Breach Security’s WebDefend Earns High Praise from SC Magazine

WebDefend web application security appliance tops competitive field

CARLSBAD, Calif., February 1, 2008 — Breach Security, Inc., the leader in web application security, announced today that its flagship WebDefend web application security appliance is featured in the “First Look” review of the February 2008 issue of the leading IT security publication, SC Magazine. WebDefend received high praise for detecting and blocking attacks, as well as identifying flaws in web application design and implementation.

Performed by Peter Stephenson, technology editor for SC Magazine, the review designated WebDefend as a “one-stop shop for managing web application security in the production environment.” The review further concluded, “If you are using active web content, such as online banking applications, you cannot afford to be without this product.”

According to the review, “The key to WebDefend’s success is twofold. First it is not inline. That means that although it sees everything, it presents no latency threat. The second key is that it is a well-thought-out, two-way analysis tool consisting of several analysis engines that communicate with both the web applications and the protection devices, such as firewalls… This cooperation allows the device to tell the firewall to sever a connection before damage or exfiltration of PCI-regulated data can occur.”

WebDefend assesses the web application in its production environment and detects insecure and flawed application design techniques that go unnoticed by scanners. The entire application is assessed and any runtime defects can be detected immediately by the security team before they are exploited by hackers. In addition, security teams can bridge the software development lifecycle gap by generating help tickets for defect remediation.

“Hackers have learned that large volumes of valuable information can easily be siphoned off of web applications that are used to manage online purchases and other vital transactions,” said Mike Pierce, CEO, Breach Security, Inc. “The SC Magazine review does an excellent job of highlighting how WebDefend provides a highly effective level of security for these critical applications and why that is important for any company doing business on the web.”

SC Magazine “First Look” review highlights of WebDefend v3.0:

  • “Because it is able to see all traffic to and from the enterprise, it can see indications of poor web application design, attempts to steal or exfiltrate credit card information, as well as weaknesses that vulnerability scanners may miss.”
  • “WebDefend can—and should—decrypt SSL if you are using HTTPS... The decryption is, of course, transparent and none of the payload content… ever is revealed. The reason this is so important is that attacks that use SSL are common and usually are missed by firewalls and intrusion detection systems.”
  • “Configuration of policies and policy elements is done from the console and is quite straightforward. We had no problems setting up policies.”

The entire text of the WebDefend review can be seen at www.scmagazineus.com.

About SC Magazine

SC Magazine provides IT security professionals with in-depth and unbiased information through timely news, comprehensive analysis, cutting-edge features, contributions from thought leaders and the best, most extensive collection of product reviews in the business. By offering a consolidated view of IT security through independent product tests and well-researched editorial content that provides the contextual backdrop for how these IT security tools will address larger demands put on businesses today, SC Magazine enables IT security pros to make the right security decisions for their companies. The brand’s portfolio includes the SC Magazine Awards, SC Directory, SC Magazine Newswire, and SC Magazine IT Security Executives Forums.

About Breach Security

Breach Security, Inc. is the leading provider of real-time, continuous web application security that protects sensitive web-based information. Breach Security’s products protect web applications from hacking attacks, data leakage, and identity theft, as well as vulnerabilities caused by insecurely coded applications. Breach Security’s solutions also support compliance requirements for the Payment Card Industry (PCI) Data Security Standard (DSS). The company’s WebDefend web application firewall is ICSA Labs certified. Founded in 2004, Breach Security is headquartered in Carlsbad, Calif. For more information, please visit www.breach.com.

###

Breach Security and WebDefend are trademarks of Breach Security, Inc. All other brand, product and service names are the trademarks, registered trademarks or service marks of their respective owners.