<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
    <title>Imperva Data Security Blog</title>
    
    <link rel="alternate" type="text/html" href="http://blog.imperva.com/" />
    <id>tag:typepad.com,2003:weblog-1880405</id>
    <updated>2010-03-05T06:15:56-08:00</updated>
    
    <generator uri="http://www.typepad.com/">TypePad</generator>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/Imperviews" /><feedburner:info uri="imperviews" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>Imperviews</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><entry>
        <title>Adding Reputation to Your Web Application Security Strategy - Podcast</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Imperviews/~3/QBLT4epHC3E/adding-reputation-to-you-web-application-security-strategy-podcast.html" />
        <link rel="replies" type="text/html" href="http://blog.imperva.com/2010/03/adding-reputation-to-you-web-application-security-strategy-podcast.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a01156f8c7ad8970c01310f67f857970c</id>
        <published>2010-03-05T06:15:56-08:00</published>
        <updated>2010-03-05T06:15:10-08:00</updated>
        <summary>On this episode of the Imperva Security Podcast Eldad Chai -- Imperva Web Application Firewall Product Manager, is interviewed. Eldad talks about adding reputation to an application security strategy, anti-automation, and adaptive response. He goes into detail on Imperva's ThreatRadar solution- what it is, how it's used, and what customers can expect to gain from it. He covers specific threat examples such as automated attacks and business logic attacks and how they can be addressed beyond blocking and alerting with capabilities such as CAPTCHA, challenge-response, redirection and more. Related information Next Generation Web Application Firewalls NG-WAF Whitepaper NG-WAF Podcast Industrialization...</summary>
        <author>
            <name>Brian Contos</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Brian Contos" />
        
        
<content type="xhtml" xml:lang="en-us" xml:base="http://blog.imperva.com/"><div xmlns="http://www.w3.org/1999/xhtml"><p /><p>On this episode of the <a href="http://www.imperva.com/resources/podcasts.asp?t=ThreatRadar&amp;d=">Imperva Security Podcast</a> Eldad Chai -- Imperva Web Application Firewall Product Manager, is interviewed.</p><p>Eldad talks about adding reputation to an application security strategy, anti-automation, and adaptive response.</p><p>He goes into detail on <a href="http://www.imperva.com/products/threatradar.html">Imperva's ThreatRadar solution</a>- what it is, how it's used, and what customers can expect to gain from it. He covers specific threat examples such as automated attacks and business logic attacks and how they can be addressed beyond blocking and alerting with capabilities such as CAPTCHA, challenge-response, redirection and more.</p><p /><p>Related information</p><p>Next Generation Web Application Firewalls</p><p><span style="font-family: Arial, Verdana; font-size: 12px; color: #444444; " /></p><ul>
<li><a href="http://blog.imperva.com/2010/03/introducing-the-next-generation-of-web-application-firewalls.html" style="color: #3864c5; font-size: 12px; font-family: Arial, Verdana; ">NG-WAF Whitepaper</a></li>
<li><a href="http://www.imperva.com/resources/podcasts.asp?t=NG-WAF&amp;d=" style="color: #3864c5; font-size: 12px; font-family: Arial, Verdana; text-decoration: underline; ">NG-WAF Podcast</a></li>
</ul>
<p><span style="color: #000000; font-family: arial, helvetica, clean, sans-serif; line-height: 16px; font-size: 13px; ">Industrialization of Hacking</span></p><ul>
<li><a href="http://blog.imperva.com/2010/03/hackings-industrial-revolution-whitepaper.html" style="color: #3864c5; font-size: 12px; font-family: Arial, Verdana; text-decoration: underline; ">Industrialization of Hacking Whitepaper</a></li>
</ul>
<p /><p style="text-align: center;"><a href="http://imperva.typepad.com/.a/6a01156f8c7ad8970c0120a9011d3e970b-pi" style="display: inline;"><img alt="THE-FONZ_s1-274" class="asset asset-image at-xid-6a01156f8c7ad8970c0120a9011d3e970b " src="http://imperva.typepad.com/.a/6a01156f8c7ad8970c0120a9011d3e970b-320wi" /></a> </p><p /><p style="text-align: center;"> </p><p /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/Imperviews/~4/QBLT4epHC3E" height="1" width="1" /></div></content>


    <feedburner:origLink>http://blog.imperva.com/2010/03/adding-reputation-to-you-web-application-security-strategy-podcast.html</feedburner:origLink></entry>
    <entry>
        <title>Tell Me Your IP and I’ll Tell You Who You Are</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Imperviews/~3/PG3GiXbbB-o/tell-me-your-ip-and-ill-tell-you-who-you-are.html" />
        <link rel="replies" type="text/html" href="http://blog.imperva.com/2010/03/tell-me-your-ip-and-ill-tell-you-who-you-are.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a01156f8c7ad8970c0120a8edbf4b970b</id>
        <published>2010-03-04T05:00:00-08:00</published>
        <updated>2010-03-04T05:00:00-08:00</updated>
        <summary>RSA San Francisco 2010 On Thursday, March 04 08:00 AM Tall Beery (Imperva Web Research Team Leader) and I will be presenting the topic: Tell Me Your IP and I’ll Tell You Who You Are. The RSA ID is NMS-301 and it will be in Orange Room #306. Abstract IP addresses are considered an unreliable method for attack detection. The session demonstrates how information derived from IP addresses can be used to improve attack detection capabilities. The presentation discusses attributes such as Geo Location, Anonymous Proxy lists etc. The presentation is supported by corroborative evidence derived from actual log data...</summary>
        <author>
            <name>Brian Contos</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Brian Contos" />
        
        
<content type="xhtml" xml:lang="en-us" xml:base="http://blog.imperva.com/"><div xmlns="http://www.w3.org/1999/xhtml"><p style="margin-top: 11px; margin-right: 0px; margin-bottom: 11px; margin-left: 0px; "><strong><a href="http://www.rsaconference.com/index.htm" target="_blank">RSA San Francisco 2010</a></strong></p><p style="margin-top: 11px; margin-right: 0px; margin-bottom: 11px; margin-left: 0px; ">On Thursday, March 04 08:00 AM Tall Beery (Imperva Web Research Team Leader) and I will be presenting the topic:  Tell Me Your IP and I’ll Tell You Who You Are.  The RSA ID is NMS-301 and it will be in Orange Room #306.</p><p style="margin-top: 11px; margin-right: 0px; margin-bottom: 11px; margin-left: 0px; "><strong>Abstract </strong></p><p style="text-align: left;margin-top: 11px; margin-right: 0px; margin-bottom: 11px; margin-left: 0px; ">IP addresses are considered an unreliable method for attack detection. The session demonstrates how information derived from IP addresses can be used to improve attack detection capabilities. The presentation discusses attributes such as Geo Location, Anonymous Proxy lists etc. The presentation is supported by corroborative evidence derived from actual log data and demonstrates some analysis tools.</p><p style="margin-top: 11px; margin-right: 0px; margin-bottom: 11px; margin-left: 0px; " /><p style="margin-top: 11px; margin-right: 0px; margin-bottom: 11px; margin-left: 0px; " /><p style="text-align: center;"><a href="http://imperva.typepad.com/.a/6a01156f8c7ad8970c01310f548900970c-pi" style="display: inline;"><img alt="Prevent-identity-theft" class="asset asset-image at-xid-6a01156f8c7ad8970c01310f548900970c " src="http://imperva.typepad.com/.a/6a01156f8c7ad8970c01310f548900970c-320wi" /></a> </p> <font color="#444444"><span style="line-height: 20px; font-size:  medium;"><span style="color: #000000; font-family: Arial,Verdana;  line-height: 16px; font-size: 13px;">Stop by our booth at RSA</span></span></font><br /><p /><p /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/Imperviews/~4/PG3GiXbbB-o" height="1" width="1" /></div></content>


    <feedburner:origLink>http://blog.imperva.com/2010/03/tell-me-your-ip-and-ill-tell-you-who-you-are.html</feedburner:origLink></entry>
    <entry>
        <title>Staring at the Beast: Six-Months of Attack Vector Research </title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Imperviews/~3/ZX1gu_u4xTU/staring-at-the-beast-sixmonths-of-attack-vector-research-.html" />
        <link rel="replies" type="text/html" href="http://blog.imperva.com/2010/03/staring-at-the-beast-sixmonths-of-attack-vector-research-.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a01156f8c7ad8970c01310f548432970c</id>
        <published>2010-03-03T06:00:00-08:00</published>
        <updated>2010-03-03T06:00:00-08:00</updated>
        <summary>RSA San Francisco 2010 On Wednesday, March 03 08:00 AM Tall Beery (Imperva Web Research Team Leader) and I will be presenting the topic: Staring at the Beast: Six-Months of Attack Vector Research. The RSA ID is SIP-201 and it will be in Orange Room #307. Abstract Security officers and vendors alike must look beyond traditional vulnerability information and become privy to the true activities of attackers. The intelligence gathered through such data collection efforts provides insight into the actual focus of hackers, current attack trends, behavioral patterns of attack, and attack tools. This session will examine data to enable...</summary>
        <author>
            <name>Brian Contos</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Brian Contos" />
        
        
<content type="xhtml" xml:lang="en-us" xml:base="http://blog.imperva.com/"><div xmlns="http://www.w3.org/1999/xhtml"><p><strong><span style="font-weight: normal; "><strong><a href="http://www.rsaconference.com/index.htm" style="color: blue !important; text-decoration: underline !important; cursor: text !important; " target="_blank">RSA San Francisco 2010</a></strong></span><br /></strong></p><p>On Wednesday, March 03 08:00 AM Tall Beery (Imperva Web Research Team Leader) and I will be presenting the topic:  Staring at the Beast: Six-Months of Attack Vector Research.  The RSA ID is SIP-201 and it will be in Orange Room #307.</p><p><strong>Abstract </strong></p><p>Security officers and vendors alike must look beyond traditional vulnerability information and become privy to the true activities of attackers. The intelligence gathered through such data collection efforts provides insight into the actual focus of hackers, current attack trends, behavioral patterns of attack, and attack tools. This session will examine data to enable us to create more effective security policies and tools in a timely manner.</p><p /><p style="text-align: center;"><a href="http://imperva.typepad.com/.a/6a01156f8c7ad8970c0120a8edb793970b-pi" style="display: inline;"><img alt="Beast" class="asset asset-image at-xid-6a01156f8c7ad8970c0120a8edb793970b " src="http://imperva.typepad.com/.a/6a01156f8c7ad8970c0120a8edb793970b-320wi" /></a> </p><p style="text-align: left;"> <span style="font-family: Arial, Verdana; ">Stop by our booth at RSA</span></p><p /><p /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/Imperviews/~4/ZX1gu_u4xTU" height="1" width="1" /></div></content>


    <feedburner:origLink>http://blog.imperva.com/2010/03/staring-at-the-beast-sixmonths-of-attack-vector-research-.html</feedburner:origLink></entry>
    <entry>
        <title>Next Generation Web Application Firewall Podcast</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Imperviews/~3/s97Z8mpI8R0/next-generation-web-application-firewall-podcast.html" />
        <link rel="replies" type="text/html" href="http://blog.imperva.com/2010/03/next-generation-web-application-firewall-podcast.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a01156f8c7ad8970c01310f52f457970c</id>
        <published>2010-03-02T07:00:22-08:00</published>
        <updated>2010-03-02T07:01:32-08:00</updated>
        <summary>In addition to the Next Generation Web Application Firewall (NG-WAF) Whitepaper Imperva has released a podcast with CTO Amichai Shulman on NG-WAF. Amichai discusses the Industrialization of Hacking (Whitepaper on that topic found here) and how that's creating a need for WAF solutions to evolve so they can address automated attacks, business logic attacks, and the existing and growing list of technical attacks such as SQL Injection, XSS, etc. He also discusses mechanism for combating automated attacks and business logic attacks, deployments within MSSP and Cloud-based environments, and other components of Imperva's NG-WAF vision. Downloads NG-WAF Whitepaper NG-WAF Podcast Industrialization...</summary>
        <author>
            <name>Brian Contos</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Brian Contos" />
        
        
<content type="xhtml" xml:lang="en-us" xml:base="http://blog.imperva.com/"><div xmlns="http://www.w3.org/1999/xhtml"><p>In addition to the Next Generation Web Application Firewall (NG-WAF) <a href="http://blog.imperva.com/2010/03/introducing-the-next-generation-of-web-application-firewalls.html">Whitepaper </a>Imperva has released a <a href="http://www.imperva.com/resources/podcasts.asp?t=NG-WAF&amp;d=">podcast with CTO Amichai Shulman</a> on NG-WAF.</p><p>Amichai discusses the <a href="http://blog.imperva.com/2010/03/hackings-industrial-revolution-whitepaper.html">I</a><a href="http://blog.imperva.com/2010/03/hackings-industrial-revolution-whitepaper.html" /><a>ndustrialization of Hacking (Whitepaper on that topic found here)</a> and how that's creating a need for WAF solutions to evolve so they can address automated attacks, business logic attacks, and the existing and growing list of technical attacks such as SQL Injection, XSS, etc. He also discusses mechanism for combating automated attacks and business logic attacks, deployments within MSSP and Cloud-based environments, and other components of Imperva's NG-WAF vision. </p><p><strong>Downloads</strong></p><p /><ul>
<li><a href="http://blog.imperva.com/2010/03/introducing-the-next-generation-of-web-application-firewalls.html">NG-WAF Whitepaper</a></li>
<li><a href="http://www.imperva.com/resources/podcasts.asp?t=NG-WAF&amp;d=">NG-WAF Podcast</a></li>
<li><a href="http://blog.imperva.com/2010/03/hackings-industrial-revolution-whitepaper.html">Industrialization of Hacking Whitepaper</a></li>
</ul>
<p /><p /><p style="text-align: center;"><a href="http://imperva.typepad.com/.a/6a01156f8c7ad8970c01310f52f397970c-pi" style="display: inline;"><img alt="Podcasting_symbol" class="asset asset-image at-xid-6a01156f8c7ad8970c01310f52f397970c " src="http://imperva.typepad.com/.a/6a01156f8c7ad8970c01310f52f397970c-120wi" /></a> <a href="http://imperva.typepad.com/.a/6a01156f8c7ad8970c01310f52f3c7970c-pi" style="display: inline;"><img alt="Whitepaper" class="asset asset-image at-xid-6a01156f8c7ad8970c01310f52f3c7970c " src="http://imperva.typepad.com/.a/6a01156f8c7ad8970c01310f52f3c7970c-120wi" /></a> </p><p style="text-align: left;"> Stop by our booth at RSA San Francisco this week (March 1st 2010) to learn more.</p> <p /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/Imperviews/~4/s97Z8mpI8R0" height="1" width="1" /></div></content>


    <feedburner:origLink>http://blog.imperva.com/2010/03/next-generation-web-application-firewall-podcast.html</feedburner:origLink></entry>
    <entry>
        <title>Introducing the Next Generation of Web Application Firewalls</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Imperviews/~3/J0WMiGR20iA/introducing-the-next-generation-of-web-application-firewalls.html" />
        <link rel="replies" type="text/html" href="http://blog.imperva.com/2010/03/introducing-the-next-generation-of-web-application-firewalls.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a01156f8c7ad8970c01310f4d9b24970c</id>
        <published>2010-03-02T06:00:00-08:00</published>
        <updated>2010-03-02T07:04:18-08:00</updated>
        <summary>Download Whitepaper This paper describes Imperva's vision for the next generation of WAFs. It details Web application security problems and solutions today, and gives perspectives on the future. While this paper is not product specific, areas where Imperva SecureSphere currently provides NG-WAF capabilities such as anti-automation, and adaptive threat response are highlighted. Download Whitepaper Stop by our booth at RSA San Francisco this week (March 1st 2010) to learn more</summary>
        <author>
            <name>Brian Contos</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Brian Contos" />
        
        
<content type="xhtml" xml:lang="en-us" xml:base="http://blog.imperva.com/"><div xmlns="http://www.w3.org/1999/xhtml"><span color="#444444" size="3;" style="font-family: Arial, Verdana"><span style="font-size: 11px; line-height: 13px;"><p><span color="#444444" size="3;" style="font-family: Arial, Verdana"><span style="font-size: 11px; line-height: 13px;"><span style="font-family: arial, helvetica, clean, sans-serif; "><a href="https://www.imperva.com/lg/lgw.asp?pid=382" style="color: blue !important; text-decoration: underline !important; cursor: text !important; ">Download Whitepaper</a></span><br /></span></span></p></span>This paper describes Imperva's vision for the next generation of WAFs. It details Web application security problems and solutions today, and gives perspectives on the future. While this paper is not product specific, areas where Imperva SecureSphere currently provides NG-WAF capabilities such as anti-automation, and adaptive threat response are highlighted.</span><p><span style="line-height: 13px; font-size: 11px; color: #444444; "><a href="https://www.imperva.com/lg/lgw.asp?pid=382">Download Whitepaper</a></span><br /></p><p><p><font color="#444444"><span style="line-height: 20px; font-size: medium; "><span style="color: #000000; font-family: Arial, Verdana; line-height: 16px; font-size: 13px; ">Stop by our booth at RSA San Francisco this week (March 1st 2010) to learn more</span><br /></span></font></p></p><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/Imperviews/~4/J0WMiGR20iA" height="1" width="1" /></div></content>


    <feedburner:origLink>http://blog.imperva.com/2010/03/introducing-the-next-generation-of-web-application-firewalls.html</feedburner:origLink></entry>
    <entry>
        <title>Hacking's Industrial Revolution - Whitepaper</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Imperviews/~3/gCKn44gNsrk/hackings-industrial-revolution-whitepaper.html" />
        <link rel="replies" type="text/html" href="http://blog.imperva.com/2010/03/hackings-industrial-revolution-whitepaper.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a01156f8c7ad8970c0120a8e6b94f970b</id>
        <published>2010-03-01T08:47:04-08:00</published>
        <updated>2010-03-02T07:03:17-08:00</updated>
        <summary>Download the Whitepaper Today, hacking is a $1T industry — up from a few billion just three years ago. In 2007, professional hacking represented a multibillion-dollar industry. At present, this same industry posts — in stolen data, IP and financial gain — more than one trillion in value. What explains this rapid growth? Industrialization. Just as the Industrial Revolution advanced methods and accelerated assembly from single to mass production in the 19th century, today's cyber crime industry has similarly transformed and automated itself to achieve scalability and increase profits. The industrialization of hacking coincides with a critical shift in what's...</summary>
        <author>
            <name>Brian Contos</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Brian Contos" />
        
        
<content type="xhtml" xml:lang="en-us" xml:base="http://blog.imperva.com/"><div xmlns="http://www.w3.org/1999/xhtml"><p><a href="https://www.imperva.com/ld/industrialization.asp?" style="color: blue !important; text-decoration: underline !important; cursor: text !important; ">Download the Whitepaper</a></p><p>Today, hacking is a $1T industry — up from a few billion just three years ago. In 2007, professional hacking represented a multibillion-dollar industry. At present, this same industry posts — in stolen data, IP and financial gain — more than one trillion in value. What explains this rapid growth? Industrialization. Just as the Industrial Revolution advanced methods and accelerated assembly from single to mass production in the 19th century, today's cyber crime industry has similarly transformed and automated itself to achieve scalability and increase profits.</p><p>The industrialization of hacking coincides with a critical shift in what's considered today's prized commodity: data. This paper explores:</p><p /><ul>
<li>The structure of industrialized hacking operations.</li>
<li>Current technologies used by hackers.</li>
<li>The most common attack methods and mitigation strategies.</li>
</ul>
<p><a href="https://www.imperva.com/ld/industrialization.asp?">Download the Whitepaper</a></p><p>Stop by our booth at RSA San Francisco this week (March 1st 2010) to 
learn more</p><p /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/Imperviews/~4/gCKn44gNsrk" height="1" width="1" /></div></content>


    <feedburner:origLink>http://blog.imperva.com/2010/03/hackings-industrial-revolution-whitepaper.html</feedburner:origLink></entry>
    <entry>
        <title>Asia IT Security Governance?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Imperviews/~3/Yao5Qy9k4QY/asia-it-security-governance.html" />
        <link rel="replies" type="text/html" href="http://blog.imperva.com/2010/02/asia-it-security-governance.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a01156f8c7ad8970c0120a8d57175970b</id>
        <published>2010-02-26T07:57:24-08:00</published>
        <updated>2010-02-26T07:57:24-08:00</updated>
        <summary>On a recent visit to Asia I had the opportunity to sit with many of our regional partners to discuss IT security regulations specific to web applications and databases. There was no surprise that PCI was at the top of the list followed by SOX for some international companies, primarily American, and then a short list of ISO and country specific regulations. Each partner I spoke with talked about a different local requirement usually still being defined or just about to become officially enforced. In each case I received the same question, "Will SecureSphere support the legislation?" The short answer...</summary>
        <author>
            <name>Terry Ray</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Terry Ray" />
        
        
<content type="xhtml" xml:lang="en-us" xml:base="http://blog.imperva.com/"><div xmlns="http://www.w3.org/1999/xhtml"><p>On a recent visit to Asia I had the opportunity to sit with many of our regional partners to discuss IT security regulations specific to web applications and databases.  There was no surprise that PCI was at the top of the list followed by SOX for some international companies, primarily American, and then a short list of ISO and country specific regulations.  Each partner I spoke with talked about a different local requirement usually still being defined or just about to become officially enforced.  In each case I received the same question, "Will SecureSphere support the legislation?"</p><p /><p>The short answer I gave them all was the same.  If the legislation requires web application security and/or monitoring, and/or defines requirements for securing and/or monitoring database and data access, the answer is 'yes'.  The reality that I have experienced so far has been that while there are various data security regulations, they all typically require the same fundamental output.  Data privacy regulations, regardless of the industry or country, at a minimum, require complying organizations to restrict and/or monitor (audit) who has access to, and to what degree they have access to, the data that must be regulated.</p><p /><p><a href="http://imperva.typepad.com/.a/6a01156f8c7ad8970c0120a8d56b34970b-pi" style="display: inline;"><img alt="Picture1" border="0" class="asset asset-image at-xid-6a01156f8c7ad8970c0120a8d56b34970b " src="http://imperva.typepad.com/.a/6a01156f8c7ad8970c0120a8d56b34970b-pi" style="width: 200px;" title="Picture1" /></a> <br />  Jimmy<span class="Apple-tab-span" style="white-space: pre;">			</span>Private Data</p><p /><p>This, of course, is quite easy for SecureSphere since it has the ability to secure and monitor (audit) any aspect of database and application activity.  All that is required of the administrator is to know what elements of data access should be monitored to comply with the regulation and to configure SecureSphere to secure and/or monitor that activity.  Of course, SecureSphere is pre-configured with the most common regulations, but as I say, it can be easily configured to meet even the most obscure legislation.</p><p /><p /><p>The most common current Asia regulations I identified are below:</p><p style="text-align: left;">PCI<img alt="" src="http://blogs.gartner.com/thomas_otter/files/2009/01/image3.png" style="border: 1px solid black; width: 100px; float: right; margin: 0px 0px 5px 5px;" /></p><p>SOX</p><p>J-SOX</p><p>K-SOX</p><p>ISO27001</p><p /><p /><p>As I stated above, there are some regulations in development for various countries, but they have yet to be ratified.  Additionally, some countries have existing regulations, but have yet to include IT data to the requirements and are still very much focused on the 'paper' books rather than electronic data.  Having worked extensively in various locations around the globe, it's always interesting to see the considerable differences from region to region and country to country.</p><p /><p /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/Imperviews/~4/Yao5Qy9k4QY" height="1" width="1" /></div></content>


    <feedburner:origLink>http://blog.imperva.com/2010/02/asia-it-security-governance.html</feedburner:origLink></entry>
    <entry>
        <title>When Idle Hands Find Holes in Security – Posting Porn on Moscow Billboard</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Imperviews/~3/UgvlCxctp00/when-idle-hands-find-holes-in-security-posting-porn-on-moscow-billboard.html" />
        <link rel="replies" type="text/html" href="http://blog.imperva.com/2010/02/when-idle-hands-find-holes-in-security-posting-porn-on-moscow-billboard.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a01156f8c7ad8970c0120a8b9836b970b</id>
        <published>2010-02-22T08:09:34-08:00</published>
        <updated>2010-02-22T16:13:13-08:00</updated>
        <summary>Ellen Messmer, at Network World, published a short, entertaining article about an unemployed Russian system administrator who hacked into a giant public billboard on a Moscow street, replacing the advertisement with a pornographic movie. …Interior Ministry's high-tech crime unit says the suspected billboard hacker is a 41-year-old unemployed man who police believe used the IP address of an organization based in Chechnya to breach a Moscow server… Needless to say, this stopped traffic both on the street and on the sidewalks stuffing them with gawkers and cell phone videophiles. Considering the ‘rubber-neck’ traffic created by someone changing a tire where...</summary>
        <author>
            <name>Terry Ray</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Terry Ray" />
        
        
<content type="xhtml" xml:lang="en-us" xml:base="http://blog.imperva.com/"><div xmlns="http://www.w3.org/1999/xhtml"><p class="MsoNormal" style="LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-outline-level: 1"><span style="font-family: 'Times New Roman', serif;"><strong><p class="MsoNormal" style="margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; "><span style="font-weight: normal;">Ellen Messmer, at Network World, published a short, entertaining <a href="http://www.networkworld.com/news/2010/021810-moscow-billboard-hacker.html" target="_blank">article</a> about an unemployed Russian system administrator who hacked into a giant public billboard on a Moscow street, replacing the advertisement with a pornographic movie.</span></p><p class="MsoNormal" style="margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; "><blockquote><span style="font-weight: normal;"><em>…Interior Ministry's high-tech crime unit says the suspected billboard hacker is a 41-year-old unemployed man who police believe used the IP address of an organization based in Chechnya to breach a Moscow server…</em></span></blockquote></p><p class="MsoNormal" style="margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; "><span style="font-weight: normal; "><strong><p class="MsoNormal" style="margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; display: inline !important; "><span style="font-weight: normal;">Needless to say, this stopped traffic both on the street and on the sidewalks stuffing them with gawkers and cell phone videophiles.  Considering the ‘rubber-neck’ traffic created by someone changing a tire where I live, I can only imagine the backup caused this incident.  Taking the security of the billboard server and public safety issues of stopping traffic aside, this article underscored for me the idle hands environment we find ourselves into today with unemployment rates steadily rising. </span></p></strong></span></p><blockquote><p class="MsoNormal" style="margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; "><span style="font-weight: normal; "><strong><p class="MsoNormal" style="margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; display: inline !important; "><span style="font-weight: normal;"><em>Statements attributed to police sources says the hacker was breaking into computers out of curiosity and had admitted to the stunt, which he allegedly said was an effort to entertain</em></span></p></strong></span></p></blockquote><p class="MsoNormal" style="margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; "><span style="font-weight: normal; "><strong><p class="MsoNormal" style="margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; display: inline !important; "><span style="font-weight: normal;">At least in this case, the alleged intent was curiosity and entertainment rather than data theft or destruction. I also consider the distribution method in this case and how the billboard could have been made to show healthcare information, credit card numbers, private financial data, etc…</span></p></strong></span></p><p class="MsoNormal" style="text-align: center;margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; "><span style="font-weight: normal; "><strong><p class="MsoNormal" style="margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; display: inline !important; "><span style="font-weight: normal;"><a href="http://imperva.typepad.com/.a/6a01156f8c7ad8970c0120a8c57a67970b-pi" style="display: inline;"><img alt="Panno_billboard_monster_397x224" class="asset asset-image at-xid-6a01156f8c7ad8970c0120a8c57a67970b " src="http://imperva.typepad.com/.a/6a01156f8c7ad8970c0120a8c57a67970b-320wi" /></a> </span></p></strong></span></p></strong></span></p><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/Imperviews/~4/UgvlCxctp00" height="1" width="1" /></div></content>


    <feedburner:origLink>http://blog.imperva.com/2010/02/when-idle-hands-find-holes-in-security-posting-porn-on-moscow-billboard.html</feedburner:origLink></entry>
    <entry>
        <title>OWASP Talks about the Attack on RockYou and the Imperva Password Study</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Imperviews/~3/pvT1JmX7Tys/owasp-talks-about-the-attack-on-rockyou-and-the-imperva-password-study.html" />
        <link rel="replies" type="text/html" href="http://blog.imperva.com/2010/02/owasp-talks-about-the-attack-on-rockyou-and-the-imperva-password-study.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a01156f8c7ad8970c012877909048970c</id>
        <published>2010-02-11T10:09:58-08:00</published>
        <updated>2010-02-11T10:09:58-08:00</updated>
        <summary>OWASP just released episode number 59. They discuss a number of topics, but during the last third of the podcast they focus on the 32 million clear text passwords that were stolen from RockYou and later posted on the Internet. They also explore Imperva's research paper that explores the strength of those passwords. The report identifies the most commonly used passwords: 1. 123456 2. 12345 3. 123456789 4. Password 5. iloveyou 6. princess 7. rockyou 8. 1234567 9. 12345678 10. abc123 "Everyone needs to understand what the combination of poor passwords means in today's world of automated cyber attacks: with...</summary>
        <author>
            <name>Brian Contos</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Brian Contos" />
        
        
<content type="xhtml" xml:lang="en-us" xml:base="http://blog.imperva.com/"><div xmlns="http://www.w3.org/1999/xhtml"><p>OWASP just released <a href="http://www.owasp.org/download/jmanico/owasp_podcast_59.mp3" target="_blank">episode number 59</a>.  They discuss a number of topics, but during the last third of the podcast they focus on the 32 million clear text passwords that were stolen from RockYou and later posted on the Internet. They also explore<a href="http://www.imperva.com/news/press/2010/01_21_Imperva_Releases_Detailed_Analysis_of_32_Million_Passwords.html"> Imperva's research paper that explores the strength of those passwords.</a></p><p>The report identifies the most commonly used passwords:<br /></p><blockquote>   1. 123456<br />   2. 12345<br />   3. 123456789<br />   4. Password<br />   5. iloveyou<br />   6. princess<br />   7. rockyou<br />   8. 1234567<br />   9. 12345678<br />  10. abc123<br /></blockquote><blockquote><em>"Everyone needs to understand what the combination of poor passwords means in today's world of automated cyber attacks: with only minimal effort, a hacker can gain access to one new account every second—or 1000 accounts every 17 minutes," explained Imperva's CTO Amichai Shulman. "The data provides a unique glimpse into the way that users select passwords and an opportunity to evaluate the true strength of passwords as a security mechanism. Never before has there been such a high volume of real-world passwords to examine."<br /></em></blockquote><p>Some key findings of the study include:</p><ul>
<li>The shortness and simplicity of passwords means many users select credentials that will make them susceptible to basic forms of cyber attacks known as "brute force attacks."</li>
<li>Nearly 50% of users used names, slang words, dictionary words or trivial passwords (consecutive digits, adjacent keyboard keys, and so on). The most common password is "123456".</li>
<li>Recommendations for users and administrators for choosing strong passwords.</li>
</ul>
<p /><p /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/Imperviews/~4/pvT1JmX7Tys" height="1" width="1" /></div></content>

        

    <feedburner:origLink>http://blog.imperva.com/2010/02/owasp-talks-about-the-attack-on-rockyou-and-the-imperva-password-study.html</feedburner:origLink><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="enclosure" href="http://feedproxy.google.com/~r/Imperviews/~5/3GFYtF8ikDg/owasp_podcast_59.mp3" length="52856319" type="audio/mpeg" /><feedburner:origEnclosureLink>http://www.owasp.org/download/jmanico/owasp_podcast_59.mp3</feedburner:origEnclosureLink></entry>
    <entry>
        <title>Cookie Poisoning Resource</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Imperviews/~3/kh38iTMEVM0/cookie-poisoning-resource.html" />
        <link rel="replies" type="text/html" href="http://blog.imperva.com/2010/02/cookie-poisoning-resource.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a01156f8c7ad8970c012877856bf9970c</id>
        <published>2010-02-10T06:01:00-08:00</published>
        <updated>2010-02-10T06:01:00-08:00</updated>
        <summary>Imperva has launched another resource: Cookie Poisoning. This resource contains information about Cookie Poisoning as well as related White papers, Webcasts, and videos. Cookie Poisoning attacks involve the modification of the contents of a cookie (personal information stored in a Web user's computer) in order to bypass security mechanisms. Using cookie poisoning attacks, attackers can gain unauthorized information about another user and steal their identity. ...or is there?</summary>
        <author>
            <name>Brian Contos</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Brian Contos" />
        
        
<content type="xhtml" xml:lang="en-us" xml:base="http://blog.imperva.com/"><div xmlns="http://www.w3.org/1999/xhtml"><p>Imperva has launched another resource:  <a href="http://www.imperva.com/resources/glossary/cookie_poisoning.html">Cookie Poisoning</a>. This resource contains information about Cookie Poisoning as well as related White papers, Webcasts, and videos.</p><p>Cookie Poisoning attacks involve the modification of the contents of a cookie (personal information stored in a Web user's computer) in order to bypass security mechanisms. Using cookie poisoning attacks, attackers can gain unauthorized information about another user and steal their identity.</p><div style="text-align: center;"><p><a href="http://imperva.typepad.com/.a/6a01156f8c7ad8970c012877856abd970c-pi" style="display: inline;"><img alt="Cookie" class="asset asset-image at-xid-6a01156f8c7ad8970c012877856abd970c " src="http://imperva.typepad.com/.a/6a01156f8c7ad8970c012877856abd970c-320wi" /></a></p><p style="text-align: left;">...or is there?</p> </div><p> </p><p><span style="font-size: 14px;"><br /></span></p><p><br /><span style="font-size: 14px;" /></p><p><br /><span style="font-size: 14px;" /></p><p><span style="font-size: 14px;" /></p><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/Imperviews/~4/kh38iTMEVM0" height="1" width="1" /></div></content>


    <feedburner:origLink>http://blog.imperva.com/2010/02/cookie-poisoning-resource.html</feedburner:origLink></entry>

</feed><!-- ph=1 --><!-- nhm:from_kauri -->
