Friday, December 11, 2009

Focused too much on perimeter protection?

Security experts at the Government Technology Research Alliance Council meeting held this week in Pennsylvania discussed the challenges facing cybersecurity professionals in 2010.  You can read the article in Government Computer News here.  Too much focus on network-layer defenses seems to be a major problem plaguing the cybersecurity community.  Heavy reliance on signature based tools means reacting to only the known, while heuristic based tools rely on past experience.  With the emergence of new and more sophisticated attacks, these types of tools are often simply not enough.  Using more sophisticated cybersecurity tools in addition to signature and heuristic based options would go a long way towards greater IT security.  It's also important to remember that threats can originate internally and many sources will suggest that internal threats, while fewer in number, often have more catastrophic consequences than external threats.  Increasing utilization of tools that don't rely on signatures or heuristics, and do not differentiate between internal or external threats can help those in both the government and commercial space stay one step ahead of emerging and unknown threats whether internal or external.

No comments:

Post a Comment