Security Power Tools
by Bryan Burns, Dave Killion, Nicolas Beauchesne, Eric Moret, Julien Sobrier, Michael Lynn, Eric Markham, Chris Iezzoni, Philippe Biondi, Jennifer Stisa Granick, Steve Manzuik, Paul Guersch
Foreword
When I first started working in information security more than 15 years ago, it was a very different field than the one we are in today. Back then, the emphasis was security primarily through network-based access lists, strong passwords, and hardened hosts. The concept of distributed systems had just started emerging, and user-based networks were made of either dumb terminals or very rudimentary network operating systems. The home environment was not network-oriented—certainly not nearly as much as it is today. There was only so much you could do as an attacker (or victim) at 1,200 or 2,400 baud.
Attack tools and defense tools were also very rudimentary. The most advanced security-related industry was—and to a certain extent, still is—the Virus/Anti-Virus industry. Can you remember the DOS Ping Pong virus from 1988? Forensics was also in its infancy and was really only limited to the high-end companies and government agencies.
In a very simple sense, security was defined primarily in a silo-like approach and achieved through air-gaps. Network connectivity, limited as it was, had tight access controls. Consequently, the network was not considered as the primary vector for attack.
Now, in what seems to be a blink of an eye, the security landscape is completely different. The change was gradual at first and increased at a rate similar to that of the growth of the Internet. The adoption of the Internet and TCP/IP as its common protocol had undoubtedly served as the primary catalyst ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access