Visualizing Security - The Challenge of 2009

By Ari Takanen  4 comments

I was browsing the Internet, just like any normal day, catching the news in the world on security. A recent release by Clarified Networks caught my eye: Logster

Logster itself is not really interesting to me personally, as using such tool would require that I would have access logs from a web server of interest, to analyze them. What is interesting from both VoIP security, and from generic software security perspective is the integration of visualization of network data together with other sources of data such as geo-location. Imagine a small local flower shop in a small distant town launching their first web portal, and then trying to explain to them that they actually need to secure that web page also. Challenging! Then imagine you show them a map of the world with visualization indicating that actually 99% of all web requests are coming from outside the target market, from different Asian countries. Effective!

What Logster basically does to software security people such as me is visualize the importance of Attack Surface analysis. The interfaces that are open for anyone to access are always most security critical. Knowing the actual users of a service, both desired and unwanted visitors, will help you in your threat analysis. It is also a powerful tool in visualizing the real life threats to management level people. Just having high rates of visitors in your Internet-enabled service does not always mean that you are actually reaching your target market.

Security Visualization

Visualization of security is the hype of 2009. Visualization itself is not the goal, but to make security easier to understand and integrate into your processes. Let's look at different technologies that have similar goals:

Dashboards bring together complex reports from complex tools, and interpret them for easier understanding.

Collaboration solutions enable you to save huge amount of time and resources in security auditing by building on top of existing work instead of re-creating everything always from scratch.

Network analyzers visualize and reverse-engineer what is really happening in the network, instead of relying on network architecture charts and similar planning documents, which might not have any indication of the realities in the network.

Security as a Service, or SaaS, in security solutions and services is a funny acronym with double meaning. Security companies worked hard to build solutions like fuzzers that automate security assessment services, and then recently started offering the same solutions again, as a cost-effective repeatable service.

Fast Development - Legacy Providers

Companies that have been truly innovative in security often bring in new technologies before other providers even notice the need for such practices. Fortunately, the fiercely competitive landscape of security has enforced all leading practitioners to follow up what is being done by forerunners of technology. I am truly happy that all these technologies that we helped prototype in early millennium caught up so fast in the generic security landscape. Those players that do not evolve, quickly vanish away from the security market. Ask your security provider what they are doing that will make your life easier!

4 comments

    Anonymous 2 years ago
    If you are like me then you have probably tired many different types of scans to try and protect your computer. There are many different options available but I have found that most of them pick up the same bugs whether you pay for the scan or download a free version. Search-and-destroy Antispyware (http://www.Search-and-destroy.com) is one of the best that I have found so far and it cost less than many of the other well-known scans on the market today. If you are searching for a good scan I suggest that you check out the antispyware solution from Search-and-destroy.
    Ari Takanen
    Ari Takanen 2 years ago
    If you are interested in more links to visualization resources, check out the collection maintained by Clarified:https://www.clarifiednetworks.com/Visualizations
    Anonymous 2 years ago
    There has been a lot of work that was done in security visualization. One of the prime resources is the security visualization portal. I have a Applied Security Visualization book, if you are interested in learning more about the topic.I would love to see you on secviz sometime! Raffy
    Ari Takanen
    Ari Takanen 2 years ago in reply to Anonymous
    A quick look at secviz.org revealed a few cool looking things. Thanks for the link! I am sure the readers will appreciate that.Personally, my interest in visualizations is in a completely different area. But it would be great to meet and discuss sometime. If interested in discussing more on this topic, just email me at: ari.takanen@codenomicon.com

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SecurityWhite Papers & Webcasts

      White Paper

      Overcome Top 7 Admin Challenges of Active Directory

      As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

      White Paper

      Insiders Can Ruin Your Company. Take Action.

      Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

      White Paper

      Top Solutions and Tools to Prevent Devastating Malware

      Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

      White Paper

      Streamline Compliance and Increase ROI

      Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

      White Paper

      X-Ray of the PCI Process-4 Proactive Steps

      This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question