About
Subscribe

A different war

Kathryn McConnachie
By Kathryn McConnachie, Digital Media Editor at ITWeb.
Johannesburg, 17 Oct 2012
User identity management, tighter access controls and security analytics are essential in the new threat landscape, says IBM's GM of security systems, Brendan Hannigan.
User identity management, tighter access controls and security analytics are essential in the new threat landscape, says IBM's GM of security systems, Brendan Hannigan.

Mobility, cloud and social are driving the most significant changes in businesses, but also posing the most serious challenges.

This is according to general manager of security systems at IBM, Brendan Hannigan, who spoke to ITWeb at the IBM Interconnect Conference, in Singapore, recently.

"While in the past, technologies for business were controlled by IT, now a lot of these innovations are actually being driven by consumers and they're sort of hefted upon IT and it's not like they have the option to stop the adoption of these new technologies. They can try and control it, but there's no way they can just stop it. It would be ridiculous to even try," says Hannigan.

According to Hannigan, throughout time there has been a constant back and forth between putting up protections and criminals working to get around them. "This particular pendulum swing that we're experiencing now is more serious than anything we've seen in the past."

Hannigan uses an analogy of a castle to illustrate the current security landscape: "Hundreds of years ago we had castles and forts to protect our villages and the people within them. Then someone would put a ladder up against the castle, so they'd build the castle wall a little higher.

"Then people would put a whole construct against the wall so a whole group of people could gain entry, and as a result, they would build a moat around the castle to further protect it. So the castle would constantly be modified, with its walls becoming bigger, wider, more difficult to reach. But the analogy now is as if someone has just landed a helicopter right in the centre of the castle.

"We can't just keep doing what we've been doing," says Hannigan, adding that the assumption still exists among businesses that if they keep building walls around their they will be safe.

"Walls used to keep everything nice and protected inside, but now everything is so connected - employees are connected, businesses are connected, applications are connected - so, unfortunately, bad things are ending up right within the castle walls and the weaknesses inside are exposed," says Hannigan. He adds that security strategies of the past are still important, but on their own, are entirely insufficient. "There's got to be a more comprehensive approach to security."

Where the money is

Hannigan adds that, in the past, the primary security concerns were so-called "classic hackers" who would just search randomly for any weaknesses and exploit those to deface a Web site or cause it to crash.

Now, however, Hannigan says the type of threat has changed for a number of reasons. "So many important things are now stored digitally. Everything from consumer information to airplane designs to turbine designs to important information about our mining discoveries, whatever it is, all of that information is stored digitally.

"Secondly, in general there's a whole population of skilled people relative to these types of technologies. Young people have a very good sense of how these technologies work. Thirdly, bad people are motivated by where the money is. Whether it be important intellectual property or actual financial information.

"Many years ago, people had hackers randomly going after them causing significant, costly inconveniences; now they have very organised entities going after them specifically, targeting them to steal things, damage things and potentially destroy their business.

"It's a very different war, a very different climate. And the techniques used by the attackers are much more sophisticated and the result is much more impactful."

Social threat

Social networking also adds a new dimension to the current threat landscape. Hannigan says: "It is a tool and technique which attackers will use to get information about a person. Not necessarily because that person's information is valuable. They get that information, because they may want to attack that person's company.

"Social networking information is a nice way to get an understanding of who that person is connected to, who they communicate with. For example, they could craft an e-mail to that person that looks very personal, very targeted. By clicking on a link in that e-mail they can install spyware on that person's computer without them knowing, and that will be just the beginning," says Hannigan.

The IBM X-Force 2012 Mid-Year Trend and Risk Report, which pulls data from more then 15 billion security events per day, from over 4 000 clients, in over 130 countries, recorded a significant increase in attacks on exposed social media passwords. Another key issue raised by the report was that of the continued disparity in mobile devices and corporate "bring you own device" (BYOD) programmes.

"Many companies are still in their infancy in adapting policies for allowing employees to connect their personal laptops or smartphones to the company network. To make BYOD work within a company, a thorough and clear policy should be in place before the first employee-owned device is added to the company's infrastructure," says the report.

Dangerous connections

According to Hannigan, while infrastructure securities like firewalls are still important, in the new environment other elements such as people security have become essential.

"Of course, many companies have basic access controls of some sort but the reality is that we have found that about only 34% of our customers actually have comprehensive identity management strategies."

Hannigan says a key example of an action companies can take to constrain the risk they're exposed to is to focus on controlling access to environments, and monitoring that access. "In particular, it's about organising priority users with the most privileged access and monitoring that very closely. Maybe even ensuring that they only have access privileges when they absolutely need them, and not all the time."

Real-time security analytics are also important in picking up irregularities, according to Hannigan. "IBM has crawlers that categorise all of the URLs on the Internet. Google does that for the purpose of helping search, IBM does that for the purpose of understanding the role of these URLs. We have categorised all of the social networking sites in the world and we take all this data and feed it into our products. The products can take action and run analytics based on that," says Hannigan. He adds that it is not about blocking access but rather putting controls in place over what content can be posted to and from such sites.

The X-Force report notes the connection between Web sites, cloud-based services, and Web mail provides a seamless experience from device to device, but warns users should be cautious about how these accounts are connected, the security of their password, and what private data has been provided for password recovery or account resetting. Hannigan acknowledges, however, that there is always room for human error, especially with the increasing use of linked accounts and a lack of education around password security.

"But with other measures in place, such as identity management, access controls and real-time analytics, we can see that at 5am a major file download took place and we can take action immediately. Having much tighter individual controls over user privileges is also key," says Hannigan.

Share