Application & Data Security
zerO'clock secure your software applications, IT systems and data, giving maximum level of confidentiality, integrity and availability to your knowledge assets.
Reliable statistics (Gartner, US Federal Bureau of Investigation, etc.) say that 75% of current cybercrimes are on application layer and 79% of web-based applications (containing confidential informations - B2B, B2C and B2E) are vulnerables. The cause of theese attacks is the lack of attention in securing applications both in development and deployment. ZerO'clock provides its customers experience, design and implementative skills in the following areas:
-
Secure Coding: Definition of standards and guidelines for secure code writing. Implementation of secure applications using innovative methodologies as Model Driven Security: which allow the inclusion of security primitives (eg. confidentiality integrity, authentication, authorization, auditing) directly during the design phase.
-
Application Security Testing: Execution of application security tests (SOA, Web, C/S, etc.) during all software lifecycle phases for vulnerabilities detection and solutions suggestion: Static Application Security Testing (sources, binaries and byte code); Dynamic Application Security Testing (black-box analysis).
-
Application Hardening and Shielding: Software integration with security features applied proactively (eg. anti-tampering obfuscation, input filtering, etc.) and reactively for intrusion prevention and detection.
-
Application/Database Activity Monitoring & Intrusion Prevention: Applications monitoring (eg. interaction with users, back-end transactions, ...) and database communications monitoring (proxy-based or agent-based mode) for identification and prevention of malicious actions or policy compliace control.
-
Web Application Firewalling: Traffic filtering solution for web applications and data servers.
-
Mobile data Protection: Encryption solutions (software and/or hardware-based) for informations stored on mobile systems (eg. laptops, PDA and smartphone).
-
Content Monitoring & Filtering (CMF) & Data Loss Prevenction (DLP): Solutions to detect and prevent the disclosure of confidential informations able to perform linguistic analysis of network traffic contents and to perform filtering in according with company security policy.

