Impart and Chill Blog

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Understand Blocked Requests Faster with Rule Tracing

Impart Security
September 11, 2024
Read article

Shifting Application Security into the Runtime

Jonathan DiVincenzo
September 5, 2024
Read article

Safely test rate limit rules with Simulated Blocking

Impart Security
September 4, 2024
Read article

See what was blocked with blocking insights

Most API security tools fall short when it comes to explaining blocked requests. They can't detail what payloads were seen, what request attributes triggered a block, or how many requests were blocked. Impart's new Blocked Request Insights visualizations address these gaps, offering security teams a clear and comprehensive understanding of their blocked traffic.
Impart Security
July 31, 2024
Read article

Develop Firewall Rules Safely with Regression Testing

Firewall Regression Testing Now AvailableWe are thrilled to announce the launch of our latest innovation: Firewall Regression Testing. This powerful new feature empowers security teams to thoroughly test firewall rule changes before they impact production traffic, bringing modern development practices to firewall management.
Impart Security
July 25, 2024
Read article

The Future of Appsec is APIs

In this conversation, Matt Johansen and Brian Joe discuss API security and its evolution from traditional application security. First and foremost, they define what we mean by “API Security.” This involves a quick history lesson on the rise of microservices and decentralized applications. They also highlight the challenges and vulnerabilities associated with API security, such as broken authentication and authorization. We even get into how AI has impacted security testing and the need for innovation in response and enforcement! Overall, the discussion provides insights into the current state and future of API security. Join us to explore the evolution of web application firewalls (WAFs) and what they can and can not do in the ever-growing world of APIs. Matt’s favorite takeaway: Traditional WAFs inspected a single request and decided if it was good or bad. Next-gen WAFs added the dimension of looking at attack traffic over time instead of that single request. Impart, and modern API Security solutions are going beyond that 2nd dimension and bringing in a lot more context to make security decisions on API traffic.
Impart Security
July 24, 2024
Read article

Why WAF Logging fails

In conversations with many security teams, I've found a common frustration: relying on WAF access logs to secure their APIs and web apps. The unfortunate truth is that WAF logs don't work in practice. This post goes into detail about why.
Marc Harrison
July 23, 2024
Read article

WAFs don't protect against modern appsec threats

July 18, 2024
Read article

The evolution of WAF and RASP

Rami McCarthy did a great post on RASP last month touching on some of the history of RASP. I thought the post was great and did a great job focusing on the competitive landscape, industry factors, and technical barriers to entry. In this post, I wanted to dig deeper into the security outcomes (read: problems to solve) that tools like RASP and WAF achieve, and also explore a bit more in depth the future of both WAF and RASP in the modern era.
Brian Joe
July 16, 2024
Read article

Why WAF Rate Limiting isn't Enough

Brian Joe
June 27, 2024
Read article

Understanding the Dell Data Breach

Recently, Dell faced a significant data breach, where a threat actor exploited API vulnerabilities to steal 49 million customer records. This incident not only underscores the growing threat of API abuse but also highlights the necessity for robust security measures to protect sensitive data.In this blog post, we will delve into the details of the Dell data breach, identify the specific API vulnerabilities exploited, and discuss how tools like Impart can address these types of security flaws.
June 20, 2024
Read article

Test Firewall Rules with Lists

Impart Security
June 19, 2024
Read article