Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Threat Intelligence: Sink or Swim?
Newest First  |  Oldest First  |  Threaded View
MichaelSentonas
50%
50%
MichaelSentonas,
User Rank: Apprentice
1/14/2015 | 8:24:51 PM
Device and industry threat intelligence

With all of the device and industry threat intelligence, I would love to tag all the information by source to make it easier to see what information is providing value.  If I am not getting any value from certain feeds then maybe stop using it, might be a nice "feature" especially to work out what you pay for in the upcoming year. 

MichaelSentonas
50%
50%
MichaelSentonas,
User Rank: Apprentice
1/12/2015 | 4:02:01 PM
Re: What about privacy?
Protecting privacy is critical and needs to be carefully respected with any sharing. Sharing intelligence should never weaken and compromise privacy but there is meaningful information that can be provided to help identify indicators of attack and compromise. There certainly have been a lot of proof of concept hacks on consumer based IoT devices, but it's in the business where there will likely be real threats that we will see in 2015. Last year we saw an attack that used the HVAC system, this year it is plausible that we will see attacks that will exploit IoT devices in the enterprise and then move laterally once inside. We should be capturing information from these devices and using the event information to better protect ourselves.
MichaelSentonas
50%
50%
MichaelSentonas,
User Rank: Apprentice
1/12/2015 | 12:09:05 PM
Re: Forwarding of all raw Data to Event Managers
You bring up a really good point, most SIEM solutions today struggle as it is, so forwarding all the event information from so many additional devices will become a massive issue if you cannot correlate it quickly and an even bigger problem if you cannot remove noise.  That said, I want to know if someone unlocked a door— say in a semiconductor fabrication plant— when they were meant to be on holidays. To your point, big data can be a big problem in the security world when you are trying to find a very specific, targeted issue, but this is also when we need to move past the traditional SIEM products which are fast becoming irrelevant and adopt more analytics and contextualization.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
1/8/2015 | 9:31:34 AM
Re: Forwarding of all raw Data to Event Managers
That's makes sense. I too am interested to see how the IoT will fare in terms with privacy. Also the difference in how enterprises will handle enterprise given devices versus personal devices as the security safeguards will differ from device to device.
1eustace
50%
50%
1eustace,
User Rank: Strategist
1/7/2015 | 8:40:28 PM
Re: Forwarding of all raw Data to Event Managers
True, the volume of data would be enormous, but one could envision a solution involving distributed real-time processing by some, if not most of the IoT nodes which themselves happen to be computing devices.  This would be similar to statistical process controls (SPC) used in manufacturing whereby humans would only be alerted on anormalies for closer examination. Create a hierarchical distributed processing architecture among processor capable nodes and gateways you may end up not needing a supercomputer afterall.  Improve algorithms with experience and you might just stand the chance to eliminate false alarms.  It is actually a clever scheme, and probably an inevitable approach as IoT node count grows, but I worry about privacy as posted in another comment.
1eustace
50%
50%
1eustace,
User Rank: Strategist
1/7/2015 | 8:27:26 PM
What about privacy?
I love the idea of "community-level information sharing and analysis centers" but what about privacy? Forward event managers a winter day log in Canada that includes sudden drop in energy consumption by the furnace, missing pet door activity, garage door access, a call to the vet, another garage door access, and the event managers will deduce with high probability of success that you came home to a sick dog.  You inadvertently just gave away pertinent detail in the form of metadata.  Point is metadata is data and can reveal a lot more than actual data.  When you start sharing IoT logs, where do you draw the line to privacy?  Thoughts?
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
1/7/2015 | 3:32:14 PM
Forwarding of all raw Data to Event Managers
Would you recommend with the IoT that all logs from these devices get forwarded to event managers? My worry is that with emerginng technologies that these new log streams won't be able to be processed efficiently until we fully comprehend their exploits. I feel in that case logs may just become noise. Thoughts?


Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment:   It's a PEN test of our cloud security.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7220
PUBLISHED: 2020-01-23
HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.
CVE-2019-15707
PUBLISHED: 2020-01-23
An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to perform system backup config download they should not be authorized for.
CVE-2019-15712
PUBLISHED: 2020-01-23
An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to access web console they should not be authorized for.
CVE-2019-16512
PUBLISHED: 2020-01-23
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is stored XSS in the Appearance modifier.
CVE-2019-16513
PUBLISHED: 2020-01-23
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests.