Vulnerabilities / Threats

2/28/2018
07:00 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

The State of Application Penetration Testing

Data from real-world pen tests shows configuration errors and cross-site scripting are the most commonly found vulnerabilities.

Misconfiguration ranks as the most common type of vulnerability discovered in real-world penetration tests, according to a newly published study.

In client engagements last year, pen-testing-as-a-service provider Cobalt found mostly misconfiguration, followed by cross-site scripting (XSS), authentication and session, exposure of sensitive data, and access control-type vulnerabilities in applications.

Finding flaws is one thing, but fixing them is another. Redirect and forward-type flaws sit unresolved the longest of any category, 41 days, while server-side request forgery, sensitive data exposure, SQL injection, and others, including business logic, get fixed most rapidly.

Caroline Wong, vice president of security strategy for Cobalt and co-author of the Pen Test Metrics Study, says misconfiguration flaws are a sign of the times. "What that tells me is that so much of security vulnerability comes not necessarily from the code we were writing, and actually may have to do with other software and infrastructure components our software depends on in order to run," she says.

"That says … organizations are making huge use of cloud services and relying on others to do their settings for them. Maybe it's something they consider to be someone else's problem, and maybe in the past they didn't depend on third parties so they didn't consider [those] security settings."

Application penetration testing, unlike vulnerability assessment, is not exactly standard practice for most organizations today. Pen testing traditionally was associated with network security, but with the emergence of secure software development lifecycle (SDL) programs, more organizations are starting to opt for a white-hat hack of their apps. "I see a lot of organizations do one application pen test a year because of PCI, or HIPAA, or a customer asking them for one," Wong says. But more organizations are starting to opt for app pen tests to "do the right thing" in their secure development practices now, she says.

The most common software security program typically includes developer training and a penetration test to get a pulse on the state of their applications' security. Wong says organizations launching appsec for the first time go with a pen test to get them started.

"What's the biggest bang for their buck to start their program? 'Show me and my organization if we have real security issues, and use that information to get to the next level to justify further investment,'" she explains. "I find that pen testing is a very common first step when they first start thinking about appsec."

While a vulnerability assessment scans for and identifies flaws, a penetration test goes deeper, manually exploiting vulnerabilities to see how an attacker could abuse them, for example.

Most organizations typically focus on vulnerability scanning. "But by and large there are pockets who do true pen testing. I think there's a larger segment that does quasi-pen testing and not full, in-depth testing," says Kevin Greene, a software assurance evangelist. "I'm not sure all folks understand" app pen testing, he notes.

Ideally, in addition to an SDL check, organizations should run regular vulnerability assessments and pen tests to get "wider coverage" of the attack surface, he says.

Gary McGraw, vice president of security technology at Synopsys, says app pen testing is employed by 87% of all firms involved in the BSIMM8 software security maturity study. BSIMM  (Build Security In Maturity Model) reports on how more than 100 major companies from a range of vertical markets measure up with their software security development lifecycles. "Pen testing is a good 'smoke test' which can help uncover major problems," McGraw says. "Automated pen testing is available as a service and can be used to cover an entire application portfolio."

But pen testing alone doesn't make a software security program, he notes. "Pen testing is the third most important software security practice after code review with a static analysis tool and architectural risk analysis," McGraw says.  

Not All Apps Getting Tested

Cobalt's study also includes new data from a survey of security, management, operations, developers, and DevOps specialists. Turns out most aren't pen testing all of their apps: just 24% say they pen test 67% to 100% of their apps, while 35% test one to 33% of their apps, and 31% say they test anywhere from 34% to 66% of their apps.

While the best practice is to pen test critical apps once every quarter, most (32%) of the respondents in the survey say they only do so annually; 16%, semiannually; 12%, quarterly; 12%, not at all yet; and 7%, more than five times a year.

More than 30% say they pen test their apps when they add a new feature or patch. Some 26% pen test their apps on an ad hoc basis, 25% at the time of a new release, and 22% when a customer requests it.

Some 46% say they would pen test more apps, but it's too expensive. That's a common deterrent, as well the expertise required for pen testing. "It requires a really skilled individual" with the expertise to know what to probe and attack, according to Greene.

And once the results come in from a pen test, they require action. "I have met organizations for whom the reason they don't do more pen tests is because they are still trying to figure out how to fix the results from their first pen test," Wong says.

"The biggest challenge of pen testing apps is finding the right people," which can be costly, she notes.

Related Content:

 

Black Hat Asia returns to Singapore with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier solutions and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Windows 10 Security Questions Prove Easy for Attackers to Exploit
Kelly Sheridan, Staff Editor, Dark Reading,  12/5/2018
Starwood Breach Reaction Focuses on 4-Year Dwell
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/5/2018
Symantec Intros USB Scanning Tool for ICS Operators
Jai Vijayan, Freelance writer,  12/5/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: I guess this answers the question: who's watching the watchers?
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-3988
PUBLISHED: 2018-12-10
Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is available to any application on the...
CVE-2018-10008
PUBLISHED: 2018-12-10
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended...
CVE-2018-10008
PUBLISHED: 2018-12-10
An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build using the workspace br...
CVE-2018-10008
PUBLISHED: 2018-12-10
A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim from logging into Jen...
CVE-2018-10008
PUBLISHED: 2018-12-10
A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.