3 ms·
I read this and my first thought is that when it comes to network security we're doing it all wrong. Every one of the mitigations relies on failable-by-design
by programd 3y ago
I read this and my first thought is that when it comes to network security we're doing it all wrong.
Every one of the mitigations relies on failable-by-design human beings to do a perfect job at closing every potential security hole. Often using obscure wizard level knowledge about the system they're working with.
Does anybody trust that ACLs will always be perfectly maintained? That credentials will always be kept up to date? that patch management will always be timely and comperhensive? You can try as hard as you want - or how much of a budget you have - but in real life you'll never patch all the potential holes. At any given time we - the royal organizational we - don't even know all the potential holes.
I think we need to treat network security like nuclear weapons. Networks need to be fail-safe. The reason nuclear weapons have many fail-safe features are because their history is rife with failures tracable to human error.
What does fail-safe even mean in network security? I have no idea but I think the question is worth asking. How do we remove humans out of the security loop? How do we make networks smarter and self securing and fail-safe?
In my (slightly dystopian) imagination the network needs to be some AI overlord model which controls it all and asks users in plain language what they want to do and decides what to allow based on the user's moral character. Then it uses its omniscient eye to surveil everything and shut down any transgressive actions.
Because clearly human beings are not up to this task.
But seriously is there any research on autonomous and self securing networks out there?