* Policy, real-time anomaly detection and context-aware security
With all the technology focus in information security, it can be easy to overlook the fact that security is primarily a people issue. Relationships of trust and the ways people use information systems are at the heart of managing IT security.
If people do not adhere to secure computing policy and practices, assumptions on which security is based may prove dangerously false. Many feel it is only a matter of time until the worms and blended threats that have overwhelmed networks with blinding speed bring us “the big one” – an attack that actually damages systems or destroys data. Without consistent enforcement of policy on how people use IT, many fear these attacks could be devastating.
The enforcement of a security policy on systems connecting to an enterprise network is at the heart of the Cisco Network Admission Control (NAC) and Microsoft Network Access Protection (NAP) initiatives; thankfully, Cisco and Microsoft have recently announced at least the intent to cooperate.
Security managers need not wait for these high-profile initiatives to come to full fruition in order to better implement security policy, however. Many alternatives are available today, such as Solsoft policy management systems, the policy-based offerings of Nortel and Enterasys, and the enterprise endpoint security frameworks of Sygate, Endforce, Check Point, WholeSecurity, InfoExpress, and many others. Policy plays a critical role in the trust placed in identity management and provisioning, and we can expect the emergence of even more comprehensive approaches to security policy management in the future.
Regardless how thorough policy management may be, the increasing variety and flexibility of “people-friendly” ways to connect to an enterprise network means that threats will always penetrate. This is a primary concern, because if “the big one” is a “zero-day” attack – a threat that spreads rapidly before its signature can be recognized – it may do considerable damage before a response can be effective. This is where “real-time” defenses can play a proactive role. Network anomaly detection techniques such as those of Q1Labs, Arbor Networks, Lancope and Mazu Networks, are merging with established signature-based approaches to intrusion prevention in products of companies such as Sourcefire, owner of the intellectual property of the popular Snort intrusion detection system. These techniques can recognize an attack before it is even known, by identifying potentially threatening network traffic.
When coupled with network discovery and awareness capabilities such as those of Lumeta or Computer Associates eTrust Network Forensics, defenses can become even more potent, as they enable the prioritization of security issues based on the actual context of a threat or vulnerability. This is the differentiator of Skybox Security, which enhances vulnerability management with the ability to prioritize based on awareness of network context and likelihood of attack. Among the interesting innovators in contextually aware security is Citrix. It may be just fine to deliver a sensitive spreadsheet to an authorized user on a LAN, but when that same user seeks access to applications from an airport kiosk, for example, Citrix access management products are increasingly able to differentiate that context and manage information delivery appropriately – particularly when the user can’t, or won’t.
Policy, real-time anomaly detection throughout the network, and context-aware measures: three key technologies for managing the security of how people use IT, and three areas particularly worth watching as they continue to mature.




