Upcoming Events

Executive conference

Cloud Connect March 16-18

Comprehensive thought leadership for executives, IT professionals and developers. Topics include: the ROI, cost and economics of on-demand computing; Migration strategies to move from on-premise to cloud-based IT; Vertical cloud specialization, tailoring features and architectures to specific applications, industries, and customer ecosystems

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up
Column - Down to Business
C O L U M N  
Security Surcharge

  October 21, 2002
  By Rob Preston


TOC Issue TOC
Printer Print this article
E-Mail E-Mail this URL
flame author Flame the author

If you're like most IT professionals, you're concerned about the security vulnerabilities of your software. Maybe you're frustrated--or even downright angry. But don't expect the situation to get better anytime soon.

Microsoft is the most visible offender, since its products get attacked more than any other vendor's. Tallies of the top 10 security targets regularly list eight or nine Microsoft products, and new vulnerabilities are discovered weekly. Last month, for instance, a security hole was found in the point-to-point tunneling protocol used in the VPN software Microsoft bundles with Windows 2000 and XP, exposing some corporate networks to attack. Earlier in the month, Microsoft released a patch to fix three flaws in its Java Virtual Machine, one of which lets attackers take control of a user's computer. Microsoft also warned of a flaw in its digital-certificate software that could let attackers steal a consumer's credit-card information.


With its year-old Trustworthy Computing Initiative, Microsoft is employing new tools to detect security flaws during development, and it's working with consulting, patch-management and other partners to alert customers and issue updates when problems arise. But when it comes right down to it, Microsoft really doesn't know what to do next. For its every step to shore up security, it's scrambling a step-and-a-half backward because of the increasing sophistication of hackers, many of whom target Microsoft products with a vengeance.

Speaking at the company's .Net developers conference a month ago, senior VP Brian Valentine admitted that Microsoft's products "just aren't engineered for security"--though he argued that other vendors' products are equally vulnerable. Even as Microsoft and others improve security, Valentine said, hackers will devise new ways to break in. The stats don't lie: In just the first half of this year, the total number of system vulnerabilities reported to CERT were about equal to all those reported in 2001.

The problem has more to do with sophistication than sloppiness: Software is more complex, making exhaustive security testing extremely difficult. Reusable application objects can pass along bugs faster than ever. Black hats are getting smarter, while amateur hackers have easier access to tools of the trade.

Yes, Microsoft and other vendors are culpable; they continue to crank out new versions of software and systems before they can be tested adequately. But vendors aren't rushing product out the door as fast as they used to, either because customers don't have the money for incremental upgrades or they're demanding higher quality from the start.

Extreme Vigilance

Microsoft's software is hit the hardest, according to the conventional wisdom, because it's the most widespread and popular, not necessarily because it's less secure than rival offerings. Still, the more features Microsoft builds into Excel, Exchange, Internet Information Server, SQL Server, Windows and other products--and the more tightly integrated those products become with one another and the more third-party developers introduce their own bugs--the more prone they are to security breaches. Extreme vigilance, Microsoft argues, is the surcharge customers must pay for the ubiquity, feature-richness and compatibility of its products.

So are you and your company willing to pay that surcharge? At the very least, that requires implementing and enforcing a cogent IT security policy; keeping strict tabs on what users deploy; knowing where you're vulnerable and deploying the requisite firewalls, antivirus tools and intrusion-detection systems; and keeping current on software patches (enterprises now spend $2 billion a year just to investigate, prioritize and deploy patches, according to Aberdeen Group). That's what it's going to take to work in a Microsoft--or any--environment. Don't count on any single platform or security vendor to bulletproof your environment for you.

--Rob Preston, rpreston@cmp.com

Best of the Web

Data deduplication: Declawing the clones

Data deduplication is emerging as a critically important new arrow in the storage administrator's quiver to answer hard questions about the increasing problem in storage growth costs.

Quick Read

Compression, Encryption, Deduplication, and Replication: Strange Bedfellows

One of the great ironies of storage technology is the inverse relationship between efficiency and security: Adding performance or reducing storage requirements almost always results in reducing the confidentiality, integrity, or availability of a system.

Quick Read

WAN Optimization Whitelists and Blacklists

Optimization is a fantastic way of saving money and creating really happy customers at the same time, but it doesn't work flawlessly for all applications.

Quick Read

WAN Optimization as a Managed Service: It's Not About the Cost

This insight examines how organizations outsourcing their WAN optimization initiatives to a third-party go about achieving their goals for application performance, reducing operational costs, and streamlining enterprise infrastructure.

Quick Read

  Sponsored Links

Premium Content

Next Generation Data Center, Delivered, November 17th
NWC


Salary

Video