IBM today introduced software it says will help customers protect Web applications from attack, particularly from the nefarious “cross site request forgery” in which an attacker can fake a request to a site gaining access to sensitive information.
The first release of IBM Rational AppScan, which builds upon security technology Big Blue acquired from Watchfire in July 2007, includes a more powerful scanning engine that can identify more application vulnerabilities. With IBM Rational AppScan, customers can identify, validate and report on application security flaws.
The latest version adds features and reporting methods for security auditors while enabling a broader pool of IT roles to participate in and drive critical web application security testing, IBM said.Traditionally, testers, developers, and IT professionals have lacked the specific security knowledge needed to effectively run scans.
New capabilities in IBM Rational AppScan, such as Scan Expert and State Inducer, broaden the availability of this critical function so IT personnel, software developers and testers are capable of running successful scans while at the same time also add new features to assist security professionals.
According to IBM Web applications are high value targets for hackers, yet many organizations have a difficult time tackling security due, in part, to a lack of application security knowledge and the size and complexity of many websites that incorporate the latest in Web 2.0 technology.
The main new features include:
- Scan Expert lets users automatically profile an application and provide the best test configuration for a successful scan. This enables more successful scanning for users with little IBM Rational AppScan or web application security experience, while improving efficiency for more knowledgeable security experts.
- A new State Inducer feature introduces accurate assessment of multi-step processes within applications. In the past Watchfire had issues with scanning some Web applications out of sequence. The new State Inducer makes complicated Web applications that require multiple steps such as shopping cart and checking out, or filling multiple forms while applying for a loan, or booking an airline reservation more secure. Until now, users would have to manually test each of these areas of the application. With State Inducer, IBM Rational AppScan can learn these sequences, ensuring they are accurately assessed for security issues, further automating, saving time and simplifying the testing process.
- Protection against the dangerous “cross site request forgery.” IBM Rational AppScan identifies areas in a Web site where businesses would be susceptible to cross-site forgery requests. Google earlier this year fixed a CSRF flaw that malefactors could exploit to steal a Gmail user’s full contact list. The ploy is similar to cross-site scripting (XSS) attacks, in which attackers booby-trap a trusted site by rigging it with links that take the visitor to malicious destinations. But whereas XSS attacks exploit the trust that a user has for a site, CSRF attacks exploit the trust a Web site has for a user, experts said.
IBM Rational AppScan will be available on November 19, 2007 stating at $14,400.




