Saturday, March 20, 2010

Bookmark and Share

Archive for the ‘Monoculture’ Category

Grimes on Monoculture

I saw a fantastic article today by Roger Grimes about the mythology of computing monocultures; great stuff and right in line with (our opinion on this topic):

And if you think patching Windows is hard, try keeping up with several OSes. I sometimes curse out loud because of all the mailing lists I have to track and all the tools I have to use to make sure my systems are patched. I’m pretty sure that, as the number of platforms increases, the amount of consistent, thorough patching decreases.

So, props to Grimes for using his head and for taking a somewhat controversial position.

Bookmark and Share

My laptop is not a Rhesus Monkey

The Register had an article today, “As Emperor of Security, I hereby decree…” It caught my attention since it was so atypical in style. The author spends some time discussing the things that he would decree if made emperor of security. Neat concept, right? I thought so too.

The mandates were totalitarian and restrictive; purposefully so (that’s sort of the point, right?) Some of them were good ideas (mandatory education for all new computer users), some were bad ideas (fines for insecure software), and some had both good points and bad points (mandatory anti-virus, anti-spyware, and firewall software). However, what really got me thinking was the discussion about “mandatory monocultures” :

It’s pretty well been proven that operating system monocultures are a bad thing. In a biological population, the introduction of a disease into a monoculture can spell doom for the entire group: since everyone is the same, everyone is vulnerable in similar ways. This is analogous to computing monocultures: if everyone is running Windows (or Mac OS X, or Linux, or whatever) and a serious compromise enters that population, then there is the danger that everyone in that group will suffer devastating losses.

This reference, of course, points back to the one and only Dan Geer “CyberInsecurity” paper that caught so much attention when it was published because of the ramifications of it’s release.

Now, I know better than to contradict Dan Geer. And I won’t, because I believe his paper to be absolutely true. But there’s a limit to how far the analogy holds; my laptop is not a Rhesus Monkey, a Lemur, or even a bacteria. While populations of machines can (and do) share a number of similarities with a population of organisms, that doesn’t mean that everything that’s true about organisms is true of laptops. For example, don’t put a bunch of laptops in a box and expect them to start making little laptops. In other words, just because certain threats are more virulent in a monoculture world, don’t assume that all of them are. And why not? First: because nobody has to manage a population of organisms, and Second: because there are more bad things than plague…

Consider two environments: one has a thousand machines each with identical OS, architecture, patch level, etc. The other also has one thousand machines but each one has different operating systems, architectures, and patch levels. Say (for the sake of argument) that two full time administrators manage that environment – a reasonable number, right? Dan’s paper points out that the first environment is much more likely to be impacted by worms; and that’s true. But which envrionment is more manageable? Which one is more likely to have automated security tasks like patch management, central monitoring, coordinated audity, etc? See what I mean?

Take the OS and application patches alone. Say that the operating systems in the second environment (the non-uniform one) each require an average of two vendor patches per week for all installed services and apps (a ridiculously low number.) Say each of those patches require 5 minutes to download, prepare, and install (another ridiculously low number.) Guess what: that patching process would take 166 full-time hours. If you had a more MANAGEABLE environment, you could have deployed something to automate that. You could start focusing on something more strategic than patches application with all the time you’d save.

Look – monoculture does increase the risk of population-level catastrophic events. However, diversity decreases the ability to manage the environment. Reduced manageability directly increases the risk of individual-level events like targeted attack. It’s not a traditional curve where the optimal position is maximum diversity; instead, it’s a bell curve: the optimal position is diversity – but manageable diversity.

Bookmark and Share

Winn’s Mad as Hell… and so am I!

Alright, apparently Winn Schwartau has decided that he can no longer tolerate the centrality of Windows in the marketplace, and he is deciding to run a hypothetical company using Mac to see where that gets him. Now, I try to be non-biased about operating systems – I use a few of them here: Solaris, Windows 2003 Server, XP, and as my typical desktop operating platform, OS X Tiger on a Macintosh iBook. I’m not a bigot about operating systems – seriously.

I am, however, also a fan of objectivity. Scientists use “double blind” techniques and other approaches to attempt to reduce bias on the part of the observer in analyzing the way that things behave. It seems to me that Winn initiating an anlaysis with the phrase, ” an experiment predicated on the hypothesis that the WinTel platform represents the greatest violation of the basic tenets of information security and has become a national economic security risk” he might be approaching the issue with a touch of bias…

Seriously, is there any question what his “results” will be at the end of this? Why even bother doing the experiment if the bias is so strong. I’m not expecting the press to be warded off based on the flawed nature of his science; in fact, I’m sure it’ll be a press extravaganza. However, I’m hoping that the folks in the field actually making security and business decisions are smart enough to see through this transparent stunt.

Bookmark and Share
“Benefit from targeted intelligence and customized comprehensive research.”
Blog Cloud

The Law: Fear It Administrative Cruft (16)
Analysts (31)
Apple (25)
AppSec (12)
Assessments (2)
Auditors (2)
Biometrics (4)
Blogs (13)
Breaches (21)
Buzzwords (2)
By Grabthar's Hammer!! (1)
Certifications (1)
Change Management (1)
Cheezburger Network (1)
Chupacabra (1)
Cloud Computing Security (4)
Collaborative Strategy Guild (2)
Compliance (4)
Copyright (9)
Credit Cards (3)
Crypto (11)
CXO Summit 2010 (1)
Cyberterrorism (2)
Data Protection (2)
DHS (25)
eBay (1)
Emergence (1)
End-to-End Encryption (2)
England (1)
Financial Fraud (1)
FISAP (1)
Forensics (5)
FTC Red Flad Rules (1)
FUD (12)
gnisreveR (2)
Google (2)
Holidays! (3)
Humor (16)
Identity Theft (4)
James Bond Shiz (1)
Legal Shiz (13)
Linux (3)
Malware (35)
Marketing and PR (9)
Messaging Security (1)
Microsoft (26)
Monoculture (3)
Mouth-Frothing (2)
Musings (17)
Open Source (3)
Oracle (21)
Outsourcing (4)
Paris Hilton (1)
Passwords (1)
PCI (4)
Phish-Eye (8)
Phones (5)
Planes (1)
Privacy (1)
Programming (1)
QDSP Blues (15)
Research (30)
Resources (6)
Rhesus Monkeys (2)
Risk Management (18)
RSA 2009 (1)
RSA 2010 (1)
SAML (1)
SAN (1)
SC Mag Blues (1)
SCADA (1)
Security Curve (8)
SecurityCurve Speaking (2)
SIEM and Log Management (5)
Social Networking (1)
SOX (1)
Speaking (2)
Spinach (1)
Spy Stuff (1)
Stealing Stuff (8)
Storage (1)
Symantec (7)
Tarot (1)
Teleological suspension of the ethical (3)
The Great Borack (1)
The Law: Fear It (10)
The Old Man of the Mountain (1)
The Regs (5)
Tokenization (1)
Useless Shizz (13)
Vendors (37)
Virtual Worlds (2)
Voting (2)
Vulnerabilities (40)
Walt Disney (2)
Wi-Fi (16)

WP Cumulus Flash tag cloud by Roy Tanck and Luke Morton requires Flash Player 9 or better.

Archives