Take time to read your paper against the rubric. I have highlighted yellow important rows which you should target.
Running head: WEB APPLICATION SECURITY 1
WEB APPLICATION SECURITY 8
Effectiveness of Veracode’s Web Application Security Testing and Scanning Solutions
Action Research
IST 8101
Bharath Yerukala
Table of contents
Proposal 8
References 11
List of Figures
Figure 1: Vendor Application Security Testing 6
Figure 2: 3 Steps to Web Application Security 7
Figure 3: Visual Representation 10
Web Application Security Testing and Scanning
Literature Review
The web technologies have tremendously advanced in the recent past. This is coupled with the changing business environment that has made the web applications more prevalent in the corporate world, as well as the government and public services (“The Government of the Hong Kong Special Administrative Region,” 2008). The organizations have found more usages of the web applications and among these usages include data storage and customer relationships management.
It is a fact that the web applications can offer both efficiency and convenience. However, these are affected by the security threats that have the ability to potentially pose risks to the corporate IT infrastructure when not handled in the appropriate manner. According to Veracode (Veracode, 2013), the modern digital works is are characterised by the interactions between the companies, and their customers, and suppliers through the web applications. The web applications are considered as the organizational link to the outside world, and this makes the corporate web applications one of the corporate most important assets for any corporation. This being the case, the cyber attackers also sees the web applications as the most important assets for the organizations, thereby making the web applications a prime target for the cyber-attacks (Veracode, 2013). It is, therefore, obligatory for the organizations to take appropriate measures to ensure that their web applications are secure.
Veracode (2015) highlights that the past few years are have been characterized by tremendous increase in security bleaches breaches and successful attacks at the web application layer. This being the case, it becomes apparent that an organization can only manage to fully secure the web application from the cyber-attacks by securing the three primary access points to the digital data. These points are the network, the software, and hardware that support the business operations.
A report on web application security presented by Desmet, Johns, Livsits, and Sabelfeld (2012) outlines a history of the evolution of the web applications “from the simple and stateless delivery mechanisms for static hypertext documents to a fully-fledged runtime environment for distributed multi-party applications” (Desmet, Johns, Livshits, & Sabelfeld, 2012, p. 1). In the modern era of web application development, the web technologies have indeed shifted from the central server technology to the richer client paradigm, as well as the livelier interaction models.
Since web application security has become paramount, security and testing has become inevitable. Web application security testing is the process of determining how secure a web application is, while the web security scanning entails looking out for vulnerabilities. According to Veracode (2016), “the software application has become the enterprise’s new security perimeter. This is true that ever when it comes to web application security and web application testing” (Veracode, 2016, para. 2).
Figure 1: Vendor application security testing. Adapted from Veracode. (n.d.). Vendor Application Security Testing. Retrieved from Veracode.cm: http://www.veracode.com/services/vendor-application-security-testing
Veracode (n.d.) defines the application security solutions as the tools and technologies for addressing the application security. Strong web application security solutions often start with a strong strategy that ought to address and continuously improve the three basic steps in web application security testing and scanning. These steps are:
· Identifying the vulnerabilities, Comment by Anand Singh: Add page or paragraph number at the end of the last bullet.
· Assessing the risk, and
· Fixing flaws and learning from past mistakes.
Figure 2: 3 steps to web application security. Adapted from Veracode. (2006). Black Box Testing / Dynamic Analysis (DAST). Retrieved from veracode.com: http://www.veracode.com/products/dynamic-analysis-dast
The end goal for any organization is to go for mature and a robust application security solution that will assess every application regardless of whether is built in-house, compiled, or purchased. The web application should also enable the developers identify and fix the vulnerabilities when they are coding. It also should take advantage of the automation and the cloud-based services to incorporate easily the security into the process of development and scaling of the program. Lastly, an ideal web application security should offer all the resources required during the processes like project scoping, reporting, remediation, vulnerability scanning, and vulnerability identification (Abela, 2014).
Proposal
Having understood the concept of web application security, as well as web application security testing and scanning, this action research will endeavour to establish the effectiveness of the web application security testing and scanning tools offered by Veracode Inc. as compared to some others in the market. The basis for this action research is the knowledge of what it takes for a web application security testing and scanning solution to be regarded as an ideal solution. The services offered and the features of the solutions is the key determining factor of the effectiveness alongside other capabilities that might include customization and the ability to integrate several web applications in the testing and scanning process.
The focus of this action research will be to identify the web application security offered by the company of reference and the ability of these solutions to solve the various web application problems. The action research will undertake also to work with the company’s employees, as well as the users to identify the benefits they derive from using Veracode’s product. The action research will have five iterations as discussed below:
Iteration 1: Research focus. The first iteration will entails the researcher determining the focus of the research. The topic and the problem under investigation is identified. After identification, several issues pertaining to the topic/problem are made clear.
Iteration 2: Reviewing literature. The second iteration will involve gaining an insight into what the topic or problem. A literature review is conducted with the aim of gaining an understanding of the nature of the problem, as well as narrow down the focus of the research as established in the first iteration. A review of literature is important because it also gives insight to what has been done by other researchers, and to also gain knowledge of methods that work and those that do not. This iteration will simply be intended to shed some more light into the issue for easier assessment.
Iteration 3: Company’s data collection This iteration entails working in the company’s environment to establish how decisions pertaining to the type of product to offer to certain customers are made. This is because an effective product will be customized to meet specific needs. Comment by Anand Singh: Awkward sentence.
Iteration 4: User data collection Iteration 4 can be said to the most important iteration, and this is because it seeks to establish user’s experience, the greatest factor that determines the effectiveness of the company’s solutions.
Iteration 5: Data analysis and reporting. The last iteration entails analysing the data collected in iterations 2, 3, and 4, and to generate and present the research report.
Iteration flows
The diagram below illustrates the iteration flows in this action research:
Iteration 1: Research Focus
Reflect
Observe
Act
Plan
Iteration 2: Research preparation
Reflect
Observe
Act
Plan
Iteration 3: Company data collection
Reflect
Observe
Act
Plan
Reflect
Observe
Act
Plan
Iteration 4: User data Collection
Iteration 5: Data analysis and reporting
Reflect
Observe
Act
Plan
Figure 3: Visual Representation Comment by Anand Singh: Figures, Tables, and other illustrations See pages 150-167 of APA manual for correct format to cite figures. – Hint: pay attention to the wording used.
References
Abela, R. (2014, April 11). Why Web Vulnerability Testing Needs to be Automated. Retrieved from netsparker.com: https://www.netsparker.com/blog/web-security/automatic-web-application-vulnerability-testing-detection/
Desmet, L., Johns, M., Livshits, B., & Sabelfeld, A. (2012). Web Application Security. New York: Microsoft.
The Government of the Hong Kong Special Administrative Region. (2008). Web Application Security. 1-26.
Veracode. (2006). Black Box Testing / Dynamic Analysis (DAST). Retrieved from veracode.com: http://www.veracode.com/products/dynamic-analysis-dast Comment by Anand Singh: Try to have variety in your references. In your future papers, add complete information about the authors and publication date information as part of your research/references.
Veracode. (2013). 3 Steps to Get Started with Web Application Security. Veracode.
Veracode. (2014). Veracode Input for Developing a Framework to Improve Critical Infrastructure Cybersecurity. Retrieved from Veracode.com: http://csrc.nist.gov/cyberframework/rfi_comments/veracode_040413.pdf
Veracode. (2015). Ultimate Guide to Getting Started With Application Security. Veracode. Retrieved from http://www.veracode.com/sites/default/files/Resources/Whitepapers/ultimate-guide-to-getting-started-with-appsec-veracode.pdf
Veracode. (2016). Web Application Testing Is Critical to Enterprise Security. Retrieved from veracode.com: http://www.veracode.com/products/dynamic-analysis-dast/web-application-security-testing
Veracode. (n.d.). Vendor Application Security Testing. Retrieved from Veracode.cm: http://www.veracode.com/services/vendor-application-security-testing
Veracode. (n.d.). What id Application Security? Retrieved from Veracode.com: http://www.veracode.com/sites/default/files/Resources/Whitepapers/what-is-application-security-veracode.pdf