Home > Security Tips > Guest Commentary > Inconsistent terminology is a security hobgoblin
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

GUEST COMMENTARY

Inconsistent terminology is a security hobgoblin


Stuart Holoman, Guest Contributor
12.17.2003
Rating: -3.25- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Cisco Systems recently teamed with major antivirus vendors to "push access privilege to routers." "Key to the program," according to a Security Wire Perspectives article, "is the new Cisco Trust Agent, a software client" installed on PCs that gathers data from other clients -- including antivirus software -- and relays it to "routers and other network devices."

So what's the problem? I'm aware of seven different definitions for "clients and servers" from hardware, software and object-oriented vendors, and none represent the terms as used in this instance.

We shouldn't really be surprised, though. The infosecurity world is filled with inconsistent terminology. Blame it on marketers deliberately misusing words to sell something. Blame it on media pundits explaining complex concepts in limited space, incorrectly using familiar words rather than taking the space to explain it accurately. Blame it on users applying terms incorrectly. The result is an imprecise language that won't support accurate discussions or understanding of the real nature of risks and mitigating controls.

To address IT security, we must clean up our language.

Perhaps we need new generalized words. Rather than computing/communications, why not "computication"? Perhaps we need to take the space to be more specific. For instance, client boxes talk to server boxes, and processes talk to processes. But boxes don't talk to processes. Perhaps we need to deal with the specifics. The topology of Netware running on ArcNet LANs? It's a "star-bus-ring-mesh-star." The server and workstations hooked up to a repeater hub with wires forms a media star. Electrically (Layer 1) all NICs are connected on a signaling bus. Link and network access (Layers 2-3) is accomplished by token passing in a logical ring. End-to-end (Layer 4), messaging is effectively a fully connected logical mesh. Using a Netware server and IPX/SPX, sessions (Layers 5-7) all home on the server, a logical star (with a different hub than the media star). Hence the overall topology is "star-bus-ring-mesh-star," and each layer has its own risks and mitigating controls which need to be dealt with separately -- layer-by-layer -- and not as a single entity with a single topology.

Risk mitigation requires precision and accuracy -- all the time. This especially applies to marketers and pundits, on whom we depend for language revealing the true nature of particular tools.

If such language is not forthcoming from these wordsmiths, we must clean up our act ourselves. We should adopt terms from standards organizations (IEEE, ISO, NIST, etc.); from projects like one by MITRE Corp., which is developing a standard language to use in searching for software bugs in computer systems; or from our own consortiums.

Whatever the source, we need to recognize the need for language which illuminates rather than obfuscates. Security by obscurity may have worked in the past, but no more. The first key to security is understanding our world in unambiguous terms. That requires unambiguous language. If we are to take this seriously, we can demand no less.

That means no more "server client agents sending messages to that router box." This will not be easy, but it could be fun.

About the author
Stuart Holoman is a principle consultant with Holocon Computications Consulting in Raleigh, NC. Formerly with Bell Laboratories, he is involved with the security and audit communities providing technical training and developing technology-independent system analysis methodologies, such as the Audit and Security Analysis (ASA) model.


Test your knowledge of basic security terminology with our quiz.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Guest Commentary,   Glossaries and Definitions,   Security Basics,   Editorials and Opinion,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Guest Commentary
Google hacking exposes a world of security flaws
Eliminating the threat of spam email attacks
Outsourcing IT services: Is it worth the security risk?
How permanent is your storage solution?
Honeypots can strengthen reconnaissance and lower intrusion noise
Freedom of speech or lack of professional responsibility?
This year compliance, next year control
Senior security member explains his position on Abagnale
Computer Security Institute's leader responds to Abagnale flap
Spokesman or poster child?

Glossaries and Definitions
The best of SearchSecurity.com

Editorials and Opinion
The best of SearchSecurity.com
Getting back to basics
Best of SearchSecurity in January 2004
Fighting the hacker myth
Of hackers and Hannibal Lechter
Security in 2004: More of the same
June 2003: The Month in Review
A feasible plan for a central virus-naming body

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts