“We didn’t know what we were going to get back–what we wanted was to objectively look at the losses caused by attacks,” said Dirck Schou, senior director of security solutions for Phoenix Technologies.
Device identification–or attestation–is a central capability of the hardware component of the trusted computing model, known as the Trusted Platform Module (TPM). Phoenix Technologies, which makes one version of the basic input/output system (BIOS) that allows operating systems to control a computer’s hardware, has created products that work with the TPM to identify the computer systems on a corporate network, but has also created products that can also work without the specialized hardware, Schou said.
Yet, more and more personal computers and laptop systems are shipped with the technology already on board. About 20 million computers, most of them laptops, shipped with the Trusted Platform Module in 2005, according to the Trusted Computing Group, the industry association that has created the hardware specification.
“For example, IP addresses could be used to authenticate some machines–and are probably sufficient under some threat models and policies to make the distinction between ‘sanctioned’ and ‘unsanctioned’ machines.”
The study found that the industries hardest hit by attacks were government, retail and high-tech, and that 78 percent of attackers used a home computer to do the deed, but that leaves a lot of questions unanswered, Schoen said.
Companies should ask whether they can reliably distinguish between sanctioned and unsanctioned computers on the network, whether employees working from home on unsanctioned computers would be allowed to access the network, and whether the technology could be deployed pervasively enough to matter. “We would need to know that the unsanctioned computers were actually necessary to the commission of these crimes, and that the crimes could not have been committed without using the unsanctioned computers,” Schoen stated in the e-mail interview.
http://www.securityfocus.com/news/11410