How secure is your security software?

News
Jun 5, 20073 mins

Experts warn of flaws in products designed to protect

Think that commercial software you just bought has been adequately tested and is ready for deployment? Think again.

WASHINGTON — Think that commercial software you just bought has been adequately tested and is ready for deployment? Think again.

According to a panel of vulnerability research experts who spoke at the Gartner IT Security Summit held here this week, enterprises should test vendor software for vulnerabilities before deploying, much like they should be testing their home-grown applications. (Read about the importance of testing.

This is particularly true for security products, since customers usually assume these products are tested more rigorously than others. But, according to Thomas Ptacek, founder of consulting firm Matasano Security, that’s rarely true.

“There’s a misconception about security products that are layered on top of other products, that they are more secure, but people who build those products are developers just like everybody else,” Ptacek said during the panel. “One thing I find when doing research is there’s no immunity that security products get to code-level or application-level security flaws.”

Security products have gotten so complex that they open themselves up to exploitation, said another panelist.

“At some point the applications you’re using have gotten so complicated that no one understands how they work anymore,” said David Maynor, co-founder of Errata Security. “Antivirus is a perfect example. You buy the application to run on your desktop to make you more secure, and in reality it makes you less secure.”

Enterprises should press vendors of all types of software for proof – usually documentation – of vulnerability testing, and do their own testing to verify claims, the panelists agreed. Chris Wysopal, co-founder of Veracode, told of a software package his previous employer purchased that claimed a certain level of encryption, but upon testing he discovered the product didn’t achieve the level it stated.

Rich Mogull, the Gartner analyst hosting the panel, asked if buyers would be better off holding vendors responsible for adequately testing their own products than having to test the software themselves.

“One way to get [vendors] to be more accountable is to prove to them that [their customers] are going to do due diligence,” said Ptacek. “If vendors know when their customers deploy their product it will undergo testing, they may take more seriously the fact that the application needs to be tested.”

Enterprise customers should also use vulnerability testing results as a bargaining chip, they said.

“Say [to the vendor] `Your application has bugs, I’m not paying list [price] for this,” suggested Maynor.

“Ideally you want to test the product during the evaluation phase, so then you can say `We need these problems fixed if we’re going to buy this product,” added Wysopal.