home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Powered by InformationWeek Business Technology Network
InformationWeek 500 Conference -- September 14-16, 2008 Registed Today!

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Special Survivor's Guide Issue
F E A T U R E  
SECURITY

The Survivor's Guide to 2002

  December 17, 2001
  By Mike Fratto



Printer Print Full Article
Printer Print This Page
Printer Download the PDF
E-Mail E-Mail This URL
Public Key Infrastructure

If there is a market still looking for a raison d'ętre, it's PKI. PKI is expensive and complicated to deploy, and its weak client support and even weaker end-user security make it a tough sell. Many analysts point out that e-commerce, the first "big problem" that PKI could solve, doesn't in fact need it. Well, not client PKI anyway--obviously, online shopping with SSL/TLS does leverage the components of a PKI, but users are still authenticated by user name-password over SSL.

The server side of PKI is well implemented, and work to make PKI more manageable is ongoing. But the model falls apart on the client side. Unless you deploy the entire vendor solution, like Entrust's Authority and desktop solutions, certificate life-cycle management is a nightmare. At best, users can renew and revoke their own certificates, but other processes, like certificate-revocation checking, are not well-supported.

Netscape and Microsoft simply couldn't put their differences aside and agree to support CDP (CRL distribution points) or OCSP (Online Certificate Status Protocol). So you standardize on a single browser or develop for both.

So where is PKI heading? Microsoft's betting that tight integration of digital certificates in Windows 2000 and XP will provide an entry point for corporations to deploy PKIs. Microsoft's Certificate Server, using a default installation, is simple to deploy and manage. In fact, setting a group policy for computer auto-enrollment distributes certificates to computers in the domain automatically. Third-party vendor developers leveraging Microsoft's CAPI (Crypto API) and CSP (Cryptographic Service Provider) can build PKI-enabled applications with very little development.

Of course, PKI is a technology in need of an application, and development has largely followed a model where specific vendors join partner programs and subsequently receive application certification when integration APIs are developed and deployed. If your application is homegrown or not one of the few certified, be prepared to spend a lot of money in custom development.

Intrusion Detection and Vulnerability Assessment

Of course, access control without monitoring is like leaving kids in a candy store. Sure, you know they're in there, but you don't know what they are doing. Like virus scanning, IDSes (intrusion detection systems) are only as current as their last update. The time lag between when an exploit hits the public to when IDS vendors develop signatures to detect them can be weeks or months. Even then, IDS systems are dubious at best.


  • Companies To Watch
  • Standards
  • Why? First, IDSes are largely signature-based. Change the footprint of the attack, and chances are it will sneak by. IDS systems will always be behind the curve. The second limitation is false positives caused by normal network traffic triggering signatures. Take an IDS and stick it onto a network, and you'll be buried in alerts in no time. Key to a successful deployment are tuning of the IDS and intimate knowledge of the network applications that are running.

    There are a few anomaly IDS systems, which monitor traffic, user and program activity and analyze logs to create a baseline, or normal network behavior. Deviations from the baseline, as well as known attack signatures, are combined to provide a broader view of the network and to highlight abnormal activity. How well procedural IDS works depends largely on how normalized the traffic patterns on your network are. We will be seeing more anomaly IDSes in the future, but unless you have the staff to install, monitor and maintain the anomaly IDS system, they may not provide much ROI (return on investment).

    Online Special

    Security still keeping you up at night? Read our "Rational Responses to Irrational Events" to help you get a grip.
    An alternative to anomaly IDSes is security event aggregation and correlation applications, such as netForensics, which monitors data from log sources and provides event correlation and analysis. No baseline is taken; events are processed live on the network as well as stored for historical trending. The driver for security event correlation is no different from that of network event correlation; raise the signal-to-noise ratio and present significant events to administrators. A tall task, and one not unlike procedural IDS.

    Mike Fratto is a senior technology editor based in Network Computing's Syracuse University Real-World Labs®; he covers all security-related topics. Prior to joining this magazine, Mike worked as an independent consultant in central New York. Send your comments on this article to him at mfratto@nwc.com.


       Page: 1 | 2 | 3 | 4 | Next Page





    Ready to take that job and shove it?

    Function:

    Keyword(s):

    State:
    SPONSOR
    RECENT JOB POSTINGS
    CAREER NEWS
    Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

    Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










    InformationWeek U.S. IT Salary Survey 2008
    Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
     
    ROLLING RIGHT ALONG
    Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



    Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








    TechSearch


    Microsite of the Week


    Powerful Information at Your Fingertips



    InformationWeek Business Technology Network
    InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
    InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
    Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo Jitter
    space
    Techweb Events Network
    InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
    Black HatGTECEnergy CampMashup CampStartup Camp
    space
    Light Reading Communications Network
    Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet Evolution
    Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
    space
    Financial Technology Network
    Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
    space
    Microsoft Technology Network
    MSDN MagazineTechNetThe Architecture Journal
    space
    App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
    About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
    Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights