December 2, 2002 (Computerworld) --
The defensive perimeter of firewalls and intrusion-detection systems that most companies rely on for network security is being bypassed by hackers who have made Web applications their newest targets, security experts warned last week.
"Perimeter defense is becoming an irrelevant term," said Kevin Soo Hoo, senior security architect at Cambridge, Mass.-based security consultancy @Stake Inc. "The emphasis [in hacking] is now shifting to the application layer. The Web application is becoming the primary vehicle for attack."
The increased demand for Web functionality has pushed almost all traffic through Ports 80 and 443 on most Web serverstypically the only two ports that are left open by most companies. And that's where hackers are turning to gain access to enterprise networks and data, said Soo Hoo. "As a result, the threat model is changing. It makes the firewall no longer the line of defense that it once was."
Soo Hoo made his comments last week in a live webcast sponsored by Santa Clara, Calif.-based Stratum8 Corp.
Stratum8 recently introduced an application firewall appliance that's designed specifically to defend against the type of threats outlined in trend data released by @Stake. Known as the Application Protection System (APS), the device sits between the firewall and the Web server and interprets the type of processes the server is attempting to perform by analyzing incoming and outgoing traffic. Based on that analysis, it can block any traffic that contains malicious code, said Abhishek Chauhan, Stratum8's chief technology officer.
The APS ships as an appliance and requires no software installation or customized configuration. In addition, Chauhan claimed that by blocking malicious code attempting to pass through HTTP ports, the technology lowers costs by reducing the number of security incidents that must be investigated. It also allows security managers to do what Chauhan called "intelligent patching" of new vulnerabilities.
Herndon, Va.-based Exostar LLC, a large aerospace and defense collaboration service provider, has tackled the issue of securing the Web applications of its users, including BAE Systems, The Boeing Co., Lockheed Martin Corp., Raytheon Co. and Rolls-Royce PLC. However, to secure its Web-enabled aerospace collaboration environment, known as ForumPass, Exostar chose hardware-based encryption technology from Woburn, Mass.-based nCipher Corp.
Exostar is using nCipher's nShield hardware security module (HSM) to provide database and document encryption within the exchange and for XML-based security used to integrate external applications and Web services.
The nCipher HSM provides end-to-end encryption and digitally signs all transactions by means of the Security Assertion Markup Language, a secure XML-based language used by Web services for the exchange of authentication information and security credentials from one site to another or for users to gain access to Web applications.
"The mind-set of aerospace and defense companies is that they don't want their intellectual property to be anywhere but under their control," said Jeff Nigriny, security manager at Exostar. But the traditional practice of encrypting databases often leaves the encryption key with the database, potentially allowing skilled hackers to steal the key.
Continued...
1 |
2 |
NEXT
|
|
|
"Yes, NASA has confirmed that some laptops taken to the International Space Station were infected with an online-gaming password stealing..."
Read more...
"Linux is more secure than most operating systems, but Not if you don't practice basic security measures..."
Read more...
Read more Security posts or See all Blogs
|
Telework can change office dynamics in ways you hadn't anticipated. Proceed cautiously.
Got a painfully slow connection or random dead spots? Our tips will help you get the most out of your wireless network.
Listen up, managers: Employees don't quit the job; they quit you.
Netbooks, ultraportables, mini-notebooks whatever you call them, they've been grabbing headlines. Are they here for the long term or just a flash in the pan?
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
|
 |
| From Laggard to Leader: Transforming the Data Center From Laggard to Leader: Transforming the Data Center Register for this complimentary live webcast today! Go to the webcast |
|
| Computerworld Executive Bulletin: Building a Robust Antivirus Defense Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs. (Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more. Download this executive briefing |
|
| Online Security Issues in Regulated Industries Download this research paper, free for a limited time, compliments of Webroot! (Source: Webroot Software) In June 2008, Computerworld invited IT and business leaders to participate in a survey on online security initiatives at their organizations. The goal of the survey was to better understand Web and e-mail security issues faced today within the regulated education, financial services, government and health care industries. The following report represents top-line results of that survey. Download this white paper |
|
|
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
|
View more whitepapers
|
|
|