Home > Security News > Analysts say 'cloudy' forecast is OK
Security News:
EMAIL THIS

Analysts say 'cloudy' forecast is OK

By Michael S. Mimoso, Senior Editor
06 Jun 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

WASHINGTON, D.C. -- The network security forecast is cloudy, and that's not a bad thing if you're to believe what analysts are saying at this week's Gartner IT Security Summit.

Gartner predicts that by 2008, carriers like AT&T, Verizon, MCI and others will operationalize security functions like firewalls and intrusion detection into routers and switches, leaving enterprises to concentrate on identity and access management and other security duties away from the perimeter. By extending security to the Internet cloud, denial-of-service attacks, for example, never reach the gateway.

"We would take what an MSSP does and mesh that with our infrastructure so that the service provider and carrier becomes one," said AT&T CISO Ed Amoroso.

CISOs, meanwhile, will still have network responsibilities like setting policy and aligning policy with an enterprise business model. They'll be alleviated of costly signature updates and license renewals.

"Carriers and ISPs will provides these services for you," Gartner research director John Pescatore said.

While this boils down to essentially outsourcing these services to carriers, enterprises may be skeptical about doing so until auditors are satisfied.

What to look for when buying an Intrusion Prevention System

Gartner research director Greg Young identified seven selection criteria IT managers should use when purchasing an IPS.  

 

--Performance/latency

--Updates (quality of   signatures)

--Price

--Inclusion of next-generation firewall

--Management and reporting capability

--Is it IPS, and not just IDS inline?

--Security functionality and how it behaves if there's a failure

"I could see some [savings] with these services, but they'd have to be secure by definition," said Neil Delaney, IT infrastructure manager with NJ Manufacturers of New Jersey. "The SLA with the carrier would have to say no DoS attacks, no scanning, no RPC viruses getting through. And let's say I push all this to the cloud, does that mean I don't have a firewall on my side anymore? What are my operational best practices then? Are these services reliable, or do I still have to have my own security as a best practice?"

In the meantime, Gartner cautions that it may be more crucial than ever to establish secure zones between IT systems and the Internet. Attacks are maturing beyond broad-based worms, and now target specific applications and business processes putting additional perimeter pressure on managers to deploy tools like next-generation firewalls that combine IPS and a Web application firewall, in addition to traditional IDS and IPS defenses.

"You're not going to see mass signatures that protect anymore," Pescatore said.

Next generation firewalls that do deep-packet inspections from vendors like Juniper Networks, Check Point and Fortinet employ a heuristics engine that drops all traffic that is not expressly permitted. Most enterprises, however, refresh their firewall purchases on a three- to five-year cycle and that makes it challenging to synch new features.

"Having a secure perimeter and more zoning around systems is more important than ever," Pescatore said.

Pescatore predicted that by the end of 2006, 75% of network IPS will also check endpoint security and do anomaly detection. Gateway and antispam protection will also be included in vendor RFPs for all-in-one security platforms. Meantime, 10GB standalone IPS appliances will also be available by the end of next year.

This article originally appeared on SearchSecurity.com.

Tags: Network Intrusion Prevention (IPS)Web Application SecurityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Intrusion Prevention (IPS)
Lesson 1 quiz: Risky business
Hacker attack techniques and tactics: Understanding hacking strategies
SIMs tools and tactics for business intelligence
IPS and IDS deployment strategies
Know when you need IDS, IPS or both
Trend Micro to acquire Third Brigade for virtualization, cloud security
What are the best practices for IPS implementation?
Host-based intrusion prevention addresses server, desktop security
Intrusion detection vs. intrusion prevention
IBM announcements mark two years of ISS marriage
Network Intrusion Prevention (IPS) Research

Web Application Security
Adobe patches ColdFusion vulnerability blocking website attack
nCircle statistics show rising Web application vulnerabilities
Twitter bugs, DNSSEC and broswer security
Month of Twitter Bugs project to document Twitter flaws
Are Web application penetration tests still important?
IT pros can detect, prevent website vulnerabilities, thwart attacks
PCI compliance requirement 6: Systems and applications
Trust eroding as social engineering attacks climb in 2009, says Kaspersky expert
US-CERT warns of Gumblar, Martuz drive-by exploits
XSS bugs, information leakage top list of website vulnerabilities

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Diffie-Hellman key exchange  (SearchSecurity.com)
intrusion prevention  (SearchSecurity.com)
network behavior analysis  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts