Analytics // Security Monitoring
4/23/2013
02:23 AM
Wendy Nather
Wendy Nather
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Did The Dog Bark In the Night?

What we still don't know, despite the data

There are many threat and breach reports out there, and many are very good, but I do confess that my favorite after all these years is still the Verizon Business Data Breach Investigations Report. Not only does it have the largest sample size (with 19 partners adding their data this year), but it also has innovative graphics and an open discussion about the limitations of its data. It's hilarious to read. By "hilarious," I don't mean, "Do they realize their fly is open?" hilarious, but the kind of hilarity you get when you buy enough tureen-sized drinks for risk analysis geeks.

When you have bad data, you quickly run out of things to do with it. When you have great data, the more you examine it, the more questions it prompts. Take, for example, the updated statistics on third-party notification -- 52% of breaches at large enterprises and 23% at small enterprises were first noticed by unrelated third parties, and almost all of those were cases of espionage. (This doesn't include breaches that were detected by common point-of-purchase fraud detection, by the way; those are considered to be related parties.)

First of all, you would think that the larger percentage would be at smaller enterprises; aren't they the ones who are less likely to be able to find things themselves? On the other hand, espionage probably targets larger enterprises, so maybe it makes more sense the way it is.

But there's a third thought buried in here: Could it be that more breaches are discovered by unrelated third parties because of the growth of threat intelligence overall? If you put more intelligence in the hands of central traffic nodes such as ISPs, then they're bound to find more in what they're already seeing. And if there are more threat intelligence vendors, then they are more likely to contact enterprises when they see indicators of compromise that they already know from other cases. So this increase might actually be a good sign.

One more heretical thought: The DBIR doesn't contain any information about the failures of organizations to detect their own breaches. Is it that they weren't doing any monitoring? Were they monitoring, but just not doing it very well? Or did they have all the latest and greatest security monitoring tools, but they didn't actually work?

I'm just going to leave that out there for the next round of drinks.

Wendy Nather is Research Director of the Enterprise Security Practice at the independent analyst firm 451 Research. You can find her on Twitter as @451wendy. Wendy Nather is Research Director of the Enterprise Security Practice at independent analyst firm 451 Research. With over 30 years of IT experience, she has worked both in financial services and in the public sector, both in the US and in Europe. Wendy's coverage areas ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5242
Published: 2014-10-21
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.

CVE-2012-5243
Published: 2014-10-21
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.

CVE-2012-5702
Published: 2014-10-21
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to i...

CVE-2013-7406
Published: 2014-10-21
SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-4514
Published: 2014-10-21
Cross-site scripting (XSS) vulnerability in includes/api_tenpay/inc.tenpay_notify.php in the Alipay plugin 3.6.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to the getDebugInfo function.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.