Click here to close now.

Welcome!

Search Authors: Carmen Gonzalez, Cloud Best Practices Network, AppDynamics Blog, Liz McMillan, Leo Reiter

News Feed Item

NSS Labs Announces Analyst Coverage and New Group Test for Breach Detection Systems

NSS Labs Predicts the BDS Market to Reach $1 Billion by 2018

AUSTIN, TX -- (Marketwire) -- 11/08/12 -- NSS Labs today announced initiation of coverage and the launch of a new group test for breach detection systems (BDS). BDS is an emerging group of security solutions focused on detecting of intrusions caused by targeted persistent attacks (TPAs) and other particularly sophisticated threats designed to harvest information from compromised systems. Fueled by the frequency and severity of data breaches and their associated costs, the BDS market will have a compound annual growth rate (CAGR) greater than 25 percent, reaching $1 billion by 2018, according to NSS Labs' forecasts.

"Although you could think of this class of product as 'next-generation intrusion detection systems (NGIDS),' we at NSS Labs feel that the 'next generation' tag has been over-used by security vendors," says Bob Walder, Chief Research Officer at NSS Labs. "These products are designed to analyze complex attacks out-of-band, detecting, rather than preventing, network breaches. Because they are not expected to operate in-line at wire speeds, they can perform much more extensive analysis of inbound and outbound traffic to detect complex threats. This means they can only alert us to network breaches that have already occurred. For this reason, we coined the term 'breach detection systems (BDS).' Rather than use different vendors' lexicons based on preferred marketing descriptions, BDS precisely defines the role these solutions are meant to perform, apart from other technologies."

View the new NSS Labs Analysis Brief - Breach Detection: Don't Fall Prey to Targeted Attacks.

Will Breach Detection Systems become the latest security "silver bullet" -- or "white elephant?"
As the attack surface broadens and highly motivated cybercriminals use increasingly innovative and dynamic approaches to deploy sophisticated crimeware, enterprises must assume that they will be (or have already been) breached. Through constant analysis of suspicious code and identification of communications with malicious hosts, breach detection systems can provide enhanced detection of advanced malware, zero-day and targeted attacks, acting as an "early warning" system for exploits that have bypassed other network security defenses. Key trends driving the demand for breach detection systems include:

  • Attack frequency and sophistication at the device level: Client-side attacks represent the fastest growing and most serious group of threats today: These attacks often install malicious code "silently" and many users don't know that they've been infected until after the fact. Breach detection systems that constantly analyze suspicious code and identify communication back to malicious hosts can provide enhanced detection of advanced malware, zero-day and targeted attacks.

  • Browsers and endpoint security products struggle to block attacks: Many traditional endpoint security solutions and browsers lack adequate exploit and evasion protection: In recent NSS Labs tests, only 2 of 13 endpoint products tested blocked more than 80% of exploits and over 60% (8 of 13) failed to block attacks where obfuscation methods for compressing and packing payloads were used. In recent browser testing, only Microsoft Internet Explorer blocked 99% of malicious downloads -- Google Chrome, Apple Safari and Mozilla Firefox lagged behind blocking only 70%, 4.3% and 4.2% respectively.

  • Awareness and safe surfing are not enough: It's not necessary to visit the "dark corners" of the Internet to be at risk: Spear-phishing and drive-by exploits are served up in employee inboxes and often incorporate the legitimate web sites of trusted brand names in their attacks. Breach detection systems recognize that many responsible, well-meaning users will inevitably still be exploited and jeopardize enterprise systems.

  • Breach detection needs to take mobile devices, other shifts into account: The growth of BYOD opens otherwise secured networks up to significant risk: The increasing number of personal mobile devices and the virtualization of offices expose the corporate network to any number of malware variants from untrusted networks that may lack the protection and capabilities of the corporate infrastructure. These mobile devices also often bypass perimeter filtering and security appliances.

Commentary: NSS Labs Research Director Francisco Artes
"Breach detection systems claim to improve the recognition of the most severe types of intrusions -- such as those with the most severe consequences if electronic health records, intellectual property or other sensitive materials are stolen -- but it remains to be seen whether vendors in this emerging segment can provide value that is not offset by new products' overhead and complexity," said Francisco Artes, Research Director at NSS Labs. "Effective BDS tools need to complement existing security investments but risk being simply another console to watch; we look forward to ongoing research and testing as these solutions mature and face real-world threats."

The NSS Labs Live Testing™ harness for the BDS tests is designed to test the five main technologies that can be used as part of a BDS solution -- virtual machine (VM) sandboxes, browser emulation, domain reputation, AV signature, and traffic analysis. NSS Labs analysts will cover numerous vendors in the BDS market, including:

  • AhnLab
  • Damballa
  • FireEye
  • Lastline
  • McAfee
  • Palo Alto Networks
  • Symantec
  • Trend Micro

NSS Labs is currently in the process of confirming which vendors will be in the first Group Test for BDS and results will be available to NSS Labs' subscribers at www.nsslabs.com once complete.

NSS Labs does not receive any compensation in return for vendor participation; all testing and research is conducted free of charge.

About NSS Labs, Inc.
NSS Labs, Inc. is the world's leading information security research and advisory company. We deliver a unique mix of test-based research and expert analysis to provide our clients with the information they need to make good security decisions. CIOs, CISOs, and information security professionals from many of the largest and most demanding enterprises rely on NSS Labs' insight, every day. Founded in 1991, the company is located in Austin, Texas. For more information, visit www.nsslabs.com.

© 2012 NSS Labs, Inc. All rights reserved. All brand, product and service names are the trademarks, registered trademarks, or service marks of their respective owners.

Add to Digg Bookmark with del.icio.us Add to Newsvine

More Stories By Marketwired .

Copyright © 2009 Marketwired. All rights reserved. All the news releases provided by Marketwired are copyrighted. Any forms of copying other than an individual user's personal reference without express written permission is prohibited. Further distribution of these materials is strictly forbidden, including but not limited to, posting, emailing, faxing, archiving in a public database, redistributing via a computer network or in a printed form.

@ThingsExpo Stories
The explosion of connected devices / sensors is creating an ever-expanding set of new and valuable data. In parallel the emerging capability of Big Data technologies to store, access, analyze, and react to this data is producing changes in business models under the umbrella of the Internet of Things (IoT). In particular within the Insurance industry, IoT appears positioned to enable deep changes by altering relationships between insurers, distributors, and the insured. In his session at @ThingsExpo, Michael Sick, a Senior Manager and Big Data Architect within Ernst and Young's Financial Servi...
Docker is an excellent platform for organizations interested in running microservices. It offers portability and consistency between development and production environments, quick provisioning times, and a simple way to isolate services. In his session at DevOps Summit at 16th Cloud Expo, Shannon Williams, co-founder of Rancher Labs, will walk through these and other benefits of using Docker to run microservices, and provide an overview of RancherOS, a minimalist distribution of Linux designed expressly to run Docker. He will also discuss Rancher, an orchestration and service discovery platf...
PubNub on Monday has announced that it is partnering with IBM to bring its sophisticated real-time data streaming and messaging capabilities to Bluemix, IBM’s cloud development platform. “Today’s app and connected devices require an always-on connection, but building a secure, scalable solution from the ground up is time consuming, resource intensive, and error-prone,” said Todd Greene, CEO of PubNub. “PubNub enables web, mobile and IoT developers building apps on IBM Bluemix to quickly add scalable realtime functionality with minimal effort and cost.”
Sensor-enabled things are becoming more commonplace, precursors to a larger and more complex framework that most consider the ultimate promise of the IoT: things connecting, interacting, sharing, storing, and over time perhaps learning and predicting based on habits, behaviors, location, preferences, purchases and more. In his session at @ThingsExpo, Tom Wesselman, Director of Communications Ecosystem Architecture at Plantronics, will examine the still nascent IoT as it is coalescing, including what it is today, what it might ultimately be, the role of wearable tech, and technology gaps stil...
Every innovation or invention was originally a daydream. You like to imagine a “what-if” scenario. And with all the attention being paid to the so-called Internet of Things (IoT) you don’t have to stretch the imagination too much to see how this may impact commercial and homeowners insurance. We’re beyond the point of accepting this as a leap of faith. The groundwork is laid. Now it’s just a matter of time. We can thank the inventors of smart thermostats for developing a practical business application that everyone can relate to. Gone are the salad days of smart home apps, the early chalkb...
CommVault has announced that top industry technology visionaries have joined its leadership team. The addition of leaders from companies such as Oracle, SAP, Microsoft, Cisco, PwC and EMC signals the continuation of CommVault Next, the company's business transformation for sales, go-to-market strategies, pricing and packaging and technology innovation. The company also announced that it had realigned its structure to create business units to more directly match how customers evaluate, deploy, operate, and purchase technology.
In the consumer IoT, everything is new, and the IT world of bits and bytes holds sway. But industrial and commercial realms encompass operational technology (OT) that has been around for 25 or 50 years. This grittier, pre-IP, more hands-on world has much to gain from Industrial IoT (IIoT) applications and principles. But adding sensors and wireless connectivity won’t work in environments that demand unwavering reliability and performance. In his session at @ThingsExpo, Ron Sege, CEO of Echelon, will discuss how as enterprise IT embraces other IoT-related technology trends, enterprises with i...
When it comes to the Internet of Things, hooking up will get you only so far. If you want customers to commit, you need to go beyond simply connecting products. You need to use the devices themselves to transform how you engage with every customer and how you manage the entire product lifecycle. In his session at @ThingsExpo, Sean Lorenz, Technical Product Manager for Xively at LogMeIn, will show how “product relationship management” can help you leverage your connected devices and the data they generate about customer usage and product performance to deliver extremely compelling and reliabl...
The Internet of Things (IoT) is causing data centers to become radically decentralized and atomized within a new paradigm known as “fog computing.” To support IoT applications, such as connected cars and smart grids, data centers' core functions will be decentralized out to the network's edges and endpoints (aka “fogs”). As this trend takes hold, Big Data analytics platforms will focus on high-volume log analysis (aka “logs”) and rely heavily on cognitive-computing algorithms (aka “cogs”) to make sense of it all.
With several hundred implementations of IoT-enabled solutions in the past 12 months alone, this session will focus on experience over the art of the possible. Many can only imagine the most advanced telematics platform ever deployed, supporting millions of customers, producing tens of thousands events or GBs per trip, and hundreds of TBs per month. With the ability to support a billion sensor events per second, over 30PB of warm data for analytics, and hundreds of PBs for an data analytics archive, in his session at @ThingsExpo, Jim Kaskade, Vice President and General Manager, Big Data & Ana...
One of the biggest impacts of the Internet of Things is and will continue to be on data; specifically data volume, management and usage. Companies are scrambling to adapt to this new and unpredictable data reality with legacy infrastructure that cannot handle the speed and volume of data. In his session at @ThingsExpo, Don DeLoach, CEO and president of Infobright, will discuss how companies need to rethink their data infrastructure to participate in the IoT, including: Data storage: Understanding the kinds of data: structured, unstructured, big/small? Analytics: What kinds and how responsiv...
Since 2008 and for the first time in history, more than half of humans live in urban areas, urging cities to become “smart.” Today, cities can leverage the wide availability of smartphones combined with new technologies such as Beacons or NFC to connect their urban furniture and environment to create citizen-first services that improve transportation, way-finding and information delivery. In her session at @ThingsExpo, Laetitia Gazel-Anthoine, CEO of Connecthings, will focus on successful use cases.
The Workspace-as-a-Service (WaaS) market will grow to $6.4B by 2018. In his session at 16th Cloud Expo, Seth Bostock, CEO of IndependenceIT, will begin by walking the audience through the evolution of Workspace as-a-Service, where it is now vs. where it going. To look beyond the desktop we must understand exactly what WaaS is, who the users are, and where it is going in the future. IT departments, ISVs and service providers must look to workflow and automation capabilities to adapt to growing demand and the rapidly changing workspace model.
Sensor-enabled things are becoming more commonplace, precursors to a larger and more complex framework that most consider the ultimate promise of the IoT: things connecting, interacting, sharing, storing, and over time perhaps learning and predicting based on habits, behaviors, location, preferences, purchases and more. In his session at @ThingsExpo, Tom Wesselman, Director of Communications Ecosystem Architecture at Plantronics, will examine the still nascent IoT as it is coalescing, including what it is today, what it might ultimately be, the role of wearable tech, and technology gaps stil...
Almost everyone sees the potential of Internet of Things but how can businesses truly unlock that potential. The key will be in the ability to discover business insight in the midst of an ocean of Big Data generated from billions of embedded devices via Systems of Discover. Businesses will also need to ensure that they can sustain that insight by leveraging the cloud for global reach, scale and elasticity.
The Internet of Things (IoT) promises to evolve the way the world does business; however, understanding how to apply it to your company can be a mystery. Most people struggle with understanding the potential business uses or tend to get caught up in the technology, resulting in solutions that fail to meet even minimum business goals. In his session at @ThingsExpo, Jesse Shiah, CEO / President / Co-Founder of AgilePoint Inc., showed what is needed to leverage the IoT to transform your business. He discussed opportunities and challenges ahead for the IoT from a market and technical point of vie...
IoT is still a vague buzzword for many people. In his session at @ThingsExpo, Mike Kavis, Vice President & Principal Cloud Architect at Cloud Technology Partners, discussed the business value of IoT that goes far beyond the general public's perception that IoT is all about wearables and home consumer services. He also discussed how IoT is perceived by investors and how venture capitalist access this space. Other topics discussed were barriers to success, what is new, what is old, and what the future may hold. Mike Kavis is Vice President & Principal Cloud Architect at Cloud Technology Pa...
Hadoop as a Service (as offered by handful of niche vendors now) is a cloud computing solution that makes medium and large-scale data processing accessible, easy, fast and inexpensive. In his session at Big Data Expo, Kumar Ramamurthy, Vice President and Chief Technologist, EIM & Big Data, at Virtusa, will discuss how this is achieved by eliminating the operational challenges of running Hadoop, so one can focus on business growth. The fragmented Hadoop distribution world and various PaaS solutions that provide a Hadoop flavor either make choices for customers very flexible in the name of opti...
The true value of the Internet of Things (IoT) lies not just in the data, but through the services that protect the data, perform the analysis and present findings in a usable way. With many IoT elements rooted in traditional IT components, Big Data and IoT isn’t just a play for enterprise. In fact, the IoT presents SMBs with the prospect of launching entirely new activities and exploring innovative areas. CompTIA research identifies several areas where IoT is expected to have the greatest impact.
Advanced Persistent Threats (APTs) are increasing at an unprecedented rate. The threat landscape of today is drastically different than just a few years ago. Attacks are much more organized and sophisticated. They are harder to detect and even harder to anticipate. In the foreseeable future it's going to get a whole lot harder. Everything you know today will change. Keeping up with this changing landscape is already a daunting task. Your organization needs to use the latest tools, methods and expertise to guard against those threats. But will that be enough? In the foreseeable future attacks w...