Take time to read your paper against the rubric. I have highlighted yellow important rows which you should target.
Running head: EFFECTIVENESS OF VERACODE’S WEB APPLICATION 1
8
EFFECTIVENESS OF VERACODE’S WEB APPLICATION
Running head should have same font as rest of your paper.
Effectiveness of Veracode’s Web Application Security Testing and Scanning Solutions
Action Research
IST8101
Bharath Yerukala
Table of contents Comment by Dr. Singh: Fix spacing please.
Methodology 5
References 8
Introduction Comment by Dr. Singh: Add title of this paper above Introduction.
The history of web application attacks dates are as far back as the year 2005, when the attackers made the web applications as their predominant target for rich data often pulled from them. More so, the attackers will not hesitate to use the web applications against the customers whereby they probe deeper into other connected systems of an enterprise (Leonard, 2016). The web applications are often developed from various reusable components and frameworks that are very popular like Java and .NET. These are often accompanied by vulnerabilities. The vulnerable web application components, as well as the insecure development practices, have set the stage for the attackers to easily manipulate the vulnerabilities that are found in code and the functional vulnerabilities that include confusing forms field on trusted websites. In other words, the attackers have made the trusted websites ‘drive-by’ traps that tend to capture the access information and also transmit malware to the unsuspecting users (Leonard, 2016).
It is a fact that all the enterprises are technology companies (Veracode, 2012). That is to say that the businesses in the present era are driven by technology characterized by things such as mobile devices, social media, cloud, and big data technologies, and these are dramatically changing the manner in which global businesses deliver innovation. An important aspects of the businesses since time immemorial has been the time to market, and this has exposed some of the information security approaches. It has also been established that most of the organizations do not adequately protect the software used to run their businesses. The ad-hoc application security programs, as well as regimens have resulted to inconsistent policies across the business units of the organization and the software development teams.
With the IT infrastructure being a core component of the organizational systems, the software application has also becomes the new security perimeter of the enterprises, and this can be illustrated by the web application security and testing (Veracode, 2012). Indeed, the web application must be made available at all times, and also offer customers, employees, and suppliers among other stakeholders with data access. This has made the web applications the weak link in the enterprise security. For such reasons, web application security testing has been made a high priority for the modern enterprises. There are a good number of web application security testing and scanning that have been shown to be very effective. However, even these do require frequent maintenance and upgrade, as well as heavy investments in the hardware and software (Veracode, 2012).
Veracode is a vendor of various web application security testing and scanning products. The founders of this company are said to have believed that web application security ought to be simple and efficient in terms of costs. In that case, the company delivers a solution to the web application testing, that is, an automated application security testing solution. This tends to make the dynamic analysis available as and when the need arises (Veracode, 2012). The firm offers software for security vulnerability assessment. This software and service often scan and identify the vulnerabilities in code (DuPaul, 2016). The company deems its vulnerability assessment tools and software to be the superior alternative and this is because of the fact that ideal vulnerability assessment software does not always deliver organizational security. The ideal software is expensive to purchase and learn, and tend to promise to find the flaws in the web applications in order to fix them before they can harm the business (DuPaul, 2016).
With the above statements being made, the question remains ‘how effective are the solutions offered by Veracode?’ in that case, this action research will seek to explore the various web application security testing and scanning solutions offered by the company and benchmark them with others in the industry in order to establish how effective they are in delivering web application security.
Methodology
This action researched will be based on the assessment of some selected software to determine their effectiveness in delivering web application security. This effectiveness will be based on the best practices in the industry. In other words, the Veracode’s web application security testing and scanning solutions will be benchmarked against a few others in the industry to establish exactly which position these software solutions are. The action research is adopted because of its features like its nature of problem assessment and solution approach.
Action research has become popular of late, and the increased usage have also made is loosely applied term that imply any attempt to investigate or improve a practice (Tripp, 2005). In that case, a succinct definition of the term action research has not yet been possible for some reasons. The first is the fact that it is a natural process and that comes in many guises, while the second one is that it has been developed differently for the different applications. However, there is a general implication of the term as was coined by Lewin – that is, a general term for four distinct terms: diagnostic, participant, empirical and experimental (Tripp, 2005). The implication here is that an action research is a research that adopts the approach of analysing a problem and finding a solution, often with the engagement of people. According to Tripp (2005), action research is about action and inquiry into that action.
Hine (2013) defines action research as a process of systematic inquiry seeking to improve the social issues that affect the everyday lives of people. He attributes the origin of the term and concept of action research to the works of Kurt Lewin who perceived action research to be a cynical and dynamic, as well as collaborative process. According to Kemmis and McTaggart (1988), action research is a collaborative process that is carried out by people with a shared concern. It is a collaborative inquiry made by the research participants into some scenario in a bid to improve justice and rationality in the underlying practices (Kemmis & McTaggart, 1988). An action recycle has also been described differently with some authors giving a framework with five components while others giving a framework with four components. The framework presented by Hine (2013) entails designing the study, collecting data, analysing the data, communicating the outcomes, and taking action. The framework of the action research cycle given by Tripp (2005) entails the plan, action, monitoring, and evaluation. Conventionally, the action research cycle entails planning, taking action, observing, and reflecting. This is the model that will be adopted in this action research.
With this description of the nature of action research, is can be made clear that its application in the context of the objectives of this research will follow the various maxims of the concept of action research. In other words, this action research will be a collaborative inquiry into the security solutions offered by Veracode and proving the myth that these solutions are indeed the most (or among the most) effective solutions in the market. It will be an inquiry undertaken by the researcher and engaging other people especially the workers and management of the company to establish the practices regarding web application security testing and scanning. Determining the effectiveness of the Veracode’s web application security testing and scanning tools will require background knowledge of the concept of web application security, and the accompanying concepts of testing and scanning.
Once the background knowledge has been fully accomplished, the next thing to do in this action research will be to establish the best practices in the industry, and then use these to gage the effectiveness of the Veracode’s solutions. The immediate implication here is that the effectiveness will be relative in that it is relative to that of other solutions. However, the knowledge of the concepts mentioned earlier on will give an overview of the threats and vulnerabilities, and this knowledge will guide the researcher and the participants on what to expect of a solution. The researcher will, in that case, also define the nature of an ideal solution that is effective in offering web application security.
References
DuPaul, N. (2016). Security Vulnerability Assessment Software. Retrieved from Veracode.com: https://www.veracode.com/security/vulnerability-assessment-software
Hine, G. (2013). The importance of action research in teacher education programs. Issues in Educational Research, 151-163. Comment by Dr. Singh: Add URL for these references.
Kemmis, S., & McTaggart, R. (1988). The action research planner. Geelong,: Deakin University Press. Comment by Dr. Singh: Add name of the country after city.
Leonard, G. (2016). Getting Started with Web Application Security. SANS, 1-12.
Tripp, D. (2005). Action Research: A Methodological Introduction. 1-21.
Veracode. (2012). Addressing the Scalability Challenge with Cloud-Based Application Security. Veracode, 1-13.
Veracode. (2016). Web Application Security Testing and Scanning. Retrieved from Veracode.com: https://www.veracode.com/products/dynamic-analysis-dast/web-application-security-testing