Application Security

8/25/2016
08:10 AM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

A Temperature-Check On The State Of Application Security

AppSec is more dangerous than network security but receives less than half the funding, according to new Ponemon study.

While most IT and security leaders believe that application security problems are inherently more risky than network security issues, appsec still doesn't get near the same kind of executive support and technical visibility that network security does, a new study out this week by Ponemon Institute shows. Fortunately, new trends in IT delivery like DevOps and continuous integration are making it possible to meet application security challenges that have hampered progress in the past. 

Examining the attitudes and practices of over IT leaders and practitioners, "Application Security in the Changing Risk Landscape" found that the majority of them believe the frequency and severity of attacks against the application layer are greater than against the network layer. Sponsored by F5 Networks, the study reports that 50% of respondents agreed that applications are attacks are more frequent and 58% agreed they are more severe.

The most commonly cited reasons that application-layer attacks are worse than network-layer attacks were that they're harder to detect and more difficult to contain. According to those surveyed, a lack of visibility in the application layer is the top barrier to achieving a strong application security posture.

In spite of the risks and challenges, application security still gets lackluster funding and support. The study shows that only 35% of respondents believe they have ample resources to detect vulnerabilities and 30% say they have enough resources to remediate those vulnerabilities. On average, the network security budget is more than double the application security budget across respondents' organizations.

In spite of a decade plus of strong advocacy for improved testing and mitigation practices within the security industry, most organizations still struggle to test regularly. A quarter of organizations still do no application testing for vulnerabilities at all, and another 33% have no pre-scheduled testing or only test annually. What's more, it appears that many organizations--about a third of them--largely depend upon the stop-gap measure of utilizing web application firewalls as their primary means of securing applications.   

One of the years-long difficulties that have hamstrung efforts to improve application security is that of accountability, due to the large number of stakeholders involved in developing, delivering, and operating software. 

"Fifty-six percent of respondents believe accountability for application security is shifting from IT to the end user or application owner," the report said. "However, at this time responsibility for ensuring the security of applications is dispersed throughout the organization." 

The shift to DevOps and continuous delivery pipelines could go a long way toward automating testing and moving responsibilities closer to the developer so that testing can be done earlier and in a more incremental fashion. About 71% of those surveyed believe that DevOps and continuous delivery stand to improve application delivery. The trick will be in how well testing procedures and technology can be streamlined into the overall automated testing framework.

"I believe that DevOps practices can be highly beneficial to application security as long as security testing is embedded into the automated testing we already do in DevOps to ensure that the apps we develop are both functionally robust and secure from the ground up," says Mike Convertino, CISO for F5.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
MarkF652
50%
50%
MarkF652,
User Rank: Apprentice
9/12/2016 | 1:22:14 PM
Re: Unsafe Code
Peter - You are spot on.  It is absolutely mindblowing that in 2016, we are still seeing AppSec receive the lack of attention that is deserves.  The short term pseudo-benefit that organizations realize is cost savings, but it only takes once for them to suffer a breach or loss of confidential data and that cost savings quickly reverses.  There really is no excuse, given that this type of effort can almost be 100% outsourced.  Funny enough, I remember, beginning in 2004, that I always thought the current year would be the year of AppSec.  I've been proven wrong, year after year, even though it has certainly garnered a lot of attention since then.  I do believe, as we see a younger generation of executives come online, that we will see a better understanding of the ramifications and the actions to mitigate.  Fingers crossed...

 
PZav
50%
50%
PZav,
User Rank: Author
8/30/2016 | 4:45:20 PM
Unsafe Code
It blows my mind that in 2016 there are still enterprises out there that don't vuln scan their apps. It would make me so nervous to have all that code out there twisting in the wind! There has to be business ramifications that aren't fully understood or are being ignored. I can't imagine that any enterprise benefits from ignoring this problem.  
12 Free, Ready-to-Use Security Tools
Steve Zurier, Freelance Writer,  10/12/2018
Most IT Security Pros Want to Change Jobs
Dark Reading Staff 10/12/2018
6 Security Trends for 2018/2019
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/15/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10839
PUBLISHED: 2018-10-16
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
CVE-2018-13399
PUBLISHED: 2018-10-16
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
CVE-2018-18381
PUBLISHED: 2018-10-16
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type header during the uploading of image attachments.
CVE-2018-18382
PUBLISHED: 2018-10-16
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.