State of Web Application Security – Sonali Shah, Invicti
Sonali Shah, Chief Product Officer for Invicti, dives into a report on the state of web application security in the federal government.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with sonali. Shah whose Chief security strategist for invicty. They are provider of tools platform services and all that good stuff for securing web applications and they have issued a new report on what's going on with security in the federal government's not only welcome the show.
Thank you for having me. So this report you guys published one of us some of the high points. I mean, there's a lot of awareness these days of web application security issues in the government post the Biden Administration issuing executive order, but what exactly is the challenge?
What did you guys see in your report? Yeah, maybe you'll meet back up a bit and just give some context is to why we did this report because I think that'll that'll provide some good sort of overview of the problem that we're facing. So, you know, as you mentioned Victory is a leader in the web application security space we've been in business for over 15 years and we have you know over 3500 customers.
A large chunk of them are in the government sector. And what we have seen both in the public and private sector is while cybersecurity in general has been a key topic for a while now in particularly recently. There has been an increased focused on application security and in particular securing web applications from the time that they're developed all the way to production.
Now when we talked to our customers in the federal local governments, we often hear of challenges, right? This is difficult thing to do security can sometimes slow down development. There's a shortage of cybersecurity professionals.
And so what we as we get more and more customers in the space, we are always talking to customers to understand what Charter roadmap be and what are the key areas that we can improve to help them? And so that was the context behind this study. So we worked with meretek and interviewed 160 federal cybersecurity leaders evenly split between defense and civilian agencies.
To understand how big of a challenge is this for them and you know kind of where the carry is where we can help them. So just kind of high level snapshot. What we learned is 76% of the respondents said that application security is a critical part of National Security.
And 88% of them experienced a breach via a web application in the past year. That's really high. You know it mirrors what we've been seeing like this trend but 86% is even higher than what you would see would say Verizon.
They release this data breach and incidents response report that Verizon dbir every year and what they say and now they're looking across all sectors not just government that's 70% of all incidents and 40% of all reaches stem from attacks on web applications. So we see this is you know in the government sector it's even more pronounced. Is it your sense that the folks in the government are not quite as mature in their practices as the private sector or they roughly equal.
It's just that there's more attention being paid because of the buying order and these folks are just as smart as anybody else. They just have the same issues maybe in a more public form. That's exactly it right.
I think whether you're it's public sector private sector there all facing the exact same challenge. So today whether it's again government or federal or state local or even private sector Enterprises web applications are the primary way that people are doing business communicating with employees with customers with Partners. There's over two billion web applications in existence today and like growing by the minute, right?
So this is a relatively new area for Enterprises to focus on And I would say that the folks we've met in the government sector are just as Savvy as those in you know, large private organizations, but they're all facing the same issue and it's even worse. I feel with the government sector because there is all of this. First of all the protecting some of the most valuable assets right the the and there the other thing is there a number one attack Factor.
If you look at all the industries across the board that are attacked the government is the most high profile. So I don't I think it's there. They're facing the exact same issues.
It's just they're getting a lot more attention right now. What exactly are some of the technical challenges that people are encountering because on the face of it? It sounds pretty simple if your average business or maybe even it leader.
You're like, okay, we need to lock down and secure the way we build these applications and then when they're deployed we need to secure them better than we have been it should be relatively straightforward and yet I feel like you know, somebody comes down and they have the little sermon on devsecops and then everybody goes back to business as usual. So what is the real challenge? It's just hard to do.
it's just period it's it sounds easy cybersecurity is just hard to do because the attacker it will just take them minutes to go in and get sensitive data. Whereas, you know, if you look at some of the the industry stats out there it can take months to years to even for for us to even identify that a breach has occurred and then attribution also is very hard. So it's Just that it's it's difficult to do.
So now the next question is why is it difficult to do? Well it requires so you mentioned devsecops right? So that's the way that where everyone's looking at attacking this problem and for some of your viewers who may not be familiar with it.
It's really just devsecops is really just embedding security into the software development life cycle very early on so from coding and testing and QA and then regularly scanning in production. But this is a change from the way software's been traditionally done. So you're you need a different set of skills.
I mean most developers today, you know, they may graduate with a degree in you know engineering but they haven't been learned how taught how to code securely it's not you know, it's not part of their requirements. So I think it's it's the skills and it's a different way of doing things and it's a different it's a different culture and that takes time to change. Is it really an effort to educate the developers many of whom I think money they're only exposure to your point was an elective in college somewhere about cybersecurity and it wasn't a requirement.
So most of them probably didn't do it. I'm Or is it more about automating the pipelines in the processes and putting the security checks in the pipelines? Because it seems like asking the developers to become Security Experts may be a big ask.
It is it absolutely is and I would say. It's both and I would add a third thing. So first of all.
The Mandate for cyber security has to come top down. that's already happened with the government right but It's got to be within the Departments. It has to be something that becomes part of the the check before anything is released has the application been scanned how many high severity vulnerabilities are there?
What has been fixed? So today when you you know, you're a developer, you've got, you know, your quarterly objectives and goals. It's usually build this feature that does X Y and Z release it on time and their quality checks that have to be passed.
Rarely, do you see in the objectives? And it should be released without vulnerabilities or without, you know, High severity vulnerabilities, whatever the criteria may be. So I think it has to be built into the culture.
Of it in in terms of how a developer views his or her job and how they're evaluated on their job. That's one piece. Of it exactly as you said providing training.
And that's where you know, there's a bunch of online courses that can be done. You can do security Champions programs that have worked that we've seen in many clients. And then the last part is you mentioned is the automation because if it's very manual.
Then it's a matter of training the developers on security but also then taking a whole bunch of time away from their core competency, which is writing good code. So you're absolutely right. You've got to automate it.
So that testing occurs within the software development life cycle automatically and the results go into the developers environment, whether it's you know, jira or service now or whatever they're using so that they can action on them quickly and in an automated fashion. You can't really talk about automation these days without bringing up Ai, and I guess my question is, you know, can AI save us from ourselves someday, or is that just wishful thinking? I hope it will but for now, I think it's wishful thinking I think a lot of security companies including ourselves are looking at you know, I think what is not wishful thinking is looking at historical data and how we can improve that involves some machine learning.
I know it's big a buzzword machine. Ml AI I think the real AI where is is not there yet. But I think there is quite a bit that we can learn from data particularly in helping us prioritize what to fix first because I think that's a big issue that everybody deals with right you get thousands of alerts from all of your various security systems.
How do you prioritize what really matters? I think that's that's where machine learning can certainly help. What's the one thing you kind of wish most organizations would focus on or you just shake your head and you see over and over again can't believe that we're still wrestling with these issues.
And it seems to me at least a lot of the attack vectors are you know been known for better part of a decade, but you know, why are we still tripping over the same issues over and over again? Yeah, that's a really good question. I mean you look at Cross site scripting SQL injections.
Like they're the same attacks that have been occurring for years and they're still the most popular ones. Look to be fair. There's a lot that's the same but there's also a lot that's changed.
The attack surface has increased first of all. And then the you're the motivations and the weight attackers work is constantly evolving. So as soon as we can't just say, all right, here's the one way into this application and this is what we should look for.
The hackers are getting more and more sophisticated. And they only have to be right once right whereas on the opposite side. The Security Professionals have to grade 100% of the time to not be breached.
So it I don't want to make a light of the problem. By saying that it's the same stuff over and over again. Some of it is but there's there is a lot of changes happening and particularly when you look at like what's happening right now right now with Russia and Ukraine the Cyber War started even before the physical War.
And there is an example of you know, you were saying why why don't people get this well companies that refuse to do business with Russia many of them were attacked and they might even be small companies that don't even have sophisticated cybersecurity teams. So I think that most companies just aren't equipped for it and they didn't think they would be attacked right? It was usually the large Banks and the Healthcare systems that thought.
Okay, we need to protect ourselves from this but now at schools, you know police forces that are are being faced with ransomware. It's the supplier that is no longer going to do business with the Russian government that is being attacked. So it's the problem has become I think more racist and the attack surface has gotten larger.
Do you think that we are developing software to fast and we need to slow down or can we keep the pace that we're on and just make it more secure. Anybody who tells you? that security Adds, no overhead.
Is line like that's just not possible. Right? I mean you think of TSA right?
It's it's gonna add time. Even if you have PreCheck, right? It takes time.
Good good security takes time. So we can absolutely continue innovating we can absolutely continue releasing software multiple times a day. It's all about what you had said earlier automation.
And I would say accuracy is the other piece of it because if you automate everything, but your results aren't accurate. It's like garbage and garbage out right develop you want to make sure that the results that get to the developers are accurate and actionable so they can quickly remediate so that you minimize the amount of time they spend on security and I think that's absolutely possible to do with you know, if you've got scans that are taking minutes. Developers can immediately get the feedback and test and and fix before they remediate so it is it is possible, but I wouldn't say that it will ever get to the point where it's zero overhead.
All right. Well folks I would just say let's have a little empathy for our federal friends. There there dealing with the same issues.
We all are except probably getting paid less for it. So hey sonali. Thanks for being on the show.
Thank you for having me. It was great discussion. All right back to you guys in the studio.