current web security challenges in latvia

10
Current web security challenges in Latvia Ēriks Dobelis, RTU RBS, BITI, eriks . dobelis @ biti . lv

Upload: sorcha

Post on 05-Jan-2016

21 views

Category:

Documents


0 download

DESCRIPTION

Ēriks Dobelis, RTU RBS, BITI, eriks . dobelis @ biti . lv. Current web security challenges in Latvia. Contents. Identity theft Code quality Single layer of control Lack of monitoring Decreasing importance of perimeter Impact of consumerisation and device specialization - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Current web security challenges in Latvia

Current web security challenges in Latvia

Ēriks Dobelis, RTU RBS, BITI, eriks . dobelis @ biti . lv

Page 2: Current web security challenges in Latvia

Contents

Identity theft Code quality Single layer of control Lack of monitoring Decreasing importance of perimeter Impact of consumerisation and

device specialization Other long term trends

Page 3: Current web security challenges in Latvia

Identity theft

Most popular authentication methods: User/password Code card Code calculator MobileID Internetbank as authentication provider

Page 4: Current web security challenges in Latvia

Identity theft (cont.)

Risks Insecure storage (esp. password, code

card) Phishing

Solutions More secure authentication methods User education

Page 5: Current web security challenges in Latvia

Code quality

Secure code development not part of typical curriculum

A lot of vulnerable code Solutions

Training and education Penetration testing Architecture

Page 6: Current web security challenges in Latvia

Single layer of control

Most web applications put 100% of security controls in code

Mistake by one developer may lead to huge impact

Solutions Application level security proxy Usage of frameworks

Page 7: Current web security challenges in Latvia

Lack of monitoring

Most organizations cannot afford dedicated security professionals

Most IDS systems fail to identify large sets of attacks

Solutions Application level security proxy Regular log analysis

Page 8: Current web security challenges in Latvia

Decreasing role of perimeter

False sense of security from firewall Increasing number of business

partners Increased use of hosted applications Solutions

Access control centralization Security policy

Page 9: Current web security challenges in Latvia

Impact of consumerisation and device specialization

Consumers using increasing range of devices to connect to web applications

Impossible to restrict browser versions and platforms

Browser vulnerabilities Solutions

Platform independent standards based development

Page 10: Current web security challenges in Latvia

Other long term trends

HTML5 new funcionality WebSockets Offline applications Local data storage and access to files Concurrency

Move to cloud Increasing power of large vendors