Reduce The Risk From Web Apps - InformationWeek
Software // Enterprise Applications
11:10 AM

Reduce The Risk From Web Apps

Security gateway from Imperva helps ease security and compliance concerns

Web-based apps improve communication among companies, their employees, customers, and business partners, but they also introduce security and compliance concerns. When Imperva Inc.'s SecureSphere Database Security Gateway ships next week, it's expected to address both issues, offering monitoring and auditing capabilities of Oracle, IBM DB2, MS-SQL, Oracle, and Sybase databases.


FFF's Bob Coates has seen how Imperva's gateway guards against threats.

FFF Enterprises Inc., a distributor of plasma products, vaccines, clinical-trial drugs, and other biopharmaceuticals, already is checking out how Imperva's network security appliance does this. FFF in November will launch a Web-based application called IG Treatment Tracker that will let patients receiving home-based care for certain immune-system deficiencies track their treatments. Using patients' PCs, the application will let them input information about their immune globulin treatment. This data will be protected by Imperva's SecureSphere Database Security Gateway.

Barring Access
"This is unique, identifiable data subject to HIPAA requirements," says Bob Coates, VP of technology for FFF. One of Coates' primary concerns is unauthorized access to information by users or hackers. One way this could be done is through a "SQL Injection" attack that would trick the company's database into letting a hacker access as much of the company's data as they wanted.

Coates has seen how Imperva's gateway, with a starting price of $30,000, guards against internal threats. During tests, a developer accidentally tripped the gateway's alert mechanism while working on IG Treatment Tracker. "He wasn't doing anything wrong," Coates says. "But since he was accessing the database, the system put out an alert."

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
[Interop ITX 2017] State Of DevOps Report
[Interop ITX 2017] State Of DevOps Report
The DevOps movement brings application development and infrastructure operations together to increase efficiency and deploy applications more quickly. But embracing DevOps means making significant cultural, organizational, and technological changes. This research report will examine how and why IT organizations are adopting DevOps methodologies, the effects on their staff and processes, and the tools they are utilizing for the best results.
Register for InformationWeek Newsletters
White Papers
Current Issue
Digital Transformation Myths & Truths
Transformation is on every IT organization's to-do list, but effectively transforming IT means a major shift in technology as well as business models and culture. In this IT Trend Report, we examine some of the misconceptions of digital transformation and look at steps you can take to succeed technically and culturally.
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll