Subscribe to RSS - Cloud

Cloud

Innovation is the icing, but what about the cake?

Submitted by Ofer Shezaf on 28 January 2013 - 12:20am
Share/Save

In recent weeks I have met several companies focusing on innovating security intelligence. Those encounters brought up an interesting challenge facing such innovations: in most cases innovators have a good idea but find it too expensive to build the required infrastructure. There is no use for an icing for a cake you cannot bake after all.

What are the possible solutions? How productizing innovation actually works? can it be improved?

Security Must Be Clouded

Submitted by Ofer Shezaf on 23 February 2012 - 9:48am
Share/Save

My recent posts have been introspective, reflecting on the state of information security. I feel the urge, especially now a few days before RSA, to venture into the future rather than address the present. Since I am shy of future telling, I will focus on a call for action: what I think should happen in information security in the coming years. Next week on the RSA exhibition floor, we will all see if 2012 will see the beginning of those trends.

Saying that, my first post is about an area that I think will be center stage this year: security in the cloud.

Google Apps Security

Submitted by Ofer Shezaf on 23 February 2012 - 9:30am
Share/Save

As Google Apps become more popular in organzations, the security issue takes central stage. The attached presentation discusses those issues. You can also watch the presentation video here.

Surprisingly, the focus not just on technical controls but also on legal issues. Among the issues discussed are:

Innovative Approach to Anti-Automation

Submitted by Ofer Shezaf on 23 March 2011 - 6:58pm
Share/Save

As WAFs traditional functionality is being absorbed in other solutions such as IPS and Load Balancers, WAFs are looking for future direction. One feature that seems to appear in many WAFs and show promise is anti-automation. Anti-automation is a complex feature not the least since automation itself is multifaceted and ill-defined. The attached presentation provides insight into automation applications from auction sniping to data scraping.

WAFs in the cloud

Submitted by Ofer Shezaf on 15 January 2010 - 9:39pm
Share/Save

In a recent OWASP meeting I gave an overview presentation on how WAFs interact with cloud computing, both utilizing the cloud and protecting cloud based applications. I have discussed the following scenarios:

  1. Enterprise Security Gateway
  2. WAF as a service: For protecting a data center or SaaS
  3. WAF for a cloud deployment: Host Based or Infrastructure Based
  4. WAF stubs

You can download the presentation here.

Tags: 

Art of Defence offers cloud based WAF on Amazon

Submitted by Ofer Shezaf on 11 November 2009 - 11:33pm
Share/Save

It was only a matter of time before someone creates an in the cloud WAF based on Amazon cloud computing services. Art of defence, one of the early WAF in the cloud solution provider. has won the innovation race this time.

RSA WAF Trend: WAF in the cloud

Submitted by Ofer Shezaf on 22 April 2009 - 1:22pm
Share/Save

As usual, RSA is the time of year companies choose for major announcements. The WAF announcements this year focus, following the general computing trend, around cloud computing:

  • Art of Defense, a WAF vendor from Germany, has launched its SaaS WAF solution which target mostly service providers and SaaS vendors.
  • Savvis, a web hosting turning into cloud services company, has added WAF in the cloud offering based on Imperva SecureSphere WAF.
  • SecureWorks, a managed security services provides, announced full management for Imperva SecureSphere and monitoring for other WAFs.

Two challenges facing WAFs in the cloud are bandwidth and complexity.