Information Security is an odd environment in that most of the leading edge research takes place away from academic and designated research institutions, out in the industry. As a result there is a curious approach to publishing new information that doesn't really exist anywhere else.
The InfoSec conference circuit is in full swing in the US at the moment, and with professionals and interested parties have to pick and choose the appropriate conferences to attend, some people have questioned the place of academic-focused conferences in an environment where most of the work seems to be done by the private individual or corporate body.
As the move to commercialise research continues ,and as companies reach out into more costly fields of research, more of these findings will go behind closed doors. When RSnake and Jeremiah Grossman, two noted online security experts, commercialised their skill sets, the volume of their open reporting shrank considerably. In addition, the value of the material decreased as well, as the commercial value of their skill sets precluded open discussion of material that was receiving commercial attention.
Unlike most industries, Information Security is a field where the leading edge knowledge base is in the industry and not in the tertiary or dedicated research institutions (not the same as the research groups that many companies operate). This has the odd effect that the academic conferences don't necessarily attract the best of what is happening with new research and findings.
With no academic peer review, rather only that of other industry participants, the value of new material at commercial conferences can be hard to determine. This is especially true for material that is shipped from conference to conference with little change (making it more PR than relevant new research).
An upside to this is that the peer review that does take place is almost instantaneous - there will be someone in the audience or who obtains the presentation who will immediately be able to test and evaluate the claims being put forward, something that Kaminsky's DNS vulnerability disclosure debacle shows well.
At least academics have the ability to fall back to ongoing peer review and technical criticism to help improve the quality and validity of their work. In the commercial Information Security world, disagreements over conclusions drawn from results can vary wildly and rapidly descend into messy flame wars.
Recently n.runs and McAfee engaged in such a slanging match over conclusions that n.runs had drawn which criticised antivirus vendor software security, something that McAfee took to heart.
Without a recognised arbiter or central panel to decide on an outcome, public arguments such as this are going to have to be an acceptable drawback to the otherwise positive unique research and disclosure environment that exists in Information Security.
Despite the egos present in Information Security, there is no tenure and you are only as good as your last exploit/disclosure.
- +
Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15
Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Virtual magic: HR specialist throws out 40 servers, adds 8TB SAN and saves $100,000 for disaster recovery 2008-12-01 15:28:00+11
Sybiz adds up for SMEs in downturn 2008-12-01 14:27:00+11
EXCOM scores back-to-back award trifecta 2008-12-01 10:46:00+11
Citect extends SCADA networks with mobility solutions 2008-12-01 09:48:00+11
Citect extends SCADA networks with mobility solutions 2008-12-01 09:48:00+11
Email Archiving 101—Customer Case Study
Join Lee Benjamin, a Microsoft Exchange MVP and Ryan Shipkowski, network administrator for Matthews, to discuss the process and ROI of implementing an email archiving solution, with emphasis on a case study from Matthews International.











