Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

5/10/2010
05:45 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

F5 Networks Files Patent Lawsuit Against WAF Vendor Imperva

Calls for injunction against Imperva for sale and use of its Web application protocol security technology

In a rare patent infringement cases involving Web application security, F5 Networks is suing Imperva for allegedly using its patented application security technology in Imperva's Web application firewall and other security products.

F5's patent suit, which the networking and security company filed on May 4, calls for both a preliminary and permanent injunction barring Imperva and others from developing, selling -- and using -- its Secure Sphere and other products that infringe on F5's so-called "Method and System for Extracting Application Protocol Characteristics" patent, which was awarded by the U.S. Patent and Trademark Office in 2001. The patent, number 6,311,278, is also referred to as the "'278 patent" in F5's filing.

The lawsuit calls for Imperva to pay F5 for "damages to compensate F5 for the infringement that has occurred," as well as court and attorney costs. "Imperva's acts of infringement have caused, and will continue to cause, substantial and irreparable injury to F5 and its rights," the F5 patent suit says. "On information and belief, Imperva committed such infringement with knowledge of the '278 patent, and such infringement was committed willfully."

[UPDATE: 5/12/10]: Imperva issued a statement today calling the lawsuit "baseless," saying that F5 turned to litigation after its WAF didn't sell well. "A few years ago, F5 began to sell its web application firewall. Few bought it, choosing instead Imperva's superior product. Unable to compete on the merits, F5 now reverts to litigation, asserting an old 1999 patent. Imperva doesn't use—or need—F5's technology," Imperva said in its statement.

"Imperva will vigorously contest this matter on behalf of itself and its customers," it said.

F5, meanwhile, provided a brief statement earlier in the week: "F5 thinks it is appropriate to take reasonable measures to defend our intellectual property rights. However, it is our current policy not to comment on pending litigation."

This isn't the first patent dispute over Web application security technology. In August 2007, Cenzic sued SPI Dynamics, now part of HP, for using its patented "fault injection" technology. SPI also filed a suit against Cenzic, and in October Cenzic and HP/SPI settled the legal matter with a cross-licensing agreement.

The patented security technology in dispute in the F5 and Imperva case is "directed generally at methods and systems for defining a set of allowable actions regarding a network application," says F5's filing with the U.S. District Court for the Western District of Washington in Seattle.

Robert Hansen, a.k.a. "RSnake" and founder of SecTheory, says F5's patented technology basically identifies which protocol the client is using to communicate with the server and defines which protocols are allowed, or not: "So if someone were to put a Web server on Port 23, it would be good if the WAF could identify that it's not an FTP server but a Web server, for example," Hansen says. "And certain methods like GET and POST might be [allowed], but PUT and DELETE would not be," for instance, he says.

The technology could also identify things like cross-site scripting (XSS) or cross-site request forgery (CSRF) attacks, he says.

Hansen says if Imperva loses the case, it's likely it would have to modify its products by removing protocol detection altogether, or performing that function using a different method. "I just hope things like this [lawsuit] don't negatively impact innovation" in Web security, he says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
Slideshows
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
Commentary
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-31755
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
CVE-2021-31756
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /gofrom/setwanType allows attackers to execute arbitrary code on the system via a crafted post request. This occurs when input vector controlled by malicious attack get copie...
CVE-2021-31757
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setVLAN allows attackers to execute arbitrary code on the system via a crafted post request.
CVE-2021-31758
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setportList allows attackers to execute arbitrary code on the system via a crafted post request.
CVE-2021-31458
PUBLISHED: 2021-05-07
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handlin...