Video

June 18, 2021

Recognize, qualify and safely use all executable objects/applications everywhere: how does that work?

CIO of a STOXX company said: “von Neumann is to blame for everything”. This certainly means that the architecture used on almost all computers worldwide originates from Mr. von Neumann and initially makes no distinction between files with user data and files with executable programs. They are all in the same file system and the operating system will know what to do with them. In addition, Mr. Bruce Schneier, a veteran of global cyber security, gave a passionate speech at the Munich Cyber Security Conference, mcsc, in which he formulated that the added value of Internet downloads, mail attachments, USB and other mobile data carriers must be preserved and IT must offer solutions as to how these can be used “securely”.

A solution for the secure use of applications must therefore look into precisely these data streams in order to recognize all executable objects, then subject them to “qualification and authentication” in order to make them suitable for use or even prohibit them for standard use. There are already hurdles here, such as encrypted files that do not immediately reveal whether they contain executable code. In most cases, the user's knowledge is needed as a key.

However, analyzing these data streams is not enough. Standard applications come into the company differently. In the best case scenario, there is a test procedure in a physically separate environment in which the new applications are tested for their functionality and, of course, their security. Not every application must have its own security functions, but the existing infrastructure of security applications, such as anti-virus solutions, must be used reliably and not circumvented - not all applications do this. The presentation presents the fields of action that are necessary to use all applications securely.