Subscribe to RSS - Research Analysis

Research Analysis

Will academic security research provide the answer?

Submitted by Ofer Shezaf on 20 November 2011 - 9:41pm
Share/Save

Industry research such as Larry Suto’s is often superficial and at times driven by external motivations. So where should we derive our research data from? While one answer may be to forgo with research data all together, another option that comes to mind is academic research. An academic paper comparing vulnerability discovery techniques that I encountered is a good test case for that...

Suto strikes again, or getting the desired results regardless of data

Submitted by Ofer Shezaf on 17 November 2011 - 11:37pm
Share/Save

Larry Suto, who brought scanners wars 1 and 2 has published a WAF effectiveness research. As usual, Larry’s work is fun to dissect. While Larry’s research is not worse than your average analyst’s work, he does try to base his conclusion on more concrete and pseudo-scientific research making it much more vulnerable to scrutiny.

Why WAFs Fail?

Submitted by Ofer Shezaf on 23 February 2011 - 10:41pm
Share/Save

While securing web applications is a well understood need, and while WAFs have clear advantages over code review and testing such as immediate mitigation and higher automation, the WAF market is still a small market. The attached presentation discusses and offers some explanations to this phenomenon. 

Is any security tool perfect?

Submitted by Ofer Shezaf on 9 February 2010 - 10:48pm
Share/Save

Larry Suto, an application security consultant, publish a sequel to his 2007 best seller research about web application scanners. In the first round Larry managed to ignite quite a controversy and drew a lot of criticism from the loosing vendors. The reason is simple: Larry found out that the scanners do not perform as well as advertised.

Forrester estimates the WAF market to be $220M in 2010

Submitted by Ofer Shezaf on 9 February 2010 - 9:55pm
Share/Save

Chenxi Wang from Forrester has released a new WAF research. According to the publicly released information Forrester sees the market as small but solid at $200M in revenues in 2009 and 10% grows this year. Is this size sufficient for a stand alone product market? time will tell.

WAFs Appearing on Gartner's Radar

Submitted by Ofer Shezaf on 24 May 2009 - 7:49am
Share/Save

One of the repeating themes in my conversations with vendors and experts on the WAF market is the lack of analyst coverage. Such coverage provides an important validation to an emerging market. It also helps to define the market, differentiating it from other market segments. And lastly it makes the corporate buyer's life easier when trying to navigate between all the choices. In short, many feel that the lack of analyst coverage limits the growth potential of the WAF market.

WHID Inclusion Critera, Again

Submitted by Ofer Shezaf on 28 January 2008 - 8:17am
Share/Save

One of the issues haunting WHID since its inception two years ago is inclusion criteria: which incidents get in? WHID goal is not to provide an alternative to Zone-h defaced sites archive or ScanSafe's Threat Alert which tracks malware planted on web sites.

Is XSS the killer vulnerability?

Submitted by Ofer Shezaf on 3 September 2007 - 3:38pm
Share/Save

XSS has dominated the Web Hacking Incidents Database statistics page since its inception. The immediate conclusion it that XSS is the most dangerous of them all. Is that so? or is it just a common research error?

Pages