
Subscribe to
Computerworld
or
Other Security Stories
February 04, 2002 (Computerworld) -- Increasing concerns about the potential for hackers to manipulate critical back-end administrative systems through security holes commonly found in corporate Web sites have prompted at least one major airline to take preventive measures.
"We are trying to defend our Web sites," said David Yaacobi, information systems security manager at El Al Israel Airlines at Ben-Gurion International Airport in Lod, Israel. "Hackers could go inside your Web sites and inject wrong or malicious code."
El Al has deployed Sanctum Inc.'s AppShield 3.1 Web application firewall technology. That deployment comes on the heels of a security audit of a major U.S. airline conducted by the Santa Clara, Calif.-based vendor. According to Sanctum CEO Peggy Weigle, during that audit the airline's Web-based systems were breached. The security team that conducted the audit managed to make its way into the airline's back-end systems, including the reservation and maintenance systems, Weigle said.
"Through a hole in the [front-end] application code, we were able to get to the back-end systems and able to download the source code of the entire application," said Weigle. "We could have obviously obtained passenger manifests, maintenance systems and whatever was there." The airline, which Weigle refused to identify for security reasons, still hasn't fixed the problems, she said.
Dan Meehan, CIO of the Federal Aviation Administration, said he received a briefing on the audit from Weigle and noted that the FAA is working with the White House to develop a more aggressive outreach program focused on the airlines. "We want to take this specific piece of information and compare notes with a few other airlines to see if this is an isolated case or not," said Meehan. However, he said, it's too early to tell whether the audit did in fact uncover a significant breach of security.
For his part, Yaacobi isn't taking any chances. Although El Al's reservation systems run on protocols that are "totally different than [standard Internet protocols] and are very difficult to hack," Yaacobi said the potential is still there, and El Al does whatever is necessary to protect them.
"Since Sept. 11, any illegal access to data or transactions through our company Web site is viewed by us as a terrorist act," said Yaacobi. "With regular attempted attacks on our site, we view Web application security critical to our overall security plan ensuring the safety of our customers."
Various Israeli government agencies deployed AppShield during the 2000 cyberconflict between pro-Palestinian and Israeli hackers.
John Pescatore, an analyst at Stamford, Conn.-based Gartner Inc., said Web application security is a serious problem for two-thirds of all corporate Web sites.
"The current generation of firewalls focuses on the network level, kind of like the walls of a fort stopping direct attack," said Pescatore. "However, close to 75% of today's attacks are tunneling through applications. Application-level firewalls are something that any critical infrastructure company needs to look at."
![]()
How Hackers Get In
Browser-based attacks exploit bugs and holes in Web-based application code. Vulnerable software includes:
User interface code, which provides the look and feel of the site.
The Web server, which supports the physical communication between the user's browser and the applications.
The front-end system, which interfaces directly with the user interface code, operating system and back-end systems.
Source: Sanctum Inc., Santa Clara, Calif.
Related stories:
|
|
Print this Story |
|
Send Us Feedback |
|
E-mail this Story |
|
Digg this Story |
|
Slashdot this Story |
|
|
|
|
|
|
|
|
All Zones Application Performance Zone Business Continuity Zone Data Center Management Zone Enterprise-Class Security Zone The File Data Management Zone Grid Computing on Windows Zone Security Management Zone ITIL Best Practices Zone The SAS Zone Storage Virtualization Zone Business Intelligence and Analytics Zone |
|
|
| ||||||||
| ||||||||
| ||||||||
|


Security Management ZoneSecurity management is the process of developing a comprehensive data protection plan. It takes into account all potential threats, the existing network environment, the future needs of the organization, and lays out a multi-tiered blueprint to integrate the security technology needed to combat these threats. CDW can help keep your network and data secure. Visit the CDW Security Management Zone now See All Zones
|
Fired up about IT? Join Sharkbait and share your true tales of IT. SharkBait is the place for you to sound off about everything IT the good, the bad, and the rest of the weird stuff you deal with every day.New baits |

"Security Directions" virtual trade show2008's Code-Red Security Issues for Protecting the EnterpriseWebcasts, white papers, demos, and more. Presented in a unique 3-d environment. Enter our show right now! Click here to enter
|

In SecurityStripping away the trappings of applications, systems and networks, information is the core asset of most organizations. Our columnist describes how asserting the importance of information governance is crucial to making that asset tangible, addressable and protected. Click here to read the latest column by Jon Espenschied |
| About Us Advertise Contacts Editorial Calendar Help Desk Jobs at IDG Privacy Policy Reprints Site Map |
|
CIO The Industry Standard |