<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Silver Tail Blog &#187; web application security</title>
	<atom:link href="http://silvertailsystems.wordpress.com/tag/web-application-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://silvertailsystems.wordpress.com</link>
	<description>Fighting against business logic abuse.</description>
	<lastBuildDate>Fri, 18 Dec 2009 12:11:53 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='silvertailsystems.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/577fb613fda4531b5f1cbba10427b2bb?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Silver Tail Blog &#187; web application security</title>
		<link>http://silvertailsystems.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://silvertailsystems.wordpress.com/osd.xml" title="Silver Tail Blog" />
		<item>
		<title>It&#8217;s all about context</title>
		<link>http://silvertailsystems.wordpress.com/2009/02/04/its-all-about-context/</link>
		<comments>http://silvertailsystems.wordpress.com/2009/02/04/its-all-about-context/#comments</comments>
		<pubDate>Thu, 05 Feb 2009 00:38:41 +0000</pubDate>
		<dc:creator>Sherrick Murdoff</dc:creator>
				<category><![CDATA[Detection]]></category>
		<category><![CDATA[business logic abuse]]></category>
		<category><![CDATA[behavior analysis]]></category>
		<category><![CDATA[context]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://silvertailsystems.wordpress.com/?p=215</guid>
		<description><![CDATA[
Lori McVittie of F5 had an interesting post on how the next level of web application security should look at &#8220;context&#8221;.  I completely agree and enjoy seeing more people shine a light on taking web security to the next level.   Context gives you the next level of information to help you make [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=215&subd=silvertailsystems&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><img class="alignleft size-full wp-image-216" title="context" src="http://silvertailsystems.files.wordpress.com/2009/02/context.jpg?w=144&#038;h=61" alt="context" width="144" height="61" /></p>
<p>Lori McVittie of F5 had an <a href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/02/03/web-application-security-where-do-go-from-here.aspx" target="_blank">interesting post</a> on how the next level of web application security should look at &#8220;context&#8221;.  I completely agree and enjoy seeing more people shine a light on taking web security to the next level.   Context gives you the next level of information to help you make more accurate &#8211; and better informed &#8211; decisions about what is happening on your website.</p>
<p>What Lori said is exactly right &#8211; the key is not only understanding the <em>current user&#8217;s session</em> and whether that user is doing something abnormal, or even suspicious, but also understanding that user&#8217;s session in context with <em>all other users&#8217; sessions</em>.  Does the current session look normal or abnormal compared to all other users of the website? This is the exactly the holistic context websites need to look at.</p>
<p>Though I agree with most of Lori&#8217;s post, she is &#8220;almost right&#8221; about today&#8217;s technology as she writes:</p>
<blockquote>
<p style="padding-left:30px;">The problem with technology, and web applications in general, is that you can&#8217;t see the user. Worse, you can&#8217;t even really see the entire context of his interactions with the web application because very few security implementations have the capability to evaluate user behavior (interaction with the application) as a holistic experience. Web application security solutions today simply can&#8217;t tell what&#8217;s normal behavior across the application.</p>
</blockquote>
<p>Believe it or not, there are ways you can <em>see</em> the user. You really can get this type of holistic context today.  It&#8217;s true that it takes some fairly powerful algorithms, but it is possible to get this context without a ton of compute power and in a meaningful way.  That&#8217;s exactly what we&#8217;re working on at <a title="Silver Tail" href="http://www.silvertailsystems.com/index.php/pages/view/solutions" target="_blank">Silver Tail</a> &#8211; bringing websites the holistic context they need to make better decisions about website events.  We even go a step further &#8211; giving you the tools you need to <a title="Silver Tail Mitigation" href="http://www.silvertailsystems.com/index.php/pages/view/fraud-mitigation-engine" target="_blank">take action</a> against the bad events without impacting the legitimate users.  Its working today and its an exciting new technique in the fight against online fraud and, specifically, business logic abuse.</p>
<p>Special thanks to Lori for raising awareness on this issue. I welcome your feedback and input&#8230;</p>
 Tagged: behavior analysis, context, Detection, web application security <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/silvertailsystems.wordpress.com/215/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/silvertailsystems.wordpress.com/215/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/silvertailsystems.wordpress.com/215/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/silvertailsystems.wordpress.com/215/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/silvertailsystems.wordpress.com/215/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/silvertailsystems.wordpress.com/215/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/silvertailsystems.wordpress.com/215/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/silvertailsystems.wordpress.com/215/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/silvertailsystems.wordpress.com/215/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/silvertailsystems.wordpress.com/215/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=215&subd=silvertailsystems&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://silvertailsystems.wordpress.com/2009/02/04/its-all-about-context/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a4f40f1e603ec693ab9ec817a4ada9d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">silvertail</media:title>
		</media:content>

		<media:content url="http://silvertailsystems.files.wordpress.com/2009/02/context.jpg" medium="image">
			<media:title type="html">context</media:title>
		</media:content>
	</item>
	</channel>
</rss>