
Our current security paradigms are almost entirely drawn from the technical work in the area in the last four decades. This legacy of protecting data and systems has provided a rich set of tools for preventing, discovering and recovering from security failures. As we have gotten better at detecting security incidents, whether they are successful or not, we have not seen an equivalent increase in our capacity for analyzing and tracing these abuses to their source. In fact, it is not uncommon for a large site to be able to detect many more intrusion attempts than it can analyze and trace in any timely fashion. In short, we are being out-scaled by the intrusion community. We need incident management tools that interoperate, scale, and decrease security investigator workload. Also, due to the multi-site (multi-country, multi-cultural, t ) nature of investigations, we need better ways for sites to communicate about security incidents, past and present. Secure software agents or other technologies are needed to allow the small number of qualified investigators to extend their reach to remote sites, and also to provide a mechanism for educating more investigators. This paper is an attempt to identify, at a minimum, some of the new technologies that we will need in order to address these issues. In some cases, we need refinements, or wider deployment of existing technologies. In other cases we need completely new tools and methods of working. This paper created quite a lively dbcussion at the workshop. It became obvious that, i f anything, the original paper was too cautious in some of its recommendations, and was not as aggressive in suggesting more radical new paradigms. Rather than re-write the paper based on the discussion, we decided to follow the excellent example o f Greenwald[1] and add an epilog that incorporates the discussion comments and our "second thoughts'" based on those comments.
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
