Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC Internet Storm Center

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Latest Diaries

NSS Labs Cyber Resilience Report

Published: 2014-08-23
Last Updated: 2014-08-23 00:36:16 UTC
by Guy Bruneau (Version: 1)
0 comment(s)

Bob Walder and Chris Morales of NSS Labs published an interesting brief. Based on last year IPS, firewall and endpoint protection tests, the effectiveness of the best device scored was 98.5%. While this is considered excellent, there is still ~2 percent of attacks that make it through the perimeter and host layer defences. Two of their proposals is to attempt to control the attacker by redirecting the attack against a target you can watch and control (i.e. tarpit the attacker) and to regularly test your network to detect problems before someone else does and exploit that system.

They have listed several recommendations but one that I think is worth focussing is be "Prepare to operate at 60 percent capacity in order to withstand a breach, which will reduce, but not eliminate, critical services." [1]

It is very likely the impact will be affecting users, customers and business. Who is prepared to continue to operate at 60% capacity without affecting business or the bottom line?

The eleven page report can be downloaded here.



Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu

0 comment(s)

If you have more information or corrections regarding our diary, please share.

Recent Diaries

OCLHashCat 1.30 Released
published 11 hours ago by Richard (0 comments)

Now supporting OpenIOC via our API!
published 1 day ago by Alex Stanford (0 comments)

Social Engineering Alive and Well
published 2 days ago by Kevin Shortt (1 comment)

Part 2: Is your home network unwittingly contributing to NTP DDOS attacks?
published 3 days ago by Rick (1 comment)

Web Server Attack Investigation - Installing a Bot and Reverse Shell via a PHP Vulnerability
published 5 days ago by Lenny (1 comment)

Part 1: Is your home network unwittingly contributing to NTP DDOS attacks?
published 5 days ago by Rick (2 comments)

Issues with Microsoft Updates
published 6 days ago by Manuel Humberto Santander Pelaacuteez (7 comments)

View All Diaries →

Latest Discussions

So, how dead is antivirus exactly?
created 2 days ago by Safensoft (0 replies)

recommender system for network intrusion detection
created 1 week ago by Anonymous (0 replies)

Stale prefixes associated with our AS
created 2 weeks ago by cj (0 replies)

DSHIELD with fail2ban
created 1 month ago by Ernest (0 replies)

Router Upgrade
created 1 month ago by ICI2Eye (2 replies)

View All Forums →

Latest News

View All News →