|
||||||||||
| Innovating The Next Big Thing | June 18, 2013 | |||||||||
|
Sections • Analyst Insights • Enterprise Insights • Network & Information Security • Enterprise Mobility • Remembering 9/11 • About Next Innovator Group
• TechnologyInnovator Contact
• NextInnovator(at)Live.com Writers Wanted
Feedjit Live Web Stats
Next Innovators
• Ghost City McAfee AudioParasitics
Barry's Books
Ads
|
McAfee Blogs: On the Road to True Connected Security
Aug 2, 2012 – Tyler Carter Here’s a quick summary of my webcast yesterday on next-generation network security. There’s a lot of hype about the changing threat landscape and challenges to traditional security strategies. The reality is that we need both familiar and new tools as we evolve the conversation from point-based solutions, which typically protect one stage in an attack sequence, to integrated, connected solutions – the best way to protect against next-generation attacks. Some hard truths about security today:
In the face of all this complexity, firewalls are a powerful but not total solution. Firewalls place an emphasis on enforcing policy and limiting and controlling access. They’re more effective at deterring broad-scale attacks than smaller, targeted ones. Security is an ongoing battle that can’t be won with a single weapon; you need a concert of weapons and individuals. The best approach is a framework that facilitates a connected approach to security. We haven’t always referred to it this way, but McAfee has had a “next-generation” IPS (intrusion protection system) in place for some time. It combines traditional IPS with more advanced elements like behavior analysis, application awareness, and network visibility. More and more, the threat prevention paying field is going to focus on anomaly detection heuristics – behavior analysis – in addition to the traditional safeguards. With a platform approach that spans an entire network, using the same tools throughout the infrastructure and coordinating threat response, we now have heightened “context awareness” that highlights anomalies. We can tell when a machine starts behaving in unexpected ways – when a computer known to be someone’s personal device starts acting like a mail server, for example. We can tell when a user’s browsing or protocol behavior changes. As for content awareness, nearly all security vendors still use signature detection as a baseline defense – it’s not true that those strategies are “dead,” as some claim – but we increasingly use reputation data, measuring a current file or IP address against past data, and file anomaly detection. (If a PDF seems to be running an executable, for example, it begs for attention.) Botnet detection is as big an issue as ever; we can look a dozens of heuristics to identify a bot on the network. When a system reaches out to many IP addresses in rapid-fire fashion, for example, that profile says “bot” very quickly. It adds up to more accurate, timely threat detection; these additions improve security defenses by up to 30 percent compared to signature defense alone. Beyond heuristic analysis, the next big value-add is generation and analysis of an enterprise-wide data layer with the help of external intelligence. Part of McAfee’s Security Connected framework is McAfee Event Reporter, a log management tool that collects and correlates millions of events from across the organization. A correlation engine analyzes them against reputation data from the cloud, isolates threatening trends, and even identifies particular events based on historical data. This turns a simple log manager or event manager into a security solution and generates a global, company-wide view of your risk posture. It doesn’t even require an all-McAfee technology landscape across the organization; the big idea here is to strive for a connected approach. To get on the road to a true connected security posture, I think you need a construct that lets you leverage “next-generation” benefits like these without forgetting about traditional safeguards. You may have a stack of individually effective one-off security solutions, but the changing threat landscape and the available streamlining potential say it’s time to combine them into a single, connected approach. In a world of more genuine threats and mushrooming network complexity, it’s the best way to stay ahead. » Send this article to a friend... » Comments? Tell us what you think... » More Network & Information Security articles... Comments
blog comments powered by Disqus
Search EnterpriseInnovator
|
Support This Site Newest Articles • 6/17 McAfee Blogs: The Defense Department Lists Mobile Security as a Top Priority • 6/17 McAfee Blogs: The Strategic Consumer • 6/17 McAfee Blogs: Keeping Your Small Business Safe from Cyberattacks • 6/17 McAfee Blogs: Exciting Times for SMBs at National Small Business Week! • 6/17 McAfee Blogs: Why whitelisting is ready for Enterprise desktops • 6/13 Gartner Says Cloud Office Systems Total 8 Percent of the Overall Office Market and Will Rise to 33 Percent by 2017 • 6/13 Gartner Says Worldwide External Controller-Based Disk Storage Market Grew 0.6 Percent in First Quarter of 2013 • 6/13 Faultline: Vodafone Kabel Deutschland talks confirmed, deal could be dusted in days • 6/13 Faultline: Comcast sneaks in Homespot revolution as “Neighborhood Hotspots” • 6/13 McAfee Blogs: Two Steps are Better Than One: Make a Hacker’s Job Harder with Two-step Verification • 6/12 Gartner Announces Keynote Speakers for its Supply Chain Executive Conference 2013 in Australia • 6/12 Gartner Says by 2019, 90 Percent of Organizations Will Have Personal Data on IT Systems They Don't Own or Control • 6/12 iSuppli: Doing What It Does Best: Apple Reinvents Existing iPhones with iOS7 and Competitive Music Launch • 6/12 McAfee Blogs: Moving up with McAfee Complete Endpoint Protection • 6/12 McAfee Blogs: Can you answer these three smart business questions about authentication? • 6/12 HP Security lab Blog: Top 10 things for security people to do at HP Discover 2013 - Las Vegas, NV • 6/12 HP Security Lab Blog: HP introduces HAVEn to combat $4 billion cyber-theft in Big Data space • 6/11 Gartner Says Worldwide Security Market to Grow 8.7 Percent in 2013 • 6/11 Gartner Says Less than 10 Percent of Enterprises Have a True Information Strategy • 6/10 Ovum: Analyst view: Google to buy Waze • 6/10 Ovum: Analyst view: Apple acknowledges the need for user interface refresh and is willing to do something pretty dramatic • 6/10 Gartner Forecasts Indian Business Intelligence Software Revenue to Reach $113 Million In 2013 • 6/10 iSuppli: It’s a Tie: Bosch and STM Hold Joint Honors as No. 1 MEMS Suppliers for 2012 • 6/10 iSuppli: 1.3GW of PV Installations Eliminated by EU Anti-Dumping Duties in 2013; Double-Digit Global Growth Still Likely • 6/10 Wireless Watch: Small Cell World Summit: industry poised to kickstart volume roll-outs • 6/10 Wireless Watch: Cisco seeks leading role in wireless via small cells • 6/10 McAfee Blogs: Syrian Crisis Reminds Us to Beware of ‘Charity’ Scams • 6/9 Frontline Sentinel: Whistleblower (Edward Snowden) Behind the NSA Surveillance Speaks Out [Interview] • 6/9 Slate: If the NSA Trusted Edward Snowden With Our Data, Why Should We Trust the NSA? • 6/8 Gartner Says Business Analytics Will Be Central for Business Reinvention • 6/8 Frontline Sentinel: Practical Tips to Improve Network Security with What You Already Have: Part 2 of 2 • 6/7 Gartner Says India Enterprise Software Market To Reach $3.92 Billion in 2013 • 6/7 iSuppli: Event Cinema Market Takes Off in Europe • 6/7 McAfee Blogs: Koobface Count Correction • 6/6 Ovum: Ovum announces winners of inaugural “BYOX Strategy” awards • 6/6 Ovum: Analyst view: SFDC acquisition of ExactTarget is expensive, but offers significant product synergies • 6/6 Gartner Says Worldwide Business Intelligence, CPM and Analytic Applications/Performance Management Software Market Grew Seven Percent in 2012 • 6/6 Faultline: Cloud browsers to gut the set top market – ActiveVideo leading the chase • 6/6 Faultline: TiVo wins its biggest ever settlement - share price barely nods • 6/6 Canalys: Canalys launches ‘Partner Program Analysis’ service - The latest addition to Canalys’ leading channels research offerings • 6/6 McAfee Blogs: Forgo Pressure to ‘Share’ and Boost Your Privacy • 6/6 McAfee Blogs: Summer Web Safety: A Cautionary Tale About The Internet • 6/6 McAfee Blogs: Malicious Dating, Ad Services Plague Japanese Users • 6/6 McAfee Blogs: Locking Down Desktops With McAfee’s Application Control • 6/6 McAfee Blogs: Fraudulent Adult Dating Services Turn 10 Years Old, Still Evolving • 6/6 HP Security Lab Blog: Combating professional security threats • 6/5 Ovum: Ovum warns BYOD is here to stay and urges CIOs to respond with a clear strategy • 6/5 What to Expect at Apple's WWDC • 6/5 Gartner Says Organizations Must Treat Information as an Asset in its Own Right • 6/5 Gartner Looks At The Impact of U.S. Visa Legislation on India Offshore Outsourcing in Upcoming Webinar Barry's Books
Ads
|
||||||||
| Top | ||||||||||