Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

1/15/2014
11:06 AM
Jeff Williams
Jeff Williams
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

What Healthcare Can Teach Us About App Security

The Centers for Disease Control protects people from health threats and increases the health security of our nation. It's a mission that's not so different from InfoSec.

Here’s our challenge: our increasing reliance on software is occurring exactly when two other trends are making security more difficult. First, software size, complexity, interconnection, and even development speed are increasing rapidly. Second, advances in software technology are rapidly making traditional security scanners and code analyzers obsolete. Seriously… this won’t end well.

Poor visibility is poor security
Most organizations, even those with "mature" application security programs, have terrible visibility into the security of their application portfolios. They might be tracking some risks from penetration tests or automated scans. They might have a spotty application and component inventory. But when you get right down to it, they probably have very little real evidence that their defenses are correct and properly used across their application portfolios. And the information that they have gathered is so far out of date that it is of little use to development projects.

Ironically, the biggest risk in a risk assessment report isn’t even captured in its pages: the risk that the assessment itself has missed something important. Typical risk assessments don’t capture all the details about what code was covered, which defenses were checked, and what tests were performed. So, for example, if an assessment doesn’t cover authentication or access control (most don’t), the report reveals nothing, and the development team is left with a very dangerous false sense of security.

With a little tweaking and some perspective, we can transform techniques like dynamic scanning, static analysis, penetration testing, code review, architecture review, and threat modeling to generate a lot of assurance.

Battling the flu with instrumentation
We can learn a lot from the world of healthcare. Did you know the mission of the Centers for Disease Control (CDC) is to protect people from “health threats” and increase the “health security” of our nation? Its mission is not as different from information technology security as you might think.

The CDC fights disease, but they’re not your typical doctors. The size and complexity of their problem forces them to use very different techniques -- techniques that scale. The CDC is using sensors and instrumentation to gather data from people, doctors, hospitals, and labs at scale. It's now monitoring more than 700,000 flu patients every week.

The CDC uses this sensor data to combat influenza. The chart below shows that this year’s flu is peaking at a similar time but is less intense than in last years. Researchers are using this data to identify strains with more accuracy and create better defenses (flu shots) to protect people.

As application security challenges continue to mount, we can take advantage of sensors and instrumentation to increase visibility and create assurance. Imagine new sensors that track security-critical information across your entire application portfolio in real time. Below is a snapshot of a real-time software assurance dashboard generated from a small organization’s application portfolio:

Each of the expected defenses represents one part of a more detailed security story. The dashboard illustrates the level of assurance for each of the expected security defenses in each application. Sampling and circumstantial evidence can be used at the lower levels, but the higher levels require more rigorous verification.

New sensor technology can gather this information directly from applications in development, test, integration, and even production. Traditional application security tools, both static and dynamic, can be retooled to generate this kind of evidence. For example, tools like OWASP’s ZAP proxy can be used to identify vulnerabilities, but can also be set up as a passive sensor. A simple ZEST script can generate continuous evidence that Cross-Site Request Forgery (CSRF) token defenses are working across an entire application portfolio.

Focusing your application security program on generating portfolio assurance has many benefits. You can learn more about this approach in my recent OWASP talk, Application Security at DevOps Speed and Portfolio Scale. This approach is far more compatible with Agile and DevOps style development than the traditional annual security test. But more importantly, it actually produces security and increases the health of your application security program.

Jeff Williams has more than 20 years of experience in software development and security. He is the founder and CEO of Aspect Security and served as the Global Chairman of the OWASP Foundation for eight years.

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
1/16/2014 | 3:49:26 PM
Wow! Check out this dashboard that tracks critical application security info in real time
Jeff, Can you expand a little bit more on how the company that developed this dashboard came up with the idea, some examples of how they are using it and some of their big sucess stories! Very cool stuff!
planetlevel
50%
50%
planetlevel,
User Rank: Author
1/17/2014 | 8:54:23 AM
Re: Wow! Check out this dashboard that tracks critical application security info in real time
Sure!  They have set up a variety of tools to report to a central server.  It's not as clean as they would like.  Some of the tools report via files, others by REST services, etc...   And their reporting engine doesn't generate a beautiful heatmap yet.  But they've got a great set of sensors started and they are adding more every day.  Their penetration testing costs are plummeting, because they no longer need to test for the items they are monitoring.  And (I believe) their assurance is going up, because the sensor they are deploying get better coverage and have more accuracy than the traditional ways of doing application security.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
1/17/2014 | 10:05:36 AM
Re: Wow! Check out this dashboard that tracks critical application security info in real time
Sounds very promising. Who's idea was it or was it a project initiated by management. Sounds like it is already showing an ROI, but what was the initial investment (ball park) in terms of h/w, s/w and other related costs?
planetlevel
50%
50%
planetlevel,
User Rank: Author
1/17/2014 | 11:24:08 AM
Re: Wow! Check out this dashboard that tracks critical application security info in real time
In this case, we worked with security team to put in place some tools to monitor application security continuously. One was ZAP proxy, which we put in place in their CI/CD environment to *passively* look for security practices. We have been adding some custom ZEST scripts to verify *their* security defenses.  There are a lot of tools -- some static, some dynamic, and some using instrumentation -- that can all help generate assurance continuously. Their initial investment was very low.  They started small just looking to verify SQL Injection defenses across their entire application inventory.  They use *positive* static analysis to verify that only parameterized queries are used across all their apps.  Now if any developer introduced a potential SQL injection problem it would show up on the dashboard immediately.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
1/21/2014 | 9:02:01 AM
Re: Wow! Check out this dashboard that tracks critical application security info in real time
Thanks for the great detail, Jeff. One last question from me (Others -- feel free to add yours to the thread!). What were some of the gotchas in the project that you would have done differently, or that didn't work out as well as you expected. 
How to Better Secure Your Microsoft 365 Environment
Kelly Sheridan, Staff Editor, Dark Reading,  1/25/2021
Attackers Leave Stolen Credentials Searchable on Google
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3331
PUBLISHED: 2021-01-27
WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted URL that loads session settings. (For example, this is exploitable in a default installation in which WinSCP is the handler for sftp:// URLs.)
CVE-2021-3326
PUBLISHED: 2021-01-27
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
CVE-2021-22641
PUBLISHED: 2021-01-27
A heap-based buffer overflow issue has been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
CVE-2021-22653
PUBLISHED: 2021-01-27
Multiple out-of-bounds write issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
CVE-2021-22655
PUBLISHED: 2021-01-27
Multiple out-of-bounds read issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).