Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
What Healthcare Can Teach Us About App Security
Newest First  |  Oldest First  |  Threaded View
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
1/21/2014 | 9:02:01 AM
Re: Wow! Check out this dashboard that tracks critical application security info in real time
Thanks for the great detail, Jeff. One last question from me (Others -- feel free to add yours to the thread!). What were some of the gotchas in the project that you would have done differently, or that didn't work out as well as you expected. 
planetlevel
50%
50%
planetlevel,
User Rank: Author
1/17/2014 | 11:24:08 AM
Re: Wow! Check out this dashboard that tracks critical application security info in real time
In this case, we worked with security team to put in place some tools to monitor application security continuously. One was ZAP proxy, which we put in place in their CI/CD environment to *passively* look for security practices. We have been adding some custom ZEST scripts to verify *their* security defenses.  There are a lot of tools -- some static, some dynamic, and some using instrumentation -- that can all help generate assurance continuously. Their initial investment was very low.  They started small just looking to verify SQL Injection defenses across their entire application inventory.  They use *positive* static analysis to verify that only parameterized queries are used across all their apps.  Now if any developer introduced a potential SQL injection problem it would show up on the dashboard immediately.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
1/17/2014 | 10:05:36 AM
Re: Wow! Check out this dashboard that tracks critical application security info in real time
Sounds very promising. Who's idea was it or was it a project initiated by management. Sounds like it is already showing an ROI, but what was the initial investment (ball park) in terms of h/w, s/w and other related costs?
planetlevel
50%
50%
planetlevel,
User Rank: Author
1/17/2014 | 8:54:23 AM
Re: Wow! Check out this dashboard that tracks critical application security info in real time
Sure!  They have set up a variety of tools to report to a central server.  It's not as clean as they would like.  Some of the tools report via files, others by REST services, etc...   And their reporting engine doesn't generate a beautiful heatmap yet.  But they've got a great set of sensors started and they are adding more every day.  Their penetration testing costs are plummeting, because they no longer need to test for the items they are monitoring.  And (I believe) their assurance is going up, because the sensor they are deploying get better coverage and have more accuracy than the traditional ways of doing application security.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
1/16/2014 | 3:49:26 PM
Wow! Check out this dashboard that tracks critical application security info in real time
Jeff, Can you expand a little bit more on how the company that developed this dashboard came up with the idea, some examples of how they are using it and some of their big sucess stories! Very cool stuff!


More SolarWinds Attack Details Emerge
Kelly Jackson Higgins, Executive Editor at Dark Reading,  1/12/2021
Vulnerability Management Has a Data Problem
Tal Morgenstern, Co-Founder & Chief Product Officer, Vulcan Cyber,  1/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-36192
PUBLISHED: 2021-01-18
An issue was discovered in the Source Integration plugin before 2.4.1 for MantisBT. An attacker can gain access to the Summary field of private Issues (either marked as Private, or part of a private Project), if they are attached to an existing Changeset. The information is visible on the view.php p...
CVE-2020-36193
PUBLISHED: 2021-01-18
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
CVE-2020-7343
PUBLISHED: 2021-01-18
Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee product updates by manipulating a directory used by MA for temporary files. The product would continue to function with out-of-date detection files.
CVE-2020-28476
PUBLISHED: 2021-01-18
All versions of package tornado are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configura...
CVE-2020-28473
PUBLISHED: 2021-01-18
The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with defa...