Unstructured Data: Threats You Cannot See

Every day, IT security teams are inundated with data, security events, network flows, configuration information, and so on, which then must be collected and analysed for potential vulnerabilities. Your team probably has a solid, established approach or even a documented strategy for doing this. If so, great. But is that enough?

Security teams need to take a cognitive approach to the increasing volumes of data flowing from sources they don't control.

The data collected by most security tools, such as firewalls and antivirus software, is structured, that is, organised in an easily searchable, relational database.

Structured data, however, amounts to only a small portion of a larger, more complicated puzzle. It's the remaining unstructured data that security teams struggle most to collect, analyse, and act upon, and the amount of unstructured data only continues to increase.

Think of how much security data flows from sources you don't control, including the massive swaths of unstructured data living on the Deep Web, from blogs, forums, or bookmarking sites.
 
This unorganised, often text-heavy data accounts for a majority of the Internet's data. IDG believes unstructured data is growing at the rate of 62% per year, and that by 2022, 93% of all data will be unstructured.

How can IT teams keep pace? The answer could lie in cognitive security, the use of big data platforms, data mining, AI, and machine learning to analyse raw data whether structured and unstructured.

But first, let's examine the problem.

Why It Matters

Understanding the magnitude of this issue requires examining the foundation of current security measures. Traditional security focuses on mitigating external threats, perimeter defenses to ward off the bad guys. As such, we often focus our security strategies on firewalls, antivirus software, and secure passwords.

Security innovation has almost always had this perimeter philosophy at its core. However, a myopic focus on perimeter protection severely limits the overall security strategy, potentially rendering it ineffective without complementary, proactive measures in place.

Consider the average IT organisation's reaction to the hundreds of thousands of daily security events. The process for today's security teams involves analysing data from antivirus software and firewalls, and then correlating that data to create a story, which in turn helps inform a solution.

In the process, security professionals are left with mountains of events to manually analyse and execute. Meanwhile, when they're busy responding to old threats, new threats continue to arise undetected. Consequently, the entire team finds itself fighting fires instead of solving or preventing problems. That doesn't leave much bandwidth for data aggregation and analysis.

Unstructured, Untold and Unknown

Next, let's think about how we, as IT professionals, share and consume security information, particularly during a major crisis. The current norm for security professionals is to update websites and social channels to explain how they've addressed a particular security issue and simply hope it reaches all relevant and necessary parties. Take, for example, this year's WannaCry attack.

The first real solution offered to organisations affected by WannaCry was explained via Twitter, by a user known as MalwareTech.

Although certainly helpful, social is by no means a perfect means of circulating widely sought, urgent information to security teams around the world.

Merely posting online assumes that in the middle of a major crisis, frantically busy security professionals are manually scouring the Internet for the information you're providing, something few people have time for in calmer times, let alone when the proverbial sky is falling.

Information sharing is critical to IT security, not only within individual organisations, but in the security industry as a whole. We rely on one another to share information about new and known threats, and often benefit from each other's knowledge and experience.

Unfortunately, the majority of information generated and shared by security professionals about breaches, threats, malware, etc., is unstructured, and thus much more difficult to unearth and apply in real time, particularly during critical security events that require immediate action.

How much time is lost and how much damage done, simply because we lack access to or awareness of viable solutions provided by our industry peers? Or because we lack a strategy for gathering and analysing the flood of unstructured data at our disposal? This is where cognitive security offers vital, immediate benefits.

Welcome to the Cognitive World  

A cognitive approach uses AI, data mining, and machine learning technologies to parse through thousands of security feeds and data sources, including the low-key, often invisible world of white- (and black-) hat bloggers and discussion forums, to aggregate and analyse unstructured and structured security data.

Meanwhile, a security professional works to perform predictive data analysis, ultimately training the system on best practices, organisational policies, and more.

Over time, the system begins to learn on its own, including how to prioritise events and recommend responses. While cognitive security cannot replace existing security tools, antivirus software, for instance, or intrusion prevention systems, the data generated can be plugged into traditional perimeter defenses. As a result, IT pros gain a better understanding of their data's meaning and how to convert insights into action.

Beyond the Perimeter

Unstructured data will only continue to proliferate. It's time to get ahead of it so that security teams can better locate analyse and respond to threats. That requires thinking beyond the perimeter and embracing security technologies that will bolster traditional defenses and provide a more proactive, intelligent security strategy.

Dark Reading:        Datamation

You Might Also Read: 

Transforming Your Database:

How To Keep Your Business Data Safe:

Get Your Data Strategy On Board:

 

« Poor North Korea Is A Cyber Superpower
AI: Experts Talk Ethical & Security Concerns »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

MobileIron

MobileIron

MobileIron provides EMM capabilities to IT organizations that need to secure mobile devices, applications and content.

ISO Quality Services Ltd

ISO Quality Services Ltd

ISO Quality Services is an independent organisation that specialises in the implementation, certification and continued auditing of ISO and BS EN Management Standards including ISO 27001..

Adeptis Group

Adeptis Group

Adeptis are experts in cyber security recruitment, providing bespoke staffing solutions to safeguard your organisation against ever-changing cyber threats.

Israel Aerospace Industries (IAI)

Israel Aerospace Industries (IAI)

IAI offers a holistic approach that provides defense forces, governments, critical infrastructures and large enterprises with end-to-end cyber security & monitoring tools.

Maritime Cybersecurity Center (MCC)

Maritime Cybersecurity Center (MCC)

Maritime Cybersecurity Center is a not-for-profit organization focused on regional cybersecurity excellence and readiness, with a special emphasis on the maritime community.

Langner

Langner

Langner is a software and consulting firm specialized in cyber security for critical infrastructure and large-scale manufacturing.

Uleska

Uleska

Uleska is a scalable platform that provides automated and continuous software security testing whilst translating cyber risk.

Aspisec

Aspisec

Aspisec is a cybersecurity company specialized in Firmware Security and Critical Infrastructure Protection.

Osirium

Osirium

The Osirium PxM Privileged Access Management platform addresses both security and compliance requirements by defining who gets access to what and when.

Nexum

Nexum

Nexum takes a comprehensive approach to security, from detecting and preventing network threats, to equipping you with the information, tools and training you need to effectively manage IT risk.

Business Resilience International Management (BRIM)

Business Resilience International Management (BRIM)

Business Resilience International Management (BRIM) is engaged by law enforcement in the UK and overseas to advise on establishing and developing Cyber Resilience Centres (CRCs) for business.

CleanCloud by SEK

CleanCloud by SEK

CleanCloud by SEK is a CSPM product focused on public cloud data protection and security regulations, with over 400 compliance checks for the market's leading frameworks and regulations.

WhiteJar

WhiteJar

WhiteJar offers an innovative approach to modern cybersecurity needs, empowering Ethical Hackers within its unique crowd platform.

Surefire Cyber

Surefire Cyber

Surefire Cyber delivers swift, strong response to cyber incidents such as ransomware, email compromise, malware, data theft, and other threats with end-to-end response capabilities.

Central Intelligence Agency (CIA)

Central Intelligence Agency (CIA)

The CIA is an independent agency responsible for providing national security intelligence to senior US policymakers. This includes cyber security related activities.

COGITANDA Dataprotect

COGITANDA Dataprotect

COGITANDA are a group of companies focused on dealing with cyber risks, managing them and insuring them.