The state of network security

News
Jul 31, 20123 mins

A review of security conference Black Hat

Network security is still as necessary as it was 15 years ago when the Black Hat Conference was first beginning. Sure the players have changed and the sophistication, but it is a classic good vs. evil scenario still.

A panel of experts at Black Hat got together to expound on what they see as the privacy and security mess of our times, and they had plenty to say about the U.S. government, cyberwar and Google.

“The government really sucks at handling classified data,” opined Marcus Ranum, CSO at Tenable Security. He said the vast WikiLeaks dumps of sensitive data from the U.S. government seen over the past few years shows that agencies such as the Department of State need to improve “data custodianship.”

As the panelists veered into the topic of who would you trust less with your data, the U.S. government or Google, ICANN CSO Jeff Moss answered that he feared Google more than the feds. That got Ranum to quip: that’s because “Google has a history of getting things done.”

Also at the conference Apple made its first appearance, however attendees walked away disappointed as Apple’s representative covered no new ground.

Through the years Apple has not not been the biggest target for malware attacks as that distinction has gone to Microsoft and its Windows operating system. Windows 8 offers some promising opportunities for attackers, but overall is a much more secure operating system than its predecessor, a researcher told the Black Hat conference.

There are at least three attack points in Windows 8 that with more work might yield vulnerabilities that could be exploited, says Sung-ting Tsai, leader of an advanced threat research team for Trend Micro.

One cannot leave Black Hat without the term espionage being bandied about. Cyber-espionage operations across the Internet are extensive yet highly targeted, says a malware researcher. And it’s not just governments targeting other governments or trying to steal corporate secrets — private security companies also are involved in these break-ins even while claiming to offer “ethical hacking services.”

In today’s cyber-espionage, “there are hundreds of tiny little botnets,” says Joe Stewart, research director at Dell SecureWorks. These command-and-control systems do one thing — compromise targeted networks of business and government in order to learn about important information worth stealing, and then swipe it.

Read more about what happened at Black Hat, including a Q&A with the father of SSH. To download this pdf you must become a Network World Insider (free registration is required).