Breaking Down Appsec Part 2: Securing the Perimeter (Identity)
The first steps to secure your application after you know your application is to secure from the outside in
We continue our series in breaking down application security so that anyone can do it without hiring expensive teams of employees. We explore our next steps by highlighting the importance of protecting the outside (the perimeter) before the inside!
In the pilot of our series on understanding what Application Security really was, we discussed that we need to treat our applications like a home and proper maintenance was needed. As part of maintenance, proper security was one aspect to maintain.
Then in part 1, we talked about the importance of understanding two sides of the same coin: yourself and your attackers (this will be talked about in depth in the threat modelling part of our series).
This part, we will talk about the beginnings of how to actually start your security analysis of your application and use some concepts from part 1.
Is Your Home a Public Playground?
You’ve called some people over for a house party! You’ve cleaned up your home, preparing some food and drinks for your guests, and the guests are starting to enter the home! As the night progresses, you notice that the number of guests seem to be suspiciously large… so the question is:
Are random people coming in AND treating your home (application) like a playground? If these randos are coming, you’re okay with them, and you’re okay with your home being a playground, then great! I’m glad we’re all having fun.

If random folks are coming and you’re not okay with them nor your home being treated like a playground, then maybe it might not be so much for you. It seems you’ve got a problem with boundaries. So what do you do…? Well there is a specific order in which you must tackle this problem: GTFO
Gate → Track → Familiarize→ Ownership

For this post, we’ll stop short at Familiarize and move into Ownership in our next post as it’s a topic that’s quite important and nuanced.
Gate

Let’s think back to our home analogy. Your home consists of various ways that you can enter and exit the home. To provide even more awareness, you must consider every entrance is also an exit to a home AND every exit is also an entrance as well!
If Santa Clause can get in and out of the chimney, then a person can also get in and out the chimney, just like Santa.
Just thinking of chimneys or entrances or backdoors as the only points to consider could be wrong thinking. Considering each room inside the home is just as important. Each room can contain precious items, memories, and people you don’t really want a bad actor stealing or destroying.
To gate is to ensure that no one comes in to the home or any of the rooms within it, so that you can prevent a bad consequence. We’re not thinking of anything else besides blocking access for now. We’ll talk about how to provide proper access to the home and some of its rooms shortly!
Your application consists of perhaps a home page and maybe that might be the front door. So then, if that’s the front door, you have to start considering every other route/endpoint potential backdoors, chimneys, windows, rooms, etc.
Lock it all down to ensure no one can get in.
Every window, every room, every door.
Every route / web endpoint.
This is the first layer of our security journey.
Track

Much like a funnel, you want to ensure that all the people, trying to come in to your now locked down home, are being centrally guided to run some checks on your supposed guests. This is so that you can track everyone who comes in to your home. Everyone who is trying to go through the previously unlocked windows, backdoors, chimney, etc. are now redirected to one single “chokepoint”, where there will be a guard waiting to ensure no randos come in to the home.
Similarly, the hundreds, thousands, millions, billions, etcetc. requests per second in to your app are being routed appropriately, funneled to one area in your application where there is centralized logic to handle them before you let requests through. We often call this security middleware for web applications. I would humbly request you watch the following video as it explains quite well what middleware is and should consist of.
Centralizing one entry way into your home or your application so that you can centrally track everyone coming in and out provides the second layer of our security journey.
Familiarize
So now we’re at a stage where you’ve now locked down the home and you’ve redirected people into one area where there’s some sort of security personnel. How many guards do you need? What is/are the guard(s) supposed to do? Do you trust those guards? Those are some pretty intense questions because the guard is really now the only one/group blocking random strangers from entering the home. If the guard is faulty, they’ll let randos through.
Let’s assume a few things:
we do hire a group of guards at the front of the home that are actually trustworthy
the group of guards will ONLY do what you specifically ask of them
every person in line is unique (let’s just say they all have completely different names)
every person in line carries with them an id that indicates who they really are (there aren’t any people who stole ids - we’ll discuss this at a later time)
So now you have to be careful what instructions you tell the guards.
We start off with familiarizing guests (Identity).
You give the guards a list of people welcome to your home
Guards are to familiarize themselves with guests by asking the individual requesting to enter the home for their identification
If the person refuses or does not have identification, then kick person out of line. If person complies, move to step 4.
Guards are to check that the name on the identification card/book matches a name on the list
Once a person on the list matches with the identification card/book, let the person in AND mark that person off on the list
Start from step 1 with new person in line
Much like the above, with applications we need to create middleware that does these repeatable steps.
Ask folks to sign in and identify themselves
Check that the person signing in truly exists in your database of users
If they don’t exist, reject the request and redirect them to sign up/sign in again. If they do exist, then let the request through.
The middleware is the guard that sits between the outside world and your application’s business logic. You must program it to ensure that the request coming in is coming from a known person, otherwise we might revert back to a period when we had no gating or funneling or guards.
Pigeon is a NYC Cybersecurity Services company, specializing in Application Security. If you or anyone you know needs application security services, please reach out to me at david@pigeonlabs.ai. We’re willing to work with you near and far!
Subscribe to Breadcrumbs
New field notes on appsec and AI agent security. Free — unsubscribe anytime.
