Andrew Rose serves Security & Risk Professionals. See the full Analyst bio.
Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
Rewind And Replay For Web App Vulnerabilities
Posted by Andrew Rose on February 10, 2012
- 258 Recommendations
- 0 comments
Security threats develop and evolve with startling rapidity, with the attackers always seeking to stay one step ahead of the S&R professional. The agility of our aggressors is understandable; they do not have the same service-focused restrictions that most organizations have, and they seek to find and exploit individual weaknesses in the vast sea of interconnecting technology that is our computing infrastructure.
If we are to stand a chance of breaking even in this game, we have to learn our lessons and ensure that we don’t repeat the same mistakes over and over. Unfortunately, it is alarmingly common to see well known vulnerabilities and weakness being baked right in to new applications and systems – just as if the past 5 years had never happened!
A recent report released by Alex Hopkins of Context Information Security shines a light on the vulnerabilities they discovered while testing almost 600 pre-release web applications during 2011. The headlines for me were:
- On average, the number of issues discovered per application is on the rise.
- Two-thirds of web applications were affected by cross site scripting (XSS).
- Nearly one in five web applications were vulnerable to SQL injection.
It makes depressing reading, but I’m interested in why this situation is occurring:
- Are S&R professionals simply not educating and guiding application developers?
- Are application developers ignoring the training and education? Are we teaching them the wrong things or do we struggle to explain the threats from XSS and SQL injection?
- Are our internal testing regimes failing, allowing flawed code to reach release candidate stage?
In my experience, most developers are keen to learn how to write secure code and there are simple and effective solutions that can really help, such as coding standards, peer review, testing standards, reusable subroutines, etc. This data, however, suggests that a fair amount of organizations are sadly overlooking these.
Training and awareness is a topic I’ll be delving into later in the year, but I’d be interested in why you think app devs don’t seem to have turned the corner and what techniques you have found to be effective in improving the quality of your firm’s coding.
search forrester's blogs
Secure the digital business future.
Attend Forrester’s Forum for Security & Risk Professionals EMEA, June 10-11, London UK
Analyst Blogs
- Andras Cser (31)
- Andrew Rose (17)
- Chris McClean (54)
- Christopher Sherman (1)
- Edward Ferrara (20)
- Eve Maler (19)
- Heidi Shey (9)
- John Kindervag (28)
- Khalid Kark (13)
- Laura Koetzle (2)
- Nick Hayes (5)
- Rick Holland (20)
- Stephanie Balaouras (50)
Top Categories
- CISO (2)
- cloud (2)
- Cyberinsurance (2)
- data security (2)
- Risk Management (2)
- Security & Risk (2)
- 2013 (1)
- access control (1)
- Application Development (1)
- Asset Management (1)
- See all
Archives
- January 2013 (2)
- November 2012 (1)
- August 2012 (1)
- July 2012 (1)
- May 2012 (1)
- March 2012 (3)
- February 2012 (2)
- January 2012 (1)
- December 2011 (2)
- October 2011 (1)
- July 2011 (2)