Attacks/Breaches
3/23/2016
10:30 AM
Preston Hogue
Preston Hogue
Commentary
Connect Directly
Twitter
RSS
E-Mail vvv
100%
0%

Think Risk When You Talk About Application Security Today

Security from a risk-based perspective puts the focus on component failures and provides robust security for the ultimate target of most attacks -- company, customer and personal data.

The definition of application security has not evolved in parallel with the current state of applications. Let me explain. Twenty years ago, applications mainly operated independently of the Internet. During this time, the process for securing apps was simply adhering to best practices for secure coding throughout the software development lifecycle. But, it’s no longer the late 90’s. While secure coding is still an essential foundation to application security, it’s only one piece of a much larger puzzle.

Security professionals must now expand our definition of application security to include a risk-based perspective that accounts for the vast number of threats we must defend against. In doing so, we’ll improve the security posture across all facets of our apps and their deployment, thereby safeguarding our data and businesses. Looking at app security from a risk-based perspective puts focus on component failures, and provides robust security for the ultimate target of most attacks—company, customer, and personal data.

Today’s attackers have a convenient route to data through the application, but a risk-based approach accounts for vulnerabilities that secure coding can’t protect against. This approach includes analyzing the exposed elements of an application, and then developing a holistic security strategy for that app in its entirety. Attackers only need one component of an app left unaccounted for in order to compromise it -- whether it’s a code vulnerability, compromised identity, network availability, weak encryption, or DNS. And once attackers are inside, the entire application, as well as the data it houses, will be affected.

Application availability is a great example of a threat beyond the scope of secure coding. Since most apps today are Internet-based, a volumetric DDoS attack can cripple, or even take them down, rendering even the most securely-written code useless. Another threat vector to consider is confidentiality. What happens when a password is stolen? The application can be compromised and its data exposed.

This situation will not get any easier. There are approximately one billion Web apps in existence today. The rapid growth of the Internet of Things—and the applications that go along with it—will lead to apps numbering in the billions, and it’s naive to think that all of them will be securely coded.

We must immediately rethink our definition of application security so we’re in a better position to effectively secure all the components that make up our apps, safeguard our data, and protect our businesses.  

Related Content: 

 

Interop 2016 Las VegasFind out more about security threats at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Click here to register. 

Preston Hogue is the Director of Security Marketing Architecture at F5 Networks and serves as a worldwide security evangelist for the company. Previously, he was a Security Product Manager at F5, specializing in network security Governance, Risk, and Compliance (GRC). He ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This is a secure windows pc.
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.