Access and Feeds

Security: Securing Application Run Time Engines to Thwart Attacks

By Dick Weisinger

Today enterprise security  is heavily focused on protecting data by preventing intrusion.  A Gartner “Maverick Research” report finds that 23 times the effort and resources are being spent on perimeter security compared to what’s being spent on application security.

Joseph Feiman, Gartner analyst and author of the report, told Forbes that “considering the ineffectiveness of perimeter protection in stopping attacks, this ratio cries for a fundamental change…  Modern security fails to test and protect all apps. Therefore, apps must be capable of security self-testing, self-diagnostics and self-protection. It should be a CISO (Chief Information Security Officer) top priority.”

Part of the reason for focusing on perimeter security as opposed to looking at app security is that it’s easier.  Brad Murdoch, business development manager at Prevoty, cites four reasons why security applications in the enterprise is hard:

  • There are too many applications with too many ways to access, making the testing and securing of all applications difficult to impossible
  • Too little time. Developers and IT are typically too focused on the feature development and delivery of new software to spend time identifying and remedying security issues.  It’s a thankless job.  There’s often little to show for the effort spent on plugging security holes that never may become issues.
  • Lack of Expertise.  Security is a topic that often isn’t taught and isn’t well understood.  Application security is an area that’s massively neglected by many developers.
  • Hacker technology is sophisticated.  While developers are typically soft on security, the opposite is true of hackers.  Hackers focus only on defeating security measures, and because of that, hacking techniques are sophisticated and evolve quickly.  Keeping pace with hackers requires a significant investment in resources and time.

Feiman sees some hope though.  He points to the fact that while there are thousands of apps, the run-time engines that power those apps is very limited in number.  The Java JVM and .NET Common Language Runtime (CLR) represent the core of a large fraction of apps.  This vein of app security is being called “Runtime Application Self-Protection” (RASP).  Some companies like Waratek and Prevoty are researching and developing this kind of security technology.

Feiman says that “we believe by 2020, 25% of Web and cloud applications will become self-protecting, up from less than 1% today.”

 

 

 

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*