Comments
Matt McLarty wrote: For more info... Follow me on Twitter See our website
Cloud Computing
Conference & Expo
November 2-4, 2009 NYC
Register Today and SAVE !..

2008 West
DIAMOND SPONSOR:
Data Direct
SOA, WOA and Cloud Computing: The New Frontier for Data Services
PLATINUM SPONSORS:
Red Hat
The Opening of Virtualization
GOLD SPONSORS:
Appsense
User Environment Management – The Third Layer of the Desktop
Cordys
Cloud Computing for Business Agility
EMC
CMIS: A Multi-Vendor Proposal for a Service-Based Content Management Interoperability Standard
Freedom OSS
Practical SOA” Max Yankelevich
Intel
Architecting an Enterprise Service Router (ESR) – A Cost-Effective Way to Scale SOA Across the Enterprise
Sensedia
Return on Assests: Bringing Visibility to your SOA Strategy
Symantec
Managing Hybrid Endpoint Environments
VMWare
Game-Changing Technology for Enterprise Clouds and Applications
Click For 2008 West
Event Webcasts

2008 West
PLATINUM SPONSORS:
Appcelerator
Get ‘Rich’ Quick: Rapid Prototyping for RIA with ZERO Server Code
Keynote Systems
Designing for and Managing Performance in the New Frontier of Rich Internet Applications
GOLD SPONSORS:
ICEsoft
How Can AJAX Improve Homeland Security?
Isomorphic
Beyond Widgets: What a RIA Platform Should Offer
Oracle
REAs: Rich Enterprise Applications
Click For 2008 Event Webcasts
In many cases, the end of the year gives you time to step back and take stock of the last 12 months. This is when many of us take a hard look at what worked and what did not, complete performance reviews, and formulate plans for the coming year. For me, it is all of those things plus a time when I u...
SYS-CON.TV
In Search of a Russian Winter of Information Systems Security
To many cyber security experts, the Maginot Line represents the wrong approach to security

Bob Gourley recently wrote about the dangers of a Maginot Line approach to network security in “The Maginot Line of Information Systems Security“, based on of the paper by Dr. Rick Forno. In the Second World War, the French relied on the Maginot Line, a string of fortifications along the German border, to repel invaders. Feeling secure behind fortified walls, they missed the developments in technology and tactics that allowed the Germans to simply bypass the Line to be well within France in just 5 days.

To many cyber security experts, the Maginot Line represents the wrong approach to security. Dr. Forno originally compared it to buying the latest and greatest software then forgetting about it, pointing out how even the “best” solutions can have hundreds of flaws and exploits, some only becoming evident after attacks. No single solution, or even combination of technical solutions, can be perfect: “Good firewalls and other purely technical solutions do their work effectively, but to a clever and determined attacker they are just obstacles to be either broken or side-slipped, whichever is most effective. ” Despite a consensus that a Maginot Line fails just as spectacularly in cyberspace as in the battlespace, a press release every few months decrying a Maginot Line approach means that we have not yet moved on fully.

What we need, then, is a Russian winter of information systems security. Throughout history, the Russian winter has been a nightmare for every invading army that tried to brave it, including the legendary Napoleonic and Nazi war machines. These were the “advanced persistent threats” of their day. While the Maginot Line was easily avoided because it couldn’t adjust or adapt, the Russian winter punished the Germans on the Eastern front. That’s because not only was the cold and the harsh weather pervasive, it gave the advantage to the defenders while allowing for human ingenuity, allowing Soviet tactics to shift and evolve with the threat. Of course, the Russian winter was just winter to the Russians, who were more accustomed and prepared for their climate than invaders.

Russian ski troops in WWII via The Chicago Tribune archive

One company working to provide a Russian winter style defense is CloudShield. Their latest product, the CS-4000, is a next generation trusted network security platform designed to protect the most critical infrastructure and most private information of our military and intelligence community. As a technical system, the CS-4000 is cutting edge, like the rest of Cloudshield’s offerings, providing deep packet inspection for mixed-traffic converged networks for total visibility and access to every byte and every bit. Like Russia’s legendary winters, Cloudshield defends from all angles, even kinetic attacks by hardening their hardware with physical security countermeasures. Unlike the Russian winter, however, CloudShield’s solutions don’t complicate IT for everyone. It’s only a Russian winter for the bad guys, while the good guys enjoy a Hawaiian spring.

What really seperated Cloudshield’s offerings, such as the CS-4000, from Maginot Line style cyber defenses is its unprecedented agility. Cloudshield provids the first open, programmable network platform, which is scalable, adapts to new policies seamlessly, and  offers not only the widest range of deployed applications but also makes developing new applications cheap, fast, and easy with their PacketWorks Integrated Development Environment and CloudShield PacketWorks Operating System.

Like the Maginot Line, many security platforms offer a static set of defenses and rely on technical solutions which, as Dr. Forno warned, invite hackers to innovate and work around them. CloudShield’s technology, like the Russian winter,  offers a flexible, active defense that can be adapted and optimized by a clever security team to adjust instantly to new threats. CloudShield’s network platforms represent an evolving paradigm in cyber securityand risk management solutions that, like Russia’s biting winds and deep snows, provide a powerful deterent and, when combined with a capable defense, become nearly impenetrable.

Read the original blog entry...

About Bob Gourley
Bob Gourley, former CTO of the Defense Intelligence Agency (DIA), is Founder and CTO of Crucial Point LLC, a technology research and advisory firm providing fact based technology reviews in support of venture capital, private equity and emerging technology firms. He has extensive industry experience in intelligence and security and was awarded an intelligence community meritorious achievement award by AFCEA in 2008, and has also been recognized as an Infoworld Top 25 CTO and as one of the most fascinating communicators in Government IT by GovFresh.

SOA World Latest Stories
Many key benefits make the Dell MDC a compelling alternative for your data center solution. In his session at the 10th International Cloud Expo, Steve Cuming, Executive Director of Data Center Solutions at Dell, will take a look at the hyper-efficient, snap-together, flexible choice m...
According to a 2011 survey by the Independent Oracle User Group, over 50% of Oracle’s customers have deployed or are considering deploying private clouds. Most private clouds today support non-production workloads because enterprises are unable to deploy mission-critical applications i...
What do the CTOs of the CIA and the U.S. Dept. of Justice and the CIO of the National Reconnaissance Office have in common with the CEOs of Eucalyptus, GoGrid, ActiveState, Appcara, OpSource and Nortonworks, the CTOs of Rackspace, SoftLayer, SOA Software and AppZero, the Founder & Gene...
In this CEO Power Panel at the 10th International Cloud Expo, moderated by Cloud Expo Conference Chair Jeremy Geelan, leading executives in the Cloud Computing and Big Data space will be discussing such topics as: Is it just wishful thinking to depict the Cloud as more than just a te...
In his session at the 10th International Cloud Expo, Marvin Wheeler, Open Data Center Alliance Chairman, will discuss the success the organization has had in charting the requirements for broad-scale enterprise adoption of the cloud and how 2012 is forecast to be the tipping point for ...
Cloud computing is creating the new Wall Street boom, according to NIA. The only industry that is as bright as cloud computing on Wall Street is social networking, NIA said in a recent report. 2012 will be known as the year cloud computing became widely adopted worldwide. Cloud comput...
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021


SYS-CON Featured Whitepapers
ADS BY GOOGLE