IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Majority of attacks aimed at web applications

Security executives claim over 90 per cent of attacks now focus on web applications rather than the traditional network route.

Web app attacks

Nearly all attacks on businesses to steal data are abusing web applications rather than the tried and tested route of networks, according to two senior security executives.

A report by WhiteHat Security and Imperva has claimed that 93 per cent of all the attacks were aimed on existing webs applications and this resulted in stolen data going into the millions.

"It is a dangerous world that we live in," claimed Amichai Shulman, chief technology officer of Imperva, during at interview with IT PRO at InfoSecurity 2010. "In 2009, stolen records were by the ten of millions and this is just [from] one type of an attack."

"The shift from network attacks to application attacks has been going on from beginning of 2000, took pace 2004 and 2005 and, if you remember the network worms in early 2000s, it is now the same level on application layer."

Despite most companies being aware of such attacks, vulnerabilities aren't being fixed quickly enough.

Stephanie Fohn, president and chief executive of WhiteHat, told IT PRO: "Vulnerabilities aren't getting fixed on time. Security has responsibility... to identify problems [then] throw that over the fence to development. They then say "oh, right, later.""

Claiming that even critical flaws can take between one and three months to fix, Fohn believed the initiative to get things done needed to come from high up in a business.

"Security needs to have somebody that is a champion, somebody with some pull in the organisation," Fohn said. "Security needs to take control of security."

Read on for more news from InfoSec 2010.

Featured Resources

Four strategies for building a hybrid workplace that works

All indications are that the future of work is hybrid, if it's not here already

Free webinar

The digital marketer’s guide to contextual insights and trends

How to use contextual intelligence to uncover new insights and inform strategies

Free Download

Ransomware and Microsoft 365 for business

What you need to know about reducing ransomware risk

Free Download

Building a modern strategy for analytics and machine learning success

Turning into business value

Free Download

Most Popular

Russian hackers declare war on 10 countries after failed Eurovision DDoS attack
hacking

Russian hackers declare war on 10 countries after failed Eurovision DDoS attack

16 May 2022
Windows Server admins say latest Patch Tuesday broke authentication policies
Server & storage

Windows Server admins say latest Patch Tuesday broke authentication policies

12 May 2022
IT admin deletes company’s databases and is jailed for seven years
Policy & legislation

IT admin deletes company’s databases and is jailed for seven years

16 May 2022