| By Paul A. Henry | Article Rating: |
|
| September 23, 2007 08:15 PM EDT | Reads: |
23,515 |
What’s Secure?
When discussing Web 2.0 security, keep this dynamic in mind:
Web 2.0 certainly allows us all to innovate on the Internet. Unfortunately, similar to what happened in the early 1990’s Internet boom, businesses and individuals are rushing the deployment of these new Web capabilities and features with little, if any, regard to security.Hence, we find ourselves in a position now, due in large part to rushed Web 2.0 implementations, that the Internet is a much more dangerous place to be than it has ever been. Web-based e-mail providers, photo-sharing Websites, blogs, Wikis, and social networking sites have all fallen victim to malicious hackers due to their lack of consideration of security in the “new” Web 2.0 world.Internet Threat Vectors
In their quest to harness the power of the Internet, enterprises began increasing the connectivity of their internal applications to the Web. The threat vector originally involved layer 4 (the network layer) of the OSI model, where inspection is primarily limited to an IP address and port numbers in stateful packet filters. But the threat vector soon shifted to layer 7 (the application layer), where attackers could exploit the vulnerabilities of Internet-connected applications. Now, for the problem: As the threat vector shifted from layer 4 to layer 7, our defenses simply did not keep pace,With the change in the threat vector, signatures for known attacks began to find their way into firewall security products. Some stateful packet filter vendors attempted to offer at least some level of application layer attack protection. This protection methodology is often called a Negative Security Model, whereby all traffic is allowed to flow freely and the protective mechanism uses the signature of known attacks layered on top of their Stateful packet filters. This approach attempts to enumerate potentially malicious traffic and to block it only once (and if) it has in fact been identified.Unfortunately, the Negative Security Model is only reactive in nature. Admittedly, these products are marketed as being proactive because of their ability to automatically block an attack on behalf of the product user. However, a signature for a given attack must first be created before any defense against that particular attack can be afforded. As a result, the use of this methodology in reality is not at all proactive and is at best only a reactive methodology. In today’s environment, where over 6,000 application vulnerabilities are reported annually, vendors are having a difficult time maintaining defensive signatures for these known attacks. What about all the unknown threats circulating across the Web? A recent study found that the typical vulnerability exists for up to 348 days before public disclosure. Hence the malicious hacker who found the vulnerability could potentially have free rein for nearly a year to exploit a vulnerability before a defensive signature can be created.The problems don’t end there. In a recent article, IBM warned that there is a colossal difference between the number of vulnerabilities disclosed publicly and the number of vulnerabilities that are discovered and are not publicly reported. IBM has estimated that up to 139,362 vulnerabilities are discovered annually – but not reported publicly. Remaining Application-Layer Risks with Web 2.0
Clearly, the increased functionality of Web 2.0 Websites along with the relatively new underlying programming languages are creating new threat vectors and revitalizing traditional threat vectors. The most common and “most concerning” threat vectors for Web 2.0 include:
- Web-borne malware
- Real-time RSS/Atom Feeds with JavaScript Malware inside
- XSS Scripting (Cross Site Scripting) – e.g., MySpace Worm
- CSRF (Cross Site Request Forgeries) – Stealing data in Java space, e.g., Gmail
- XSS filter bypassing – ENCODING
- Exponential XSS Attacks – No need to limit to one Website
- Forging “request headers” using Flash
- Backdooring Media Files – JavaScript in everything
Published September 23, 2007 Reads 23,515
Copyright © 2007 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Paul A. Henry
Paul Henry is global information security expert, with more than 20 years' experience managing security initiatives for Global 2000 enterprises and government organizations worldwide. At Secure Computing, he plays a key strategic role in new product development and directions. In his role as vice president of technology evangelism, he also advises and consults on some of the world's most challenging and high-risk information security projects, including the National Banking System in Saudi Arabia, Department of Defense's Satellite Data Project, USA, and both government as well as telecommunications projects through out Japan.
![]() |
Julian 09/19/07 07:23:21 PM EDT | |||
Awesome read - well done... It talks about Web2.0 and sheds some light on whether we're really at Web2.0 or Web 16.0... Julian Stone - ProWorkflow.com |
||||
- 4th International Cloud Computing Conference & Expo Starts Today
- Cloud Computing Journal Continues To Publish World's Best Cloud Analysts
- SOA World Magazine "Readers' Choice Awards" Voting Is Now Open
- Amazon Web Services Database in the Cloud
- CIA's Jill Tummler Singer Newest Ulitzer Author
- CSC's VP of Cloud Computing to Discuss Orchestration in the Cloud
- Cisco, EMC, VMware & Intel Form Acadia JV
- Plone and Drupal: Different Approaches, Different Results
- Virtualization Expo Call for Papers Deadline December 15
- Sun To Cut 3,000 Jobs, Blames EC
- Move Over BI, Here Comes PI - Performance Intelligence
- Qt DevDays 2009 - Munich
- 4th International Cloud Computing Conference & Expo Starts Today
- 1st Annual GovIT Expo: Letter from the Technical Chair
- SAP CTO to Speak at 4th International Cloud Computing Expo
- Cloud Computing Journal Continues To Publish World's Best Cloud Analysts
- Current Trends in the Data Management Market
- SOA World Magazine "Readers' Choice Awards" Voting Is Now Open
- Apps.gov Will Help Federal Agencies Embrace the Cloud: Vivek Kundra
- Is AT&T Apple's Achilles Heel?
- Oracle-Sun: Gartner Suspects EC of Ulterior Motives
- Amazon Web Services Database in the Cloud
- CIA's Jill Tummler Singer Newest Ulitzer Author
- CSC's VP of Cloud Computing to Discuss Orchestration in the Cloud
- Web Services Using ColdFusion and Apache CXF
- The Top 250 Players in the Cloud Computing Ecosystem
- Eclipse "Pollinate" Project to Integrate with Apache Beehive
- Red Hat Named "Platinum Sponsor" of Virtualization Conference & Expo
- Apache's Tomcat 5.5 is First Release Ever to Use Eclipse JDT Java Compiler
- Beehive Code Now Available in Apache
- An Introduction to Ant
- "Beehive" Now Officially an Open Source Project: Apache Beehive
- SourceLabs Completes Open Source Java Middleware Platform With Apache Tomcat
- Apache Announces Jetspeed 2.0 Open Source Enterprise Portal
- How to Build RIAs with Apache Derby and Grizzly Comet
- Apache Geronimo To Miss August 6 Launch Date Target







































