The Macrosite for News, Analysis and Opinion about the Future of the Internet
Scott Koegler

A Provider's Lessons on SaaS Security

Written by Scott Koegler
11/22/2010 7 comments
no ratings
DISCUSS     Email This

The last time I proposed that we should collectively “get over” our concerns about SaaS and cloud security issues, I was making the point that whether we think these kinds of services are secure or not, the time has come to deal with the issues in the same way we deal with security for hosted applications.

The reality is that just because you've implemented a SaaS application doesn't mean you’re necessarily any more -- or any less -- safe from security threats.

I don't believe any one technology has a lock on security. From my perspective, if there is either data of any value or personal notoriety to be gained by penetrating an enterprise, you'd better be vigilant about the apps you use - whether they are inside or outside your firewall.

A report just released by security SaaS vendor Veracode provides a great insight into the kinds of vulnerabilities they've found in the nearly 3,000 assessments they've performed. Here’s a recap of Vercode’s top findings from their assessment of 2,922 applications:

Eight out of 10 Web applications failed to comply with the OWASP Top 10, a list of the 10 most dangerous Web flaws;

Cross-site scripting is the most common vulnerability;

Third-party applications were found to have the lowest security quality;

No single method of application security testing is adequate by itself.

What I find fascinating about this report (aside from the findings themselves) is the way the company is able to draw its conclusions. The assessment application is a SaaS-based application, and the results are stored in a single datastore. This makes all their results available for aggregated research. That means it's possible to fairly easily create reports based on nearly any criteria. That’s a strength of the SaaS-based approach, and one that puts the technology at the top of my list of “great strides in computing.” On the other hand, I wonder how Veracode’s applications themselves stack up against the same tests they perform for their clients.

If you look through the report, you'll see conclusions based on application type, developer type, industry vertical, vulnerability type, time to resolve identified issues, application language, and several other top-priority evaluations.

The first two findings above are particularly interesting in that they point out that the majority of all software fails to meet “acceptable” security levels and that an Internet connection that supports cross-site scripting is the main culprit in enabling the most prevalent vulnerability.

The message I take away from this is that the easy way to be secure is to unplug the Internet connection. Unfortunately, that's increasingly impractical if not impossible in today's connected environments. The second best practice is to perform vulnerability assessments on all your applications, and where possible, include commitments to resolve deficiencies in contracts and SLAs, prior to making any business arrangements.

— Scott Koegler was a CIO for 15 years and has been writing about technology for the last 18 years. He is editor of www.ec-bp.org, a newsletter that addresses supply chain technologies, and manages other newsletters at www.YourCompanyNewsletter.com. You can contact him at scott@koegler.net.

DISCUSS     Email This
Current display:       newest comments first       display in chronological order
nimantha.de
IQ Crew
Tuesday November 30, 2010 5:40:18 AM
no ratings

Software as a Service another Open Source revolution. Gud post mate.. Its always nice to learn the protective methodology. 

JC Cameron
IQ Crew
Tuesday November 23, 2010 3:55:36 PM
no ratings

Security always seems to be the item at the bottom of the list that no one wants to get to or think about.  It is always 'we'll get there when we can' or 'that's good enough for now' or 'no one would really even bother to try to get into this'.

It's tough stuff - the black hats are always out there always looking for an opportunity and being paranoid about it rarely makes you friends - the cost is high, the effort is high, and it is hard to know when you've actually done a good job in the end.

-jc

Scott Koegler
Thinkernetter
Tuesday November 23, 2010 1:32:09 PM
no ratings

I'm not proposing that Veracode is better than (or even as good as) any other provider. I take their analysis as a good look at the state of software security, which seems to be pretty poor. It doesn't seem to me that the company is looking to promote its own agenda by way of its research, other than to say that if you're using software, you probably need to be doing some testing and then some fixing. That said, I'm sure they would be happy to contract to help with those kinds of tasks.

jnieusma
Rank: Cave Painter
Tuesday November 23, 2010 1:10:52 PM
no ratings

Is Veracode any better at securing these issues than other products? It seems like just another product propaganda publication. When setting up a network, the IT department, be it one guy or twenty, has their own recommendations for security. The various products on the market will always be sniping at one another. How do you choose?

modza
IQ Crew
Monday November 22, 2010 5:09:26 PM
no ratings

In any and all roles: writing specs, developing, error-checking, testing, deploying, maintaining, using?

Combine the report you quote with one from a couple of months ago that a similar proportion of IT professionals don't take all the obvious precautions themselves, and one might be inclined to throw one's hands up and give up. But the (very slow) progress of checklists for doctors is encouraging. Simple thing like a checklist. Check off the top ten items on this report and the one I referred to, and you probably stop 99% of all problems before they can get a foothold.

 

Michael P. Kassner
Thinkernetter
Monday November 22, 2010 10:25:18 AM
no ratings

I don't think SaaS security should be talked about unless you include virtualization. The fact that multiple databases can reside on the same piece of hardware has to be a security consideration, just as much as the fact that the data is cloud-based. 

abdlah
IQ Crew
Monday November 22, 2010 6:27:19 AM
no ratings

Clearly there is work, as there always has been, to be done in an attempt to secure our applications over the Internet. Since identifying a problem is half the solution, what needs to be done now is to find ways to resolve the vulnerabilities identified.

Security would always be an issue, the realistic thing is to have a means of reducing its negative effect.

The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from Scott Koegler
Scott Koegler
Scott Koegler   12/26/2011   15 comments
Email continues to grow despite the seemingly endless onslaught of social media sites featuring updates for hundreds of millions of people around the globe. The reason for email’s continued prominence becomes obvious when you understand that social media is a “go-to” communication method, while email is a “hear-from” communication.
Scott Koegler
Scott Koegler   10/6/2011   11 comments
The majority of enterprise resource planning (ERP) systems -- in fact, the majority of all applications in use in enterprises of all sizes today -- are server-based. The burden of maintaining and managing these systems represents a significant percentage of company time and revenue.
Scott Koegler
Scott Koegler   9/27/2011   24 comments
3D printers are not particularly new. They have been used increasingly for rapid prototyping and for producing unique replacement parts for the last few years. The real news is that there's likely to be a 3D printer on your desk in the near future. You'll be dragging 3D images you find online to your 3D printer icon, turning the Internet into a physical prototyping and creative delivery service.
Scott Koegler
Scott Koegler   9/13/2011   23 comments
Storing images online is nothing new. Services ranging from Flickr to Picassa and hundreds more deliver photo-hosting and viewing experiences as a matter of course. But all these services have something in common: limitations with regard to photo editing.
5
of
IETV: the thinkerNet on film
5
of
2pm EDT
Thu
Mar 15th
an IBM information resource
sponsored content
an IBM information resource
sponsored content
Empowered CMOs, Empowered Customers
Chief marketing officers (CMOs) are at a crossroads. Like CFOs a decade ago, their position in the organization is about to change dramatically, impacting not only traditional marketing functions like public relations and promotion, but also requiring a greater partnership with fellow C-suite decision makers. In interviews with over 1,700 CMOs worldwide, IBM found that CMOs are keenly aware of their specific set of challenges.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Free Internet Act Could Launch Positive Change
Joe Stanganelli
In a recent Internet Evolution post, Ron Miller
likened the current legal battles regarding intellectual property and the Internet to a fantasy universe. While Ron specifically invoked The Lord of the Rings mythos in his piece, new developments on Reddit suggest that this fantasy realm analogy may more properly reflect the DC Comics Universe.

CLICK FOR MORE
Mary E. Shacklett
Cloud Needs System Management Superstructure

12|26|11   |   2:14   |   No comments


Cloud is pushing classic corporate data centers beyond their physical boundaries and into new territory to where they one day might be expected to federate with different clouds. For this to happen seamlessly, a new class of systems management superstructure software will be needed.
Mary E. Shacklett
Help Is Coming for Virtual Image Deployment

11|15|11   |   2:18   |   3 comments


Today, most sites manually create scripts for virtual system image and deployment in the cloud. This consumes time and can introduce error. Now, systems vendors are coming to the rescue with new automation tools that expedite and bulletproof the process. This is good news for the cloud.
Second Shooter
IBM's New Vision of the Cloud

2|16|12   |   2:07   |   10 comments


IBM's latest user survey suggests that the real value of the cloud lies in enabling new business models, not in doing old IT stuff cheaply. If that's the case, we need a whole different kind of cloud debate, and a new vision of cloud services.
Mary E. Shacklett
Verticals Need Turnkey Cloud Solutions

1|3|12   |   2:28   |   3 comments


65% of CIOs are on board with cloud, but 55% are still thinking about it. Risk is the major barrier to entry. Cloud purveyors can help to address this by providing turnkey cloud solutions targeted at specific vertical industry markets.
Staci Cenis
Multnomah County: Multco Commons Gets a Go-Live Date

12|22|11   |   1:12   |   No comments


Staci Cenis gives an update on Multnomah County's project status and new go-live date.
Staci Cenis
Multnomah County: Multco Commons Hits a Project Delay

12|2|11   |   1:01   |   1 comment


Multnomah County has hit a delay with its intranet migration.
Mary E. Shacklett
Risking Lock-In With Commodity Cloud Solutions

12|1|11   |   2:06   |   No comments


Companies might be eager to secure commodity cloud solutions like virtual desktop infrastructure (VDI), but they need to maintain their agility so they can change vendors in the future, if need be.
Sherry Swackhamer
Multnomah County: More Flexibility, Less Cost

11|29|11   |   0:53   |   No comments


Multnomah County's CIO explains the decision to move the internal intranet to an external cloud.
David Austin
Multnomah County: Moving on From 'Old & Clunky'

11|23|11   |   2:16   |   No comments


Dave Austin, communications director for Multnomah County, discusses why he's excited to move from the county's "old and clunky" intranet and onto an open-source platform, and how this change will help him do his job.
Staci Cenis
Multnomah County: Cloud Cost Savings

11|18|11   |   1:10   |   1 comment


Staci Cenis, IT project manager for Multnomah County, discusses the cost savings of moving to the cloud and how this transition will bring users functionalities they've been requesting for a long time.
Kim Davis
Thinking Pretty at TED

3|2|12   |   2:14   |   1 comment


Dewar's Hub at TED 2012 is an interactive Twitter tool that lets you rummage vaguely through a world of ideas.
what.the.ferraro
Goodbye, Real Life. Hello Video in a Hat

3|2|12   |   2:36   |   7 comments


Are you officially done interacting with society? There's a hat for that.
Second Shooter
AT&T Creates More Neutrality Confusion

3|1|12   |   2:12   |   2 comments


The AT&T notion of letting some apps "buy" the data for its users seems inconsistent with the neutrality principles designed to keep big sites from dominating the Internet. Is the principle wrong, or is AT&T's policy wrong? We need a consistent position here.
Reiter's Block
The Web Needs National Grammar Day

2|29|12   |   2:59   |   52 comments


March 4 is National Grammar Day, and you enterprise and consumer bloggers need to pay attention.
Wisdom of the Big Chair
Video Conferencing Presents New Security Holes

2|28|12   |   1:57   |   4 comments


Video conferencing is becoming much more common in business today, but it introduces new security issues. For instance, intruders may be able to tap into your sessions and learn trade secrets. Here are steps companies can take to ensure their sessions are secure.
what.the.ferraro
Adventures With Siri

2|27|12   |   03:56   |   14 comments


Nicole and Kim (and their respective accents) request things of Siri, the iPhone 4S virtual assistant, to see what she's capable of. The result? Not much.
Second Shooter
Gaming May Drive Apple's 7-Inch iPad

2|24|12   |   2:05   |   15 comments


We think Amazon's Kindle Fire is pushing Apple to a smaller iPad format. But Sony's Vita and the interest in a small device for portable gaming may create the real threat. Keep your eye on the tablet-gaming space!
Reiter's Block
Google's Password Generator Is Limited

2|23|12   |   2:51   |   15 comments


Google's developing a password generator and manager for Chrome, but it's got a ways to go.
Kim Davis
Angry in Space

2|22|12   |   1:41   |   19 comments


We've come 50 years from John Glenn's first Earth orbit to the launch of "Angry Birds in Space." Progress?
Mary E. Shacklett
Corporate Email Needs Best-Practices

2|21|12   |   2:08   |   8 comments


Corporate email is a great natural time manager, a great way to communicate across time zones, and a natural way to keep records on ongoing projects and conversations. But there are limits to its benefits.

Enabling People and Organizations to Harness the Transformative Power of Technology