Welcome | Sign In
CRMBuyer.com
ECT News Exclusives

EXCLUSIVE INTERVIEW
Cracks in the US Cybersecurity Walls: Q&A With NetWitness CEO Amit Yoran

Print Version
E-Mail Article
Reprints
Cracks in the US Cybersecurity Walls: Q&A With NetWitness CEO Amit Yoran

When the long-promised U.S. "cyberczar" position is filled, the person at the top will have more than political and policy issues to untangle. There are huge problems with the country's current technological approach to cybersecurity, says Amit Yoran, who served as a top cybersecurity adviser in the Bush administration.


Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!

Cybersecurity is a shambles in the U.S., but nobody seems able to do anything about it, and things appear to be going from bad to worse. Both Presidents George W. Bush and Obama have promised to appoint a cybersecurity czar -- or "cybersecurity coordinator," as the current administration calls the position -- but still there is none.

Early in August, White House cybersecurity adviser Melissa Hathaway -- who was at the helm in an "acting" capacity -- resigned, saying the president was taking too long to make a permanent appointment and bemoaning her inability to drive any real change.

The reasons behind her resignation were eerily familiar: In 2004, Amit Yoran, who was then holding what essentially was Hathaway's post in the Bush administration, stepped down after just one year, citing much the same reasons. He became the third official to quit the post in two years.

Yoran had made his mark in the private sector by founding network security firm Riptech, which was acquired by Symantec (Nasdaq: SYMC) for US$145 million in 2002.

After leaving the White House, Yoran founded another company, NetWitness, a provider of distributed, real-time enterprise security solutions based on full packet capture and deep session analysis from the network to the application layers. NetWitness serves customers in the U.S. defense, national law enforcement and intelligence sectors, as well as critical infrastructure organizations and Global 1,000 companies.

Yoran, who is still ticked off at the state of U.S. national cybersecurity and says its existing "defense in depth" approach is outdated, discussed the issue with TechNewsWorld in an exclusive interview.

TechNewsWorld: You say existing defense-in-depth approaches predominantly rely on antiquated security technologies such as firewalls and intrusion-detection systems. Can you elaborate on defense in depth?

Amit Yoran: Defense in depth means implementing multiple security countermeasures to deal Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse with the same problem. So, to stop a nation-sponsored or criminal attacker, you might employ several technologies. Unfortunately, many of these have not kept pace with current threats.

TechNewsWorld: What is the aim of defense-in-depth systems?

Yoran: Defense in depth is not a system; it is a strategy Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales for implementing security technologies. It is a "layering" of technologies to provide additional depth. One technology is not enough, so you add more technologies to provide additional defenses, hoping the combination will work. Defense in depth systems include firewalls; antivirus; intrusion-detection systems, network behavioral analysis systems, and data-loss protection systems

TNW: Why do you say the government's defense in depth systems are antiquated?

Yoran: Many are based on the concept of "signatures," which assume that you have foreknowledge of an attack. This approach is unrealistic in a world where attackers are creating designer malware and zero-day exploits crafted to circumvent the signatures understood by existing security countermeasures. A next-generation approach does not rely on signatures or statistical modeling.

TNW: As a former director of US-CERT and the National Cyber Security Division of DHS, what flaws in the federal cybersecurity model did you note?

Yoran: There were gaps in the network visibility with existing security products (i.e., defense in depth). Organizations needed a way to view network events more deeply and accurately using full packet capture technologies.

TNW: Didn't CSIS' recommendations to then-incoming president Obama in November address that threat and recommend action to resolve the cybersecurity shortcomings of the Federal cybersecurity model?

Yoran: Sure, and this will happen eventually, but we just had the 60-day review, and we are waiting to see how the cyberczar position shakes out. The president said good things. Agencies need to keep moving forward and plan new and improved security defenses. But better White House strategy and coordination also will help. There needs to be better clarity with regard to how threat data is shared both within the government and to and from the private sector.

TNW: What are the top federal CISOs doing to remedy cybersecurity gaps in their organizations?

Yoran: Over 60 percent of federal CISOs have moved to adopt new types of security-monitoring solutions to close the defense in depth gaps I mentioned during the last two years. All of them have based their solution on NetWitness NextGen full packet capture.

TNW: Is anyone coordinating all these efforts from the top to create a federal government-wide model, or are these actions of CISOs going to result again in islands of cybersecurity at different levels of capability?

Yoran: Not yet, but the president has committed to appoint someone.

TNW: Won't it be difficult to have one uniform approach, given the different security requirements of different federal organizations and the specific additional requirements of sensitive agencies such as DHS, NSA, FBI and CIA?

Yoran: Yes. Different agencies have different priorities and goals. Some have data that are more sensitive than others. There can be high-level standards, but each agency must protect its data in accordance with its sensitivity and criticality. And they must consider the issue I mentioned of the problems with defense in depth and moving to a new level of network visibility.

TNW: You have, of course, an ax to grind, as you are CEO of NetWitness. Notwithstanding that, how will the technology help improve cybersecurity?

Yoran: Organizations have very clear gaps in network visibility due to the limitations of current network-monitoring technologies. Since NetWitness is based upon full packet capture and session analysis, the technology sees and records everything and can provide the kind of detailed content and context to network actions and behaviors that let security operations staff work faster, smarter and with more certainty. That's why over 60 percent of the federal government has implemented NetWitness.

TNW: Deep packet inspection and rendition of the results in English instead of hex representations notwithstanding, the results must be reflected in real-time and tied in to some sort of alarm that alerts IT admin immediately. Also, there must be some sort of process set up to ensure that the right action is taken immediately on receipt of the alarm. Please comment.

Yoran: Correct. That's exactly what we do. Unlike other products that are simply large packet file stores or PCAP libraries, we've actually built an infrastructure that serves three real-time missions for some of the largest federal networks: 1) continuous augmented awareness -- that is, making existing defense in-depth tools smarter and faster; 2) optimization of incident response, providing new and better information on new kinds of alerts to incident responders and giving them context to alerts they receive from other technologies; and 3) cyberthreat intelligence: providing real-time fusion with third-party data sources regarding botnets, dynamicDNS, malware, warez and other traffic with bad reputations flowing across networks, allowing organizations to build short and long-term intelligence profiles.

TNW: Also, NetWitness tackles only a small part of the overall problem. It would be better to use it in conjunction with policy administration and governance and provisioning/deprovisioning systems that are activated immediately any change occurs in users' roles or access rights, yes? Please comment.

Yoran: I agree that NetWitness is not a silver bullet and should be used in conjunction with other technologies for maximum effect.


Print Version E-Mail Article Reprints More by Richard Adhikari


Related News Alerts

Symantec Activate Alert | Search Archives

More by Richard Adhikari

New Pogoplug Brings Mobile Devices Into the Cloud
November 20, 2009
The Pogoplug allows a user to run a personal cloud server from a home network. The data resides on hard drives and thumb drives that plug directly into the Pogoplug device; from there, the data can be accessed from anywhere via the Internet. Keep in mind that some ISPs forbid customers from hooking servers up to residential connections, though those rules are rarely enforced.
Google Spills Chrome OS' Guts
November 19, 2009
Google has made public the source code for its upcoming Chrome operating system. The OS will begin appearing on consumer-targeted netbooks next year. Chrome is built to live completely on the Web -- very little data is stored directly on the user's hard drive. This could make for much faster boot times and enhance security.
Cyberfraud Arrests Unlikely to Stem ZeuS Rampage
November 18, 2009
Two alleged cybercrooks have been nabbed in the UK on suspicion of using a well-know Trojan to commit banking fraud. The malware in question in known as "ZeuS" or "Zbot," and althought it's quite common, it's also sometimes difficult for antivirus applications to nail. Simple software kits exist online for relatively inexperienced hackers to create unique malware for the purpose of fraud.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network