Silver Tail Systems Blog

Preventing Online Fraud Through Web Session Intelligence

Business Logic Flaws – Still Impossible to Detect Automatically?

There has been a lot of discussion about business logic flaws in blogs and such lately.  Jeremiah Grossman’s article on The Seven Business Logic Flaws that Put Your Website At Risk gets referenced quite often.

Even a recent announcement by SANS talks about how difficult it can be to automatically detect business logic flaws.

But isn’t it true that the traffic on a website could show you these flaws?  In the case that criminals are able to exploit certain issues with business logic, that traffic on websites is going to look different from normal traffic.   So, using technology like the behavior analytics in Silver Tail Systems’ Forensics solution is one way to detect these business logic flaws without understanding them ahead of time.

May 10, 2010 - Posted by | Uncategorized

1 Comment »

  1. [...] Business Logic Flaws – Still Impossible to Detect Automatically … [...]

    Pingback by Hacking Internet Banking Applications | May 12, 2010 | Reply


Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.