Security advances not keeping pace with technology
Trying to lock down your company’s applications and protect your systems from attack? If so, security scanners and source-code analysis tools are not up to the job — despite vendor claims to the contrary. “There’s an awful lot of marketing spiel, people introducing technology tools that are sold as silver bullets,” said Mark Curphey, vice president of professional services at McAfee Inc.’s Foundstone division, in an interview. “The reality is, in a large enterprise, those things generally don’t work.” “Technology is increasing at such a fast and crazy pace, but security technology isn’t keeping up with it. With application security it’s even worse,” Curphey said. Security tools, such as code scanners, are able to detect just 1 percent to 2 percent of vulnerabilities in an application, leaving “gaping holes” behind, he said.
