Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Big Data & The Security Skills Shortage
Oldest First  |  Newest First  |  Threaded View
Ulf Mattsson
100%
0%
Ulf Mattsson,
User Rank: Moderator
4/29/2015 | 2:23:14 PM
A wider skill shortage
I agree that "in the security space, its next to impossible to find security professionals with just one of these specialized, essential skill sets." I'm also concerned about all sensitive business data that we are collecting in Big Data.

I think that Big Data is changing the way we are dealing with data. Unfortunately, many organizations have rushed into Big Data focused solely on ROI, and privacy is an afterthought. Many companies are now collecting data files into Big Data environments without fully understand what specific sensitive information that is hidden in those files.

Since there is a shortage in Big Data skills and an industry-wide shortage in data security personnel, many organizations don't even know they are doing anything wrong from a security perspective. In many cases they do not have the resources to analyze before collecting huge volumes of data files.

I think that many organizations shortly will be struggling with a major big data barrier:

1. I think a big data security crisis is likely to occur very soon and few organizations have the ability to deal with it.
2. We have little knowledge about data loss or theft in big data environments.
3. I imagine it is happening today but has not been disclosed to the public.

I recently read the Gartner Report "Big Data Needs a Data-Centric Security Focus" concluding "In order to avoid security chaos, Chief Information Security Officers (CISOs) need to approach big data through a data-centric approach. The report suggests that new data-centric audit and protection solutions and management approaches are required.

I noted that companies are starting to follow these guidelines. For example, Hortonworks Hadoop distribution for Big Data recently released the types of features that Gartner is recommending, including data tokenization (on the node!), advanced HDFS Encryption, key management and auditing.

Ulf Mattsson, CTO Protegrity
HM
50%
50%
HM,
User Rank: Apprentice
4/30/2015 | 2:12:11 PM
Big Data
Peter, great article. We are seeing an increase in businesses seeking specialized skills to help address challenges that arose with the era of big data. The open source HPCC Systems platform from LexisNexis helps to fill this gap by allowing data analysts themselves to own the complete data lifecycle. Designed by data scientists, the programming language called ECL is declarative and expresses data algorithms across the entire HPCC platform. Their built-in analytics libraries for Machine Learning and BI integration provide a complete integrated solution from data ingestion and data processing to data delivery. HPCC Systems provides proven solutions to handle what are now called Big Data problems, and have been doing so for more than a decade.
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
4/30/2015 | 5:48:02 PM
Dream Job - Opportunity for the Industry
While I agree that this analyst probably doesn't exist in the formal InfoSec organization, I'd argue that there are probably hackers out there that actually have the needed skillset but haven't touched on every area you've noted with full expertise.  What I think you are describing, however, is a dream job.  I think there is an opportunity here for the InfoSec industry to build out the skillset requirements and the education needs toward honing these skills into a certifiable InfoSec career role.  Understand, the result might have to be a whole new collection of tools; I've read several books on data science and have been wowed by the Python and R code out there some data scientists are using to work with data on the scale you describe.  Marry that to either several years' experience in the underground, or working as a white hat in corporate environments, and you have your unicorn.  

I think if this could become a certification track, not only would the InfoSec sector be the better for it, but, damn, would the work-day get that much more interesting and enjoyable for some lucky geeks :-)
PSchlampp
50%
50%
PSchlampp,
User Rank: Author
5/1/2015 | 2:53:20 PM
Re: Dream Job - Opportunity for the Industry
Christian – Thanks for the response. I agree with your assessment, it is a dream job, but I fear that it's a dream job for only a handful of people. I will borrow from the well published quote – "A data scientist is someone who is better at statistics than any software engineer and better at software engineering than any statistician". You can expand that quote to say – A security analyst needs to be a better security expert than data scientist and software engineer, and a better data scientist than a security expert and software engineer. . .and you get the rest". My point is that while there will be smart people that work in all three domains and can acquire the right skill set – the industry needs people with these skills in vast numbers not only a handful. As a security professional and with faith in human ingenuity, I would rather have security analysts combat cybercriminals and defend my organization over machines. As a vendor, what we can do is provide the right tools and data insights to the security analyst so that they are spending all their time making decisions as opposed to collecting and preparing data for analysis.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Enterprise Cybersecurity Plans in a Post-Pandemic World
Download the Enterprise Cybersecurity Plans in a Post-Pandemic World report to understand how security leaders are maintaining pace with pandemic-related challenges, and where there is room for improvement.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-29763
PUBLISHED: 2021-09-16
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service. IBM X-Force ID: 202267.
CVE-2021-29825
PUBLISHED: 2021-09-16
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM X-Force ID: 204470.
CVE-2021-29842
PUBLISHED: 2021-09-16
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.
CVE-2021-29752
PUBLISHED: 2021-09-16
IBM Db2 11.2 and 11.5 contains an information disclosure vulnerability, exposing remote storage credentials to privileged users under specific conditions. IBM X-Fporce ID: 201780.
CVE-2021-34798
PUBLISHED: 2021-09-16
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.