YoVDO

Injecting Security Into Web Apps With Runtime Patching And Context Learning

Offered By: nullcon via YouTube

Tags

nullcon Courses SQL Injection Courses Web Application Security Courses

Course Description

Overview

Explore cutting-edge web application security techniques in this 55-minute conference talk from nullcon Goa 2017. Delve into Runtime Application Self Protection (RASP) and learn how to implement runtime patching algorithms to secure vulnerable applications against code injection and other logical issues. Discover methods for preventing SQL injection, remote command execution, cross-site scripting, and more through dynamic rule generation and context-aware protection. Compare RASP to traditional Web Application Firewalls (WAFs) and understand its advantages in tackling modern AppSec challenges like session hijacking, Layer 7 DDoS, and credential stuffing. Gain insights into the future of runtime protection and its potential to defend against zero-day vulnerabilities affecting framework and language components.

Syllabus

Intro
AGENDA WHAT THE TALK IS ABOUT?
STATE OF WEB FRAMEWORK SECURITY Remote Os Command Execution - No
APPLICATION SECURITY RULE OF THUMB
RUNTIME APPLICATION SELF DEFENCE
TYPES OF RASP
FOCUS OF RESEARCH
MONKEY PATCHING
LEXICAL ANALYSIS AND TOKEN GENERATION
PREVENTING CODE INJECTION VULNERABILITIES
REMOTE OS COMMAND INJECTION HOOK
REMOTE OS COMMAND INJECTION PROTECT
PREVENTING HEADER INJECTION
FILE UPLOAD PROTECTION
PREVENTING PATH TRAVERSAL
THE RASP ADVANTAGES
BIGGEST ADVANTAGE


Taught by

nullcon

Related Courses

Unearthing Malicious and Risky OpenSource Packages Using Packj
nullcon via YouTube
Pushing Security Left by Mutating Byte Code
nullcon via YouTube
The Faces of MacOS Malware - Detecting Anomalies in a Poisoned Apple
nullcon via YouTube
Contextomy - Let's Debug Together
nullcon via YouTube
Mind The Gap - The Linux Ecosystem Kernel Patch Gap
nullcon via YouTube