Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics //

Security Monitoring

6/28/2013
02:16 PM
Wendy Nather
Wendy Nather
Commentary
50%
50%

Surrendering The Endpoint

Imagine there’s no desktop...

What if you had to design all of your security and monitoring around the fact that it's not your endpoint any more, and it will never be your endpoint again?

Yes, I know there are a few verticals where the security requirements are so stringent this won't be the case; the organization insists on end-to-end ownership along with end-to-end management. But let's all partake of the clue buffet: For the majority of enterprises out there, the ownership and control are going to continue to erode, and it will be harder for security teams to argue that the business should pay for redundant endpoints; the potential capital savings are too great with BYOD. If you're giving your data to a third-party provider already, then why wouldn't you do that on the user end as well?

When you do the thought experiment, a few issues might come to light. One is that if it's not your endpoint, how can you assert the right to monitor it? (NSA jokes can go in the comments section.) Monitoring may have to become more granular. The enterprise could have the right to monitor any interactions involving the infrastructure that it does own: You could watch the traffic from a phone that's hitting your server, but you couldn't watch all the phone's traffic.

If you can't monitor what's actually happening on the endpoint, then it's pretty clear that you need to get your enterprise data off of it. We're seeing more vendors offering "panes of glass" applications that allow a mobile user to view the application that's hosted by the enterprise. In other words, we had a thin client back when it was a Web browser and a Web server. The client got thicker when we developed mobile applications, and now we're putting the client back on a diet because we shouldn't trust the endpoint after all.

The corollary to withdrawing from the endpoint is that you can't trust it any more. Companies that provide applications to customers, such as banking apps, know this all too well. (One figure I've heard is that roughly 25 percent of a bank's customers are accessing its site from an infected endpoint.) The type of monitoring you do has to change. You'll treat the endpoint as potentially hostile; you won't care what happens on it, as long as it behaves itself when it's accessing your resources.

So if you surrender the endpoint, you'll just have to pull your defensive perimeter in tighter. Some say that the app has become the perimeter, some say it's the data, and some claim it's the identity. You'll have to do more behavior monitoring and up-front authentication because you'll have to decide with each session whether to continue to trust that user. Again, this is not news to several industry groups out there. But the very organizations that will benefit most financially from BYOD are probably the ones that still need to learn this and must rearchitect their security accordingly.

Wendy Nather is Research Director of the Enterprise Security Practice at the independent analyst firm 451 Research. You can find her on Twitter as @451wendy. Wendy Nather is Research Director of the Enterprise Security Practice at independent analyst firm 451 Research. With over 30 years of IT experience, she has worked both in financial services and in the public sector, both in the US and in Europe. Wendy's coverage areas ... View Full Bio

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
New 'Nanodegree' Program Provides Hands-On Cybersecurity Training
Nicole Ferraro, Contributing Writer,  8/3/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15820
PUBLISHED: 2020-08-08
In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.
CVE-2020-15821
PUBLISHED: 2020-08-08
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
CVE-2020-15823
PUBLISHED: 2020-08-08
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
CVE-2020-15824
PUBLISHED: 2020-08-08
In JetBrains Kotlin before 1.4.0, there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.
CVE-2020-15825
PUBLISHED: 2020-08-08
In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.