Digital Transformation and the Shadow Code Risk
September 23, 2020

Ameet Naik
PerimeterX

Businesses across the world are accelerating their digital transformation as consumers increasingly shift to online channels. Web applications have become a critical element of this digital journey and keeping them secure and performant is now more important than ever. However, there are new challenges that application developers face while delivering and maintaining these business-critical applications.

Web application developers often rely on open source libraries and third-party scripts in order to innovate faster and keep pace with evolving business needs. These scripts and libraries — often added without approvals or security validation — introduce hidden risks into the organization and make it challenging to ensure data privacy and to comply with regulations.

Collectively referred to as "Shadow Code," these scripts provide essential services such as payments, analytics, chatbots, advertising or social media integrations. However, application security teams often don't have a comprehensive understanding of what these scripts actually do, creating opportunities for malicious code injection attacks.


The Client-Side Blind Side

Often introduced without any formal approval process or security validation, these scripts run on the client side, which means traditional monitoring and security tools cannot provide the same visibility and control that you might have over server-side apps. This is a major blind side for appsec teams. So how big is this problem?

PerimeterX, in conjunction with Osterman Research, completed the second annual survey of application security professionals to uncover the extent and impact of Shadow Code across organizations in a diverse set of industries. The report, Shadow Code: The Hidden Risk to Your Website, finds that only 8% of respondents have complete insights into the third-party code running on their website. This is a very low result, which means that the vast majority of web applications out there have high levels of Shadow Code running on them.

The Trust Deficit

Given the extensive amount of third-party code running on web applications, the survey also examined the relationship between the users and the providers of third-party scripts. Over 30% of the respondents reported that they do not trust the providers of their third-party scripts. Yet, they allow this Shadow Code to run on the client-side of their web applications. This poses considerable business risk to the owners of these web applications.

As data privacy regulations like the California Consumer Privacy Act (CCPA) and the Global Data Protection Regulation (GDPR) impose strict penalties for client-side data breaches running into the hundreds of millions of dollars, application owners need to be more vigilant about the security of third-party scripts on their web applications.

The survey found that only 30% of survey respondents believed that their externally-facing web properties are completely secure from threats like Magecart attacks, down from about 40% in the 2019 survey.

Limited Controls

Application owners are turning to client-side behavioral analysis solutions that can baseline the behavior of first- and third-party scripts to identify anomalies that could signal a compromise. However, they need more mitigation options when dealing with such threats.

Only 22% of the survey respondents indicated that they or their teams have the full authority to shut down any suspicious script that they might find running on their website. This is down from 32% in 2019. For example, if the anomalous script processes payments, it's very difficult to shut it down while the team analyzes the root cause. Solutions that can surgically stop specific script actions without shutting down the entire script can offer a useful middle ground to already constrained appsec teams.

Compliance Remains Elusive

Only 30% of respondents to the survey reported that their externally facing web properties are secure and thus compliant with data privacy regulations. These statistics suggest that we are at the very early stages of identifying and grappling with the Shadow Code problem.

Much like with Shadow IT, when CIOs were forced to implement BYO device policies and tolerate more cloud services and apps in use than they could imagine, CISOs no longer have the luxury of saying no to third-party code. Meanwhile data privacy regulations are tightening worldwide and client-side attacks, such as Magecart, are on the rise, leading to massive data breaches and fines.

Shadow Code Best Practices

Shadow Code is here to stay and eliminating third-party scripts is not the answer. Application development and security teams can gain control over this problem by combining static testing of internal code, with runtime behavioral analysis of third-party scripts that can identify security risks in real time. Client-side application security solutions can offer a wide range of mitigation options to manage threats present within Shadow Code. Web applications can continue to benefit from the vast ecosystem of third-party services without compromising their users' data privacy.

Ameet Naik is a Security Evangelist at PerimeterX
Share this

Industry News

July 18, 2024

Mission Cloud announced the launch of Mission Cloud Engagements - DevOps, a platform designed to transform how businesses manage and execute their AWS DevOps projects.

July 18, 2024

Accelario announces the release of its free TDM solution, including database virtualization and data anonymization.

July 18, 2024

RAVEL (formerly StratusCore) introduced RAVEL Orchestrate’s new Bare Metal Build Station functionality, which empowers IT and DevOps teams in SMBs or enterprises to intelligently prepare and deploy customized images to any physical machine connected to a network.

July 17, 2024

OpenText™ announced its solution to speed the triage and remediation of vulnerabilities throughout the stages of code development, OpenText Fortify Aviator, an AI-powered code security solution, saves developers significant time by enabling faster and easier auditing and remediation of static application security testing (SAST) vulnerabilities—all within a single solution​.

July 17, 2024

Tricentis announced the acquisition of SeaLights, a SaaS-based, software quality intelligence platform.

July 17, 2024

CAST is now available as software as a service (SaaS).

July 16, 2024

OpenText announced its latest product innovations with Cloud Editions (CE) 24.3.

July 16, 2024

Red Hat introduced new capabilities and enhancements for Red Hat OpenShift, the hybrid cloud application platform powered by Kubernetes, as well as the general availability of Red Hat Advanced Cluster Security Cloud Service.

July 16, 2024

DevEx Connect launched as a community-driven independent research, analyst and events organization focusing on everything under the DevEx umbrella, including DevOps, SRE and Platform Engineering.

July 15, 2024

Elastic announced support for Amazon Bedrock-hosted models in Elasticsearch Open Inference API and Playground.

July 11, 2024

Progress announced new and powerful enhancements in the latest release of Progress® LoadMaster® 360, its cloud-based unified application delivery platform. These enhancements help organizations protect their web applications against increasingly sophisticated cyberattacks and provide customers with an optimal application experience.

July 11, 2024

Virtusa announced a strategic partnership with Quality Clouds, a provider of SaaS governance solutions for Salesforce and ServiceNow platforms.

July 11, 2024

Zesty launched its newest offering, Commitment Manager for Amazon RDS (Relational Database Service).

July 10, 2024

MacStadium unveiled Orka Desktop, a free, local macOS virtualization tool.