Oligo Security, the runtime security company, today announced the launch of the Application Attack Matrix, a standardized framework to categorize tactics, techniques, and procedures (TTPs) for applica...
Collaboration with world-renowned cyber leaders yields a timely framework for how attackers target modern enterprise applications
TEL AVIV, Israel: Oligo Security, the runtime security company, today announced the launch of the Application Attack Matrix, a standardized framework to categorize tactics, techniques, and procedures (TTPs) for application-layer attacks. Developed in collaboration with leading experts in threat intelligence and application security, the matrix was shaped with input from contributors from companies like AWS, Google Cloud (Mandiant), Intel, Microsoft, Salesforce, and other organizations at the forefront of cybersecurity. It is designed to help security teams, developers, and threat hunters better understand how attackers target modern applications, build more effective defenses, and bridge the gap between application security and broader security operations.
The sharp rise in software vulnerabilities year over year has created major challenges for security teams working to protect applications – even at small scales. Adversaries have taken advantage of this surge, with vulnerability exploits overtaking phishing as an initial attack vector1. Vulnerability exploits have also remained one of the top methods used by attackers to gain access to organizations for the past 5 years in Mandiant investigations2, with many critical vulnerabilities exploited within 48 hours of disclosure3.
“Attackers target applications more today than any point in history, and it is time for the industry to stop focusing on treating post-exploit symptoms and get to the root cause: the initial exploit attempts that happen in the application layer,” said Gal Elbaz, co-founder and CTO, Oligo Security. “We started this framework to help defenders understand how applications are targeted so that the industry can act together to bolster defenses. We invite anyone who wants to contribute to join us in making this a vendor agnostic, collaborative effort that hopes to create a standard methodology for protecting against application attacks.”
Application-layer attacks target applications in production environments, including web and server-side apps, and often bypass traditional detection systems to exploit vulnerabilities deep within the software stack. Current security solutions and frameworks are primarily focused on infrastructure or workload-level tactics and techniques, such as cloud and mobile technologies, networks, operating systems and endpoints. This leaves a gap in standardization for defending against application-layer attacks that increasingly stem from vulnerability exploitation.
To close this gap, the Application Attack Matrix focuses on:
“The level of threat activity originating in the application layer makes an application-focused attack matrix critical,” said Jaime Blasco, Ballistic Ventures Threat Intelligence Advisor and Creator of Open Threat Exchange. “Applications have become beyond essential to business operations, and organizations as a whole are struggling with inconsistent security strategies, incomplete threat coverage, and ineffective incident response for modern applications. This initiative fills an important gap, empowering organizations to defend against the next-generation of threats that increasingly originate and stay in the application layer.”
More information:
Sources:
About Oligo Security
Oligo protects applications against attackers with the industry’s leading runtime security platform. With deep application inspection through real-time monitoring and context-aware analysis, Oligo enables customers to instantly see all of the vulnerabilities in their environments, identify those that matter most, and stop application-based attacks in their tracks. https://www.oligo.security/
Fonte: Business Wire
Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…
G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes
Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries
Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…