Showing posts with label events. Show all posts
Showing posts with label events. Show all posts

Mar 2, 2011

Redefining the security gateway

This week I'm at the Pacific Crest Emerging Technologies Summit in San Francisco. And security is hot.

Apparently, enterprise IT buyers are not the only ones interested in information security products. Investors - institutional, hedge funds, private equity, etc - are all trying to read the tea leaves of the marketing soup being slung by security vendors. It's a stark contrast to the crowds at BlackHat and Defcon. These investors want to understand which companies will outperform or under-perform their competitors in the marketplace. While they clearly posses great knowledge about the financials of these companies, several are admittedly struggling to understand the technology table-stakes and differentiators required to compete. Increasingly, they're realizing they need to understand the security tech a little better in order to formulate and justify their investment thesis. I'm fielding questions like: Why do we need new security gateways? What is application control about? How are enterprises buying/using the technology? Can opensource security compete? Which approach will win? Which companies have products vs. platforms? With 20 to 40 competing companies in security market segments, surely not all of them can 'perform' and survive long term as stand-alone entities.

In a few hours I'll be tackling some of these questions on a panel with some of the leaders in network security - Barracuda, Fortinet and Sourcefire. This should be a good debate, and we'll have to follow up with some of those larger players who aren't represented, like Check Point, Cisco, HP/TippingPoint, IBM/ISS, Juniper.

RSA update

Like most, I'm recovering from the annual pilgrimage to the RSA conference in San Francisco two weeks ago. As usual, it was a great mecca in which to reconnect with friends, clients, business partners and new folks in the community. I'd especially like to thank all the supporters in our enterprise and vendor advisory boards. The NSS team is grateful for getting 60 of the busiest people in the biz to actively participate in discussions about how to improve information security through testing. It’s a topic that’s garnering momentum. I thank all of you for your input and suggestions on how we can improve and continue to deliver meaningful, actionable information services.

What are your priorities and concerns for 2011? Let us know and you could win a $100 AMEX card. Respondents will receive complementary access to the research results. Take the survey.

New Research
  • We have a number of endpoint protection platform (EPP) and network security reports we are rolling out, including EPP evasion, multi-vector attack protection, next generation firewall (NGFW), and firewall (FW). There will be a subsequent post on each of these.
  • We have been busy coordinating remediation of an important security issue with a number of firewall vendors. Stay tuned for the full report.
  • As Anti-malware continues to fail to protect endpoints, we have been investigating alternatives such as application control (application whitelisting), and secure browsing. While much of this has been performed for private clients in the financial services industry, we are gearing up for a proper group test of these technologies in Q2. Vendors, submit your products. Enterprise buyers, let us know what challenges you’re facing, your criteria and experiences. Contact us

Also New from NSS Labs
  • We rolled out a new video explaining the use cases for our services and how we can help organizations make informed infosec decisions.
  • We also have new collateral which goes into greater detail. See the services overview, or dive into our
  • Finally, NSS is actively expanding to meet the demands of our growing Fortune 2000 client base. If you’re a talented, hands-on infosec professional who understands the value of testing and ethical hacking, and is passionate about improving information security, we should talk. Contact us about career opportunities.

Mar 4, 2010

GroupThink and InfoSec - SecurityBSidesSF

At about 1:45h into the video, Vik Phatak begins his talk about group think in infosec. It is a well-reasoned argument for more aggressive testing in order to improve our defenses. We present methodologies and results from our testing of IPS and Anti-malware products to make the case that we have much work to do and must stay vigilant and innovative.


Jan 7, 2009

Webinar: 10Gbps Intrusion Prevention

Are 10Gbps network IPS products mature enough for deployment? Depends... Join our upcoming webcast to find out why 10Gbps IPS is more than 10 times more difficult to get right than 1Gbps IPS. NSS Labs' Vik Phatak will also walk through a checklist of criteria to look for when evaluating products. We'll also give a behind the scenes look at how we implement our industry standard IPS test methodology using products like BreakingPoint.

You can also look forward to some real experiences culled from our 10Gbps IPS group test. The first results forthcoming end of January 09 and the full report end of Q1.

Oct 28, 2008

RSA Conference: Short-term impact of the financial crisis

Here at the RSA Security Conference 2008 in London's ExCel Centre. In a recent interview with netevents I was asked -
Q: "What's the long-term security outlook?"
A: Long-term it’s good for several reasons.
1. Vendors are constantly developing new and improved products.
2. Users are getting more awareness and practical security training.
3. Companies derive competitive advantages by connecting with suppliers, customers and partners. It's increasingly understood by business managers that 'networking stuff' is needed to make money. And thanks to compliance mandates like PCI DSS, security is getting more attention and funding. Or at least it was.

Short-term there’s an increasing danger secondary ripple effects of the financial crisis. IT Security organizations, and other cost centers, will likely be squeezed to invest less time, resources and finances on solving security problems. This would be a dangerous win for the bad guys, who could have weaker, poorer funded defenses to contend with.

Contrast this with the time when governments on both sides of the axis had a clear focus and funding for cryptographic technologies as a lever in the information warfare of WWII.

Oct 6, 2008

North American PCI Community Meeting

We just got back from the North American PCI community meeting. The turnout was about double compared to the 2007 meeting, with all the major QSAs and many name brand retailers and banks in attendance. and the SSC has clearly achieved quite a bit in the last year. Changes to the new PCI DSS version 1.2 were discussed, the first in-person Special Interest Group (SIG) meetings took place, and there were even about 40 vendor exhibits. Branden Williams, Director of the PCI Practice at Verisign, and I sat down and talked about some of the trends and changes in DSS 1.2 (watch the video).

The exhibits were a great opportunity to meet face to face with top technical representatives from these vendors and QSAs. And for them they got direct access to key influencers and decision-makers in the PCI community. Interesting note about the marketing banners, just about all claimed to have an easy PCI Compliance solution. Of course the practitioners know there is no magical "PCI Compliance Solution" and that it is more of a process or journey where the multiple layers of details cannot be avoided. But clearly some marketers are going for the standard easy benefit-oriented taglines, because after all, a marketer's goal is to get you to stop and listen. We heard a lot of merchants and card brands talking about the challenge of getting that next layer of information, which was a great segue into what NSS Labs does to validate vendor product functionality and specifically how it relates to PCI DSS.

Vik and I are serving as secretary for the Wireless Security SIG and I was honored to be able to address the community and provide an update of the SIGs activities. The goal of the SIGs is to make recommendations to the council, which will then review the recommendations, ask questions and render the final decisions. Without revealing too much, it is important to know that we are not taking a technology-centric approach that will make life harder for merchants. Rather, the SIG has decided to take a problem-oriented approach to the task, by focusing first on the problems we are trying to solve for specific groups of users. Very similar to the methods taught by pragmatic marketing. So, Level 3 & 4 merchants who believe they do not have wireless in their network would be one use case; Level 1 & 2s with known use of WiFi would be another. Of course there are many details, and there are sub-groups working on implementation guides and advanced technologies (like BlueTooth and Satellite). If you're a participating organization and would like to 'participate' drop me a line - rmoy AT you know where.

Aug 13, 2008

About Deep Packet Inspection

What is DPI? How can it be used effectively? What are the different use cases and requirements for such products?
We recently hosted a webinar in which we discuss this and the methodologies needed to properly evaluate the DPI functionality of network devices under the demanding network conditions in which they will be deployed. The webinar can be viewed here.

Jun 17, 2008

To infinity and beyond!

Well, perhaps not as glamorous as Buzz Lightyear's famous launch slogan, but still exciting for the universe, er industry, is our move to 10Gbps testing and beyond. Today we are launching a mini-webinar series starting July 16, discussing high-speed deep packet inspection testing. More information.

May 5, 2008

Bankinfosecurity.com interview with Rick Moy on Product Testing

My interview with Tom Field of BankInfoSecurity.com at RSA about NSS Labs and how our product evaluations are helping the banking and payment card industry with security and compliance.

Listen to the interview
View page at bankinfosecurity.com

Apr 27, 2008

Interview with Martin McKeay at RSA

I had the pleasure of a brief chat with Martin of Networks Security Podcasts about what we do at NSS Labs. Martin is a prolific security blogger, podcaster, and QSA by day. Listen to the interview here: http://www.mckeay.net/2008/04/09/rsa-2008-rick-moy-nss-labs/

Apr 14, 2008

Rocking RSA

Last week's RSA Conference 2008 in San Francisco was one of the best one's I've ever been to. For purely selfish reasons! NSS Labs had a number of firsts.
  • It was our first time to have a booth at any trade show.
  • Over a dozen product vendors proudly displayed their NSS Approved logos at their booths. These large shiny plaques are about 5 times larger than the typical plastic sign you might otherwise see floating about.
  • Our debut was accompanied by the support of a broad ecosystem of test tool providers, security vendors, and others who shared our booth as partners.
  • We hosted two incredibly well attended Advisory Group sessions on testing and PCI.
  • We released a record number of product certification reports.
  • We threw the undisputed coolest party of all RSA and hung out with the heavy-lifters of the security industry, press, and analyst community. Where else could you get your groove on, and enjoy a shoe shine, shave and massage?
What could we possibly do next? I ask myself.