* Users need to challenge their strategic security vendors to start acting more proactively
If there is one lesson we should learn from the big win over the liqui-bombers in the United Kingdom, it is the importance of intelligence. Not only did the authorities take some dangerous folks out of the mix, but the definitive proof of the plan made such drastic restrictions on liquids acceptable to a skeptical public. Terrorists can attack hundreds of thousands of targets, so how do you know which ones to focus on and protect more aggressively? In one word: intelligence.
Security folk spend an awful lot of time researching what things are broken, and much less time figuring out which of those broken things are going to be used to compromise machines. Everyone goes to a show like Black Hat and gets all fired up about how cool it is to break things. That’s called research.
As we’ve seen with all the focus around the wireless exploits and virtual machine rootkits, just because something is vulnerable, doesn’t mean an attack is going to be launched imminently. Security research is an important part of the process, and I respect those who spend their time figuring out what is broken and work with the vendors at risk to fix it.
But I also want to call out all of the security intelligence types who do the yeoman’s work of trying to figure out what the bad guys are going to do next. How did we know that Microsoft’s recent high-profile patch (MS06-040) was being exploited by the bad guys and it was absolutely critical that everyone patch immediately? It’s because some unsung heroes practice the art of security intelligence.
Who are these security intelligentsia? They typically are either government agents working to crack a crime ring (notice that a warning on MS06-040 came from the Department of Homeland Security) or they work for a private enterprise and realize the need to track this information to make their products more relevant and keep them ahead of the curve. They spend their time trying to break into these cabals of bad guys, become a trusted part of their world and monitor the traffic. This way they figure out what these networks of bad guys are up to.
Let me provide more context. Information security professionals face an attack surface that spans every network, server, endpoint and application. Combine this with a literally infinite number of attack vectors that can be used at any time to compromise a system.
I’m very comfortable with the statement that no network, system, endpoint or application is 100% secure. If you have an application running disconnected from the network in an impenetrable vault then you have dramatically reduced your chances of compromise – but I digress.
So working harder is not the answer. We have to work smarter and the only way to work smarter is to know what’s coming. Someone needs to do the grunt work of tracking the bad guys and figuring out what they are up to. The reactive security model will always have a place to ensure we aren’t compromised by attacks we know about. But to provide real protection, we need to be more proactive.
The fundamental problem with security intelligence today is that it is a closed, cloistered community. In order to not compromise the agents, you need to be careful about how and when you use this information. But that means it’s hard for your run-of-the-mill security administrator to get access to what is coming next. There are a few security alert services from the likes of Cisco, ISS, Symantec and VeriSign with more on the way – but they have not really become pervasive.
There is little, if any, context for the intelligence. It seems that all the pieces of data that could have prevented the 9/11 attacks were there. But we didn’t put the pieces together in time to provide the context to prevent the attacks. Hindsight is 20/20, but that intelligence failure will be seared on the psyche of all of us for generations to come.
Security professionals have too much to do, and an ever changing asset base makes it hard to keep up with everything that is vulnerable. Finding the time to fix it is another resource sink. The process needs to be automated. I know some vendors have been working on this for a long time, but the results have left a lot to be desired.
So consider this a call for action. If you are a user, start challenging your strategic security vendors to start acting more proactively. Make it clear that sooner rather than later you are going to start investing your money with vendors that are ahead of the curve, not behind it.
If you are a vendor, I’ve laid down the gauntlet. The dominant security players must be able to anticipate the next attack. Those that can figure out how to integrate the crystal ball into their offerings in a more meaningful fashion than pre-emptive marketing mumbo jumbo will find customers beating a path to their door.




