The Value of Large-Scale Data Collection and Analysis: BotNet Prevention

At today’s White House event on Stopping Botnets, Michael DeCesare, Co-President of McAfee, made a compelling case for the value of large-scale data analysis in botnet prevention.

“We’re often asked what can be done to combat botnets, and here is the basic answer: We need to make sure that individual machines are not infected in the first place. We need to do this by delivering security faster than our adversaries deliver malware…Indeed, having real-time visibility into emerging threats and a comprehensive view across the threat landscape is a powerful means of defeating botnets, which can multiply extremely quickly. One robust technology that enables this real-time global visibility is called Global Threat Intelligence. With Global Threat Intelligence, millions of sensors scan the Internet across the globe and feedback real-time data on botnets and other threats. This data is instantaneously correlated and fed back into security products, delivering real-time protection to customers, as we identify and block the malicious files, IPs and URLs used by the botnets. With even more threat data from more security organizations fed into this network, customers would get even more comprehensive visibility into the quickly changing patterns of botnet infestations and could take immediate steps to counter them.”

Mr. DeCesare’s comment at the White House today echoes what all security professionals know: constant monitoring of the Internet by security firms and real-time analysis of the vast quantities of data collected is absolutely vital to the fight against infected computers and other cybersecurity threats.

Other companies also collect and analyze Internet data for the purpose of cybersecurity threat detection. Google recently launched a notification effort for users of computers and routers infected with the DNSChanger malware. Users will see a message at the top of the Google search results page. Without the compilation and analysis of vast amounts of Internet information such a notification project could not even get off the ground.

The problem is enormous. According to McAfee’s latest quarterly report, more than 5 million systems were infected with botnets per month between January and March of 2012. The collection and analysis of massive amounts of Internet data for security threats cannot by itself solve this worldwide collective problem. But without it efforts to reduce the problem will surely fail.

At the White House meeting today, speakers emphasized the need for public private partnerships, collaboration across industry, the need for all agents in the ecosystem to do their part, the importance of the government as a convener of collective effort. While all this is important and can be done with additional regulation, the domestic and international policy space must be large enough to accommodate the needs of security firms to collect and analyze large amounts of Internet data.


Mark MacCarthy, Vice President, Public Policy at SIIA, directs SIIA’s public policy initiatives in the areas of intellectual property enforcement, information privacy, cybersecurity, cloud computing and the promotion of educational technology.

Forced Localization: The New Protectionism

What do the following examples have in common?

  • In 2009, China proposed an indigenous innovation policy that would have explicitly restricted government contracts to goods whose embodied intellectual property was domestically owned.
  • In 2010, Norway ruled that cities could not use cloud computing services unless the servers were located domestically. Denmark followed suit in 2011.
  • In 2011, Kazakhstan attempted to require all .kz domains to operate on domestic servers.
  • In 2012, India proposed a requirement that government agencies purchase electronic goods and services with 30% local content.

These cases are examples of required localization: governments attempt to restrict the sale of goods and services within their territory to those which have been produced locally. The localization can be in terms of embodied intellectual property rights, manufacturing facilities, or facilities providing cloud computing services.

Governments cite national security concerns, or consumer protection issues or privacy and government access worries when imposing these restrictions. From a trade and economic point of view, however, they increase economic nationalism at the expense international trade.

What seemed like a series of isolated incidents now seems to be a trend, which if left unchecked, could seriously undermine the goal of increasing the flow of goods and services across borders. The 2012 Special 301 Report (p. 18) and the 2012 Section 1377 telecom trade report document the extent to which these localization initiatives could hinder bi-lateral, regional and global economic integration.

SIIA and other worldwide businesses and trade associations are seeking an effective response to the growing threat of a new protectionism based on localization initiatives.

Two principals that are gaining wide currency among industry and NGOs stand in stark opposition to this new protectionism. These principles are embodied in the agreement between the Office of the United States Trade Representative and the European Commission on a set of trade-related principles for information and communication technology (ICT) services:

  • Cross-Border Information Flows: Governments should not prevent service suppliers of other countries, or customers of those suppliers, from electronically transferring information internally or across borders, accessing publicly available information, or accessing their own information stored in other countries.
  • Local Infrastructure: Governments should not require ICT service suppliers to use local infrastructure, or establish a local presence, as a condition of supplying services. In addition, governments should not give priority or preferential treatment to national suppliers of ICT services in the use of local infrastructure, national spectrum, or orbital resources.

Since this agreement was made in April 2011, several intergovernmental, industry and non-governmental civil society groups have endorsed these principles, including SIIA, the Aspen Institute, the Organization for Economic Cooperation and Development (OECD), and a group of trade associations and companies lead by the National Foreign Trade Council.

There is momentum in both the private sector and the U.S. government to take on this issue in the strongest possible way. The US government is ramping up its efforts to move these principles forward. For instance, they are embodied in the electronic commerce chapter of the U.S. proposal in the Trans-Pacific Partnership (TPP) trade negotiations.

SIIA urges that this issue be moved to the highest levels of U.S. government decision making and raised in all significant international venues including economic gatherings of heads of state such as the recent G-8 meeting, meetings of the ministers of the Asia Pacific Economic Cooperation group, committees of the World Trade Organization, OECD working groups and trade discussions such as TPP. Only a sustained, high-level commitment from the U. S. government will turn the tide against this new form of economic nationalism.


Mark MacCarthy, Vice President, Public Policy at SIIA, directs SIIA’s public policy initiatives in the areas of intellectual property enforcement, information privacy, cybersecurity, cloud computing and the promotion of educational technology.

Gearing up for DataContent: Data Insight from Russ Perkins

We are excited about our partnership with the InfoCommerce Group to produce DataContent 2012, coming up October 9-11 in Philadephia. The conference will focus on discovering the next big thing in publishing: The intersection of Data, Community and Markets at DataContent 2012.

If you don’t know him, Russ Perkins the founder of InfoCommerce Group is one of the more thoughtful individuals in our industry on all things data. As we lead up to the conference, we will be highlighting posts from his blog which focus on the issues and topics we will be discussing at DataContent 2012. Enjoy!

To Find Gold, Dig Deep
The travails of the traditional yellow pages industry are serious, with no end in sight. There are some interesting lessons and insights that can be drawn from the remarkable and relatively rapid meltdown of this seemingly bulletproof and impossibly profitable segment of the data publishing industry. Read more

To Market, To Market
I have long been interested in the fine line that often divides marketplaces and buying guides, a topic that I am sure keeps all of us up at night at least every so often. A string of recent new website announcements has me back thinking about this again. Read more

If the Pipe Fits
Clay Shirky, the well-known professor at the renowned Interactive Telecommunications Program at NYU, in a recent interview gave this summation of the publishing industry: Publishing is not evolving. Publishing is going away. Because the word “publishing” means a cadre of professionals who are taking on the incredible difficulty and complexity and expense of making something public. That’s not a job anymore. That’s a button Read more

Tracking Error

A new report released by the Federal Trade Commission this week makes a strong case for increased online consumer privacy protection. This report builds on the “Consumer Data Privacy Bill of Rights” issued by the White House last month. The White House document is largely aspirational, setting general goals such as “Consumers have a right to secure the responsible handling of personal data.” The FTC report is far more specific, and includes an endorsement of a “do not track” option for consumers, along with a recommendation that “data brokers” be required to allow consumers to inspect the data that have been collected about them. Read more

Made to Measure
It’s been well-known for many years that Google periodically alters its search algorithms. These changes are made for two reasons: to improve the quality of search results, and to push back against those sites that it believes are gaming the system. To Google, gaming the system means that a website operator has divined in part how the Google search algorithm prioritizes results, and uses that knowledge to improve its own search results rankings. Read more

Dead Letter Office
I got a call from the new postmaster at our local post office the other day. Her staff had apparently discovered a sizable stack of year-old nixies from our conference promotions, and wanted to know if I would still be interested in them, for the requisite fee of course. After ruefully noting that the Postal Service is, “really hurting for money,” she pretty much offered to drop them off right away if we would just have a check waiting. Read more


Jennifer HansenJennifer Hansen is Program Manager for the SIIA Content Division.

This week in the Federal Cloud: April 30-May 4

There were a couple of expected but relatively big announcements around cloud in the federal government this week. First and foremost was the issuance of the Federal IT Shared Services Strategy on May 2nd by Federal CIO, Steve VanRoekel. The Shared Services Strategy, like the Shared-First Initiative before it, seeks to reduce the overall cost of government by eliminating duplicative IT and streamlining operations, while moving agencies to shared platforms for commodity IT (like email and storage), support IT (HR and financial management) and eventually mission IT (performance management). Under the plan, agencies have until August 31 to create their shared services roadmaps.

Also this week, we heard the first definitive date for the launching of the FedRAMP Initial Operational Capabilities (IOC), as it was publically announced that June 6th would be the date. This means, according to the FedRAMP timeline that we will see an operational program, with limited scope. We should also expect to see progress toward the official authorization/certification of CSPs, an updated Concept of Operations, and updated continuous monitoring guidance. It also means we will have to have approved third party assessors (3PAOs) in the very near term as they play an integral part in certifying CSPs. It was originally expected that we would have approved 3PAOs in April, but that date was later pushed to early May.

In other cloud news:


Michael Hettinger is VP for the Public Sector Innovation Group (PSIG) at SIIA. Follow his PSIG tweets at @SIIAPSIG.

SIIA Welcomes Aspen Insitute’s Cross Border Data Principles

Today the Aspen Institute released its first report on its IDEA project. It is a first-rate summary of Internet freedom issues and a call to action to implement principles designed to keep the Internet an open, vibrant platform for free expression and economic activity. In particular, the report endorses the cross-border data flow principles that SIIA has been supporting:

Free Flow of Information Principles
1. Governments should allow the free flow of information globally.
a. Allowing information to move freely and be stored globally permits the capture of economies of scale and makes it possible to reap the economic benefits associated with the Internet.
2. Governments should not artificially or geographically restrict facilities and information storage.
a. Artificially limiting the location of data geographically reduces the resiliency of the Internet and undermines its stability.
b. Governments should not require that facilities or information be located in a specific country or region.

SIIA member companies rely on the Internet as a platform for free expression, the distribution of content protection by strong intellectual property rules, electronic commerce, cloud computing and a unprecedented range of economic and cultural activities. SIIA is committed to maintaining the openness and viability of a free Internet. SIIA congratulates the Aspen Institute for putting together these principles and for carrying forward this important work. We look forward to working with policy makers to implement them.


Mark MacCarthy, Vice President, Public Policy at SIIA, directs SIIA’s public policy initiatives in the areas of intellectual property enforcement, information privacy, cybersecurity, cloud computing and the promotion of educational technology.

SIIA Member Spotlight: Crowd Fusion, The Agile Data Model

I had a chance to talk with Crowd Fusion’s CEO Brian Alvey to learn how Crowd Fusion uses an Agile Data Model to shake up the market and get customer’s sites and apps to market quickly and efficiently. Brian is also speaking at Content VIA Platforms  on May 10 in San Francisco where he will share experiences and war stories gained working on behalf of major publishers interacting with Apple, Facebook, Android and other platforms.

_____________________

Kathy: Hi Brian, tell us about your Crowd Fusion, what you do?

Brian Alvey, CEO, Crowd Fusion

Brian: Crowd Fusion is high-end multi-platform publishing software. These days publishers need to do more than ever, but they need to do it with tighter budgets. Crowd Fusion makes it easy to publish the same content to all the latest platforms and devices — all without expanding their production teams.

 

Kathy: Who are your customers?

Brian: Publishers and large brands. Our platform has been used by TMZ, Warner Bros/Telepictures, Myspace, The Daily, Essence and Best Buy’s Tecca.com.

 

Kathy: Tell is what is unique about Crowd Fusion?

Brian: We invented an agile data model that lets us and our customers get sites and apps to market faster and iterate more frequently.

 

Kathy: What are some unique challenges you’ve experienced at Crowd Fusion?

Brian: We work with high-end publishers and big media brands, so we’ve had to solve for 3 kinds of scale: traffic, content and workflow. One of our strengths is that our platform is cloud-native. Not only can you manage content in our CMS, you can also launch new servers and coordinate infrastructure all using a web browser — even on an iPad.

 

Kathy: What do you see as the biggest trends in the industry the next 12-18 months?

Brian: Tablet publishing. Multi-platform publishing. Mobile commerce.

 

Kathy:  What do you hope to get out of your SIIA membership?

Brian: Meeting people who face the same publishing and technology challenges we deal with.

 

Kathy: One thing the industry doesn’t know about you or others in your company?

Brian: We are a completely virtual company. We have no real office space. Our team works from home, Starbucks, customer offices, grandma’s house, wherever. We have 30 people and they are spread out across 18 U.S. states, Canada, New Zealand, Australia and Italy.

 

Kathy: Whats the best way to contact you?

Brian: On Twitter: @crowdfusion or @brianalvey for me, Or by email: brian@crowdfusion.com.


Kathy Greenler Sexton is Vice President

SIIA Joins Call for U.S. Action to Promote Cross-Border Data Flows

Today, SIIA endorsed principles for promoting cross-border data flows. SIIA joined with the National Foreign Trade Council and other trade associations representing a broad range of U.S. companies in supporting this major business priority. The principles seek to bring to bear the resources of trade law to promote the global flow of data across national boundaries.

American businesses are being harmed by the many barriers inhibiting the flow of data across international borders. Many countries want to impose restrictions on the transfer of data, while others seek to inhibit access by companies or individuals to lawfully available information located outside their jurisdiction. Still others demand that companies provide computing or information services through domestic facilities, in effect requiring localization of plant and equipment.

These practices inhibit economic growth, trade in services, innovation and the free expression of ideas in the global economy. The principles endorsed by SIIA underscore the significance of the problem and encourage the U.S. government to seek remedies in a variety of international organizations. The forums where this problem can be addressed include the World Trade Organization (WTO), Asia Pacific Economic Cooperation (APEC) forum, OECD, and regional trade negotiations such as the Trans-Pacific Partnership.

SIIA’s goal is to have the U.S. government treat these practices as violations of current international rules concerning digital goods, services and information. By joining with the rest of the U.S. business community in endorsing these principles, SIIA is urging the U.S. government to identify these practices as violations of international rules and resolve them through WTO or bilateral consultations.

The principles also address the important issues of intellectual property protection and limitations on liability for internet intermediaries. But rather than reinventing the wheel, the principles reference the approach contained in the Communiqué on Principles for Internet Policymaking related to intellectual property protection and limiting intermediary liability developed by the Organization for Economic Cooperation and Development (OECD) in June 2011.


Mark MacCarthy, Vice President, Public Policy at SIIA, directs SIIA’s public policy initiatives in the areas of intellectual property enforcement, information privacy, cybersecurity, cloud computing and the promotion of educational technology.