Source: [id: 41018; name: CSO; isActive: true; siteId: 3] -- CSO -- $content.altguid

Hackback: Stick It to 'Em

In June, Huff and two colleagues received a patent for a platform designed to allow companies to take an offensive approach to intrusion response.

By Simone Kaplan

April 01, 2003CSO — Have you ever fantasized about catching a hacker in action? What a sweet moment it would be. Your network could snare interlopers like a spider's web, allowing you to swoop in and neutralize the intruder without him even knowing what happened. Well, thanks to Julie Huff, a systems architect at Northrop Grumman Information Technology, your fantasy is no longer the ultimate CSO dream. In June, Huff and two colleagues received a patent for a platform designed to allow companies to take an offensive approach to intrusion response. The platform, called Security Kinetix, is designed around "agents" that watch over individual computer or network nodes and can defend the node or spy on a hacker, depending on what the network administrator wants. Huff's system doesn't go after hackers itself, but clients can customize the agent architecture to build whatever sort of counterattack they want.

"Response is what the owner of a particular system defines response to be," Huff says. "No one can predict what hackers will come up with, but we wanted to give people a tool to help them fight back."

Most intrusion detection products don't allow companies to be flexible in their responses. A company may not want to shut users out of the system if they fail the password three times in a row, but a lot of products will cut them off, Huff says. If you're in the military and you have computers in remote areas, you need to be able to respond to anomalies quickly, perhaps by cutting stolen computers off from the network or shutting down remote nodes that are being scanned by hackers.

"We haven't designed the system to shoot magic firebolts through a firewall, but if that's what you need, we'll help you build it," Huff says.

Read more about network security in CSOonline's Network Security section.

RESOURCE CENTER