Dr. Dobb's is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


Channels ▼
RSS

Top 10 Reasons Security Products Don't Work


4. Security products don't work well together

Point products can be a pain -- your firewall, IPS, vulnerability assessment, antivirus, antispyware, and host-based security tools for the most part all do their own thing and don't talk to one another. Some enterprises complain that the danger of these tools not sharing is they may not have a true picture of their security landscape until it's too late and they've been hacked.

But does sharing data among all of these tools really make sense? The promise of security information management (SIM) has yet to be fulfilled, says Ptacek. And the all-in-one security tool approach so far is mostly a small- to medium-sized business phenomenon.

"People don't need a lot of correlation between tools. When they do, it's specific, and they build their own" interfaces," Ptacek says.

And integrating security data may not be useful anyway. "Security vendors haven't demonstrated that you can take these pieces of a broken mirror and get a clear picture," Ptacek adds. "These products are built separately and aren't related to one another."

Michael Rothman, president of Security Incite, says it's up to customers to press vendors for the integration if they need it -- not the other way around. "If you need shared data, you should push vendors for it," Rothman says. "The vendor that's going to prevail is the one that provides the most actionable information to make sure you can block those attacks. If that means you pull it out of a syslog, or there's a product-integration relationship, that's what they're going to have to do."

But it's not a matter of security tools interoperating, says Nate Lawson, engineering director for Cryptography Research. The missing link is a standard way for security tools to report their vulnerability data in a common format, he says. "There's room for standardization here -" if an IDS and AV scanner throw their report data into a database, that would be useful," he says.

Meanwhile, AV, anti-spyware, and host-based IPS products are gradually becoming integrated. Antivirus vendors such as Symantec and McAfee are adding more host-based IPS and spyware, for instance, and spyware and host-based IPS vendors are adding more AV features.

Still, not all security tools will, nor should, work together, says Tom Maufer, director of technical marketing for Mu Security. "AV scanners, penetration testers, and Web app scanners are designed to do a very specific job," Maufer says. "That's where that vendor's expertise lies."


Related Reading


More Insights






Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dr. Dobb's encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dr. Dobb's moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing or spam. Dr. Dobb's further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.