The False Positive: Still tomorrow’s mistake!

  • warning: preg_match() expects parameter 2 to be string, array given in /var/www/html/includes/bootstrap.inc on line 684.
  • warning: preg_match() expects parameter 2 to be string, array given in /var/www/html/includes/bootstrap.inc on line 684.
  • warning: preg_match() expects parameter 2 to be string, array given in /var/www/html/includes/bootstrap.inc on line 684.
  • warning: preg_match() expects parameter 2 to be string, array given in /var/www/html/includes/bootstrap.inc on line 684.

The False Positive: Still tomorrow’s mistake!

By Richard Moss | Jul 2, 2009 | 1214 reads

The topic of the 'false positive' has always been an issue for the security profession and the subject has been in the news again recently; last week, following the announcement of Michael Jackson’s death, Google News found its website so inundated with page requests that its security systems and [human] analysts mistook the legitimate traffic for a denial of service attack – so convinced were Google that they disconnected the news site for a short period of time.

Closer to home, the mainland’s deployment of the controversial content control software ‘Green Dam’ has generated numerous press articles and criticism (but staying on the subject of false positives) a story that brought a wry smile to my face last week was ‘Green Dam’ blocking internet downloads of pictures of pigs (those filthy swine, always making the news somehow).

The software can be used for multiple purposes but is reportedly designed to target online pornography by scanning images for key attributes of pornography and apparently an excess of pink colored areas is one of those – so presumably the excess of pink pig flesh caused Green Dam to block downloads of pig pictures. 

This of course raises questions of how popular pig-picture downloads are in mainland china, but perhaps that’s a topic for another blog.

But let’s be honest with ourselves: the expression “false positive” is just another way of saying “mistake” – a mistake where legitimate email, content or applications have been incorrectly blocked in the name of security when they shouldn’t have been. And it's really hard to get this bit right - anyone involved in the deployment and tuning of an IPS system can tell you just how time-consuming and laborious the effort is in getting a complex security system tuned to the behavior of the enterprise and to accurately reproduce and solve any problems when they arise!

Furthermore, as much of an enterprises’ security requirements are outsourced today (think anti-virus, SPAM control, managed security services) the reporting requirements to a 3rd party vendor can become quiet onerous and needs to be very specific or there is little they can do to help.

However, the false positive is not a new phenomenon; yet it is one that has not successfully been resolved over the past few years - although the industry might argue that great improvements have been made in the area (an example being the accelerated deployment of IPS over the more widely accepted IDS systems of the past, although I would argue that IPS deployments still block traffic in a limited fashion, sort of an IDS+ rather than a true IPS!).

 
 
12

Add comment

Post a Comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <a> <p> <span> <div> <h1> <h2> <h3> <h4> <h5> <h6> <img> <img /> <map> <area> <hr> <br> <br /> <ul> <ol> <li> <dl> <dt> <dd> <table> <tr> <td> <em> <b> <u> <i> <strong> <font> <del> <ins> <sub> <sup> <quote> <blockquote> <pre> <address> <code> <cite> <embed> <object> <strike> <caption>
  • Lines and paragraphs break automatically.
  • Use <!--pagebreak--> to create page breaks.

More information about formatting options

 

Comments

Comments

Dresses, evening, cocktail,

Dresses, evening, cocktail, prom dresses, formal gowns from eiDress. Homecoming dresses and bridesmaid.
Evening Dresses
Cocktail Dresses
Formal Gowns
Prom Dresses: Find Online fashionable prom dresses,homecoming dresses from top USA prom gowns designers,
Evening dresses, sexy Tops , casual dress ,sexy
Custom Dresses
Elegant couture designer evening gowns, sexy dresses, inexpensive on sale prom dresses,
bridesmaid dresses
Nationwide bridal salon offers bridal and wedding gowns, bridesmaid dresses,
flower girl dresses, tuxedos, and other special occasion apparel. Site includes a bridal
wedding dresses
designer wedding dress

Don Ed Hardy is an American

Don Ed Hardy is an American tattoo artist born in Iowa in 1945, and raised in Southern California.tiffany jewellery
ed hardy shoes
A pupil of Sailor Jerry, Hardy is recognized for incorporating Japanese tattoo aesthetic and technique into his work
ed hardy

our company was vested with

our company was vested with production authority of the U.S. National Football League (nfl jersey) in China. Therefore we are one of the largest nfl jerseys center in China and our products have been exported to Europe and America market for cheap nfl jerseys time.

第二の永久歯といわ

第二の永久歯といわれるインプラントですが、興味はあっても
インプラント治療に対して、 不安をお持ちの方がたくさんいらっしゃいます。

Information on Blogger

richard
Based in Hong Kong Richard Moss is a Chartered Engineer registered with the Engineering Council in the UK and member of the Institution of Engineering and Technology (CEng MIET) as well as the International Compliance Association (MICA). With 27 years experience in the communications industry, 17 of which have been spent in Information Security, Richard is the Managing Director at eBorders, a business solutions company enabling secure collaboration within, and between, enterprises, and former General Manager and Head of BT's Business Continuity, Security & Governance Practice in Asia Pacific.
leave a comment

knowledge_central_tab

 
 
Knowledge Central
Today's top security priorities
Attacks based on vulnerabilities in websites are skyrocketing, and not many solutions are available to protect organizations against them. How do you deal with this and other key security issues today?
Taking a holistic business-centric approach to security
Today’s CIOs face multiple challenges, including the need to innovate in an extremely competitive business climate, address highly dynamic regulatory and compliance challenges, speed ROI to counter shrinking IT budgets, and secure their organizations against a wide barrage of sophisticated threats.
 
 
 
UTM product offers Logansport Savings Bank superior protection
Astaro Security Gateway’s IPS was able to block attacks that other intrusion prevention systems (IPS) missed at Logansport Savings Bank.
Hong Leong Financial opts for Juniper Networks at new Malaysia head office, data center
Hong Leong Financial Group Berhad builds complete and seamless data center and office network infrastructure with Juniper switches, security devices and Junos software.