Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Waratek tackles Java application security

Waratek Java Application Security monitors, detects and blocks risky application behaviors.

Article comments

Waratek is introducing its first product aimed at Java application security, and it works by identifying weaknesses, especially in open-source platforms, and then acts like a shield against attacks.

Waratek Java Application Security (JAS) is installed in the Java Virtual Machine to monitor the JVM runtime and detect attacks such as SQL Injection, and block them.

"Certain behavior wouldn't be allowed at runtime," says Prateep Bandharangshi, director of client security solutions at Waratek, adding, "It's kind of a virtual patching." It also works by detecting abnormal file manipulation or unexpected network connections and can quarantine what are deemed to be "illegal operations" inside the application.

Waratek was founded in Dublin, Ireland in 2009 by father-and-son team, John Holt, chief operating officer and John Matthew Holt, chief technology officer, and the firm has a CloudVM capability to help organizations deploy multiple apps on a single server. Brian Maccaba, CEO, says Java Application Security is Waratek's first security product.

While Java-based software--especially open source--is in much demand in the enterprise, the challenge is keeping up with vulnerabilities that should be patched, the company points out. Waratek's JVM runtime approach can be set up to act like a patch without having to stop the application or make code changes. Waratek's approach differs from that taken by Web application firewalls, for example, in blocking attacks because it operates down in the JVM layer to monitor network packet, files system calls and CPU instructions. It works to flag "risky API" calls. It can be deployed in monitoring mode alone or in blocking mode.

Waratek JAS can also be used to audit and log activity for compliance reporting and forensics, the company says.

Waratek has received $18 million in venture-capital funding from Mangrove Capital and angel investors. Maccaba says pricing of Waratek JAS is based on how large the enterprise deployment is but can get into the "six-figure" range.



Share:

More from Techworld

More relevant IT news

Comments



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *