Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Web apps become new weakest security link

December 2, 2002 12:00 PM ET

Computerworld - The defensive perimeter of firewalls and intrusion-detection systems that most companies rely on for network security is being bypassed by hackers who have made Web applications their newest targets, security experts warned last week.

"Perimeter defense is becoming an irrelevant term," said Kevin Soo Hoo, senior security architect at Cambridge, Mass.-based security consultancy @Stake Inc. "The emphasis [in hacking] is now shifting to the application layer. The Web application is becoming the primary vehicle for attack."


The increased demand for Web functionality has pushed almost all traffic through Ports 80 and 443 on most Web servers—typically the only two ports that are left open by most companies. And that's where hackers are turning to gain access to enterprise networks and data, said Soo Hoo. "As a result, the threat model is changing. It makes the firewall no longer the line of defense that it once was."


Soo Hoo made his comments last week in a live webcast sponsored by Santa Clara, Calif.-based Stratum8 Corp.


Stratum8 recently introduced an application firewall appliance that's designed specifically to defend against the type of threats outlined in trend data released by @Stake. Known as the Application Protection System (APS), the device sits between the firewall and the Web server and interprets the type of processes the server is attempting to perform by analyzing incoming and outgoing traffic. Based on that analysis, it can block any traffic that contains malicious code, said Abhishek Chauhan, Stratum8's chief technology officer.


The APS ships as an appliance and requires no software installation or customized configuration. In addition, Chauhan claimed that by blocking malicious code attempting to pass through HTTP ports, the technology lowers costs by reducing the number of security incidents that must be investigated. It also allows security managers to do what Chauhan called "intelligent patching" of new vulnerabilities.


Herndon, Va.-based Exostar LLC, a large aerospace and defense collaboration service provider, has tackled the issue of securing the Web applications of its users, including BAE Systems, The Boeing Co., Lockheed Martin Corp., Raytheon Co. and Rolls-Royce PLC. However, to secure its Web-enabled aerospace collaboration environment, known as ForumPass, Exostar chose hardware-based encryption technology from Woburn, Mass.-based nCipher Corp.


Exostar is using nCipher's nShield hardware security module (HSM) to provide database and document encryption within the exchange and for XML-based security used to integrate external applications and Web services.


The nCipher HSM provides end-to-end encryption and digitally signs all transactions by means of the Security Assertion Markup Language, a secure XML-based language used by Web services for the exchange of authentication information and security credentials from one site to another or for users to gain access to Web applications.




Jump to comments

Security

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...