Search
Lori MacVittie - Two Different Socks
You are here: DevCentral > Weblogs

posted on Thursday, June 19, 2008 4:08 AM

Verizon Business recently released its 2008 Data Breach Investigations Report, covering more than 500 different security breach incidents occurring in the past four years. It's a fascinating read and should be mandatory for business and IT professionals alike.

The report should be of assistance to those attempting to decide whether to comply with requirement 6.6 of PCI DSS by deploying an application firewall or engaging in code reviews. The answer? Both are necessary; not because the standard requires both, but because employing both will provide the best coverage across a varied set of attacks.   Verizon's report indicates that web applications are a significant percentage of the venue exploited in the incidents studied.

 

As if that weren't bad enough, of the 59% of all attacks resulting from hacking and intrusions, 39% were targeted at the application layer.

Breakdown of Hacking/Intrusion Breaches

Attacks targeting applications, software, and services were by far the most common technique, representing 39 percent of all hacking activity leading to data compromise. This follows a trend in recent years of attacks moving up the stack.

Verizon attributes the rise in breaches deriving from hacking with this nugget of truth: "many tools are available to help automate and accelerate the attack process". The question, then, is why aren't more organizations garnering help automating and accelerating the defense process by deploying a web application firewall?

What Verizon's research should do is scare the crap out of you. Seriously. But what it should also do is provide a sturdier soapbox on which security professionals can stand when they're trying to explain that yes, code reviews and web application firewalls are both A Very Good Idea. With attackers moving "up the stack" at an alarming rate, it seems only prudent that security professionals employ All Means Necessary to prevent their organization from being showcased in Verizon's next data security breach report.

Imbibing: Water



Feedback

No comments posted yet.

Let Me Know What You Think


Please use the form below if you have any comments, questions, or suggestions.

Title:
 
Name:
 
Email: (so we can show your gravatar)
Website:
Comment: Allowed tags: blockquote, a, strong, em, p, u, strike, super, sub, code
 
Please add 2 and 6 and type the answer here:

Blog Stats

Posts:980
Comments:1685
Stories:0
Trackbacks:583
  

Image Galleries

  

Application Delivery

  

Cloud Computing

  

Random

  

Security

  

Chat Catcher

82,243 Members in 102 Countries and Growing!

Join DevCentral Today!

About DevCentral

DevCentral has been a successful, thriving community for many years. We have always strived to bring you the best technical documentation, discussion forums, blogs, media and much more that we can.

So dive in, get familiar with DevCentral. We hope you like it, we hope it makes your job easier, and lets you get that much more power out of the community. To learn more, make sure to check out the Getting Started section. And if you have any problems, or think something could be easier to use, drop us a line to let us know.

Got It !

We've received your comment and transmitted it directly to DevCentral HQ.

Thanks for taking time to let us know what's on your mind. At DevCentral | Community Matters!

Get In Touch With Us

Have questions, suggestions or just want to get something off your chest?

Use our handy form below to Direct Connect with DevCentral Mission Control.

Send Us Feedback       or