Data Breach Investigations Report 2011
Whilst on the subject of new information security reports from WhiteHat Security and Veracode, here is another one to add to your reading material.
SQL injection attacks, cross-site scripting, authentication bypass, and exploitation of session variables contributed to nearly half of breaches attributed to hacking or network intrusion.
The 2011 Data Breach Investigations Report examines data from data breach investigations for Verizon's customers. So, a lot wider than application security, but useful reading.
...don't just focus your logging efforts on network, operating system, IDS, and firewall logs and neglect remote access services, web applications, databases, and other critical applications. These can be a rich data set for detecting, preventing, and investigating breaches.
The information about how long it takes from point-of-entry to compromise, and compromise to discovery are interesting. Especially when the vast majority of data breaches are apparently discovered by third parties — not the target of the attack themselves.
Will that be you?
Posted on: 26 April 2011 at 19:10 hrs

Comments are filtered automatically and should appear shortly after they been checked.