Security & Mobility Blog

Security Automation: Easing the Way to More Secure Systems

by Juniper Employee on 10-22-2010 11:38 AM - last edited on 02-08-2011 05:16 PM

At the recent IT Security Automation Conference, U.S. Government cybersecurity experts like Howard Schmidt and Tony Sager spoke about the value of security automation and continuous monitoring. What are they talking about and can it be useful in a commercial setting?

 

Security automation is a broad topic. Basically, it involves automating the drudgery of information security so that humans can concentrate on the more interesting parts. This automation is a constant process. As security technology gets better, more things can be automated. Today, we enjoy automated detection and blocking of malware and spam, automated response to DDoS attacks, etc.

 

One early area for security automation was software patching. In the old days, patching was manual. About ten years ago, most companies moved to automated patching. Today, even home users enjoy automated patching built into the operating system. Automated patching is not perfect but the benefits (reduced effort and better security) outweigh the downsides (occasional problems caused by patches).

 

Endpoint configuration management is another area where automation is moving rapidly. Windows Group Policy provides a basic level of controls for settings like minimum password length. Enterprise security management tools extend this control to other platforms and provide valuable management features like reporting. Network Access Control products ensure uniform compliance.

 

As a huge decentralized organization, the U.S. Government has led the charge in security automation. At first, they used a decentralized approach. Agencies were graded on security measures but granted considerable flexibility in managing their own affairs. This provided ineffective, leading to the creation of a uniform Federal Desktop Core Configuration (since replaced by the United States Government Configuration Baseline). Still, security management was painful and expensive. In a 2008 memo, the Office of Management and Budget aimed to ease compliance by requiring all agencies to use the new Security Content Automation Protocol in managing endpoint security. SCAP helps agencies reduce costs by letting them import machine-readable configuration checklists, modifying them only as necessary.

 

The latest developments in security automation are real-time information sharing protocols like IF-MAP. With these protocols, security products from many vendors can work together, sharing information and alerts in real-time. If a network sensor discovers a problem, it can post an event in a standard format. Analysis and enforcement can be handled by products from other vendors. This multi-vendor approach enables users to choose the best product for each job while ensuring that the products all work together.

 

Is security automation right for you? Well, you’re already enjoying the benefits of some forms of security automation: automated malware and spam scanning, etc. The question is really how much automation you want. As with any new technology, you should learn more and try things out before you deploy them widely. But don’t ignore the potential for security automation to reduce costs and improve security when compared to manual approaches. It has already done so many times over.

Post a Comment
Be sure to enter a unique name. You can't reuse a name that's already in use.
Be sure to enter a unique email address. You can't reuse an email address that's already in use.
Type the characters you see in the picture above.Type the words you hear.
About Security & Mobility Now

Discussing a wide range of topics impacting enterprises and data center security.

Subscribe to Security & Mobility Now RSS Icon

Our Bloggers

Sanjay Beri
VP & GM, Junos Pulse Business Unit

Profile | Subscribe

Steve Hanna
Distinguished Engineer

Profile | Subscribe

Krishna Narayanaswamy
Distinguished Engineer

Profile | Subscribe

Amir Ben-Efraim
Vice President, Cloud Security

Profile | Subscribe

Ashwin Krishnan
Director, Product Management

Profile | Subscribe

Leslie Lambert
Chief Information Security Officer

Profile | Subscribe

Oliver Tavakoli
CTO, SBU

Profile | Subscribe

Ellen Brigham
Director, Product Marketing

Profile | Subscribe

Bryan Burns
Distinguished Engineer

Profile | Subscribe

Daniel V. Hoffman, CISSP, CEH, CHFI
Chief Mobile Security Evangelist

Profile | Subscribe

Peter Lunk
Director, Product Marketing

Profile | Subscribe

Chris Wee
Director, Security Services

Profile | Subscribe

Tamir Hardof
Director, Product Marketing

Profile | Subscribe

Johnnie Konstantas
Director, Product Marketing

Profile | Subscribe

Galina Pildush
Product Line Engineer

Profile | Subscribe

Bill Pfeifer
Product Line Engineer

Profile | Subscribe

Rod Bachelor
Product Line Manager

Profile | Subscribe

Ashutosh Thakur
Product Line Manager

Profile | Subscribe

Stefan Fouant
Technical Trainer

Profile | Subscribe

Seema Kathuria
Product Marketing Manager

Profile | Subscribe

Joe Tomasello
Senior Product Manager

Profile | Subscribe

Erin O'Malley
Product Marketing Manager

Profile | Subscribe

Karl Lynn
Security Research Engineer

Profile | Subscribe

Subbu Iyer
Product Line Manager

Profile | Subscribe

Gajraj Singh
Director, Product Marketing

Profile | Subscribe

Other Juniper Blogs
Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.