• Skip Navigation |
  • Accessibility 
Sustainable Manufacturing Summit (19-21 Nov, Belgium)
IT-Director.com Logo
  • What is Symantec's vision?
  • MarketSight 7.0 - Survey Analysis Made Simple
  • Learning from the credit crunch to avoid a broadband crunch
 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • RESEARCH
  • EVENTS
  • NEWSWIRE
  • BLOGS
  • POLLS

  

Member Login | Become a Member

 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • PLM North America 2008
    13th October - 15th October
    St Augustine, USA
  • Storage Expo 2008
    15th October - 16th October
    London, United Kingdom
POPULAR PAPERS
  • Keep Talking Not Spending by Quocirca
  • Remote IT Management by Quocirca
  • We are all IT users now by Quocirca
TRANSLATE PAGE



USEFUL LINKS
  • Last 7 Days
  • Archives
  • Market Place
  • Top Articles
  • Hall of Flame
INTERACT
  • Advertising
  • About IT-Director.com
  • Site Feedback
  • Newsletters
  • Contact Us
  • Registration
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Say Again? - "The spinal column is a long bunch of bones. The head sits on the top and you sit on the bottom." - from Kids Say the Darndest Things

ADVERTISEMENT
Blogs > Sageza Says

Is Bot Defense the IDS of 2008?

Lawrence Dietz By: Lawrence Dietz, Research Director, Sageza Group, Inc.
Published: 6th December 2007
Copyright Sageza Group, Inc. © 2007
Logo for Sageza Group, Inc.
Page Tools

Request Reprints
Tell A Friend
Contact Author

Recent Blog Posts
  • The Virtual Appliance?
  • Networking Re-Pondered at 37,000 feet
  • The empowerment of Power
  • History isn't always the best teacher
  • HP, MIT, and DSpace Foundation
  • FCC, 700 MHz, Wireless Carriers, and the Mobile Internet
Blog Archive
  • September, 2008
  • October, 2007
  • September, 2007
  • August, 2007
  • July, 2007
  • June, 2007
  • May, 2007
  • April, 2007
  • March, 2007
  • February, 2007
  • January, 2007
  • December, 2006
Syndication
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon

I don't think there is any question that bots and botnets are a dangerous threat. The combination of a worm delivery vehicle and a malware payload of varying capabilities is a potent one that attackers have morphed to suit their own purposes. Bot defense is proving to be a difficult task even as traditional AV vendors and others have purported to include bot defense in and among the various protections they offer.

There are also a couple of specialty vendors that focus on the threat and claim to be able to identify not just the threat, but the best way to defeat it in the future. If this all sounds strangely like the rhetoric surrounding Intrusion Detection Systems in the early days—it's because it does. As you may recall, IDS vendors all touted their ability to identify attacks. The market bifurcated itself into network and host and vendors pretty much camped out on one side or the other.

Then one day, at a Gartner security conference of all places, an analyst (Richard Stienon, now with Fortinet) coined the phrase "IDS is dead!" The market went into a tizzy with much scurrying around by vendors to re-position themselves as Intrusion Prevention rather than Intrusion Detection. In retrospect Stienon merely stated the obvious that end user organizations didn't want a complete description of their problem, they wanted technology to make sure the problem didn't occur in the first place.

So should it be with bots and botnets. The community wants and needs prevention more than it needs detection and identification. I offer this blog as a call for vendors to develop measures that do more than diagnose the threat but can provide detailed guidance to non-security professionals such as those that work in the Network Operations Center (NOC) to help them thwart these efforts in an exceptionally timely manner. Ideally perhaps the products would also offer the capability to invoke the recommended solution with a key stroke or two in accordance with previously approved security and operations protocols and permissions.

We know that the edge belongs to the attacker. Security professionals have to win all the time to keep their IT world safe, attackers only have to win a few times to accomplish their goals. Let's hope that the botnet world becomes a proving ground for being one step a head of the enemy, rather than behind them.

Reader Comments

We are no longer accepting comments against this item. We suggest contacting the author directly.

  • Site Map
  • | Terms of Use
  • | Privacy

Published by: IT Analysis Communications Ltd.
T: +44 (0)203 051 5760 | F: +44 (0)870 345 9922