Web Applications Under Attack - Four Eye-Opening Findings
- Source:
- The Internet
- Published:
- Apr 13, 2009
- Pages:
- 6
Today's business and government organizations depend on software applications to conduct their operations. The need to exchange information with customers, partners and suppliers further requires these applications to increasingly open up to the outside world - bypassing firewalls and other traditional network security designed to protect them and the valuable data they contain. These "open", and largely "web enabled" applications are subject to greater and greater levels and types of attacks as hackers exploit vulnerabilities within the software.
Although there are numerous reports covering viruses, network-based attacks, public vulnerability announcements, and Spam/Phishing schemes, there is little empirical data on the attacks that specifically target web applications. This report aims to shed light on how applications are being attacked.
Over the past six months, Fortify Software gathered data via its Fortify Defender product from numerous, Internet-facing sources. Data for this report was collected from live sites that use Fortify Defender for the expressed purpose of highlighting key findings and trends on real-world attack patterns.
From this data, Fortify expert analysis identified four top trends that can serve to inform decisions around application security strategies:
1. Bot Storming
2. The Rise of "Google Hacking"
3. Directed Attacks
4. The Global and Invisible Nature of Web Application Attackers
Other The Internet White Papers
Re-engineering Legacy to Web Application
Reengineering of software is described as the examination and alteration of a system to reconstitute in a new form. The approach is to renovate and extend the current application into new technology to best support the needs of the current business. Application modernization should be achieved by leveraging the existing investment in application infrastructure and reposition the product advantageously for the future. The challenge on hand is to convert legacy application to web application by reengineering legacy components to re-usable components. The web application can be easily integrated with web technologies.
- Application Modernization And Migration Trends In 2009/2010
- Application Modernization: Three High Payback Strategies
- A Case For Better Project Estimation & Planning And Estimating From Use Casess
- Progress Apama in Manufacturing – Complex Event Processing for Driving Bottom-Line Results
- The ROI of Defragmenting the Windows Enterprise
- Web Browsing: The Challenge for Business
- Safe and Productive Browsing in a Dangerous Web World: The Challenge for Business
- Laptop Durability and Security Center
- Hacking Your PBX: 15 Ways to Make the Most of a Modern Phone System
- Bandwidth Bandits
- Protect: Protect Today, Secure Your Future. Best Practices
- Monitoring Enterprise-wide Business Risk
- The Impact of Disk Fragmentation on Servers
- Six Steps to Reduce Risk and Improve Control over Real-time Communications
- The Total Economic Impact of Juniper Networks’ JUNOS Network Operation System
- The 5 Reasons to Worry about Your DNS
- Filtering the Spectrum of Internet Threats
- Fighting the Hidden Dangers of Internet Access
- Threat Roundup and Forecast: Cybercrime Isn’t Predictable. But Trend Micro is.
- Comparing Email Management Systems that Protect Against Spam, Viruses, Malware and Phishing Attacks
- A Window Into Mobile Device Security
- Computing as a Service - Securing Enterprise Cloud
- Web Threats 2010: The Risks Ramp Up
- Build vs. Buy: The Hidden Costs of License Management
- Protecting personally identifiable information: What data is at risk and what you can do about it
- Top Ten Web Threats and how to eliminate them
- Liberating the Inbox: How to Make Email Safe and Productive Again
- The 5 Reasons to Worry about Your DNS
- Fighting the Hidden Dangers of Internet Access
- Sophos Security Threat Report 2007
- Threat Roundup and Forecast: Cybercrime Isn’t Predictable. But Trend Micro is.
- Comparing Email Management Systems that Protect Against Spam, Viruses, Malware and Phishing Attacks
- France Telecom and HP: “Together, we can do more”
- Six Steps to Reduce Risk and Improve Control over Real-time Communications
- Reducing the Risk of DNS Cache Poisoning by the Kaminsky DNS Vulnerability
- Improving the View with IP Videoconferencing
- Google Apps in the Enterprise: A Promotion-Enhancing or Career-Limiting Move for Architects?
- Employee Web Use and Misuse


