The False Positive: Still tomorrow’s mistake!

The False Positive: Still tomorrow’s mistake!

By Richard Moss | Jul 2, 2009 | 3381 reads

The topic of the 'false positive' has always been an issue for the security profession and the subject has been in the news again recently; last week, following the announcement of Michael Jackson’s death, Google News found its website so inundated with page requests that its security systems and [human] analysts mistook the legitimate traffic for a denial of service attack – so convinced were Google that they disconnected the news site for a short period of time.

Closer to home, the mainland’s deployment of the controversial content control software ‘Green Dam’ has generated numerous press articles and criticism (but staying on the subject of false positives) a story that brought a wry smile to my face last week was ‘Green Dam’ blocking internet downloads of pictures of pigs (those filthy swine, always making the news somehow).

The software can be used for multiple purposes but is reportedly designed to target online pornography by scanning images for key attributes of pornography and apparently an excess of pink colored areas is one of those – so presumably the excess of pink pig flesh caused Green Dam to block downloads of pig pictures. 

This of course raises questions of how popular pig-picture downloads are in mainland china, but perhaps that’s a topic for another blog.

But let’s be honest with ourselves: the expression “false positive” is just another way of saying “mistake” – a mistake where legitimate email, content or applications have been incorrectly blocked in the name of security when they shouldn’t have been. And it's really hard to get this bit right - anyone involved in the deployment and tuning of an IPS system can tell you just how time-consuming and laborious the effort is in getting a complex security system tuned to the behavior of the enterprise and to accurately reproduce and solve any problems when they arise!

Furthermore, as much of an enterprises’ security requirements are outsourced today (think anti-virus, SPAM control, managed security services) the reporting requirements to a 3rd party vendor can become quiet onerous and needs to be very specific or there is little they can do to help.

However, the false positive is not a new phenomenon; yet it is one that has not successfully been resolved over the past few years - although the industry might argue that great improvements have been made in the area (an example being the accelerated deployment of IPS over the more widely accepted IDS systems of the past, although I would argue that IPS deployments still block traffic in a limited fashion, sort of an IDS+ rather than a true IPS!).

 
 

Add comment

Post a Comment

The content of this field is kept private and will not be shown publicly.
Verification Code
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
 

Comments

Comments

Dresses, evening, cocktail,

Dresses, evening, cocktail, prom dresses, formal gowns from eiDress. Homecoming dresses and bridesmaid.
Evening Dresses
Cocktail Dresses
Formal Gowns
Prom Dresses: Find Online fashionable prom dresses,homecoming dresses from top USA prom gowns designers,
Evening dresses, sexy Tops , casual dress ,sexy
Custom Dresses
Elegant couture designer evening gowns, sexy dresses, inexpensive on sale prom dresses,
bridesmaid dresses
Nationwide bridal salon offers bridal and wedding gowns, bridesmaid dresses,
flower girl dresses, tuxedos, and other special occasion apparel. Site includes a bridal
wedding dresses
designer wedding dress

Don Ed Hardy is an American

Don Ed Hardy is an American tattoo artist born in Iowa in 1945, and raised in Southern California.tiffany jewellery
ed hardy shoes
A pupil of Sailor Jerry, Hardy is recognized for incorporating Japanese tattoo aesthetic and technique into his work
ed hardy

our company was vested with

our company was vested with production authority of the U.S. National Football League (nfl jersey) in China. Therefore we are one of the largest nfl jerseys center in China and our products have been exported to Europe and America market for cheap nfl jerseys time.

第二の永久歯といわ

第二の永久歯といわれるインプラントですが、興味はあっても
インプラント治療に対して、 不安をお持ちの方がたくさんいらっしゃいます。

Information on Blogger

leave a comment

knowledge_central_tab

 
 
Knowledge Central
Trusted Mobility Index
The mobile ecosystem of devices, services and networks is at a critical inflection point.While the mobile revolution is unleashing massive opportunities in both emerging and mature economies, it is also increasing in complexity and confusion. The reality is the lightning-fast adoption of powerful, smart devices is outpacing society’s ability to secure them. Today, trust in mobility hangs in the balance.
The state of the Internet, Q4, 2011
Geography appears to play a role in frequency of observed attacks on specific ports. For example, Port 23 (Telnet) is a favorite target for attacks observed to be originating from South Korea and Turkey, where it accounted for more than five times the number of attacks targeting the next most popular port (445 in both countries). Other instances of geography-based port targeting include observed attacks centered on Port 1433 (Microsoft SQL Server) in China and on Port 80 (WWW/HTTP) in Indonesia.
 
 
 
HID Global deploys a centralized, web-based IP access control solution at Fuxi Power Plant
Unable to meet the needs for real-time monitoring with its traditional patrol system, China's Fuxi Power Plant has deployed HID Global's VertX V2000.
StubHub: How to spot fraud before it happens
Whenever a list of log-on credentials is dumped onto the Web, retailers get hit with waves of automated attacks. Here's how ticket marketplace StubHub fights the threat.