Analytics // Security Monitoring
6/28/2013
02:16 PM
Wendy Nather
Wendy Nather
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Surrendering The Endpoint

Imagine there’s no desktop...

What if you had to design all of your security and monitoring around the fact that it's not your endpoint any more, and it will never be your endpoint again?

Yes, I know there are a few verticals where the security requirements are so stringent this won't be the case; the organization insists on end-to-end ownership along with end-to-end management. But let's all partake of the clue buffet: For the majority of enterprises out there, the ownership and control are going to continue to erode, and it will be harder for security teams to argue that the business should pay for redundant endpoints; the potential capital savings are too great with BYOD. If you're giving your data to a third-party provider already, then why wouldn't you do that on the user end as well?

When you do the thought experiment, a few issues might come to light. One is that if it's not your endpoint, how can you assert the right to monitor it? (NSA jokes can go in the comments section.) Monitoring may have to become more granular. The enterprise could have the right to monitor any interactions involving the infrastructure that it does own: You could watch the traffic from a phone that's hitting your server, but you couldn't watch all the phone's traffic.

If you can't monitor what's actually happening on the endpoint, then it's pretty clear that you need to get your enterprise data off of it. We're seeing more vendors offering "panes of glass" applications that allow a mobile user to view the application that's hosted by the enterprise. In other words, we had a thin client back when it was a Web browser and a Web server. The client got thicker when we developed mobile applications, and now we're putting the client back on a diet because we shouldn't trust the endpoint after all.

The corollary to withdrawing from the endpoint is that you can't trust it any more. Companies that provide applications to customers, such as banking apps, know this all too well. (One figure I've heard is that roughly 25 percent of a bank's customers are accessing its site from an infected endpoint.) The type of monitoring you do has to change. You'll treat the endpoint as potentially hostile; you won't care what happens on it, as long as it behaves itself when it's accessing your resources.

So if you surrender the endpoint, you'll just have to pull your defensive perimeter in tighter. Some say that the app has become the perimeter, some say it's the data, and some claim it's the identity. You'll have to do more behavior monitoring and up-front authentication because you'll have to decide with each session whether to continue to trust that user. Again, this is not news to several industry groups out there. But the very organizations that will benefit most financially from BYOD are probably the ones that still need to learn this and must rearchitect their security accordingly.

Wendy Nather is Research Director of the Enterprise Security Practice at the independent analyst firm 451 Research. You can find her on Twitter as @451wendy. Wendy Nather is Research Director of the Enterprise Security Practice at independent analyst firm 451 Research. With over 30 years of IT experience, she has worked both in financial services and in the public sector, both in the US and in Europe. Wendy's coverage areas ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-3304
Published: 2014-10-30
Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.

CVE-2013-7409
Published: 2014-10-30
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .m3u (playlist) file.

CVE-2014-3446
Published: 2014-10-30
SQL injection vulnerability in wcm/system/pages/admin/getnode.aspx in BSS Continuity CMS 4.2.22640.0 allows remote attackers to execute arbitrary SQL commands via the nodeid parameter.

CVE-2014-3584
Published: 2014-10-30
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.

CVE-2014-3623
Published: 2014-10-30
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vect...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.