Semanticspace.com
Home Quicklinks Contact Us
Home Quick Links
gobuton
 
About Us Solutions Industries Products Careers News Partners Resources
 
End-to-End Reliable Services for your Quality needs
Quality Icon Quality Assurance
Services
Processes
Engagement Model
Security Testing
 
Product Engineering
Package
Enterprise
 
Request for demo
 
Request Soluition Information
 
From banking and brokerage to shopping, customers increasingly interact with a firm directly through Web Applications. For years, IT organizations have invested in web application security testing, but Web applications are only part of the story, the reliability of the infrastructure they run on is just as important. Most firms spend far less on Web Application Security testing than they actually should.

SemanticSpace's Web Application Security Assessment (WASA) quickly brings to light weaknesses and points directly to corrective actions needed.
Web Application Security Assessment
SemanticSpace's WASA is a unique process that helps your organization to identify the risks associated with exposure to the Internet. Semantic Space web application security team provides comprehensive testing solutions with appropriate countermeasures to mitigate the risks and helps your application to be less vulnerable and more secure.
Impacts
Technical Vulnerabilities Business Risks
  Arrow URL Manipulation Arrow Personal information modification
  Arrow SQL Injection Arrow Pricelist modification
  Arrow Cross Site Scripting Arrow User impersonation
  Arrow Weak Session Tracking Arrow Unauthorized funds transfer to accounts
  Arrow Passwords in Memory Arrow Privilege escalation of use account
  Arrow Buffer Overflows Arrow Wrong Transactions
  Arrow Configuration Issues Arrow Unauthorized logins
  Arrow Web server configuration Arrow Breach of customer trust
  Arrow Invalidated Inputs    
  Arrow Session Hijacking    
  Arrow Credential management    
Offerings and Technologies
Wasa Services
Highlights
  Arrow Semantic Space follows a combinational risk based approach for security testing i.e. 80% manual testing and 20% automated (tool) testing
  Arrow Comprehensive report with snapshots of the results obtained
  Arrow Highest security clearance of consultants at all levels
  Arrow All solutions follow easy to understand and easy to implement model
Benefits
  Arrow Timely and valuable application vulnerability information to assist in developing proactive protection measures
  Arrow Protection of business and information assets against hacking and loss of valuable data
  Arrow Assistance in increase of customer confidence and trust on the application
  Arrow Mitigation of loss of customer's confidential information
  Arrow Overcoming legal hassles due to failure of the application security
  Arrow Reduced cost of recovery and fixes due to loss of information
Web Application Security Testing > Production  
Need:
 
  Arrow Web Application Security testing is used , from a black box perspective, when the tester has limited knowledge of the system under test or when access to source code is not available. Black box testing is normally associated with activities that occur during the pre-deployment test phase (system test) or on a periodic basis after the system has been deployed i.e. in Production
Arrow Web Application Security tests are conducted to identify and resolve potential security vulnerabilities, to periodically identify and resolve security issues within deployed systems. From a business perspective, organizations conduct Web Application security assessments to conform to regulatory requirements, protect confidential and proprietary information, and protect the organization’s brand and reputation
Production
Benefits:
 
  Arrow Test any Application with any technology for security weaknesses for live applications such as a Website ex: www.semanticspace.com
Arrow Provide appropriate recommendations and solutions without looking into source code using "Code Snippets"
Arrow Target Segments: Enterprises, Ecommerce Web Sites, Development Houses and Portals
Web Application Security Testing > Design level
Need:
Arrow Secure web application design is not product-specific and is helpful in securely designing and implementing any Web application, regardless of the platform
Arrow Restrictions imposed by infrastructure security are identified  
Arrow The web application security assessment in the design level recognizes and accommodates Design
 
  • Restrictions imposed by hosting environments (including application isolation requirements)
  • The target environment code-access-security trust level is known, the design identifies the deployment infrastructure requirements and the deployment configuration of the application
  • Domain structures, remote application servers, and database servers are identified, clustering requirements
  • The application configuration maintenance points (such as what needs to be configured and what tools are available for an IDC admin)
  • Secure communication features provided by the platform and the application are known
  • The design identifies the certificate authority (CA) to be used by the site to support SSL
Arrow The design addresses Web farm considerations (including session state management, machine specific encryption keys, Secure Sockets Layer (SSL), certificate deployment issues, and roaming profiles) and addresses the required scalability and performance criteria and so the need for an assessment in this level
Benefits:
  Arrow Semantic Space testing team reviews the design of your application as it relates to the target deployment environment
Arrow We consider the constraints imposed by the underlying infrastructure-layer security and the operational practices in use
Arrow We review the security approach that was used for critical areas of your application by focusing on the set of categories that have the most impact on security
Arrow We review the logical layers of your application, and evaluate your security choices within your presentation, business, and data access logic
Arrow We recommend solutions in the entire life cycle as an ongoing effort
Arrow Target segments: Development Houses
Web Application Security Testing > Pre-Deployment
Need:
Arrow It is estimated that it can cost twenty times more to fix a coding problem that is discovered after the product has been released than it would have cost if discovered during the system test phase i.e. during pre-deployment phase Pre deployment
Arrow Considering the personnel and processes required to address a security issue after deployment, help-desk personnel that are required to take trouble calls from the customer; support engineers who are required to confirm and diagnose the problem; developers who are needed to implement code fixes; QA personnel who are called to perform system regression tests; and managers to oversee the entire process, it is prudent to perform application security testing in the pre-deployment phase itself
Arrow Additional expenses are to be considered, such as those associated with patch distribution and the maintenance of multiple concurrently deployed versions
Arrow Additionally, serious post-deployment software vulnerability may result in potential business issues, such as damage to brand or company reputation, and potential legal liability issues
Arrow Application security test tools can be used during the system test phase to identify and address the issues mentioned above, reduce system development costs, and reduce business risks associated with company reputation and liability
Benefits:
Arrow We at Semantic Space identify implementation errors that were not discovered during code reviews, unit tests, or security white box tests
Arrow We discover potential security issues resulting from boundary conditions that were difficult to identify and understand during the design and implementation phases
Arrow We uncover security issues resulting from incorrect product builds (e.g., old or missing modules/files)
Arrow We also detect security issues that arise as a result of interaction with underlying environment (e.g., improper configuration files, unhardened OS and applications)
Arrow Semantic Space tests security weaknesses in applications pre-production (beta) stage
Arrow We provide solutions and recommendations according to the industry known standards – Open Web Application Security Project. www.owasp.org
Arrow Our target Segments: Development Houses
Web Application Security Testing > Code Review
Need:
  Arrow Security code reviews focus on identifying insecure coding techniques and vulnerabilities that could lead to security issues Code Review
Arrow The cost to repair web application security vulnerability during the early stages of source code program development is about 2% of the cost to repair that same flaw in a production environment. The repair cost does not take into account the potential costs associated with the exploit of security vulnerabilities
Arrow The review goal is to identify as many potential security vulnerabilities as possible before the code is deployed
Arrow Removing a defect after software is operational can cost between two and five times as much as correcting the error within the development and QA process
Arrow If 50 percent of software vulnerabilities were removed prior to production use, enterprise management costs would be reduced by 75 percent each
Arrow Defect correction during code and unit tests can reduce the cost impact by an additional factor of between 3 and 20
Benefits:
  Arrow Unlike the surface-style testing in our code review our consultants walk through code line-by-line, looking for flaws that would allow an attacker to take control of your application
Arrow Our approach allows us to take a much more holistic view of your application and identify vulnerabilities and exposure points that would have otherwise been hidden by cursory assessments
Arrow We provide a targeted, cost-effective code review to identify areas in the code that can be improved for greater security
Arrow Test the source code of the mentioned technologies for security flaws and recommend appropriate alternates / remedies to plug in the weaknesses at development stage
Arrow Target Segment : Development Houses (In house / External)
Arrow Our code review helps:
 
  • Greatly reduce false positives identified through alternate testing methods
  • You to reduce development costs
  • Us to understand your software development life cycle maturity
  © Copyright SemanticSpace Technologies. 2007 Disclaimer | Privacy Policy