Security in My Rear-View Mirror Marcus J. Ranum works for Tenable - - PowerPoint PPT Presentation

security in my rear view mirror
SMART_READER_LITE
LIVE PREVIEW

Security in My Rear-View Mirror Marcus J. Ranum works for Tenable - - PowerPoint PPT Presentation

Security in My Rear-View Mirror Marcus J. Ranum works for Tenable Network Security, Inc. Trajectory Optimism We can do this! Firewalls Browser active content Cloud Malware Cloud 1989 1997 2008 IoT Current Trends Management:


slide-1
SLIDE 1

Security in My Rear-View Mirror

Marcus J. Ranum works for Tenable Network Security, Inc.

slide-2
SLIDE 2

Trajectory

1989 We can do this! Optimism Firewalls Browser active content Malware Cloud Cloud IoT 2008 1997

slide-3
SLIDE 3

Current Trends

  • Management:

– Do more with less – Process not people – Off the shelf software – No in-house development capability

slide-4
SLIDE 4

A Problem

  • Everything I advocate is the opposite of

“do more with less”

slide-5
SLIDE 5

The Problem

  • Management is chasing fads and

engaging in false optimism

– Keep buying anti-malware products “maybe the next one will work” – Keep freeform data-sharing “maybe we’ll figure out where it is someday” – Keep desktop systems administration “configuration management is hard”

slide-6
SLIDE 6

Market Dynamics

  • The security world is getting crushed

from 3 sides at once:

– Top – Bottom – Flank

slide-7
SLIDE 7

Market Dynamics

  • From the top, the security market is

getting crushed by cloud computing

– Cloud is configuration management and automation – If you won’t/can’t/are too stupid to do it, we’ll do it for you, and aggregate the cost

slide-8
SLIDE 8

Market Dynamics

  • From the bottom, the security market is

getting crushed by the apparent savings

  • f BYOD

– Not, you know, the reality of BYOD – It’s just a way of pushing the cost of management onto the user

slide-9
SLIDE 9

Market Dynamics

  • From the side, the security market is

getting crushed by new management models

– Apple walled garden software (but knowing Apple, it’s not too late to screw up) – Software as a service

slide-10
SLIDE 10

If You Were Paying Attention

  • You may have noticed that I just said

that security is almost entirely being driven by management costs

– Specifically system administration / configuration management

slide-11
SLIDE 11

If You Were Paying Attention

  • This is why current focus on standards

and compliance (PCI, etc) is ill-advised

– It is another management cost – If organizations realize this, they’ll figure

  • ut how to game compliance
  • Switch to cloud
  • Switch to configuration management and

automation

slide-12
SLIDE 12

Digging Out Of The Hole

  • Stop doing “penetrate and patch”

– The industry must/will switch to streaming software updates with version repudiation – It’s heading that way for everything, it probably won’t be good enough – Switch to whitelisting applications and traffic and storage

  • Focus on aggregate management cost
slide-13
SLIDE 13

How to Talk to Managment

  • Use small words
slide-14
SLIDE 14

How to Talk to Managment

  • Joking aside:

– Use comparative results – “we did X, and it resulted in Y” – “we spend X amount of time on each incident, compared to Y amount of time in aggregate configuration management”

  • Help them understand where the effort

is going

slide-15
SLIDE 15

How to Talk to Managment

  • This applies to software, as well!!

– “I know you say ‘we don’t do software development’ but Oracle and Arcsight and everything we have to configure is software

  • development. We need to look at long-term

maintenance and management costs, not top line cost.”

slide-16
SLIDE 16

How to Talk to Managment

  • Eventually someone must ask:

– “Are cheaper Windows/PC combinations actually cheaper than a Mac, if we look at them over a 5-year cycle including maintenance and management costs as well as add-on software and management

  • f add-on software?”

– Do you know the true cost of malware?

slide-17
SLIDE 17

All of This Means:

  • Maintain metrics

– It is effectively impossible to make honest cost-based system projections without data about current outcomes

  • “When is the best time to plant a mighty
  • ak tree?”
slide-18
SLIDE 18

My Advice To You

  • If you’re working in security, work with a

focus on management and automation

– That’s mostly what we do, anyway – Forms of management that can be, will be ditched – Forms of management that can be, will be automated

slide-19
SLIDE 19

My Advice To You

  • If you’re working in software, work with

a focus on management and automation

– CASE tools failed in the 80s and 90s because they made writing bad code harder – Make it easier to write good code faster and you will get rich*

* If you don’t die of frustration, first

slide-20
SLIDE 20

My Advice To You

  • Avoid “forensic management” careers

– Vulnerability management – Asset management – Penetration testing – Compliance auditing

  • These are fields that are targeted for

cost-cutting (which will mean increased competition)

slide-21
SLIDE 21

My Advice To You

  • Want to make a ton of $Euro?

– Application whitelisting as a service – Storage management as a service

slide-22
SLIDE 22

Summary

  • It probably sounds like I am “big” on

configuration management

– Yes

  • Why?

– Security is properly a sub-discipline of systems and network administration – We exist as an industry because they suck

slide-23
SLIDE 23

Security in My Rear-View Mirror

Marcus J. Ranum works for Tenable Network Security, Inc.

slide-24
SLIDE 24

Trajectory

1989 We can do this! Optimism Firewalls Browser active content Malware Cloud Cloud IoT 2008 1997

slide-25
SLIDE 25

Current Trends

  • Management:

– Do more with less – Process not people – Off the shelf software – No in-house development capability

slide-26
SLIDE 26

A Problem

  • Everything I advocate is the opposite of

“do more with less”

slide-27
SLIDE 27

The Problem

  • Management is chasing fads and

engaging in false optimism

– Keep buying anti-malware products “maybe the next one will work” – Keep freeform data-sharing “maybe we’ll figure out where it is someday” – Keep desktop systems administration “configuration management is hard”

slide-28
SLIDE 28

Market Dynamics

  • The security world is getting crushed

from 3 sides at once:

– Top – Bottom – Flank

slide-29
SLIDE 29

Market Dynamics

  • From the top, the security market is

getting crushed by cloud computing

– Cloud is configuration management and automation – If you won’t/can’t/are too stupid to do it, we’ll do it for you, and aggregate the cost

slide-30
SLIDE 30

Market Dynamics

  • From the bottom, the security market is

getting crushed by the apparent savings

  • f BYOD

– Not, you know, the reality of BYOD – It’s just a way of pushing the cost of management onto the user

slide-31
SLIDE 31

Market Dynamics

  • From the side, the security market is

getting crushed by new management models

– Apple walled garden software (but knowing Apple, it’s not too late to screw up) – Software as a service

slide-32
SLIDE 32

If You Were Paying Attention

  • You may have noticed that I just said

that security is almost entirely being driven by management costs

– Specifically system administration / configuration management

slide-33
SLIDE 33

If You Were Paying Attention

  • This is why current focus on standards

and compliance (PCI, etc) is ill-advised

– It is another management cost – If organizations realize this, they’ll figure

  • ut how to game compliance
  • Switch to cloud
  • Switch to configuration management and

automation

slide-34
SLIDE 34

Digging Out Of The Hole

  • Stop doing “penetrate and patch”

– The industry must/will switch to streaming software updates with version repudiation – It’s heading that way for everything, it probably won’t be good enough – Switch to whitelisting applications and traffic and storage

  • Focus on aggregate management cost
slide-35
SLIDE 35

How to Talk to Managment

  • Use small words
slide-36
SLIDE 36

How to Talk to Managment

  • Joking aside:

– Use comparative results – “we did X, and it resulted in Y” – “we spend X amount of time on each incident, compared to Y amount of time in aggregate configuration management”

  • Help them understand where the effort

is going

slide-37
SLIDE 37

How to Talk to Managment

  • This applies to software, as well!!

– “I know you say ‘we don’t do software development’ but Oracle and Arcsight and everything we have to configure is software

  • development. We need to look at long-term

maintenance and management costs, not top line cost.”

slide-38
SLIDE 38

How to Talk to Managment

  • Eventually someone must ask:

– “Are cheaper Windows/PC combinations actually cheaper than a Mac, if we look at them over a 5-year cycle including maintenance and management costs as well as add-on software and management

  • f add-on software?”

– Do you know the true cost of malware?

slide-39
SLIDE 39

All of This Means:

  • Maintain metrics

– It is effectively impossible to make honest cost-based system projections without data about current outcomes

  • “When is the best time to plant a mighty
  • ak tree?”
slide-40
SLIDE 40

My Advice To You

  • If you’re working in security, work with a

focus on management and automation

– That’s mostly what we do, anyway – Forms of management that can be, will be ditched – Forms of management that can be, will be automated

slide-41
SLIDE 41

My Advice To You

  • If you’re working in software, work with

a focus on management and automation

– CASE tools failed in the 80s and 90s because they made writing bad code harder – Make it easier to write good code faster and you will get rich*

* If you don’t die of frustration, first
slide-42
SLIDE 42

My Advice To You

  • Avoid “forensic management” careers

– Vulnerability management – Asset management – Penetration testing – Compliance auditing

  • These are fields that are targeted for

cost-cutting (which will mean increased competition)

slide-43
SLIDE 43

My Advice To You

  • Want to make a ton of $Euro?

– Application whitelisting as a service – Storage management as a service

slide-44
SLIDE 44

Summary

  • It probably sounds like I am “big” on

configuration management

– Yes

  • Why?

– Security is properly a sub-discipline of systems and network administration – We exist as an industry because they suck