13
PREVENTING HEADER INJECTION
14
FILE UPLOAD PROTECTION
15
PREVENTING PATH TRAVERSAL
16
THE RASP ADVANTAGES
17
BIGGEST ADVANTAGE
Description:
Explore cutting-edge web application security techniques in this 55-minute conference talk from nullcon Goa 2017. Delve into Runtime Application Self Protection (RASP) and learn how to implement runtime patching algorithms to secure vulnerable applications against code injection and other logical issues. Discover methods for preventing SQL injection, remote command execution, cross-site scripting, and more through dynamic rule generation and context-aware protection. Compare RASP to traditional Web Application Firewalls (WAFs) and understand its advantages in tackling modern AppSec challenges like session hijacking, Layer 7 DDoS, and credential stuffing. Gain insights into the future of runtime protection and its potential to defend against zero-day vulnerabilities affecting framework and language components.
Injecting Security Into Web Apps With Runtime Patching And Context Learning