SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Threat prediction a flawed security approach

Threat prediction a flawed security approach

By:  Andreas Antonopoulos  On: 05 May 2008 For: Network World (US) (DW) Creator

The less we focus on specific threats and the more we accept uncertainty, the better we can prepare for new threats

Recently, I wrote about the challenge of trying to predict attacks, and how that approach leads to "anti-X" security strategies that are rapidly made obsolete by each new wave of threats.

The strategy of threat prediction suffers from two major flaws. First, it assumes predictability in a field that is full of surprises. Security is adversarial, and the adversaries already knows what we are doing -- they can read this magazine, for example. New attacks are not designed in a vacuum; they are designed explicitly to sidestep our expectations. If we base our defenses on predicted threats, attackers sidestep our defenses when they sidestep our expectations.

Second, threat prediction causes tunnel vision. It pushes us to focus on attacks rather than assets, on the "bad" rather than the "valuable." This plays right into the hands of attackers, as tunnel vision narrows our defenses thereby making them easier to bypass. Rather than trying to predict threats, we should focus on general security preparedness.

Read more

For more articles on security issues, visit IT World Canada's Security Knowledge Centre

After all, there is no such thing as a "secure" company or system. Everything can be broken with enough effort and money. Secure companies are not those that do not get breached; every company will suffer a security failure (or several) sooner or later. Rather, secure companies are those that minimize both the incidence of successful attacks and then further minimize the impact of those few breaches. Accepting breaches as normal, business-as-usual and unavoidable puts the emphasis on preparedness rather than prediction.

Of course, this does not invalidate the need to establish defenses and controls that are specific. Just like a flu shot in the fall, you may take precautions against specific threats that are known and predictable. But most companies put a lot less emphasis on preparedness that they do on specific threats. We have seen this in our research year after year, where we find very few companies with specific, well designed and well drilled incident-response policies. It's as if "incidents" represent the failure of security that no one wants to acknowledge. "Incidents" are of course the norm, not the exception. To repeat a biological example, we should be putting a lot more emphasis on frequent hand washing while keeping some chicken soup in stock, rather than trying to find more vaccines to take every fall.

Security preparedness favours the operational over the technological and the generic over the specific. The emphasis on operational security means more skilled people and fewer shiny appliances. The emphasis on the generic means more broad security controls (encryption, authentication, audit and monitoring) rather than specific silver bullets (anti-X). Uncertainty makes us uncomfortable but in fact is an ally. The less we focus on specific threats and the more we accept uncertainty, the better we can prepare for new threats.


Sign up for our Newsletters
Tags: preparedness












Print |  Views: 566   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Andreas Antonopoulos Andreas Antonopoulos is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Mistakes, not insiders, to blame for most breaches
Mistakes, not insiders, to blame for most breaches While many security vendors have been banging the drum about the threat of malicious insiders, this report indicates organizations should be more wary of outside attacks
Cyber crooks exploit recession, social media in '09
Cyber crooks exploit recession, social media in '09Cybercrime becomes all about building online communities, as crooks step up efforts to take advantage of the global fear over the recession and harness emerging social net technologies to spread malware
One in five Canuck firms report security violations
One in five Canuck firms report security violationsAccording to a new survey by CA Canada, enterprise data breaches caused by security attacks have doubled since 2006. Info-Tech’s James Quin notes not all breaches necessarily cause harm but the feds should mandate encryption.
Fortinet lists August’s most dangerous online threats
two viruses disguised as security software antivirus xp 2008 and xp security center have topped fortinet’s top 10 list of august’s most reported online threats. the sunnyvale, cali
blog comments powered by Disqus