Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Using "offensive technologies" to secure networks

Network security researchers to focus on attacks and defense
By Bob Brown , Network World , 05/14/2007
  • Share/Email
  • Tweet This
  • Comment
  • Print

The First Usenix Workshop on Offensive Technologies is coming to Boston on Aug 6. It’s hard to resist an event called WOOT, even though we weren’t quite sure what it was all about. So we shot an e-mail to Tal Garfinkel, a Ph.D graduate student in Stanford University’s computer science department and one of WOOT’s program chairs, and asked him to explain.

What do you mean exactly by “offensive technologies”?

There are many ways to chop up the conceptual space of computer security. One way is by grouping technologies into those required for attack and defense. The primary focus of traditional academic computer security has been defense. Intrusion detection, access control, bug detection/prevention and the like. The primary focus of much of the more "black hat" or "grey hat" communities has been offensive technologies -- techniques for exploiting software weaknesses, reverse engineering, information gathering, evading detection and the like. Interestingly, for any given question in the defensive space -- for example, how do you defend against keyloggers? -- there is a dual in the offensive space, such as: How do you design a better keylogger? By understanding both perspectives, one gets a deeper understanding of computer security, and for many years one side has informed the other.

Many of us have read some of the black hat magazines, read the code of attack tools, and followed the state of the art in attack to inform our view of defense. However, the coverage of that side of the equation has often been spotty. The editorial quality of places like Phrack is quite low, and the lack of peer review means sometimes the veracity of claims being made is questionable. In black hat, for example, the metric for quality often seems to be how much news the hype about your work induces, rather than how original, important or credible your claims are.

Why the need for this separate workshop from the broader Usenix Security Symposium taking place that week in Boston?

While attack technologies have definitely been part of forums like Usenix Security for a while, the bar for publishing new attack work is quite high in terms of novelty and certain topics (such as reverse engineering, malware design, automatic exploit development) are often overlooked entirely. Often there is work that would really be helpful to have in the literature to help researchers understand the state of the art in offensive practice, that simply doesn't fit the model of what we are currently looking for in academic conferences. The absence of this work not only means we have a less than complete literature to draw from, but also tends to exclude many practitioners who have a lot of valuable stuff to contribute to the academic discourse.

I think if you look at our program committee you find a really interesting cross section of folks from different backgrounds with different relationships to attack technologies -- this is both to represent different view points and attract broader participation.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (9)
Login
Forgot your account info?

You need to know how the hackers are doing what they're doingBy Anonymous on May 14, 2007, 3:32 pmLike Harry Potter's "Defense against the Dark Arts" class - unless you know HOW the dark wizards operate - how do you protect against them? Re: Using 'offensive...

Reply | Read entire comment

Woot ArticleBy Neil Robinson on May 16, 2007, 6:03 amSorry, I read this and found absolutely nothing new. Just the same old stuff about perimeter security raked up again - and no evidence of any research. "hard...

Reply | Read entire comment

Right and wrong replyBy Antonio Maña on May 16, 2007, 5:03 pmThe comment by Neil Robinson is right in many aspects. In particular in promoting "appropriate security" as opposed to "total security", The latter, apart from being...

Reply | Read entire comment

Woot: right and wrong replyBy Neil Robinson on May 17, 2007, 3:12 amHi, Antonio. Thanks for your comments. Take a lesson from history. In World War 1, the French built the ultimate in perimeter security. The Magineau Line....

Reply | Read entire comment

Interesting. I share your opinion!By Antonio Maña on May 17, 2007, 11:21 amHi Neil, Thanks for the link. Very interesting indeed. Essentially, my first message was about agreeing with your comment, while not really understanding the...

Reply | Read entire comment

Definition of withinBy Tal Garfinkel on May 17, 2007, 12:20 pmBy "within" the permitter I meant, inside, as in not the permitter but beyond. i.e. everything behind the firewall.

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed