Web apps become new weakest security link
Computerworld -
The defensive perimeter of firewalls and intrusion-detection systems that most companies rely on for network security is being bypassed by hackers who have made Web applications their newest targets, security experts warned last week.
"Perimeter defense is becoming an irrelevant term," said Kevin Soo Hoo, senior security architect at Cambridge, Mass.-based security consultancy @Stake Inc. "The emphasis [in hacking] is now shifting to the application layer. The Web application is becoming the primary vehicle for attack."
The increased demand for Web functionality has pushed almost all traffic through Ports 80 and 443 on most Web serverstypically the only two ports that are left open by most companies. And that's where hackers are turning to gain access to enterprise networks and data, said Soo Hoo. "As a result, the threat model is changing. It makes the firewall no longer the line of defense that it once was."
Soo Hoo made his comments last week in a live webcast sponsored by Santa Clara, Calif.-based Stratum8 Corp.
Stratum8 recently introduced an application firewall appliance that's designed specifically to defend against the type of threats outlined in trend data released by @Stake. Known as the Application Protection System (APS), the device sits between the firewall and the Web server and interprets the type of processes the server is attempting to perform by analyzing incoming and outgoing traffic. Based on that analysis, it can block any traffic that contains malicious code, said Abhishek Chauhan, Stratum8's chief technology officer.
The APS ships as an appliance and requires no software installation or customized configuration. In addition, Chauhan claimed that by blocking malicious code attempting to pass through HTTP ports, the technology lowers costs by reducing the number of security incidents that must be investigated. It also allows security managers to do what Chauhan called "intelligent patching" of new vulnerabilities.
Herndon, Va.-based Exostar LLC, a large aerospace and defense collaboration service provider, has tackled the issue of securing the Web applications of its users, including BAE Systems, The Boeing Co., Lockheed Martin Corp., Raytheon Co. and Rolls-Royce PLC. However, to secure its Web-enabled aerospace collaboration environment, known as ForumPass, Exostar chose hardware-based encryption technology from Woburn, Mass.-based nCipher Corp.
Exostar is using nCipher's nShield hardware security module (HSM) to provide database and document encryption within the exchange and for XML-based security used to integrate external applications and Web services.
The nCipher HSM provides end-to-end encryption and digitally signs all transactions by means of the Security Assertion Markup Language, a secure XML-based language used by Web services for the exchange of authentication information and security credentials from one site to another or for users to gain access to Web applications.
Security
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Share our Strength
Download Now
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Top 10 Things to Know about Data Protection
Download Now
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...
Ponemon Study: The Business Risk of a Lost Laptop
Download Now
Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.
Airport Insecurity: The Case of Lost Laptops
Download Now
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...
