Browse Definitions :
Definition

runtime application self-protection (RASP)

Contributor(s): Ivy Wigmore

Runtime application self-protection (RASP) is security software that integrates with an application or its runtime environment during execution and constantly intercepts calls to the application to check their security, permitting those deemed safe and blocking those that could indicate an attack. RASP can protect against application attacks such as SQL injection because it can make sense of the commands involved and distinguish normal sequences from suspicious instructions or requests.

Application security is often neglected during software development and most apps lack the capacity to detect and block attacks. RASP adds security to applications that might otherwise be vulnerable. Because it has insight into what's happening within the application, RASP can analyze application behavior and the context in which it occurs, unlike perimeter-based protection, such as web application firewalls (WAF). That capacity makes it possible for the software to respond to attacks in real time.

RASP has two operational modes. In diagnostic mode, the software monitors calls to the application and sounds an alarm if a suspect call is made. In self-protection mode, RASP can prevent the execution of suspect instructions or terminate a user session.

RASP technology is designed for the two most popular application servers, Java virtual machine (JVM) and .NET Common Language Runtime. Additional implementations are expected. Vendors of RAST products include Contrast, HP, Immunio, Promon, Veracode, Waratek and WhiteHat Security.

Joseph Feiman first advocated the concept behind RASP in his 2014 research report, "Stop Protecting Your Apps; It's Time for Apps to Protect Themselves."

Jeff Williams delivers an introductory tutorial on RASP:

This was last updated in February 2017

Continue Reading About runtime application self-protection (RASP)

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

Powered by:

SearchCompliance

  • smart contract

    A smart contract, also known as a cryptocontract, is a computer program that directly controls the transfer of digital currencies...

  • risk map (risk heat map)

    A risk map, also known as a risk heat map, is a data visualization tool for communicating specific risks an organization faces. A...

  • internal audit (IA)

    An internal audit (IA) is an organizational initiative to monitor and analyze its own business operations in order to determine ...

SearchSecurity

SearchHealthIT

  • Health IT (health information technology)

    Health IT (health information technology) is the area of IT involving the design, development, creation, use and maintenance of ...

  • fee-for-service (FFS)

    Fee-for-service (FFS) is a payment model in which doctors, hospitals, and medical practices charge separately for each service ...

  • biomedical informatics

    Biomedical informatics is the branch of health informatics that uses data to help clinicians, researchers and scientists improve ...

SearchDisasterRecovery

  • risk mitigation

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a data center.

  • ransomware recovery

    Ransomware recovery is the process of resuming options following a cyberattack that demands payment in exchange for unlocking ...

  • natural disaster recovery

    Natural disaster recovery is the process of recovering data and resuming business operations following a natural disaster.

SearchStorage

  • RAID 5

    RAID 5 is a redundant array of independent disks configuration that uses disk striping with parity.

  • non-volatile storage (NVS)

    Non-volatile storage (NVS) is a broad collection of technologies and devices that do not require a continuous power supply to ...

  • petabyte

    A petabyte is a measure of memory or data storage capacity that is equal to 2 to the 50th power of bytes.

Close