More Options, More Vulnerable

BARTLESVILLE, Okla. — Online crooks wielding SQL-injections have become more interested in 66 FCU as it works to expand its website business, with features such as membership enrollment.

Processing Content

"We're also seeing a lot of bot scans," in addition to SQL-injection attempts, said Clint Brown, programmer at the $400-million CU. "People are phishing to see where we as programmers have put down our guard."

Vigilant programmers and solid programming code aren't enough to keep thieves at bay, said Trenton South, who is also a programmer at the CU. "You can't anticipate everything an attacker will think of. You need someone to help you whose sole focus is to filter traffic for you."

Keeping Watch

Thus, a Web application firewall keeps watch over the CU's sites, blocking or sending alerts on threats. "We're monitoring Web traffic so that we're aware of attacks on our website databases," explained South. "We're introducing a lot more interactivity and exchanging sensitive information. We had to think twice about how to protect that info on both sides over HTTPS."

66 FCU started running the SecureSphere Web Application Firewall in March as part of a decision to host its website in-house. Now, the CU has more control over the amount and type of interactions with members, South said. SecureSphere is offered by Redwood Shores, Calif.-based Imperva.

Along with this newfound interactivity comes the particulary pervasive threat of SQL injection, he continued. Often automatically performed by software robots, an SQL injection is an attack on a Web application database, such as one that supports membership enrollment or Internet banking transactions. Cyber thieves can program the "bots" to identify security vulnerabilities in an application and then steal non-public financial information.

"We had a network firewall and a company performing baseline IDS, but no application firewall," South said. "It became apparent that we needed to protect ourselves and our members with that extra layer. We needed to be able to automatically block or send outbound traffic."

SecureSphere protects Web applications from attacks such as SQL injections, Cross Site Scripting, session hijacking, buffer overflow and cooking tampering, in part by validating Internet protocol addresses. The firewall can prevent non-public information from leaving on outbound network traffic-something that is prone to happen even when a network rejects a malicious SQL query, said South: the network can pass along an error message that inadvertently contains sensitive information. "Imperva stops that," he said.

SecureSphere's Dynamic Profiling feature automatically "learns" the structure of Web applications and how they are expected to be used. Over time, the technology applies what it has learned by instantly recognizing a change to an application and recommending a corresponding security policy. "Without Dynamic Profiling, manageability of an application firewall is a lot more complex," said Mark Kraynak, VP-marketing, Imperva.

Some argue that application firewalls aren't the cure for SQL injections as they are subject to false positives and don't address the root of the problem: programming code vulnerabilities. Instead, programmers should manually review and fix broken code.

Supplementing The Firewall

Kraynak agreed CUs should be looking at coding practices as a supplement to a firewall, and South said he can sort through security alerts using SecureSphere's real-time dashboard and create graphical reports — "we can see incidents that tell us if we need to tweak our code."

False positives are negligible, said South. "That's only happened once, so I would say false positives are no problem at all."

66 FCU hopes to use its newfound website interactivity first to offer online membership enrollment, added South. In the past, interacting with members and potential members online was limited to e-mail communications.


For reprint and licensing requests for this article, click here.
Technology
MORE FROM AMERICAN BANKER
Load More