Showing posts with label web services security testing. Show all posts
Showing posts with label web services security testing. Show all posts

Thursday, 18 December 2014

Firing Range – Latest Open Source testbed from Google to evaluate Security Testing tools



And here comes Firing Range!

Google's 'Firing Range' is a step towards securing web applications against hacking. Released in November 2014, it is an open source Java application built on Google App Engine which provides a test ground for testing the effectiveness of security test tools. And it contains a wide range of XSS (Cross Site Scripting) and other web vulnerabilities which are helpful to ‘test’ security testing tools. 

Why do we need a testbed at all? Testbeds are used by Securitytesting tool vendors who want to create perfect test tools which are ready to test all vulnerabilities. And the only way to ensure test tools are more and more accurate is to test the tool itself against a testbed full of vulnerabilities - a synthetic testbed to both test current capabilities of the tool & set goals for what is needed to catch next.

Multiple testbeds similar to Google’s Firing Range are also available which can be leveraged to evaluate the effectiveness of a security testing/assessment tool. Some of them are OWASP WebGoat, OWASP Broken Web Applications Project (OWASPBWA), OWASP Hackademic, Damn Vulnerable Web Application (DVWA), Mutillidae and Metasploitable.

How does Google Firing Range benefit businesses?

As websites get more dynamic and complex, they have become more vulnerable to cyber-attacks. A report from Centre for Strategic and International Studies (CSIS) puts the average cost to global economy from cyber attacks at approximately $400bn. Businesses stand to face millions of dollars in penalties when sensitive information like credit card details, social security numbers etc. fall into the hands of hackers. The associated loss of goodwill and trust could take years to regain. 

  • Major companies like Sony Entertainment, eBay, Snapchat and Apple iCloud became recent targets of hacking. 
  • The security bug Heartbleed, impacting over 66% of websites, remained undetected for 2 years exposing user login details to hackers.
The above shows hacking is rampant and bugs can be very hard to detect.

Firing Range attempts to increase the chances of detecting bugs and other vulnerabilities in the web application by enabling efficient security testing tools. It provides a detailed testbed which Web Application Vulnerability Scanners can use to detect vulnerability in the website.  Its biggest advantage is it takes care of web vulnerabilities due to XSS. According to Claudio Criscione, security engineer at Google, XSS bugs represent 70% of all vulnerabilities detected at Google.

Firing Range is an open source code. Developers are free to try it, build upon it and give suggestions to improve the tool. It brings the advantage of Google's rich experience in web security. 

As companies strive to attract customers through innovative websites, they cannot afford to ignore the need to ensure their customers a safe web experience. Partnering with a third party that has expertise in evaluating security testing/assessment tools can be helpful in strengthening and increasing the effectiveness of the tool. Gallop's Security Testing CoE will undertake the rigorous process of evaluating the Security Assessment tool, leveraging not only Google’s Firing Range but also similar testbeds like OWASP WebGoat, OWASP Broken Web Applications Project (OWASPBWA), Damn Vulnerable Web Application (DVWA), Mutillidae, OWASP Hackademic, Metasploitable.

Gallop Solutions excels in providing software security testingservices using proprietary test accelerators and expertise in world’s leading test tools. With partnerships with these leading security test tool vendors, clients get to work with trained and certified test professionals at Gallop. If you have an application which needs to be security-tested, leverage the benefits of our pre-built security test framework which accelerates your test cycle while assuring quality. Drop us a line and we would be glad to assist.

Friday, 28 November 2014

Test Security before Security is breached



The advent of Internet entrepreneurs around the globe has triggered the development and launch of web and mobile applications to an extent that every process is being probed for the possibility of turning it into an application. Every day, billions of digital interactions are accelerating operations, executing transactions and multiplying opportunities. This phenomenal rise in the adoption of digital assets is matched by the growing concerns on the status of information security.

Security Testing is more than Pre-emptive penetration with responsible disclosure
In a digital asset, a vulnerability is either discovered with security testing or is inevitably discovered at the expense of a security breach. Recurrent incidents of security breaches corrode the credibility of the information system’s security and can lead to a decline in the user base. Being one step ahead of a potential security breach is not a matter of advantage, it is the primary benchmark of commitment to information security.

Every information system is vulnerable as long as it is not absolutely isolated.

A smart phone enables a user to contact friends, post updates on social networks, send e-mails, play games, make financial transactions, order/purchase products. With sync options, hackers can choose a wide range of options to penetrate into your device and then penetrate the user’s accounts through the device. The same holds true for web applications, enterprise applications and e-commerce sites as well, although the penetration threats might be different.

Increased usage of IT demands multi-layer Security Testing

Social networks with amazing options to consolidate user generated content, e-mail services with staggering population of active user accounts and search engines with enormous data are blurring the line between the creation and consumption of data. Not very long ago, enterprises (including governments) have recognized the wealth of the digital identities and built processes to replace direct human interactions for recurrent processes wherever possible.

Risk mitigation inconstantly evolving scenarios

Thus we have mission critical scenarios spanning across multiple applications synched to a single device/e-mail id, payment transactions in handheld devices and desktops via apps, strategic access control in an organization, pathways to server etc. Security compromise of any single component spreads the risk to all the connected components and contacts making it imperative for the users to sanitize the overall security.

The sheer volume and diverse ways in which information is being exchanged makes SecurityTesting a high priority in a business strategy, and thus brings security testers high in demand. Prioritized risk mitigation allows business organizations to proceed with the initiatives with stringent security testing for the areas which deserve to be made resilient.

Security is a continuous concern and Security Testing is a consistent effort.

So how does an organization leverage Security Testing to ensure resilience, pre-empt defects and enable quick response? In the following three steps with resonant executions:

1.       Focus on high risk areas – Pockets of confidential information, business facing apps, mobile apps, web apps, network, server, cloud, ERP/Admin control panels and Key user accounts etc.
2.       Random testing on overall system – Execute attempts in scenarios which are often unthought of, unspecified in the requirements or considered as low risk
3.       Information Security specific eco system awareness - Contingency for estimated capacity of load balancer in case of DDOS attacks, knowledge of new breed of malware, virus and sanitization of bugs reported in the ecosystem