Hackers targeting human/machine interfaces

Apr 27, 2009 6:48 AM
Tags: security | hackers

Better security technology means that hackers are focusing more on the point where humans meet machines in their efforts to penetrate systems, an IBM security expert has said.

In his keynote to the RSA 2009 conference, Brian Truskowski, general manager of IBM's Internet Security Systems (ISS) business, told delegates that despite all the improvements in security technology the human element was still the key weakness in any system.

“We need to admit humans will always fall for a good hoax, then we need to accept it and move on,” he said.

“Humans are an infinite threat to security. This is why security has moved to the machine/human interaction point, chiefly the browser and the application.”

He gave the example of Kevin Mitnick, one of the most famous hackers of all time. Mitnick himself admitted that his success was down less to his computer knowledge and more to an ability to fool people with social engineering.

Truskowski said that for security to be effective it needed to be built into the enterprise from the ground up and be responsive. Too many vendors focused just on blocking one attack vector when a more flexible approach was needed.

The situation was similar to the Titanic, he said. The ship builders focused on strength, speed and luxury and ignored maneuverability, which proved fatal for many of the passengers.

“Too many chief executives see the iceberg coming but can't do anything about it,” Truskowski said.

Companies should focus on building flexible network security and consider offloading part of the business to managed security vendors, he continued, as there are simply not enough good security personnel available for IT departments to hire.

Copyright ©v3.co.uk


  • Email a Friend
  • Print Page
Hackers targeting human/machine interfaces
 
Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment
 
 
 
Top Stories
Adelaide gets nod for high density data centre
Gauvin to build data centre in old Mitsubishi plant.
 
Datacom calls in structural engineers for data centre
Post incident report on flood damaged data centre.
 
Plans afoot for new Sydney-US fibre link
Kiwi big wigs plan new Pacific cable.
 
Spotlightthe topics we're following
Latest Comments
"What is the point of these plans, they remind of something Telstra would offer, they wouldn't be ..."
by HubertCumberdale Mar 15, 2010 9:26 PM
 
"It is true to say that there are a lot of complex factors to consider and a lot of costs ..."
by tallguy Mar 15, 2010 7:44 PM
 
"Tim, Very interested to know where your information is coming from. As someone who has been ..."
by Primeribfan Mar 15, 2010 6:51 PM
 
"Indeed, I don't advocate voting for Libs because of this. It would be a tragedy for Abbott to ..."
by Sams Mar 15, 2010 5:37 PM
 
"@ Graeme. I don't think that's a like-for-like comparison. NSW Govt says the $2240 includes ..."
by rycrozier Mar 15, 2010 5:21 PM
1) HTC Magic3 plans 2%
2) Nokia N9739 plans 4%
3) Nokia E7227 plans 2%
4) Nokia E7144 plans 3%
5) Apple iPhone 3GS 32GB32 plans 6%
1) 37 plans 100%
2) Optus41 plans 5%
3) iiNet32 plans 6%
4) Dodo34 plans 4%
5) Telstra BigPond30 plans 3%

Mobiles | Broadband | Credit Cards

Haymarket - iTnews