Making Shift Left' Work With Continuous Application Security
Making Shift Left' Work With Continuous Application Security
Making Shift Left' Work With Continuous Application Security
1 ©2020, Virsec
Testing Tools Come at a Premium Cost
Conventional application testing tools can help improve secure coding practices by identifying
vulnerabilities early in the development process. However, tools like those shown below can
require extensive expertise – not only with the application being tested, but the tool itself and the
types of attacks and security challenges to which it is prone. Testers require extensive experience
to understand flaws common to specific coding languages. Programming languages often have
vulnerabilities that can be exploited. For instance, some are vulnerable to buffer overflow while
others have flaws that make them open to attacks by code injection.
Overall these tools all share common shortcomings because they typically:
• Deliver vague recommendations that don’t pinpoint software flaws or help prioritize
vulnerabilities,
• Don’t scale, requiring huge amounts of tedious and intense manual labor.
2 ©2020, Virsec
Combining Attack Simulation with Runtime Application Protection
Virsec is the first security vendor to combine advanced CI/CD application testing with continuous
monitoring during runtime, delivering unprecedented accuracy, time savings, and real-world
attack prevention. Built on the world’s most advanced application security platform, Virsec has
integrated automated attack simulation, intelligent fuzzing, and context-sensitive instrumentation
to deliver a new level of end-to-end security at all stages of the SDLC. This extends the capabilities
of the Virsec Security Platform which instantly detects when developer code is subverted by
attacker code. Virsec proactively stops malicious code from executing within an application,
without relying on exploit signatures, heuristics or behavioral rules.
The Virsec Security Platform (VSP) is the first solution to provide continuous and holistic protection
across this cycle, from development through production including:
• Forensics
Detecting flaws in software or 3rd-party tools that can be exploited, regardless of whether
existing vulnerabilities have been discovered.
3 ©2020, Virsec
• Runtime Protection – Preproduction
Virsec’s industry-leading runtime protection detects vulnerabilities that allow legitimate
code to be subverted by attackers to run their own malicious code. In preproduction, this
provides comprehensive results from the Attack Simulator.
• Security Configuration
Enables developers to automatically configure applications for continuous protection
during production.
• Security Analytics
Detects advanced fileless and zero-day threats without using signatures, regardless of
whether existing vulnerabilities have been discovered.
• Ticketing
Collects detailed, actionable forensics and integrates with enterprise ticketing systems like
JIRA to track SDLC remediation.
4 ©2020, Virsec
How it Works
The Virsec Security Platform incorporates these key components to deliver end-to-end application
protection:
Intelligent Fuzzing
Virsec automates testing, injecting thousands of combinations of URLs, parameters, obfuscation
techniques, and OWASP threats, stress testing every user input of the HTTP packet. Specialized
payloads are added into the HTTP request line, parameters, query strings, fragments, headers and
key-value pairs. This delivers code coverage, diversity, and entropy testing far beyond the
capabilities of manual penetration testing.
5 ©2020, Virsec
databases. Virsec detects threats the first time, without relying on rules, heuristics, learning or
constantly updating signatures.
6 ©2020, Virsec
Compensating Controls During Runtime
Virsec is the first solution to close the loop between development and production, applying the
same advanced attack detection during testing, and runtime production. This continuous
monitoring and protection approach effectively provides compensating controls for vulnerabilities
that could not be remediated in a timely manner because of time-to-market deadlines.
The Virsec Security Platform not only detects attacks – it can take a wide range of protection
actions to stop attacks within milliseconds at the very first step in the attack kill chain. Virsec is the
only testing solution that continuously monitors and protects applications during runtime, and
new threats detected during runtime can be automatically reported back to development teams
for ongoing remediation.
About Virsec
Virsec provides a radically new approach to protect against advanced targeted attacks, delivering
unprecedented visibility and protection for enterprise applications and industrial controls, from
today’s most dangerous threats. Through its unique technology, Virsec definitively prevents
attacks that bypass conventional security tools, such as fileless attacks, memory exploits and
attacks that weaponize at runtime. Virsec’s patented technology deterministically stops advanced
attacks in real-time, delivering unprecedented accuracy, while eliminating false positives. The
solution provides virtual patching and compensating controls for any application, whether new,
legacy, or un-patchable.
7 ©2020, Virsec