By Jack M. Germain TechNewsWorld
12/18/07 4:00 AM PT
"The Web is really the Wild Wild West of attackers today," said Michael Sutton, security evangelist for HP quality management. "This condition is now out of the shadows because security experts can actually show proof of the kinds of attacks coming through these Web 2.0 holes. Now we have much better statistics to demonstrate the kind of attacks being made."
eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.
Web 2.0 applications are quickly taking over traditional activities on the Internet. Web sites are becoming interactive as they offer multiple function applications. This, in turn, is creating greater security risks for both consumers and network operators.
One of the biggest concerns is the need for Web 2.0 developers to build their applications with total security in mind from the ground up. Until now, too many developers built software the traditional way with security add-ons at the top of the heap.
"The Web is enhancing at a tremendously active pace today compared to five years ago. Web sites used to be little more than online billboards. Today, they are distributors of complex applications with multiple functions," Michael Sutton, security evangelist for HP (NYSE: HPQ) quality management, told TechNewsWorld.
HP acquired Web application security firm SPI Dynamics in June as part of a business strategy to ramp up Web security for its clients. TechNewsWorld recently met with Sutton to discuss HP's efforts in dealing with the growing threats associated with Web 2.0.
TechNewsWorld: What do you see as the most problematic aspects of the Internet today?
Michael Sutton: There are no more static pages on the Web. Instead, Web sites thrive on user-supplied input. Web applications are now all about mission critical delivery. That makes me very concerned about Web 2.0 security.
TechNewsWorld: Do you see the Internet reaching a growth plateau now that Web 2.0 applications are so popular?
Sutton: It's just the opposite. The Web as we see it today will be much dramatically different in the next two to three years. The use of Ajax on Web sites makes them much more responsive. Its use will increase. We will see current technology such as Flash fade as newer technology gets pushed to developers. Take, for instance, Microsoft's (Nasdaq: MSFT) Silverlight technology.
TechNewsWorld: How does this rapid development impact on security issues?
Sutton: These new programming methods are changing all of the old rules. Now attackers are going after holes in Web sites that are much more accessible with all of the Web 2.0 apps running on them. Many of these security holes had always been there, but nobody used them. Today, we can no longer rely on security by obscurity.
TechNewsWorld: How would you characterize the state of security on the Internet today?
Sutton: There is far too much low-hanging fruit. The Web is really the Wild Wild West of attackers today. This condition is now out of the shadows because security experts can actually show proof of the kinds of attacks coming through these Web 2.0 holes. Now we have much better statistics to demonstrate the kind of attacks being made.
TechNewsWorld: Why are security attempts failing at blocking these threats?
Sutton: We are getting too many emerging attacks that we haven't seen before. We are getting better at locking down programs, but the hackers are getting better at the kinds of attacks they pull off as well. For instance, the two top vulnerabilities are cross-site and SQL injection attacks. Cross-sites happen because browsers can be tricked into accessing embedded data. SQL injection attacks prey on programming language for back-end databases. The attackers can read and overwrite data that they should not be able to access.
TechNewsWorld: How prevalent are these vulnerabilities?
Sutton: Cross-site scripting is so heavily used by hackers that at least 85 percent of all Web sites are vulnerable to attack. Sequel injection attacks victimize 25 percent.
TechNewsWorld: What steps do site developers have to take to reduce these vulnerabilities?
Sutton: Fixes for most Web 2.0 application vulnerabilities are not that difficult. Software developers need controls to limit the types of input allowed through the rules. But we tend not to do this. That's when things slip through the holes.
TechNewsWorld: Why aren't Web app developers more mindful of this security fix?
Sutton: Today, so many people can build a Web application without formal programming training. They use tools that build the programs to run on the Web site. The people doing these builds are not real developers or security experts. We are seeing a huge explosion of vulnerabilities as a result. This is not being done deliberately, of course. It is just that they do not know enough about security.
TechNewsWorld: How can security companies overcome this problem?
Sutton: The industry needs to involve developers and all the players along the way. I am a firm believer in the need to build security software by default. Building in security is like doing an audit. Nobody likes to take those steps, but it is a necessary evil. The skill sets used to be localized for software only. Not anymore. Different skill sets are needed for Web applications.
TechNewsWorld: So how do security companies turn this problem around?
Sutton: Developers cannot just rely on the security team. They get involved way too late in the development process. The developers, quality assurance teams and management all have to be involved. Giving them tools is only one part of the solution. Security is bigger than that.
TechNewsWorld: You are a security tool company. Are you saying that your efforts are not working?
Sutton: We need to educate all players in the process. They do need our automated tools. These tools are getting quite mature. But the tools are not better than seasoned security teams. It is more of a one-two punch process. Web applications are way too complex today. A company can't hire enough humans to find all the security holes in software and Web site architecture. So tools become invaluable.
TechNewsWorld: Is anything else needed to curb security concerns with Web 2.0 applications?
Sutton: Every QA (quality assurance) and developer team member needs a security background. We built security functionality into our tools platform so developers using it are already working with security. This is not an impossible task.
The Linux Foundation's Jim Zemlin: Linux Adoption's Next Phase December 14, 2007
"In 2008 we will see the Linux ecosystem applying a federation into one platform," said Jim Zemlin, director of The Linux Foundation. "A lot of Linux distros will compete in the marketplace. The particular flavor of Linux will matter in that different distros will cater to specific environments such as the Mobile Internet. All of these will center on the Linux Standard Base."
Related Stories
HP Beefs Up Signage Biz With NUR Macroprinters Buy December 10, 2007
The NUR deal is not the first in HP's effort to widen its portfolio of digital presses and wide-format printers. Three months ago, HP acquired MacDermid ColorSpan, another manufacturer of wide-format digital inkjet printers "and a key supplier to sign shop franchises, quick printers and other small to midsize sign-making and screen-printing businesses," said HP.
Grisoft Grabs LinkScanner Tech, Targets Security Heavy Hitters December 05, 2007
Other companies in the antivirus space have not embraced dynamic, real-time analysis and protection of Web data, said Grisoft CEO J. R. Smith. "The acquisition will allow Grisoft to leapfrog the safe surfing initiatives of other anti-virus vendors, who have focused on database-driven approaches that are incompatible with the dynamic, elusive nature of these threats."
HP Embraces Telecom With New Blade Server December 05, 2007
Already a platform giant, HP is now nudging its blade server portfolio into new territory for the company -- telecom. The company released a carrier-grade version of its BladeSystem product line that is developed specifically for telecom companies. HP's entry into this market will make it a competitor with Sun Microsystems and IBM, which already have a hardware presence in the industry.
Related News Alerts
More by Jack M. Germain
Microsoft FOSSifies .Net Micro Framework November 18, 2009
Microsoft has declared its .Net Micro framework open source under the Apace 2.0 license. Not all bits of .Net Micro are covered, however. Its TCP/IP stack has been stripped, as has its cryptography libraries. Rights to the TCP/IP stack aren't Redmond's to give, and the cryptography libraries are used outside of the scope of the .Net Micro framework, according to the company.
New Ubuntu OS Features Create Good Karma November 13, 2009
Amidst the OS upgrades from Apple and Microsoft over the last few months, the Linux OS Ubuntu got a version bump of its own. Ubuntu 9.10, or Karmic Koala, is well worth the effort to upgrade, and its developers have made the process easier -- if you're using the full-sized desktop/notebook version. The Remix version, intended for netbooks, caused quite a few headaches.
Samsung Chimes In With Bada Mobile OS November 11, 2009
With Android, iPhone, BlackBerry, WinMo, Symbian, WebOS and plenty other mobile platforms fighting for space, is there room for one more? Samsung believes there is, and it's announced a new open mobile platform called "Bada." The company, which already makes handsets for several existing platforms, says Bada will make app-making easy for developers. The first Bada handset should be out in the first half of 2010.