Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

2/4/2016
02:00 PM
50%
50%

Cybersecurity Smackdown: What Side Are You On?

Analytics vs. Encryption. Prevention vs. Detection. Machine Learning: Promise or Hype? The Firewall: Dead or Still Breathing? The sharpest minds in the security industry debate some of the industry's most contentious issues.

It’s debate season – at least in the political realm. So to get into the spirit of the US primary election, Dark Reading has put together in one place excerpts from our ongoing series of great cybersecurity debates about four hot new information security technologies versus their legacy counterparts. Industry leaders make impassioned arguments for the new versus the tried and true, or a combination of the two.

 

ANALYTICS VS. ENCRYPTION

Encryption Has Its Place But It Isn’t Foolproof

By Doug Clare, Vice President of Product Management, FICO

Encryption technology is improving, as are best practices in deploying it; and everyone should embrace these improvements. But encryption alone is not enough, and may induce a false sense of security among those who depend on it. Read more.

As Good As They're Getting, Analytics Don't Inherently Protect Data

By Scott Petry, Co-Founder & CEO of Authentic8

The suggestion to “use analytics to secure your system” is flawed, and the argument to shift away from data security systems like encryption and move to analytics is fallacious. In fact, analytics is not an either-or-choice with encryption. Suggesting that firms choose between the two is like a doctor telling a patient to choose either vitamins or exercise. Both have their place in a healthy lifestyle. Read more.

 

MACHINE LEARNING: HYPE VS. PROMISE   

Machine Learning Is Cybersecurity's Latest Pipe Dream

By Simon Crosby, co-founder and CTO at Bromium

There is a huge difference between being pleased when Netflix recommends a movie you like, and expecting Netflix to never recommend a movie that you don’t like. So while applying machine learning to your security feeds might deliver some helpful insights, you cannot rely on such a system to reliably deliver only valid results. Read more.

Machine Learning: Perception Problem? Maybe. Pipe Dream? No Way!

By Mike Paquette, VP Products, Prelert

In the most common misperception, machine learning is thought to be a magic box of algorithms that you let loose on your data and they start producing nuggets of brilliant insight for you. If you apply this misperception to the use of machine learning for cybersecurity, you might think that after deploying it, your security experts will be out of a job since algorithms will be doing all their important threat detection and prevention work. The reality is that ML is a practical way to use newer technology to automate the analysis of log data to better detect cyberthreat activity, under the direction and guidance of an organization's security experts. Read more

 

PREVENTION VS. DETECTION

Time’s Running Out for the $76 Billion Detection Industry

By Simon Crosby, co-founder and CTO at Bromium

Enterprises spend a mind-boggling $76 billion each year to “protect” themselves from cyber-attacks, but the bad guys keep winning because most protection solutions are based on detection instead of prevention. What’s wrong? The answer is the same today as it was in ancient Troy when the Greek army suddenly disappeared, leaving behind an innocent-looking horse that the Trojans willingly brought inside the gates. Read more.

Detection: A Balanced Approach For Mitigating Risk

By Josh Goldfarb, VP and CTO - Emerging Technologies, FireEye

Prevention is necessary, but not sufficient, for a robust and mature security program. Only detection and response can complete the security picture that begins with prevention. Read more

 

THE FIREWALL IS DEAD. LONG LIVE THE FIREWALL.

Why the Firewall is Increasingly Irrelevant

By Asaf Cidon, Co-Founder & CEO, Sookasa

Firewalls only protect what work used to be, not what it is today, a distributed collection of employees connected by mobile devices, in turn connected to the cloud. The only way to secure all company data, then, is to extend enterprise-grade security to these employees’ devices and cloud applications. Read more.

Firewalls Sustain Foundation of Sound Security

By Jody Brazil, Co-Founder & CEO, FireMon

Effective security management will always retain a multi-layered approach necessitating mechanisms that control and limit access. While this may not someday require dependence on network security devices, in today’s environment the firewall remains one of the critical building blocks of network security. Read more

 Interop 2016 Las VegasFind out more about cutting edge security at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Register today and receive an early bird discount of $200.

 

 

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
lorraine89
50%
50%
lorraine89,
User Rank: Ninja
9/26/2016 | 10:06:26 AM
Cyber security
Nice informative article. Though no matter if it is Analytics vs. Encryption. or Prevention vs. Detection at the end of the day, the side which incorporates taking preventive measures before hand is the winning one. Encryption for instance is by far the best method to secure your online connections as well as your personal files or folders on systems. Online encryption in the form of vpn is essential like I use Purevpn to deploy encrypted connection to my server for privacy and security. 
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/9/2016 | 12:55:23 PM
Re: Adopt key less encryption
Quantum computing and the security solutions that it can provide particularly excite me.  It's hard to defeat quantum physics when you have the observer effect and dark matter and all of these mysteries at play.

Of course, as the field -- and our understanding of it -- becomes more advanced, perhaps so too will hacking methods.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/9/2016 | 12:52:59 PM
Re: The problem is people.
@Stephen: Indeed!  As many security colleagues of mine agree, you can have the best security tools in the world -- but they will do you no good if your employees leave the doors wide open!

It's analytics.  It's encryption.  It's firewalls.  It's anti-malware.  It's training.  It's EVERYTHING.
oneilldon
50%
50%
oneilldon,
User Rank: Guru
2/7/2016 | 3:49:02 PM
Adopt key less encryption
Even the ordered mathematical encryption approach is losing ground to advancements in computational capability. In addition to being far too computationally intensive, the operational advantage of pairing of math-based encryption systems and advanced computing, on the verge of Quantum Computing, may be tilting in favor of the determined STEM-endowed nation state adversary.

Now a national security and competitiveness challenge, the state of encryption calls for new thinking, innovation, and disruptive action. It is a false promise that ordered mathematical encryption will yield privacy and security.

One alternative to extricate ourselves from this trap is to invent and adopt key less encryption without dependence on ever increasing advancements in computational technology and without encryption keys to be confiscated by the government only to be hacked by bad actors.
StephenR232
50%
50%
StephenR232,
User Rank: Apprentice
2/6/2016 | 7:01:01 PM
The problem is people.
The root cause for most events is people doing dumb things they've already been told not to do. The only meaningful solution is to take people out of the equation. When the internet is for the most part machines interacting with other machines is when this arms race can be fought to a stalemate. Until then, the side with the most people will lose.
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-29430
PUBLISHED: 2021-04-15
Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send an HTTP request with a very large body, leading to memory exhaustion and denial of service. Sydent also does not limit response size for requests it mak...
CVE-2021-29431
PUBLISHED: 2021-04-15
Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible to exfiltrate data or control request headers, but it might be possible to use the attack to perform a...
CVE-2021-29432
PUBLISHED: 2021-04-15
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.
CVE-2021-29447
PUBLISHED: 2021-04-15
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has be...
CVE-2021-30245
PUBLISHED: 2021-04-15
The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks. The problem has existed since about 2006 and the issue is also in 4.1.9. If the link is specifically crafted this could lead to untrusted code execution. It is always best practice to ...