Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Microsoft virtualization tools reinforce user's data center plans
Air traffic network glitch cleared-up for now
Cisco buys into e-mail with $215 million PostPath acquisition
Locked iPhones can be unlocked without a password
Baseball's video and secure telephone links ready for instant replay
China aims for petaflop computer in 2010
Mozilla garners praise over Firefox security feature
Mt. Sinai Medical Center looks to open standards for patient smartcards
Immersion to pay Microsoft $20 million to settle patent suit
Expand Networks secures $8.5 million in venture capital
Alcatel-Lucent intros Gigabit Ethernet switches
Storage market thrives in down economy
Hosted RFID service targets mobile users
Best Western downplays data breach
Google drops Bluetooth, GTalkService APIs from Android 1.0

Internet too complex to secure, says exec

Related linksToday's breaking news
Send to a friendFeedback


When he goes to Washington, D.C. next week to testify before the U.S. Congress on computer and Internet security, Bruce Schneier, the CTO of Counterpane Internet Security, would like to tell them that such efforts are currently done poorly and with the wrong goals.

He will also tell Congress that "the Internet is too complex to secure," as he said in a speech on the last day of the Black Hat Briefings security conference here Thursday.

"Often when I tell people that, they get very disturbed," he said. But nonetheless, "we're losing ground every year," because every new product is less secure; every new level of complexity or integration makes a product less secure, he said.

Events seem to bear out his conclusions: despite there being more computer security companies and software than at any other time, viruses, worms, Web page defacements and other security incidents are seemingly happening more often than ever before.

This is because security is approached with the wrong attitude, he said.

"One of the reasons we do security so poorly on the Internet is because we think if computers are involved, it's magic," but it's not, Schneier said. Applying the same principles used in physical security to Internet security will be more effective, he said.

"Firewalls will never prevent unauthorized network access. That's OK: We can't buy a device that will prevent murder (either)," he said.

Current computer security practices are too focused on prevention, leading to ineffective measures, he said.

"If you want to secure your house, you wouldn't get thicker walls."

Rather, in the physical world, security is implemented to manage risks, not to try to eliminate them, he said. Grocery stores accept that some shoplifting will occur, but try to compensate for it by using security devices, employees and insurance, he said. Despite all this, they accept that shoplifting will never be eliminated. This is good business, however, because the alternatives would be unworkable, he said.

Computer security must adopt the same stance, but hasn't yet, he said. "When (computer) security decisions are made, it's only more or less secure, it's not smarter or dumber (business)."

Despite the industry's incorrect philosophical bent, Schneier sees hope on the horizon in the form of monitoring and response systems, insurance and law enforcement.

Rather than focusing energies and budgets on prevention, computer security efforts ought to be spread across prevention, detection and response, he said. Though prevention is important, it is not foolproof, he said. Having the other two features will help manage and mitigate risks, he said.

"Detection, response - if it works well enough - makes up for shoddy prevention," said Schneier, whose company, Counterpane, sells a security monitoring service.

Additionally, Schneier sees more companies turning to the insurance industry for Internet or e-business insurance, a move that will drastically impact computer security.

"I believe insurance will make a great difference in computer security," he said. "Since the turn of the century, the insurance industry has driven what sort of security you have."

In this case, insurance companies will force their clients to make product purchase decisions based on security, which, in turn, will lead to more secure products. Schneier doesn't expect this development to happen for three to five years, however.

Lastly, Schneier said that the continued prosecution of computer crime will create a deterrent effect which will reduce such crime.

"If crime doesn't pay, then people are less likely to do it," he said.

"The online world isn't any different than the offline world," and it ought to be secured the same way, he said. Perhaps Congress will take note.

Counterpane, in Cupertino, Calif., is at www.counterpane.com

The IDG News Service is a Network World affiliate.

Related Links

 
NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.