UPDATED 16:52 EDT / AUGUST 04 2015

NEWS

Fighting fire with fire: Anonymous security net targets enterprises

Paul Kurtz, TruSTARPaul Kurtz believes US enterprises have a fundamental disadvantage in fighting cyber attacks: The bad guys are cooperating with each other while the good guys work alone.

Concerns about government regulation, bad publicity and intellectual property theft prevent organizations from telling anyone outside their four walls about security threats they face, said Kurtz (right), former cybersecurity advisor to the White House under Presidents Clinton and Bush and director of counterterrorism for the National Security Council. The result: victims fight attackers with one hand tied behind their backs. “The paradigm of each of us trying to defend ourselves must change,” he said.

Kurtz is trying to do something about it. He’s teamed up with former eBay, Inc. Chief Information Security Officer Dave Cullinane to launch TruSTAR Technology, LLC, a SaaS platform which they describe as the industry’s first global anonymous cyber incident-sharing platform.

Kurtz, who left the government in 2003 after nearly 20 years working with weaponry, counterterrorism and cyber security, said he’s long been both fascinated and frustrated by the fact that cybercriminals freely share their techniques with each other, reasoning that opportunity is virtually limitless and more information benefits everyone.

Not so within corporations, however. Government-regulated entities like banks and securities firms, in particular, “say publicly they’re sharing security information, but privately they’ll tell you it’s really a mess,” he said. “That’s because if you’re a regulated entity, you don’t want the government to regulate you more.” So you stay quiet and cover your losses. The result is that the same exploits are targeted again and again by criminals, with predictable success.

Corporate behavior is unlikely to change, so TruSTAR provides the guaranteed anonymity that Kurtz believes is essential to getting businesses to crank open the lid on information.

Assuring anonymity without undermining credibility is a tricky task. The company is using a patent-pending anonymous authentication algorithm in which members share just enough information about themselves with the community to validate that they belong there while TruSTAR shares just enough information with them to verify that they aren’t an imposter.

Prospective members must provide a Dun & Bradstreet number and go through a credit check and approval process. Vetting is an ongoing process.

When a members share information about a new attack, it’s immediately checked against an incident database. “We can find others who have experienced the same pain and correlate with ongoing attacks,” Kurtz said. Once members began collaborating with each other, they can choose to reveal their identities or stay anonymous. However, every new incident report is filed anonymously.

TruSTAR is strictly for corporate customers. “We are not a sharing mechanism for white hat hackers. We are for enterprises,” Kurtz said. About a dozen Fortune 500 companies have joined so far.

The services carries a membership fee, but Kurtz described it as “affordable. Won’t want to charge people for giving up their secrets,” he added.


Since you’re here …

… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.

If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.