Mar 9, 2015

Cyber security challenges

Cyber security is difficult. It’s actually so difficult that a few years ago the US National Academy of Engineering named securing the cyberspace as one of Grand Challenges of Engineering. Other challenges were e.g. providing access to clean water for everyone and making solar energy economical.

What makes cyber security so hard? There are several reasons. One is the complexity of networks and services. It is plain impossible for anyone to fully understand all the technologies, players, connections and code behind any important or popular service. Second is irrationality of users’ behavior. We tend to think that people are rational, risk-calculating machines. Although we know that’s not the case, services are still designed based on assumption that users will make rational decisions and behave. Third reason is that economics doesn't work for better security. Security level of software-based services is very difficult to explain and prove to users. The implication is that users won’t pay for better security, because they don’t see what they will get. That creates a well-known “market for lemons” problem, where it makes sense for vendors and service providers to implement just the minimum acceptable level of security.

It seems that there are endless list of reasons for cyber security problems, but I’ll add just one more. Fourth reason is that software engineering is very young science. We don’t well understand how to create quality software, not to mention secure software. Sometimes it seems to me that we are like kids playing with all new and fancy technology wanting it all right now without thinking of dangers.

So, how to tackle these problems? I afraid that cyber security will go south for a while before it’s going to get better. The most important thing needed is an attitude change of consumers and vendors. Consumers shouldn't accept insecure products and services – and we should understand that there’s a price tag coming with security. Vendors should make security of their products and services user-friendly, visible and understandable. Security should be sold as an enabler and protector of privacy. We’ll probably need regulation in order to get rid of the externalities and to speed up the process.

All our complex Internet services are based on code. It’s not just that Facebook page or cloud service, but the whole Internet runs on code. All the devices connected to it run some code. Then we stack all these separately coded devices, components and products together to create some new service, what the original developer never thought of. Hence our inability to create secure, quality software is a real problem. From my experience most developers would like to create good, secure code and many even know how to do it, but they have no time or incentives to do so. Universities need to start teaching how create good, secure software for modern, complex environments. Organizations need to understand that coding security in to the services require resources - it’s not just the user visible features that matters.

We certainly need better security products and automation to protect complex software-based services from ever increasing threats. I’m worried that there seems to be lack of security innovations. Technology innovations happen very fast horizontally and often also vertically, but security innovations happen much slower pace and most (if not all) of them seem to be horizontal innovations. We should have more non-security people involved in designing security of products and services. We need views regarding human behavior, economics, user interfaces, etc. Cyber security is too important to be left just to cyber security experts. We also should aim higher that “just security” or even resilience. We should think about anti-fragile systems – systems that become more secure if someone tries to breach them.

Cyber security will stay as a grand challenge for a long time. We need to understand that security can’t be isolated from technology, people, processes and organizations. We need to raise above technology and look at the bigger picture to build secure services. Cyber security will get worse before it’ll get better. We have taken the first step to right direction, though, by understanding that it’s the challenge worth solving. 

Jan 11, 2015

Concensus of 2015 security predictions

I find many security predictions unusable, uninteresting and often just pure marketing material or even misleading. Just for the fun of it, I still like to see the big picture of latest predictions. As in previous years I got security predictions from ten different companies and instead of reading them all, I just put all predictions together and created a word-cloud from combined text.

I used predictions from the same companies as last year: Fortinet, Information Security Forum, Kaspersky, Microsoft, Sophos, Symantec, WatchGuard, Websense, Trend Micro and FireEye.

Here's the "concensus" word-cloud:

2015 security predictions















Compare that to last year's predictions:

2014 security predictions
















Couple of observations. The big ones - as in previous year - are data, devices, mobile and malware. There's a bit more focus on information now, not just data. In 2015 cyber is back. It was big on 2013 list, but less so last year. On the other hand, privacy have disappeared. It wasn't big before, but at least it was there.

My summary last year was: Expect data-stealing malware attacks against all devices.

Since no groundbreaking threats are seen, my summary this year is: Expect attacks against Internet-facing (cyber) systems. The attackers are more likely to go after valuable information, not just raw data.

This year I also tried another approach. I created a separate word-cloud from only the topics of security threats found from the predictions:

2015 security threats - topics only















Interestingly, from that picture, Internet of Things pops out. However, since the vendors often like to play with words when thinking of topic names and headlines, I find the full-text word cloud more interesting. Can't deny the security threat of IoT, though.

Feel free to make you own interpretations or - god forbid - read the individual predictions. You may also check this good summary of the 15 security predictions for 2015.

To me personally, the most useful security predictions document is Information Security Forum's (ISF) Threat Horizon report. It's freely available only to members and for others it's a bit expensive. However, a year old The Executive Summary of Threat Horizon 2016 is downloadable for free (requires registration). A new Threat Horizon 2017 should be out for members pretty soon now.

The Executive Summary of Threat Horizon 2016 shows this threat development according to global member organizations of the ISF:














Check also my word-clouds from previous years. Word-cloud of 2014 security predictions and Mother of all 2013 security predictions.

Nov 29, 2014

Information increases security

The complexity and connectivity of ICT-systems are increasing faster than ever. New technology innovations are born frequently and IT is embedded in all imaginable things. This fast-paced change guarantees, that information security challenges will be plenty. No one person can master the whole huge information security field. Being "an information security expert" is as impossible as being "an Internet expert". Information security professional can be either a generalist, who has wide understanding of the field, or a specialist, who has deep knowledge of one or two specific areas.

The flood of information is a challenge. There is so much to read, watch and learn. Self-motivated learning is a must for information security professionals. I strongly believe in Friedman's formula CQ + PQ > IQ, which says that curiosity and passion are more important for professionals than intelligence.

I recommend Twitter to all colleagues who want to keep themselves on the pulse of information flow. Books, magazines, blogs and research papers are good sources for getting deeper understanding of selected information security topics. Network with you colleagues to share practical experiences - what works and what doesn't. Conversations with fellow experts are also a good therapy - it's soothing to know that everyone has same challenges with their information security programs and practices. Nowadays many seminars are mostly good for networking rather than actually learning something new.

When you are experienced enough and feel that information security talks and challenges start to be same old stuff over and over again, it's time to broaden your horizon. For example better understanding of risk management, business management and behavioral economics will give you tools for applying your information security skills in new and innovative ways. I have find Coursera online courses valuable learning tools.

It's said that the more you learn the better you understand how little you know. In other words, if you think you already master information security, you are still a novice.

Finnish version of this text is available here.

Feb 2, 2014

How to convince the board to accept information security investment?

In last years I've been involved in some information security research projects led by a Finnish University. One of these projects studied what makes the executive board to accept a security investment proposal. Professor Mikko Siponen, who is responsible of this research, has given couple of public presentations explaining the findings. Mikko was ranked best European Information Systems researcher on 2011 and 2012 (world #29) by Association for Information Systems.

Since there's no public version available in English, I summarize here the main points of the research findings.

Earlier research on information security investments is based on following assumptions:

  • decision makers can assess risks neutrally
  • decision makers are able to make rational decisions based on complex calculations
  • investment has a linear effect to risks
  • all relevant information is available
  • decision makers know all the possible choices
  • decision makers always try to maximize net profits

In reality the assumptions are not realistic:

  • information is asymmetric and incomplete
  • some information is subjective (opinions) or guesses
  • adversaries may have other goals than maximising profit
  • calculations require simplified models

The research:

  • questionnaire was sent to 690 biggest Finnish businesses
  • 134 answers, mostly CEOs, Executive Vice President and some CIOs
  • questions were information security investment scenarios and the respondents were asked about their decision
  • each person got five scenarios, which were randomly selected from 162 different scenarios
  • scenarios had elements like: negative vs. positive presentation approach, likelihood and possible impact of the security threat, cost of mitigation/countermeasures (security investment)

The goal was to study decision making styles (rational vs. emotional) and persuasion methods.

Findings from the study:

  • in general persons who respond to emotional arguments, tend to support the investment proposal presented in a negative manner (e.g. emphasizing threats, losses)
  • in general persons who respond to rational/factual arguments, tend to support the investment proposal presented in a positive manner (e.g. emphasizing benefits)
  • increasing likelihood and severity of the threat effected positively and linearly to the investment decision
  • increasing costs of the investment decreased linearly the willingness to invest
  • investment proposal presented using negative language (threats) is more likely to be accepted than the proposal emphasizing positive outcomes
  • even investments meant to tackle low level threats are not so easily rejected, when presented in a negative manner
  • information security investment is a complicated process, which success factors are rarely understood by any individual alone
  • ROI and ROSI do not play any significant role in information security investment decisions
  • CISO must get allies from different levels of the organization
  • CISO needs to understand both the management view and the "regular" staff  view
  • CISO's communications skills and personal relationships to other players are very important
  • a justified need for the information security investment coming from the organization helps to get the investment accepted
  • one key challenge is that the need for the information security investment is usually crystal clear for the CISO, but it's not so for the management and the staff
  • clear organizational responsibilities are important
  • In general, staff support of the information security solution (investment) and solution's usability, suitability to current processes and social acceptance are more important factors than strength/quality of the solution or ROI/ROSI calculations

I hope I managed to catch the core points of the research. I can't give more background information or justifications of the results since I'm not the researcher:-)  It's easy for me to agree with the results, though.

Dec 27, 2013

Word-cloud of 2014 security predictions

A year ago I wrote a mother of all security predictions. I created word-clouds from 2013 security predictions of 10 different companies and also a separate word-cloud from combined texts of all them. Creating the word-clouds was more fun than actually reading the predictions:-)

Now, just after Christmas, I'm feeling even lazier and decided to create only one world-cloud from the combined predictions of following companies: FortinetInformation Security Forum, Kaspersky, Microsoft, Sophos, Symantec, WatchGuard, Websense, Trend Micro and FireEye. My intention was to use same companies as last year, but couldn't easily find anything from Stonesoft (McAfee) and F-Secure. Got Trend Micro and FireEye instead.

Here's the word-cloud made with Wordle.

2014 security predictions















For the comparison, here's the last year's word-cloud.
2013 security predictions















What can we see from these? Mobile doesn't seem to be on predictions focus so much as last year and data has more visibility. Malware attacks seems to be on everyone's map, targets being devices in general, not just mobile devices. Since everyone mentions data a lot, it could mean that attackers are predicted to be after valuable data more than trying to just blackmail or create havoc.

So, number 1 security prediction for 2014 is: Expect data-stealing malware attacks against all devices.

No surprise there. What actually surprised me was that word cyber didn't dominate the cloud. I take that as a positive sign.