New Users

Tomorrow's Technology Today - Application Security

An Approach to Testing Web Application Security

Current Scenario: A

Technology

Tomorrow's Technology Today: A

Conclusion: Testing Web applications for security defects is now considered a necessary part of the development process. However, none of the traditional methods of automated security testing provides comprehensive security coverage and accurate results for Web applications. While source code analysis is capable of finding insecure programming practices that have potentially rendered the code vulnerable to malicious attacks, it can be limited by the types of languages that have been utilized in crafting the Web application and can only find potential vulnerabilities rather than actionable results. While black box testing techniques are beneficial because they eliminate language dependency and the need for parsing the source or binary code into an analyzable form, they are also limited by the fact that do not have access to the source code, and if unable to "guess" where some pages or files are located, can provide a false sense of security by producing numerous false negatives. Only an approach that combines the strengths of both source code analysis and black box testing can be used to produce secure Web applications. This hybrid analysis approach can provide broad code coverage, identify all points of input to an application, track data as it moves through an application, and then validate the vulnerabilities it does find, ultimately resulting in more accurate results. Developers should look toward hybrid analysis tools that combine the depth of source code analysis with the accuracy of black box testing to help them secure code more easily and confidently.

S.P.I. Dynamics, Inc.
115 Perimeter Center Place NE
Suite 1100
Atlanta, GA 30346 USA
Tel: 1-866-774-2700 or 678-781-4800

Download the actual white paper
From Info Security Products Guide site: CLICK HERE

Recommend this to others:

1    2    3    4    5  
Rating Key: 1=Worst 2=Satisfactory 3=Good 4=Very Good 5=Excellent
     
Please include your complete details here:
     
First Name :
Middle Name :
Last Name :
     
Title :
Company Name :
Mailing Address :
     
City :
State :
Zip / Postal Code :
Country :
Telephone :
(with area & country code)
Primary Email :
     
Yes, I want to subscribe to email newsletters from Silicon Valley Communications (please tick here)
Yes, I want to receive promotional offers
Yes, please include my email in your power voters list
     
 
     

HOME |

ADVERTISE WITH US |

TELL US ABOUT YOURSELF |

UPDATED PRIVACY POLICY |

CONTACT OUR EDITORS |

Copyright © 2006 Silicon Valley Communications - All rights reserved.

   Info Security Products Guide  Storage Products Guide  Wireless Products Guide  Software Products Guide  Network Products Guide