Application security

November 2012 Information Security

Despite an array of security tools at their disposal, companies are still under cyber attack and, if one looks at the number of known successful attacks on business data and finances, it seems that the criminals are winning. Of course, in South Africa most of these breaches are not publicised because there is no requirement on the part of the company to acknowledge successful intrusions. This may change in the near future, but the reality is that publicising attacks is not the solution.

Some say that the embarrassment factor once a breach is public will force companies to tighten their digital perimeters as a risk mitigation measure. But then, what do they do about the internal threats from employees who see a vulnerability and decide to ‘borrow’ some company money to fund their weekend trip to the casino or support their neighbourhood syndicate? Most people in the know will tell you that the prevalence of internal fraud is far higher than external attacks.

The latest South African Cyber Threat Barometer for 2012/13 estimates that R2,65 billion was lost to cyber crime in the period from January 2011 to August 2012, with just over R660 million that was not recovered. To download the barometer for free, please go to www.securitysa.com/*cyberthreat-za (this is a shortened link that will take you to http://www.wolfpackrisk.com/wp-content/uploads/2012/10/SA%202012%20Cyber%20Threat%20Barometer_Hi_res.pdf).

At the recent CA Symposium in Johannesburg, Hi-Tech Security Solutions spoke to Ed Medcalf, regional commercial manager, CA Technologies, about the latest in application security.

Ed Medcalf
Ed Medcalf

While we all enjoy the technology available today that allows us to access the corporate network and applications from anywhere, using almost any device, the convenience is offset by a reduction in security because the perimeter of the business is now everywhere. If, for example, you log into an application while at the airport and someone watches you type in your password, if that password is your only defence, the watcher can now access whatever you can. Similarly, if you have malware on your mobile device courtesy of a funky app you downloaded, your personal details as well as your access credentials to corporate digital assets are also compromised.

Instead of monitoring data streams and stored data for known malware strings, as most antivirus applications do, Medcalf suggests it is time to monitor the context of application access rather than only the data. Add to this the context of the user’s behaviour and the business has a good chance of stopping both internal and external shenanigans.

It is important to remember that a valid user will not need malware to access corporate systems as they are allowed, or even supposed to be there. However, if you know the user’s normal behaviour, such as what applications he uses, what authority he has and where he accesses the system from, you can adjust the security protocols to grant access while remaining secure.

Medcalf gives the example of a CFO accessing sensitive data. If the CFO is authenticated and logs on from his office PC, continues with his normal behaviour at the times he usually does his work, he can be granted access transparently. If however, he logs in at midnight from an unknown device, the system can automatically insist on more security to ensure the access is legitimate, or even deny access because it is too risky.

If you are already monitoring the data going through applications, this added layer of security will not add any latency or slow the user at all. Medcalf adds that CA works with customers to set policies to implement this type of application security, looking at variables that make sense to the company, such as the number of times a user requests access, the value of transactions he normally handles, and whether he crosses boundaries like financial ceilings and so forth.

Naturally, application security based on behaviour is only one tool in the arsenal of protection companies need to take to secure their digital assets and bank accounts from internal and external threats.

The security process starts with authenticating users and making sure they have access to what they need to do their jobs. It also includes taking the time to create workable policies that set behavioural limits, such as how much money an individual can authorise for payment and who needs to verify the final payment etc.

It also means controlling access via mobile devices. If the CEO above accesses the network via his Galaxy Tablet and the company knows this device is his and has the relevant security installed, access is granted. If however, it is an unknown device, access can be denied or limited.

In the good old days, digital security was an application you could install and basically forget. Today it has become a craft that requires cooperation across different disciplines within the company, focused on developing a constantly evolving solution.



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Open source code can also be open risk
Information Security Infrastructure
Software development has changed significantly over the years, and today, open-source code increasingly forms the foundation of modern applications, with surveys indicating that 60 – 90% of the average application's code base consists of open-source components.

Read more...
DeepSneak deception
Information Security News & Events
Kaspersky Global Research & Analysis researchers have discovered a new malicious campaign which is distributing a Trojan through a fake DeepSeek-R1 Large Language Model (LLM) app for PCs.

Read more...
SA’s strained, loadshedding-prone grid faces cyberthreats
Power Management Information Security
South Africa’s energy sector, already battered by decades of underinvestment and loadshedding, faces another escalating crisis; a wave of cyberthreats that could turn disruptions into catastrophic failures. Attacks are already happening internationally.

Read more...
Almost 50% of companies choose to pay the ransom
News & Events Information Security
This year’s Sophos State of Ransomware 2025 report found that nearly 50% of companies paid the ransom to get their data back, the second-highest rate of ransom payment for ransom demands in six years.

Read more...
Survey highlights cost of cyberdamage to industrial companies
Kaspersky Information Security News & Events
The majority of industrial organisations estimate their financial losses caused by cyberattacks to be over $1 million, while almost one in four report losses exceeding $5 million, and for some, it surpasses $10 million.

Read more...
Digital economy needs an agile approach to cybersecurity
Information Security News & Events
South Africa is the most targeted country in Africa when it comes to infostealer and ransomware attacks. Being at the forefront of the continent’s digital transformation puts South Africa in the crosshairs for sophisticated cyberattacks

Read more...
SIEM rule threat coverage validation
Information Security News & Events
New AI-detection engineering assistant from Cymulate automates SIEM rule validation for SecOps and blue teams by streamlining threat detection engineering with automated testing, control integrations and enhanced detections.

Read more...
Cybersecurity a challenge in digitalising OT
Kaspersky Information Security Industrial (Industry)
According to a study by Kaspersky and VDC Research on securing operational technology environments, the primary risks are inadequate security measures, insufficient resources allocated to OT cybersecurity, challenges surrounding regulatory compliance, and the complexities of IT/OT integration.

Read more...
Are AI agents a game-changer?
Information Security
While AI-powered chatbots have been around for a while, AI agents go beyond simple assistants, functioning as self-learning digital operatives that plan, execute, and adapt in real time. These advancements do not just enhance cybercriminal tactics, they may fundamentally change the battlefield.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.