New approaches are beginning to emerge as the community realizes fundamental changes are needed in cybersecurity.
endif; ?>After spending a lot of time reading a lot of words about a lot of cybersecurity attacks, trends and patterns start to take shape.
Based on little more than an outsider’s observations, it just seems like the current popular mindset toward security isn’t very effective. In general, it seems like an attack-and-defend type of relationship. The attackers, or hackers or malware developers or what have you, are the orcs catapulting boulders at the white brick walls of corporate Gondor, behind which CIOs sit on horses and rally their army of nameless network professionals to protect what has been destroyed.
RELATED: Useful security threat data advisory tools
All Lord of the Rings metaphors aside, that’s the essence of the narrative that seems to keep popping up. Maybe it’s being perpetuated by us, a media that’s crazed to report the latest data breach of cyberwarfare accusation and to captivate our readership with a distinct sense of characterization of the parties involved. Maybe it’s just how it actually is. But isn’t it interesting to consider how much influence this publicly driven mindset could have on the millions of dollars corporate decision makers pour into their security resources every year?
RELATED: Microsoft’s MAPP reportedly hacked, RDP exploits coming sooner than expected
Naturally, any different approach or philosophy around security is interesting. Randy Franklin Smith, CEO of the Monterey Technology Group, considered the possibilities of a bait-and-track approach to identifying vulnerabilities and the sources of data leaks in a recent espionage-inspired contribution to Lumension’s Optimal Security blog.
There, Smith suggested that enterprises could create honeypots to attract targeted attacks. This entails setting up folders that are filled with files formatted to appear like they could be valuable, but are in fact worthless. He even cited some enterprises that create fake personas, puppets almost, complete with fake corporate email addresses, phone extensions and even social networking accounts that make them appear to be easy social-engineering or phishing targets for cybercriminals.
Through an auditing system, Smith says enterprises with these empty targets in place can at least find where cyber-attacks are coming from, if not also identifying the culprit. And even though Smith advised against using it for seeking vulnerable, or even corrupt, internal employees, these honeypots could be effective bait for those on the payroll who cause havoc as well.
Other interesting new methods can help change the fundamental philosophies around cybersecurity as well. I’ve always been a fan of Pwn2Own and other competitions that value the work of hackers and provide positive reinforcement rather than bemoan them for forcing the enterprise to do more work (those that aren’t overtly malicious, that is).
And another ongoing project at the Multi-State Internet Security and Analysis Center (MS-ISAC), for example, is establishing new private sector partnerships to help resolve the supply-and-demand relationship that may keep some financially limited potential customers from reaping the benefits of vendor solutions. Through the Trusted Cyber Security Purchasing Alliance, the MS-ISAC identifies common needs among its members (state, local, territorial and tribal governments) and seeks out vendors that can address them. The alliance then organizes bulk purchases of the vendors’ security products, giving budget-restricted local governments a discount on security solutions.
These are all positive signs that the enterprise is beginning to realize that no matter how strong they might think their walls are, others are taking just as many notes to determine their weaknesses. Because it’s starting to look more and more like almost anybody can be hacked, it’s time to start considering new ways to determine how easily it can be done, and what it would take to prevent it.
Colin Neagle covers Microsoft security and network management for Network World. Keep up with his blog: Rated Critical, follow him on Twitter: @ntwrkwrldneagle. Colin’s email is cneagle@nww.com.




