Imperva Web Activity Monitoring Solution Closes the Loop Between Security Operations...

* Reuters is not responsible for the content in this press release.

Tue Aug 5, 2008 8:05am EDT

Imperva Web Activity Monitoring Solution Closes the Loop Between Security Operations and Developers

   SecureSphere Provides Continuous Real-Time Visibility into Attack
 Methods and Application Responses to Automate Vulnerability Discovery
REDWOOD SHORES, Calif.--(Business Wire)--
Imperva(R), the leader in application data security, today
announced that its award-winning SecureSphere Web Application Firewall
now supports comprehensive Web Activity Monitoring (WAM) to automate
the discovery and accelerate the remediation of application
vulnerabilities in production systems. In addition to blocking
attacks, SecureSphere now records malicious inputs and application
responses to provide development teams with the information they need
to pinpoint and fix coding flaws.

   These enhancements expand SecureSphere's role as an application
protection and security lifecycle management platform, which includes
the ability to bi-directionally share data with leading vulnerability
scanning tools.

   "Because they monitor web traffic and detect attacks, Web
Application Firewalls should help developers find and fix flaws in
production code. But in reality, the process is too tedious and
costly," said Andrew Jaquith, program manager in Yankee Group's
Enabling Technologies Enterprise group. "In contrast, Imperva's Web
Activity Monitoring solution feeds alerts and reports to both security
and development teams, closing the loop between security operations
and application developers."

   Comprehensive Web Activity Monitoring

   WAM adds another dimension to SecureSphere's application security
lifecycle management capabilities, which enable IT departments to
connect the dots between web application firewall protection, code
reviews, and vulnerability scanning. SecureSphere serves as a hub for
the exchange and correlation of web application security information
and provides a means to identify vulnerabilities in production
applications in real-time. SecureSphere WAM provides:

   --  Alerts on unrecognized attack behaviors to pinpoint potential
        new exploits

   --  Anomalous application activity alerts, to uncover potential
        logical flaws in the code

   --  Real-time alerts that capture full response pages on
        suspicious activity

   --  Sensitive data usage reports that document which parts of an
        application process confidential data such as credit card
        data, social security numbers or other personally identifiable
        information (PII)

   --  Application profile reports that show characteristics of the
        application in use, including pre-defined views of broken
        links, broken inbound referrers, page response time by URLs,
        as well as custom analysis capability

   --  Profile change alerts and reports that identify and track
        application changes to support closed-loop QA and change
        control processes

   "Historically, Web Application Firewalls have focused on reducing
threats to online applications, while code review and vulnerability
scanning technologies have focused on discovering vulnerabilities,"
said Amichai Shulman, CTO of Imperva. "With Web Activity Monitoring,
SecureSphere closes this gap by blocking malicious inputs and
capturing detailed information on how applications respond to live
queries, which allows developers to fix code level security holes."

   Availability

   SecureSphere Web Application Firewall with Web Activity Monitoring
is available immediately from Imperva and its business partners
worldwide

   About Imperva

   Imperva, the leader in application data security, delivers
activity monitoring, real-time protection, and risk management
solutions for business applications and data. Imperva's practical
solutions provide full visibility into sensitive data, database and
application access, enabling granular control and maintenance of
critical data. Over 4500 of the world's leading enterprises and
government organizations in over 35 countries rely on Imperva's
automated, scalable and business-relevant solutions to prevent data
theft, data abuse and ensure data integrity.

   For more information, visit www.imperva.com.

   Imperva and SecureSphere are registered trademarks of Imperva,
Inc. All other brand or product names are trademarks or registered
trademarks of their respective holders.

Imperva
Mark Kraynak, 650-832-6005
mark@imperva.com

Copyright Business Wire 2008
Comments (0)
This discussion is now closed. We welcome comments on our articles for a limited period after their publication.