Playing defense

Defense is everything when it comes to system security. Unfortunately the really big (government) money appears to be (foolishly) concentrated on offense. Some good news below from this year’s DEFCON.

Over the last few days we’ve discovered that the offense-centric strategies being employed by the U.S. and its allies have actually degraded our ability to effectively defend against attacks by other states and even economic competitors.

Sort of like pulling the trigger and hitting your friend in the face with bird shot because you had insufficient situational awareness.

Taking no account for predictable consequences is a key indicator of incompetence, or anarchy. Where I come that kind of thing gets you hired. Apparently in other places it gets you a government pension.

Alexandre Pinto’s talk at DEFCON 21 focused on using machine learning in defending networks. Defending Networks with Incomplete Information runs under an hour and could provide hope for those who have tried SEIM (Security Event and Incident Management) solutions and found them wanting.

I especially appreciated his comparison of SEIM with Identity Management projects for their budget-busting qualities. From Alexandre’s video notes:

Let’s face it: we may win some battles, but we are losing the war pretty badly. Regardless of the advances in malware and targeted attacks detection technologies, our top security practitioners can only do so much in a 24 hour day. Even less, if you let them eat and sleep. On the other hand, there is a severe shortage of capable people to do “simple” security monitoring effectively, let alone complex incident detection and response.

Enter the use of Machine Learning as a way to automatically prioritize and classify potential events and attacks as something can could potentially be blocked automatically, is clearly benign, or is really worth the time of your analyst.

This entry was posted in Security, System Administration on by .

About phil

My name is Phil Lembo. In my day job I’m an enterprise IT architect for a leading distribution and services company. The rest of my time I try to maintain a semi-normal family life in the suburbs of Raleigh, NC. E-mail me at philipATlembobrothersDOTcom. The opinions expressed here are entirely my own and not those of my employers, past, present or future (except where I quote others, who will need to accept responsibility for their own rants).