Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
What Healthcare Can Teach Us About App Security
Newest First  |  Oldest First  |  Threaded View
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
1/21/2014 | 9:02:01 AM
Re: Wow! Check out this dashboard that tracks critical application security info in real time
Thanks for the great detail, Jeff. One last question from me (Others -- feel free to add yours to the thread!). What were some of the gotchas in the project that you would have done differently, or that didn't work out as well as you expected. 
planetlevel
planetlevel,
User Rank: Author
1/17/2014 | 11:24:08 AM
Re: Wow! Check out this dashboard that tracks critical application security info in real time
In this case, we worked with security team to put in place some tools to monitor application security continuously. One was ZAP proxy, which we put in place in their CI/CD environment to *passively* look for security practices. We have been adding some custom ZEST scripts to verify *their* security defenses.  There are a lot of tools -- some static, some dynamic, and some using instrumentation -- that can all help generate assurance continuously. Their initial investment was very low.  They started small just looking to verify SQL Injection defenses across their entire application inventory.  They use *positive* static analysis to verify that only parameterized queries are used across all their apps.  Now if any developer introduced a potential SQL injection problem it would show up on the dashboard immediately.
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
1/17/2014 | 10:05:36 AM
Re: Wow! Check out this dashboard that tracks critical application security info in real time
Sounds very promising. Who's idea was it or was it a project initiated by management. Sounds like it is already showing an ROI, but what was the initial investment (ball park) in terms of h/w, s/w and other related costs?
planetlevel
planetlevel,
User Rank: Author
1/17/2014 | 8:54:23 AM
Re: Wow! Check out this dashboard that tracks critical application security info in real time
Sure!  They have set up a variety of tools to report to a central server.  It's not as clean as they would like.  Some of the tools report via files, others by REST services, etc...   And their reporting engine doesn't generate a beautiful heatmap yet.  But they've got a great set of sensors started and they are adding more every day.  Their penetration testing costs are plummeting, because they no longer need to test for the items they are monitoring.  And (I believe) their assurance is going up, because the sensor they are deploying get better coverage and have more accuracy than the traditional ways of doing application security.
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
1/16/2014 | 3:49:26 PM
Wow! Check out this dashboard that tracks critical application security info in real time
Jeff, Can you expand a little bit more on how the company that developed this dashboard came up with the idea, some examples of how they are using it and some of their big sucess stories! Very cool stuff!


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Promise and Reality of Cloud Security
Cloud security has been part of the cybersecurity conversation for years but has been on the sidelines for most enterprises. The shift to remote work during the COVID-19 pandemic and digital transformation projects have moved cloud infrastructure front-and-center as enterprises address the associated security risks. This report - a compilation of cutting-edge Black Hat research, in-depth Omdia analysis, and comprehensive Dark Reading reporting - explores how cloud security is rapidly evolving.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-24830
PUBLISHED: 2023-01-30
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 before 0.13.3.
CVE-2023-0512
PUBLISHED: 2023-01-30
Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.
CVE-2022-23334
PUBLISHED: 2023-01-30
The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.
CVE-2022-26872
PUBLISHED: 2023-01-30
AMI Megarac Password reset interception via API
CVE-2022-46087
PUBLISHED: 2023-01-30
CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification received by the admin user.