60 likes | 80 Views
This paper discusses the capabilities and limitations of endpoint security solutions, highlighting an ideal security model, defense strategies, and regulatory aspects. It also seeks feedback for future collaborations.
E N D
Capabilities and Limitations of Endpoint Security Solutions (CLESS) IETF 104, Monday 25th of March 2019, Prague Arnaud Taddei (Arnaud_Taddei@symantec.com) CandidWueest (Candid_Wueest@symantec.com) Kevin Roundy (Kevin_Roundy@symantec.com) Dominique Lazanski (dml@lastpresslabel.com)
Introduction to CLESS • Why? A gap in the « codification » of endpointsecurity? • Whynow? Many « environmental » changes (technical, regulations, etc.) • What? • In the long term, a full review of endpointsecurity in all its dimensions • Currentlywestartedwith • EndpointModels • ThreatLandscape • Endpointsecuritycapabilities • An idealendpointsecurity • Defence in depth • Endpointsecurity limitations • Examplefrom production data • Regulatory aspects • Status? An earlydraft on purpose, weseek feedback and future collaboration
Where to findit? Table of Contenthttps://github.com/smart-rg/drafts/blob/master/draft-taddei-cless-introduction-00.txt
LessonsLearntAlready • Much harder thaninitiallythought • Couldn’tfindanysatisfying: • ThreatLandscapemethodology for endpointsecurity • Capabilitieslist and methodology for endpointsecurity (not just 3rd party) • Good potential of work for SMART on boththreatlandscape and capabilities • Production data fromManaged Security Services • Interestingmethodology • Study on the last 3 months on hundreds of enterprisecustomers • Endpointonlysecuritygives a lot of results • Critical events not detected by endpoints
Questions for Future Development • Endpointmodelingbetween ‘UEs’ and ‘Hosts’ • Betteruniformityacross the document • ThreatLandscapeMethodology • Alignwith or fork from MITRE ATT&CK? • Shoulditbedone in this I-D? • IntrinsicCapabilities • Need a muchdeeperinventory • Other Aspects • Shouldwe have an economic section? • Regulations and HumanRights sections – need a good neutral balance • New Requirements, New Limits, New Constraints • Other real production data?
QUESTIONS ? THANK YOU