Welcome | Sign In
ECommerceTimes.com
News

Study: Web Security Spending To Surge

Print Version
E-Mail Article
Reprints
Study: Web Security Spending To Surge

The report noted that it is not uncommon for Web sites to add so much new code daily that operators are unable to maintain patches or fix holes in systems.


eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.

Spending on Web security efforts is expected to triple in the next four years, according to a new report released by research firm IDC.

The report predicted that security spending will increase 60.5 percent annually to nearly US$700 million by 2006, compared with $65 million in 2001.

According to IDC, while enterprises continue to invest in security measures like firewall protection, Web sites and applications continue to fall victim to hackers and crackers.

"Web presence for businesses today is essential; but just as it is essential, it is also the center of security problems," said Charles Kolodgy, research manager of IDC's Internet Security Software service.

"Securing Web sites and the corresponding applications and databases is a difficult problem, as Web sites exist to be accessible and firewall ports need to be left open for communication," Kolodgy added.

Security Focus Misaligned

The IDC report pointed to security at the application layer as the most vulnerable, noting that most efforts at protection are built instead around the network layer.

Kolodgy told the E-Commerce Times that as corporations begin to make Web security a business focus, as opposed to an IT focus, and as they place more e-commerce and critical functions online, spending in these areas will increase.

"The Web presence needs a tighter type of security," he said. "Unlike your back-end systems or your corporate network, where you have definitive entrance and authentication measures, your Web site is just there."

The report identified the weak areas in a majority of companies' Web server and application security. They included the use of firewalls and IDS (intrusion detection systems) to secure the application layer, poor programming of CGI scripts and bugs in Web server applications, source code that is available for viewing by users, and freely available hacking tools.

The report noted that it is not uncommon for Web sites to add so much new code daily that operators are unable to maintain patches or fix holes in systems.

Change in Attacks

Certain types of attacks, according to IDC, are relatively easy to launch, including efforts to "poison" a Web sites' cookies to gain unauthorized information about a server. As applications do not expect anyone to change cookies, they may process a poisoned cookie that modifies fixed data fields.

Hackers also may employ a tactic called cross-site scripting in which malicious code, usually in the form of a script tag, is added to a URL, then executed when a user clicks on that URL.

The report also highlighted the practice of modifying a URL by using various characters and symbols to bypass Web controls and break out of a server's root directory to access files.

Methods to thwart such attacks, IDC said, include the use of host intrusion prevention and detection systems, application shields, GAP appliances to physically separate different networks, exit control to prevent the display of unauthorized alternation to the content of a Web site and vulnerability assessment scanning.

Security Companies Thriving

Security-related companies are already feeling the effects of a corporate and consumer focus on keeping systems safe from attack.

Security firm Symantec (Nasdaq: SYMC) on Wednesday announced plans to purchase SecurityFocus, Recourse Technologies and Riptech in separate acquisitions worth a total of $355 million.

The company also reported fiscal first-quarter results that outpaced Wall Street expectations, attributing its strong showing in part to robust consumer sales of antivirus software. Earnings for the quarter totaled $56.6 million, up from a net loss of $21.2 million in the year-ago period.


Print Version E-Mail Article Reprints More by Lisa Gill


Talkback: Join the Discussion.
Vulnerability Notification Service
hubbelyo
Posted 2002-07-20
At work we use a vulnerability notification service to keep up-to-date with the software we are ...
Re: Vulnerability Notification Service
faelyne
Posted 2002-07-22
Vulnerability assessment is certainly the way to go. I make the analogy between using a ...

Related News Alerts

Symantec Activate Alert | Search Archives

More by Lisa Gill

How Web Services Will Change E-Business
February 28, 2003
IDC has estimated that just 5 percent of U.S. businesses in 2002 had completed a Web services project. But by 2008, the research firm said, 80 percent of firms will have such a project under way.
The Big Business of Fighting Spam
February 10, 2003
Though Brightmail CEO Enrique Salem could not disclose 2002 earnings, he said an IDC estimate that Brightmail earned about $8 million in revenue in 2001 is "pretty close, maybe a little low," then noted that the company's revenue doubled in 2002.
IBM Wins Ford Motor Services Contract
February 06, 2003
Although Ford spokesperson Paul Wood could not comment on the duration of the contract, Dassault's Keith Pillow said it is a long-term deal that is to last for five years.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network