Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

10/10/2019
05:35 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

AppSec 'Spaghetti on the Wall' Tool Strategy Undermining Security

At many organizations, the attitude to securing software appears to be throwing a lot of technology at the problem, a new study finds.

New research suggests that the strategy for many companies to reduce application security risk is to simply stack up on multiple tools and hope they do the job.

Radware recently surveyed some 300 senior executives, security researchers, app developers, and IT professionals from organizations with worldwide operations. The survey focused on the types of application security technologies that organizations are deploying; responsibility for the AppSec function; the most prevalent threats and other topics related to Web application security.

The security vendor discovered that a high percentage of organizations are using an array of technologies — not always optimized for interoperability — to try and keep AppSec risks low.

Seventy-five percent in the survey had a Web Application Firewall (WAF), 63% a cloud WAF service, 59% did code reviews and 53% were using tools for dynamic application security testing (DAST), static testing (SAST) and runtime application self protection (RASP). More than half of those using containers also had container security tools including those specific to Docker.

"While this may sound promising, it feels like organizations are taking the 'spaghetti on the wall' approach," to application security Radware said in a blog this week. "They hope that having multiple solutions in place will do the job."

And Radware's data showed that for a majority of companies, that strategy is not working especially well, at least in terms of a breach mitigation standpoint. Ninety percent of the organizations that Radware surveyed had experienced an application security related data breach, and nearly the same proportion — 88% — reported application-level attacks throughout the year. The most common security issues included access violations, SQL-injection, DoS and protocol attacks, session/cookie poisoning, API manipulations, and cross-site request forgery.

"We found that while embracing emerging technologies and concepts — and following all security practices — attacks happen [because] organizations struggle to adjust the required structures, roles, processes, and skillsets," says Ben Zilberman, senior product marketing manager at Radware.

Containers, Microservices Proliferate

Radware found a majority of organizations have moved away from a predominantly monolithic application model to architectures that are more oriented towards microservices, containers, and serverless-infrastructures.

More than two-thirds (67%) had deployed microservices/containers, and 90% had a DevOps or DevSecOps team in place. Some of the organizations with DevSecOps teams said they had at least one DevSecOps professional for every six software developers. Others pegged the ratio at one for every 10.

The data suggests that many organizations are embracing new technologies and approaches to keep up with broader digital transformation goals. But attitudes towards security have still to catch up.  DevOps teams focused on agility often settle for a "good enough" or even a "hell no" approach to security, Radware said.

Not surprisingly, while it's the CISO or CSO who's primarily responsible for enterprise security, at many organizations they are not the ones calling the shots on application security. Radware found that the broader IT department is still the main influencer for security tools selection, policy definition, and application security implementation. When it comes to tool selection, in fact, Radware found the CISO has less of a say than IT, the business owner, and the DevOps team.

"The fact that DevOps and security are still equal powers in terms of influence and [that] it's still IT that has the most weight in decision making" is surprising, says Zilberman.

False confidence in technology is another issue. Sixty-seven percent of the respondents in the Radware survey described open-source code as being more secure — though many have identified it as being one of the primary sources of security vulnerabilities in software. Sixty-eight percent felt that microservices provide for better security and 77% believed that going serverless would help improve proactive defense capabilities.

The biggest mistake that organizations are making is assuming that technology itself can solve all the problems, Zilberman notes. "To make the best use, they should engage security professionals better and let them be business enablers rather than pushing them off," he says.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "Works of Art: Cybersecurity Inspires 6 Winning Ideas"

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft to Officially End Support for Windows 7, Server 2008
Kelly Sheridan, Staff Editor, Dark Reading,  1/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15625
PUBLISHED: 2020-01-18
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
CVE-2019-19696
PUBLISHED: 2020-01-18
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishi...
CVE-2019-19697
PUBLISHED: 2020-01-18
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administr...
CVE-2019-20357
PUBLISHED: 2020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.
CVE-2020-7222
PUBLISHED: 2020-01-18
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (...