You are here: silicon.com > Software > Security Strategy

Security Strategy

Insecure software an open door to hackers

How careless...

By Pia Heikkila

Published: 11 February 2002 16:31 GMT

Companies are putting themselves increasingly at risk by letting hackers in via poorly designed software, according to security experts.

Applications which are accessed over the internet can be at risk from a variety of attacks such as cookie poisoning, database sabotage and protocol piggybacking. These attacks are designed to take advantage of the built-in weaknesses some applications have.

Gunter Ollman, principal consultant at Internet Security Systems (ISS), claimed most UK companies are not aware of the threats.

He said: "Most companies are aware of the traditional hacker threats and have firewalls in place. But they have forgotten to secure the applications themselves. A haphazardly designed database can easily give the hacker a way in via the company's website for instance."

Tal Gilat, CEO of Israeli firm Kavado, which specialises in application level security, said companies have an outdated view of security.

"Most IT managers still endorse the traditional network security approach to protecting their applications. But security solutions such as VPNs, firewalls and intrusion detection systems do not protect the applications. No two applications are implemented the same way across businesses. Each application is always unique which makes them vulnerable," he said.

Ollman said there are no short-term solutions to the problem. "The only way to secure applications is to design the software with security in mind," he said.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Senior Software Engineer

CompanyMcAfee creates best-of-breed computer security solutions that span large enterprises, governments, small- & medium-sized businesses, & ...

IT Security & Risk Consultant

Further to this you will have to have a broad technical knowledge of information security systems such as firewalls, identity and access management, ...

Security Analyst

Up to date technical knowledge of the latest security threats and knowledge of security standards including ISO27002/ISO 17799. TECHNICAL SKILLS : ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: