SlideShare a Scribd company logo
1© 2017 Rogue Wave Software, Inc. All Rights Reserved. 1
Speed and security
for your PHP application
2© 2017 Rogue Wave Software, Inc. All Rights Reserved. 2
Slavey Karadzhov
Senior solutions consultant
Rogue Wave Software
Presenters
Dr. Johannes Dahse
CEO & Co-Founder
RIPS Technologies
Kai Schmithuesen
Account executive - Zend
Rogue Wave Software
3© 2017 Rogue Wave Software, Inc. All Rights Reserved. 3
Agenda
4© 2017 Rogue Wave Software, Inc. All Rights Reserved. 4
Agenda
• The importance of speed and security for your business
• Boosting your PHP with Zend Server
– Understand and analyze bottlenecks
– Optimize Code / Tune Settings
– Develop
• Fast but is it secure
– Analyze your source code with ease
– Protect production servers from vulnerabilities
• Competition
• Q&A
5© 2017 Rogue Wave Software, Inc. All Rights Reserved. 5
Click to watch the full webinar
6© 2017 Rogue Wave Software, Inc. All Rights Reserved. 6
The importance of speed and security
for your business
7© 2017 Rogue Wave Software, Inc. All Rights Reserved. 7
How performance impacts your business
If an e-commerce site is making $100,000 per day, a 1 second page
delay could potentially cost you $2.5 million in lost sales every year
Mobile sites that loaded in 5 seconds earned almost double the
revenue of sites that took 19 seconds to load
73%
of mobile internet users
have encountered a
website that was
too slow to load
51%
of mobile internet users
have encountered a
website that crashed, froze, or received
an error
A 1 second delay in page
response can result in a 7%
reduction in conversions
47%
of consumers expect a web page to
load in
2 seconds or less
8© 2017 Rogue Wave Software, Inc. All Rights Reserved. 8
How security impacts your business
● Cyber criminals perform 1,000,000 web attacks per day
● General web attacks affect everyone
○ Website infection for malware/phishing campaigns
○ Web server compromise for botnets, DDoS attacks
● Targeted web attacks
○ Steal intellectual property
○ Steal sensitive data (credit cards, PII, passwords)
● $200,000 average data breach costs
● 50,000 websites are hacked daily
9© 2017 Rogue Wave Software, Inc. All Rights Reserved. 9
Get up to speed with Zend Server
10© 2017 Rogue Wave Software, Inc. All Rights Reserved. 10
Speed depends on ...
11© 2017 Rogue Wave Software, Inc. All Rights Reserved. 11
Speeding up an app is ...
Continuous process that involves
● Understand and analyze bottlenecks
○ auto-scaling
○ caching
● Optimize Code / Tune Settings
○ with or without human intervention
● Develop
12© 2017 Rogue Wave Software, Inc. All Rights Reserved. 12
In PHP speed depends on ...
•The Zend PHP Engine
•Proven PHP modules
•PHP components to allow OpCache, DataCache and PageCache
•First class monitoring tools
13© 2017 Rogue Wave Software, Inc. All Rights Reserved. 13
Zend Server is speed
•Perfected from the developers of the Zend PHP engine
•With seamless optimizations built in the core
•With multiple components that boost your PHP applications
•And monitoring that helps you understand your PHP application.
14© 2017 Rogue Wave Software, Inc. All Rights Reserved. 14
Peace of mind with RIPS Technologies
17© 2017 Rogue Wave Software, Inc. All Rights Reserved. 17
Top security vulnerabilities used in web attacks
websites have at least one
medium-severe vulnerability
40%
Cross-site scripting
Inject malicious JavaScript code
rendered by visitors
24%
SQL injection
Manipulate database query to
retrieve sensitive data
7%
Path traversal
Manipulate file operation to steal
sensitive files
4%
File inclusion
Induce a file for code execution
84%
18© 2017 Rogue Wave Software, Inc. All Rights Reserved. 18
Security challenges
Challenge:
Stay up-to-date with
all attack
techniques / pitfalls
Security
awareness
Challenge:
Growing code and
team sizes
Secure
development
Challenge:
Time to market
pressure
Security
testing
Compliance requirements
GDPR, PCI DSS, HIPAA, OWASP ASVS, OWASP Top 10
19© 2017 Rogue Wave Software, Inc. All Rights Reserved. 19
RIPS Code Analysis scans your application
● RIPS scans your source code and detects security bugs
● Technology leader for PHP Static Application Security Testing (SAST)
● Unique language-specific approach, built by security experts
20© 2017 Rogue Wave Software, Inc. All Rights Reserved. 20
RIPS Code Analysis detects unknown security issues
● Supports PHP 3-7, large code bases, and frameworks
● Scans your source code within minutes for
○ 100+ security vulnerability categories
○ 60+ code quality issue categories
○ 40+ misconfiguration categories
● Track record of unknown vulnerabilities reported in popular cores:
21© 2017 Rogue Wave Software, Inc. All Rights Reserved. 21
RIPS Code Analysis protects your application
● Seamless integration into every step of your SDLC setup
● Block vulnerable code before it is deployed on your production server
sonarqube
22© 2017 Rogue Wave Software, Inc. All Rights Reserved. 22
Visit us at ZendCon → 15th – 17th October Las
Vegas
Sponsored by:
23© 2017 Rogue Wave Software, Inc. All Rights Reserved. 23
Visit us at PHP.Ruhr → 11th November Dortmund
Sponsored by:
24© 2017 Rogue Wave Software, Inc. All Rights Reserved. 24
Interested to give it a test drive?
25© 2017 Rogue Wave Software, Inc. All Rights Reserved. 25
Competition
What we will do:
We will contact you to review your projects and pick the three most interesting in terms of scope and complexity. We will help you to
install Zend Server including RIPS plugin on your infrastructure for your project and support you during a three month trial phase
We are looking to give three projects the chance to test Zend Server and RIPS
What you will do:
Type “Interested” into the Q&A panel
26© 2017 Rogue Wave Software, Inc. All Rights Reserved. 26
Click to watch the full webinar
27© 2017 Rogue Wave Software, Inc. All Rights Reserved. 27
Q&A
28© 2017 Rogue Wave Software, Inc. All Rights Reserved. 28
Thank You
29© 2017 Rogue Wave Software, Inc. All Rights Reserved. 29
Speed and security for your PHP
application
Kai Schmithüsen
Account Executive Zend EMEA
Slavey Karadzhov
Senior Consultant, Professional Services @ RogueWave
Johannes Dahse
CEO & Co-founder @ RIPS Technologies
30© 2017 Rogue Wave Software, Inc. All Rights Reserved. 30
References
•https://developer.akamai.com/blog/2016/09/14/mobile-load-time-user-
abandonment
•https://pages.zend.com/rs/zendtechnologies/images/PHP7-
Performance%20Infographic.pdf
•https://www.zimuel.it/blog/strong-cryptography-in-php
•https://www.infopoint-security.de/media/Trustwave_2018-
GSR_20180329_Interactive.pdf
31© 2017 Rogue Wave Software, Inc. All Rights Reserved. 31
Click to watch the full webinar

More Related Content

PDF
Develop microservices in php
PDF
Automated Server Administration for DevSecOps
PPTX
Third Party Performance (Velocity, 2014)
PDF
Serverless Security: Are you ready for the Future?
PDF
Serverless Security: What's Left To Protect
PDF
MRA AMA: Ingenious: The Journey to Service Mesh using a Microservices Demo App
PDF
[Wroclaw #9] The purge - dealing with secrets in Opera Software
PDF
DevSecCon London 2017: Hands-on secure software development from design to de...
Develop microservices in php
Automated Server Administration for DevSecOps
Third Party Performance (Velocity, 2014)
Serverless Security: Are you ready for the Future?
Serverless Security: What's Left To Protect
MRA AMA: Ingenious: The Journey to Service Mesh using a Microservices Demo App
[Wroclaw #9] The purge - dealing with secrets in Opera Software
DevSecCon London 2017: Hands-on secure software development from design to de...

What's hot (20)

PDF
Anatomy of a Cloud Hack
PPTX
Session: A Reference Architecture for Running Modern APIs with NGINX Unit and...
PDF
Optimizing ModSecurity on NGINX and NGINX Plus
PPTX
Using Puppet With A Secrets Server
PPT
Automating security test using Selenium and OWASP ZAP - Practical DevSecOps
PDF
Secure Architecture and Programming 101
PPTX
Cybereason - behind the HackingTeam infection server
PDF
Cover Your Apps While Still Using npm
PPTX
Authenticating to HashiCorp Vault in a VMware vSphere Environment
PDF
JavaOne 2014: Retrofitting OAuth 2.0 Security into Existing REST Services - C...
PDF
[201702]Qubit Security Pitch deck
PPTX
Tests your pipeline might be missing
PDF
Secure your Hadoop clusters with BlueTalon SecureAccess for WebHDFS
PDF
Mitigate potential compliance risks
PDF
CodeFest 2014 - Pentesting client/server API
PPTX
2020 05-tech saturday-devsecops-#2-v03
PPTX
Experiences Bringing CD to a DoD Project
PDF
Recipe for good secrets management
PDF
Are you ready to be hacked?
PDF
Securing your EmberJS Application
Anatomy of a Cloud Hack
Session: A Reference Architecture for Running Modern APIs with NGINX Unit and...
Optimizing ModSecurity on NGINX and NGINX Plus
Using Puppet With A Secrets Server
Automating security test using Selenium and OWASP ZAP - Practical DevSecOps
Secure Architecture and Programming 101
Cybereason - behind the HackingTeam infection server
Cover Your Apps While Still Using npm
Authenticating to HashiCorp Vault in a VMware vSphere Environment
JavaOne 2014: Retrofitting OAuth 2.0 Security into Existing REST Services - C...
[201702]Qubit Security Pitch deck
Tests your pipeline might be missing
Secure your Hadoop clusters with BlueTalon SecureAccess for WebHDFS
Mitigate potential compliance risks
CodeFest 2014 - Pentesting client/server API
2020 05-tech saturday-devsecops-#2-v03
Experiences Bringing CD to a DoD Project
Recipe for good secrets management
Are you ready to be hacked?
Securing your EmberJS Application
Ad

Similar to Speed and security for your PHP application (20)

PPTX
Ongoing management of your PHP 7 application
PDF
Enterprise-class mobile apps: Moving your business into the future - Amy Ande...
PPTX
Building and managing applications fast for IBM i
PPTX
Keeping up with PHP
PDF
2013 - Dustin whittle - Escalando PHP en la vida real
PPTX
Continuous security: Bringing agility to the secure development lifecycle
PPTX
To PHP 7 and beyond
PPTX
Northeast PHP - High Performance PHP
PDF
Web hackingtools 2015
PDF
Web hackingtools 2015
PDF
Create code confidence for better application security
PPT
Top 10 Scalability Mistakes
PPT
Top 30 Scalability Mistakes
PPTX
The road towards better automotive cybersecurity
PPT
Apache Con 2008 Top 10 Mistakes
PPTX
Php security common 2011
PPT
Top 10 Scalability Mistakes
PPT
Web Application Hacking 2004
PPTX
Secure programming with php
PPTX
Optimizing performance
Ongoing management of your PHP 7 application
Enterprise-class mobile apps: Moving your business into the future - Amy Ande...
Building and managing applications fast for IBM i
Keeping up with PHP
2013 - Dustin whittle - Escalando PHP en la vida real
Continuous security: Bringing agility to the secure development lifecycle
To PHP 7 and beyond
Northeast PHP - High Performance PHP
Web hackingtools 2015
Web hackingtools 2015
Create code confidence for better application security
Top 10 Scalability Mistakes
Top 30 Scalability Mistakes
The road towards better automotive cybersecurity
Apache Con 2008 Top 10 Mistakes
Php security common 2011
Top 10 Scalability Mistakes
Web Application Hacking 2004
Secure programming with php
Optimizing performance
Ad

More from Zend by Rogue Wave Software (20)

PDF
Building web APIs in PHP with Zend Expressive
PDF
Speed up web APIs with Expressive and Swoole (PHP Day 2018)
PDF
The Sodium crypto library of PHP 7.2 (PHP Day 2018)
PDF
Develop web APIs in PHP using middleware with Expressive (Code Europe)
PDF
Middleware web APIs in PHP 7.x
PDF
Developing web APIs using middleware in PHP 7
PDF
The Docker development template for PHP
PDF
The most exciting features of PHP 7.1
PPTX
Unit testing for project managers
PDF
The new features of PHP 7
PPTX
Deploying PHP apps on the cloud
PPTX
Data is dead. Long live data!
PPTX
Resolving problems & high availability
PPTX
Developing apps faster
PPTX
Fundamentals of performance tuning PHP on IBM i
PPTX
Getting started with PHP on IBM i
PDF
Continuous Delivery e-book
PDF
Standard CMS on standard PHP Stack - Drupal and Zend Server
PDF
Dev & Prod - PHP Applications in the Cloud
PDF
The Truth about Lambdas and Closures in PHP
Building web APIs in PHP with Zend Expressive
Speed up web APIs with Expressive and Swoole (PHP Day 2018)
The Sodium crypto library of PHP 7.2 (PHP Day 2018)
Develop web APIs in PHP using middleware with Expressive (Code Europe)
Middleware web APIs in PHP 7.x
Developing web APIs using middleware in PHP 7
The Docker development template for PHP
The most exciting features of PHP 7.1
Unit testing for project managers
The new features of PHP 7
Deploying PHP apps on the cloud
Data is dead. Long live data!
Resolving problems & high availability
Developing apps faster
Fundamentals of performance tuning PHP on IBM i
Getting started with PHP on IBM i
Continuous Delivery e-book
Standard CMS on standard PHP Stack - Drupal and Zend Server
Dev & Prod - PHP Applications in the Cloud
The Truth about Lambdas and Closures in PHP

Recently uploaded (20)

PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
Understanding Forklifts - TECH EHS Solution
PDF
2025 Textile ERP Trends: SAP, Odoo & Oracle
PDF
medical staffing services at VALiNTRY
PDF
Flood Susceptibility Mapping Using Image-Based 2D-CNN Deep Learnin. Overview ...
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PPTX
Odoo POS Development Services by CandidRoot Solutions
PDF
System and Network Administration Chapter 2
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PDF
Nekopoi APK 2025 free lastest update
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PDF
Adobe Illustrator 28.6 Crack My Vision of Vector Design
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PDF
AI in Product Development-omnex systems
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PDF
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
PPTX
Introduction to Artificial Intelligence
PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PDF
How to Migrate SBCGlobal Email to Yahoo Easily
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
Understanding Forklifts - TECH EHS Solution
2025 Textile ERP Trends: SAP, Odoo & Oracle
medical staffing services at VALiNTRY
Flood Susceptibility Mapping Using Image-Based 2D-CNN Deep Learnin. Overview ...
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
Odoo POS Development Services by CandidRoot Solutions
System and Network Administration Chapter 2
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
Nekopoi APK 2025 free lastest update
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
Adobe Illustrator 28.6 Crack My Vision of Vector Design
Design an Analysis of Algorithms II-SECS-1021-03
AI in Product Development-omnex systems
Wondershare Filmora 15 Crack With Activation Key [2025
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
Introduction to Artificial Intelligence
Navsoft: AI-Powered Business Solutions & Custom Software Development
How to Migrate SBCGlobal Email to Yahoo Easily
Internet Downloader Manager (IDM) Crack 6.42 Build 41

Speed and security for your PHP application

  • 1. 1© 2017 Rogue Wave Software, Inc. All Rights Reserved. 1 Speed and security for your PHP application
  • 2. 2© 2017 Rogue Wave Software, Inc. All Rights Reserved. 2 Slavey Karadzhov Senior solutions consultant Rogue Wave Software Presenters Dr. Johannes Dahse CEO & Co-Founder RIPS Technologies Kai Schmithuesen Account executive - Zend Rogue Wave Software
  • 3. 3© 2017 Rogue Wave Software, Inc. All Rights Reserved. 3 Agenda
  • 4. 4© 2017 Rogue Wave Software, Inc. All Rights Reserved. 4 Agenda • The importance of speed and security for your business • Boosting your PHP with Zend Server – Understand and analyze bottlenecks – Optimize Code / Tune Settings – Develop • Fast but is it secure – Analyze your source code with ease – Protect production servers from vulnerabilities • Competition • Q&A
  • 5. 5© 2017 Rogue Wave Software, Inc. All Rights Reserved. 5 Click to watch the full webinar
  • 6. 6© 2017 Rogue Wave Software, Inc. All Rights Reserved. 6 The importance of speed and security for your business
  • 7. 7© 2017 Rogue Wave Software, Inc. All Rights Reserved. 7 How performance impacts your business If an e-commerce site is making $100,000 per day, a 1 second page delay could potentially cost you $2.5 million in lost sales every year Mobile sites that loaded in 5 seconds earned almost double the revenue of sites that took 19 seconds to load 73% of mobile internet users have encountered a website that was too slow to load 51% of mobile internet users have encountered a website that crashed, froze, or received an error A 1 second delay in page response can result in a 7% reduction in conversions 47% of consumers expect a web page to load in 2 seconds or less
  • 8. 8© 2017 Rogue Wave Software, Inc. All Rights Reserved. 8 How security impacts your business ● Cyber criminals perform 1,000,000 web attacks per day ● General web attacks affect everyone ○ Website infection for malware/phishing campaigns ○ Web server compromise for botnets, DDoS attacks ● Targeted web attacks ○ Steal intellectual property ○ Steal sensitive data (credit cards, PII, passwords) ● $200,000 average data breach costs ● 50,000 websites are hacked daily
  • 9. 9© 2017 Rogue Wave Software, Inc. All Rights Reserved. 9 Get up to speed with Zend Server
  • 10. 10© 2017 Rogue Wave Software, Inc. All Rights Reserved. 10 Speed depends on ...
  • 11. 11© 2017 Rogue Wave Software, Inc. All Rights Reserved. 11 Speeding up an app is ... Continuous process that involves ● Understand and analyze bottlenecks ○ auto-scaling ○ caching ● Optimize Code / Tune Settings ○ with or without human intervention ● Develop
  • 12. 12© 2017 Rogue Wave Software, Inc. All Rights Reserved. 12 In PHP speed depends on ... •The Zend PHP Engine •Proven PHP modules •PHP components to allow OpCache, DataCache and PageCache •First class monitoring tools
  • 13. 13© 2017 Rogue Wave Software, Inc. All Rights Reserved. 13 Zend Server is speed •Perfected from the developers of the Zend PHP engine •With seamless optimizations built in the core •With multiple components that boost your PHP applications •And monitoring that helps you understand your PHP application.
  • 14. 14© 2017 Rogue Wave Software, Inc. All Rights Reserved. 14 Peace of mind with RIPS Technologies
  • 15. 17© 2017 Rogue Wave Software, Inc. All Rights Reserved. 17 Top security vulnerabilities used in web attacks websites have at least one medium-severe vulnerability 40% Cross-site scripting Inject malicious JavaScript code rendered by visitors 24% SQL injection Manipulate database query to retrieve sensitive data 7% Path traversal Manipulate file operation to steal sensitive files 4% File inclusion Induce a file for code execution 84%
  • 16. 18© 2017 Rogue Wave Software, Inc. All Rights Reserved. 18 Security challenges Challenge: Stay up-to-date with all attack techniques / pitfalls Security awareness Challenge: Growing code and team sizes Secure development Challenge: Time to market pressure Security testing Compliance requirements GDPR, PCI DSS, HIPAA, OWASP ASVS, OWASP Top 10
  • 17. 19© 2017 Rogue Wave Software, Inc. All Rights Reserved. 19 RIPS Code Analysis scans your application ● RIPS scans your source code and detects security bugs ● Technology leader for PHP Static Application Security Testing (SAST) ● Unique language-specific approach, built by security experts
  • 18. 20© 2017 Rogue Wave Software, Inc. All Rights Reserved. 20 RIPS Code Analysis detects unknown security issues ● Supports PHP 3-7, large code bases, and frameworks ● Scans your source code within minutes for ○ 100+ security vulnerability categories ○ 60+ code quality issue categories ○ 40+ misconfiguration categories ● Track record of unknown vulnerabilities reported in popular cores:
  • 19. 21© 2017 Rogue Wave Software, Inc. All Rights Reserved. 21 RIPS Code Analysis protects your application ● Seamless integration into every step of your SDLC setup ● Block vulnerable code before it is deployed on your production server sonarqube
  • 20. 22© 2017 Rogue Wave Software, Inc. All Rights Reserved. 22 Visit us at ZendCon → 15th – 17th October Las Vegas Sponsored by:
  • 21. 23© 2017 Rogue Wave Software, Inc. All Rights Reserved. 23 Visit us at PHP.Ruhr → 11th November Dortmund Sponsored by:
  • 22. 24© 2017 Rogue Wave Software, Inc. All Rights Reserved. 24 Interested to give it a test drive?
  • 23. 25© 2017 Rogue Wave Software, Inc. All Rights Reserved. 25 Competition What we will do: We will contact you to review your projects and pick the three most interesting in terms of scope and complexity. We will help you to install Zend Server including RIPS plugin on your infrastructure for your project and support you during a three month trial phase We are looking to give three projects the chance to test Zend Server and RIPS What you will do: Type “Interested” into the Q&A panel
  • 24. 26© 2017 Rogue Wave Software, Inc. All Rights Reserved. 26 Click to watch the full webinar
  • 25. 27© 2017 Rogue Wave Software, Inc. All Rights Reserved. 27 Q&A
  • 26. 28© 2017 Rogue Wave Software, Inc. All Rights Reserved. 28 Thank You
  • 27. 29© 2017 Rogue Wave Software, Inc. All Rights Reserved. 29 Speed and security for your PHP application Kai Schmithüsen Account Executive Zend EMEA Slavey Karadzhov Senior Consultant, Professional Services @ RogueWave Johannes Dahse CEO & Co-founder @ RIPS Technologies
  • 28. 30© 2017 Rogue Wave Software, Inc. All Rights Reserved. 30 References •https://developer.akamai.com/blog/2016/09/14/mobile-load-time-user- abandonment •https://pages.zend.com/rs/zendtechnologies/images/PHP7- Performance%20Infographic.pdf •https://www.zimuel.it/blog/strong-cryptography-in-php •https://www.infopoint-security.de/media/Trustwave_2018- GSR_20180329_Interactive.pdf
  • 29. 31© 2017 Rogue Wave Software, Inc. All Rights Reserved. 31 Click to watch the full webinar