| By RIA News Desk | Article Rating: |
|
| January 29, 2007 11:00 AM EST | Reads: |
7,091 |
Today's web applications are complex and dynamic; combining client and server side processing with Web 2.0 technologies such as AJAX, SOAP, SOA and Flash. Traditional application scanners fail to discover security vulnerabilities exposed by use of these new technologies, resulting in high false negatives rates. The new web requires a fundamental revolution in assessment technology.
"Anyone developing web applications today should incorporate new Web 2.0 technologies to improve user experience and satisfy customer requirements," said Caleb Sima, co-founder and CTO, SPI Dynamics. "But implementation of these new technologies is a double-edged sword, creating enormous new attack surfaces that leave web applications more exposed than ever before. Leveraging our Phoenix architecture, SPI Dynamics is the first company to provide an automated web application security tool that can discover vulnerabilities in today's web applications. We are pleased to provide another leading innovation from SPI Dynamics to continue to ensure our customers receive the best and broadest web application security coverage."The Phoenix architecture will provide the foundation for SPI Dynamics' entire product line, enabling faster, more accurate scans and facilitating analysis of the new dynamic technologies typically associated with Web 2.0. The first SPI Dynamics' product to utilize the Phoenix architecture is WebInspect 7.
The new Phoenix architecture enables:
- Faster Scans, More Accurate Results - SPI Dynamics' new patent-pending simultaneous crawl and audit (SCA) technology combines the application crawl and audit into a single fluid process. By conducting these activities in parallel instead of sequentially, scan times are reduced by 50 percent or more.
- Immediate Results - This new auditing approach provides results to the tester within seconds of starting an assessment and continues to report in real time throughout the scan.
- Broader Coverage, Reduced False Negatives - WebInspect 7 includes intelligent scanning engines capable of analyzing complex Web 2.0 technologies to provide broader testing coverage than possible with earlier legacy scanning architectures. WebInspect 7 exposes application logic that was previously hidden, revealing security vulnerabilities undetectable through automated security testing.
- Simultaneous Scans - Users can now launch and manage multiple concurrent scans, greatly increasing testing throughput with WebInspect 7.
- Advanced Authentication Management - New automated mechanisms eliminate the complexities of authentication even with applications using advanced technologies such as two-factor authentication or CAPTCHA. WebInspect 7 can both authenticate with secure web applications and detect when re-authentication is required. This is essential to ensure complete coverage.
- Support for IPv6 - WebInspect 7 is ready for the future Internet with full support for IPv6.
Published January 29, 2007 Reads 7,091
Copyright © 2007 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
About RIA News Desk
Ever since Google popularized a smarter, more responsive and interactive Web experience by using AJAX (Asynchronous JavaScript + XML) for its Google Maps & Gmail applications, SYS-CON's RIA News Desk has been covering every aspect of Rich Internet Applications and those creating and deploying them. If you have breaking RIA news, please send it to RIA@sys-con.com to share your product and company news coverage with AJAXWorld readers.
![]() |
ajax news desk 01/29/07 01:01:15 PM EST | |||
S.P.I. Dynamics announced the company's Phoenix architecture - the first and only technology able to analyze complex Web 2.0 applications to reveal previously undetectable vulnerabilities.Today's web applications are complex and dynamic; combining client and server side processing with Web 2.0 technologies such as AJAX, SOAP, SOA and Flash. |
||||
- AJAX World RIA Conference & Expo Kicks Off in New York City
- What is Web 3.0?
- AJAXWorld RIA Conference & Expo 2009 West: Call for Papers
- AJAX and RIA 2009: More Choices, Tough Decisions
- Ulitzer’s Amazing First 30 Days in Public Beta
- SYS-CON Announces Government IT Conference & Expo
- RIAs for Web 3.0 Using the Microsoft Platform
- REA Is Where RIA Becomes the Norm
- Why an Application Grid?
- 2nd International Cloud Computing Expo New York Photo Album
- AJAX World RIA Conference & Expo Kicks Off in New York City
- What is Web 3.0?
- Developing Rich Client Applications Using Swing - II
- AJAXWorld RIA Conference & Expo 2009 West: Call for Papers
- AJAX and RIA 2009: More Choices, Tough Decisions
- AJAX World RIA Conference Awards Announced
- WebORB Launched for Flex, Flash, AJAX and Silverlight
- Appcelerator Revolutionizes UI Prototyping
- Adobe Takes LiveCycle into the Cloud
- Ulitzer’s Amazing First 30 Days in Public Beta
- Building a Drag-and-Drop Shopping Cart with AJAX
- What Is AJAX?
- Google Maps! AJAX-Style Web Development Using ASP.NET
- Flashback to January 2006: Exclusive SYS-CON.TV Interviews on "OpenAjax Alliance" Announcement
- AJAXWorld Conference & Expo to Take Place October 2-4, 2006, at the Santa Clara Convention Center, California
- AJAX Sponsor Webcasts Are Now Available at AJAXWorld Website
- How and Why AJAX, Not Java, Became the Favored Technology for Rich Internet Applications
- "Real-World AJAX" One-Day Seminar Arrives in Silicon Valley
- AJAXWorld University Announces AJAX Developer Bootcamp
- AJAX Support In JadeLiquid WebRenderer v3.1






































