* AT&T points to an intelligent network to thwart cyberattacks
endif; ?>The most promising way to fix today’s cybersecurity problems is to rethink the Internet’s basic architecture to add more intelligence to the network and less capability to its end-points, according to Ed Amoroso, AT&T’s chief security officer. Amoroso made his remarks at the Tenth Annual Gartner IT Security Summit held in Washington D.C., in early June. More than 1,000 network executives attended the Gartner event.
The most promising way to fix today’s cybersecurity problems is to rethink the Internet’s basic architecture to add more intelligence to the network and less capability to its end-points, according to Ed Amoroso, AT&T’s chief security officer.
Amoroso made his remarks at the Tenth Annual Gartner IT Security Summit held in Washington D.C., in early June. Some 1,500 network executives attended the Gartner event.
In a frank assessment of the state of Internet security, Amoroso said he sees little promise in the IT industry’s ongoing efforts to improve software development and systems administration processes.
“There is no industry like software where we sell products that we know are broken,” Amoroso said. “We should be ashamed” by the quality of software produced today, he added.
Fixing software development processes requires overhauling computer science education and establishing better standards, which cannot be accomplished quickly, he said.
Meanwhile, efforts to improve systems administration via user education are destined to fail, Amoroso predicted. As evidence, he pointed to decades-long governmental efforts to encourage people to quit smoking and use seatbelts. If people won’t change their behavior when their lives are in danger, why would they change their behavior for as elusive a goal as reducing the risk of a cyberattack, he asked.
“The answer is rethinking networking,” Amoroso says, advocating that instead of having a dumb network with smart end-points, we migrate to an architecture where the network is more intelligent. “We have to swing some of the intelligence back to a more centralized architecture.”
As an example of the type of intelligence found in AT&T’s IP network, Amoroso pointed to a new early warning system that the carrier recently began offering enterprise customers. AT&T researchers developed the service after noticing that in the days and weeks prior to a major worm or virus attack, AT&T’s network operations staff noticed anomalies in the reams of network traffic data that they receive each day.
“In the last two years, through our research and traffic analysis, we stumbled on to something that helps with early intrusion detection,” Amoroso says.
The researchers noticed fizzled attempts at sending worms and viruses. For example, AT&T researchers saw anomalies seven days before the Blaster worm attack and four days before a recent Cisco software glitch was revealed. “Terrorists can’t write software either,” Amoroso cracked.
AT&T collects more than 1-terabyte of traffic data per hour. Every 5 minutes, AT&T’s network can assess the traffic patterns that it is seeing compared to what it should be seeing. AT&T is using this intelligence to tip-off its enterprise customers about potential cyberattacks before they happen.
“The network watches in living color what’s going on in the network,” Amoroso explains. “This is the future of intrusion detection. Short of fixing software problems and short of fixing system administration problems, this is the last great hope for the next few years.”




