Fortify urges security rethink

May 31, 2005, 8:22pm PDT | Length: 00:03:30
Roger Thornton of Fortify says as companies spend more on information security, the number of exploits continues to rise. He says it's time to re-examine the security around software.

Transcript

Fortify urges security rethink

Hi, I'm Roger Thornton, CTO of Fortify Software. The subjecttoday is information security, more specifically, the security dilemma, one,two, three.

One, if we were to take a look at information security todayand give it a grade, what grade do you think it would get? Well, let's take alook at some facts. Today, businesses are spending more money than they everhave on securing information systems, protecting them from worms, viruses,malicious insiders and hackers. Literally billions of dollars are being spenton this and the desired effect is for the exploits that rob private data andharm systems to go down. But I probably don't have to tell you that thoseexploits are rising and are, in fact, at an all time high. Our hacker math isall wrong.

Two, why is that? Well, what do the experts have to say?According to the national institute of standards and technology, 92% of all thevulnerabilities that they tracked in 2003 were actually at the applicationlevel, operating systems and business applications, not at the network.According to the Gartner group, last year 70% of all the information systemvulnerabilities and large corporations were again at the application softwarelevel, not at the network. It has something to do with the way that we thinkabout security. Traditionally, we think about protecting the thing that'simportant to us. In this case, it's the software that holds our business dataand automates business processes, and we put it behind walls so that the badguys can't get at it. Well, about 10 years ago, what we figured out, if we tookcomputer programs and we poked through those walls and made those programs talkto other programs, we got things like the World Wide Web, e-mail, instantmessenger. Well when business got a hold of this technology, they did all sortsof things like integrating, manufacturing systems, moving inventory partinformation between companies, automating financial systems, moving financialinformation between companies, automating healthcare systems, moving healthcare information in real time, synchronized transactions between businesses.What does this do to our security profile? Well, what it does is, it makesthese walls less effective or maybe even absolutely ineffective at protectingthe software.

This is at the heart of what's causing us the problem withour hacker math, if we're able to make the software itself fundamentallysecure, then the fact that it's poking through our walls fireware, firewalls,intrusion detection systems, and so forth, we will get a handle on our hackermath and a number of exploits will go down. So I would say, we don't have asecurity dilemma, today we have a software dilemma.

Business class SaaS

Business class SaaS

Sponsored: The Software as a Service market is expected to double by 2012. Martin Capurro,...

Getting hooked: Phishing, pharming and online threats

Getting hooked: Phishing, pharming and online threats

Sponsored: There's no shortage of malicious code on the Internet. Agent Peterson of the Geek...

Vista: User account security

Vista: User account security

David Berlind, executive editor at ZDnet, explains how new security features in Windows Vista...

Protect privacy with encryption

Protect privacy with encryption

Sponsored: Paul Needham, director of product management for database security at Oracle,...

Vista: User account security

Vista: User account security

David Berlind, executive editor at ZDnet, explains how new security features in Windows Vista...

Security in a Web  2.0 world

Security in a Web 2.0 world

Malware is increasing with the popularity of social networking sites. Dan Nadir, vice president...

Two-factor authentication

Two-factor authentication

Dennis Hoffman, vice president of enterprise solutions at RSA, explains how a security process...

VoIP security: The real risks

VoIP security: The real risks

Like traditional data networks, voice networks carry their share of security risks. VOIP Watch's...

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

White Papers, Webcasts, & Resources

Facebook Activity