Study Nails Extent of Insecure Software
What percentage of commercial software would you estimate to be secure? 90 percent... higher? It must be safe if it's being sold commercially, whether for enterprise or consumer applications, right? The actual percentage may shock you.
Only 42 percent of software passed core-security testing, according to a new report, "State of Software Security" (registration required, or you can download just the executive summary). With the release of this ground-breaking security report, Veracode has demonstrated that most commercial software applications are to some degree insecure. This report includes some shocking revelations, namely, that organizations are highly prone to attack, and users extremely vulnerable to cybercriminal activity.
Test results were even worse when applied against known industry standards such as Open Web Application Security Project Top 10 (2007) and CWE/SANS Top 25 most dangerous programming errors (2009). An almost unbelievable 88 percent of developed applications failed in testing against these benchmarks.
In general, only 38 percent of commercially developed software and a paltry 31 percent of internally developed code passed muster. The report also found that coding from third parties actually formed a major component in many applications, even when labeled as "internally developed."
"Third party" is an apparently loose description of components that could have passed (and in many cases did pass) through several developers' hands with no testing before integration and no system of approved suppliers.
Despite the conventional wisdom in some quarters that open-source software is more vulnerable, Veracode actually found open-source apps were safer overall, with fewer potential backdoor vulnerabilities than any other commercial software supplied. Also it had a better all-around score with a faster remedial turnaround -- 36 days, compared to 82 days for commercial development.
Vulnerabilities were found in all coding languages, but the biggest offenders were found to be applications using the C/C++ language. This could be explained in part by the continued popularity of C/C++, but also many such applications used third-party vendors for sections of coding, which remained untested for security.
This was further shown to increase the risk of attack from remote code execution, including buffer or integer overflows. Such hybrids of managed and native code originating from a heterogeneous software supply chain only add to the overall problem, and can be exploited for nefarious purposes, as seen in the recent Aurora attacks.
Despite years of warnings on the threat of cross-site scripting (XSS) vulnerabilities developers are shown to be surprisingly unaware of the essence and extent of the problem. Lack of security training was singled out for criticism; applications where developers had security training were safer and still provided a cost-effective coding solution.
Financial and governmental sectors were found to have the most secure systems. More investment and new industry requirements following data breaches may have stimulated action by related industries, and although more still needs to be done, other sectors can learn from these examples of securing the backdoor.
Security requirements in outsourced suppliers are often overlooked in an environment where outsourcing is seen as the cheaper option and, increasingly, as a component in applications. This presents a problem when security specifics are not fully detailed and no minimum acceptance testing is required.
Many in the security community who advocate publicizing vulnerability issues have argued for some time that the majority of software being supplied to enterprises, governmental departments, and end users alike was not secure. Now we have evidence to support this perspective. If nothing else, consumers and enterprises should demand an approved standard or third-party mark of security for software applications, just as we do with prescription drugs and electrical appliances.
By Jart Armin
HostExploit News Feeds
Latest News
-
Router Hacking, Warkitting Take Stage at Black Hat Router hacking and modem security is in the news again, thanks...
-
Millions of fake items seized in fight against counterfeiting and piracy A regional breakdown of the fight against piracy and counterfeiting...
-
Nation needs ways of reducing Internet censorship The Internet is reportedly among the candidates for this year’s...
- 1
- 2
- 3
HE Twitter
Google Security News
- Researchers Hack the Internet to Keep Us Safe - Black Web 2.0 15:47 (GMT) - 30.07.2010
- Read all 'Cyber Command' posts in Military Tech - CNET (blog) 14:18 (GMT) - 30.07.2010
- Norton Internet Security 2010 - ITWorld Canada 12:34 (GMT) - 30.07.2010
- Webroot Internet Security Complete 2011 - PC Magazine 11:01 (GMT) - 30.07.2010
- Internet 'key holders' are insurance against cyber attack - msnbc.com 9:47 (GMT) - 30.07.2010
- McAfee Acquires tenCube – Makers of WaveSecure - Phandroid.com 7:55 (GMT) - 30.07.2010
- Skull Security Offers Up 100 Million Facebook Profiles to Anybody - DailyFinance 22:00 (GMT) - 29.07.2010
- Black Hat 2010 - Day One Roundup - The Tech Herald 19:08 (GMT) - 29.07.2010
- RIM Acquires Internet Domain Name Rights to Blackpad.com - Bloomberg 17:24 (GMT) - 28.07.2010
- Webroot adds functions to security software (podcast) - CNET 21:41 (GMT) - 26.07.2010



