<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Research Papers - Securosis</title><link>https://securosis.com/research/papers/</link><description>Recent posts tagged Research Papers from Securosis</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 24 Jul 2026 20:03:35 +0000</lastBuildDate><atom:link href="https://securosis.com/research/papers/" rel="self" type="application/rss+xml"/><item><title>The Universal Cloud Threat Model</title><link>https://securosis.com/research/papers/the-universal-cloud-threat-model-for-cloud-native-security/</link><pubDate>Tue, 23 Apr 2024 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/the-universal-cloud-threat-model-for-cloud-native-security/</guid><description>
&lt;p&gt;The Universal Cloud Threat Model is a collaboration between PrimeHarbor Technologies and Securosis. It is a &lt;em&gt;cloud-centric&lt;/em&gt; threat model to help organizations focus security efforts on the most-common attacks most organizations will experience. The UCTM is designed as an adjunct to other threat models. From the introduction:&lt;/p&gt;</description></item><item><title>Modernizing SecOps for Cloud</title><link>https://securosis.com/research/papers/modernizing-secops-for-cloud/</link><pubDate>Fri, 23 Feb 2024 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/modernizing-secops-for-cloud/</guid><description>
&lt;p&gt;Security Operations, SecOps for short, has been one of the more difficult security domains to modernize for cloud. It requires a combination of new subject matter expertise, new technologies, process updates, and even a slightly different mindset. Cloud impacts SecOps in ways both obvious and subtle, and because most organizations still have datacenters and offices, teams need to add new skills and update operations while still supporting everything already on their plates. It’s a daunting challenge, but one that can be made much easier to tackle by distilling down, into the core of how cloud changes things, and taking lessons from the successes of early adopters.&lt;/p&gt;</description></item><item><title>Data Security in the SaaS Age</title><link>https://securosis.com/research/papers/data-security-in-the-saas-age/</link><pubDate>Sat, 26 Jun 2021 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/data-security-in-the-saas-age/</guid><description>
&lt;p&gt;Data security remains elusive. You can think of it as something of a holy grail. We’ve been espousing the idea of data-centric security for years, focusing on protecting the data, so you can worry less about securing devices, networks, and associated infrastructure. As with most big ideas, it seemed like a good idea at the time.&lt;/p&gt;</description></item><item><title>Securing APIs: The New Application Attack Surface</title><link>https://securosis.com/research/papers/securing-apis-the-new-application-attack-surface-2/</link><pubDate>Sat, 26 Jun 2021 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/securing-apis-the-new-application-attack-surface-2/</guid><description>
&lt;p&gt;The way applications are built, deployed, and maintained in most organizations is being disrupted. Macro changes include the ongoing cloud migration disrupting the tech stack, new application design patterns bringing microservices to the forefront, and DevOps changing dev/release practices. As we’ve been slowly navigating this sea change, the common thread across these changes is increasing reliance on Application Programming Interfaces (APIs).&lt;/p&gt;</description></item><item><title>Security Hygiene: The First Line of Security</title><link>https://securosis.com/research/papers/security-hygiene-the-first-line-of-security/</link><pubDate>Sat, 26 Jun 2021 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/security-hygiene-the-first-line-of-security/</guid><description>
&lt;p&gt;After many decades as security professionals, it’s depressing to keep seeing the same issues and mistakes. It feels like we’re stuck in hacker Groundhog Day. Get up, clean up the mistakes made by users or administrators, handle a new attack, and fill out compliance reports, only to have to do it all over again the next day.&lt;/p&gt;</description></item><item><title>Enterprise DevSecOps</title><link>https://securosis.com/research/papers/enterprise-devsecops-2/</link><pubDate>Tue, 10 Dec 2019 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/enterprise-devsecops-2/</guid><description>
&lt;p&gt;This is our latest iteration on how to build a DevSecOps program. This research paper is the result of hundreds of hours of research and several hundred conversations with Fortune 1000 firms on the challenges companies face and the problems they are most interested in tackling. We go deep into covering all phases and facets of secure application development. And we did a complete reversal on the naming convention; from DevOps to DevSecOps. It became obvious during our calls that despite the idealism involved with leaving ‘Sec’ out of the title, security is getting short shifted and it needs to be called out.&lt;/p&gt;</description></item><item><title>Understanding and Selecting RASP 2019 Research Paper</title><link>https://securosis.com/research/papers/understanding-and-selecting-rasp-2019-research-paper-2/</link><pubDate>Tue, 19 Nov 2019 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/understanding-and-selecting-rasp-2019-research-paper-2/</guid><description>
&lt;p&gt;So what is RASP? Runtime Application Self-Protection (RASP) is an application security technology which embeds into an application or application runtime environment, examining requests at the application layer to detect attacks and misuse in real time. RASP functions in the application context, which enables it to monitor security – and apply controls – very precisely. This means better detection because you see what the application is being asked to do, and can also offer better performance, as you only need to check the relevant subset of policies for each request.&lt;/p&gt;</description></item><item><title>Security Monitoring State of the Union</title><link>https://securosis.com/research/papers/security-monitoring-state-of-the-union/</link><pubDate>Mon, 27 May 2019 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/security-monitoring-state-of-the-union/</guid><description>
&lt;p&gt;A few years ago we wrote a paper called &lt;em&gt;Security Monitoring Team of Rivals&lt;/em&gt; , which really highlighted the reality that you had to make your SIEM and security analytics products work together. The analytics platforms could not provide the broader capabilities delivered by the SIEM, especially in the areas of compliance and incident response. And the SIEM wasn’t really built to do higher end analytics, and it showed when trying to do anything but fairly simple correlation.&lt;/p&gt;</description></item><item><title>Multi-Cloud Key Management 2019</title><link>https://securosis.com/research/papers/multi-cloud-key-management-2019/</link><pubDate>Thu, 16 May 2019 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/multi-cloud-key-management-2019/</guid><description>
&lt;p&gt;Discussion on multi-cloud strategies is atop the list of inbound questions customer ask us. “How do you architect applications and what technologies will promote a cloud neutral approach?” is what is commonly asked, and all have a fear of vendor lock-in. As such, they want critical security controls to be under &lt;em&gt;their&lt;/em&gt; control. And given most customers worry over control of encryption keys, key management is always a major issue. As such, we are re-launching our research work on multi-cloud key management. Infrastructure as a Service entails handing over some security and operational control to the service provider. But responsibility for your data security does go along with it. Your provider ensures compute, storage, and networking components are secure from external attackers and other tenants, but &lt;em&gt;you&lt;/em&gt; must protect your data and application access to it. That means you need to control the elements of the cloud that related to data access and security, to avoid any possibility of your cloud vendor(s) viewing it.&lt;/p&gt;</description></item><item><title>Making an Impact with Security Awareness Training</title><link>https://securosis.com/research/papers/making-an-impact-with-security-awareness-training/</link><pubDate>Sat, 29 Dec 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/making-an-impact-with-security-awareness-training/</guid><description>
&lt;p&gt;If you want your organization to take security awareness training seriously, you need to plan for that. If you don’t know what success looks like you are unlikely to get there. To define success you need a firm understanding of why the organization needs awareness training. We are talking about communicating business justification for security awareness training, and more importantly what results you expect from your organization’s investment of time and resources.&lt;/p&gt;</description></item><item><title>Scaling Network Security</title><link>https://securosis.com/research/papers/scaling-network-security-2/</link><pubDate>Sat, 29 Dec 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/scaling-network-security-2/</guid><description>
&lt;p&gt;Existing network security architectures, based mostly on preventing attacks from external adversaries, don’t reflect the changing dynamics of enterprise networks. With business partners and other trusted parties needing more access to corporate data and the encapsulation of most application traffic in standard protocols (Port 80 and 443), digging a moat around your corporate network no longer provides the protection your organization needs. Additionally, network speeds continue to increase putting a strain on inline network security controls that much scale at the same rate as the networks.&lt;/p&gt;</description></item><item><title>Evolving to Security Decision Support</title><link>https://securosis.com/research/papers/evolving-to-security-decision-support-2/</link><pubDate>Fri, 01 Jun 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/evolving-to-security-decision-support-2/</guid><description>
&lt;p&gt;Not that it was ever really easy, but at least you used to know what tactics adversaries were using, and had a general idea of where they would end up, because you knew where your important data was, and which (single) type of device normally accessed it: the PC. It’s hard to believe we now long for the days of early PCs and centralized data repositories. Given the changes in the attack surface and capabilities of adversaries, you need a better way to assess your organization’s security posture, detect attacks, and determine applicable methods to work around and eventually remediate exposures in your environment.&lt;/p&gt;</description></item><item><title>Complete Guide to Enterprise Container Security</title><link>https://securosis.com/research/papers/complete-guide-to-enterprise-container-security-2/</link><pubDate>Mon, 02 Apr 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/complete-guide-to-enterprise-container-security-2/</guid><description>
&lt;p&gt;Our newest paper, A Complete Guide to Enterprise Container Security, is a full update of our previous research on container security. A lot has happened over the last 18 months, which prompted a significant rewrite of our original content. As more organizations accept that containers are now the common media for applications, the platform focus is shifting to containers, with steps taken at each stage of the container lifecycle to ensure what actually goes into production is fully tested.&lt;/p&gt;</description></item><item><title>The Future of Security Operations</title><link>https://securosis.com/research/papers/the-future-of-security-operations-2/</link><pubDate>Fri, 23 Mar 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/the-future-of-security-operations-2/</guid><description>
&lt;p&gt;Security teams are behind the 8 ball. It’s not like the infrastructure is getting less complicated. Or additional resources and personnel are dropping from the sky to save the day. Given that traditional security operations approaches will not scale to meet the requirements of protecting data in today’s complicated and increasingly cloud-based architectures, what to do? Well, we need to think differently.&lt;/p&gt;</description></item><item><title>Understanding Secrets Management</title><link>https://securosis.com/research/papers/understanding-secrets-management-2/</link><pubDate>Tue, 02 Jan 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/understanding-secrets-management-2/</guid><description>
&lt;p&gt;If you’ve worked in IT or development you have seen it before: user names and passwords sitting in a file. When your database starts up, or when you run an automation script, it grabs the credentials it needs to function. The problem is obvious: admins and attackers alike know this common practice, and they both know where to look for easy access to applications and services.&lt;/p&gt;</description></item><item><title>Understanding and Selecting a DLP Solution v3</title><link>https://securosis.com/research/papers/understanding-and-selecting-a-dlp-solution-v3-2/</link><pubDate>Sat, 30 Dec 2017 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/understanding-and-selecting-a-dlp-solution-v3-2/</guid><description>
&lt;p&gt;Selecting DLP technology can still be very confusing, as various aspects of DLP have appeared in a variety of other product categories as value-add features, blurring the lines between purpose-built DLP solutions and traditional security controls, including next-generation firewalls and email security gateways. Meanwhile purpose-built DLP tools continue to evolve – expanding coverage, features, and capabilities to address advanced and innovative means of exfiltrating data.&lt;/p&gt;</description></item><item><title>Dynamic Security Asssessment</title><link>https://securosis.com/research/papers/dynamic-security-asssessment/</link><pubDate>Sun, 17 Dec 2017 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/dynamic-security-asssessment/</guid><description>
&lt;p&gt;We have been fans of testing the security of infrastructure and applications – at least as long as we have been researching security. As useful as it is for understanding which devices and applications are vulnerable, a simple scan provides limited information. Penetration tests are useful because they provide a sense of what is really at risk. But a pen test is resource-intensive and expensive – especially if you use an external testing firm. And the results characterize your environment at a single point in time. As soon as you blink your environment has changed, and the validity of your findings starts to degrade.&lt;/p&gt;</description></item><item><title>Endpoint Advanced Protection</title><link>https://securosis.com/research/papers/endpoint-advanced-protection-2/</link><pubDate>Thu, 09 Nov 2017 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/endpoint-advanced-protection-2/</guid><description>
&lt;p&gt;Innovation comes and goes in security. Back in 2007 network security had been stagnant for more than a few years. It was the same old same old. Firewall does this. IPS does that. Web proxy does a third thing. None of them did their jobs particularly well, all struggling to keep up with attacks encapsulated in common protocols. Then the next generation firewall emerged, and it turned out that regardless of what it was called, it was more than a firewall. It was the evolution of the network security gateway.&lt;/p&gt;</description></item><item><title>Intro to Threat Operations</title><link>https://securosis.com/research/papers/intro-to-threat-operations/</link><pubDate>Mon, 06 Nov 2017 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/intro-to-threat-operations/</guid><description>
&lt;p&gt;Can you really ‘manage’ threats? Is that even a worthwhile goal? And how do you even define a threat? We have seen better descriptions of how adversaries operate by abstracting multiple attacks/threats into a campaign, capturing a set of interrelated attacks with a common mission. A campaign is a better way to think about how you are being attacked than the piecemeal approach of treating every attack as an independent event and defaulting to the traditional threat management cycle: Prevent (good luck!), Detect, Investigate, and Remediate.&lt;/p&gt;</description></item><item><title>Multi-cloud Key Management</title><link>https://securosis.com/research/papers/multi-cloud-key-management/</link><pubDate>Wed, 24 May 2017 00:00:00 +0000</pubDate><guid>https://securosis.com/research/papers/multi-cloud-key-management/</guid><description>
&lt;p&gt;We are proud to announce the launch of our newest research paper, on multi-cloud key management, covering how to tackle data security and compliance issues in diverse cloud computing environments. Infrastructure as a Service entails handing over ownership and operational control of IT infrastructure to a third party. But responsibility for data security cannot go along with it. Your provider ensures compute, storage, and networking components are secure from external attackers and other tenants, but &lt;em&gt;you&lt;/em&gt; must protect your data and application access to it. Some of you trust your cloud providers, while others do not. Or you might trust one cloud service but not others. Regardless, to maintain control of your data you must engineer cloud security controls to ensure compliance with internal security requirements, as well as regulatory and contractual obligations. That means you need to control the elements of the cloud that related to data access and security, to avoid any possibility of your cloud vendor(s) viewing it.&lt;/p&gt;</description></item></channel></rss>