Showing posts with label IT religion. Show all posts
Showing posts with label IT religion. Show all posts

Saturday, November 10, 2012

More on building secure IT systems

Last week, I wrote how the current system (of designing and developing IT systems) is broken. How business will simply not be able to support high-levels of post-facto InfoSec expenditure that is necessitated by increasing sophistication (and automation) of attacks. That we need to build security into our systems at design & development time.

It appears that I am not alone in this thinking. I came across a paper (in the SANS library) by Dan Lyon - apparently as a part of his GIAS GSEC Gold Certification effort - titled "Systems Engineering: Required for Cost Effective Development of Secure Products (PDF document)". In this he builds a case to take a Systems Engineering approach to build-in security into products; and that building security right from design makes more sense than otherwise.

He also refers to others writings and talks on the subject (though as a means to introducing the need for systems engineering approach), such as:

  • Software Security: Building Security In (2006), by Gary McGraw
  • The Security Development Lifecycle (2006), by Michael Howard and Steve Lipner
  • At the SANS Rocky Mountain 2012 Conference John Strand: "... the current state of information security is broken; new approaches are needed for information security. Many current practices for achieving information security are applied after a product has been developed. Examples such as firewalls, intrusion detection, intrusion prevention and antivirus are all external systems to what organizations use to conduct business..."
While it is gratifying to see that I am not alone in this line of thinking, I wonder why so little progress has been  made in building more secure IT systems from ground-up. Perhaps it is because of one or more of these reasons:
  1. Addiction by tradition: We are so deeply habituated to current development processes that we are unable to break free from them.
  2. Demand-side ignorance: Businesses don't see (and consultants are unable to make them see) the perils of current approach; and hence they are not ready to pay. In the absence of demand (from businesses), supply chain isn't ready to invest and gear-up.
  3. Supply-side ignorance: The word hasn't quite spread into the developer world! Yes, even in today's hyper-connected over-communicated world, this can happen. Too many people have yet to adopt new digital media consumption methods; and those who have, are subjected to information overloads that much gets filtered out.
  4. Industry Ostrich posturing: This could be deliberate (vested interest by current approach's beneficiaries) and/or simple denial. 

What do you think are the reasons?

I am exploring the possibility of me doing something about it (instead of merely whining / writing about it). Stay tuned.

Tuesday, November 6, 2012

Built-in robustness in IT Systems

Yes, it is true. We are woefully short of InfoSec professionals. Recent events (including the spate of #5Nov attacks) bear it out. We need more (and better trained) professionals to protect our systems; better technologies and products. One-way gateways, passive DNS traffic monitoring systems, more sensors, more analytics, you name them.

Yet, we are missing something fundamental in the picture.
Would you knowingly build your home with termite-infested wood and water-soluble walls? Would you  forego doors and locks and ignore building safety codes - just because you can add a swanky swimming pool with the money you save?
Would you then insist that we hire more security guards, buy more fire sensors, build protective shields on the outside and install props to shore up the insides of this hopelessly vulnerable home?
Absolutely not. Yet, we do it every day, when building our critical IT systems. Aren't we?
Well, the problem isn't so obvious with IT systems as with our homes. Neither the systems nor the weaknesses are visible to the naked eye. We can therefore make convenient assumptions on what is good enough security and still not lose sleep at night.

For decades, innovation and IT systems have romanced each other - and focused nearly exclusively on functionality, ease of use, etc. Yes, there have been developments in security - but almost all of them are post-facto solutions. Not built-in security. Not robust-by-design. Not in every component of the system.

Thanks to this approach, we are soon reaching a point where the IT sprawl will collapse on itself in a catastrophic sequence of events. Unless we shift our focus to the process of building the systems in the first place.

Networking technologies are beginning to show this trend in a small way. Computing, not so much. Operating Systems are only scratching the surface with the notable exception of OpenBSD and Kaspersky OS (is it named yet?). Databases, Application Platforms and Application software themselves haven't even begun. How many software professionals have even heard of secure coding? 0.001%? Or less?

We must change now and change quickly. Businesses will not be able to bear the burden of spiraling costs of post-facto and ineffective security solutions for long. We may not perish yet, but that is nothing to celebrate.

Thursday, October 18, 2012

Taking Mac to the cleaners

Mac was a fault-finder with a mission. Everyday, he and his pet pooch Pooper would troll the streets of GovCairo looking for muck to rake up. GovCairo, being a usual sort of city, had it's share of muck to rake. So every once in a while, he would find a really juicy bit of muck - and would go to town with it. To some of the news-tablet makers, Mac was a hero. He gave them muck to feed on, when they were starving. They lapped it up and praised him. That made him feel like he and his Pooper are the most upright citizens in the whole world.

One day, Mac found out that the city spends a lot of money on street cleaners. He went and demanded that the city admin fire all the cleaners. They are a useless drain on public money, he said. I never see them working, he said. The streets don't need cleaning, they are already clean, he said. They should be building GovPyramids; and since they aren't, it is their fault, he said. When the city admin refused to oblige, Mac got upset. He threw a tantrum, became abusive to the cleaners and anyone who didn't support his rant about the unfairness of it all. For good measure he also ranted about the city admin, calling them ribbon-cutters, cronies to ribbon-cutters and MA-Lits (a clever insult he often used to mean illiterates, he once explained).

Well, here is the deal Mac. You never see them because they work early and you wake up late. Since you don't understand street cleaning tech (despite your fancy degree), even when you see them, you mistake them for someone else. The streets are clean because they are doing their job. No, no one told them to build GovPyramids. It is hard to build GovPyramids, when your job is something else; and when the GovPyramid masons' guild wouldn't let you anywhere their turf.

Some of the cleaners feel Mac needs help. You know, a bit off his rocker. A marble or two missing. No one could be that bad, ranting and trolling for a living. But heck, who knows? They send him their "Get well soon" wishes.

The cleaners do wonder whether Mac's problem is also being exacerbated by the news-tablet makers and muck-hungry public who won't double-check their facts and give Mac the cheap thrills for his trolling.

Note: This unfortunate story-from-the-real-life had to be written due to repeated allegations about the IT-Street cleaners by a Mac-gone-berserk.

Update (18-Oct):
Just saw Mac's response to my uncharacteristically acidic comments on the BabuBlogger site. Point well taken, Mac. I (honestly) don't know if I was jealous of your rising fame, but thank you. I will introspect. Perhaps you too might find an iota of truth in what I say. And yes, all the very best to you.

Saturday, August 13, 2011

SOA by God's decree

I am not a religious person, but I believe we are in dire need of an IT religion.

Imagine mighty IT Gods looking over you. Imagine RC or Nandan visiting the TOGAF temple every morning and applying the SOA tilak before attending office.

Before you write me off, stop and think. Wouldn't it be nice to receive some support from an Almighty to do all the good things that need to be done?

We wouldn't need exorbitant studies and implementation plans spanning decades on whether and which EAF to use for the government. Our IT Vedas would've already explored the concepts and told us what to do.

We wouldn't need to quote best practices from Australian or Estonian governments to put in place comprehensive citizen empowerment frameworks. The IT Bible would've already endorsed it. They (the best practices) would figure frequently in sermons in the local IT Churches.

We would only hire consultants to implement the teachings - not to figure out and write the policies, processes and procedures (I beg your pardon... I mean "teachings"). We wouldn't really need so many technical committees. SOA would not only be decreed by the SOA Granth Sahib but suitable practices would all be detailed for those willing to undergo baptism.

IT security wouldn't be such a big problem, Inshallah. The Prophet would frown upon the sins of credit card thefts and his followers would declare jihad on any DDOS attacker. We would be taught from childhood that hacking is a sin that is severely punished by Allah.


I can see that I have fired your imagination - and probably indignation too. Before you get any bright ideas, let me warn you that I am an IT GodMan ordained by Lord vIShnu v3.0 as Swami Sas3Dev. So think twice before you flame me.


Honestly, we suffer from two serious problems in the industry:

  1. Credibility: Anyone we give good advice to, needs the advice ratified by a committee or a PhD or someone of repute. It wouldn't be so, if a religious text extolled its virtues.
  2. Divergent Expertise: No two experts agree on anything. Religion brings about the focus and agreement on good things to do and sins to avoid. Divergence of practices without diluting the convergence of good-vs-bad is such a good thing.
Beyond this, I leave it to your imagination.


Note: My humble apologies for all the name dropping. No, not just to the Gods and Advaita (for multiplicity of Gods in my imagination) philosophers, but to the real people as well. All done with a good intent.