• Jump to Left Menu
  • Jump to Right Menu
  • Jump to Main Content
  • Jump to Footer
  • Accessibility Page
IT-Director.com Logo

 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Register For Membership | Member Login

 
 
DOMAINS
  • Business Issues
  • Channels
  • Enterprise
  • Services
  • SME
  • Technology
FEATURED EVENTS
  • Telecoms Tech World
    4th June - 5th June
    London, United Kingdom
  • CIMdata PLM Certificate Program
    10th June - 14th June
    Oslo, Norway
POPULAR PAPERS
  • FM, IT and Data Centres by Quocirca
  • The next frontier for managed print services by Quocirca
  • Beyond Big Data - The New Information Economy by Quocirca
USEFUL LINKS
  • Last 7 Days
  • Archives
  • Top Articles
SHARE THIS PAGE
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Famous Slights - "He looked as inconspicuous as a tarantula on a slice of angel food." - Raymond Chandler

PAGE TOOLS
RECENT POSTS
  • CA - Same old same old, or new opportunities?
  • Dreaming of the perfect trip
  • Policing the virtual perimeter
  • Kaspersky Lab - Russia's IT security jewel
  • Is the use of cloud sharing systems worrying you?
  • The age of bring-your-own-identity (BYOID)
ADVERTISEMENT
BLOG ARCHIVE
  • May, 2013
  • April, 2013
  • March, 2013
  • February, 2013
  • January, 2013
  • November, 2012
  • October, 2012
  • September, 2012
  • August, 2012
  • July, 2012
  • June, 2012
  • May, 2012
Blogs > Quocirca

Deploying advanced cyber-security intelligence

Bob Tarzey By: Bob Tarzey, Service Director, Quocirca
Published: 20th August 2012
Copyright Quocirca © 2012
Logo for Quocirca
Tweet

During a speech in June 2012, Jonathan Evans, the chief of the UK’s home security agency MI5, stated that it was “fighting 'astonishing' levels of cyber-attacks”. The worry is not just about the number, but the sophistication and the degree of targeting of individual people and organisations. This is making it harder and harder to detect and stop such attacks with conventional cyber security defences.

As a consequence, many are evaluating advanced tools that supplement point security products such as anti-virus, firewalls and intrusion prevention systems (IPS). This includes deploying what some are calling advanced security intelligence (ASI). ASI is the ability to look at a wide range of information sources in real time and spot that something anomalous is going on; this could be an attack or dangerous or undesirable user behaviour, another risk that needs to be mitigated.

ASI builds on existing technology such as log management and SIEM (security information and event management) tools. The vendors involved, which include LogRhythm, IBM (via its Q1 Labs acquisition) and McAfee (via its Nitro Security acquisition), are souping their products up, in particular their SIEM tools, to provide ASI capabilities. Some are using the term NG-SIEM (next generation SIEM).

Here are some examples of where ASI may succeed where point security products have failed:

  • Signature-based anti-virus software cannot detect new malware (zero-day) attacks. However, using ASI to correlate server activity logs could identify that a given server is being used to contact many other end-points on a given private network and is sending messages out to an unusual IP address (probably a command and control server). The recent Flame malware worked in a similar way to this. ASI would have been one way of detecting such an attack in advance (others are pointed out in a recent article by Quocirca).
  • An intrusion prevention system (IPS) may prevent multiple failed attempts to access a server from a particular bad IP address, but may not see that data is already being copied from that server due to a single successful penetration that was well enough disguised. Correlating log and event files could identify that two such events are related and lead to the prevention of a data theft. A so-called advanced persistent threat (APT) could have this sort of profile.
  • It may be normal for a known user to access a given application remotely and out of office hours, but not if the request is coming from a location where they cannot physically be located. Correlating each access request against the previous successful access request and checking the geographic location of the devices used can identify a physically impossible event such as a user having moved from London to Paris in the space a few minutes or hours, even if the bona fide user’s job role could see them legitimately in both locations.
  • It might be usual for an employee to access customer information; it may also be usual for them to download such data to a file for reporting reasons. However, for them to copy the data to a non-compliant location, for example a cloud storage resource in a certain country, should raise an alarm. There may be no malicious intent here; perhaps this is an example of a line-of-business commissioning its own cloud resources (an increasingly common practice). This requires rules that understand user access rights and compliance rules and the ability to correlate these in real time with attempts to copy data and the location of the target storage service.

ASI tools can make use of many sources of IT intelligence data in real time. They also have central policy engines which allow customers to write their own rules as well as including a wide range of out-of-the-box rules (e.g. flagging suspicious activity, such as multiple machines simultaneously attempting connections to unauthorised IP addresses outside of a given network).

For businesses, there is no end to the struggle to get the upper hand over cyber-criminals. For governments, the situation is arguably even worse, as cyber-space becomes the 5th theatre for warfare (after land, sea, air and space) and terrorists see cyber-space as a way to go after critical infrastructure. All have to keep upping the ante, to avoid falling too far behind, or perhaps even get ahead, turning cyber security into an offensive rather than defensive act.

Quocirca’s report Advanced Cyber Security Intelligence is freely available here.

Reader Comments

We have not received any comments against this entry. Why not be the first?

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.

  • Contact
  • | Site Map
  • | Terms of Use
  • | Privacy Policy
  • | Cookie Policy

Published by: IT Analysis Communications Ltd.
T: +44 (0)190 888 0760 | F: +44 (0)190 888 0761