Sanctum (company)

Last updated
Sanctum
Type Private Company
Industry Software,
Information Technology
PredecessorPerfecto Technologies
Founded1997
Founder Gili Raanan and Eran Reshef
Defunct2006
FateAcquired
Successor IBM
Headquarters Herzliya, Israel,
Products AppShield and AppScan
Website www.IBM.com

Sanctum was a Santa Clara, California-based information technology company focused on application security. Sanctum offered a firewall, AppShield, and scanner, AppScan, for application-layer security for Web environments. [1]

Contents

In 2003 Sanctum was merged with Watchfire and the company was subsequently acquired by IBM. [2]

History

Sanctum was founded in 1997 as Perfecto Technologies, by Eran Reshef and Gili Raanan.

The company released its first product AppShield in summer of 1999. [3]

The company has done an extensive research in application security and applying formal methods to real life software [4] in collaboration with Turing Award winner Professor Amir Penueli. Early research in 1996 and 1997 led to the invention, in parallel to other teams, of CAPTCHA technology, and the application for a US patent for CAPTCHA. [5]

In 2000 the company renamed itself to Sanctum. [6] The company was backed by investors Sequoia Capital, Intel Capital, Goldman Sachs, DLJ, Walden and Mofet. [7]

Products

The AppShield product was the first product to inspect incoming Hypertext Transfer Protocol requests and block malicious attacks based on a dynamic policy which was composed by analyzing the outgoing HTML pages. [8] [9]

Later in June 2000 the company introduced AppScan the world's first Web Security Vulnerability Assessment solution. [10] Among the first clients for AppScan were Yahoo!, [11] Bank of America and AT&T. [12]

Related Research Articles

<span class="mw-page-title-main">Optical character recognition</span> Computer recognition of visual text

Optical character recognition or optical character reader (OCR) is the electronic or mechanical conversion of images of typed, handwritten or printed text into machine-encoded text, whether from a scanned document, a photo of a document, a scene photo or from subtitle text superimposed on an image.

<span class="mw-page-title-main">Instant messaging</span> Form of communication over the internet

Instant messaging (IM) technology is a type of online chat allowing real-time text transmission over the Internet or another computer network. Messages are typically transmitted between two or more parties, when each user inputs text and triggers a transmission to the recipient(s), who are all connected on a common network. It differs from email in that conversations over instant messaging happen in real-time. Most modern IM applications use push technology and also add other features such as emojis, file transfer, chatbots, voice over IP, or video chat capabilities.

Internet Security Systems, Inc., often known simply as ISS or ISSX, was a provider of security software and managed security services. It provided software and services for computers, servers, networks, and remote locations that involve preemptive security against threats before they affect a business. Founded in 1994, the company was acquired by IBM in 2006.

A CAPTCHA is a type of challenge–response test used in computing to determine whether the user is human in order to deter bot attacks and spam.

<span class="mw-page-title-main">Citrix Systems</span> American software company

Citrix Systems, Inc. is an American multinational cloud computing and virtualization technology company that provides server, application and desktop virtualization, networking, software as a service (SaaS), and cloud computing technologies. Citrix products were claimed to be in use by over 400,000 clients worldwide, including 99% of the Fortune 100, and 98% of the Fortune 500.

Mobile app development is the act or process by which a mobile app is developed for one or more mobile devices, which can include personal digital assistants (PDA), enterprise digital assistants (EDA), or mobile phones. Such software applications are specifically designed to run on mobile devices, taking numerous hardware constraints into consideration. Common constraints include CPU architecture and speeds, available memory (RAM), limited data storage capacities, and considerable variation in displays and input methods. These applications can be pre-installed on phones during manufacturing or delivered as web applications, using server-side or client-side processing to provide an "application-like" experience within a web browser.

Qualys, Inc. is an American technology firm based in Foster City, California, specializing in cloud security, compliance and related services.

reCAPTCHA CAPTCHA implementation owned by Google

reCAPTCHA Inc. is a CAPTCHA system owned by Google. It enables web hosts to distinguish between human and automated access to websites. The original version asked users to decipher hard to read text or match images. Version 2 also asked users to decipher text or match images if the analysis of cookies and canvas rendering suggested the page was being downloaded automatically. Since version 3, reCAPTCHA will never interrupt users and is intended to run automatically when users load pages or click buttons.

Ericom Software, Inc. is a Closter, New Jersey-based company that provides web isolation and remote application access software to businesses.

<span class="mw-page-title-main">VirusTotal</span> Cybersecurity website owned by Chronicle

VirusTotal is a website created by the Spanish security company Hispasec Sistemas. Launched in June 2004, it was acquired by Google in September 2012. The company's ownership switched in January 2018 to Chronicle, a subsidiary of Google.

<span class="mw-page-title-main">WaveMaker</span> Low-code programming platform

WaveMaker is an enterprise-grade Java low-code development platform for building software applications and platforms. WaveMaker Inc. is headquartered in Mountain View, California. For enterprises, WaveMaker is a low-code platform that aims to accelerate their app development and IT modernization efforts. For ISVs, it is a consumable low-code component that can sit inside their product and offer customizations.

Veracode is an application security company based in Burlington, Massachusetts. Founded in 2006, it provides SaaS application security that integrates application analysis into development pipelines.

<span class="mw-page-title-main">Tufin</span> Software company

Tufin is a security policy management company specializing in the automation of security policy changes across hybrid platforms and security and compliance. The Tufin Orchestration Suite supports next-generation firewalls, network layer firewalls, routers, network switches, load balancers, web proxies, private and public cloud platforms and micro-services.

A mobile application or app is a computer program or software application designed to run on a mobile device such as a phone, tablet, or watch. Mobile applications often stand in contrast to desktop applications which are designed to run on desktop computers, and web applications which run in mobile web browsers rather than directly on the mobile device.

HCL AppScan, previously known as IBM AppScan, is a family of desktop and web security testing and monitoring tools, formerly a part of the Rational Software division of IBM. In July 2019, the product was acquired by HCL Technologies and is currently marketed under HCL Software, a product development division of HCL Technologies. AppScan is designed to test both on-premises and web applications for security vulnerabilities during the development process, when it is least expensive to fix such problems. The product scans the behavior of each application, whether an off-the-shelf application or internally developed, and develops a program intended to test all of its functions for both common and application-specific vulnerabilities. This family of products is capable of performing SAST, DAST, IAST and Mobile Analysis against the user's source code and check for vulnerabilities.

<span class="mw-page-title-main">Web application firewall</span> HTTP specific network security system

A web application firewall (WAF) is a specific form of application firewall that filters, monitors, and blocks HTTP traffic to and from a web service. By inspecting HTTP traffic, it can prevent attacks exploiting a web application's known vulnerabilities, such as SQL injection, cross-site scripting (XSS), file inclusion, and improper system configuration.

Perforce Software, Inc. is an American developer of software used for developing and running applications, including version control software, web-based repository management, developer collaboration, application lifecycle management, web application servers, debugging tools and Agile planning software.

<span class="mw-page-title-main">Gili Raanan</span> Israeli inventor

Gili Raanan is an Israeli venture capitalist and one of the inventors of CAPTCHA, the WAF and many other inventions in the fields of application security and discovery. Raanan started Sanctum in 1997, and invented the first Web application firewall AppShield and the first Web application penetration testing software AppScan. He later started NLayers which was acquired by EMC Corporation pioneering the science of Application discovery and understanding. He is an investor and a General Partner at Sequoia Capital, the Founder of Cyberstarts, and was a board member at Adallom, Armis Security, Onavo, Moovit, Innovid (NYSE:CTV) and Snaptu.

AppShield was the world's first Application firewall. AppShield was conceptualized by Eran Reshef and Gili Raanan and was introduced to the market by Perfecto Technologies in the summer of 1999. AppShield is a safeguard for many systems as it is protection for code and data. The Appshield product was the first product to inspect incoming Hypertext Transfer Protocol requests and block malicious attacks based on a dynamic policy which was composed by analyzing the outgoing HTML pages. AppShield is used to isolate the target applications registers and address space from the other applications and can utilize memory in a unique way and in return, the rootkit can't access it's memory. The product faced many market adoption challenges and Sanctum was forced to introduce a complementary solution named Appscan to demonstrate the need in Application security. In 2004, F5 Networks acquired AppShield's intellectual properties from Sanctum and discontinued the technology. Gartner's Magic Quadrant (MQ) 2015 for Web Application Firewalls estimates that the global WAF market size is as big as $420 million, with 24 percent annual growth. AppShield can rewrite application framework in Android and IOS and it will not modify the IOS for the device.

References

  1. "What the Watchfire-Sanctum acquisition means for Web app security" . Retrieved 2016-09-12.
  2. "IBM Buys Watchfire". PCWorld. 2007-06-06. Retrieved 2016-09-12.
  3. Messmer, Ellen. "CNN - New tool blocks wily e-comm hacker tricks - September 7, 1999". edition.cnn.com. Retrieved 2016-09-12.
  4. Kesten, Yonit; Klein, Amit; Pnueli, Amir; Raanan, Gil (1999-09-20). Wing, Jeannette M.; Woodcock, Jim; Davies, Jim (eds.). FM'99 — Formal Methods. Lecture Notes in Computer Science. Springer Berlin Heidelberg. pp.  173–194. doi:10.1007/3-540-48119-2_12. ISBN   9783540665878. S2CID   41193257.
  5. "Method and system for discriminating a human action from a computerized action". 2004-03-01.{{cite journal}}: Cite journal requires |journal= (help)
  6. "Perfecto Changes Name to Sanctum - Globes English". Globes. Retrieved 2016-09-12.
  7. "DLJ'S Sprout Group Leads $16 Million Investment in Perfecto Technologies; Premier Venture Firm Backs eBusiness Security Software Company. - Free Online Library". www.thefreelibrary.com. Retrieved 2016-09-12.
  8. "Method and system for extracting application protocol characteristics". 1999-07-01.{{cite journal}}: Cite journal requires |journal= (help)
  9. "Method and system for dynamic refinement of security policies". 2002-12-31.{{cite journal}}: Cite journal requires |journal= (help)
  10. "Sanctum Introduces AppScan: Industry's First Automated Web Application Security Audit Tool. - Free Online Library". www.thefreelibrary.com. Retrieved 2016-09-12.
  11. Network World. IDG Network World Inc. 2000-06-19.
  12. "Sanctum, Inc. cited as leader in key web security sector" . Retrieved 2016-09-12.