<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BusinessTechFeed &#187; Secerno</title>
	<atom:link href="http://businesstechfeed.com/tag/secerno/feed/" rel="self" type="application/rss+xml" />
	<link>http://businesstechfeed.com</link>
	<description>For The People Feeding Business With Technology</description>
	<lastBuildDate>Thu, 17 Jun 2010 03:09:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Linking Network and Database Security</title>
		<link>http://businesstechfeed.com/2008/11/linking-network-and-database-security/</link>
		<comments>http://businesstechfeed.com/2008/11/linking-network-and-database-security/#comments</comments>
		<pubDate>Tue, 18 Nov 2008 14:35:04 +0000</pubDate>
		<dc:creator>Benjamin Ellis</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[F5 Networks]]></category>
		<category><![CDATA[Secerno]]></category>

		<guid isPermaLink="false">http://businesstechfeed.com/?p=187</guid>
		<description><![CDATA[When I last spoke with  F5 Networks (F5 Networks &#8211; A Case of Applications and the Network) it was clear that they were getting more focussed on the higher application layers. Our discussion touched on Secerno, a specialist database security company based out of the UK. Today the two companies have announced a joint solution which should be [...]]]></description>
			<content:encoded><![CDATA[<p>When I last spoke with  <a href="http://www.f5.com/">F5 Networks</a> (<a title="F5 Networks - A Case of Applications and the Network" rel="bookmark" href="http://businesstechfeed.com/2008/10/f5-networks-a-case-of-applications-and-the-network/">F5 Networks &#8211; A Case of Applications and the Network</a>) it was clear that they were getting more focussed on the higher application layers. Our discussion touched on Secerno, a specialist database security company based out of the UK. Today the two companies have announced a joint solution which should be of interest to anyone building web-based applications that have a database back-end.<span id="more-187"></span></p>
<p>I spoke with James Spooner of <a href="http://www.secerno.com/">Secerno</a> and Bill Beverley of F5 Networks <a href="http://www.secerno.com/?pg=press-releases&amp;newsid=644">about their solution</a>, which is based around the F5 BIG-IP ASM and Secerno DataWall products. Essentially they are working together to provide a more joined up security solution. While much has happened to deliver more integration between the lower network levels and applications, no-one has really tackled the problem of integrating application and database security &#8211; at least not in the web application space.</p>
<p>This is where F5 Networks and Secerno have jointly focussed their effort. By using customized rules on the F5 box, DataWall can be notified of anomalies at the web traffic layer. This gives Secerno&#8217;s product user-level visibility (down to the session level) of what is happening in web applications. In theory this approach should increase the ability to protect back-end databases, and reduce the number of false positives. </p>
<p>The F5 BIG-IP provides more than half a dozen attributes that can be used to correlate web transactions to database transactions, enabling very granular blocking of attempts to exploit SQL security vulnerabilities (see <a href="http://blogger.xs4all.nl/gjvm/archive/2008/10/29/420695.aspx">here</a>). Suspicious activity can be reported up to SIM/SEM security management products and used for security forensics.</p>
<p>It is an interesting development, with lots of potential for expanded functionality. Using web-based applications is an attractive way of sharing information outside of the organization, either via Web 2.0 style APIs, or web portals. They can be quick to develop, and provide efficiency and competitive advantage. The downside is that such applications often require access into databases with sensitive information. The F5 and Secerno solution is a worthy attempt to deliver high levels of security, but still enable business flexibility &#8211; making both companies&#8217; solutions more attractive.</p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://businesstechfeed.com/2008/11/identity-management/" title="Identity Management">Identity Management</a></li><li><a href="http://businesstechfeed.com/2008/10/f5-networks-a-case-of-applications-and-the-network/" title="F5 Networks &#8211; A Case of Applications and the Network">F5 Networks &#8211; A Case of Applications and the Network</a></li><li><a href="http://businesstechfeed.com/2008/09/when-blurred-e-mail-goes-from-bad-to-worse/" title="When Blurred e-mail Goes From Bad to Worse">When Blurred e-mail Goes From Bad to Worse</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://businesstechfeed.com/2008/11/linking-network-and-database-security/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

