Download presentation
Presentation is loading. Please wait.
Published byEleanor Wood Modified over 9 years ago
1
Software Security Common Vulnerabilities Encoded During Development Chris Wysopal, CTO & Co-Founder, Veracode. ISACA Luncheon, 11:30am Tuesday, February 5, 2013
2
http://www.veracode.com/reports
3
The Data Set Applications from over 300 commercial and US government customers Scanned 9,910 applications over past 18 months Ranged in size from 100KB to 6GB Software was pre-release and in production Internally built, outsourced, open source, and commercial ISV code 3
4
4 ▸ Industry vertical ▸ Application supplier (internal, third-party, etc.) ▸ Application type ▸ Assurance level ▸ Language ▸ Platform Application Metadata ▸ Scan number ▸ Scan date ▸ Lines of code ▸ Flaw type Scan Data ▸ Flaw counts ▸ Flaw percentages ▸ Application count ▸ Risk-adjusted rating ▸ First scan acceptance rate ▸ Time between scans ▸ Days to remediation ▸ Scans to remediation ▸ CWE/SANS Top25 (pass/fail) ▸ OWASP Top Ten (pass/fail) ▸ Custom policies Application Security Metrics
5
5
6
Top 5 Attacked Web Application Vulnerabilities 6
7
7
8
8
9
9
10
Top 3 Vulnerabilities by Language 10
11
Top 3 Vulnerabilities by Language 11
12
Different developers deliver different vulns 12
13
Different industries accept different vulns 13 Vulnerability distribution by industry
14
How about mobile apps?
15
15 Distribution by industry Distribution by supplier type
16
16 Percentage of Android Apps Affected
17
17 Percentage of iOS Apps Affected
18
Study of Enterprise Testing of the Software Supply Chain 18 Feature Supplement of Veracode’s State of Software Security Report
19
Vendor Applications Are Proliferating Today’s business pressures require software and development outsourcing. Average enterprise has 600 mission critical apps. 65% or 390 apps are externally developed. Explosive growth in outsourced, commercial, SaaS, mobile and open source. Most enterprises understand the risk, not how to manage it. Source: Outsourcing Software Security Quocirca Research - April, 2012 Veracode Confidential
20
Dataset Overview Data from 939 application builds from Jan 2011 to Jun 2012
21
Testing Vendor Applications is a Growing Trend 21
22
Testing Vendor Applications a Growing Trend 22 Dominated by 2 industriesBroader distribution of industries Enterprises in many more industries request vendor application security tests Mar 2010 – Jul 2011 Aug 2011 – Jun 2012
23
Why is Vendor Application Testing a Growing Trend? 23 “Over the past 24 months, the number of security incidents attributed to customers, partners, and suppliers has nearly doubled.” –PwC 2012 Global State of Information Security Survey
26
* Slight differences between the total percentages in figures are due to rounding
29
29
30
Chris Wysopal cwysopal@veracode.com @weldpond Q UESTIONS ?
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.