News
News
3/4/2003
02:07 PM
Connect Directly
RSS
E-Mail
50%
50%

Vendors Pitch Application-Security Spec

AVDL will be designed to provide a standard way for application vulnerabilities to be defined and classified.

IT security pros are aware that hackers and data thieves are increasingly targeting software vulnerabilities that traditional intrusion-detection systems, firewalls, and antivirus software do little to defend against. To thwart the growing threats, more companies have been turning to various security products to get the job done: patch-management applications to push software updates across the network; application and vulnerability scanners to find security holes; and application firewalls to block attacks waged against Web apps.

A small group of Internet security companies have an idea they hope will make it easier for administrators to lock down their apps. The group has proposed the Application Vulnerability Description Language to the standards group Oasis. AVDL, based on XML, will be designed to provide a standard way for application vulnerabilities to be defined and classified so all of the applications companies use to secure their apps will speak the same language when it comes to security threats.

The group, founded by Citadel Security Software, GuardedNet, NetContinuum, SPI Dynamics, and Teros, hopes to have version 1.0 of the spec completed by year's end. The first full meeting of the Oasis technical committee is slated for May 15.

If it works as promised, AVDL would help security pros better react to newfound software vulnerabilities and attacks, says Pete Lindstrom, research director for Spire Security. Eric Ogren, senior analyst at the Yankee Group, agrees. "This is a good idea to better help companies manage risks to the application security," he says.

The group says that with AVDL, application vulnerability-assessment tools, such as those provided by SPI Dynamics, will be better able to better report on the state of application security throughout an organization at any point in time. Security event managers, such as those made by GuardedNet, will be able to better correlate security problems found in applications with actual security attacks and related events.

Gene Banman, CEO for NetContinuum, which makes network- and application-security appliances, says the developments shows that the application-security market is beginning to mature. The standard will let all security companies focusing on Web apps help customers better secure their apps, he says. "By having a standard protocol for which we can communicate information about vulnerabilities," Banman says, "application intrusion-prevention tools will be able to better understand a company's applications vulnerabilities and then set security policies based on the specific vulnerabilities that we found by these assessment tools."

Comment  | 
Print  | 
More Insights
The Business of Going Digital
The Business of Going Digital
Digital business isn't about changing code; it's about changing what legacy sales, distribution, customer service, and product groups do in the new digital age. It's about bringing big data analytics, mobile, social, marketing automation, cloud computing, and the app economy together to launch new products and services. We're seeing new titles in this digital revolution, new responsibilities, new business models, and major shifts in technology spending.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Tech Digest - July 22, 2014
Sophisticated attacks demand real-time risk management and continuous monitoring. Here's how federal agencies are meeting that challenge.
Flash Poll
Video
Slideshows
Twitter Feed
InformationWeek Radio
Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.