introduction to appscan enterprise

17
® IBM Software Group © 2007 IBM Corporation Introduction to AppScan Enterprise

Upload: doque

Post on 04-Jan-2017

228 views

Category:

Documents


4 download

TRANSCRIPT

Page 1: Introduction to AppScan Enterprise

®

IBM Software Group

© 2007 IBM Corporation

Introduction to AppScan Enterprise

Page 2: Introduction to AppScan Enterprise

2

ContentsThe Application Security ProblemWhat is AppScan Enterprise?Main FeaturesHow does AppScan Enterprise work?Key Concepts and TerminologyUser Interface Tour

Page 3: Introduction to AppScan Enterprise

3

Network Server

WebApplications

The Web Application Security Reality

% of Attacks % of Dollars

75%

10%

25%

90%

Sources: Gartner, Watchfire

Security Spending

of All Attacks on Information SecurityAre Directed to the Web Application Layer

75%75%of All Web Applications Are Vulnerable2/32/3

Page 4: Introduction to AppScan Enterprise

4

Web Application Security Challenges

Difficulty Managing 3rd Party VendorsDifficulty Managing 3rd Party Vendors555

Not Monitoring Deployed ApplicationsNot Monitoring Deployed Applications444

Catching Problems Late in the CycleCatching Problems Late in the Cycle333

Lack of Control and VisibilityLack of Control and Visibility222

Security Team Has Become a BottleneckSecurity Team Has Become a Bottleneck111

Page 5: Introduction to AppScan Enterprise

5

Web Application Security EvolutionWeb Application Security Evolution

StrategicStrategicStrategicStrategicStrategicEnterprise-WideScalable Solution

Solving The Problem Requires a Strategic Approach

TacticalTactical Manual Efforts, Desktop Audit Tools2-3 Internal Security Experts

OutsourcedOutsourced ConsultantsPen Testing

UnawareUnaware

Page 6: Introduction to AppScan Enterprise

6

SCALESCALE

Reuse and Run Multiple Scans

Across Applications

INFORMINFORM

Push Reportsto Developers,

QA, andNon-Security Staff

MONITORMONITOR

Manage Problem Resolution Through

Trending ReportsAppScan EnterpriseAppScan EnterpriseAppScan Enterprise

What is AppScan Enterprise?

Security Team

Integrate Web Application Security in the SDLC

Page 7: Introduction to AppScan Enterprise

7

AppScan Enterprise – Key Features & Benefits

Increase visibility and better understand enterprise risks

Controlled, Web-based Report DistributionControlled, Web-based Report Distribution

333

Controlled, Web-based Application TestingControlled, Web-based Application Testing

222

111

Enterprise Metrics and VisibilityEnterprise Metrics and Visibility

Easily distribute reportsControl the access to information

Enable Development and QA to perform testing during SDLCControl what applications each user can test

444 Issue ManagementIssue Management

Focus on fixing issues, not just finding issues

Page 8: Introduction to AppScan Enterprise

8

Multiple Report Levels

DashboardsReport Pack SummariesDetailed ReportsAbout this… Reports

Page 9: Introduction to AppScan Enterprise

9

Report CategoriesInventory Reports

Broken LinksHostsPagesetc.

Security ReportsApplication Security Issues Infrastructure Security Issues Remediation Tasks Security Risk Assessment

Compliance ReportsSafe Harbour Sarbanes-Oxley Act (SOX) Visa CISPetc.

Page 10: Introduction to AppScan Enterprise

10

User Roles and Access Permissions

Security Manager

Pen Tester

Developer

Compliance Officer

AppScan Enterprise

Control access to informationAssign user rolesSpecify what applications a user can scanSpecify what types of tests a user can perform

Page 11: Introduction to AppScan Enterprise

11

What does AppScan Enterprise test for?

Network

Operating System

Applications

Database

Web Server

Web Server Configuration

Third-party Components

Web Applications

AppScanEnterprise

Page 12: Introduction to AppScan Enterprise

12

How does AppScan Enterprise work?

Traverses a web applicationApproaches an application as a black-boxTests by sending modified HTTP requestsThousands of tests for identifying hundreds of vulnerabilities

HTTP Request

HTTP Response WebServers

Application

Databases

Web Application

Page 13: Introduction to AppScan Enterprise

13

AppScan Enterprise Architecture

Clients AppScan Enterprise Target Sites

Page 14: Introduction to AppScan Enterprise

14

TerminologyContent Scan Job

Infrastructure Scan Job

Import Job

Report Pack

Dashboard

Folder

Page 15: Introduction to AppScan Enterprise

15

Jobs, Report Packs, Reports & Dashboards

Job4Infrastructure

Scan

Job2Security

Data Import

Job1Security

Scan

Global Scan Data

Job3Security

Scan

Reports

Report Pack 1

Report Pack 2

Report Pack 3

Dashboard 1

Dashboard 2

Page 16: Introduction to AppScan Enterprise

16

Web-Based User Interface

Enter your user name and password

Navigate to AppScan Enterprise, e.g.

http://aseserver/appscan

Page 17: Introduction to AppScan Enterprise

17

Quick Scan vs. Advanced ViewThe UI mode is set in the user’s propertiesQuick Scan View

Makes it easier to create a scan by abstracting complexityLeverages scan templates created by the administratorReduces the scan configuration timeSuitable for developers, QA specialists who create ad-hoc scans

Advanced ViewExposes all scan optionsSuitable for administrators and advanced users