Firewall Wizards mailing list archives

Re: Re: Flawed Surveys [was: VPN endpoints]


From: "Paul D. Robertson" <paul () compuwar net>
Date: Wed, 1 Sep 2004 20:34:42 -0400 (EDT)

On Wed, 1 Sep 2004, Bruce B. Platt wrote:

How appropriate for this thread.  Who wants to admit in a survey that
they aren't doing what is needed to stay secure?

Surprisingly enough, there are people who will.  A lot of it depends, I
think, upon the goal of the survey- things people have a vested interest
in the outcome of seem to get straighter answers than things where the
information doesn't seem to have a direct benefit- or maybe it's something
else, but I've done some limited test surveys[1] specifically about
security inside an organization (not blind either) where the results varied a
little between respondents in a company, but where they admitted where
things were weak.

Referring to your blaster comments, why don't we just start plotting
reverse lookups of probes from infected outward-facing machines, or
spewers of virus laden mail and then use that data to create a db of
"insecure" organizations.  (ad hoc definition of an insecure organization.)

The issue with the probe stuff is that I could start spewing spoofed
packets to make my competitors look bad.  However, I'm all up for a good
listing of probes, spam and worms by company.

Depending on the terms and wiggle stuff, I might be willing to host it-
I'll have to think about the potential liability downsides first though.

Take that, then survey executives from those firms and other firms with
small numbers of outward-directed probes or virus transmissions.  There
is an operational definition of insecurity stated above which can be
compared to survey results.  Perhaps this gets around the self-selected
issue as well as some others.

Might be worth spinning up a network-admin-based f'd company type site
too- maybe start building a club to beat some of the more irresponsible
companies into submission...

Paul
[1] Non-scientific, poor question format, covered in brown polish.  Never
used the results, other than to see how my views of the organizations
differed with the IT staff.
-----------------------------------------------------------------------------
Paul D. Robertson      "My statements in this message are personal opinions
paul () compuwar net       which may have no basis whatsoever in fact."
probertson () trusecure com Director of Risk Assessment TruSecure Corporation
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: