Web Applications Under Attack - Four Eye-Opening Findings

Source:
The Internet
Published:
Apr 13, 2009
Pages:
6

Today's business and government organizations depend on software applications to conduct their operations. The need to exchange information with customers, partners and suppliers further requires these applications to increasingly open up to the outside world - bypassing firewalls and other traditional network security designed to protect them and the valuable data they contain. These "open", and largely "web enabled" applications are subject to greater and greater levels and types of attacks as hackers exploit vulnerabilities within the software.

Although there are numerous reports covering viruses, network-based attacks, public vulnerability announcements, and Spam/Phishing schemes, there is little empirical data on the attacks that specifically target web applications. This report aims to shed light on how applications are being attacked.

Over the past six months, Fortify Software gathered data via its Fortify Defender product from numerous, Internet-facing sources. Data for this report was collected from live sites that use Fortify Defender for the expressed purpose of highlighting key findings and trends on real-world attack patterns.

From this data, Fortify expert analysis identified four top trends that can serve to inform decisions around application security strategies:
1. Bot Storming
2. The Rise of "Google Hacking"
3. Directed Attacks
4. The Global and Invisible Nature of Web Application Attackers

To download the full whitepaper/case study, please provide the following information:

Other The Internet White Papers

Re-engineering Legacy to Web Application

Reengineering of software is described as the examination and alteration of a system to reconstitute in a new form. The approach is to renovate and extend the current application into new technology to best support the needs of the current business. Application modernization should be achieved by leveraging the existing investment in application infrastructure and reposition the product advantageously for the future. The challenge on hand is to convert legacy application to web application by reengineering legacy components to re-usable components. The web application can be easily integrated with web technologies.