08 October 2010

Web Application Security Incident Analysis

The Web Hacking Incident Database 2010 semi-annual report was published in early September. I have only just managed to find time to read it.

Partial screen capture of a page from the Web Application Security Consortium's Web Hacking Incident Database (WHID) report for January to June 2010 showing a pie chart of attack methods

This latest report for January to June 2010 analyses actual reported incidents (e.g. data breaches) collected by the Web Hacking Incident Database (WHID), a project of the Web Application Security Consortium and supported by Trustwave SpiderLabs. The WHID's goal is to raise awareness of the web application security (webappsec) problem and provide information for statistical analysis of web application security incidents. The data only include disclosed and reported targetted (i.e. non-random) attacks against specific organisations (see Zone-H for wider data on random or opportunistic defacement hacks).

The information is very clearly presented and includes attack source geographic location, the drivers (outcomes), attack methods, weaknesses exploited and organisation type. It will be very useful for risk and security professionals who want to prioritise resources protecting their web sites, applications and the associated data. In case you haven't guessed "SQL injection is still the top known attack category".

If you haven't seen them yet, the "real-time" interactive charts on the project's home page are fantastic. Other ways to keep up-to-date are using the RSS feed or Twitter.

Posted on: 08 October 2010 at 08:55 hrs

Comments Comments (1) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Hi,
Unfortunately the numbers won't do much for the perception that security teams don't always focus on greatest business risk compared, reducing ROI.
Always good to have some hard(ish) figures to backup a requirement and/or protection though. Thanks for sharing.
1 Added by mobile web application Posted on 11 October 2010 at 05:50 hrs
Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Web Application Security Incident Analysis
http://www.clerkendweller.com/2010/10/8/Web-Application-Security-Incident-Analysis
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2010/10/8/Web-Application-Security-Incident-Analysis
Requested by 38.107.179.224 on Thursday, 17 May 2012 at 22:05 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2010-2012 clerkendweller.com