What the Computer Security Industry Doesn’t Want You to Know
Review by Steve Hardwick, CISSP
I have worked in the information security business for more than 10 years, and I’ve learned there is one constant throughout – change. Keeping up with the ever-present cat and mouse battle between the hackers and security industry is a full time job. The Myths of Security by John Viega (O’Reilly Media, $29.95) provides a good view of what the security industry faces and why they sometimes fall short in the eyes of many people. So the next time you are hitting your computer with your keyboard in utter frustration, put it down, pick up this book and take a look at why computer security is so hard. You can also learn what doesn’t work to secure computers – and by extension, good security practices. Some of the biggest security weaknesses will surprise you.
This book begins by outlining how easy it is to have a security problem. Early chapters cover the methods of attacking computer systems and how they have evolved. These include simple viruses focused on specific operating systems up to more sophisticated Web-based attacks and social engineering exploits. New attacks are independent on the operating system; rather, they exploit the lack of knowledge of the user. (Despite their sanguine outlook, even Apple users are wide open to these types of attacks.) Chapter 15 has an excellent example of a phishing attack that demonstrates how the bad guy can get key information without ever touching the operating system. According to the Anti-Phishing Working Group, June of 2009 was the second-highest month for number of new phishing sites detected.
The author makes two very crucial points: First, it is no longer just a battle of viruses anymore – any computer user is vulnerable. Second, users will want an antivirus application that can deal with all manner of information security threats — viruses, malware, adware, phishing, cross site scripting and more.
Read the rest of this entry »
Recent Comments