Good security news in short supply

commentary With the start of the new year, it's time to take a shot at predicting the key trends that will define the field of information security in 2006. Here goes:

Jon Oltsik New attack vectors will grow precipitously
We witnessed damaging malicious code attacks like Sober (U, V and W) and Zotob in 2005. But these outbreaks tended to cluster around e-mail or Internet worms. The bad guys will get more creative this year. Look for a big increase in the number of attacks via instant-messaging clients, Internet Protocol telephony, cell phones, Bluetooth and XML. Spyware will also become stealthier and continue to escalate from a nuisance to a real threat. Anticipate more attacks on non-Windows platforms (Linux, Unix, Macs), network infrastructure (BGP, DNS, IOS), and specific applications (backup software, databases, and so on).

Rootkits become familiar to the masses
A rootkit is an extremely clandestine type of malware that hides itself within operating system kernels or application binaries. Rootkits present a huge threat because they make subtle changes to systems to open vulnerabilities and they cover their tracks. Rootkits are also extremely hard to detect and remain invisible to most of the security software we all depend upon.

Now here's the scary part: We will see more and more rootkit attacks in 2006, so you'll likely read about them everywhere, from an internal e-mail to The Wall Street Journal. By next year, expect your retired parents in Florida to ask you about preventing and remediating rootkits -- with a real sense of urgency.

Secure development processes become mandatory
Users are simply fed up with sloppy vulnerability-ridden code and weak security support from most independent software vendors. Look for large organisations to clamp down by placing contractual demands on software providers mandating that they implement security processes and metrics or take a hike.

Microsoft is ahead of the pack in this area, while "unbreakable" Oracle lags way behind and could lose major contracts as a result.

It is important to note that mandates for secure development processes impact all software vendors, not just application and OS providers. Popular software like Hewlett-Packard's OpenView, EMC's VMWare and SAP's products will face the same scrutiny.

Security management moves to network operations
At an enterprise level, network security depends on spotting anomalous activities and capturing security events. These requirements are not unique; network operation centers have the same needs to keep the network up and running, so it is logical that these two activities move under the same roof.

As network ops takes over security oversight, expect a lot of market consolidation. Security vendors that focus on network "flow" (for instance, traffic analysis -- Arbor, Lancope, Mazu and Q1 Labs) and security incident/event management (eIQ, Intellitactics and Network Intelligence) will be scooped up and added to tools from Computer Associates International, Compuware, HP or IBM.

The number of attacks will probably decrease, but the severity will continue to rise -- think one step forward and two steps back.
Key management becomes a major new requirement
Database, networking, storage and firewall vendors either have or will add encryption to their solutions in 2006. This, of course, will set up the old information technology scenario, where there are oodles of point key management and policy management systems scattered throughout the enterprise.

Multiple key management servers create a slew of problems like redundant controls, excess overhead, security weaknesses and disaster recovery issues. As Ross Perot might say, "that dog don't hunt." The IBM mainframe group is already pitching the wisdom of centralised key management as are other pioneering start-ups. By 2007, this discussion will become commonplace.

More security outsourcing
It's hard enough to administer a firewall and intrusion detection systems, to also deal with abundant security solutions for e-mail, IP telephony, Web services, wireless devices, and so on. Complexity is the enemy of strong security, and most companies do a really poor job here. Smart companies will recognise this weakness and outsource some of their security grunt work. Dumb organisations will experience security breaches instead.

This is the just the tip of the iceberg. Suffice it to say, 2006 will likely be an ugly year. The number of attacks will probably decrease, but the severity will continue to rise -- think one step forward and two steps back.

On the plus side, large organisations will finally start to implement real enterprise-class security solutions or outsource pieces that are just too onerous to own. In the meantime, look for at least one killer security breach that tanks a large -- and previously well-reputed -- organisation.

Jon Oltsik is a senior analyst at the Enterprise Strategy Group.

Advertisement

Talkback 7 comments

    Security News Anonymous -- 24/01/06 (in reply to #120127816)

    Well think www.whitedust.net provides an excellent source of security news.

    I agree Anonymous -- 12/02/06 (in reply to #120127817)

    I was going to say that having read the article. Whitedust seems to be the best out there - constantly updated and with their own papers as well. I'd suggest anyone who hasn't already check it out

    Internet banking and credit card security Dean Procter -- 10/02/06

    Good news - we have a system to render all phishing attacks and trojan attacks useless. The money is usually what the attackers are after.
    Our new system protects all credit card, Eftpos, ATM, card-not-present, and internet banking transactions, even if the attacker has the PIN password, logon, card,(even the PC) etc even if the owner is unaware that they have been compromised.
    The cost is about 1/100th of a cent per transaction. Even better the system can contact law enforcement/retail security directly at the street level.
    Once deployed we will see an end to these types of fraud.
    There will be no use in having card numbers or even the card and the pin as the thief still won't get any money, instead they're effectively alerting the police as to their location.

    Details? Anonimouse -- 23/02/06 (in reply to #120128967)

    Any more details u can give us then? url?

    I'll believe this only when I see it...

    Transaction Security Anonymous -- 03/03/06 (in reply to #120129729)

    I put my name on it so that those who should can freely ring me and ask me. I'm more than happy to discuss it with an interested party like a bank etc
    If you qualify email me.
    If you're actually in the business you can get my details from the USSS site.
    If not then you'll have to line up like the rest to be arrested within a minute of attempting to beat it.

    Is this guy for reaL...?????? Anonymous -- 12/02/06

    Users are simply fed up with sloppy vulnerability-ridden code and weak security support from most independent software vendors. Look for large organisations to clamp down by placing contractual demands on software providers mandating that they implement security processes and metrics or take a hike.

    Microsoft is ahead of the pack in this area, while "unbreakable" Oracle lags way behind and could lose major contracts as a result.

    BWAHAHHAHAHAHHAHAHAAAA !!!!... Microsoft, security, Microsoft!!!!

    Oh well, yet another Microsoft patsy spreading some more propoganda for Bill.

    His credibility just went down the toilet.

    Research the facts - pal Anonymous -- 13/02/06 (in reply to #120129165)

    Microsoft has the fastest 'vendor to patch' and has for a long time, sources Gartner, IDC, and Metagroup (prior to Gartner buying them out).

    Microsoft spends an approx 1/3 of its 7 billion USD R&D budget on security. Majority of that money is on code quality - mayber Oracle should do the same.

    Why has MS taken so many proactive steps? Because biggots like you hasseled them and went to alternative systems. Customer churn will motivate even the most hardnosed executive that they need to do something.

    Clear your mind, focus on the facts and get with the programme.

    If you like religious wars go and become a JW!

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Chris Duckett Get extensions going in Firefox, redux
    Previously on Null Pointer we looked at getting extensions working in Firefox betas, and that was great until the fine folks at Firefox changed their minds.
  • Array How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • More blogs »

Tags

Back to top

Featured