Welcome | Sign In
LinuxInsider.com
Exploits & Vulnerabilities

The Webification of App Security

Print Version
E-Mail Article
Reprints
The Webification of App Security

As more e-commerce operations use increasingly complex Web applications on their sites, security becomes a tricker problem to tackle. Reliance on the browser and the variety of different frameworks in use muddles the situation further. Two companies -- Zeus Technology and European firm Art of Defence -- are partnering to try out a two-pronged approach to the question of Web app security.


Web applications are growing in popularity, and with this increasing ubiquity of Web apps, security is more than ever becoming the No. 1 challenge for enterprises. Traditional network component vendors are under pressure to solve security challenges. However, developing this capability on their own is complex, expensive and requires new skills.

Enter the cooperative spirit. Zeus Technology, a load balancing solutions provider, has partnered with Web security firm Art of Defence to supply Web application security technology through an OEM deal Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse.

"A wide range of Web apps exist for the payment card industry and e-commerce," David Day, CTO for Zeus Technology, told the E-Commerce Times. "These organizations are under increasing pressure to meet regulations for security."

Day's company provides software that enables organizations to visualize and manipulate the flow of traffic to their Web-enabled applications. Web security firm Art of Defence's flagship solution, Hyperguard, is a scalable distributed Web application firewall (dWAF) that defends against Web app attacks. It has the capability of being deployed in multiple instances.

In May, Art of Defence signed a partnership deal with Zeus that furthered its plan to partner with Web infrastructure component, network security and cloud application providers serving the U.S. market.

Web of Need

Improved Web application security, in the eyes of Zeus Technology CEO Paul Brennan, is critical for online services. The combination of products covered by this partnership provides a way for companies to customize their infrastructure security and thus protect against malicious attacks deployed on any physical, virtual or cloud platform.

Of particular concern is compliance for PCI DSS. Online payment systems have become expected services in most industries, according Georg Hess, founder and CEO of Art of Defence. The demand for cloud computing is growing beyond a simple fallback for overloaded existing infrastructure. It is pushing Web applications out of the classical enterprise network perimeter.

"The need is to meet the challenge of authentication. Firewalls are no longer doing a good job. E-commerce businesses make it easier for hackers to get into software code," Hess told the E-Commerce Times.

Browser Brute

One of the major differences in prepping for better security with Web apps over locally installed software is the total reliance on the Web browser, noted Hess. It is now a common business tool.

"We've seen in the last three or four years the growth of vulnerabilities. Applications need to open port 80, so we need e-commerce protection. Firewalls can only handle pattern matching. They lack an understanding for things beyond virus recognition," Hess said.

The early functionality of firewalls was essential to security. Clearly, they were a good first step. However, firewalls are limited to pattern matching, and the industry needs more than that for top security today, he explained.

Threat Frameworks

Obstacles to Web app security include complexity and expense. Five to 10 different frameworks are in use, and each different solution targets some individual focus, according to Hess.

"Companies customize their solution. Security is not about opening or closing ports or identifying channels. It becomes very different for each banking system, for instance," he said.

That level of security did not exist 10 years ago. Neither did the added security risk associated with today's external partners.

"Now all that is changed. The code has become public," said Hess.

Securing the Clouds

Traditional firewall approaches do not work with today's cloud and Web app technology. Rather than dumping volumes of data into the clouds, they should be used just for overflow storage, suggested Zeus Technology's Day.

"This is the cornerstone of cloud security," he said. "I'm seeing an increasing level of interest for an appliance layer solution. We set out looking for a vendor solution to work with ours," he added in explaining what led to the partnership on security.

Day wants to see the typical security solution providing additional hardware-based firewall solutions. That, combined with complementary proactive security factors, is a vital component, he said.

"Security added by workers makes another protective fence. This makes it harder for attackers. And so does penetration testing," Day said.

Lots of Layers

A good approach for securing Web applications is a strong defensive depth chart, Hess noted. Protection that is based on one layer of security is not good enough.

"This is one difference in how Software as a Service (SaaS) and ISPs (Internet service providers) approach security," Hess said. "Webification of security is needed for baseline security coverage," he added.

Software auditing is not always enforced -- it's too expensive for many users. For the online services world, it becomes a pricing issue.

Fancy Smancy

Both Hess and Day are convinced that in today's world of Web app security, too many providers are trying to do too much in terms of interface features and functionality. Often, the development of these complex Web apps actually weakens security because they take up more development time, which comes off product testing time.

"The industry does have to go beyond what we have now. We don't always need fancy. But whatever is used needs to be reliable and effective," said Hess.

Day sees many service providers who regard security as a key delivery issue. They use layers of security. Still, security is not equally effective in all delivery environments.

"You will find different levels of security for networks, cloud and hosted environments," said Day.

Gaming 101

Will Web-based applications ever be truly secure? Hess thinks not, and Day does not dispute that view.

"The industry will never get rid of the cat and mouse game regarding security. The industry needs faster fixes," said Hess.


Print Version E-Mail Article Reprints More by Jack M. Germain


More by Jack M. Germain

Microsoft FOSSifies .Net Micro Framework
November 18, 2009
Microsoft has declared its .Net Micro framework open source under the Apace 2.0 license. Not all bits of .Net Micro are covered, however. Its TCP/IP stack has been stripped, as has its cryptography libraries. Rights to the TCP/IP stack aren't Redmond's to give, and the cryptography libraries are used outside of the scope of the .Net Micro framework, according to the company.
New Ubuntu OS Features Create Good Karma
November 13, 2009
Amidst the OS upgrades from Apple and Microsoft over the last few months, the Linux OS Ubuntu got a version bump of its own. Ubuntu 9.10, or Karmic Koala, is well worth the effort to upgrade, and its developers have made the process easier -- if you're using the full-sized desktop/notebook version. The Remix version, intended for netbooks, caused quite a few headaches.
Samsung Chimes In With Bada Mobile OS
November 11, 2009
With Android, iPhone, BlackBerry, WinMo, Symbian, WebOS and plenty other mobile platforms fighting for space, is there room for one more? Samsung believes there is, and it's announced a new open mobile platform called "Bada." The company, which already makes handsets for several existing platforms, says Bada will make app-making easy for developers. The first Bada handset should be out in the first half of 2010.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network