<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Inspirasi dan Ide &#187; IT Industry</title>
	<atom:link href="http://ariesaryanto.com/tag/it-industry/feed" rel="self" type="application/rss+xml" />
	<link>http://ariesaryanto.com</link>
	<description>Inspirasi &#124; Ide &#124; Network</description>
	<lastBuildDate>Mon, 27 Jul 2009 07:17:35 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>7 dirty secrets of the security industry</title>
		<link>http://ariesaryanto.com/7-dirty-secrets-of-the-security-industry</link>
		<comments>http://ariesaryanto.com/7-dirty-secrets-of-the-security-industry#comments</comments>
		<pubDate>Thu, 08 May 2008 07:54:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[IT Industry]]></category>
		<category><![CDATA[Security Industry]]></category>

		<guid isPermaLink="false">http://ariesaryanto.com/?p=13</guid>
		<description><![CDATA[Corporate IT executives need to beware the seven dirty secrets of the security industry that can undermine the safety of business networks, a security expert told attendees at Interop Las Vegas.“It’s best to have a healthy level of skepticism about what security vendors are trying to tell you,” says Joshua Corman, principal security strategist for [...]]]></description>
			<content:encoded><![CDATA[<p align="left">Corporate IT executives need to beware the seven dirty secrets of the security industry that can undermine the safety of business networks, a security expert told attendees at <a href="http://www.networkworld.com/news/2008/042108-interop-top-stories.html"><span style="color: black; text-decoration: none">Interop Las Vegas</span></a>.“It’s best to have a healthy level of skepticism about what security vendors are trying to tell you,” says Joshua Corman, principal security strategist for IBM/ISS, which itself is a security vendor.<br />
<span style="color: black">He called his talk &#8220;Unsafe at any speed: 7 Dirty Secrets of the Security Industry,&#8221; harkening back to the 1960s’ Ralph Nader book about automobile safety, <em>Unsafe at Any Speed</em>. Nader’s book took car makers to task for worrying more about cosmetic improvements that upgrades to make cars more safe. <o:p></o:p><br />
Security vendors have at times invested development money in management GUIs rather than new security features. And they have a tendency to add features only when customers demand them, he says. “The goal of the security vendor is not to secure, it’s to make money,” Corman says. <o:p></o:p><br />
He says that is his “zeroth” dirty secret of the security industry. These are the other seven:<o:p></o:p></span><br />
<strong><span style="color: black">1. Antivirus certifications are misleading.</span></strong><span style="color: black"> <o:p></o:p><br />
The certification standards confirm that devices block 100% of all replicating malcode. The catch is that 75% of malcode coming into networks is non-replicating, such as Trojans. When the standard was set, non-replicating malcode represented 5% of malcode, Corman says. “Certification means [a product] caught 100% of 25% of the bad stuff,” he says. (Compare <a href="http://www.networkworld.com/buyersguides/guide.php?cat=865465"><span style="color: black; text-decoration: none">antivirus</span></a> products) <o:p></o:p></span><br />
<strong><span style="color: black">2. There is no perimeter</span></strong><span style="color: black">. <o:p></o:p><br />
Vendors say that the <a href="http://www.networkworld.com/news/2007/091007-jericho-forum-firewalls.html"><span style="color: black; text-decoration: none">network perimeter must be defended</span></a>, but most data that is actually lost doesn’t go through the firewall. Half of all <a href="http://search.networkworld.com/query.html?qt=data+breaches&amp;"><span style="color: black; text-decoration: none">breaches</span></a> are the result of either lost laptops or lost thumb drives or other removable media. Businesses need to tighten up their business processes at least as much as they need to tighten up network perimeters, he says. “If you still believe in perimeters, you may as well believe in Santa Claus,” he says. <o:p></o:p></span><br />
<strong><span style="color: black">3. Risk analysis threatens vendors.</span></strong><span style="color: black"> <o:p></o:p><br />
Security vendors want businesses to buy what they sell, so they push specific products to block specific threats. NAC, for example, might solve a real problem. But if the problem doesn’t have a major impact on the company’s top three business priorities, it probably doesn’t need to be addressed. <a href="http://www.networkworld.com/columnists/2007/111907-risk-reward.html"><span style="color: black; text-decoration: none">Risk assessment</span></a> may determine that improved business processes or hardening configurations of existing gear are all that are needed, Corman says. “You need to understand the environment and the big priorities,” he says. <o:p></o:p></span><br />
<strong><span style="color: black">4. There is more to risk than just weak software.</span></strong><span style="color: black"> <o:p></o:p><br />
Security vendors push protecting against software vulnerabilities, but those <a href="http://www.networkworld.com/columnists/2007/101807-backspin.html"><span style="color: black; text-decoration: none">flaws don’t represent the source</span></a> of the bulk of successful exploits, Corman says. Weak passwords, weak configurations of devices &#8211; particularly default configurations &#8211; and weak people &#8211; easy victims of social engineering, are bigger problems, he says. “If software were perfect, we’d still have viruses, Trojans, etc., that don’t need software flaws to work,” he says.<o:p></o:p></span><br />
<strong><span style="color: black">5. Compliance threatens security.</span></strong><span style="color: black"> <o:p></o:p><br />
Compliance itself is not bad, but complying with security standards set by government, such as HIPAA, or industries, such as PCI, are not enough to keep networks secure, Corman says. The problem is that regulations create a budget and resource conflict between what compliance demands and what network executives think really needs doing to best secure the business it supports. Complying with such standards also signals to potential attackers the exact defenses businesses have. “If PCI tells them where the fortifications are and they start targeting other areas,” he says. (Compare <a href="http://www.networkworld.com/buyersguides/guide.php?cat=865475"><span style="color: black; text-decoration: none">Network Auditing and Compliance</span></a> products) <o:p></o:p></span><br />
<strong><span style="color: black">6. Vendor blind spots allowed the Storm worm outbreak to happen.</span></strong><span style="color: black"> <o:p></o:p><br />
Corporate defenses that check behavior of network devices can spot machines taken over by the bot network, but there is no such protection for consumer networks. Behavior-based antivirus software for endpoints and anomaly detection systems also work, but not for those who don’t have them, he says. “<a href="http://www.networkworld.com/news/2008/011008-storm-splinters-starts-phishing-say.html"><span style="color: black; text-decoration: none">Storm recognized the biggest blind spots</span></a> in antivirus and exploited them, and Storm employs great social engineering,” Corman says. <o:p></o:p></span><br />
<strong><span style="color: black">7. Security has grown well past do-it-yourself.</span></strong><span style="color: black"> <o:p></o:p><br />
Security vendors try to convince businesses that <a href="http://www.networkworld.com/news/2007/120507-warning-accountability-should-not-be.html"><span style="color: black; text-decoration: none">security is so complex</span></a> that they cannot possibly do it alone, Corman says. But the security needs of businesses are so individual that merely choosing a product is not enough. “It’s not enough to have the right tool. It needs to be installed and configured properly for the environment,” he says, and that can best be done by the IT staff itself. <o:p></o:p></span></p>
<p align="left">&nbsp;</p>
<p class="MsoNormal" align="left"><span style="color: black"><o:p> </o:p></span></p>
]]></content:encoded>
			<wfw:commentRss>http://ariesaryanto.com/7-dirty-secrets-of-the-security-industry/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
