Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Unfair and Deceptive Practices in the Cloud | Main | Social Networking for Developers Still Coming Up Short »

Rethinking Cybersecurity Strategies

The New York Times article U.S. Steps Up Efforts in Digital Defenses mentions vague references to increasingly sophisticated attacks on U.S. cyberinfrastructure. Even with few details, the article paints a clear picture: our usual methods for securing IT systems are not enough.

"The fortress model simply will not work for cyber," said one senior military officer who has been deeply engaged in the debate for several years. "Someone will always get in."

So what do we do? When dealing with symmetric threats, like another nation, the U.S. can threaten retaliation as long as it has a credible cyberwarfare capability. That doesn't work for asymmetric threats, like those from a band of nationalistic attackers, and it certainly isn't an option for businesses.

We can take a lesson from evolution which has managed to produce a wide array of organisms that can survive in environments riddled with pathogens, like bacteria and viruses.

Design patterns like redundant systems, feedback loops and ability to identify malicious agents are part of the solution. Consider one example. Our immune systems can detect chemical markers on cells that don't belong in the body; digital identification mechanisms serve and analogous function in distributed systems. We know a request is valid if it is accompanied by a digital certificate from someone with authorization to request the service. Being able to reliably identify an agent operating in your environment (biological or digital) is a basic requirement of robust security. There are more but this demonstrates the idea.

The burden of securing infrastructure is becoming more a matter of how we design complex systems to be resilient and less about building walls and keeping the bad guys out.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/1034

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net