By Jeff Williams, Co-Founder, Chief Technology Officer
June 10, 2016
Brace yourself. Recent advances in application security are about to spawn an onslaught of application security tool vendors who think you absolutely must have their "complete" solution to protect your applications.
They want to sell you the old stuff... static analysis (SAST), dynamic analysis (DAST), and web application firewall (WAF). They might include a library analysis tool. And they're going to want to sell you the new stuff... interactive analysis (IAST) and runtime self-protection (RASP). And they're going to tell you that you need all of this stuff in order to meet the needs of DevOps!
They're basically saying that "tool soup" is the best approach. I couldn't disagree more. Tool soup not only doesn't address the key speed, scalability, and process fit problems in appsec, it won't solve critical false positive and, even more importantly, false negative problems. It's a monster all right.
Let's just step back from the madness and think for a second about what DevOps projects actually need. These projects are relying on automation to move code from development to production very quickly, so security has to work at DevOps speed and portfolio scale.
My advice? Don't order the "Tool Soup" -- it will just make your application security problems worse.
Ditch the old stuff that doesn't really do the job. Contrast is the world's first and only unified IAST and RASP platform. Just add a single application-layer agent to your application stack... that's it. From that point forward, Contrast continuously protects your apps from both vulnerabilities and attacks.
Using deep security instrumentation, Contrast takes advantage of the elements of static and dynamic analysis that actually work well, and adds the power of configuration analysis, library analysis, runtime analysis, attack protection, log enhancement, CVE shields, and bot blocking. That's all in the single easily deployed agent.
This unified analysis has access to the "context" (code, HTTP traffic, libraries, data flow, architecture, etc...) needed to produce amazingly accurate results in real time. And Contrast is a distributed solution that scales to hundreds or thousands of applications in parallel. Imagine controlling application security policy across your entire portfolio from the first line of code all the way through production.
This isn't just what DevOps needs... it's what every enterprise that's betting their future on software needs.
Jeff brings more than 20 years of security leadership experience as co-founder and Chief Technology Officer of Contrast Security. He recently authored the DZone DevSecOps, IAST, and RASP refcards and speaks frequently at conferences including JavaOne (Java Rockstar), BlackHat, QCon, RSA, OWASP, Velocity, and PivotalOne. Jeff is also a founder and major contributor to OWASP, where he served as Global Chairman for 9 years, and created the OWASP Top 10, OWASP Enterprise Security API, OWASP Application Security Verification Standard, XSS Prevention Cheat Sheet, and many more popular open source projects. Jeff has a BA from Virginia, an MA from George Mason, and a JD from Georgetown.
Get the latest content from Contrast directly to your mailbox. By subscribing, you will stay up to date with all the latest and greatest from Contrast.