openskills.info
Course Preview

Runtime Application Security

Runtime application security places detection and protection inside a running application or its language runtime. It uses execution context to recognize harmful operations and can report or block them before they complete.

itOffensive security and application security

Don't Panic - Runtime Application Security

Runtime application security observes and controls software while it executes. Its best-known form is runtime application self-protection, or RASP. A RASP control runs inside the application process or language runtime. That position lets it examine an operation with application context before the operation reaches a sensitive sink such as a database, file system, network client, template engine, or command interpreter.

NIST describes RASP as runtime instrumentation that detects and blocks exploitation by using information from executing software. That location distinguishes it from a web application firewall. A WAF inspects network requests at a boundary. RASP can see what the application does with a request after parsing, routing, decoding, and business logic have changed it. The controls complement each other because each has a different view.

A typical path instruments selected functions, associates untrusted input with the request, and watches that data move toward sinks. At a sink, the sensor combines the operation, arguments, data origin, call path, user, route, and policy. Policy may permit, record, or interrupt. Common modes are off, monitor, and block. Virtual patches are narrowly scoped runtime rules that reduce exploitability while code is fixed.

Coverage is limited by supported languages, frameworks, versions, and process architectures. Unsupported workers and native extensions create gaps that a green agent status will not reveal. Start in monitor mode long enough to tune false positives, then block high-confidence classes. Keep virtual patches owned and time-bounded so they do not become permanent policy debt.

Read the Intro for the protection path and WAF contrast. Use the Cheatsheet when you need the component and mode map. Landscape places RASP beside related application security tools; Updates tracks NIST SP 800-53 and OWASP AppSensor pages this course uses for the vendor-neutral framing.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources