{"id":32826,"date":"2018-08-15T09:51:14","date_gmt":"2018-08-15T01:51:14","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=32826"},"modified":"2018-08-15T09:51:14","modified_gmt":"2018-08-15T01:51:14","slug":"4-steps-to-improving-application-security","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2018\/08\/15\/4-steps-to-improving-application-security\/","title":{"rendered":"4 steps to improving application security"},"content":{"rendered":"<p>In 2006, Clive Humby, a Sheffield mathematician, made headlines when he declared that \u2018data was the new oil\u2019. Though it has been a decade, the realization that there is a lot of money to be made \u2013 and lost \u2013 through the handling of big data has just begun to dawn on many business people.<span class=\"Apple-converted-space\">\u00a0<\/span><\/p>\n<p>Data breaches continue to be a threat to enterprises and consumers, especially in the wake of recent events here in the Philippines and across the region, such as Facebook-Cambridge Analytica and SingHealth cyber hack.<\/p>\n<p>And since data is gold, applications are increasingly the target of cybercriminals. New research by F5 Labs found that web and applications attacks are the largest cause of security breaches (30 percent), with an average reported cost of close to US$8 Million per breach. It also found that a typical organization runs 765 web applications, with 34 percent of them considered mission-critical.<span class=\"Apple-converted-space\">\u00a0<\/span><\/p>\n<p>The research, using data gathered from Loryka and WhiteHat Security, provides analysis of the current threat landscape, detailed research stats and steps to secure applications to protect users and data.<span class=\"Apple-converted-space\">\u00a0<\/span><\/p>\n<p>Highlights from the F5 Labs\u2019 <a href=\"https:\/\/www.f5.com\/labs\/articles\/threat-intelligence\/2018-Application-Protection-Report\"><i>Protecting Applications 2018 Report<\/i><\/a><i> <\/i>include:<span class=\"Apple-converted-space\">\u00a0<\/span><\/p>\n<p><b><i>Denial-of-service (DDoS) Attacks<\/i><\/b><\/p>\n<ul>\n<li>Credential theft, DDoS attacks, and web fraud are the top three attacks that are the most devastating to organizations represented in the global study.<span class=\"Apple-converted-space\">\u00a0<\/span><\/li>\n<li>69% of respondents in China and India are most concerned about DDoS attacks.<\/li>\n<li>APAC accounted for 17 percent of DDoS attacks in 2017, with a spike from Q4 2017 to Q1 2018.<\/li>\n<li>Security Response: DDoS attacks are pervasive across all levels of the application tier. It is critical that every organization has a DDoS response strategy.<span class=\"Apple-converted-space\">\u00a0<\/span><\/li>\n<\/ul>\n<p><b><i>Account Access Hijacking<span class=\"Apple-converted-space\">\u00a0<\/span><\/i><\/b><\/p>\n<ul>\n<li>Breach records analysis shows that 13 percent of all web app breaches in 2017 and 1Q 2018 were access-related.<span class=\"Apple-converted-space\">\u00a0<\/span><\/li>\n<li>Some of the top categories were:<span class=\"Apple-converted-space\">\u00a0<\/span>\n<ul>\n<li>Credentials stolen via compromised email (34%)<\/li>\n<li>Access control misconfiguration (23%)<span class=\"Apple-converted-space\">\u00a0<\/span><\/li>\n<li>Brute force attacks to crack passwords (5%)<span class=\"Apple-converted-space\">\u00a0<\/span><\/li>\n<li>Credential stuffing from stolen passwords (9%)<\/li>\n<li>Social engineering theft (3%)<span class=\"Apple-converted-space\">\u00a0<\/span><\/li>\n<\/ul>\n<\/li>\n<li>Security Response: Stronger authentication solutions for mission-critical applications or for external applications over which organizations don\u2019t have full control.<\/li>\n<\/ul>\n<p><b><i>Injection Attacks<span class=\"Apple-converted-space\">\u00a0<\/span><\/i><\/b><\/p>\n<ul>\n<li>Injection attacks allow an attacker to insert commands or new code directly into a running application with malicious intent.<span class=\"Apple-converted-space\">\u00a0<\/span><\/li>\n<li>Injection vulnerabilities (weaknesses that have not yet been exploited) are prevalent. Those composed 17 percent of all discovered vulnerabilities in 2017.<\/li>\n<li>Security response: High priority should be given to finding, patching, and blocking injection vulnerabilities.<\/li>\n<\/ul>\n<p><b><i>How likely are you to be hacked?<span class=\"Apple-converted-space\">\u00a0<\/span><\/i><\/b><\/p>\n<p>In general, there are two types of attackers: opportunists and targeted attackers:<\/p>\n<ul>\n<li><b>Opportunist attackers<\/b> keep their ROI high by keeping costs low. They use a spray-and-pray approach to sweep the Internet looking for easy pickings. These attackers come at you with canned exploits and known methods. If rebuffed, they quickly move on to the next target.<\/li>\n<li><b>Targeted attackers<\/b> choose their targets carefully. Their goal could be espionage or a high payoff, but it\u2019s likely that once you\u2019re in their sights, they\u2019re coming after you. Though less prevalent, such attackers are generally more motivated<\/li>\n<\/ul>\n<p><b><i>How can organizations improve application security?<span class=\"Apple-converted-space\">\u00a0<\/span><\/i><\/b><\/p>\n<p>Below are four low-difficulty steps:<span class=\"Apple-converted-space\">\u00a0<\/span><\/p>\n<ol>\n<li><b>Understand your environment: <\/b>Know what applications you have and what data repositories they access.<span class=\"Apple-converted-space\">\u00a0<\/span><\/li>\n<li><b>Reduce your attack surface: <\/b>Attackers will probe any part of an application service that is visible on the internet for possible exploitation.<span class=\"Apple-converted-space\">\u00a0<\/span><\/li>\n<li><b>Prioritize defenses based on risk: <\/b>Know which applications are important and minimize the attack surface by identifying applications that need additional resources.<span class=\"Apple-converted-space\">\u00a0<\/span><\/li>\n<li><b>Select flexible and integrated defense tools: <\/b>Have<b> <\/b>a good but manageable selection of flexible, powerful solutions to cover controls for prevention, detection, and recovery from existing and emerging threats.<span class=\"Apple-converted-space\">\u00a0<\/span><\/li>\n<\/ol>\n<p>Building a solid application defense strategy requires understanding each app and its areas of vulnerability, assigning an appropriate level of risk to the app according to the value of the data it contains, and taking a holistic view to securing applications based on their vulnerabilities, threats, and level of risk.<span class=\"Apple-converted-space\">\u00a0<\/span><\/p>\n<p>Read the <a href=\"https:\/\/www.f5.com\/labs\/articles\/threat-intelligence\/2018-Application-Protection-Report\">full report<\/a> to explore these core threat areas, understand their impact on apps in more detail, and obtain practical guidance on building an application defense strategy that works for your organization.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In 2006, Clive Humby, a Sheffield mathematician, made headlines when he declared that \u2018data was the new oil\u2019. Though it has been a decade, the realization that there is a lot of money to be made \u2013 and lost \u2013 through the handling of big data has just begun to dawn on many business people.\u00a0 [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":32827,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2098,15,19,25],"tags":[4968,6245,6151,286],"class_list":["post-32826","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-apps-3","category-business","category-headlines","category-software","tag-ddos-attacks","tag-f5-labs","tag-high-tech","tag-it-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/32826","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=32826"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/32826\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/32827"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=32826"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=32826"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=32826"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}