13
The Smartest Way to Protect Websites and Web Apps from Attacks

The Smartest Way to Protect Websites and Web Apps from Attacks

  • Upload
    owena

  • View
    32

  • Download
    0

Embed Size (px)

DESCRIPTION

The Smartest Way to Protect Websites and Web Apps from Attacks. Inconvenient Statistics. 70%. Database. of ALL threats are at the Web application layer. Port 80. App Server. Gartner. Port 80. 73%. Network Perimeter. - PowerPoint PPT Presentation

Citation preview

Page 1: The  Smartest Way to Protect  Websites and Web Apps from Attacks

The Smartest Way to Protect Websites and Web Apps from Attacks

Page 2: The  Smartest Way to Protect  Websites and Web Apps from Attacks

Port 80

Inconvenient Statistics

Port 80

Network Perimeter

App Server

Database of ALL threats are at the Web application layer.Gartner

70%

of organizations have been hacked in the past two years through insecure Web apps.

73%

Ponemon Institute

Page 3: The  Smartest Way to Protect  Websites and Web Apps from Attacks

Hacker ThreatsTargeted Scans

Advanced Persistent Threat (APT)

Targets a specific site for any vulnerability.

Script loaded onto a bot network to carry out attack.

JAN JUNE DEC

Sophisticated, targeted attack (APT). Low and slow to avoid detection.

Library AttacksScript run against multiple sites seeking a specific vulnerability.

IP ScanScript KiddieGeneric scripts and tools against one site.

Scripts & Tool Exploits Targeted Scan

Botnet Human Hacker

Page 4: The  Smartest Way to Protect  Websites and Web Apps from Attacks

The Cost of an Attack

Theft

RevenueReputation

Sony Stolen Records | 100M

Sony Direct Costs | $171M• 28 day network closure• Lost customers• Security improvements

Sony Lawsuits| $1-2B

Ponemon Institute| Average breach costs $214 per record stolen

Page 5: The  Smartest Way to Protect  Websites and Web Apps from Attacks

Deception Points - detect threats without false positives.

Track individual devices

Understand attacker’s capabilities and intent

Adaptive responses, including block, warn and deceive.

The Mykonos Advantage

Deception-based Security

Detect Track Profile Respond

Page 6: The  Smartest Way to Protect  Websites and Web Apps from Attacks

Detection by Deception

App Server

Client

Server Configuration

Network Perimeter

DatabaseFirewall

Query String Parameters

Tar Traps

Hidden Input Fields

Page 7: The  Smartest Way to Protect  Websites and Web Apps from Attacks

Track Attackers Beyond the IP

Track Software and Script AttacksFingerprinting

HTTP communications.

Track Browser AttacksPersistent Token

Capacity to persist in all browsers including various privacy control features.

Track IP Address

Page 8: The  Smartest Way to Protect  Websites and Web Apps from Attacks

Attacker threat level

Smart Profile of Attacker

Incident history

Every attacker assigned a name

Page 9: The  Smartest Way to Protect  Websites and Web Apps from Attacks

Mykonos ResponsesHuman Hacker

Botnet Targeted Scan

IP Scan Scripts &Tools Exploits

Warn attacker Block user Force CAPTCHA Slow connection Simulate broken application Force log-out

Respond and Deceive

All responses are available for any type of threat. Highlighted responses are most appropriate for each type of threat.

Page 10: The  Smartest Way to Protect  Websites and Web Apps from Attacks

Security Administration

• SMTP alerting• Reporting (Pdf, HTML)• CLI for exporting data into SIEM tool

• Web-based console• Real-time• On-demand threat information

Page 11: The  Smartest Way to Protect  Websites and Web Apps from Attacks

Unified Protection Across Platforms

App Server Database

Internal

Virtualized

Cloud

Conn

ectiv

e Ti

ssue

Page 12: The  Smartest Way to Protect  Websites and Web Apps from Attacks

Case Study & Customers“Within 20 minutes, ….we were looking at the activity taking place on our web applications.”

“10% of our traffic was…malicious.”

Keir Asher Senior Technical AnalystBrown Printing

Page 13: The  Smartest Way to Protect  Websites and Web Apps from Attacks

2010 Cool VendorApplication Security

“The smartest buy of the year for any organization with an online presence.” 1st Place Winner, Security Innovators Throwdown 2010

SINET 16 Security Innovator 2011

1st Place Information SecurityWall Street Journal Technology Innovation Awards 2011