With the viruses and worms of the future likely to threaten networks across the world within seconds of their release, networks need to be self-defending, says Eric van Gend, Cisco business development manager.
Van Gend, who manages Cisco`s Russia, Middle East and Africa operations, told the Cisco Secure Tour in Sandton on Tuesday that the "threat evolution" is in its third generation, with network denial-of-service attacks, the blended threat of worms, viruses and Trojans, turbo worms and widespread system hacking all capable of affecting the world in a matter of minutes.
"The Slammer virus infected over 75 000 hosts within 11 minutes across the globe, doubling its infection rate every 8.5 seconds, causing network outages, cancelled airline flights and ATM failures.
"In the future, attacks like these will happen in a matter of seconds," he said.
Van Gend noted that companies should not rely solely on security software and the release of latest patches, as hackers and malicious programs will exploit vulnerabilities as soon as they become aware of them.
"Using networking tools, Cisco`s network identified 'unusual` traffic and an alarm was triggered by our anomaly-detection technology six seconds after Slammer`s release. After 10 seconds, the appropriate ports inside and outside Cisco had been locked down. Thirty seconds after the launch, a vulnerability scan was conducted and no infections were found within Cisco."
Self-defence in action
To help company networks be self-defending, Cisco CEO John Chambers announced the launch of Network Admission Control (NAC) in November.
NAC aims to provide companies with the technology to stop threats like the Slammer virus by scanning devices when they attempt to connect to a corporate network to ensure they have the correct security software, and isolating traffic if it is suspicious.
Developed in conjunction with Network Associates, Symantec and Trend Micro, NAC secures networks and tackles the risks posed by mobile and remote workers in enterprise environments who connect to corporate networks.
Gend said initial NAC capability would be delivered in the second quarter in Cisco routers. Future NAC extensions will include more Cisco network devices, more endpoint security software and endpoint platforms, and more industry co-sponsors, he added.
"The benefits of NAC for the customer will include dramatically improved security for non-compliant hosts and therefore lower costs, increased network resilience and productivity, extended value from Cisco network infrastructure investment, and increased value of the company`s existing investment in anti-virus software."
IBM joins NAC
David Bowdler, IBM`s Europe, Middle East and Africa director for its alliance with Cisco, who also presented at the Cisco Secure Tour, said IBM joined the NAC in February. Under the agreement, IBM integrates its Tivoli security management software with Cisco NAC products.
Bowdler said the NAC is important because it helps companies secure the entire organisation. The partnership with Cisco will provide clients with integrated user provisioning, integrated endpoint security, automated compliance and security services, he noted.
To counter the wave of new threats sweeping against companies, said Bowdler, companies have to ensure they are secure on an infrastructure, application, operation and process level.
"A company`s first step should be to assess its security and privacy status in these four areas against best practice. An end-to-end security solution then needs to be built to protect assets and detect threats immediately. Thirdly, security needs to be managed as a continuous process, monitoring recovery and managed services processes," he said.
Van Gend said by integrating security, having industry collaboration in the form of the NAC, and providing companies with a system level end-to-end solution, companies will be able to dramatically improve their networks` ability to identify, prevent and adapt to threats.

