Category Archives: Security

Information Technology Security Ecosystem – Part 1

While having a discussion, I thought of writing a blog covering all important layers of Information Technology Security ecosystem with some relevant links – so here it goes.

Here are some important layers for the same:

  • Physical security
  • Hardware security
  • Network security
  • Endpoint security
  • Application security
  • Data security
  • Identity and access management security
  • Cloud / infrastructure security
  • Operational security
  • Governance, risk and compliance
  • Human security
  • Emerging technology security like AIML, Quantum computing, Blockchain, IoT, etc.

Some links from Wikipedia and internet for the above as reference:

Differences between SAST and DAST – BARD Generated

SAST and DAST: Two Key Players in Application Security

When it comes to protecting your software from malicious actors, you need a solid security strategy. Two crucial techniques in this arsenal are Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST). Let’s break down what each does and how they differ:

SAST:

  • What it is: SAST examines the source code of your application for potential security vulnerabilities, like buffer overflows or SQL injections. It’s like a code inspector, sniffing out flaws before they become exploitable.
  • How it works: SAST tools analyze the code structure, identifying patterns and constructs known to harbor vulnerabilities. They then flag these concerns for developers to fix.
  • Benefits:
  • Early detection: Finds vulnerabilities early in the development process, making them easier and cheaper to fix.
  • White-box approach: Provides detailed information about the vulnerability, including its location and potential impact.
  • Focus on coding practices: Promotes secure coding practices and helps developers learn from past mistakes.

DAST:

  • What it is: DAST simulates the actions of an attacker, probing your running application for exploitable weaknesses. It’s like trying to break into your own house to find security gaps.
  • How it works: DAST tools send automated or manual attacks against your application, looking for responses that indicate a vulnerability. They might try injecting malicious code or manipulating input fields to see if they can gain unauthorized access.
  • Benefits:
  • Real-world simulations: Identifies vulnerabilities that an actual attacker might exploit.
  • Comprehensive scanning: Tests the entire application, including external dependencies and APIs.
  • Black-box approach: Does not require access to the source code, making it useful for testing third-party applications.

Key Differences:

  • Timing: SAST is best for early development stages, while DAST works better on later builds or even deployed applications.
  • Approach: SAST is white-box (focuses on code), while DAST is black-box (simulates attacker perspective).
  • Vulnerability types: SAST finds potential flaws, while DAST identifies exploitable vulnerabilities.

The Takeaway:

SAST and DAST are not competitors, but rather complementary tools. Both offer unique perspectives on your application’s security posture. Ideally, you should use them combined throughout the development lifecycle for a comprehensive security strategy.

Remember, a secure application is not just built, it’s continuously maintained. SAST and DAST can help you proactively identify and address vulnerabilities, making your software a fortress against the ever-evolving threat landscape.

I hope this helps! Let me know if you have any further questions about SAST, DAST, or application security in general.

SAST and DAST Tools: Your Security Allies

When it comes to safeguarding your software, static application security testing (SAST) and dynamic application security testing (DAST) are your allies in identifying and resolving vulnerabilities. But with so many tools available, choosing the right ones can be overwhelming. Here’s a glimpse into some popular options for both SAST and DAST:

SAST Tools:

  • SonarQube: An open-source platform offering static code analysis for over 25 programming languages. It goes beyond security, covering code quality and smells, contributing to overall software health.
  • Fortify: A powerful SAST tool by HCL Technologies, known for its deep source code analysis and accurate vulnerability detection. It integrates seamlessly with development workflows and supports various languages.
  • Coverity: A leading SAST solution by Synopsys, especially adept at finding memory corruption vulnerabilities in C and C++ code. Its focus on high-impact flaws makes it a valuable asset for secure coding practices.
  • Veracode: A comprehensive SAST platform offering analysis for various application types, including web, mobile, and APIs. It provides detailed reports and prioritizes vulnerabilities based on exploitability and severity.

DAST Tools:

  • Burp Suite: An open-source favorite among security professionals, Burp Suite offers a comprehensive toolkit for manual and automated DAST. Its extensibility through plugins allows for customization and targeted scanning.
  • Acunetix: A user-friendly DAST tool known for its intuitive interface and automated scanning capabilities. It covers web applications, APIs, and mobile apps, providing detailed reports and remediation guidance.
  • Netsparker: Another powerful DAST platform with advanced features like web crawler, fuzzing, and SQL injection testing. It excels at identifying complex vulnerabilities and offers integration with CI/CD pipelines.
  • Invicti: A cloud-based DAST solution featuring fast scanning speeds and scalability. It supports various applications and operating systems, making it a versatile option for diverse environments.

Remember, the best tool choice depends on your specific needs and preferences. Consider factors like budget, programming language support, desired features, and ease of use when making your decision.

Feel free to ask if you’d like to delve deeper into any specific tool or have questions about your security testing strategy!

Security & Cookie links @ www.Liferay.com – Part 1

List of Liferay security & cookie related links which includes Cookies, XSS, CSRF, OWASP, CORS, SSO, IAM, Service Action Policies and more:

  1. Known vulnerabilities: Known Vulnerabilities – Liferay
  2. Security statement: Security Statement | Liferay
  3. LXC Cloud security: DXP Cloud Security | Liferay
  4. Securing Liferay page: Securing Liferay – Liferay Learn
  5. Help center DXP 7.0: Liferay DXP Security Overview – Liferay Help Center
  6. Help center DXP 7.1: Introduction to Securing Liferay DXP – Liferay Help Center
  7. Administration security: Security – Liferay Learn
  8. Search security DXP 7.2: Installing Liferay Enterprise Search Security – Liferay Help Center
  9. Search security DXP 7.1: Installing Liferay Enterprise Search Security – Liferay Help Center
  10. Securing ElasticSearch DXP 7.3/7.4: Securing Elasticsearch – Liferay Learn
  11. Reporting security issues: Reporting Security Issues – Liferay
  12. Liferay product cookies: Liferay Product Cookies – Liferay Help Center
  13. Cookie list: Cookies list that could be found in a Liferay Portal and their usage – Liferay Help Center
  14. Login cookies: List of Cookies That Are Affected at Liferay Login – Liferay Help Center
  15. Liferay cloud cookies: Liferay Cloud cookies – Liferay Help Center

Email me: Neil@HarwaniSystems.in

Railway safety

Some suggestions for railway safety:

  • Put threads of wire inside track while building along with insulated areas in track to hold the wire safely
  • Sensors at each joining fish plate attached to wire and WIFI / low energy Bluetooth or other devices
  • Extra ballast and heavy concrete for IED protection
  • Weld all fish plates, clamps and other things with shock absorbing joints for heat and train movement
  • At each track joint of fish plate put WIFI sensor which sends encrypted signal and tells if conductivity is right from wire in track to sense damage / sabotage
  • Red Blue shift based radio sets sensing distance with unique codes for each train which tell if trains on same track are coming towards each other mapped to WIFI sensors on track to avoid collision like TCAS of flights

Too many accidents – this could be a good start

Open source security platform for security of physical installations

I hope to publish my thoughts on innovation around software on this blog. Starting off with my first post.

We live in a world where security has now evolved from physical to cyber to multiple levels and context. Open source software has been a revolution which now is reaching us at all levels: Mobile (Android), Enterprise software (Liferay, Alfresco, Hadoop, MongoDB, etc.) and it caters to security in a holistic way by allowing people/groups to pick holes in the systems and thus, giving opportunity to authorities to fix them in the background and allow improvements.

Similarly we can device a system based on open source principles for security of physical / real world installations via an open source and collaborative platform

We could create an open source platform on one of the open source support sites like SourceForge

Pillars of platforms around which it should be built (these also give the high level classification of collaboration):

1. Assets
2. Threats
3. Defenses
4. Strategy

Assets: 1. Threat level based classification based on location, work done by asset, importance

Threats: 1. Physical, 2. Cyber 3. Design 4. Evolving and future

Defenses: 1. Explicit, 2. Implicit 3. Mixed

Strategy: 1. Offensive, 2. Defensive, 3. Mixed

People can come and post installations (Assets), then debate/discuss issues (Threats), find and suggest solutions (Defenses) and based on these three suggest overall Strategy to mitigate risks

See you later with another innovation thought in few days