<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AllThingsD &#187; Art Coviello</title>
	<atom:link href="http://allthingsd.com/tag/art-coviello/feed/" rel="self" type="application/rss+xml" />
	<link>http://allthingsd.com</link>
	<description></description>
	<lastBuildDate>Sat, 26 May 2012 14:31:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><image>
		  <url>http://allthingsd.com/theme/images/logo-rss.jpg</url>
		  <title>All Things Digital</title>
		  <link>http://allthingsd.com/</link>
		  <width>144</width>
		  <height>22</height>
	</image>		<item>
		<title>Seven Questions for RSA Security Head Art Coviello</title>
		<link>http://allthingsd.com/20120227/seven-questions-for-rsa-security-head-art-coviello/</link>
		<comments>http://allthingsd.com/20120227/seven-questions-for-rsa-security-head-art-coviello/#comments</comments>
		<pubDate>Mon, 27 Feb 2012 14:50:39 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[analytics]]></category>
		<category><![CDATA[Art Coviello]]></category>
		<category><![CDATA[big data]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[EMC]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[intelligence]]></category>
		<category><![CDATA[Lockheed Martin]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[RSA Conference]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=178287</guid>
		<description><![CDATA[A year after an attack on its widely used security system, the head of RSA Security talks about lessons learned and what the computer security industry needs to do next.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20120227/seven-questions-for-rsa-security-head-art-coviello/coviello-rsa/" rel="attachment wp-att-178294"><img src="http://allthingsd.com/files/2012/02/coviello-rsa-380x285.png" alt="" title="coviello-rsa" width="380" height="285" class="alignright size-Featured wp-image-178294" /></a>It&#8217;s been almost a year since the security company RSA disclosed that it had come under what it described as an &#8220;<a href="http://allthingsd.com/20110317/rsa-under-extremely-sophisticated-attack-yes-the-tokens-are-involved/">extremely sophisticated</a>&#8221; cyberattack.</p>
<p>It went on to explain <a href="http://allthingsd.com/20110404/rsa-explains-how-it-was-hacked/">some of the circumstances </a> of the attack, a little bit about what data was taken, and then later conceded that at least some of that  information was used to launch an ultimately unsuccessful attack <a href="http://allthingsd.com/20110527/lockheed-martin-network-disrupted-rsa-tokens-reportedly-involved/">against the defense contractor Lockheed Martin</a>.</p>
<p>Last year was a tough one for RSA. Its security tokens, which generate six-digit numbers that act as a second constantly-changing password to help keep intruders out of sensitive computer systems, are the backbone of the security systems of many companies and government agencies.</p>
<p>Art Coviello, the onetime CEO of RSA and now executive vice president of its parent EMC, will be giving a keynote address tomorrow at the annual RSA Security Conference in San Francisco. I thought it might be a good chance to talk with him about the legacy of the attack on RSA, see if there was anything new he could share about what was learned about the attack, and how what happened is shaping RSA&#8217;s thinking about the computer security landscape.</p>
<p><strong>AllThingsD: Art, You&#8217;ll be speaking at RSA about a year after the infamous attack on your company. How are you approaching the speech, and what are you going to say?</strong></p>
<p><strong>Coviello</strong>: Part of what I&#8217;ll be talking about is the renewed sense of dedication we have to our mission, our responsibility to customers to regaining and maintaining their confidence. And also applying the lessons learned and sharing them vigorously, not only with our attack, but some of the other attacks that we have privileged insight into. And the bottom line is that we do hope, in the final analysis, that people have more of a sense of urgency in protecting themselves, because the truth of the matter is that we weren&#8217;t alone. The theme will be how security has to change from the kind of perimeter defenses that seemed to be dissolving even before our attack, to the requirement for more resilient security based on intelligence that you can get on a more real-time basis. So I&#8217;ll be outlining RSA&#8217;s vision for intelligence-driven security.</p>
<p>It will be a fairly strong call to action for the industry. We&#8217;ve had a great run in creating a trusted digital world, for all its weaknesses and idiosyncrasies. But as you see with trends like the consumerization of IT, we&#8217;ve never had a generation of employees and consumers that has been as technology-savvy as we have today, and in many instances they&#8217;re getting ahead of the enterprise IT organization&#8217;s ability to absorb the technologies they use day in and day out. And that puts an even bigger burden, from a security perspective, on IT organizations. And so they need to manage what they can&#8217;t directly control, and secure what they can&#8217;t directly control, and that means perimeters are nonexistent. So how do you get the intelligent controls you do have deployed more intelligently, so that even if things are out of reach, they&#8217;re not out of your ability to secure them? Our attack did not only raise awareness, but also the action level of people. </p>
<p><strong>The attack that RSA suffered last year caught a lot of people by surprise. For those who haven&#8217;t kept track, have there been any new disclosures or information disclosed since, or is there anything new that you&#8217;ve learned?</strong></p>
<p>No. And the funny part about it, as with all things in the press, if nothing bad happens, nothing gets written about. To date, there has been only one instance where it has been suggested that the information stolen from us has been used in another attack. And that was Lockheed Martin. And that attack was unsuccessful. There have been no other attacks, and believe me, we have stayed close with law enforcement and other sources, and have run down every one of these that has been reported, and there&#8217;s no substantiation of even another attempted attack, let alone a successful one. So we stand by the original decision we made in March, which was to announce that information had been stolen, to announce that you couldn&#8217;t launch a direct attack with the information stolen, and that if you took the remediation steps that we advised our clients to take, you&#8217;d be fine.</p>
<p>I think &#8212; and this is my theory &#8212; the attacker thought that they would be able to get in, steal the information they got from us without being caught, and then steal information from others, and combine them. And, quite frankly, because of our quick action in detecting that we were breached and some information stolen, we blew their cover. I can&#8217;t think of a reason to explain why they would go to all that trouble and you would only see one instance of a follow-up attack, and that one instance was stopped. And that got lost in all the coverage. </p>
<p><strong>The impression I got was that the attacker seemed to get that this was an attack that was only partially successful, and that whoever it was &#8212; the speculation was that it was China &#8212; they only got a little of what they had hoped to get, and once detected, the jig was up. Is that more or less how you see it?</strong></p>
<p>I couldn&#8217;t put it better than that. And we said that everything we saw pointed to a nation-state, but we never had the smoking gun to point to a particular country as the source of the attack.</p>
<p><strong>So then what happened after the attack was that, since a lot of people and companies and government agencies had put a lot of faith in the RSA dongles and your system to keep people out, there was a bit of a crisis with that faith.</strong></p>
<p>Totally true, let me step in here. That was one of the issues we had to wrestle with when the Lockheed incident happened. Because of the Lockheed thing, people thought we had to issue new tokens to everyone. That was not the case. We continued to stand by the remediation. But we had to recognize the angst and the perception among customers. And that is why we had to offer to replace the tokens. And sure, there were a number of customers who did, but the vast majority did not. No one likes the fact that it happened, but our concern right from day one was for the customers. The proof of the pudding is that our customers are still taking tokens. We&#8217;ve lost a negligible number of customers. And, in fact, we&#8217;ll be talking this week about some surveys showing that people are still buying tokens.</p>
<p><strong>So you say in your remarks you plan to talk about real-time security intelligence, which is something I&#8217;ve talked about <a href="http://allthingsd.com/20120221/big-blue-goes-big-on-it-security/">with IBM recently</a>. Is real-time intelligence the direction where the entire security industry has to go?</strong></p>
<p>First of all, the NetWitness &#8212; and this is another irony in all this &#8212; I signed the purchase and sale agreement to purchase NetWitness just a few days before the attack on RSA. And one of the reasons we bought it is that we had it deployed all across EMC. And we viewed it as being very effective in spotting anomalies in network traffic. So the issue today, especially with the porous perimeters that we have, is not whether or not you can or will be breached, because you can be breached. The issue is how fast can you spot it. </p>
<p>The Verizon data-breach report (<a href=http://www.verizonbusiness.com/resources/reports/rp_data-breach-investigations-report-2011_en_xg.pdf>PDF here</a>) says that more than 90 percent of exfiltrations occur within hours or days of the initial breach. But about 79 percent of breaches aren&#8217;t spotted until weeks after they occur. We were able to see the attack in progress, which is why we were able to minimize the information that did get out, and we were within a blink of an eye of stopping the attack altogether. And it was based on this NetWitness technology. But since we acquired it, we have been leveraging it to see not just movements of packets, but to combine with our (Security Event Management) product to not just log information, but ingest all kinds of contextual information. This is unprecedented in security technology and, frankly, IBM doesn&#8217;t have it. </p>
<p>And one of the things that I&#8217;ll be saying in the keynote is that the age of Big Data has arrived for security, and it has. It is a Big Data problem. If you&#8217;re going to be able to spot these attacks in real time and have a resilient security system, as opposed to one that breaks and doesn&#8217;t bend, which is what the perimeter defenses do today, then you have to have real-time analytical capability. Only today do we have the storage and analytical capability, and the ability to deploy it at scale. One disadvantage of the attackers is that they are not legitimate. There will always be something in how they get access, or what they do, that will allows us to find them out.</p>
<p><strong>The observation I made in talking with IBM last week is that there are so many new problems and threats emerging that it&#8217;s not only difficult to keep track of them, but it&#8217;s also hard to filter security vendors who offer conflicting visions and products they all say are a panacea. CIOs are getting confused, and are having a hard time calibrating their priorities. How do they find any clarity these days?</strong></p>
<p>Let me read a line from my keynote: We have to stop being linear thinkers, blindly adding controls on top of failed models. It&#8217;s the model itself that is broken. If a vendor is coming to you, saying, &#8220;I&#8217;ve got this new control, just add it to this uncoordinated silo of controls that already exist,&#8221; then they are not doing you much of a service. What we&#8217;re advocating is that people double down on some of the qualitative things that have nothing do with technology. So the first element of having what we call an intelligence-driven security system is doing a better job of assessing and managing risk. And I&#8217;m going to put a challenge out to the audience, and I&#8217;m going to say that no one does this meaningfully, and no one does it well.</p>
<p><strong>So what needs to change?</strong></p>
<p>When I talk about understanding the threats outside-in, as well as inside-out, what I mean is not only understanding what your material assets are, but marrying that knowledge to an understanding of who might attack you, how they might come at you. The next step is getting leverage from the controls that you have. You have to disinvest in some. Let&#8217;s face it, 10 or 12 years ago, antivirus signatures numbered in the tens of thousands. Now they number in the tens of millions. How can that make any sense? As soon as you have a signature, someone has a new virus to overcome it. It&#8217;s these static models that don&#8217;t bend, but break, that have to change. The controls that we have have to be more intelligent.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120227/seven-questions-for-rsa-security-head-art-coviello/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SecurIDs Come Under Siege</title>
		<link>http://allthingsd.com/20110606/securids-come-under-siege/</link>
		<comments>http://allthingsd.com/20110606/securids-come-under-siege/#comments</comments>
		<pubDate>Tue, 07 Jun 2011 00:36:45 +0000</pubDate>
		<dc:creator>Siobhan Gorman and Shara Tibken</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Voices]]></category>
		<category><![CDATA[Art Coviello]]></category>
		<category><![CDATA[EMC]]></category>
		<category><![CDATA[intruders]]></category>
		<category><![CDATA[Lockheed Martin]]></category>
		<category><![CDATA[RSA Security]]></category>
		<category><![CDATA[SecurID]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=83453</guid>
		<description><![CDATA[RSA Security is offering to replace its well-known SecurID tokens--devices used by 40 million corporate workers to securely log on to their computers--"for virtually every customer we have," the company's chairman, Art Coviello, said in an interview.]]></description>
			<content:encoded><![CDATA[<p>RSA Security is offering to replace its well-known SecurID tokens&#8211;devices used by 40 million corporate workers to securely log on to their computers&#8211;&#8221;for virtually every customer we have,&#8221; the company&#8217;s chairman, Art Coviello, said in an interview.</p>
<p>In a letter to customers Monday, the EMC Corp. unit openly acknowledged for the first time that intruders had breached its security systems at defense contractor Lockheed Martin Corp.</p>
<p><a href="http://online.wsj.com/article/SB10001424052702304906004576369990616694366.html">Read the rest of this post on the original site »</a></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20110606/securids-come-under-siege/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RSA Under &quot;Extremely Sophisticated&quot; Attack; Yes, That Includes Those Tokens</title>
		<link>http://allthingsd.com/20110317/rsa-under-extremely-sophisticated-attack-yes-the-tokens-are-involved/</link>
		<comments>http://allthingsd.com/20110317/rsa-under-extremely-sophisticated-attack-yes-the-tokens-are-involved/#comments</comments>
		<pubDate>Fri, 18 Mar 2011 00:15:41 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[advanced persistent threat]]></category>
		<category><![CDATA[Arik Hesseldahl]]></category>
		<category><![CDATA[Art Coviello]]></category>
		<category><![CDATA[EMC]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[information secrity]]></category>
		<category><![CDATA[NewEnterprise]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[script kiddie]]></category>
		<category><![CDATA[SecurID]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security feature]]></category>

		<guid isPermaLink="false">http://newenterprise.allthingsd.com/?p=4110</guid>
		<description><![CDATA[Security company RSA has disclosed an attack on its systems. Data regarding its SecurID tokens, widely used by companies and governments, was taken.]]></description>
			<content:encoded><![CDATA[<p><img src="http://newenterprise.allthingsd.com/files/2011/03/RSA_SecurID_SID800-275x130.jpg" alt="" title="RSA_SecurID_SID800" width="275" height="130" class="alignright size-medium wp-image-4111" />Security company RSA today disclosed what it described as an &#8220;extremely sophisticated attack&#8221; against its technology. The disclosure came in a <a href="http://www.rsa.com/node.aspx?id=3872">blog post by Art Coviello</a>, the former RSA CEO who saw the company through its 2006 acquisition by EMC.</p>
<p>Coviello didn&#8217;t disclose many details about the attack, but said the attackers were able to extract some information about the company&#8217;s SecurID products. The backbone of the SecurID system is the keychain-sized tokens like the one pictured that generate a new number every 30 seconds or so, and used to log in to computer networks and other systems. The tokens and software that generates numbers in the same way on smart phones are widely used by corporations and governments to keep attackers out. As of 2009, RSA estimated that 40 million people used the tokens and another 250 million used RSA software on their smart phones.</p>
<p>Coviello said that so far it doesn&#8217;t look like the SecurID system has been compromised. But the information taken by the attackers could make an attack that would compromise it somewhat easier. &#8220;While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers, this information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack,&#8221; he wrote. &#8220;We are very actively communicating this situation to RSA customers and providing immediate steps for them to take to strengthen their SecurID implementations.&#8221;</p>
<p>RSA has classified the attack as an &#8220;Advanced Persistent Threat&#8221; which in security industry parlance means it&#8217;s sophisticated enough that it may require the resources of a nation state to carry out, though the phrase is often met with mild derision by security professionals. As one put it, APT is another way of saying &#8220;<a href="http://twitter.com/thierryzoller/statuses/48514483492102144">not attacked by a script kiddie</a>.&#8221;</p>
<p>It remains to be seen exactly how significant this incident will prove to be over the long term. As one security expert put it to me, if algorithm used to generate the numbers displayed by the token is compromised in any way, confidence in the SecurID system will plummet, and the cost to RSA and EMC could be serious. Not only will there be the cost to replace all those tokens, but work will have to be done to change the software algorithm used to generate the numbers. Neither will be inconsequential. EMC shares finished the day up 25 cents or nearly 1 percent, but are falling slightly in after-hours trading as the news about this attack has come to light.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20110317/rsa-under-extremely-sophisticated-attack-yes-the-tokens-are-involved/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

