Home > Security News > A hodgepodge approach to verifying Web users
Security News:
EMAIL THIS

A hodgepodge approach to verifying Web users

By Bill Brenner
05 Jul 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

In this age of data thievery, most security experts will tell you strong authentication is a must -- especially when the company offers Web-based services. But if a recent survey is any indication, developers are struggling to adopt methods that are consistent across the enterprise.

A lack of IT staff and support from the business side of the operation is one reason, said Joe McKendrick, an analyst with Santa Cruz, Calif.-based research firm Evans Data Corp. Mergers and acquisitions are another factor. As companies merge, a lot of legacy systems come along for the ride, making it harder to develop consistent authentication procedures.

"A majority of companies are
Related stories

Former National Security Agency director says authentication is critic

 

Is single sign-on ready for prime time?

not sharing their Web services with other business units across the enterprise," McKendrick said. "This is a result of not having enough IT talent with Web services skills, as well as management buy-in to the concept. Web services and SOA [service-oriented architecture] need skilled evangelists to help drive the adoption of the technology forward. This isn't happening yet."

McKendrick and a team of Evans Data analysts surveyed more than 400 Web service developers in June and found they are more likely to rely on their own custom-developed authentication methods than industry standards like the Secure Sockets Layer [SSL] or the Simple Object Access Protocol [SOAP].

Almost one in four developers [23%] said they devised their own security mechanisms to protect online transactions compared to 22% who use SSL and 9% who use SOAP. A quarter of respondents acknowledged authentication remains the thorniest aspect of their Web services security plans. Eight of 10 respondents [79%] said they encounter organizational resistance when they try to move their efforts forward. One out of five respondents [19%] said they can't find enough IT talent versed in Web services development to get the job done. Meanwhile:

  • 55% of respondents said Web services are being shared with only one other business unit within the company and in some cases there's no sharing at all. Only 6.5% said they are sharing Web services across more than 20 business units.
  • 68% of developers have either adopted SOA or are in the process of doing so. But they acknowledged actual implementations are still few and far between.

'All this stuff lying around'
When you consider all the mergers and acquisitions of recent years, McKendrick said the findings aren't all that surprising. When one company acquires another, it absorbs an array of technology, including authentication devices.

"In a typical situation the IT staff is pretty heterogeneous, using a mixture of platforms, systems and architecture under a single roof," he said. "A larger company may have several types of systems for the production, the supply chain, the financial division or the inventory division. You may have different companies with separate IT staffs who have worked on separate [authentication] systems for their own areas. So with mergers and acquisitions you get all this stuff lying around."

For companies looking to adopt more consistent authentication methods, McKendrick said involvement from the business side of the enterprise is a must. "Web services and SOA touch so many parts of the organization today that it's not just a matter for IT anymore," he said. "It's about rebuilding the business process. So you need people from the business side involved."

Making it work for now
The hodgepodge approach may not be all bad, McKendrick said. With the advancement of single sign-on techniques like federated identity management, it's possible for companies to make do with diverse systems.

"If you look at what the Web services standards committees are saying, there's a push for things like federated identity management, where with one token you can end the need to be re-authenticated every time you have to pull data from a new system," he said.

"A token is like a driver's license," he added. "If you have a driver's license from Massachusetts and you're driving to Florida, police in every state you pass through aren't going to stop you and force you to get a new license for their state. With one license you're able to drive through other states."

It's similar with a token, he said, adding, "The federated identity management approach might be one way to make companies function with different authentication systems."

Tags: Web Services Security and SOA SecurityEnterprise Single Sign-On (SSO)PKI and Digital CertificatesSecurity Token and Smart Card TechnologyVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Web Services Security and SOA Security
Security testing firm uncovers XML vulnerabilities
Cryptographers say cloud computing can be secured
Information security book excerpts and reviews
Will cloud computing and virtualization save the day?
MySpace, Facebook ignoring basic principles of security
Kaminsky: DNS flaw capable of attacks on many fronts
Kaminsky on DNS rebinding attacks, hacking techniques
Which operating system can best secure an FTP site?
IBM's Watchfire halts network research, focuses on Web apps
How does identity propagation work?

Enterprise Single Sign-On (SSO)
How to log in to multiple servers with federated single sign-on (SSO)
Security on a budget: How to make the most of authentication tools
Best Identity and Access Management Products
Changing times for identity management
Kerberos configuration as an authentication system for single sign-on
How to use single sign-on for Web access control to prevent malware
Learn about enterprise strategy for server virtualization single sign-on
Enterprise single sign-on: Easing the authentication process
Exploring authentication methods: How to develop secure systems
User provisioning and SSO for PeopleSoft- and Unix-based products
Enterprise Single Sign-On (SSO) Research

PKI and Digital Certificates
Best Authentication Products
DoD urges less network anonymity, more PKI use
Researchers to demonstrate new EV SSL man-in-the-middle hacks
Portable security storage device could replace OTP devices
What is most misunderstood about EV SSL certificates?
VeriSign addresses MD5 flaw
Rogue digital certificates strike blow to Internet security
Can any firm or organization get a digital signature certificate?
How to obtain a digital certificate for a server
PKI and digital certificates: Security, authentication and implementation
PKI and Digital Certificates Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
single sign-on  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts