Wednesday, December 2, 2015

Asymmetric Defense Failures

No. I'm not talking about the cost of an attack vs. the cost of defending the network. I'm talking about traffic flows. Communications are bidirectional, ingress and egress, yet many still focus on only ingress protection mechanisms.

You need both. For example, your firewall and intrusion prevention system (malware, etc.) may do a fantastic job at identifying incoming attacks. However, you also need egress detective and protective controls. For example, your DLP system can help identify data exfiltration – egress – and your network behavior anomaly detection appliance can help identify potentially compromised hosts communicating to command and control servers.

There's actually much more to write about on this topic. But for now, suffice to say that intelligent context and control of communications are important from both perspectives.