SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Information Architecture >> Identity Management

IBM executive targets online criminals

IBM executive targets online criminals

By:  Denise Dubie  On: 03 Jul 2007 For: Network World (U.S.) Creator

Kris Lamb, director of X-Force, IBM's primary security research organizaiton talks about what he sees as the most critical challenges and opportunities facing enterprise IT security managers today.

At IBM Internet Security System's, the company's primary security research organization is called X-Force. Kris Lamb, director of X-Force, says his group is charged with knowing where potential threats will arise and deliver product, services and education to customers about how to stay ahead of the risk. Recently Lamb discussed with Network World Senior Editor Denise Dubie what he sees as the most critical challenges and opportunities facing enterprise IT security managers today.

Tell me a bit about your role as director of X-Force at IBM Internet Security Systems.

We are the thought leaders for our customers and the company around applied security technology, the security landscape, threat forecasting, creation of new technology solutions that we may bring to market in the form of new products or new service offerings.

We also provide the content delivery services for all of our products that we currently sell, such as antivirus updates or IPS updates or content filtering updates are delivered out of the X-Force organization.

We also have a consulting portion of X-Force that delivers security consulting services to our clients. All told X-Force is a sizeable organization made up of a lot of research and development disciplines that are centered on security expertise.

What are some major trends or changes in the security industry X-Force is currently tracking?

Over the last 12 to 18 months or so, we've seen the hard right turn of the criminal underground shifting from a notoriety-driven motivation to a very highly-organized financially-driven motivation. Money is really driving what they do. All of the security vulnerabilities or exploits or computers they control represent real dollars to them given the activities they are using these resources for.

Before it was about notoriety, it was about being seen or noticed, or getting a lot of press coverage by Web site defacements and denial of service attacks that were very public. Now the criminals don't want to be detected because when they are detected they lose control of the computing resources and they are not able to engage in the criminal activities such as computer bot exploitation or malware spreading or phishing recruitment runs.

They lose those assets or the ability to conduct those activities and that means they are losing money. The criminal underground is now engaging in very shrewd, very guarded sets of activities.

How does this motivation shift change security threats?

A real big philosophical and structural change is happening. We are seeing the threat landscape go through a major change. Over the last 12 months, the types of threats and attacks that are being exploited and really being used in the criminal underground are much more application-centric and browser-centric in nature.

Rather than the vulnerabilities of old that were more operating system related and low level in nature, whether is be default Windows or Unix services these vulnerabilities are still being found and leveraged, but by and large the motivation and the areas of threat research going on among the criminal underground are around highly repeatable, highly undetectable types of attacks.


Sign up for our Newsletters












Print |  Views: 729   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Denise Dubie Denise Dubie is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Cyber crooks exploit recession, social media in '09
Cyber crooks exploit recession, social media in '09Cybercrime becomes all about building online communities, as crooks step up efforts to take advantage of the global fear over the recession and harness emerging social net technologies to spread malware
How to not have your Web site hacked like Sony's
How to not have your Web site hacked like Sony'sA SQL injection attack was used to plant malicious code on pages of two popular Sony Playstation games - SingStar Pop and God of War, reports security company Sophos. Hundreds of Web pages from other businesses have also been compromised.
Cisco, IBM, Intel, Juniper, MS fight cyber terror together
Cisco, IBM, Intel, Juniper, MS fight cyber terror togetherIndustry Consortium for Advancement of Security on the Internet (ICASI) is a nonprofit organization designed to let vendors and customers work together on global IT security threats and resolve them in a government-neutral way
Fortinet lists August’s most dangerous online threats
two viruses disguised as security software antivirus xp 2008 and xp security center have topped fortinet’s top 10 list of august’s most reported online threats. the sunnyvale, cali
blog comments powered by Disqus