Mention Web application security to an IT administrator at most companies
and you may elicit a grimace. The growing tangle of dynamic Web 2.0
applications make it almost impossible for traditional bug scanners to catch
most Web vulnerabilities.
Recognizing this architectural challenge, SPI Dynamics created
Phoenix, a new Web application security architecture to analyze Web 2.0
applications and find previously undetectable Web flaws.
Erik Peterson, vice president of product management for SPI, said modern Web
applications built from technologies such as AJAX, RSS and Flash combine
client and server side processing and are therefore more complex.
SPI argues that current application scanners, including its current
WebInspect portfolio, are built on dated architectures developed in 2000.
Not surprisingly, they haven’t kept up with the evolution of Web
applications, so they don’t find newer security vulnerabilities.
This leads to high false negative rates, meaning the flaws aren’t being
detected by the software and the IT auditor has no idea something is wrong
until it’s too late.
“AJAX exploded and changed how Web applications are built and deployed,”
Peterson said, explaining the need for Phoenix. Hackers evolve from
hobbyists to professionals. It’s a billion-dollar industry for these folks
to be taking advantage of opportunities out there.
“The complete re-architecture of our product was necessary to keep at the
forefront of where the Web was going. We feel like it’s going to pay off
for us in spades.”
Phoenix will serve as the foundation of SPI’s security software going
forward, but the architecture has been employed first in WebInspect 7, the
company’s Web scanner.
WebInspect 7 assesses a Web service by discovering all XML input parameters
and performing parameter manipulation on each XML field looking for
vulnerabilities within the service.
The software exposes hidden application logic, revealing security flaws that
could not be found through automated security testing.
Peterson said WebInspect 7 is distinct from other Web scanners because it
includes simultaneous crawl and audit (SCA) and concurrent application
scanning.
These tools make the scanner faster and more accurate and performing these
tasks at the same time may cut flaw scan times in half or more. WebInspect 7
can also perform multiple concurrent scans to cover more ground on the Web
and in the computer network.
Moreover, the software boasts new automated checkpoints to eliminate
authentication issues for applications using two-factor authentication or
CAPTCHA (completely automated public Turing test to tell computers and
humans apart). WebInspect 7 can authenticate with secure Web applications
and determine when re-authentication is required.
WebInspect 7, which SPI will begin selling Feb. 14, supports IPv6
(define), a major requirement for future computing.
This article was first published on InternetNews.com. To read the full article, click here.
Ethics and Artificial Intelligence: Driving Greater Equality
FEATURE | By James Maguire,
December 16, 2020
AI vs. Machine Learning vs. Deep Learning
FEATURE | By Cynthia Harvey,
December 11, 2020
Huawei’s AI Update: Things Are Moving Faster Than We Think
FEATURE | By Rob Enderle,
December 04, 2020
Keeping Machine Learning Algorithms Honest in the ‘Ethics-First’ Era
ARTIFICIAL INTELLIGENCE | By Guest Author,
November 18, 2020
Key Trends in Chatbots and RPA
FEATURE | By Guest Author,
November 10, 2020
FEATURE | By Samuel Greengard,
November 05, 2020
ARTIFICIAL INTELLIGENCE | By Guest Author,
November 02, 2020
How Intel’s Work With Autonomous Cars Could Redefine General Purpose AI
ARTIFICIAL INTELLIGENCE | By Rob Enderle,
October 29, 2020
Dell Technologies World: Weaving Together Human And Machine Interaction For AI And Robotics
ARTIFICIAL INTELLIGENCE | By Rob Enderle,
October 23, 2020
The Super Moderator, or How IBM Project Debater Could Save Social Media
FEATURE | By Rob Enderle,
October 16, 2020
FEATURE | By Cynthia Harvey,
October 07, 2020
ARTIFICIAL INTELLIGENCE | By Guest Author,
October 05, 2020
CIOs Discuss the Promise of AI and Data Science
FEATURE | By Guest Author,
September 25, 2020
Microsoft Is Building An AI Product That Could Predict The Future
FEATURE | By Rob Enderle,
September 25, 2020
Top 10 Machine Learning Companies 2021
FEATURE | By Cynthia Harvey,
September 22, 2020
NVIDIA and ARM: Massively Changing The AI Landscape
ARTIFICIAL INTELLIGENCE | By Rob Enderle,
September 18, 2020
Continuous Intelligence: Expert Discussion [Video and Podcast]
ARTIFICIAL INTELLIGENCE | By James Maguire,
September 14, 2020
Artificial Intelligence: Governance and Ethics [Video]
ARTIFICIAL INTELLIGENCE | By James Maguire,
September 13, 2020
IBM Watson At The US Open: Showcasing The Power Of A Mature Enterprise-Class AI
FEATURE | By Rob Enderle,
September 11, 2020
Artificial Intelligence: Perception vs. Reality
FEATURE | By James Maguire,
September 09, 2020
Datamation is the leading industry resource for B2B data professionals and technology buyers. Datamation's focus is on providing insight into the latest trends and innovation in AI, data security, big data, and more, along with in-depth product recommendations and comparisons. More than 1.7M users gain insight and guidance from Datamation every year.
Advertise with TechnologyAdvice on Datamation and our other data and technology-focused platforms.
Advertise with Us
Property of TechnologyAdvice.
© 2025 TechnologyAdvice. All Rights Reserved
Advertiser Disclosure: Some of the products that appear on this
site are from companies from which TechnologyAdvice receives
compensation. This compensation may impact how and where products
appear on this site including, for example, the order in which
they appear. TechnologyAdvice does not include all companies
or all types of products available in the marketplace.