Security & Mobility Blog

Giving Thanks for Security Progress

by Juniper Employee on 11-22-2011 12:04 PM - last edited on 11-22-2011 12:04 PM

In the Information Security field, we're faced with a constant barrage of bad news: new vulnerabilities, exploits, and successful attacks. When we do our jobs well, there's no news at all. Just an absence of bad news as systems hum along normally and the ever-present storm of attacks is deflected. But maybe it's good once a year to reflect on the good news of information security. So let's take a few minutes to give thanks for some pieces of good news from this year.

 

Sharing Best Practices

 

Information security has traditionally been a black art. However, we are making progress in this area. The CISSP certification and the CISSP Common Book of Knowledge have established common standards for the industry. The latest advance in the state of the art is the widespread adoption of the SANS Top 20 Critical Security Controls and the Australian DSD's Top 35 Mitigation Strategies. These lists of recommended controls are not just opinions. They're based on analysis of actual incidents to determine which controls were most effective.

 

Fruitful Cooperation Among Industry & Government

 

While individual parties can locally block a particular attack, global action generally requires multi-party coordination. This year has seen several examples of such coordinated action: the takedown of the Rustock and Coreflood botnets and the DIB Cyber Pilot. The ISACs continue their good work but it's encouraging to see some demonstrable value coming out of industry-government cooperation. And private companies and security practioners have also been working together to create and improve collective defenses: in ISSA, TSCP, I-4, TCG, and other forums.

 

Increased Funding for Cybersecurity Research

 

Today, defending a network or information system is much harder than attacking one. To change these dynamics, we need new approaches to cybersecurity. So it's encouraging to see that DARPA is planning to increase its spending for cybersecurity research from $120M in FY2011 to $208M in FY2012.  This research may not pay off for years but it's good to see that senior executives are giving the problem the attention that it deserves.

 

Serious Attacks on Embedded Systems

 

Serious security folks have known for years that embedded systems are rarely secure. But utilities, chemical plants, and manufacturing facilities are critically dependent on embedded systems, as part of Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems. The prevalent security control in such environments is to isolate insecure production systems from the Internet and from corporate networks. This year, Stuxnet pointed out the many flaws in this approach. And Stuxnet was just the start. Duqu and many others are rapidly expanding these attacks.
Does this seem like bad news? Well, sometimes bad news can be good news. The first step to solving a problem is awareness. Many eyes have been opened this year and thousands of people are working on creative solutions. Next year should see those being delivered, just as the wave of attacks begins to crest.

 

Planning for Next Year

 

As we plan for next year's cybersecurity activities, let's remember the lessons from this past year's successes:

 

  • Share Best Practices With Others
  • Work With Others for Maximum Impact
  • Raise Awareness of Risks
  • Use Increased Awareness to Drive Increased Funding

If we keep these lessons in mind, we may have a lot more to be thankful for next year.

Post a Comment
Be sure to enter a unique name. You can't reuse a name that's already in use.
Be sure to enter a unique email address. You can't reuse an email address that's already in use.
Type the characters you see in the picture above.Type the words you hear.
About Security & Mobility Now

Discussing a wide range of topics impacting enterprises and data center security.

Subscribe to Security & Mobility Now RSS Icon

Our Bloggers

Sanjay Beri
VP & GM, Junos Pulse Business Unit

Profile | Subscribe

Steve Hanna
Distinguished Engineer

Profile | Subscribe

Krishna Narayanaswamy
Distinguished Engineer

Profile | Subscribe

Amir Ben-Efraim
Vice President, Cloud Security

Profile | Subscribe

Ashwin Krishnan
Director, Product Management

Profile | Subscribe

Leslie Lambert
Chief Information Security Officer

Profile | Subscribe

Oliver Tavakoli
CTO, SBU

Profile | Subscribe

Ellen Brigham
Director, Product Marketing

Profile | Subscribe

Bryan Burns
Distinguished Engineer

Profile | Subscribe

Daniel V. Hoffman, CISSP, CEH, CHFI
Chief Mobile Security Evangelist

Profile | Subscribe

Peter Lunk
Director, Product Marketing

Profile | Subscribe

Chris Wee
Director, Security Services

Profile | Subscribe

Tamir Hardof
Director, Product Marketing

Profile | Subscribe

Johnnie Konstantas
Director, Product Marketing

Profile | Subscribe

Galina Pildush
Product Line Engineer

Profile | Subscribe

Bill Pfeifer
Product Line Engineer

Profile | Subscribe

Rod Bachelor
Product Line Manager

Profile | Subscribe

Ashutosh Thakur
Product Line Manager

Profile | Subscribe

Stefan Fouant
Technical Trainer

Profile | Subscribe

Seema Kathuria
Product Marketing Manager

Profile | Subscribe

Joe Tomasello
Senior Product Manager

Profile | Subscribe

Erin O'Malley
Product Marketing Manager

Profile | Subscribe

Karl Lynn
Security Research Engineer

Profile | Subscribe

Subbu Iyer
Product Line Manager

Profile | Subscribe

Gajraj Singh
Director, Product Marketing

Profile | Subscribe

Other Juniper Blogs
Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.