In the first column of this year, I discussed computer security outlook and hopes for 2008. I forecast more of the same that we saw in 2007: more spam, more malware, more bad guys basically owning the Internet and our connected computers. I don't see any trends or new leaders with significant power to change the status quo.
That doesn't mean there aren't solutions. Last year, in several columns, I detailed one of the ways that a more secure Internet might be forged in the future. It's my vision. And the more I think about it, it's the only way I can see the Internet becoming significantly more secure. All other plans that I've come across break down under scrutiny or seem to rely on us becoming accustomed to a significant amount of computer crime. The other plans might reduce computer crime, but only temporarily and by a small amount.
I'm far from a computer genius, but I have convinced myself, and a few others, that my plan is right and everyone else's plan is wrong. Boy, I love having my own column.
The perfect plan
Here's my plan in a nutshell: All computer devices, users, and transactions must be authenticated by default.
That's it.
Why do malicious hackers hack? Because we can't catch them. Until we put in place default mechanisms to ensure that most criminals are identified and caught (instead of the current tiny minority now apprehended), hacking will continue unabated.
Instead, we must make all computers, users, and their network communications authenticated and identifiable by default. We start by making hardware impervious to hardware hacks. If someone hacks the hardware, it will refuse to boot. Personally, I don't want to stop hardware mods to iPhones and Xboxes. I just want to stop malicious hackers from modifying participating hardware in such a way that it bypasses all the other mechanisms I propose. Like in the OSI model, if you compromise a lower layer, you can't trust the upper layers.
After verifying a hardware device's boot sequence, the firmware/software portion of the boot process would be verified and accomplished. Each device would have a unique hardware ID that specifically identifies the device and cannot be spoofed.
The user is authenticated using two-factor (or more) or biometric identifiers. Network administrators where the computing device originates, whether on a corporate network, an ISP, or a telco switch, would be held accountable for correctly authenticating the users on their networks.
All OSes and programs would be authenticated and approved before running. If the executable or supporting file isn't approved, it doesn't load into memory. If you allow users to install everything they want without some sort of security approval, then you will never stop bad things or bad people from abusing computers. I'll discuss this more in next week's column.
Because approved users can still do bad things using approved programs, it's essential that network packets be authenticated from source to destination, and traceable back to their originating point. This will prevent a user from creating malware and sending it to another location, or prevent a malicious user from using another innocent user's computer to do the same. In my Internet world, if the bad guy "borrowed" someone else's computer, we'd always be able to trace the perpetrator back to their lair.
Routers and networks that carry our information from point A to point B would also be authenticated and their unique identities added to each passed packet. It wouldn't be as slow as you think -- network devices are working at electric speeds (the speed of light minus minor, unavoidable impedances). Tacking on a unique, authenticable identifier will not add that much overhead.
- +
Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15
Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Know thy self: Reduce costs, secure data and ensure compliance with identity management
CRM your salespeople will love
Wireless LANs: Is my enterprise at risk?
Everything you need to know about email and web security (but were afraid to ask)
Achieving the impossible: Unlimited application scalability
Solve Exchange Mailbox Storage Issues Once and for All
Delivering the Power of Choice with Microsoft Dynamics CRM
Enterprise Wireless WLAN Security
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
PGP and Ponemon Institute Unveil Inaugural Australian Data Breach Study 2008 2008-11-20 17:34:00+11
Symantec Cloud Services Transform Data Centre Operations Through Proactive Management 2008-11-20 12:06:00+11
Verizon Business Offers Tips to Building a Successful Unified Communications and Collaboration Plan 2008-11-20 12:04:00+11
AARNet Brings 4K Digital Cinema to Australia: First 4K HD Video Signal delivered into Australia by AARNet 2008-11-20 12:02:00+11
NetApp Named 2008 Citrix Ready Solution of the Year by Citrix Systems 2008-11-20 11:33:00+11
Solve Exchange Mailbox Storage Issues Once and for All
Join industry expert Bob Spurzem and Chuck Arconi of Fox Hollow to discover how to reduce Exchange total storage and keep it at a manageable level. Learn how Exchange storage growth can be contained without sacrificing security and accessibility.









