<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Veracode Security Blog: Application security research, security trends and opinions</title>
	<atom:link href="http://www.veracode.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Fri, 18 May 2012 16:17:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Weekly News Roundup</title>
		<link>http://www.veracode.com/blog/2012/05/weekly-news-roundup-17/</link>
		<comments>http://www.veracode.com/blog/2012/05/weekly-news-roundup-17/#comments</comments>
		<pubDate>Fri, 18 May 2012 15:38:04 +0000</pubDate>
		<dc:creator>Nate Lord</dc:creator>
				<category><![CDATA[ALL THINGS SECURITY]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=5353</guid>
		<description><![CDATA[Happy Friday all, and I hope everyone had a great week. Here are the top headlines from this past week in the security world. Enjoy! Cyber Security Index: &#8220;Cyber Security Index Highlights Political Threats, Business Partner Risk&#8221; by Paul Roberts (@paulfroberts). This article from Threatpost looks at this year&#8217;s Index of Cyber Security score of [...]]]></description>
			<content:encoded><![CDATA[<p>Happy Friday all, and I hope everyone had a great week. Here are the top headlines from this past week in the security world. Enjoy!</p>
<p><strong>Cyber Security Index</strong>: &#8220;<a href="http://threatpost.com/en_us/blogs/cyber-security-index-highlights-political-threats-business-partner-risk-051412" target="_blank">Cyber Security Index Highlights Political Threats, Business Partner Risk</a>&#8221; by Paul Roberts (<a href="https://twitter.com/#!/paulfroberts" target="_blank">@paulfroberts</a>). This article from Threatpost looks at this year&#8217;s Index of Cyber Security score of 1292, which is 292 points higher than when it was introduced last April. The Index was created by Dan Geer and Mukul Pareek in an attempt to gauge the level of perceived cyber risk and concern based on surveys conducted amongst cyber security professionals. Since its inception, the index has been steadily rising &#8211; a trend that can most likely be credited to the increasing number of cyber attacks taking place and the media exposure these attacks have gained. The article also provides a graph showing the &#8220;Cyber Fear&#8221; Index from month-to-month since March 2011 and a look at what sort of information we can expect to see on next year&#8217;s report.</p>
<p><strong>Unisys Security Index</strong>: &#8220;<a href="http://www.eweek.com/c/a/Security/Americans-Rate-CyberSecurity-as-Hot-Issue-in-Presidential-Election-Survey-829209/" target="_blank">Americans Rate Cyber-Security as Hot Issue in Presidential Election: Survey</a>&#8221; by Brian Prince (<a href="https://twitter.com/#!/eweeknews" target="_blank">@eweeknews</a>). Unisys recently conducted a survery for its bi-annual Security Index, and the results show a major increase in American focus on Cyber-Security awareness and concern as an issue in the upcoming presidential election. Despite this finding, the Unisys Security Index still dropped overall for security concern. Read the full article for more statistics from the Index as well as Prince&#8217;s analysis on these national trends. For further commentary on today&#8217;s cyber threat environment check out our <a href="http://www.veracode.com/blog/2012/01/a-conversation-with-richard-clarke-part-i/" target="_blank">Q&#038;A with cyber security guru Richard Clarke</a>.</p>
<p><strong>Enterprise Mobile Security</strong>: &#8220;<a href="http://www.cso.com.au/article/424525/companies_slow_react_mobile_security_threat/" target="_blank">Companies slow to react to mobile security threat</a>&#8221; by Antone Gonsalves (<a href="https://twitter.com/#!/antoneg" target="_blank">@antoneg</a>). This article offers Antone Gonsalves&#8217; take on the findings from a new study on mobile security from Juniper Networks. The main takeaway from the study is that employees are using mobile devices at work to engage in high-risk activities, often without company consent. Juniper found nearly 90% of employees surveyed to be using their own devices to interact with sensitive company data and that in over 40% of these cases the employer was unaware they were doing so. In addition to these issues, mobile malware is increasing at an alarming rate, subjecting companies to possible data theft or breaches. On a more positive note, Juniper&#8217;s report found that a strong share of those surveyed are willing to work with their employers to protect their devices. </p>
<p>For more on &#8220;Bring your own Device&#8221; policy, check out our <a href="http://www.veracode.com/blog/2012/05/interview-with-dan-guido-at-source-boston-2012-part-2/">new video interview series</a> with <a href="https://twitter.com/#!/dguido" target="_blank">Dan Guido</a> of <a href="http://www.trailofbits.com/" target="_blank">Trail of Bits</a>. In this segment Dan discusses BYOD for businesses and mobile platform security. Read our post and watch the video <a href="http://www.veracode.com/blog/2012/05/interview-with-dan-guido-at-source-boston-2012-part-2/" target="_blank">here</a>.</p>
<p><strong>Data Breach Aftermath</strong>: &#8220;<a href="http://krebsonsecurity.com/2012/05/global-payments-breach-fueled-prepaid-card-fraud/" target="_blank">Global Payments Breach Fueled Prepaid Card Fraud</a>&#8221; by Brian Krebs (<a href="https://twitter.com/#!/briankrebs" target="_blank">@briankrebs</a>). Unfortunately it looks like the fallout from the Global Payments data breach is not yet over. Since early March of this year there have been numerous cases of debit card fraud using Union Savings Bank information stolen in the Global Payments breach that made headlines earlier in the year. According to bank officials, the fraud has already cost Union Savings Bank about $75,000, with another $10,000 being spent on replacing customer cards. Additionally, the fraud cases have brought up some new questions about the timing and extent of the damage of the Global Payments breach itself.</p>
<p><a href="http://www.veracode.com/security/data-breach"><strong>Click here</strong></a> to learn about data breaches in general.  </p>
<p><strong>SEC Guidance</strong>: &#8220;<a href="http://taosecurity.blogspot.com/2012/05/sec-guidance-is-really-big-deal.html" target="_blank">SEC Guidance Is a Really Big Deal</a>&#8221; by Richard Bejtlich (<a href="https://twitter.com/#!/TaoSecurity" target="_blank">@TaoSecurity</a>). Richard Bejtlich wrote this blog post after speaking on SEC guidance at a recent conference. According to Richard, the SEC guidance is a &#8220;game changer&#8221; for several reasons, including its plans for enforcement and an increase in lawsuits and whistleblowing against companies with poor disclosure practices. Richard also provides insights to the new SEC guidance from Congress and Senator Jay Rockefeller.</p>
<p><a href="http://info.veracode.com/webinar-vulnerability-of-publicly-traded-companies.html">CLICK HERE to view our webinar</a> showcasing latest research findings about software security posture of public companies. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2012/05/weekly-news-roundup-17/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privacy and Confidentiality on the Eve of the Facebook IPO</title>
		<link>http://www.veracode.com/blog/2012/05/privacy-and-confidentiality-on-the-eve-of-the-facebook-ipo/</link>
		<comments>http://www.veracode.com/blog/2012/05/privacy-and-confidentiality-on-the-eve-of-the-facebook-ipo/#comments</comments>
		<pubDate>Thu, 17 May 2012 23:02:11 +0000</pubDate>
		<dc:creator>Tyler Shields</dc:creator>
				<category><![CDATA[Application Security]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=5254</guid>
		<description><![CDATA[Tonight is the last night that Facebook will be a privately held company. In the morning, Facebook shares will hit the market and there will be a feeding frenzy from investors world wide. Stock buyers will put up somewhere near 16 billion (yes with a &#8220;B&#8221;) dollars to own a portion of the social networking [...]]]></description>
			<content:encoded><![CDATA[<p>Tonight is the last night that <a href="http://www.facebook.com" title="Facebook" target="_blank">Facebook</a> will be a privately held company. In the morning, Facebook shares will hit the market and there will be a feeding frenzy from investors world wide. Stock buyers will put up somewhere near <a href="http://online.wsj.com/article/BT-CO-20120516-713214.html" title="Wall Street Journal Update #4 on Facebook IPO" target="_blank">16 billion (yes with a &#8220;B&#8221;) dollars</a> to own a portion of the social networking behemoth. However, the <a href="http://www.veracode.com/blog" title="Veracode Blog" target="_blank">Veracode blog</a> isn&#8217;t a stock trading or business blog, it&#8217;s a security blog. The real concern with Facebook for us security practitioners, is a lack of privacy.</p>
<p><center><div id="attachment_5287" class="wp-caption center" style="width: 310px"><a href="http://www.veracode.com/blog/wp-content/uploads/2012/05/Facebook-IPO.jpg"><img src="http://www.veracode.com/blog/wp-content/uploads/2012/05/Facebook-IPO-300x145.jpg" alt="" title="Facebook-IPO" width="300" height="145" align="center" class="size-medium wp-image-5287" /></a><p class="wp-caption-text">Photo Courtesy of techtwisted.com</p></div></center></p>
<p>The ability to choose what is disclosed to others is the essence of <a href="http://en.wikipedia.org/wiki/Privacy" title="Wikipedia on Privacy" target="_blank">privacy</a> today. Some would argue that this disclosure policy is not really privacy but equates more closely to <a href="http://en.wikipedia.org/wiki/Confidentiality" title="Confidentiality on Wikipedia" target="_blank">confidentiality</a>. Confidentiality deals with relationships and not individual privacy.  Confidentiality “involves trusting others to refrain from revealing personal information to unauthorized individuals.” </p>
<p>It’s in this choice of disclosure that the essence of privacy resides. The fact that we willingly give information from ourselves to another entity does not inherently mean that we give permission for that entity to share it with others. Nor does it give the entity the permission to sell, use, or otherwise attempt to profit from that information. Yet that exact premise is what numerous businesses are built upon today. Privacy transference is a major problem.</p>
<p>We click through and digitally sign user agreements that give web properties the rights to share any and all data we upload to third parties. This includes online social networks, games, software as a service solutions, and especially mobile device applications and providers. Advertising is becoming more and more targeted thanks to the customer specific profiles being created. (See Veracode post &#8211; <a href="http://www.veracode.com/blog/2011/04/mobile-apps-invading-your-privacy/" title="Mobile Apps Invading Your Privacy" target="_blank">Mobile Apps Invading Your Privacy</a>)</p>
<p>Three specific Internet phenomenon have exacerbated the privacy problem to that of high risk making it something that will have to be solved sooner rather than later. The quantity of data we are putting online is enormous and growing exponentially. The type of data that is being placed online is becoming increasingly more private, and in the event we are diligent and only put up public data, many times private information can be inferred. Finally, thanks to big data and the continually lowering cost of storage, we can be assured that all of the data that we place online will be there long after we are gone. The collection of content and the mapping of that data to create a detailed consumer profile is rapidly becoming a major issue for individuals world wide. The collection of detailed data crosses personal boundaries for those that feel it will be abused.</p>
<p>As always I&#8217;m sure people want to know how to fix the problem. I don&#8217;t have an answer. I wish I did because this is a real problem that requires intelligent solutions. My gut tells me that the problem will be solved eventually via government regulation and intervention. For the sake of businesses and consumers today I hope that we can police ourselves and do the right thing so that government intervention isn&#8217;t required. Businesses need to stop private data transference. Consumers must stop putting sensitive data online (I know, this one is a pipe-dream). And everyone must opt OUT of tracking by default and allow users who want the convenience of direct marketing to choose that service, not the other way around.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2012/05/privacy-and-confidentiality-on-the-eve-of-the-facebook-ipo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interview with Dan Guido at SOURCE Boston 2012 &#8211; Part 3</title>
		<link>http://www.veracode.com/blog/2012/05/interview-with-dan-guido-at-source-boston-2012-part-3/</link>
		<comments>http://www.veracode.com/blog/2012/05/interview-with-dan-guido-at-source-boston-2012-part-3/#comments</comments>
		<pubDate>Thu, 17 May 2012 15:18:42 +0000</pubDate>
		<dc:creator>Niru Raghavan</dc:creator>
				<category><![CDATA[ALL THINGS SECURITY]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=5228</guid>
		<description><![CDATA[In this, our third and final interview segment with Dan Guido, Co-Founder and CEO of Trail of Bits, Dan talks about how organizations should prepare to face security threats, and attack vectors that pose the greatest threat to enterprises today. Watch the interview. ]]></description>
			<content:encoded><![CDATA[<p>In this, our third and final interview segment with <a href="http://twitter.com/#!/dguido" target="_blank">Dan Guido</a>, Co-Founder and CEO of <a href="http://www.trailofbits.com/about/" target="_blank">Trail of Bits</a>, Dan talks about security threats, and attack vectors that pose the greatest threat to enterprises today. Watch the interview below. </p>
<p>
&nbsp; </p>
<p><center><iframe width="480" height="270" src="http://www.youtube.com/embed/zHX2sjy_Iw0?fs=1&#038;feature=oembed" frameborder="0" allowfullscreen></iframe></center></p>
<p>
&nbsp; </p>
<p>We also added in a quick summary to cover the highlights of the interview. </p>
<p><strong>How can organizations prepare to face security threats? </strong><br />
Dan states that organizations should look at all the attacks that are happening in the industry they are in, (from peers, <a href="http://www.veracode.com/blog/2012/04/veracode-state-of-software-security-report-feature-supplement-on-public-companies/">data releases</a> from security companies), so they can learn from the lessons that other companies have experienced. Dan states that there is not enough sharing of information in the industry about attacker techniques, tactics and procedures that have been used to perform compromises. Companies need to collect and analyze attack data, understand what hackers are doing, and then utilize that information to develop defenses that work against the techniques being used. Security programs should be able to trace back to actual reductions in data loss. </p>
<p><strong>Which attack vectors pose the greatest threat to enterprises today? </strong><br />
Dan stresses the importance of protecting the entire enterprise from threats, not just protecting one single application. That said, he also notes that attackers interested in financial fraud or credit card theft will be focused on compromising individual applications. To defend against them, enterprises may want to use dynamic web scanning, or source code auditing per application. </p>
<p>To view the other interviews with Dan Guido posted as part of this series, click on the links below. </p>
<p><a href="http://www.veracode.com/blog/2012/05/interview-with-dan-guido-at-source-boston-2012-part-i/">1. Interview with Dan Guido on Vulnerabilities</a><br />
<a href="http://www.veracode.com/blog/2012/05/interview-with-dan-guido-at-source-boston-2012-part-2/">2. Interview with Dan Guido on Mobile Platforms and BYOD</a></p>
<p>Let us know how you liked this interview series with Dan Guido, and if you have any suggestions for other hot topics you would like to see industry experts discuss. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2012/05/interview-with-dan-guido-at-source-boston-2012-part-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Veracode’s Chris Wysopal Appointed to Black Hat’s Content Review Panel</title>
		<link>http://www.veracode.com/blog/2012/05/veracodes-chris-wysopal-appointed-to-black-hats-content-review-panel/</link>
		<comments>http://www.veracode.com/blog/2012/05/veracodes-chris-wysopal-appointed-to-black-hats-content-review-panel/#comments</comments>
		<pubDate>Wed, 16 May 2012 17:58:27 +0000</pubDate>
		<dc:creator>Anne Nielsen</dc:creator>
				<category><![CDATA[ALL THINGS SECURITY]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=5217</guid>
		<description><![CDATA[We were very excited and honored to announce that our own CTO and Co-Founder, Chris Wysopal, had been appointed to the Black Hat Review Board where he will advise Black Hat on its strategic direction, assist in reviewing and programming conference content, and provide extended reach into the research community. According to Trey Lord, General [...]]]></description>
			<content:encoded><![CDATA[<p>We were very excited and honored to announce that our own CTO and Co-Founder, <a href="http://www.veracode.com/blog/chris-wysopal-co-founder-and-chief-technology-officer/">Chris Wysopal</a>, had been <a href="http://www.prnewswire.com/news-releases/black-hat-expands-content-review-board-149078215.html" target="_blank">appointed to the Black Hat Review Board</a> where he will advise Black Hat on its strategic direction, assist in reviewing and programming conference content, and provide extended reach into the research community. According to Trey Lord, General Manager of Black Hat, Chris’s appointment reflects his long-standing contributions to Black Hat as well his stature as an influential subject matter expert in the industry.  A prestigious group, the <a href="http://www.blackhat.com/html/review-board.html" target="_blank">review board</a> is comprised of 21 experts from many different areas of information security and includes such luminaries as Robert Hansen, Jeff Moss, Chris Hoff, Yuji Ukai, and Alex Stamos. </p>
<p><a href="http://www.blackhat.com/html/bh-us-12/" target="_blank">Black Hat</a> (Las Vegas &#8211; July 21-26, 2012) provides briefings and training for security professionals from around the world. Black Hat differentiates itself by working at many levels within the corporate and government communities. This unmatched informational reach enables Black Hat attendees to be continuously aware of the newest vulnerabilities, defense mechanisms, and industry trends. Black Hat has grown over the past 15 years from a single annual conference in Las Vegas to a global conference series with annual events in Abu Dhabi, Barcelona, Las Vegas and Washington DC. It has also become a premiere venue for elite security researchers and the best security trainers to find their audience.</p>
<p>Congratulations Chris!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2012/05/veracodes-chris-wysopal-appointed-to-black-hats-content-review-panel/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interview with Dan Guido at SOURCE Boston 2012 – Part 2</title>
		<link>http://www.veracode.com/blog/2012/05/interview-with-dan-guido-at-source-boston-2012-part-2/</link>
		<comments>http://www.veracode.com/blog/2012/05/interview-with-dan-guido-at-source-boston-2012-part-2/#comments</comments>
		<pubDate>Tue, 15 May 2012 16:11:05 +0000</pubDate>
		<dc:creator>Niru Raghavan</dc:creator>
				<category><![CDATA[ALL THINGS SECURITY]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=5111</guid>
		<description><![CDATA[In this second segment of the interview with Dan Guido, CEO and co-founder of Trail of Bits, Dan focuses on vulnerabilities in mobile devices, and shares the outcome of his research findings that he presented at SOURCE called “Mobile Exploit Intelligence Project”. ]]></description>
			<content:encoded><![CDATA[<p>In this second segment of the interview with <a href="http://twitter.com/#!/dguido" target="_blank">Dan Guido</a>, CEO and co-founder of <a href="http://www.trailofbits.com/about/" target="_blank">Trail of Bits</a>, Dan focuses on vulnerabilities in mobile devices, and shares the outcome of his research findings that he <a href="http://www.sourceconference.com/boston/speakers_2012.asp#dguido" target="_blank">presented at SOURCE</a> called “Mobile Exploit Intelligence Project”. Click Play to watch the interview.</p>
<p>
&nbsp; </p>
<p><center><iframe width="480" height="270" src="http://www.youtube.com/embed/edfgKvEzN7g?fs=1&#038;feature=oembed" frameborder="0" allowfullscreen></iframe></center></p>
<p>
&nbsp; </p>
<p>Read below for a quick synopsis of the interview. </p>
<p><strong>Is iOS the most secure platform? </strong><br />
Dan states that it’s definitely possible to exploit vulnerabilities in iOS. He then goes on to explain that it’s either too costly to do this or there are other mitigations that prevent this from happening.  By disincentivizing the mobile malware community from performing malware attacks on the iOS platform using clever design choices, Apple demonstrated a different approach to tackle the problem of mobile malware. Dan concludes that Apple’s approach has been different and certainly a very effective response to the mobile malware problem</p>
<p>Dan mentions that trying to trace every single unique identifier for very single malicious application is neither effective nor intelligent, in addition to also being resource heavy on an organization.  </p>
<p><strong>What are your recommendations with respect to “bring your own device” policy? </strong></p>
<p>Dan references his research presentation that he delivered at SOURCE Boston this year titled “Mobile Exploit Intelligence Project”.  As part of the research, Dan collected a comprehensive database of every piece of mobile malware that affected iOS and Android. This research was used to draw conclusions as to what security measures would be effective if implemented on those devices to protect against the malware that currently exists in the wild. </p>
<p>He points out that there are not really any mobile security products in the market right now that can mitigate against these flaws. To have an effective BYOD policy, Dan states that you need to assume that your devices are compromised, no endpoint security products that can prevent your devices from being compromised.  One possible solution Dan talks about is the concept of “secure containers” to store encrypted information on mobile devices. Dan’s colleague, <a href="http://twitter.com/#!/dinodaizovi" target="_blank">Dino Dai Zovi</a> has written a paper on how effective the data protection APIs are on iOS, and how it is somewhat tenable to create secure containers to store encrypted information in iOS. </p>
<p><a href="http://www.youtube.com/watch?v=00M7GZASIfg" target="_blank">CLICK HERE</a> to view Dan&#8217;s presentation at SOURCE Boston titled &#8220;Mobile Exploit Intelligence Project&#8221;.  </p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2012/05/interview-with-dan-guido-at-source-boston-2012-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Data Integrity? Learn How to Ensure Database Data Integrity via Checks, Tests, &amp; Best Practices</title>
		<link>http://www.veracode.com/blog/2012/05/what-is-data-integrity/</link>
		<comments>http://www.veracode.com/blog/2012/05/what-is-data-integrity/#comments</comments>
		<pubDate>Mon, 14 May 2012 13:26:53 +0000</pubDate>
		<dc:creator>Fergal Glynn</dc:creator>
				<category><![CDATA[ALL THINGS SECURITY]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=5015</guid>
		<description><![CDATA[Data integrity is a fundamental component of information security. In its broadest use, “data integrity” refers to the accuracy and consistency of data stored in a database, data warehouse, data mart or other construct. The term – Data Integrity &#8211; can be used to describe a state, a process or a function – and is [...]]]></description>
			<content:encoded><![CDATA[<p>Data integrity is a fundamental component of information security. In its broadest use, “data integrity” refers to the accuracy and consistency of data stored in a database, data warehouse, data mart or other construct. The term – Data Integrity &#8211; can be used to describe a state, a process or a function – and is often used as a proxy for “data quality”.</p>
<p>Data with “integrity” is said to have a complete or whole structure. Data values are standardized according to a data model and/or data type. All characteristics of the data must be correct – including business rules, relations, dates, definitions and lineage – for data to be complete. Data integrity is imposed within a database when it is designed and is authenticated through the ongoing use of error checking and validation routines. As a simple example, to maintain data integrity numeric columns/cells should not accept alphabetic data.</p>
<div id="related_posts">
<div id="related_posts_content">
<div>
<h4>Editor&#8217;s Pick</h4>
<p><a href="http://www.veracode.com/blog/2012/04/what-is-owasp-guide-to-the-owasp-application-security-top-10/" rel="bookmark" title="Permanent Link to What is OWASP? Guide to the OWASP Application Security Top 10">What is OWASP? Guide to the OWASP Application Security Top 10</a></p>
<p><a href="http://www.veracode.com/blog/2012/04/what-is-a-buffer-overflow-learn-about-buffer-overrun-vulnerabilities-exploits-attacks/" rel="bookmark" title="Permanent Link to What is a Buffer Overflow? Learn About Buffer Overrun Vulnerabilities, Exploits &#038; Attacks">What is a Buffer Overflow? Learn About Buffer Overrun Vulnerabilities, Exploits &#038; Attacks</a></p>
</p></div>
</div>
</div>
<p>As a process, data integrity verifies that data has remained unaltered in transit from creation to reception. As a state or condition, Data Integrity is a measure of the validity and fidelity of a data object. As a function related to security, a data integrity service maintains information exactly as it was inputted, and is auditable to affirm its reliability. Data undergoes any number of operations in support of decision-making, such as capture, storage, retrieval, update and transfer. Data integrity can also be a performance measure during these operations based on the detected error rate. </p>
<p>Data must be kept free from corruption, modification or unauthorized disclosure to drive any number of mission-critical business processes with accuracy. Inaccuracies can occur either accidentally  (e.g .through programming errors), or maliciously (e.g. through breaches or hacks). Database security professionals employ any number of practices to assure data integrity, including:</p>
<ul>
<li>Data encryption, which locks data by cipher</li>
<li>Data backup, which stores a copy of data in an alternate location</li>
<li>Access controls, including assignment of read/write privileges</li>
<li>Input validation, to prevent incorrect data entry</li>
<li>Data validation, to certify uncorrupted transmission</li>
</ul>
<p>Software developers must also be concerned with data integrity. They can define integrity constraints to enforce business rules on data when entered into an application. Business rules specify conditions and relationships that must always be true, or must always be false. When a data integrity constraint is applied to a database table, all data in the table must conform to the corresponding rule.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2012/05/what-is-data-integrity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weekly News Roundup</title>
		<link>http://www.veracode.com/blog/2012/05/weekly-news-roundup-16/</link>
		<comments>http://www.veracode.com/blog/2012/05/weekly-news-roundup-16/#comments</comments>
		<pubDate>Fri, 11 May 2012 17:09:31 +0000</pubDate>
		<dc:creator>Zack Cronin</dc:creator>
				<category><![CDATA[ALL THINGS SECURITY]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=5073</guid>
		<description><![CDATA[Happy Friday all! Make the day go by a little faster by taking some time out to catch up with a few highlights from this week’s news stories: Twitter In The News: An interesting occurrence with Twitter this week was the supposed hack that resulted in the posting of over 50,000 user names and passwords [...]]]></description>
			<content:encoded><![CDATA[<p>Happy Friday all! Make the day go by a little faster by taking some time out to catch up with a few highlights from this week’s news stories:</p>
<p><strong>Twitter In The News:</strong>  An interesting occurrence with Twitter this week was the supposed hack that resulted in the posting of over 50,000 user names and passwords online. An initial report by <a href="http://twitter.com/#!/jpmello" target="_blank">John Mello</a> in <a href="http://www.pcworld.com/article/255326/twitter_breached_50k_accounts_posted_to_internet.html" target="_blank">PC World</a> reported that “some of the accounts are duds created by robot programs.” Jay Alabaster said in a <a href="http://www.computerworld.com/s/article/9227040/Twitter_blog_post_says_company_leaked_no_user_data" target="_blank">later article</a> posted in <a href="http://twitter.com/#!/computerworld" target="_blank">ComputerWorld</a> that, “None of the recently leaked Twitter logins and passwords came from within the company, according to a message posted on Twitter&#8217;s Japanese blog Thursday,” after it was determined that the posted accounts were duplicates, unmatched credentials, and spam accounts. </p>
<div id="related_posts">
<div id="related_posts_content">
<div>
<h4>Editor&#8217;s Pick</h4>
<p><a href="http://www.veracode.com/blog/2010/05/html5-security-in-a-nutshell/" rel="bookmark" title="HTML5 Security in a </p>
<p>Nutshell">HTML5 Security in a Nutshell</a></p>
<p><a href="http://www.veracode.com/blog/2010/07/deadly-combo-zero-day-application-vulnerability-os-vulnerability-attacker-win/" rel="bookmark" title="Deadly Combo: Zero Day Application Vulnerability + OS Vulnerability = Attacker Win">Deadly Combo: Zero Day Application Vulnerability + OS Vulnerability = Attacker Win</a></p>
<p><a href="http://www.veracode.com/blog/2008/02/new-unit-of-reviews-code-quality/" rel="bookmark" title="New Unit of Reviewed Code Quality">New Unit of Reviewed Code Quality</a></p>
<p><a href="http://www.veracode.com/blog/2009/01/how-to-protect-your-users-from-password-theft/" rel="bookmark" title="How To Protect Your Users From Password Theft">How To Protect Your Users From Password Theft</a></p>
<p><a href="http://www.veracode.com/blog/2011/03/a-financial-model-for-application-security-debt/" rel="bookmark" title="A Financial Model for Application Security Debt">A Financial Model for Application Security Debt</a></p>
</div>
</div>
</div>
<p><strong>Spike in SQL Injection attacks:</strong> A mass increase of the number of SQL Injection attacks has occurred. A <a href="http://www.darkreading.com/database-security/167901020/security/news/240000077/mass-sql-injections-spike-again.html" target="_blank">Dark Reading article</a> by <a href="http://twitter.com/#!/erickachick" target="_blank">Ericka Chickowski</a> reports that researchers have found that there has been a spike in automated SQLi attacks, which are being used by hackers to seek out sites that are vulnerable to the attack, who then sell the information in a monetization process.  Organizations are being warned to keep up with patches, monitor applications, and use appropriate security measures. More information about Veracode and SQL Injection, as well as how you can protect yourself can be found <a href="http://info.veracode.com/sql-injection-cheat-sheet.html" target="_blank">here</a>.</p>
<p><strong>BYOD:</strong> A recently trending issue in the security world is BYOD. As reported by Ellen Messmer in <a href="http://twitter.com/#!/pcworld" target="_blank">PC World</a>, a new survey “<a href="http://www.pcworld.com/businesscenter/article/255317/mobile_byod_users_want_more_security.html" target="_blank">shows wildly abundant use of mobile devices, but profound concerns about security and how employee-owned devices ought to be used for business purposes</a>.” It is also found that, “One-third of the IT professionals in the survey reported their company has already experienced some type of security threat associated with personal mobile devices accessing corporate data.”</p>
<p><strong>Vulnerability in PHP:</strong> A very large number of sites using PHP scripting language are currently endangered by an unpatched vulnerability in the code, writes <a href="http://twitter.com/#!/dangoodin001" target="_blank">Dan Gooding</a> in <a href="http://arstechnica.com/business/2012/05/attackers-target-unpatched-php-bug-allowing-malicious-code-execution/" target="_blank">Arstechnica</a>. The weakness allows hackers to remotely take control of servers when the PHP sites are running CGI (not FastCGI). Even worse, the full details of the exploit went public, providing hackers with all the information they need to locate and take advantage of the vulnerabilities. There are updates and patches available to mitigate the risk. </p>
<p><strong>Keeping the London Olympics safe from cyber attacks:</strong> With the threat of cyber attacks on the 2012 Summer Olympics in London,  Atos, the IT outsource for the games, <a href="http://www.pcworld.com/article/255049/londons_olympics_plans_include_cybersecurity.html" target="_blank">has wrapped up its first round of testing</a> writes <a href="http://twitter.com/#!/anhnguyen" target="_blank">Anh Nguyen</a>. He further reports that, “The CIO for the London Organizing Committee for the Olympic Games (LOCOG) said last year that cyber criminals would find it &#8216;very hard&#8217; to launch a distributed denial of service (DDoS) attack on the Games&#8217; website.”</p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2012/05/weekly-news-roundup-16/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interview with Dan Guido at SOURCE Boston 2012 &#8211; Part I</title>
		<link>http://www.veracode.com/blog/2012/05/interview-with-dan-guido-at-source-boston-2012-part-i/</link>
		<comments>http://www.veracode.com/blog/2012/05/interview-with-dan-guido-at-source-boston-2012-part-i/#comments</comments>
		<pubDate>Thu, 10 May 2012 15:38:35 +0000</pubDate>
		<dc:creator>Niru Raghavan</dc:creator>
				<category><![CDATA[ALL THINGS SECURITY]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=5025</guid>
		<description><![CDATA[We recently sat down with Dan Guido, CEO and Co-Founder of Trail of Bits at SOURCE Boston 2012, to get his views on topics related to application security. In the first of a three part segment, Dan's commentary focuses on vulnerabilities in general. You can watch the interview  here.]]></description>
			<content:encoded><![CDATA[<p>We recently sat down with <a href="http://www.trailofbits.com/about/" target="_blank">Dan Guido</a>, CEO and Co-Founder of <a href="http://www.trailofbits.com/" target="_blank">Trail of Bits</a> at <a href="http://www.sourceconference.com/boston/speakers_2012.asp#dguido" target="_blank">SOURCE Boston 2012</a>, to get his views on topics related to application security. In the first of a three part segment, Dan&#8217;s commentary focuses on vulnerabilities in general. You can watch the interview  here. </p>
<p><center><iframe width="480" height="270" src="http://www.youtube.com/embed/uU0ZlR7f7gQ?fs=1&#038;feature=oembed" frameborder="0" allowfullscreen></iframe></center></p>
<p>
&nbsp; </p>
<p>We&#8217;ve also included a short recap of highlights of the interview in this post. </p>
<p><strong>How can organizations better communicate around vulnerabilities? </strong><br />
Dan details the behavioral problem that exists in most organizations today when vulnerabilities are found in software. He notes that organizations are very concerned about individual vulnerabilities, not as much about the reasons as to why the vulnerabilities exist. Dan notes that mitigation efforts should be focused around classes of vulnerabilities, not the individual vulnerabilities that are found. </p>
<p><strong>Which vulnerabilities matter most on the web?  </strong><br />
Dan talks about the disparity between the vulnerabilities that the security industry focuses on vs. vulnerabilities that hackers care about. He further goes on to mention that vulnerabilities that matter most on the web are the ones that gain the hacker a shell on a server, like <a href="http://www.veracode.com/security/sql-injection">SQL Injection</a> or remote command execution. </p>
<p><strong>Should different businesses focus on different vulnerabilities? </strong><br />
Dan focuses on the vulnerabilities organizations should care about, depending on the type of business model they use. For instance, a service provider whose customers have individual user accounts or a social networking websites like Facebook should care about <a href="http://www.veracode.com/security/xss">Cross-site scripting (XSS)</a>. On the other hand, SQL Injection attacks have increased in frequency, and should be on every organization’s watch list. </p>
<p>Stay tuned for more sessions with Dan Guido which we will be showcasing next week on our blog. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2012/05/interview-with-dan-guido-at-source-boston-2012-part-i/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Mining A Mountain of Zero Day Vulnerabilities &#8211; Webinar Q&amp;A</title>
		<link>http://www.veracode.com/blog/2012/05/data-mining-a-mountain-of-zero-day-vulnerabilities-webinar-qa/</link>
		<comments>http://www.veracode.com/blog/2012/05/data-mining-a-mountain-of-zero-day-vulnerabilities-webinar-qa/#comments</comments>
		<pubDate>Tue, 08 May 2012 15:40:46 +0000</pubDate>
		<dc:creator>Anne Nielsen</dc:creator>
				<category><![CDATA[ALL THINGS SECURITY]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=4944</guid>
		<description><![CDATA[With a goal of helping people understand the overall state of application security, Chris Wysopal, Veracode’s CTO and Co-Founder, recently gave a webinar, “Data Mining a Mountain of Zero-Day Vulnerabilities.” Chris examined the anonymized vulnerability data set produced by Veracode over the course of our analysis of thousands of applications submitted to us by large [...]]]></description>
			<content:encoded><![CDATA[<p>With a goal of helping people understand the overall state of application security, <a href="http://www.veracode.com/about/chris-wysopal.html">Chris Wysopal</a>, Veracode’s CTO and Co-Founder, recently gave a webinar, “<a href="http://info.veracode.com/webinar-data-mining-zero-day-vulnerabilities.html">Data Mining a Mountain of Zero-Day Vulnerabilities</a>.” Chris examined the anonymized vulnerability data set produced by Veracode over the course of our analysis of thousands of applications submitted to us by large enterprises, commercial software vendors, open source projects, and software outsourcers. This data set generated interesting observations about <a href="http://www.veracode.com/">application security</a> in various industry verticals, and common mistakes developers make when <a href="http://www.veracode.com/security/code-security">coding software</a>. </p>
<p>The webinar enjoyed ample audience participation and response, including a few questions submitted by attendees which did not get addressed live on the webinar due to time constraints. Below we highlight a few of those.</p>
<div id="related_posts">
<div id="related_posts_content">
<div>
<h4>Editor&#8217;s Pick</h4>
<p><a href="http://www.veracode.com/blog/2011/05/possible-playstation-network-attack-vectors/" rel="bookmark" title="Possible PlayStation Network Attack Vectors">Possible PlayStation Network Attack Vectors</a></p>
<p><a href="http://www.veracode.com/blog/2012/01/delivering-unhappiness/" rel="bookmark" title="Delivering Unhappiness">Delivering Unhappiness</a></p>
<p><a href="http://www.veracode.com/blog/2008/08/mbta-hack-is-it-really-this-easy/" rel="bookmark" title="MBTA Hack: Is It Really This Easy?">MBTA Hack: Is It Really This Easy?</a></p>
<p><a href="http://www.veracode.com/blog/2009/07/blackberry-spyware-dissected/" rel="bookmark" title="BlackBerry Spyware Dissected">BlackBerry Spyware Dissected</a></p>
<p><a href="http://www.veracode.com/blog/2008/09/learning-from-sarah-palin-yahoo-email-compromise/" rel="bookmark" title="Learning From Sarah Palin’s Yahoo Mail Compromise">Learning From Sarah Palin’s Yahoo Mail Compromise</a></p>
</div>
</div>
</div>
<p><strong>Q</strong>: Of the software development houses that are producing these &#8220;vulnerable&#8221; applications, how many of them have a security assessment phase in their <a href="http://info.veracode.com/veracode-sdlc-datasheet.html">development life-cycle</a>?</p>
<p><strong>Wysopal</strong>: The software developers do not disclose to us what security they perform in the SDLC.  It is likely that those who have robust programs are the ones passing our test and the ones with no programs are failing but that is just a hypothesis.  We would need to ask each customer what application security processes they are performing.</p>
<p><strong>Q</strong>: Did you study look at the platform or Operating System upon which the application executes as a factor?</p>
<p><strong>Wysopal</strong>: No it does not.  For most application layer vulnerabilities this does not matter however.</p>
<p><strong>Q</strong>: Can you define the &#8220;information leakage&#8221; vulnerability? Is there a catalog describing all the vulnerabilities commented in this presentation?</p>
<p><strong>Wysopal</strong>: Information leakage happens when sensitive information is displayed to the user inadvertently. An example would be pathnames or database IP addresses returned within an error message to a user.  An attacker can use this information to attack the system. The MITRE CWE website catalogs application vulnerabilities.  Here is an example: <a href="http://cwe.mitre.org/data/definitions/209.html" target="_blank">http://cwe.mitre.org/data/definitions/209.html</a></p>
<p><strong>Q</strong>: Of all of the vulnerabilities you find in these applications, which is the most easily exploited ?</p>
<p><strong>Wysopal</strong>:  The top 4 exploited as determined by the Web Hacking Incident Database are :</p>
<p><strong>1</strong>.  <a href="http://www.veracode.com/security/sql-injection">SQL Injection</a><br />
<strong>2</strong>.  <a href="http://www.veracode.com/security/xss">Cross site scripting</a><br />
<strong>3</strong>.  <a href="http://www.veracode.com/security/data-loss-prevention">Information leakage</a><br />
<strong>4</strong>.  Command injections</p>
<p>Other reports have ranked directory traversal as another often exploited vulnerability.</p>
<p><strong>Q</strong>: Once you complete your testing for a company, what is the usual request/reaction from the business and do you provide them a solution regarding how  to make their environment more secure?</p>
<p><strong>Wysopal</strong>:  Veracode provides a remediation roadmap which includes prioritization and information on how to remediate each specific issue.  Some organizations remediate and others choose not to.  It depends on the severity of the issues and the businesses tolerance for risk.</p>
<p><strong>Q</strong>: The total of Percentage of Hacks seems to be low in the below slide. What methods of attack make up the other 64%?</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2012/05/datamining-webinar-1.png"><img src="http://www.veracode.com/blog/wp-content/uploads/2012/05/datamining-webinar-1.png" alt="" title="datamining-webinar-1" width="482" height="358" class="alignleft size-full wp-image-4993" /></a></p>
<p><strong>Wysopal</strong>: According to the Web Hacking Incident Database, the other top attack methods are the following:</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2012/05/datamining-webinar-2.png"><img src="http://www.veracode.com/blog/wp-content/uploads/2012/05/datamining-webinar-2.png" alt="" title="datamining-webinar-2" width="351" height="272" class="alignleft size-full wp-image-4996" /></a></p>
<p>Less than 1%: </p>
<ul>
<li>Clickjacking</li>
<li>Malvertising</li>
<li>Forceful Browsing</li>
<li>Malware</li>
<li>Phishing</li>
<li>Remote File Inclusion (RFI)</li>
<li>Domain Hijacking</li>
<li>Hidden Parameter Manipulation</li>
<li>Local File Inclusion (LFI)</li>
</ul>
<p>If you have any additional questions for Chris Wysopal on this subject, feel free to send them over.</p>
<p>To get a recorded video of the webinar with slides, <a href="http://info.veracode.com/webinar-data-mining-zero-day-vulnerabilities.html">click here</a>. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2012/05/data-mining-a-mountain-of-zero-day-vulnerabilities-webinar-qa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cybersecurity Risks in Public Companies Infographic</title>
		<link>http://www.veracode.com/blog/2012/05/state-of-software-security-cybersecurity-risks-in-public-companies/</link>
		<comments>http://www.veracode.com/blog/2012/05/state-of-software-security-cybersecurity-risks-in-public-companies/#comments</comments>
		<pubDate>Mon, 07 May 2012 14:20:01 +0000</pubDate>
		<dc:creator>Niru Raghavan</dc:creator>
				<category><![CDATA[INFOGRAPHICS]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=4950</guid>
		<description><![CDATA[Following new SEC guidance issued in the US relating to disclosure of cybersecurity risks in company filings, public companies are beginning to be measured by regulators and investors on the strength of their cybersecurity solution and ability to protect intellectual property and customer data. This infographic looks at the state of software security in public companies, and shows why companies and investors alike should care.]]></description>
			<content:encoded><![CDATA[<p><!-- AddThis Button BEGIN --></p>
<div class="addthis_toolbox" style="display: inline-block;float: left; width: 300px;"><a class="addthis_button_facebook_like" style="float:left;width:85px;"></a><a class="addthis_button_tweet"tw:via="Veracode"  style="float:left;width:100px;"></a><a class="addthis_button_google_plusone" style="float:left;width:60px;padding-top:2px;"></a></div>
<p><script src="http://s7.addthis.com/js/250/addthis_widget.js#pubid=ra-4e80d12b3f023972" type="text/javascript"></script><br />
<!-- AddThis Button END --></p>
<p>Following new SEC guidance issued in the US relating to disclosure of cybersecurity risks in company filings, public companies are beginning to be measured by regulators and investors on the strength of their cybersecurity solution and ability to protect intellectual property and customer data. This infographic looks at the state of software security in public companies, and shows why companies and investors alike should care. </p>
<p><a href="http://www.veracode.com/soss"> <img src="http://www.veracode.com/blog/wp-content/uploads/2012/05/veracode-soss-public-companies-graphic.jpg"alt="Veracode CyberSecurity in Public Companies" width="650" height="4191"> <br /></a></p>
<h2>Add this Infographic to Your Website for FREE!</h2>
<p></p>
<h3>Small Version</h3>
<div><textarea cols="80" rows="5" style="width:600px; height:100px;">
<p><a href="http://www.veracode.com/soss"><img src="http://www.veracode.com/blog/wp-content/uploads/2012/05/veracode-soss-public-companies-graphic.jpg" width="325" height="2096" alt="Social Media Security Basics"/></a></p>
<p>Infographic by <a href="http://www.veracode.com/">Veracode Application Security</a></p>
<p></textarea></div>
<h3>Large Version</h3>
<div><textarea cols="80" rows="5" style="width:600px; height:100px;">
<p><a href="http://www.veracode.com/soss"><img src="http://www.veracode.com/blog/wp-content/uploads/2012/05/veracode-soss-public-companies-graphic.jpg" width="650" height="4191" alt="Social Media Security Basics"/></a></p>
<p>Infographic by <a href="http://www.veracode.com/">Veracode Application Security</a></p>
<p></textarea></div>
<p>Infographic by <a href="http://www.veracode.com/">Veracode Application Security</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2012/05/state-of-software-security-cybersecurity-risks-in-public-companies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

