SUBSCRIBE

Challenge vendors to prove security solutions work: RSA chief

Organizations have to pressure IT security pros and the security industry to prove their solutions are effective in the face of seemingly unstoppable cyber attacks, says the head of one of the worldโ€™s biggest security vendors.

Amit Yoran, president ofย  RSA, issued the call at the outset of his companyโ€™s annual security conference in San Francisco, where it is expected that dozens of vendors will announce new products.

But Yoran not only suggested organizations cast a jaundiced eye at this weekโ€™s press releases, he also called on the industry to overhaul itself.

โ€œChallenge yourself and challenge us vendors,โ€ he urged in a keynote speech. Ask โ€œdoes this (new product) really help? Or is this another castle wall that will inevitably be breached?โ€

โ€œOur industry has adopted a defensive mindset that mimics the dark ages,โ€ he complained, with strategies of digging deeper moats and higher castle walls around enterprises.

โ€œBeyond this irrational obsession with perimeters, the security profession follows an equally absurd path to detecting these advanced threats,โ€ he said, monitoring traffic with signature- based detection and anti-malware. But, he pointed out, these solutions can only warn about threats they know about.

โ€œMany security professionals base their security programs on the futile aggregation of this virtually blind telemetry, from intrusion detection systems, AV platforms and firewall logs, implementing that glorious and increasingly useless money pit known as SIEM (security information and event management),โ€ he said.

(According to last yearโ€™s Verizon Data Breach report, less than one per cent of threats were successfully caught by SIMS systems, he pointed out).

โ€œThe single most common and most catastrophic mistake made by security teams today is under-scoping an incident and rushing to clean up a compromised system without really understanding the true scope or broader campaign,โ€ Yoran also said.

Last year was dubbed by some the year of the mega breach โ€” with breaches at Home Depot and Sony โ€” and this year may be โ€œthe year of the super mega breach.โ€

โ€œThe largest enterprises with the most sophisticated next generation security tools werenโ€™t able to stop miscreants from breaking in and making off with millions of dollars, personal information and sensitive secrets, not to mention damaging reputations,โ€ he pointed out.

But he said, security pros and the industry can do five things for success:

โ€“โ€œStop believing advanced protections work.โ€ Sometimes they do, sometimes they donโ€™t. So ask vendors if their solutions really are effective;

โ€“Adopt deep and pervasive network visibility from endpoint to the cloud to have any hope of seeing and understanding attacks. Without it, โ€œyouโ€™re only pretending to do security.โ€ It will make SIEM what itโ€™s supposed to be, he added.

โ€“End authentication and identity vulnerabilities, including having too many admin accounts. Many attacks rely on stolen credentials;

โ€“Leverage external threat intelligence, either from vendors or private industry associations. โ€œAnd for Godโ€™s sake do away with PDF and email sharing of intelligence and response co-0rdination. Weโ€™ve seen attackers specifically compromise mail servers to eavesdrop on communications between the sysop and network defenders. Ouch.โ€ ;

โ€“Understand what matters most in your organization to prioritize limited resources.

The record breaches of 2014 were โ€œyet another reminder weโ€™re losing this contestโ€ with attackers,โ€ he said. โ€œThe adversaries are outmaneovering the industry, theyโ€™re outgunning the industry, theyโ€™re winning by every possible measure.โ€

But, he concluded, for the security industry โ€œthis is not a technology problem โ€” this is a mindset problem.โ€

โ€œItโ€™s time for a new sense of exploration, awareness and understanding. Itโ€™s time for security to escape our dark ages and purse our own age of enlightenment.โ€


Related Download
Can we save the open web? Sponsor: Acquia
Can we save the open web?
Join the creator of Drupal, Dries Buytaert, in a discussion about the webโ€™s evolution, how we can put the power of the internet back into the hands of the people, and how you can prepare your organization.
Register Now


Tech Jobs

Categories