DZone
Thanks for visiting DZone today,
Edit Profile
  • Manage Email Subscriptions
  • How to Post to DZone
  • Article Submission Guidelines
Sign Out View Profile
  • Post an Article
  • Manage My Drafts
Over 2 million developers have joined DZone.
Log In / Join
Refcards Trend Reports Events Over 2 million developers have joined DZone. Join Today! Thanks for visiting DZone today,
Edit Profile Manage Email Subscriptions Moderation Admin Console How to Post to DZone Article Submission Guidelines
View Profile
Sign Out
Refcards
Trend Reports
Events
Zones
Culture and Methodologies Agile Career Development Methodologies Team Management
Data Engineering AI/ML Big Data Data Databases IoT
Software Design and Architecture Cloud Architecture Containers Integration Microservices Performance Security
Coding Frameworks Java JavaScript Languages Tools
Testing, Deployment, and Maintenance Deployment DevOps and CI/CD Maintenance Monitoring and Observability Testing, Tools, and Frameworks
Partner Zones AWS Cloud
by AWS Developer Relations
Culture and Methodologies
Agile Career Development Methodologies Team Management
Data Engineering
AI/ML Big Data Data Databases IoT
Software Design and Architecture
Cloud Architecture Containers Integration Microservices Performance Security
Coding
Frameworks Java JavaScript Languages Tools
Testing, Deployment, and Maintenance
Deployment DevOps and CI/CD Maintenance Monitoring and Observability Testing, Tools, and Frameworks
Partner Zones
AWS Cloud
by AWS Developer Relations
The Latest "Software Integration: The Intersection of APIs, Microservices, and Cloud-Based Systems" Trend Report
Get the report
  1. DZone
  2. Software Design and Architecture
  3. Security
  4. [DZone Research] Vulnerabilities/Attacks Developers Face

[DZone Research] Vulnerabilities/Attacks Developers Face

We take a look at some data from the 2018 DZone Security Survey, focusing on vulnerabilities and attacks developers often face.

Jordan Baker user avatar by
Jordan Baker
·
Sep. 24, 18 · Analysis
Like (2)
Save
Tweet
Share
2.75K Views

Join the DZone community and get the full member experience.

Join For Free

This article is part of the Key Research Findings from the 2018 DZone Guide to Security: Defending Your Code.

Introduction

Over the past 12 months, the IT industry has witnessed several large-scale attacks, such as the hacking of Equifax and instances of ransomware like NotPetya, and vulnerabilities exploited, like the infamous struts vulnerability that eventually led to the Equifax hack. But do the realities on the ground match the sensational headlines?

Threats: SQLi, Phishing, and DDoS

We asked our survey-takers what threats have most concerned their organization over the past year. Despite the flabbergastingly bad past year for cybersecurity, our respondents’ answers remained virtually identical to those reported in the 2017 DZone Security Survey. 52% reported phishing as their organization’s biggest concern, 46% said SQL injection (SQLi), 39% said DDoS, 36% reported ransomware, and 31% said cross-site scripting (XSS) attacks. Even when we compare this data to our two main developer verticals (web app and enterprise business app developers), the numbers regarding threats that concern their organizations don’t undergo any statistically significant changes.

Something interesting does pop out, however, when we compare the threats that most concern organizations and the types of vulnerabilities developers encounter most often. While most vulnerabilities our respondents reported encountering were not that surprising, such as authentication + session management (43%) and cross-site scripting (40%), unvalidated redirects + forwards were selected by a rather small number of respondents. Unvalidated redirects and forwards was the eighth most common vulnerability from the OWASP Top 10 faced by respondents, with 23% of survey-takers reporting to have had issues with this vulnerability. The low position of unvalidated redirects + forwards is surprising given the role this vulnerability plays in the spread of phishing attacks, which was the most prominent organizational security concern among our respondents. Unvalidated redirects + forwards are, in fact, the programmatic mechanism for driving users to a seemingly innocuous, but malicious site (Paul Ionescu, “The 10 Most Common Application Attacks in Action,” SecurityIntelligence by IBM). Thus, despite a low instance of phishing attacks over the past year, it seems organizations are bracing for this type of cyber attack to increase in frequency.

Given that 39% of respondents reported having faced issues with denial-of-service attacks, let’s quickly go over the data regarding this common type of attack. Having to deal with many high-resource connections proved by far the most common instance of DDoS attacks faced by survey takers, with 54% of respondents having faced this issue. The second most common DDoS faced was requests for large files (30%). No other form of DDoS attack registered more than 18% of respondents’ votes.

Conclusion: Vulnerabilities' Effects on Deployments

So, how do these attacks and vulnerabilities affect respondents’ ability to deploy their software? 43% reported that security analysis and vulnerability-fixing had a medium impact, 36% reported a low impact, and 13% reported a high impact. These numbers are, again, nearly identical to last year’s DZone Security Survey results. But, as we discussed in another article, security concerns do not always waylay deployments. 

This article is part of the Key Research Findings from the 2018 DZone Guide to Security: Defending Your Code.

DZone dev Vulnerability

Opinions expressed by DZone contributors are their own.

Popular on DZone

  • Beyond Coding: The 5 Must-Have Skills to Have If You Want to Become a Senior Programmer
  • Navigating Progressive Delivery: Feature Flag Debugging Common Challenges and Effective Resolution
  • When Should We Move to Microservices?
  • Use Golang for Data Processing With Amazon Kinesis and AWS Lambda

Comments

Partner Resources

X

ABOUT US

  • About DZone
  • Send feedback
  • Careers
  • Sitemap

ADVERTISE

  • Advertise with DZone

CONTRIBUTE ON DZONE

  • Article Submission Guidelines
  • Become a Contributor
  • Visit the Writers' Zone

LEGAL

  • Terms of Service
  • Privacy Policy

CONTACT US

  • 600 Park Offices Drive
  • Suite 300
  • Durham, NC 27709
  • support@dzone.com
  • +1 (919) 678-0300

Let's be friends: