Why network-based security doesn’t cut it anymore

News
Jun 14, 20078 mins

One venture capitalist’s argument for investing heavily in client-side security

A venture capitalist argues that the focus should be on client-side, rather than network-based security.

There are a couple of different ways.

One company I’ve invested in, Fortify Software, is not a client agent, but it is based on the concept that you have to secure the actual assets, and the theory there was if you could identify security vulnerabilities in source code and remove them, then there would be nothing to exploit.

For the most part, Trojans, worms and viruses exploit faults in code. Fortify sells to the enterprise: Most of the software in the world is developed by enterprises, not by [independent software vendors]. The whole concept is that if you can get at the root cause, we’d be better off. We learned this in the manufacturing sector. If you get the defect out early, it is far better than if you have to do a recall.

Like patches . . .

To me the whole rise of patches is a recall. It’s kind of ridiculous that people have gotten used to doing patches. We need to be checking for and removing security flaws before they ever make it out to the marketplace.

What’s the real problem with network-based security?

Just by doing packet sniffing and looking at traffic going across the network, you’re going to miss a ton of things, especially stuff that’s encrypted or stuff that happens off the client. Security is something burned to a thumb drive, it’s something burned to a CD, it’s something encrypted before it’s e-mailed — Web e-mail or corporate or via instant messaging or chat. You need to take a look at it before somebody tries to obfuscate it.

Looking at it on the wire gets you too far away from the context of what you’re actually trying to protect. The further out of context you are, the less secure you will be. The more false-positives you get and the more of them you get, the less people listen to it. That’s kind of what’s happened in the firewall and IDS space. You get so far out of context that the logs just don’t get looked at anymore. The closest you can be to context is being on the device or being in the application you’re trying to protect, and I think that’s the trend you’re going to see in security going forward. It’s easier to install an appliance to sniff network packets, but it won’t make you more secure.

So you’re investing in client-oriented companies . . .

I did a company in content-management filtering called Oakley Networks, and the reason I did it is that it had a client agent. The rest of the companies in that area for the most part were doing gateways.

Bit9 is another one I’ve been working on which is kind of the anti-antivirus. The biggest fault in doing the antivirus software is, the thought never occurred to us that knowing what is bad is impossible, knowing what is good is possible. So, we inverted the problem and said we’ll only allow what is good to execute.

That puts you in a much better position to try to identify these things that are unknown and bad. The only way you can do that is with a client agent that prevents anything from running that’s not authorized to run. I get to the client agent, not because I’m a client agent purist but because I think it’s the only way to truly secure the data, the applications, the endpoints.

Have you seen evidence that the new stuff is actually improving security?

It’s early yet. To be fair to network-based security, it was a first-of-its-kind thing and it was slowing things down, but the sophistication of attacks and porousness of our networks – by design – is very different from what we were trying to protect when we developed network-based solutions.

I do know people that are starting to do secure-code audits and go through some code fortification are experiencing much lower incidents in breaches, and that makes sense to me. The more you do that – Microsoft has been working on that for a while, too – you’re going to see less and less trouble. I do believe at some point in time — and it might be three to five years – that doing secure coding won’t even be thought about, it will just be done. That will have a profound effect on slowing things down.

Speaking of Microsoft, what’s your take on its security efforts of late?

Most of the code and applications in the world are not written by Microsoft, so I would never blame Microsoft. They’re doing their part to curtail as much as they can the various exploits. I applaud them for trying different things. But they are not a security company. Security to them is a cost center and not a profit center, so it is difficult for them to focus on it.

What are the risks in focusing on the client?

Getting client-agent software to work is really hard because of compatibility issues and testing suites needed to do it, and all the permutations of the OS, and all the various stacks you are running. Getting it to work at industrial strength and be deployed in an enterprise is much harder than doing a network gateway product. It’s probably one of the biggest inhibitors to deployment — and then you’ve got people who have to go and buy seven different client agents. That’s hard, too. People would like an überagent that takes care of everything for you, and that’s going to take time.

It’s a function of how secure you want to be. I get asked a lot to talk to CSOs and CIOs, and I don’t want to profess to tell them how secure you should be, but ask them to assess how secure they are and whether that is good enough. How much risk are you willing to take? What I propose is that if you have a purely network-based security set of solutions, you are taking good amounts of risk. Are you OK with that? Some industries are, some are not.

Yet it could be hard to resist the pitches of companies like Cisco that push for security in the network, right?

I just say to you it is a way to look at life that was a way to look at it a while ago. Think about it. If you could get to root-cause down to what is being attacked, what anybody is after and protect that, you wouldn’t have to protect the roads. But do I think anybody is about to take down their roadblocks? No, I don’t. I get to think five to ten years out. We’re at the beginning stages of shifting and inverting where security dollars are going to be spent and why they’re going to be spent there, and that’s going to come to the advantage of some companies and the disadvantage of others.

But can big IT shops really afford to take a chance on buying security products from start-ups that probably won’t even be around in a few years?

Security is the Number 1 spend item now and particularly for the future for corporate IT. They’re willing to take the risk to get best-of-breed. The interesting thing about security breaches over time is, it was just people screwing around. Most of the early viruses we stopped didn’t do a whole lot.

Now people don’t want you to know that they’ve breached. It’s big business and the stakes are much higher. The ability to steal and do various malicious and nefarious criminal activities is leading to a whole new set of technologies. Anticrimeware software is more of what you’re going to see. It’s not stopping the hacker from spreading a virus around your network just to make you clean it up.

Who’s going to be this new cyberpolice force? I propose it will be different than what we’ve seen in the past. Take the whole area of bots. How would you infiltrate a bot army? In the human world, you would be a CIA operative and you would sit there and gather human intelligence. How would you do a similar thing in the bot world to gather intelligence, feed it back somewhere and take countermeasure actions? That’s what we’re going to need to do.

We’ve heard about bots and had our share of phishing, spyware and the rest. What’s the next big threat?

The whole idea of sleeper bots, things that will get planted and not be activated for many years and who knows why, will be interesting. They could have many different uses, and I think that’s going to keep us busy for the next bunch of years.


More Q&A’s from Bob Brown:

* Why Acopia didn’t get a Christmas card from Network Appliance or EMC

* Behind the scenes of MIT’s network

* The bare facts about naked telecommuting