Feeds

Patchy app development security slammed

Eight out of 10 tested apps riddled with flaws

Next gen security for virtualised datacentres

Eight in 10 applications failed to pass stricter security testing standards in test by application security assessment firm Veracode.

Veracode tightened up its testing procedures so that apps prone to cross-site scripting and SQL injection errors automatically failed. This zero tolerance policy reflects that fact that these two classes of errors are so frequently exploited by hackers of varied stripes to access customer data or intellectual property.

Data from the Web Hacking Incident Database suggests that 20 per cent of reported breaches can be traced back to SQL injection exploits of one type or another.

Last year, under a less strict testing regime, 57 per cent of apps failed to pass muster on first inspection. This figure has reached 80 per cent under the new zero-tolerance for SQL injection policy.

The latest edition of Veracode's State of Software Security Report covers results from the analysis of 9,910 applications submitted to Veracode’s cloud-based application security testing platform over the last 18 months. The security firm reports that government apps are "less resilient to common attacks compared to other sectors". For example, analysis by Veracode revealed that 40 percent of government web applications accessed had SQL Injection issues as compared to 29 percent for finance and 30 percent for software development firms.

The study also discovered that common application development mistakes are also creep into mobile applications. Veracode found that mobile developers tend to make similar mistakes to enterprise developers, such as the use of hard-coded cryptographic keys. More than 40 per cent of the Android applications analysed had at least one instance of this flaw, which makes it easier for attackers to launch broader assaults. Attackers need only obtain the one common key to attack all instances of a vulnerable application in the same way and (perhaps) at the same time.

On a more positive note, Veracode reckons insecure software can usually be remediated quickly, without negatively impacting rapid development cycles. More than 80 per cent of the apps that flunked Veracode's tests at the first attempt were successfully modified to make a passing grade within one week, it reports. Developer training and education can successfully improve the security quality of the applications out of the gate, Veracode adds.

The latest edition of Veracode’s State of Software Security Report can be downloaded here. The study includes more details on the most commonly exploited vulnerabilities and the risks associated with commercial software as well as a detailed remediation workflow study. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Why has the web gone to hell? Market chaos and HUMAN NATURE
Tim Berners-Lee isn't happy, but we should be
Mozilla's 'Tiles' ads debut in new Firefox nightlies
You can try turning them off and on again
Microsoft boots 1,500 dodgy apps from the Windows Store
DEVELOPERS! DEVELOPERS! DEVELOPERS! Naughty, misleading developers!
'Stop dissing Google or quit': OK, I quit, says Code Club co-founder
And now a message from our sponsors: 'STFU or else'
Apple promises to lift Curse of the Drained iPhone 5 Battery
Have you tried turning it off and...? Never mind, here's a replacement
Uber, Lyft and cutting corners: The true face of the Sharing Economy
Casual labour and tired ideas = not really web-tastic
Linux turns 23 and Linus Torvalds celebrates as only he can
No, not with swearing, but by controlling the release cycle
prev story

Whitepapers

Gartner critical capabilities for enterprise endpoint backup
Learn why inSync received the highest overall rating from Druva and is the top choice for the mobile workforce.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.