Good security news in short supply

commentary With the start of the new year, it's time to take a shot at predicting the key trends that will define the field of information security in 2006. Here goes:

Jon Oltsik New attack vectors will grow precipitously
We witnessed damaging malicious code attacks like Sober (U, V and W) and Zotob in 2005. But these outbreaks tended to cluster around e-mail or Internet worms. The bad guys will get more creative this year. Look for a big increase in the number of attacks via instant-messaging clients, Internet Protocol telephony, cell phones, Bluetooth and XML. Spyware will also become stealthier and continue to escalate from a nuisance to a real threat. Anticipate more attacks on non-Windows platforms (Linux, Unix, Macs), network infrastructure (BGP, DNS, IOS), and specific applications (backup software, databases, and so on).

Rootkits become familiar to the masses
A rootkit is an extremely clandestine type of malware that hides itself within operating system kernels or application binaries. Rootkits present a huge threat because they make subtle changes to systems to open vulnerabilities and they cover their tracks. Rootkits are also extremely hard to detect and remain invisible to most of the security software we all depend upon.

Now here's the scary part: We will see more and more rootkit attacks in 2006, so you'll likely read about them everywhere, from an internal e-mail to The Wall Street Journal. By next year, expect your retired parents in Florida to ask you about preventing and remediating rootkits -- with a real sense of urgency.

Secure development processes become mandatory
Users are simply fed up with sloppy vulnerability-ridden code and weak security support from most independent software vendors. Look for large organisations to clamp down by placing contractual demands on software providers mandating that they implement security processes and metrics or take a hike.

Microsoft is ahead of the pack in this area, while "unbreakable" Oracle lags way behind and could lose major contracts as a result.

It is important to note that mandates for secure development processes impact all software vendors, not just application and OS providers. Popular software like Hewlett-Packard's OpenView, EMC's VMWare and SAP's products will face the same scrutiny.

Security management moves to network operations
At an enterprise level, network security depends on spotting anomalous activities and capturing security events. These requirements are not unique; network operation centers have the same needs to keep the network up and running, so it is logical that these two activities move under the same roof.

As network ops takes over security oversight, expect a lot of market consolidation. Security vendors that focus on network "flow" (for instance, traffic analysis -- Arbor, Lancope, Mazu and Q1 Labs) and security incident/event management (eIQ, Intellitactics and Network Intelligence) will be scooped up and added to tools from Computer Associates International, Compuware, HP or IBM.

The number of attacks will probably decrease, but the severity will continue to rise -- think one step forward and two steps back.
Key management becomes a major new requirement
Database, networking, storage and firewall vendors either have or will add encryption to their solutions in 2006. This, of course, will set up the old information technology scenario, where there are oodles of point key management and policy management systems scattered throughout the enterprise.

Multiple key management servers create a slew of problems like redundant controls, excess overhead, security weaknesses and disaster recovery issues. As Ross Perot might say, "that dog don't hunt." The IBM mainframe group is already pitching the wisdom of centralised key management as are other pioneering start-ups. By 2007, this discussion will become commonplace.

More security outsourcing
It's hard enough to administer a firewall and intrusion detection systems, to also deal with abundant security solutions for e-mail, IP telephony, Web services, wireless devices, and so on. Complexity is the enemy of strong security, and most companies do a really poor job here. Smart companies will recognise this weakness and outsource some of their security grunt work. Dumb organisations will experience security breaches instead.

This is the just the tip of the iceberg. Suffice it to say, 2006 will likely be an ugly year. The number of attacks will probably decrease, but the severity will continue to rise -- think one step forward and two steps back.

On the plus side, large organisations will finally start to implement real enterprise-class security solutions or outsource pieces that are just too onerous to own. In the meantime, look for at least one killer security breach that tanks a large -- and previously well-reputed -- organisation.

Jon Oltsik is a senior analyst at the Enterprise Strategy Group.

Advertisement

Talkback 7 comments

    Security NewsAnonymous -- 24/01/06 (in reply to #120127816)

    Well think www.whitedust.net provides an excellent source of security news.

    I agreeAnonymous -- 12/02/06 (in reply to #120127817)

    I was going to say that having read the article. Whitedust seems to be the best out there - constantly updated and with their own papers as well. I'd suggest anyone who hasn't already check it out

    Internet banking and credit card securityDean Procter -- 10/02/06

    Good news - we have a system to render all phishing attacks and trojan attacks useless. The money is usually what the attackers are after.
    Our new system protects all credit card, Eftpos, ATM, card-not-present, and internet banking transactions, even if the attacker has the PIN password, logon, card,(even the PC) etc even if the owner is unaware that they have been compromised.
    The cost is about 1/100th of a cent per transaction. Even better the system can contact law enforcement/retail security directly at the street level.
    Once deployed we will see an end to these types of fraud.
    There will be no use in having card numbers or even the card and the pin as the thief still won't get any money, instead they're effectively alerting the police as to their location.

    Details?Anonimouse -- 23/02/06 (in reply to #120128967)

    Any more details u can give us then? url?

    I'll believe this only when I see it...

    Transaction SecurityAnonymous -- 03/03/06 (in reply to #120129729)

    I put my name on it so that those who should can freely ring me and ask me. I'm more than happy to discuss it with an interested party like a bank etc
    If you qualify email me.
    If you're actually in the business you can get my details from the USSS site.
    If not then you'll have to line up like the rest to be arrested within a minute of attempting to beat it.

    Is this guy for reaL...??????Anonymous -- 12/02/06

    Users are simply fed up with sloppy vulnerability-ridden code and weak security support from most independent software vendors. Look for large organisations to clamp down by placing contractual demands on software providers mandating that they implement security processes and metrics or take a hike.

    Microsoft is ahead of the pack in this area, while "unbreakable" Oracle lags way behind and could lose major contracts as a result.

    BWAHAHHAHAHAHHAHAHAAAA !!!!... Microsoft, security, Microsoft!!!!

    Oh well, yet another Microsoft patsy spreading some more propoganda for Bill.

    His credibility just went down the toilet.

    Research the facts - palAnonymous -- 13/02/06 (in reply to #120129165)

    Microsoft has the fastest 'vendor to patch' and has for a long time, sources Gartner, IDC, and Metagroup (prior to Gartner buying them out).

    Microsoft spends an approx 1/3 of its 7 billion USD R&D budget on security. Majority of that money is on code quality - mayber Oracle should do the same.

    Why has MS taken so many proactive steps? Because biggots like you hasseled them and went to alternative systems. Customer churn will motivate even the most hardnosed executive that they need to do something.

    Clear your mind, focus on the facts and get with the programme.

    If you like religious wars go and become a JW!

Add your opinion


Latest Videos

Blogs

  • Chris Duckett PayPal launches Aussie developer program
    PayPal announced the opening of its certification program for Australian developers today, making Australia the first country outside of the US to offer certification.
  • Array Cash cow in a BigTinCan?
    Around one third of Australia's telcos have shut their doors over time, but that isn't stopping new ventures hoping to chip away at carriers' mobile call bonanza. By fighting carriers at the smartphone rather than the home phone, could the latest two contenders be onto something big?
  • Array A third of the way to a zettabyte
    This week on Twisted Wire we look at how internet usage is changing in Australia and around the world. How are we meeting this demand and how is the cost structure changing for the service provider?
  • More blogs »

Tags

Back to top

Featured