Security - CIOInsight
Home arrow Security arrow Web App Vulnerabilities Emerge as Enterprise Security Threat

Security Slideshow:
Web App Vulnerabilities Emerge as Enterprise Security Threat

By Dennis McCafferty on 2010-10-13


Information security threats are striking networks with more sophistication than ever, according to a recent report from HP. Many incidents are related to the growing employee use of Web-based business applications and social-networking sites while on the corporate network. While these tools help build brand awareness, increase customer sales/interaction and improve productivity, the applications often open up the enterprise to serious security threats. The report urges CIOs and other senior tech managers to reduce risk by studying PDF flaws; shutting down attacks faster by identifying new, covert techniques of attack; and preventing older threats from recurring by recognizing their pervasiveness. “By understanding the increased risk these applications pose to the corporate network,” says Mike Dausin, manager of advanced security intelligence for HP TippingPoint DVLabs, which produced the report, “organizations can implement remediation strategies to ensure that business processes – as well as data – remain secure.” The reporttracks incidents for first-half 2010; here are some of the statistical highlights:

LATEST STORIES

BLOGS
 
  • of

80 percent

80 percent is the share of network attacks that target Web-based systems.

4,059

4,059 is the total number of Web application vulnerabilities found for first-half 2010.

790

790 is the number of cross-site scripting vulnerabilities impacting Web applications in first-half 2010.

155

155 is the number of cross-site request forgery vulnerabilities impacting Web applications in first-half 2010.

542

542 is the number of SQL-injection vulnerabilities impacting Web applications in first-half 2010.

385

385 is the number of buffer-overflow vulnerabilities impacting Web applications in first-half 2010.

378

378 is the number of “remote-file include” vulnerabilities impacting Web applications in first-half 2010.

418

418 is the number of denial-of-service vulnerabilities impacting Web applications in first-half 2010.

Known, Un-Patched Vulnerabilities

MS ExplorerJune 2010: 6May 2010: 1

Known, Un-Patched Vulnerabilities

Mozilla FirefoxJune 2010: 9May 2010: 2

Known, Un-Patched Vulnerabilities

Safari/WebKitJune 2010: 20 May 2010: 19

Known, Un-Patched Vulnerabilities

Flash/ShockwareJune 2010: 12May 2010: 9

199,077

199,077 is the number of HTTP client-side attacks in June 2010, mostly stemming from malicious JavaScript and file-format attacks, up from just under 150,000 in May.

12 million

More than 12 million is the number of HTTP server-side attacks in June, mostly XSS, SQL Injection and PHP RFI, up from just over 9.8 million in May.

28,477

28,477 is the number of SMB attacks in June, up from an estimated 28,200 in May.

82,203

82,203 is the number of JavaScript-based attacks in June, up from about 67,500 in May.

  • More slideshows

FEATURED SPONSORED VIDEOS

FEATURED SPONSORED ARTICLES

Erasable E-Paper Saves Trees, Cuts Costs

Why Smart Companies Should Adopt the Lessons of Gaming

Interest in Mobile WiFi Hotspots Fuels New Solutions

A Closer Look at Public Cloud Security

View More Articles

  Brought to You By
Click Here



 

Advertisement

Sponsored Links
  • Try Windows Azure free for 90 days

  • Introducing the world's first family of systems with integrated expertise

  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 77% of the Fortune 500 Manage Content Securely with Box.
  • Leverage your virtual computing environment with Dell.
  • Build an IT Infrastructure That Delivers the Future
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • eWEEK Quick LInks

     
    Close this advertisement