TitleWeb Application Security

Cisco Data Center Day 2007

TiWtleeb Application Security

Leo Chan Product Manager ? Application Networking Services Cisco Systems APAC

Presentation_ID

? 2006 Cisco Systems, Inc. All rights reserved. Cisco Confidential

1

Session agenda

Web Application Security: background Top Web Application Attacks:

? Input validation bypass ? SQL injection ? Cross-Site Scripting (XSS) ? Cookie Tampering / Session Hijacking

Cisco's Web Application Firewall

? Cisco AVS

BRKAPP-1007

? 2006 Cisco Systems, Inc. All rights reserved. Cisco Confidential

2

Web Application Security: background

BRKAPP-1007

? 2006 Cisco Systems, Inc. All rights reserved. Cisco Confidential

3

Applications: the Weak Link to the Crown Jewels

Data Disclosure

Customer Confidentiality

Applications Give Unprecedented Access to Critical Business Data

Identity Theft

BRKAPP-1007

? 2006 Cisco Systems, Inc. All rights reserved. Cisco Confidential

Service Disruption

4

Just off the press

BRKAPP-1007

? 2006 Cisco Systems, Inc. All rights reserved. Cisco Confidential

5

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download