Download presentation
Presentation is loading. Please wait.
Published byMyron Poole Modified over 9 years ago
1
10/14/2015 Introducing Worry-Free SecureSite
2
Copyright 2007 - Trend Micro Inc. Agenda Problem –SQL injection –XSS Solution Market opportunity Target customers Competitive Key Selling Points/Strategies
3
Copyright 2007 - Trend Micro Inc. The threat environment Complexity Crimeware Spyware Spam Mass Mailers Intelligent Botnets Web Threats Multi-Vector Multi-Component Web Polymorphic Rapid Variants Single Instance Single Target Regional Attacks Silent, Hidden Hard to Clean Botnet Enabled Information Stealing Vulnerabilities Worm/ Outbreaks
4
Copyright 2007 - Trend Micro Inc. How vulnerable are Web sites? Fifty per cent – one of every two – online retail sites have serious vulnerabilities 1 –SQL injection –XSS vulnerabilities More than 22,000 known xss vulnerabilities identified at named Web sites 2 –Only 5% fixed More than 40% of Web threat incidents involved legitimate sites unknowingly distributing malware 3 1)Trend Micro research 2008 2)www.xssed.com, April 2008 3)TrendLabs Blog
5
Copyright 2007 - Trend Micro Inc. What is SQL injection? Injecting a script into website’s SQL database via online form Injecting a script into SQL database via Web-based form –Can be prevented with field parameters –Proliferation of forms w/ distributed owners is challenge
6
Copyright 2007 - Trend Micro Inc. What is SQL Injection?
7
Copyright 2007 - Trend Micro Inc. What is XSS? XSS = cross–site scripting to inject malware into Web pages –Local –Non-persistent –Persistent Takes advantage of site-specific vulnerabilities Can be used to: –Hijack and redirect user’s session –Access user session cookie and impersonate end-user –Can bypass access controls such as same origin policy –Can be used to craft phishing attacks and browser exploits
8
Copyright 2007 - Trend Micro Inc. What is XSS?
9
Copyright 2007 - Trend Micro Inc. What is XSS?
10
Copyright 2007 - Trend Micro Inc. What is XSS?
11
Copyright 2007 - Trend Micro Inc. What is XSS?
12
Copyright 2007 - Trend Micro Inc. What is XSS?
13
Copyright 2007 - Trend Micro Inc. What is XSS?
14
Copyright 2007 - Trend Micro Inc. What is Worry-Free SecureSite? 1.Assess, validate and monitor web sites against vulnerabilities 2.SecureSite mark for validated sites 3.If necessary, remediation steps and documentation provided
15
Copyright 2007 - Trend Micro Inc. How is Worry-Free SecureSite different than competition? Provided by a widely known and trusted security vendor Channel partners have required experience to help remediate vulnerabilities Affordable pricing to drive volume adoption and partner service revenue –Mark priced affordably for smaller online retailers –Ongoing scanning priced affordably for larger websites
16
Copyright 2007 - Trend Micro Inc. Level the playing field for your online retail customers New service business –OnDemand web application vulnerability assessment –Remediation services –Ongoing vulnerability monitoring –PCI compliance Higher recurring revenue –Hosted solutions have up to 2x higher re-purchase rates than equivalent tradt’l software Worry-Free SecureSite Benefits to Channel Partners
17
Copyright 2007 - Trend Micro Inc. How is Worry-Free SecureSite available? Annual hosted subscription Licensed per domain scanned Free trials available –Try and buy –Enable OnDemand scanning and reports
18
Copyright 2007 - Trend Micro Inc. Why Trend Micro? Web Filtering Security-as- a-Service Web-based Centralized Management Network Access Control Email Reputation Services Gateway Virus Protection 2-Hour Virus Response SLA 19951996199719981999200020012002200320042005200620072008 LAN Server Virus Protection Server-based Email Virus Protection Threat Lifecycle Management Strategy Trend Micro and Cisco Integrated Gateway Content Security Botnet Identification Service Our #1 goal is to create value for our customers through continuous innovation Compliance Data Leak Prevention Web Threat Protection
19
Copyright 2007 - Trend Micro Inc. Why Trend Micro? More than 3.2 billion websites monitored on a daily basis
20
Copyright 2007 - Trend Micro Inc. Why Trend Micro? TrendLabs helps provide a worldwide platform for delivering timely threat intelligence, service, and support anytime, anywhere.
21
Copyright 2007 - Trend Micro Inc. Competition
22
Copyright 2007 - Trend Micro Inc. Competition
23
Copyright 2007 - Trend Micro Inc. Competition
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.