home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Powered by InformationWeek Business Technology Network
InformationWeek 500 Conference -- September 14-16, 2008 Registed Today!

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



Column - Down to Business
C O L U M N  
Security Surcharge

  October 21, 2002
  By Rob Preston


TOC Issue TOC
Printer Print this article
E-Mail E-Mail this URL
flame author Flame the author

If you're like most IT professionals, you're concerned about the security vulnerabilities of your software. Maybe you're frustrated--or even downright angry. But don't expect the situation to get better anytime soon.

Microsoft is the most visible offender, since its products get attacked more than any other vendor's. Tallies of the top 10 security targets regularly list eight or nine Microsoft products, and new vulnerabilities are discovered weekly. Last month, for instance, a security hole was found in the point-to-point tunneling protocol used in the VPN software Microsoft bundles with Windows 2000 and XP, exposing some corporate networks to attack. Earlier in the month, Microsoft released a patch to fix three flaws in its Java Virtual Machine, one of which lets attackers take control of a user's computer. Microsoft also warned of a flaw in its digital-certificate software that could let attackers steal a consumer's credit-card information.


With its year-old Trustworthy Computing Initiative, Microsoft is employing new tools to detect security flaws during development, and it's working with consulting, patch-management and other partners to alert customers and issue updates when problems arise. But when it comes right down to it, Microsoft really doesn't know what to do next. For its every step to shore up security, it's scrambling a step-and-a-half backward because of the increasing sophistication of hackers, many of whom target Microsoft products with a vengeance.

Speaking at the company's .Net developers conference a month ago, senior VP Brian Valentine admitted that Microsoft's products "just aren't engineered for security"--though he argued that other vendors' products are equally vulnerable. Even as Microsoft and others improve security, Valentine said, hackers will devise new ways to break in. The stats don't lie: In just the first half of this year, the total number of system vulnerabilities reported to CERT were about equal to all those reported in 2001.

The problem has more to do with sophistication than sloppiness: Software is more complex, making exhaustive security testing extremely difficult. Reusable application objects can pass along bugs faster than ever. Black hats are getting smarter, while amateur hackers have easier access to tools of the trade.

Yes, Microsoft and other vendors are culpable; they continue to crank out new versions of software and systems before they can be tested adequately. But vendors aren't rushing product out the door as fast as they used to, either because customers don't have the money for incremental upgrades or they're demanding higher quality from the start.

Extreme Vigilance

Microsoft's software is hit the hardest, according to the conventional wisdom, because it's the most widespread and popular, not necessarily because it's less secure than rival offerings. Still, the more features Microsoft builds into Excel, Exchange, Internet Information Server, SQL Server, Windows and other products--and the more tightly integrated those products become with one another and the more third-party developers introduce their own bugs--the more prone they are to security breaches. Extreme vigilance, Microsoft argues, is the surcharge customers must pay for the ubiquity, feature-richness and compatibility of its products.

So are you and your company willing to pay that surcharge? At the very least, that requires implementing and enforcing a cogent IT security policy; keeping strict tabs on what users deploy; knowing where you're vulnerable and deploying the requisite firewalls, antivirus tools and intrusion-detection systems; and keeping current on software patches (enterprises now spend $2 billion a year just to investigate, prioritize and deploy patches, according to Aberdeen Group). That's what it's going to take to work in a Microsoft--or any--environment. Don't count on any single platform or security vendor to bulletproof your environment for you.

--Rob Preston, rpreston@cmp.com






Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo Jitter
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet Evolution
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights