How Can Internet Security Scale With Modern Business?

1.6K views
•
March 1, 2012
by
RSAC Cybersecurity
YouTube video player
How Can Internet Security Scale With Modern Business?

TL;DR

Internet security must shift from fragmented perimeter defenses toward coordinated, scalable services that protect trust as networks, cloud systems, connected devices, and on-demand business models expand. Organizations should continuously assess exposed systems, strengthen SSL configurations and certificate governance, and collaborate with governments, internet providers, hosting companies, and technology vendors to identify and dismantle botnets.

Transcript

Good afternoon, and thank you for taking the time so we can discuss, you know, how we could, uh, build a more effective or take a more effective approach to security. 2011, I'm sure we all agree, is, has been the year of data breaches. Unfortunately, it look like that 2012 maybe may well be, uh, even worse. So let's try to understand why, what's, w... Read More

Key Insights

  • Security strategy is under pressure from two conflicting requirements: enterprises must protect their infrastructure while expanding network access to compete, connect with the world, and support new services. A reflexive effort to close networks cannot accommodate the business demand for greater connectivity.
  • Cloud computing is an enabling layer for on-demand services because it can coordinate reservations, track distributed assets, and connect users through mobile devices. The Autolib example shows how cloud technology can help transform a physical product into a continuously monitored service.
  • Disruptive technology is changing the value of information relative to physical equipment. John Deere tractors collect soil humidity, yield, location, and other measurements, leading to the argument that accumulated agricultural data could eventually become more valuable than the tractor itself.
  • Internet trustworthiness is a central security challenge because expanding digital services depend on reliable communication and authentication. Weaknesses in SSL deployment, certificate governance, and botnet response therefore affect more than individual organizations, they undermine the infrastructure supporting connected services.
  • SSL implementation is widely inconsistent across public websites. Qualys scanning found that a large share still supported a protocol broken long before the keynote, most supported weak ciphers, and only a very small group supported the latest and more secure TLS protocol.
  • Certificate-authority governance is a systemic problem because many authorities can issue trusted certificates without adequate control. Compromised or rogue authorities can enable false certificates, making secure-looking connections vulnerable even when website operators and users believe encryption is protecting them.
  • Browser-based certificate checks can expose interception when a browser knows which certificate a particular service should present. Google's use of this approach helped reveal surveillance involving improper certificates, but the protection described in the keynote applied specifically to Google services rather than the wider internet.
  • Botnet mitigation is most effective when governments, internet providers, hosting companies, corporations, and technology vendors coordinate identification and takedowns. Microsoft's actions demonstrated meaningful reductions in malicious email traffic, while fragmented efforts limit the ability to respond consistently across networks.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why does modern enterprise security need a new approach?

Modern enterprise security needs a new approach because organizations must protect their systems while simultaneously expanding connectivity to customers, partners, cloud platforms, mobile users, and emerging services. Traditional instincts favor closing networks, but competitive business requirements push them outward. Accelerating technological change makes this conflict more difficult, so security architecture must scale with increasingly open and service-oriented operations.

Q: How does the on-demand car model relate to cybersecurity?

The on-demand car model demonstrates how cloud computing, mobile access, tracking, and modern manufacturing can rapidly transform a purchased product into a monitored service. Philippe Courtot uses that disruption as an analogy for security. Instead of relying only on fixed infrastructure and traditional defensive products, organizations can use technological change to create scalable security models aligned with modern business services.

Q: What makes internet trustworthiness a major security concern?

Internet trustworthiness is essential because cloud services, connected vehicles, agricultural systems, and other digital services depend on users reaching authentic systems through protected connections. Weak SSL configurations, unreliable certificate authorities, and botnets can compromise that foundation. If the internet cannot reliably establish identity and secure communication, businesses cannot safely expand the connected services on which their operations increasingly depend.

Q: What problems did the SSL website scan reveal?

The Qualys scan revealed that a large share of websites still supported an obsolete SSL protocol that had been broken long before the keynote. Most of the scanned sites also supported weak ciphers, while only a very small group supported the latest, more secure TLS protocol. The findings showed that basic encryption configuration remained seriously inconsistent across public websites.

Q: How can organizations improve their SSL configuration?

Organizations can begin by testing their public SSL implementation with the SSL Labs service mentioned in the keynote. The assessment can identify support for obsolete protocols, weak ciphers, and other configuration weaknesses. These implementation problems are presented as relatively easy to fix compared with governance failures, so regular testing and remediation provide a practical first step toward stronger internet-facing security.

Q: Why is certificate-authority governance difficult to fix?

Certificate-authority governance is difficult because trust is distributed across many authorities, with insufficient control over their behavior and security. An authority can be compromised or potentially act improperly, allowing fraudulent certificates to appear legitimate. Unlike a simple server configuration error, this weakness affects the broader trust model and therefore requires coordinated structural reform rather than isolated action by one website.

Q: How did certificate checking help reveal online surveillance?

Google enabled SSL across its services and configured Chrome to recognize whether a browser received the proper Google certificate. When a different certificate appeared, the mismatch exposed that secure connections were being intercepted in Iran. The example shows how certificate pinning or service-specific verification can reveal improper certificates, while also highlighting that the described protection did not automatically cover every internet service.

Q: How can governments and companies respond more effectively to botnets?

Governments, internet service providers, hosting providers, corporations, and technology companies can respond more effectively by sharing information, identifying infected infrastructure, and coordinating botnet takedowns. Programs described in several countries illustrate this collaborative model, while Microsoft's actions showed that targeted intervention can substantially reduce malicious email traffic. Fragmented efforts are less capable of addressing botnets that operate across organizational and national boundaries.

Summary & Key Takeaways

  • Accelerating technological change forces enterprises to secure their infrastructure while opening networks to customers, partners, cloud services, and connected devices. The shared electric-car model illustrates how cloud computing can transform a product into an on-demand service, suggesting that security must also be redesigned around scalable services rather than traditional ownership and fixed boundaries.

  • Internet trust depends partly on correctly implemented SSL and reliable certificate authorities. Scanning by Qualys found widespread support for obsolete protocols and weak ciphers, while very few sites supported the latest secure protocol. Configuration problems can be corrected, but weak certificate-authority governance creates a deeper systemic risk requiring industry-wide changes and stronger verification mechanisms.

  • Botnet control requires sustained cooperation among governments, internet service providers, hosting providers, corporations, and technology companies. Coordinated programs in several countries and Microsoft's takedown efforts showed that intervention can substantially reduce malicious traffic. The broader lesson is that modern security problems cross organizational boundaries and cannot be solved effectively through isolated defensive programs alone.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚