Data Mining a Mountain of Chris Wysopal CTO & Co-founder Zero - - PowerPoint PPT Presentation

data mining a mountain of
SMART_READER_LITE
LIVE PREVIEW

Data Mining a Mountain of Chris Wysopal CTO & Co-founder Zero - - PowerPoint PPT Presentation

Data Mining a Mountain of Chris Wysopal CTO & Co-founder Zero Day Vulnerabilities The Data Set Applications from over 300 commercial and US government customers Scanned 9,910 applications over past 18 months Ranged in size


slide-1
SLIDE 1

Data Mining a Mountain of Zero Day Vulnerabilities

Chris Wysopal CTO & Co-founder

slide-2
SLIDE 2

The Data Set

  • Applications from over 300

commercial and US government customers

  • Scanned 9,910

applications over past 18 months

  • Ranged in size from 100KB

to 6GB

  • Software was pre-release

and in production

  • Internally built, outsourced,

and commercial ISV code

slide-3
SLIDE 3

▸ Industry vertical ▸ Application supplier (internal, third- party, etc.) ▸ Application type ▸ Assurance level ▸ Language ▸ Platform

Applicatio n Data

▸ Scan number ▸ Scan date ▸ Lines of code

Scan Data

▸ Flaw counts ▸ Flaw percentages ▸ Application count ▸ Risk-adjusted rating ▸ First scan acceptance rate ▸ Time between scans ▸ Days to remediation ▸ Scans to remediation ▸ PCI-DSS (pass/ fail) ▸ CWE/SANS Top25 (pass/fail) ▸ OWASP Top Ten (pass/fail) ▸ Custom policies

Enterpris e Metrics

slide-4
SLIDE 4
slide-5
SLIDE 5

The latent Vulnerabiliesvs. The Attacks

slide-6
SLIDE 6

Top 5 Attacked Web Application Vulnerabilities

slide-7
SLIDE 7

Let’s take a closer look at the numbers

slide-8
SLIDE 8
slide-9
SLIDE 9
slide-10
SLIDE 10
slide-11
SLIDE 11
slide-12
SLIDE 12

Top 3 Vulnerabilities by Language

slide-13
SLIDE 13

Top 3 Vulnerabilities by Language

slide-14
SLIDE 14

Different developers deliver different vulns

slide-15
SLIDE 15

Different developers deliver different vulns

Vulnerability distribution by industry ulnerability distribution by industry

slide-16
SLIDE 16

Are DEVELOPERs making any progress at eradicating cross- site scripting or sql injection?

slide-17
SLIDE 17
slide-18
SLIDE 18
slide-19
SLIDE 19

Dare we ask, How is the U.S. government sector doing?

slide-20
SLIDE 20
slide-21
SLIDE 21
slide-22
SLIDE 22

What percentage

  • f WEB

applications fail OWASP TOP TEN?

a) 34% b) 57% c) 86% d) 99%

slide-23
SLIDE 23
slide-24
SLIDE 24
slide-25
SLIDE 25

Who is holding their software vendors accountable?

slide-26
SLIDE 26
slide-27
SLIDE 27
slide-28
SLIDE 28

So I hear you can run applications on smart phones?

slide-29
SLIDE 29
slide-30
SLIDE 30
slide-31
SLIDE 31

When given an exam on application security fundamentals,

  • ver half of

developers…

a) Receive an A b) Receive a B or worse c) Receive a C or worse d) Fail (receive a D or F)

slide-32
SLIDE 32
slide-33
SLIDE 33
slide-34
SLIDE 34

Chris Wysopal cwysopal@veracode. com @weldpond

QUESTIONS?