Risk
2/26/2014
12:10 PM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

Juniper Security Chief Takes Swipe At Security Apathy

RSA keynote urges more innovation and active defense

RSA CONFERENCE 2014 -- San Francisco -- Yesterday at RSA, Juniper Network's security honcho urged security professionals to be bolder in their outrage for what was happening to their information and to take risks on approaches that challenge current conventions.

RSA Conference 2014
Click here for more articles about the RSA Conference.

"Our privacy is being invaded, or IP is being stolen, the public trust is at an all-time low, and the attack on our information is outrageous," said Nawaf Bitar, senior vice president and general manager of the security business unit at Juniper. "But you know what? I don't think we give a damn. I'm fed up with talking about outrage."

In his keynote at the show, Bitar pointed out that American society in general suffers from what he calls First World Outrage, an ill that has most people throwing up only mild, token signs of caring about circumstances that they truly think little about and act not at all to change. Compared to true acts of outrage, acts of resistance like Tibetan self-immolation and the Tiananmen Square protests, First World Outrage looks meaningless.

"'Liking' a cause on Facebook is not outrage. Retweeting a link is not outrage. Posting a bad review is not outrage. Not showing up at a conference is not outrage," he said, specifically taking a swipe at those boycotting the RSA Conference over RSA's cooperation with the NSA.

Most people don't take true action from outrage unless family or income is threatened by circumstances, he told the audience. But he believes a third major concern should spur more of us to true action: threats to our information.

"We should be outraged. Nation-state attacks against our companies are putting our jobs and our economy at risk. Cyberattacks that steal our personal information are a daily occurrence," he said. "Our information is one of our most important possessions and we should treat it as such."

What is happening to information today should have the security industry up in arms and willing to respond meaningfully and radically, he urged.

"In cybersecurity we continue to cling to old ideas even in the face of obvious deficiencies and limitations," he explained. "For example, we espouse the signature approach to eradicate known viruses. Today, we all know that approach is far from perfect."

In business, meaningful response doesn't just mean doing the same thing we always have done. Instead, he advocated for more revolutionary approaches and some calculated risk taking, explaining that as things stand today, even in an industry of innovators, innovation is often met with harsh skepticism.

"How can we stifle innovation? Don't get me wrong -- every new technique deserves scrutiny. Every bad idea needs to be challenged," Bitar said. "But we must be careful not to dismiss too quickly, for it is the incomplete and partial solutions today that will lead to the breakthroughs of the future."

In particular, active defense, something juniper has advocated for some time now, should be something considered and tried, he told the audience.

"We should be truly outraged, not first-world outraged. The time for apathy is over," he urged. "We cannot go on the offensive and hack back, but we can no longer remain passive. It's time for a new type of offense -- a type of active defense that disrupts the economics of hacking and challenges convention. It's time for all of us to turn the tables on the attackers."

However, for as much rhetoric as Bitar espoused, there weren't many details of exactly how he hoped the industry would carry it all out. Some analysts were skeptical.

"He draws these great parallels with all these other people who are being killed, imprisoned and oppressed in daily life, but what are we supposed to do? Are we supposed to set fire to our ones and zeros?" said Wendy Nather, research director for security at 451 Research. "It's great to say we should all be outraged. [But] he didn't really say what we should be doing."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-4594
Published: 2014-10-25
The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allows remote anonymous users to use the payment of other anonymous users when submitting a form that requires payment.

CVE-2014-0476
Published: 2014-10-25
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.

CVE-2014-1927
Published: 2014-10-25
The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "$(" command-substitution sequences, a different vulnerability than CVE-2014-1928....

CVE-2014-1928
Published: 2014-10-25
The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "\" (backslash) characters to form multi-command sequences, a different vulner...

CVE-2014-1929
Published: 2014-10-25
python-gnupg 0.3.5 and 0.3.6 allows context-dependent attackers to have an unspecified impact via vectors related to "option injection through positional arguments." NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.