What application-level security really means

Opinion
Dec 13, 20043 mins

* Application-level security means different things to different people

Recent advances in defenses that target malicious network traffic have made it possible to analyze that traffic in real time for potential threats.

These techniques enable visibility throughout the entire seven-layer OSI model of the network stack. In this model, the ultimate payload data is carried at the application layer. But the evolution of the term “application” has led to some confusion as to what defense at this level really means. Today, it implies at least three different types of security – and it’s important to know the differences.

The first type revolves around techniques having visibility into network traffic throughout the stack. Sometimes referred to as “application-level” defenses, the real implication of these techniques is that they extend firewall concepts beyond past approaches which concentrated on threats primarily at Layers 3 and 4 – that is, maliciously or malformed IP, ICMP, TCP, UDP, or other protocols that operate at this level. Merging techniques of intrusion prevention with firewalls, application-level defenses can now examine and act on threatening network content at every layer.

Defenses are network- as well as host-based. Network defenses imply a high degree of performance, as suggested by the powerful deep inspection technologies of Juniper Networks, or the innovative parallelism of the Radware security switch – but they also blur boundaries with emerging intrusion prevention techniques, such as those being developed by Sourcefire. In addition, a number of other defenses have visibility into application-level content, but fly under a more specific banner, such as the many different approaches to content filtering and security.

Then there is a subset of these defenses that provides application security proper. If your goal in deploying application-level defense is securing applications themselves, this is the functionality you need to know about. In this sense, “application” refers to the n-tier integration of functionality that supports many of today’s Web-enabled environments – so the term “Web application” is also used in this context. These applications typically combine Web, database, security and network functionality, and may include ERP systems, for example.

Because of the many claims and counterclaims in this area, a group of vendors representing different approaches to this aspect of application security have collectively put forward a minimum standard for what application security means in this sense. In combination with the respected ICSA Labs division of TruSecure (now Cybertrust since merging with Betrusted), the standards proposed by F5 Networks, Imperva, NetContinuum and Teros include: prevention of command execution attacks; the enforcement of strict controls on application inputs; and prevention of tampering with form fields, URLs, parameters, and state information such as cookies.

A third major and emerging aspect of application-focused security is the increasing segment of vendors that focus on the defense of malicious or malformed XML. Sometimes called “XML firewalls,” vendors include DataPower, Forum Systems, and Reactivity. This segment is positioning itself to secure a growing number of Web services deployments, considered by many to be the future of distributed application integration.

With this profusion of focus on securing the application content of today’s infrastructures, it’s no wonder that there is often confusion as to what “application security” really means. But it’s becoming increasingly critical for the enterprise to know and understand the differences.

Security objectives for service-level management are still in their infancy, yet enterprises as well as service providers are under scrutiny as never before for compliance and liability issues directly related to application and identity security. We’ll look at these increasingly critical aspects of service management in upcoming newsletters.