Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

8/25/2016
08:10 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

A Temperature-Check On The State Of Application Security

AppSec is more dangerous than network security but receives less than half the funding, according to new Ponemon study.

While most IT and security leaders believe that application security problems are inherently more risky than network security issues, appsec still doesn't get near the same kind of executive support and technical visibility that network security does, a new study out this week by Ponemon Institute shows. Fortunately, new trends in IT delivery like DevOps and continuous integration are making it possible to meet application security challenges that have hampered progress in the past. 

Examining the attitudes and practices of over IT leaders and practitioners, "Application Security in the Changing Risk Landscape" found that the majority of them believe the frequency and severity of attacks against the application layer are greater than against the network layer. Sponsored by F5 Networks, the study reports that 50% of respondents agreed that applications are attacks are more frequent and 58% agreed they are more severe.

The most commonly cited reasons that application-layer attacks are worse than network-layer attacks were that they're harder to detect and more difficult to contain. According to those surveyed, a lack of visibility in the application layer is the top barrier to achieving a strong application security posture.

In spite of the risks and challenges, application security still gets lackluster funding and support. The study shows that only 35% of respondents believe they have ample resources to detect vulnerabilities and 30% say they have enough resources to remediate those vulnerabilities. On average, the network security budget is more than double the application security budget across respondents' organizations.

In spite of a decade plus of strong advocacy for improved testing and mitigation practices within the security industry, most organizations still struggle to test regularly. A quarter of organizations still do no application testing for vulnerabilities at all, and another 33% have no pre-scheduled testing or only test annually. What's more, it appears that many organizations--about a third of them--largely depend upon the stop-gap measure of utilizing web application firewalls as their primary means of securing applications.   

One of the years-long difficulties that have hamstrung efforts to improve application security is that of accountability, due to the large number of stakeholders involved in developing, delivering, and operating software. 

"Fifty-six percent of respondents believe accountability for application security is shifting from IT to the end user or application owner," the report said. "However, at this time responsibility for ensuring the security of applications is dispersed throughout the organization." 

The shift to DevOps and continuous delivery pipelines could go a long way toward automating testing and moving responsibilities closer to the developer so that testing can be done earlier and in a more incremental fashion. About 71% of those surveyed believe that DevOps and continuous delivery stand to improve application delivery. The trick will be in how well testing procedures and technology can be streamlined into the overall automated testing framework.

"I believe that DevOps practices can be highly beneficial to application security as long as security testing is embedded into the automated testing we already do in DevOps to ensure that the apps we develop are both functionally robust and secure from the ground up," says Mike Convertino, CISO for F5.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
MarkF652
50%
50%
MarkF652,
User Rank: Apprentice
9/12/2016 | 1:22:14 PM
Re: Unsafe Code
Peter - You are spot on.  It is absolutely mindblowing that in 2016, we are still seeing AppSec receive the lack of attention that is deserves.  The short term pseudo-benefit that organizations realize is cost savings, but it only takes once for them to suffer a breach or loss of confidential data and that cost savings quickly reverses.  There really is no excuse, given that this type of effort can almost be 100% outsourced.  Funny enough, I remember, beginning in 2004, that I always thought the current year would be the year of AppSec.  I've been proven wrong, year after year, even though it has certainly garnered a lot of attention since then.  I do believe, as we see a younger generation of executives come online, that we will see a better understanding of the ramifications and the actions to mitigate.  Fingers crossed...

 
PZav
50%
50%
PZav,
User Rank: Author
8/30/2016 | 4:45:20 PM
Unsafe Code
It blows my mind that in 2016 there are still enterprises out there that don't vuln scan their apps. It would make me so nervous to have all that code out there twisting in the wind! There has to be business ramifications that aren't fully understood or are being ignored. I can't imagine that any enterprise benefits from ignoring this problem.  
HackerOne Drops Mobile Voting App Vendor Voatz
Dark Reading Staff 3/30/2020
Limited-Time Free Offers to Secure the Enterprise Amid COVID-19
Curtis Franklin Jr., Senior Editor at Dark Reading,  3/31/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11565
PUBLISHED: 2020-04-06
An issue was discovered in the Linux kernel through 5.6.2. mpol_parse_str in mm/mempolicy.c has a stack-based out-of-bounds write because an empty nodelist is mishandled during mount option parsing, aka CID-aa9f7d5172fa.
CVE-2020-11558
PUBLISHED: 2020-04-05
An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_code_base.c does not properly decide when to make gf_isom_box_del calls. This leads to various use-after-free outcomes involving mdia_Read, gf_isom_delete_movie, and gf_isom_parse_m...
CVE-2020-11547
PUBLISHED: 2020-04-05
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.
CVE-2020-11548
PUBLISHED: 2020-04-05
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
CVE-2020-11542
PUBLISHED: 2020-04-04
3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring.