Posts

Showing posts with the label analysis

Digital Offense Capabilities Are Currently Net Negative for the Security Ecosystem

Image
Proposition Digital offense capabilities are currently net negative for the security ecosystem.[0] The costs of improved digital offense currently outweigh the benefits. The legitimate benefits of digital offense accrue primarily to the security one percent  ( #securityonepercent ), and to intelligence, military, and law enforcement agencies. The derived defensive benefits depend on the nature of the defender. The entire security ecosystem bears the costs, and in some cases even those who see tangible benefit may suffer costs exceeding those benefits. The Reason Limitations of scaling are the reason why digital offense capabilities are currently net negative. Consider the case of an actor developing a digital offense capability, and publishing it to the general public.  From the target side, limitations on scaling prevent complete mitigation or remediation of the vulnerability. The situation is much different from the offense perspective. Any actor may leverage the offense cap...

Extending Security Event Correlation

Image
Last year at this time I wrote a series of posts on security event correlation . I offered the following definition in the final post: Security event correlation is the process of applying criteria to data inputs, generally of a conditional ("if-then") nature, in order to generate actionable data outputs. Since then what I have found is that products and people still claim this as a goal, but for the most part achieving it remains elusive. Please also see that last post for what SEC is not , i.e., SEC is not simply collection (of data sources), normalization (of data sources), prioritization (of events), suppression (via thresholding), accumulation (via simple incrementing counters), centralization (of policies), summarization (via reports), administration (of software), or delegation (of tasks). So is SEC anything else? Based on some operational uses I have seen, I think I can safely introduce an extension to "true" SEC: applying information from one or more data...