Members

Technology Zones

Articles

Hosted By

MaximumASP

Info

Caleb Sima Profile

photo Caleb Sima (Caleb_Sima)
02 May 2006
Atlanta United States
CTO
http://www.spidynamics.com

Caleb Sima is the co-founder of SPI Dynamics, a Web application security products company. He currently serves as the CTO and director of SPI Labs, SPI Dynamics’ R&D security team. Prior to co-founding SPI Dynamics, Caleb was a member of the elite X-Force R&D team at Internet Security Systems, and worked as a security engineer for S1 Corporation. Caleb is a regular speaker and press resource on Web application security testing methods and has contributed to (IN)Secure Magazine, Baseline Magazine and been featured in the Associated Press.

This user has contributed 6 articles, 0 code samples and posted 0 messages in our discussion forums.

Technology Interests

      Articles & Tutorials

    • Effective Controls for Attaining Continuous Application Security Throughout the Web Application Development Life Cycle

      by Caleb_Sima

      Improving your Web application development process is one of the best ways to avoid security vulnerabilities and nasty surprises during security assessments. Learn about the points in the software development life cycle where additional security awareness and training is needed to ensure that your organization remains successful and secure.. Read full article

    • Web Application Vulnerability Assessment Essentials

      by Caleb_Sima

      It is important for a business to understand the fundamentals of running a vulnerability assessment in order to determine how one will be run and what can be expected from the results. A web application security scanner can automate the process, but a quality assessment may still require actual human eyes to catch specific issues. Learn more about the whys and hows of vulnerability assessments.. Read full article

    • Beyond Stored Procedures: Defense-in-Depth Against SQL Injection

      by Caleb_Sima

      While the awareness of SQL Injection attacks has grown in recent years, most developers’ knowledge of how to prevent such attacks is still inadequate. Stored procedures are only part of the answer, and it is also crucial to implement a defense-in-depth strategy. Learn how to build your defense-in-depth strategy, as well as why it is important to validate user input and how to add damage control to your strategy.. Read full article

    • The Software Development Life Cycle: When to Secure Your Process

      by Caleb_Sima

      Learn about six common weaknesses that lead to vulnerable code and security exploits, as well as how to resolve these problems without slowing aggressive product schedules. This article also includes a list of resources that further illustrate information security and secure coding and offer insight, principles, and processes that can be integrated to further improve software security.. Read full article

    • 13 Ways to Get your Developers on Board with Software Security

      by Caleb_Sima

      You may find that despite your best efforts, it can be difficult to get your developers on board with software security and ongoing security training. Developers are independent thinkers who need to be given solid reasons why they need to develop with software security in mind. In this article, you will learn 13 ways to get your developers to work with you, rather than against you, toward building a more secure final product. . Read full article

    • Implementing Effective Vulnerability Remediation Strategies Within the Web Application Development Lifecycle

      by Caleb_Sima

      After a security assessment has been performed as part of the web application development lifecycle, it is important to understand how to address and fix any application vulnerabilities that are uncovered. Learn more about the steps that should be taken during the remediation process, from categorization to testing and validation, and find out why collaboration among developers is critical for success.. Read full article