In Depth
Information Security Predictions in 2004
In 2004, information security will require a splash of the old, a dash of the new and a healthy dose of brainpower.
By Chris Lindquist
Companies are also working to create tools that deal with vulnerabilities that have nothing to do with holes in the underlying code, McClure says, but simply in users' difficulty with properly configuring systems. "Vulnerabilities make up maybe half, maybe two-thirds of the attacks," he notes. The rest, he says, are misconfigurations: systems with default passwords still in place, ports open unnecessarily and security features not even turned on. Today's tools don't really deal with these configuration issues sufficiently, McClure says, though a few have begun to try.
And then there's the other answer
"You end up loading a device that can't fail," Bletsas says. "You exercise it when your switch melts after the next worm attack. Remember, the Internet is an end-to-end network, which by design is supposed to do nothing more than forward packets at its core. Every defense strategy that relies on adding more complex functions to the network's core is bound to fail."
There are other security areas begging for simplification as well. Encryption technologies are common culprits, requiring a complex infrastructure and laborious user interaction to use effectively. "Strong e-mail has been available, but almost no one uses it because it's too complicated. PKI has failed completely because the user interface makes no sense to most people. Many don't use file encryption because they're afraid that they'll lose the data if they forget the key," says Counterpane's Schneier. "The security works great
"We need to hide the complexity," says Grance. "We want [security] to be like a TV. We don't know exactly how it works, but we know how to watch it."Getting TogetherCommunication and cooperation must also play a role going forward. At the macro level, organizations
$firstKeyword
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



