Issue No. 01 - January/February (2011 vol. 9)
ISSN: 1540-7993
pp: 91-92
Richard Bejtlich , General Electric
John Steven , Cigital
Gunnar Peterson , Arctec Group
Richard Bejtlich leads a conversation on how incident detection and response (IDR) teams' focus on detecting and preventing attacks has moved from targeting OSs to unauthorized-access-application functionality and data. He discusses why this makes IDR so much more difficult and what these new targets mean for IDR. Department editors Gunnar Peterson and John Steven respond with tactics on how application security teams can help.
incident detection and response, IDR, application security, software engineering, security and privacy

