• Skip Navigation |
  • Accessibility 
IT-Director.com Logo
  • Managed hosting in Europe
  • CSC - Cloud Strategy Coming
  • The quantity of quality (management software vendors) is shrinking
 

Main navigation - go to a section of this website:

  • CHANNEL
  • ARCHIVE
  • PAPERS
  • RESEARCH
  • EVENTS
  • NEWSWIRE
  • BLOGS
  • MARKETPLACE

  

Member Login | Become a Member

 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • Invest in Spain: Business Opportunities in Biotechnology, Pharma and Life Sciences Sector
    14th July - 14th July
    Webinar (online)
  • Building the Perfect Council Web Site 09
    15th July
    London, United Kingdom
POPULAR PAPERS
  • Managed hosting in Europe - June 2009 by Quocirca
  • Body shop to mind shop by Quocirca
  • Creation of Accessible Documents by Bloor Research
TRANSLATE PAGE



USEFUL LINKS
  • Last 7 Days
  • Archives
  • Market Place
  • Top Articles
  • Hall of Flame
INTERACT
  • Advertising
  • Site Feedback
  • Newsletters
  • Contact Us
  • Registration
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Observations - "The radical of one century is the conservative of the next. The radical invents the views. When he has worn them out the conservative adopts them." - Mark Twain

ADVERTISEMENT
MARKETPLACE
  • Western Digital Elements 1TB USB 2.0 External Hard Drive - Black
    Western Digital Elements 1TB USB 2.0 External Hard Drive - Black
  • Western Digital My Passport Essential 250GB USB Portable External Hard Drive
    Western Digital My Passport Essential 250GB USB Portable External Hard Drive
  • Western Digital My Passport Essential 320GB USB Portable External Hard Drive
    Western Digital My Passport Essential 320GB USB Portable External Hard Drive
Blogs > Sageza Says

Is Bot Defense the IDS of 2008?

Lawrence Dietz By: Lawrence Dietz, Research Director, Sageza Group, Inc.
Published: 6th December 2007
Copyright Sageza Group, Inc. © 2007
Logo for Sageza Group, Inc.
Page Tools

Request Reprints
Tell A Friend
Contact Author

Recent Blog Posts
  • JavaONE: Bright Future or Riding off into the Sunset?
  • The Virtual Appliance?
  • Networking Re-Pondered at 37,000 feet
  • The empowerment of Power
  • History isn't always the best teacher
  • HP, MIT, and DSpace Foundation
Blog Archive
  • June, 2009
  • September, 2008
  • October, 2007
  • September, 2007
  • August, 2007
  • July, 2007
  • June, 2007
  • May, 2007
  • April, 2007
  • March, 2007
  • February, 2007
  • January, 2007
Syndication
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon

I don't think there is any question that bots and botnets are a dangerous threat. The combination of a worm delivery vehicle and a malware payload of varying capabilities is a potent one that attackers have morphed to suit their own purposes. Bot defense is proving to be a difficult task even as traditional AV vendors and others have purported to include bot defense in and among the various protections they offer.

There are also a couple of specialty vendors that focus on the threat and claim to be able to identify not just the threat, but the best way to defeat it in the future. If this all sounds strangely like the rhetoric surrounding Intrusion Detection Systems in the early days—it's because it does. As you may recall, IDS vendors all touted their ability to identify attacks. The market bifurcated itself into network and host and vendors pretty much camped out on one side or the other.

Then one day, at a Gartner security conference of all places, an analyst (Richard Stienon, now with Fortinet) coined the phrase "IDS is dead!" The market went into a tizzy with much scurrying around by vendors to re-position themselves as Intrusion Prevention rather than Intrusion Detection. In retrospect Stienon merely stated the obvious that end user organizations didn't want a complete description of their problem, they wanted technology to make sure the problem didn't occur in the first place.

So should it be with bots and botnets. The community wants and needs prevention more than it needs detection and identification. I offer this blog as a call for vendors to develop measures that do more than diagnose the threat but can provide detailed guidance to non-security professionals such as those that work in the Network Operations Center (NOC) to help them thwart these efforts in an exceptionally timely manner. Ideally perhaps the products would also offer the capability to invoke the recommended solution with a key stroke or two in accordance with previously approved security and operations protocols and permissions.

We know that the edge belongs to the attacker. Security professionals have to win all the time to keep their IT world safe, attackers only have to win a few times to accomplish their goals. Let's hope that the botnet world becomes a proving ground for being one step a head of the enemy, rather than behind them.

Reader Comments

We are no longer accepting comments against this item. We suggest contacting the author directly.

  • Site Map
  • | Terms of Use
  • | Privacy

Published by: IT Analysis Communications Ltd.
T: +44 (0)190 888 0760 | F: +44 (0)190 888 0761