* The risks posed by authorized application functionality
Not that long ago, the top priority of IT security was protecting the network. That still ranks high today, of course – but a number of issues have converged over the past year to highlight just exactly what it is we’re trying to protect. Spyware has risen from a little-recognized issue to a top priority, while worms and compound attacks not only wreak havoc on availability and performance, they sometimes leave behind lingering yet unseen threats that can also collect sensitive information – or the ability to take some measure of control over an infected system.
Not that long ago, the top priority of IT security was protecting the network. That still ranks high today, of course – but a number of issues have converged over the past year to highlight just exactly what it is we’re trying to protect.
Spyware has risen from a little-recognized issue to a top priority, while worms and compound attacks not only wreak havoc on availability and performance, they sometimes leave behind lingering yet unseen threats that can also collect sensitive information – or the ability to take some measure of control over an infected system.
Remote control is not always seen as a threat, however, and in fact may be acknowledged functionality of applications that is seen as legitimate. For example: in a September 2004 paper, computer scientists at Columbia University (see link below) noted that any Skype host having a public IP address, adequate CPU, memory, and network bandwidth could become a Skype super node, able to facilitate the connections of other hosts to the Skype network. This raises the question of the risks posed by authorized functionality. Peer-to-peer networks can support file transfers and unauthorized communications – but so can legitimate e-mail and messaging.
The proliferation of privacy regulation has combined with these factors to raise the bar on IT security beyond the network. As attackers and legitimate applications alike seek greater access to information assets – and as the enterprise reconsiders what it means to trust its IT users – the focus of defense increasingly turns toward protecting enterprise information itself.
These factors are spurring the emergence of solutions for securing data. Many techniques incorporate some valuable lessons learned from the failure of cryptography to fulfill its dot-com promise. Others represent a repurposing of network and application security techniques, while still others are entirely new innovations defining the field. The boom in anti-spyware and solutions for mail and messaging security are the most visible manifestations of this trend today – but here are some of the others you should be keeping your eye on:
* Data leakage prevention, which combines the ability to recognize sensitive information with controls on how or whether certain information can leave the trusted network.
* Enterprise rights management, a cousin of digital rights management applied to enterprise information users and consumers.
* Application of information lifecycle techniques to managing the security lifecycle of data in storage, in transit or in use, including encryption applied to data in storage or in databases themselves, as well as techniques for giving structure to unstructured data throughout the enterprise, enabling its identification and classification for security and compliance purposes.
* Web and enterprise application defenses, particularly those focused on securing application data.
* Adaptations of acceptable use enforcement solutions such as URL filtering geared toward protecting the enterprise from questionable or unauthorized external connections.
* Enhancements of remote connectivity solutions such as VPNs to include stronger data protection measures.
If you are using – or shopping – one or more of these data security techniques, I’d be very interested in hearing from you about why you’re interested, what works, what you think doesn’t, and what you think will succeed as this trend continues to take shape. I’ll report back on what you have to say in a future newsletter.
* Link to a PDF of “An analysis of the Skype peer-to-peer Internet telephony protocol,” by Salman A. Baset and Henning Schulzrinne, Columbia University.
From page 1, under “1. Introduction”:
“A super node is an ordinary host’s end-point on the Skype network. Any node with a public IP address having sufficient CPU, memory, and network bandwidth is a candidate to become a super node. An ordinary host must connect to a super node and must register itself with the Skype login server for a successful login.”




