Top Banner
Why care about application security? Paweł Krawczyk (IPSec.pl) [email protected]
35

infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Nov 21, 2014

Download

Documents

infoShare

 
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Why care about application security?

Paweł Krawczyk (IPSec.pl)[email protected]

Page 2: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Sony PSN• April 2011• PSN & Qriosity outage• 80m records lost• May 3

– Another 25m records– Sony Online

Entertainment outage

Page 3: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Small issues are important

Challenger 1986

Sony 2011

Page 4: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

• Top hack (2009)• 130 million personal records

– Credit card numbers

Page 5: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Fast & furious...

Source: datalossdb.org

Page 6: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

$$$• Settlements

– Visa = $60.0m– AmEx = $ 3.5m– Consumer = $ 4.8m

• Ponemon Institute estimate– At $60 cost per record = $7.8b– Now $140 (2010)– Indirect costs (e.g. lost business)

Source: datalossdb.org

Page 7: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

NYSE

Sou

rce:

dat

alos

sdb.

org

Page 8: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Side effect• CC’s prices drop on „black market”• 2008$10-20• 2009$2-6

Numbers from: Finjan, Kaspersky

Page 9: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Grace periodfor startups?

Page 10: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)
Page 11: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Source: dereknewton.com

Page 12: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Farming

Sou

rce:

his

tory

fork

ids.

org

Page 13: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Malware farming• Mass 500k websites infections

–2011 (LizaMoon), 2008• Results for website owners

– Blacklisted in: Google Safe Browsing, Microsoft Phishing Filter, OpenDNS etc.

Page 14: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)
Page 15: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)
Page 16: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)
Page 17: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)
Page 18: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Your website• Blacklisted

– Google Safe Browsing, Microsoft Phishing Filter, OpenDNS etc.

Page 19: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Best ways to get hacked• Guaranteed

– Use ancient Wordpress, Joomla, PHPbb...– Use trivial passwords for FTP, SSH...

• Likely– Write your own application...

Page 20: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Tumblr

Source: niebezpiecznik.pl, Reddit

Page 21: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Bad news live long

Source: niebezpiecznik.pl

Page 22: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

.pl

As seen on 23 March 2011

Page 23: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Wyższa Szkoła Policji

Sou

rce:

pra

wo.

vagl

a.pl

Page 24: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Sąd Okręgowy w Częstochowie

Sou

rce:

pra

wo.

vagl

a.pl

Page 25: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Data protection laws• Poland - up to 50’000 PLN fines

– May issue order to stop processing data• Audit reports are public

– Would you trust them in future?

Page 26: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Going international?

GBP 5,6m

GBP 17,5m

GBP 3m

Page 27: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

How to fix stuff?

Sou

rce:

NA

SA

, Wik

iped

ia (A

pollo

13

- 197

0)

Page 28: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Is

Security

Enemy of economy?

Page 29: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Security

is

Economy

Page 30: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Eliminate bugs early

Applied Software Measurement, Capers Jones, 1996Building Security Into The Software Life Cycle, Marco M. Morana, 2006

Early code audit

Page 31: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

It’s cheaper than...

Applied Software Measurement, Capers Jones, 1996Building Security Into The Software Life Cycle, Marco M. Morana, 2006

PentestLate code audit

Page 32: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

And way cheaper than...

Applied Software Measurement, Capers Jones, 1996Building Security Into The Software Life Cycle, Marco M. Morana, 2006

Hack!

Page 33: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

How?• Dough Hubbard „The Failure of Risk

Management”• Security Assurance Maturity Model

(OpenSAMM)• Security Development Lifecycle (SDL)

Page 34: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Ask peers• OWASP

– Open Web Application Security Project– www.owasp.org

• ISSA– Information Systems Security

Association– www.issa.org.pl

Page 35: infoShare 2011 - Paweł Krawczyk - Why care about application security (open)

Questions, comments?

[email protected]