Recent studies confirm that attackers are increasingly targeting web applications to breach the security defenses of organizations. The Verizon 2012 Data Breach Investigation report indicates that for large organizations, 54 percent of the hacking vectors for the investigated breaches were associated with web applications. The report adds that attackers are increasingly using hybrid attacks, with 61 percent of all breaches featuring a combination of hacking techniques and malware.
A new case study with Microsoft describes how their Information Security & Risk Management (ISRM) Team uses QualysGuard WAS to evaluate the security of its hundreds of web applications coming online through its subsidiaries every year. In the case study,
With QualysGuard WAS 3.0, organizations can discover and catalog web applications on a global scale, then identify and remediate web applications vulnerabilities accurately and cost-effectively. QualysGuard WAS 3.0 provides malware detection for web sites, using advanced behavioral analysis to identify even zero-day malware that may infect users. The service proactively scans web sites for malware, providing automated alerts and in-depth reporting to enable prompt identification and resolution of vulnerabilities.
Additionally, 3.0 introduces advanced scanning configurations and reporting enhancements including report creation wizard and scorecard reports based on asset groups or tags, making it easy for users to create and customize reports for the audience they are targeting.
"Saba provides cloud-based learning and talent management solutions to over 10.4 million subscribers all over the world, making security and compliance a top priority for us," said
Lastly, attack proxies and integrated pen testing tools for scanning web applications compliment automated scanning and can provide organizations with another perspective on vulnerabilities that may be present in web applications. QualysGuard WAS 3.0 enables organizations to integrate the scan results of attack proxies such as Burp Suite with its automated scans, presenting comprehensive reports of the results, giving organizations a complete view of vulnerabilities across their web applications.
"As web applications have become the front door through which we exchange information, having an up-to-date inventory of all web applications within an enterprise is a key step to secure corporate data; and automating this process is essential," said
Pricing and Availability
QualysGuard WAS 3.0 availability is targeted for the end of
For more information about QualysGuard WAS, please visit: https://www.qualys.com/was3.0.
To read the full case study on Microsoft's use of QualysGuard WAS, visit: https://www.qualys.com/customers/microsoft.
About
For more information, please visitwww.qualys.com.
CONTACT:Source:Melinda Marks Qualys, Inc. (650) 801-6242 mmarks@qualys.comRod McLeod Bateman Group for Qualys (415) 503-1818 qualys@bateman-group.com
News Provided by Acquire Media