Skip to main content

By clicking Submit, you agree to the developerWorks terms of use.

The first time you sign into developerWorks, a profile is created for you. Select information in your profile (name, country/region, and company) is displayed to the public and will accompany any content you post. You may update your IBM account at any time.

All information submitted is secure.

  • Close [x]

The first time you sign in to developerWorks, a profile is created for you, so you need to choose a display name. Your display name accompanies the content you post on developerworks.

Please choose a display name between 3-31 characters. Your display name must be unique in the developerWorks community and should not be your email address for privacy reasons.

By clicking Submit, you agree to the developerWorks terms of use.

All information submitted is secure.

  • Close [x]

Secure web and cloud applications

How to address security vulnerabilities

Paul Ionescu (pionescu@ca.ibm.com), Secure Engineering Program Coordinator for IBM Security Systems, IBM
Photo of Paul Ionescu
Paul Ionescu leads the secure engineering program for the IBM Security Systems division. He is also part of the AppScan Research and Development team. Since he joined IBM in 2007 he worked in several areas of the application security business including support, technical sales, technical enablement and development.
Robin Langford, developerWorks Managing Editor, IBM
Photo of Robin Langford
Robin Langford, developerWorks managing editor, divides her time between rich media production and IBM product trials. Before developerWorks, she wrote for, edited, and managed information for IBM software and hardware in development. Her degrees are in English from Auburn University in Auburn, AL, and Technical writing from Rensselaer Polytechnic Institute in Troy, NY.
Scott Laningham (scottla@us.ibm.com), developerWorks Podcast Editor, IBM
Scott Laningham
Scott Laningham, host of developerWorks podcasts, was previously editor of developerWorks newsletters. Prior to IBM, he was an award-winning reporter and director for news programming featured on Public Radio International, a freelance writer for the American Communications Foundation and CBS Radio, and a songwriter/musician.
Kane Scarlett, developerWorks Editor, Freelance Consultant
Kane Scarlett
Kane Scarlett is a technology journalist/analyst with 20 years in the business, working for such publishers as National Geographic, Population Reference Bureau, Miller Freeman, and IDG, and managing, editing, and writing for such august journals as JavaWorld, LinuxWorld, and of course, developerWorks.

Summary:  Application vulnerabilities are often the primary entry point for security breaches. Explore common weaknesses in applications, typical web attacks, and learn the key secure engineering measures to put in place.

Date:  26 Sep 2012
Level:  Introductory

Activity:  4720 views
Comments:  

You can listen to the audio version, read the transcript, or view the video.

Security expert Paul Ionescu addresses the basic issues, concerns, challenges, and solutions to making cloud and web applications secure. Learn the common vulnerabilities, trends in web attacks, and the key practices to build into the software development cycle.

To learn more about the threats, practices, and resources available to help you build secure applications, check out these resources:

developerWorks Security: Pragmatic, intelligent, risk-based practices

Explore the many security-related resources now available on the developerWorks Security page. Find links to technical content, the security community, security practices, and the IBM products that help enable secure applications.

The General Manager of IBM Security Systems, Brendan Hannigan, speaks often on the topic of security, especially as it relates to web technologies. For more information on technology security from the enterprise perspective, watch Brendan's videos:

Also, try this expert advice:

Finally, you can explore IBM's solution, IBM Security AppScan family, a market-leading portfolio of application security and risk management solutions for mobile and web applications.


Resources

Biographies

Photo of Paul Ionescu

Paul Ionescu leads the secure engineering program for the IBM Security Systems division. He is also part of the AppScan Research and Development team. Since he joined IBM in 2007 he worked in several areas of the application security business including support, technical sales, technical enablement and development.

Photo of Robin Langford

Robin Langford, developerWorks managing editor, divides her time between rich media production and IBM product trials. Before developerWorks, she wrote for, edited, and managed information for IBM software and hardware in development. Her degrees are in English from Auburn University in Auburn, AL, and Technical writing from Rensselaer Polytechnic Institute in Troy, NY.

Scott Laningham

Scott Laningham, host of developerWorks podcasts, was previously editor of developerWorks newsletters. Prior to IBM, he was an award-winning reporter and director for news programming featured on Public Radio International, a freelance writer for the American Communications Foundation and CBS Radio, and a songwriter/musician.

Kane Scarlett

Kane Scarlett is a technology journalist/analyst with 20 years in the business, working for such publishers as National Geographic, Population Reference Bureau, Miller Freeman, and IDG, and managing, editing, and writing for such august journals as JavaWorld, LinuxWorld, and of course, developerWorks.

Comments



static.content.url=http://www.ibm.com/developerworks/js/artrating/
SITE_ID=1
Zone=Security, Web development
ArticleID=836034
SummaryTitle=Secure web and cloud applications
publish-date=09262012

My developerWorks community