Anton Chuvakin
Original URL: http://blogs.gartner.com/anton-chuvakin/2012/02/02/many-faces-of-application-security-monitoring/ | Archive.org Snapshot
Anton Chuvakin
Research Director
1 year with Gartner
7 years IT industry
Anton Chuvakin is a research director at Gartner's IT1 Security and Risk Management group. Before Mr. Chuvakin joined Gartner, his job responsibilities included security product management, evangelist… Read Full Bio
Coverage Areas:
by Anton Chuvakin | February 2, 2012 | 9 Comments
Everybody knows what “network security monitoring” actually is (even if not everybody is DOING it…). There is a whole book on the subject. In addition, there is a shared understanding in security community about it. Specifically, NSM includes various logs/alerts, packets, flows, session captures, etc.
However, what is “application security monitoring” (ASM)? As I am pursuing my second research project this quarter – one related to SIEM technology futures – I am coming across people attaching the “ASM” label to various technologies and processes. Specifically, these are:
In your opinion, do any of the above constitute application security monitoring on their own?
Personally, I doubt it. At best, ASM might mean “all of the above” or “many of the above," but I think a few components needed to achieve ongoing visibility of all security-relevant activities inside off-the-shelf and custom applications have not even emerged yet. It may be that security has to outgrow its network roots first and get some application DNA implanted.
The theme that also seems to emerge in my research is that unlike with NSM, answering “what happened?” (example: “error 945842 on application XYZ”) is comparatively less important than answering “what it means?” (example: “security control failed to prevent malicious activity at application XYZ that is important for our business”). Thus, we need to both collect more telemetry AND context, as well as build tools to make sense of that data!
Thus, both enterprises and vendors have work to do in the coming years!
Category: application monitoring security Tags: application security, security, security monitoring
1 Ivan Ristic February 2, 2012 at 8:57 pm
The name “web application firewall” is very indicative of the prevailing line of thought in application security defense today. Most people are interested in quick fixes and that’s where the word “firewall” comes from. It is, of course, unreasonable to expect that a WAF will be successful in “firewalling” against complex attacks (where even traditional firewalls — dealing with much simpler attack scenarios — often fail). In the hands of a skilled operator a WAF can be used for foolproof protection via virtual patching, but outside that, WAFs’ main purpose is to increase the cost of an attack. In the meantime, most people are missing out on the benefits of application-layer situational awareness. It took years for NSM to gain popularity, and it will take many more years for ASM to come anywhere near. There is sadly still very little interest in application-layer defense.
I would guess that most WAFs today are indeed are designed as application-layer IPS products, but it does not have to be that way. To me, monitoring of application-level traffic was always the most important characteristic of a WAF.
2 Anton Chuvakin February 2, 2012 at 9:36 pm
Ivan, thanks for the comments. Am I correct that “W” in WAF stands for “web”? This was essentially my point: even if WAFs do 10x better than they currently do, only web apps get the protection.
And, how often are WAFs deployed internally, NOT at the perimeter?
“There is sadly still very little interest in application-layer defense.”
3 Many Faces of Application Security Monitoring « Tips On Security February 3, 2012 at 3:54 am
[...] the article here: Many Faces of Application Security Monitoring Comments [...]
4 JTH February 3, 2012 at 10:50 am
In order to have ‘proper’ application monitoring in place one should really consider building it in. The output should be going to logs which also have some or many of your sources. This sound quite close to ‘telemetry’ idea, and this is how I understand ‘application context’.
The application logs then would show behaviour data from the application users and misusers. The behaviour data is based on application features and typically quite hard to catch by any third party tools.
These sources then would be monitored and analysed by persons or event correlation software and persons.
The coverage of the monitoring and its sources are mandated by the classification of the system i.e. probably only mission critical systems would be having such dedicated application monitoring. Most will do less.
Please note, that vulnerability management is ‘sort of’ part of the application monitoring too. All the components of the software: libraries, frameworks, auxilliary software sources should be monitored for any critical security vulnerabilities, as the normal vulnerability management targets: operating systems, databases, web servers etc.
And when you get paranoid, do you trust your code? Will you do monitoring during the development of the software? The code reviews and other App Sec methods will cover that field.
5 Anton Chuvakin February 3, 2012 at 4:19 pm
> In order to have ‘proper’ application monitoring in place one should really consider building it in.
Good idea indeed! And, yes, I used the word “telemetry” to mean “logs and whatever else needed.”
However, waiting for it to happen would be somewhat counterproductive, right? Yes, 3rd party tools will have trouble, but what choice to organizations have if “built-it-in” isn’t there?
You are right about VM, but I like to remind myself that vuln assessment is ASSESSMENT (and generates useful context data for monitoring) which is different from MONITORING.
6 The IT Services Site - James M. Connolly - Know What's Going On Inside Your Apps February 3, 2012 at 8:52 pm
[...] blogger was Anton Chuvakin, who wrote about the Many Faces of Application Security Monitoring. Chuvakin did a nice job of looking at how IT organizations believe they are monitoring application [...]
7 JTH February 4, 2012 at 8:39 am
Regarding your comment on vulnerability management – I tend to differ the vulnerability assessment – scanning, testing from vulnerability management, which actually does not need any tools, only the information of the software assets. Monitoring in this context would be searching information of the vulnerability sources and your own source code which typically is not followed by any other party. Sorry about vague use of words over here.
Relying on the vulnerability scanning tools such as Nessus would not necessary reveal all the weaknesses of the software as the scan will not penetrate through application logic, would not otherwise be ‘visible’ to the scanner as it may be in the case of software libraries.
8 Adrianna Ruzbasan February 4, 2012 at 2:55 pm
[...]Swedish therapeutic massage was produced using techniques utilized by the Swedish physiologist as [...]…
9 britax b agile stroller February 5, 2012 at 8:54 pm
[...]took the item. ” In reality, whether or not it can be about your mouth officer, or tibia and leg guards, it is [...]…
Comments or opinions expressed on this blog are those of the individual contributors only, and do not necessarily represent the views of Gartner, Inc. or its management. Readers may copy and redistribute blog postings on other blogs, or otherwise for private, non-commercial or journalistic purposes. This content may not be used for any other purposes in any other formats or media. The content on this blog is provided on an "as-is" basis. Gartner shall not be liable for any damages whatsoever arising out of the content or use of this blog.
© 2012 Gartner, Inc and/or its affiliates. All rights reserved.