Breach Security Executive Addresses the Department of Homeland Security

May 2, 2008

CARLSBAD, Calif. , May 2 /PRNewswire/ -- Breach Security, Inc., the leader in web application security, today announced that Ryan C. Barnett , director of application security, will present results from the Web Application Security Consortium (WASC) Web Hacking Incident Database (WHID) project at the 2008 Department of Homeland Security Software Assurance Forum. Barnett was invited to educate attendees on website vulnerabilities, hacking techniques and attacks, as well as new web application security technologies in use to counter them. Barnett will provide deep analysis of real-world incidents such as the types of sites targeted, motivation, sources and impact of each attack, in addition to best-practices for monitoring web application security and protecting against intruders.

Barnett, Global Information Assurance Certified as an Intrusion Analyst (GCIA), Forensic Analyst (GCFA) and Incident Handler (GCIH), is also a SANS Institute faculty member and a member of WASC. Event logistics:

When: May 7, 2008, 4:20 p.m. E.T. Location: The Software Assurance Forum Sheraton Premiere, Tysons Corner, VA Pavilions 22 & 23 What: Topic: "Web Hacking Incidents Database" Session highlights include: -- In 2007, nearly 70 percent of attacks were financially motivated. -- 2007 WHID data indicates that more than 44 percent of incidents over the course of the year were tied to non-commercial sites such as government and education. -- More than 20 percent of the total, SQL injections dominate as the most common techniques used in the attacks. -- One-third of the incidents were a result of an operational issue, such as unintentionally publishing sensitive information online, rather than a programming mistake. -- The SANS Institute predicts that there will continue to be major vulnerabilities in nearly 50 percent of web applications in 2008.

To view the 2007 Web Hacking Incident Report in its entirety, visit: http://www.webappsec.org/projects/whid/statistics.shtml.

To attend the event and Ryan's session, please sign up at http://www.bowheadevents.com/swaforum2008/reg.cfm.

About Ryan Barnett

Ryan C. Barnett , Director of Application Security, Breach Security, Breach Security, Inc., is a recognized security thought leader and evangelist who frequently speaks with the media and industry groups. He is director of application security at Breach Security and a SANS Institute faculty member. He holds six SANS Global Information Assurance Certifications, serves as the team lead for the Center for Internet Security Apache Benchmark Project and is a member of the Web Application Security Consortium. Mr. Barnett's web security book, "Preventing Web Attacks with Apache," was published by Addison/Wesley in 2006.

About Breach Security, Inc.

Breach Security, Inc. is the leading provider of real-time, continuous web application security that protects sensitive web-based information. Breach Security's products protect web applications from hacking attacks and data leakage, and ensure applications operate as intended. The company's products are trusted by thousands of organizations around the world, including leaders in finance, healthcare, ecommerce, travel, and government. For more information, please visit http://www.breach.com.

SOURCE Breach Security, Inc.

Copyright © 2008 PR Newswire Association LLC. All Rights Reserved.