Two Dimensional Thinking and APT

January 30th, 2010 admin

I expect many readers will recognize the image at left as representing part of the final space battle in Star Trek II: The Wrath of Khan. During this battle, Kirk and Spock realize Khan’s tactics are limited. Khan is treating the battle like it is occuring on the open seas, not in space. Spock says: He is intelligent, but not experienced. His pattern indicates two-dimensional thinking. I though this quote could describe many of the advanced persistent threat critics, particularly those who claim “it’s just espionage” or “there’s nothing new about this.” Consider this one last argument to change your mind. (Ha, like that will happen. For everyone else, this is how I arrive at my conclusions.) I think the problem is APT critics are thinking in one or two dimensions at most, when really this…


Originally posted on TAOSecurity

 
  Related Posts
Reaction to 60 Minutes Story
Reaction to 60 Minutes Story
I found the new 60 Minutes update on information warfare to be interesting. I fear that the debate over whether or not “hackers” disabled Brazil’s electrical grid will overshadow the real issue presented in the story: advanced persistent threats are here, have been here, and will continue to be here. Some critics claim APT must... 
What Is APT and What Does It Want?
What Is APT and What Does It Want?
This has been the week to discuss the advanced persistent threat , although some people are already telling me Google v China with respect to APT is “silly,” or that the attack vectors were what everyone has been talking about for years, and were somewhat sloppily orchestrated at that. I think many of these critics are missing the... 
Frank Furedi on Worst-Case Thinking
Nice essay by sociologist Frank Furedi on worse-case thinking, exemplified by our reaction to the Icelandic volcano: I am not a natural scientist, and I claim no authority to say anything of value about the risks posed by volcanic ash clouds to flying aircraft. However, as a sociologist interested in the process of decision-making, it is evident to... 
Ponemon Institute Misses the Mark
Ponemon Institute Misses the Mark
Today the Ponemon Institute announced results of a survey they conducted titled Growing Risk of Advanced Threats: Study of IT Practitioners in the United States . Unfortunately, this survey looks like it is mainly the blind asking the blind to describe a threat neither really understands. For example, the survey states: While the definition of... 
Space Terrorism
Space terrorism? Yes, space terrorism. This article, by someone at the European Space Policy Institute, hypes a terrorst threat I’ve never seen hyped before. The author waves a bunch of scare stories around, and then concludes that “the threat of ‘Space Terrorism’ is both real and latent,” then talks about countermeasures.... 
My Article on Advanced Persistent Threat Posted
My Article on Advanced Persistent Threat Posted
My article Understanding the Advanced Persistent Threat provides an overview of APT . It’s the cover story in the July 2010 Information Security Magazine . From the article: The term advanced persistent threat, or APT, joined the common vocabulary of the information security profession in mid-January, when Google announced its intellectual... 
Mandiant M-Trends on APT
Mandiant M-Trends on APT
If you want to read a concise yet informative and clue-backed report on advanced persistent threat , I recommend completing this form to receive the first Mandiant M-Trends report. Mandiant occupies a unique position with respect to this problem because they are one of only two security service companies with substantial counter-APT consulting... 
Bejtlich Returns to PaulDotCom Podcast
Bejtlich Returns to PaulDotCom Podcast
The guys at PaulDotCom posted the podcast .mp3 (39 MB) they conducted last week . It was another debate between myself and Ron Gula. We contrast control-centric and threat-centric defensive strategies, as well as discuss advanced persistent threat. Thanks for having us. I had forgotten that I was on their second show in January 2006! Copyright... 
Example of Threat-Centric Security
Example of Threat-Centric Security
In my last post I mentioned the need to take threat-centric approaches to advanced persistent threat . No sooner than I had posted those thoughts do I read this: Beijing ’strongly indignant’ about U.S.-Taiwan arms sale The Obama administration announced the sale Friday of $6 billion worth of Patriot anti-missile systems, helicopters,... 
Answering APT Misconceptions
Answering APT Misconceptions
There’s finally some good reporting on advanced persistent threat appearing in various news sources. A new Christian Science Monitor story, one by Federal Computer Week , and one by Wired are making progress in raising awareness. Unfortunately, there’s plenty of Tweeting and blogging by people who refuse to understand what is happening... 
  Related Tweets from Twitter

There was an error processing the Feed, if this is your page, please check the information provided in your profile.

  Related News from Digg
No comments yet.
You must be logged in to post a comment.
TOP