I recently read the TechRadar for Security & Risk Professionals: Network Threat Mitigation, Q3 2009 by Forrester. This report reviewed 14 different threat mitigation categories. These included encryption, wireless IDS/IPS, UTM, Intrusion prevention, network access control,Web-content filtering and a few others.
It is obvious that the bad guys are highly organized and very skilled. The number and sophistication of attacks do not seem to be going down but instead increasing. Forrester identified three areas they see in their client companies:
-
The current controls are either not able to prevent the type of threats we see today of the solutions and how they are used need to be re-thought.
-
Companies fear inline protection. Even though many companies have successfully deployed Intrusion Prevention, there is a general fear the IPS will block legitimate traffic.
-
Companies lack visibility into what is really happening on their networks. This is somewhat by design because what you do not know you do not have to address.
Forrester did a good job of grouping the type of technologies and providing a ranking on their business value. I agree in general with their assessments.
Technology |
Business Value |
Firewall Auditing |
Low |
Network Encryption |
Negative |
Network Threat Modeling |
Negative |
Network Access Control |
Low |
UTM |
Low |
Email Security Gateway |
High |
Network Firewall |
High |
Vulnerability Scanners |
Medium |
NBAD |
Negative |
IDS |
Negative |
IPS |
High |
Web Proxy |
Medium |
Application Firewalls |
Low |
Wireless IDS/IPS |
Medium |