Varsha Saraogi (VS): Why are airports and airline companies becoming more vulnerable to cyber attack?
Paul Farrington (PF): The consequence of a cyberattack affects an airline and has a knock-on effect on passengers.When there is a cybersecurity incident its going to get media attention and rise to the top in the news agenda.
In our State of Software Security Report published at the end of 2018, there is an excerpt for industries in infrastructure which includes the aviation industry. It found that airports did a good job in closing out the flaws or potential vulnerabilities that are found in software within the first hundred days and, they actually beat the global averages across many different industries. So in that respect, evidence suggests that aviation companies do take their responsibility seriously in addressing the potential security risk.
However, what we do see with industries relating to infrastructure is that after a period of time things remained unfixed. After 125 days they start to deteriorate and become more delinquent. Complacency does set in and thats where greater attention should actually be paid to ensure that across the software development lifecycle, developers are not just fixing the complex and sophisticated risks but actually addressing things like cross-site scripting, and preventing issues which could allow an attacker to penetrate a system.
VS: Why are airlines and airports so unprepared?
PF: Over the last 20 years an awful lot of attention and quite rightly has been paid to physical security, and ensuring that we have the tech in place to prevent a physical attack. Now, we need to ensure that were giving due attention and focus to preventing cybersecurity attacks. The Department of Transport has a five-year plan and a cybersecurity strategy which talks about all the measures that need to be in place.
The government along with the regulatory bodies in the UK, CAA and in the US, FAA are taking the responsibility seriously. But I think we also need to ensure that across the board, not just for the physical security but in software, were getting systems up to scratch. In our State of Software Security Report, [we found that] in the aviation industry, unfortunately, most software applications failed common security standards.
There is a security standard called the open web application security project and it provides a checklist of vulnerabilities the security bugs we really dont want to see in your software application. Only one in four applications that were tested against the standard passed the first inspection. The majority of those applications failed. Whether theyre on the ground or in flight, its crucial that we do a better job of ensuring that the systems which people rely on are safe and secure and the attackers dont have any bail to breach.
VS: How does Veracodes Greenlight software work?
PF: [Chris Wysopal and Christien Rioux created] a security tool, which when they co-founded Veracode became known as static analysis. Think of this as an MRI scanner, where youre looking deep into the tissue that makes up the software for the potential weaknesses that an attacker could actually exploit to damage the system. But in the early days, static analysis was looking at the entire application which can take time to address the different potential weaknesses.
In the culture now, with the DevOps sentiment analysis in the last decade, developers are demanding faster analysis techniques because theyre under pressure to ensure that theyre producing software at a higher velocity. Greenlight actually uses the static analysis techniques, but rather than just looking at the entire application, it is able to look at the incremental and analyse the things that have just been changed in a file. Greenlight is able to give developers feedback on the code theyve created within seconds. The reason why we call it Greenlight actually is when they write a secure code, they get a green light, as an affirmation that what theyve just done is correct.
Where security vulnerabilities have been spotted in the code, the software will actually highlight it and say this is a potential security vulnerability, or a flaw has been found and this needs to be addressed in the following ways. Developers can then make the changes when they get the results in seconds. If you compare that to receiving results an hour or a week later, the focus is lost and the incentive for the software engineer to actually address the issues are less.
VS: How can technology help airports combat cyberattacks?
PF: There is indeed too much emphasis on using clever human beings to find issues that automation would do ten times faster. So we need to make sure were getting that balance correct.
Trying to tackle the security problem with human beings wont scale because there are only so many security experts in the world. In fact in 2019 today, there are more than two million vacancies across the world for cybersecurity experts and manual penetration testers are a part of that deficit of people who are qualified to perform analysis.
VS: Do you think human decision making can be balanced with automation?
PF: Market pressures will move more towards automation whether youre an airport or an airline company. There needs to be sufficient emphasis from the government and from the regulators to address this issue.
In practical terms, with a combination of using automation and the right tools, we need to ensure that we have security experts in DevOps teams in companies for embedding security across the organisation. As we call them DevSecOps, which is an evolution of DevOps, and they ensure that security is part of the entire conversation.
In terms of automation, when software gets committed back to the repository, what we can do is automate the scanning of that software. So without a developer needing to press a button, the software is scanned for vulnerabilities and those results are sent to the development team. In case of a functional defect, a ticket gets created and added to the systems backlog which is a list of security issues that need to be addressed.
By doing so, it becomes just part of the normal hygiene of how software gets created and maintained. Having that as part of a company of creating code using automation and having a blinking light on the developers desktop when theres a security issue means that without any undue coercing or disincentives to the developer, the software engineers address issues as they crop up as part of just the everyday working and this ensures that the software becomes more secure.
VS: How is technology like this likely to progress in the future?
PF: If you can leverage automation it gives you greater time to think about things like threat modelling.
Through the process of threat modelling, one can pre-empt the kind of potential attack and could subvert the application even before code is being written, ensuring that the software is designed in such a way that makes it really extremely hard for an attacker to take control.
Additionally, the way software gets created today is quite different from 20 years ago as the majority of it is comprised of open source components code written outside your organisation. The problem with using open source software is that just like your own there is a tendency for it to be insecure. If it hasnt been tested then there is a significant chance that vulnerabilities will exist in that software, so ensuring that were using open source components that are secure is really important. Critically, around 80 to 90% of companies use open-source software many of which up until now have been unaware of how software is being created.
Going forward, the emphasis needs to be placed on how software is being brought in. What were talking about is a software supply chain because thats of crucial importance to aviation.
Enter your details here to receive your free whitepaper.
Close survey
Close
View original post here:
Q&A: Veracode on automation and how to tackle cyber attacks in aviation - Airport Technology
- Automation Personnel Services - Temporary Staffing ... [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation | Define Automation at Dictionary.com [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation | Definition of automation by Merriam-Webster [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation | The Car Company Tycoon Game [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation - Wikipedia, the free encyclopedia [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation - Cloud process & workflow automation | Microsoft ... [Last Updated On: June 29th, 2016] [Originally Added On: June 29th, 2016]
- Riverside Automation - Machine Controls [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Automation: The Car Company Tycoon Game Windows - Mod DB [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- System Integration | Industrial Automation [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- WinAutomation - Smart Macro Recorder, Web Automation ... [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Automation Solutions - Home [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- The Automation Conference [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Rohtek Automation [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- JL Automation, LLC | Home Automation, A/V Automation [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Four fundamentals of workplace automation | McKinsey & Company [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- Leviton Security & Home Automation [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- EVA Automation [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- News | Automation | The Car Company Tycoon Game [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- Automation - The Car Company Tycoon Game on Steam [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- Test automation - Wikipedia, the free encyclopedia [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- Job Seekers - Automation Personnel Services [Last Updated On: October 8th, 2016] [Originally Added On: October 8th, 2016]
- Custom Automation & Machine Design | Automation GT [Last Updated On: October 31st, 2016] [Originally Added On: October 31st, 2016]
- iAutomation [Last Updated On: October 31st, 2016] [Originally Added On: October 31st, 2016]
- Test automation - Wikipedia [Last Updated On: November 16th, 2016] [Originally Added On: November 16th, 2016]
- Automation - Official Site [Last Updated On: November 19th, 2016] [Originally Added On: November 19th, 2016]
- Beckhoff Automation - Wikipedia [Last Updated On: November 21st, 2016] [Originally Added On: November 21st, 2016]
- Automation - Security Hyperstore [Last Updated On: November 21st, 2016] [Originally Added On: November 21st, 2016]
- IT Automation - BMC [Last Updated On: November 29th, 2016] [Originally Added On: November 29th, 2016]
- ID Automation [Last Updated On: November 29th, 2016] [Originally Added On: November 29th, 2016]
- The Best Home Automation Systems of 2016 | Top Ten Reviews [Last Updated On: December 24th, 2016] [Originally Added On: December 24th, 2016]
- What is Home Automation? | Home Automation Systems [Last Updated On: December 24th, 2016] [Originally Added On: December 24th, 2016]
- Beyond Automation - hbr.org [Last Updated On: December 25th, 2016] [Originally Added On: December 25th, 2016]
- Build automation - Wikipedia [Last Updated On: December 26th, 2016] [Originally Added On: December 26th, 2016]
- Home automation - Wikipedia [Last Updated On: January 10th, 2017] [Originally Added On: January 10th, 2017]
- Automation | Food Engineering [Last Updated On: January 13th, 2017] [Originally Added On: January 13th, 2017]
- Home Automation - Enerwave Home Automation [Last Updated On: January 14th, 2017] [Originally Added On: January 14th, 2017]
- Automation - DESHAZO [Last Updated On: January 14th, 2017] [Originally Added On: January 14th, 2017]
- Robots, Automation, EOAT, Grippers, Conveyors, Guarding [Last Updated On: January 26th, 2017] [Originally Added On: January 26th, 2017]
- Werner Electric | Automation [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Automationtechies | Automation Engineering Recruiting [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Automation - Mazak Corporation [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Automation | Technologies | Systems | Integrator ... [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Test Automation Services for Development of Regression ... [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Carlo Gavazzi Automation Components [Last Updated On: January 30th, 2017] [Originally Added On: January 30th, 2017]
- UI Automation Overview - msdn.microsoft.com [Last Updated On: February 5th, 2017] [Originally Added On: February 5th, 2017]
- New telecom transformation goals require service automation - TechTarget [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Global Hazardous Waste Handling Automation Market: By Products ... - Business Wire (press release) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- 2M Automation wins IoT support from Schneider - Electronics EETimes (registration) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Futures Shaped by Automation and Catastrophe: Peter Frase on Capitalism's Endgame - Truth-Out [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Automation expected to displace insurance underwriters, real estate brokers - CIO Dive [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Automation, robots could replace 250000 public sector workers in the next 15 years - Computer Business Review [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Design Automation Conference - Business Wire (press release) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- The Perks Of Automation And The Risks: Why To Think Twice About Getting Into That Driverless Uber - Forbes [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Lib Dems Should Embrace Automation of the Workforce - Liberal Democrat Voice [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Voices Reinventing enterprise finance by overhauling AP automation - Accounting Today [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How Accountants Can Use Automation Their Advantage - Accountingweb.com (blog) [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- DFLabs Launches the First Security Automation and Orchestration Platform based Upon Supervised Active Intelligence - Business Wire (press release) [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- QAD Automation Solutions is Honda Approved - Yahoo Finance [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- VIDEO: Going Big on Automation in a Small Footprint Facility - ENGINEERING.com [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Building a better model of human-automation interaction - Phys.Org [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- AlixPartners examines automation in manufacturing and logistics management - Logistics Management [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Report: Test automation is increasing - SD Times - SDTimes.com [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Automation is the unavoidable future of the economy - The Daily Cougar [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- GM's Cruise Automation Is Testing An App to Order Self-Driving ... - Fortune [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Speeders beware: Legislation would allow automation crackdown ... - SFGate [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Orbita Ingenieria: New Age Terminal Automation - Port Technology International [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- A Sharper Focus on the Edge - Automation World [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Rockwell Automation Surged 10% in January as Growth Picked Up Steam - Motley Fool [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Most people are optimistic about workplace automation, social data suggests - ZDNet [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Improving Behavior Through Automation of Vehicle Systems - School Transportation News (blog) [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- 'We employ insane levels of automation' Kris Canekeratne - Times of India [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Why Don't We See More Automation in Federal Networks? - Nextgov [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Technobabble: Automation and the modern worker - CIO Dive [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Readers Write (Feb. 12): The moose population; jobs, start-ups and automation; diversity in the funny pages - Minneapolis Star Tribune [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Automation Nightmare: Philosopher Warns We Are Creating a World Without Consciousness - Big Think [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Automation can replace bureaucrats and save taxpayers money - Hot Air [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Automation can revitalize the US workforce - Fox News [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- TigerStop hopes to ride automation to new heights - The Columbian [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Hexadite Unveils Custom Playbooks Following One Millionth Automated Cybersecurity Investigation - Yahoo Finance [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- NEC updates postal automation system for Hongkong Post - ETCIO.com [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]