  • "If we can't see the attack, we can't stop it"...
    Sometimes it helps to state the obvious. Here's another way to think about it. "I can't share it if I didn't 'see' it in the first place." I have no argument with General Alexander's plea for greater information sharing, but it presumes that an organization "saw" an attack in the first place. All too often organizations are blind. They may have gotten an increase in IPS hits, but nothing specific. Perhaps their log files showed some increased activity, but again, nothing precise. Defensive systems like firewalls, IPS and malware analysis are all important, but none of them give you visibility into an active, in-progress attack. A new approach is needed. You must assume you've been breached and you will be again. Now you need the tools to identify the who, what and where of the attack. We'll continue to talk about this idea and more on our blog. Check us out at http://bit.ly/GVqaZP John Worrall CounterTack (www.CounterTack.com)
