Risk
2/26/2014
12:10 PM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

Juniper Security Chief Takes Swipe At Security Apathy

RSA keynote urges more innovation and active defense

RSA CONFERENCE 2014 -- San Francisco -- Yesterday at RSA, Juniper Network's security honcho urged security professionals to be bolder in their outrage for what was happening to their information and to take risks on approaches that challenge current conventions.

RSA Conference 2014
Click here for more articles about the RSA Conference.

"Our privacy is being invaded, or IP is being stolen, the public trust is at an all-time low, and the attack on our information is outrageous," said Nawaf Bitar, senior vice president and general manager of the security business unit at Juniper. "But you know what? I don't think we give a damn. I'm fed up with talking about outrage."

In his keynote at the show, Bitar pointed out that American society in general suffers from what he calls First World Outrage, an ill that has most people throwing up only mild, token signs of caring about circumstances that they truly think little about and act not at all to change. Compared to true acts of outrage, acts of resistance like Tibetan self-immolation and the Tiananmen Square protests, First World Outrage looks meaningless.

"'Liking' a cause on Facebook is not outrage. Retweeting a link is not outrage. Posting a bad review is not outrage. Not showing up at a conference is not outrage," he said, specifically taking a swipe at those boycotting the RSA Conference over RSA's cooperation with the NSA.

Most people don't take true action from outrage unless family or income is threatened by circumstances, he told the audience. But he believes a third major concern should spur more of us to true action: threats to our information.

"We should be outraged. Nation-state attacks against our companies are putting our jobs and our economy at risk. Cyberattacks that steal our personal information are a daily occurrence," he said. "Our information is one of our most important possessions and we should treat it as such."

What is happening to information today should have the security industry up in arms and willing to respond meaningfully and radically, he urged.

"In cybersecurity we continue to cling to old ideas even in the face of obvious deficiencies and limitations," he explained. "For example, we espouse the signature approach to eradicate known viruses. Today, we all know that approach is far from perfect."

In business, meaningful response doesn't just mean doing the same thing we always have done. Instead, he advocated for more revolutionary approaches and some calculated risk taking, explaining that as things stand today, even in an industry of innovators, innovation is often met with harsh skepticism.

"How can we stifle innovation? Don't get me wrong -- every new technique deserves scrutiny. Every bad idea needs to be challenged," Bitar said. "But we must be careful not to dismiss too quickly, for it is the incomplete and partial solutions today that will lead to the breakthroughs of the future."

In particular, active defense, something juniper has advocated for some time now, should be something considered and tried, he told the audience.

"We should be truly outraged, not first-world outraged. The time for apathy is over," he urged. "We cannot go on the offensive and hack back, but we can no longer remain passive. It's time for a new type of offense -- a type of active defense that disrupts the economics of hacking and challenges convention. It's time for all of us to turn the tables on the attackers."

However, for as much rhetoric as Bitar espoused, there weren't many details of exactly how he hoped the industry would carry it all out. Some analysts were skeptical.

"He draws these great parallels with all these other people who are being killed, imprisoned and oppressed in daily life, but what are we supposed to do? Are we supposed to set fire to our ones and zeros?" said Wendy Nather, research director for security at 451 Research. "It's great to say we should all be outraged. [But] he didn't really say what we should be doing."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-2595
Published: 2014-08-31
The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, enables MSM_CAM_IOCTL_SET_MEM_MAP_INFO ioctl calls for an unrestricted mmap interface, which all...

CVE-2013-2597
Published: 2014-08-31
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that lever...

CVE-2013-2598
Published: 2014-08-31
app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to overwrite signature-verification code via crafted boot-image load-destination header values that specify memory ...

CVE-2013-2599
Published: 2014-08-31
A certain Qualcomm Innovation Center (QuIC) patch to the NativeDaemonConnector class in services/java/com/android/server/NativeDaemonConnector.java in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.3.x enables debug logging, which allows attackers to obtain sensitive disk-encryption pas...

CVE-2013-6124
Published: 2014-08-31
The Qualcomm Innovation Center (QuIC) init scripts in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.4.x allow local users to modify file metadata via a symlink attack on a file accessed by a (1) chown or (2) chmod command, as demonstrated by changing the permissions of an arbitrary fil...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.