Feeds

Infosec 'needs warrior cryptoboffins' to beat hackers

Drop and give me 50 better data sets, maggot

Beginner's guide to SSL certificates

RSA Europe The infosec industry needs to move beyond "faith-based security" to an evidence-based approach that takes ideas from battlefield combat if corporations are ever to get ahead of hackers and keep security spending down to manageable levels.

Joshua Corman, director of security intelligence at Akamai, argued that while almost every enterprise attempts to develop security metrics for its environment, these approaches are more akin to "numerology" than hard science.

Raw data and numbers are rarely available in the field of information security and, when they are, they tend to get misquoted or misunderstood, according to Corman. For example, a widely cited misquote from a Verizon data breach report – "90 per cent of breaches in 2008 were due to patchable vulnerabilities where a patch had been available for 12-18 months" – is often taken as a basis by enterprises for developing a security policy.

In truth the sentence needed to be qualified "of the 22 per cent that were patchable [the patch had been available for more than a year]. By 2009, only 6.7 per cent (six of 90) breaches stemmed from patchable vulnerabilities. The following year, zero breaches were due to patchable vulnerabilities.

Despite this, most CISOs have programs to "patch faster" while adversaries have moved elsewhere".

Another problem is that advice designed to address the main security shortfalls in small businesses is sometimes misapplied to large enterprises. Raw data on accidents can be applied to draw up actuarial tables for insurance purposes, but the same approach doesn't work in information security, according to Corman.

"Collecting data and numbers to try to develop actuarial tables for security just doesn't work because the problem space just isn't like that," Corman argued. "Information security is less about actuarial tables and more about game theory."

Vendor-supplied statistics are often misleading, Corman told El Reg. "Vendors pluck out figures that support their sales pitch. They use statistics like a drunk uses lampposts – more for support than illumination."

Rather than taking lessons from industry surveys, analyst reports or vendor-supplied arguments, security managers should look to lessons from military doctrine. The "observe, orient, decide and act" loop can be applied as well to fighting cyber-adversaries with unknown capabilities and tactics as it is in battlefield situations, according to Corman.

Corman is due to expand on his ideas during a conference debate snappily entitled Metrics are Bunk!?: A Zombie Apocalypse, Football/Soccer & Security Metrics at the RSA Conference in Europe on Thursday. ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.