Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

8/25/2016
08:10 AM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

A Temperature-Check On The State Of Application Security

AppSec is more dangerous than network security but receives less than half the funding, according to new Ponemon study.

While most IT and security leaders believe that application security problems are inherently more risky than network security issues, appsec still doesn't get near the same kind of executive support and technical visibility that network security does, a new study out this week by Ponemon Institute shows. Fortunately, new trends in IT delivery like DevOps and continuous integration are making it possible to meet application security challenges that have hampered progress in the past. 

Examining the attitudes and practices of over IT leaders and practitioners, "Application Security in the Changing Risk Landscape" found that the majority of them believe the frequency and severity of attacks against the application layer are greater than against the network layer. Sponsored by F5 Networks, the study reports that 50% of respondents agreed that applications are attacks are more frequent and 58% agreed they are more severe.

The most commonly cited reasons that application-layer attacks are worse than network-layer attacks were that they're harder to detect and more difficult to contain. According to those surveyed, a lack of visibility in the application layer is the top barrier to achieving a strong application security posture.

In spite of the risks and challenges, application security still gets lackluster funding and support. The study shows that only 35% of respondents believe they have ample resources to detect vulnerabilities and 30% say they have enough resources to remediate those vulnerabilities. On average, the network security budget is more than double the application security budget across respondents' organizations.

In spite of a decade plus of strong advocacy for improved testing and mitigation practices within the security industry, most organizations still struggle to test regularly. A quarter of organizations still do no application testing for vulnerabilities at all, and another 33% have no pre-scheduled testing or only test annually. What's more, it appears that many organizations--about a third of them--largely depend upon the stop-gap measure of utilizing web application firewalls as their primary means of securing applications.   

One of the years-long difficulties that have hamstrung efforts to improve application security is that of accountability, due to the large number of stakeholders involved in developing, delivering, and operating software. 

"Fifty-six percent of respondents believe accountability for application security is shifting from IT to the end user or application owner," the report said. "However, at this time responsibility for ensuring the security of applications is dispersed throughout the organization." 

The shift to DevOps and continuous delivery pipelines could go a long way toward automating testing and moving responsibilities closer to the developer so that testing can be done earlier and in a more incremental fashion. About 71% of those surveyed believe that DevOps and continuous delivery stand to improve application delivery. The trick will be in how well testing procedures and technology can be streamlined into the overall automated testing framework.

"I believe that DevOps practices can be highly beneficial to application security as long as security testing is embedded into the automated testing we already do in DevOps to ensure that the apps we develop are both functionally robust and secure from the ground up," says Mike Convertino, CISO for F5.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
MarkF652
50%
50%
MarkF652,
User Rank: Apprentice
9/12/2016 | 1:22:14 PM
Re: Unsafe Code
Peter - You are spot on.  It is absolutely mindblowing that in 2016, we are still seeing AppSec receive the lack of attention that is deserves.  The short term pseudo-benefit that organizations realize is cost savings, but it only takes once for them to suffer a breach or loss of confidential data and that cost savings quickly reverses.  There really is no excuse, given that this type of effort can almost be 100% outsourced.  Funny enough, I remember, beginning in 2004, that I always thought the current year would be the year of AppSec.  I've been proven wrong, year after year, even though it has certainly garnered a lot of attention since then.  I do believe, as we see a younger generation of executives come online, that we will see a better understanding of the ramifications and the actions to mitigate.  Fingers crossed...

 
PZav
50%
50%
PZav,
User Rank: Author
8/30/2016 | 4:45:20 PM
Unsafe Code
It blows my mind that in 2016 there are still enterprises out there that don't vuln scan their apps. It would make me so nervous to have all that code out there twisting in the wind! There has to be business ramifications that aren't fully understood or are being ignored. I can't imagine that any enterprise benefits from ignoring this problem.  
How Attackers Infiltrate the Supply Chain & What to Do About It
Shay Nahari, Head of Red-Team Services at CyberArk,  7/16/2019
US Mayors Commit to Just Saying No to Ransomware
Robert Lemos, Contributing Writer,  7/16/2019
The Problem with Proprietary Testing: NSS Labs vs. CrowdStrike
Brian Monkman, Executive Director at NetSecOPEN,  7/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-12551
PUBLISHED: 2019-07-22
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.
CVE-2019-12552
PUBLISHED: 2019-07-22
In SweetScape 010 Editor 9.0.1, an integer overflow during the initialization of variables could allow an attacker to cause a denial of service.
CVE-2019-3414
PUBLISHED: 2019-07-22
All versions up to V1.19.20.02 of ZTE OTCP product are impacted by XSS vulnerability. Due to XSS, when an attacker invokes the security management to obtain the resources of the specified operation code owned by a user, the malicious script code could be transmitted in the parameter. If the front en...
CVE-2019-10102
PUBLISHED: 2019-07-22
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". Th...
CVE-2019-10102
PUBLISHED: 2019-07-22
aubio 0.4.8 and earlier is affected by: null pointer. The impact is: crash. The component is: filterbank. The attack vector is: pass invalid arguments to new_aubio_filterbank. The fixed version is: after commit eda95c9c22b4f0b466ae94c4708765eaae6e709e.