Stopping Business Logic Attacks: Why a WAF is no Longer Enough - Karl Triebes - ASW #255 episode artwork

EPISODE · Sep 19, 2023 · 1H 15M

Stopping Business Logic Attacks: Why a WAF is no Longer Enough - Karl Triebes - ASW #255

from Application Security Weekly (Audio)

The majority of attacks are now automated, with a growing number of attacks targeting business logic via APIs, which is unique to every organization. This shift makes traditional signature-based defenses insufficient to stop targeted business logic attacks on their own. In this discussion, Karl Triebes shares how flaws in business logic design can leave applications and APIs open to attack and what tools organizations need to effectively mitigate these threats. This segment is sponsored by Imperva. Visit https://securityweekly.com/imperva to learn more about them! In the news segment, a slew of XSS in Azure's HDInsights, CNCF releases fuzzing and security audits on Kyverno and Dragonfly2, CISA shares a roadmap for security open source software, race conditions and repojacking in GitHub, and more! Visit https://securityweekly.com/asw for all the latest episodes! Follow us on Twitter: https://www.twitter.com/secweekly Like us on Facebook: https://www.facebook.com/secweekly Show Notes: https://securityweekly.com/asw-255

NOW PLAYING

Stopping Business Logic Attacks: Why a WAF is no Longer Enough - Karl Triebes - ASW #255

0:00 1:15:53

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Frequently Asked Questions

How long is this episode of Application Security Weekly (Audio)?

This episode is 1 hour and 15 minutes long.

When was this Application Security Weekly (Audio) episode published?

This episode was published on September 19, 2023.

What is this episode about?

The majority of attacks are now automated, with a growing number of attacks targeting business logic via APIs, which is unique to every organization. This shift makes traditional signature-based defenses insufficient to stop targeted business logic...

Can I download this Application Security Weekly (Audio) episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!