Gartner: Developers must be responsible for security

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

…popular desktop security environments do. So these are new products that are emerging now. The desktop is not as secure as we'd like it to be, and there's still tons of room for improvement on the desktop and laptop side of the equation.

Then there's new application environments, like Web 2.0 environments. There was a great presentation by David Backley [chief technology officer at Australian bank Westpac] about how they're using Facebook-type social-networking environments within Westpac to promote collaboration and teamwork, and they're looking at virtual worlds, like Second Life, as well. These sorts of new applications that rely on large distributed network deployment introduce all sorts of new aggregations of security risks.

I say "aggregations"; to break down these application types — virtual worlds, social networks, blogs, whatever it is — if you look at the components that make these up, they're no different from any other application. They may use a language that's a bit newer — Ajax or new forms of HTML — but they're still languages and they still have the same issues: validation and making sure the code has not been altered — the same basic thing.

The issue in the new Web 2.0 world that we're all dealing with is that those components cannot exist by themselves. It's not that you can get a copy of a word processor in one nice tidy piece on its own; Web 2.0 applications are often made up of dozens of these individual components. Those components may come from different companies or may be home-grown, developed internally. Ensuring the security of each one of those components is critical if you're going to ensure the security of the network.

With the increased complexity of these collections, or mashups, the challenge to secure them goes up logarithmically. Every time we add more systems together, the [number of] potential interactions, and the potential corruptions among them, expands, and we have to secure each of them. The only way we can secure the whole mass is to secure each component by monitoring, managing data transfer, firewalling, and, in the end, we just have to watch our applications like a hawk. Now these are all standard approaches. Nothing about this is new. We're doing all of these already. The issue is that it's getting more and more complex — we have to do it more aggressively; we have to do it faster; we have to do it at a much more granular level within the application than we have in the past.

In the end, we just have to watch our applications like a hawk

Andrew Walls, Gartner

As a result, we're seeing vendors with products and services coming out which focus on different levels within applications — to do code reviews, application vulnerability scanning, testing, continuous scanning and testing of application suites. This is all self-defence — how can we automate these tasks to be as responsive as we can be to continue to secure our organisation? It's all about: how can we manage burgeoning complexity in the application environment? The processes are the same as they've always been, but we need to do it faster, and we need to do a lot more of it.

Nobody is going to give you more budget to do it, of course, so you've got to do it with what you've got. You've got to develop your staff, and your tools and your relationships with vendors — you've got to be a much more adept and sophisticated manager to manage security these days.

To what extent is security management going to be playing catch up with the malicious side of the security industry?
You can close the gap to a certain extent, but you're always going to be lagging slightly behind. This is the same situation that law enforcement faces: certain national governments notwithstanding, you generally can't arrest someone before they've done something wrong.

It's very difficult to defend against a truly novel attack. We know how to defend against attacks that are in classes of attacks that we know. A virus? Well, we know how to defend against viruses; we understand essentially how they work. We understand buffer overflows, so…

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

5 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

13 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

14 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

15 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

17 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

19 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

20 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

20 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

20 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

21 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

23 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint