nullcon Goa 2017 - Injecting Security Into Web Apps With Runtime Patching And Context Learning
About this talk
This talk focuses on web application security, specifically addressing the limitations of traditional Web Application Firewalls (WAFs) in detecting and thwarting code injection vulnerabilities. The speaker, Ajin Abraham, presents his research on implementing a runtime application patching algorithm to protect insecurely coded applications from various web attacks such as SQL Injection and Cross Site Scripting. He introduces Runtime Application Self Protection (RASP), a next-generation technology that injects security into applications by understanding their internal workings, enabling real-time defense against sophisticated threats. The session includes proof of concept code and demonstrations of methodologies to prevent vulnerabilities that traditional WAFs cannot address, offering insights into the future of runtime protection in application security.
More from this event
See all 33 talks →
nullcon Goa 2017 - Antivirus Evasion Reconstructed Veil 3 0 by Chris Truncer
59:38
nullcon Goa 2017 - Barbarians At The Gateway by Dave Lewis
42:56
nullcon Goa 2017 - Drone Hijacking And Other IoT Hacking With GNU Radio And SDR by Arthur Garipov
46:02
nullcon 2017 - Invoke Obfuscation: Powershell Obfuscation Techniques n How To Try To Detect Them
55:26