Juniper's "device fingerprinting" security technology gets mixed reviews

Detection and blocking of security threats against organizations often is done through IP address-based methods and reputation services, but Juniper this week launched an effort to encourage security managers to abandon IP-based detection in favor of the "device fingerprinting" its security gear now supports to pinpoint devices used in online attacks. The idea is getting mixed reviews so far.

Juniper's device fingerprinting pinpoints attacks from specific devices and identifies them in a way that can be disseminated through its Junos Spotlight Secure global attacker database and shared among Juniper customers where this threat intelligence can be put to use in Juniper security products that guard web applications and other gateways.

Juniper customers Forbes and Revlon backed the approach in public statements made this week. "Current protections need to evolve beyond IP-based blocking to definitive attack prevention and we see Juniper's new products as a step in the right direction," said David Giambruno, senior vice president and CIO at Revlon.

[Background: Juniper security products use "device fingerprints" to way to detect, block attacks]

[NEWS: Stuxnet was attacking Iran's nuke program a year earlier than thought

The idea of pinpointing devices known to be used in attacks and automatically detecting and blocking them is so compelling, that Art Coviello, executive chair of RSA, the security division of EMC, alluded to the Juniper announcement during his keynote yesterday at the RSA Conference, saying RSA would be contacting Juniper to find out about possibly including this type of device fingerprinting in its own threat-intelligence feeds.

Device fingerprinting it's not an entirely new technology by any means appears to have appeal to security professionals though they have qualms about abandoning IP-based threat detection. And they wonder if Juniper's device fingerprinting technology might raise the same old issues about vendor lock-in.

When a panel of four chief information security officers (CISO) at the RSA Conference here this week was asked their reaction to the idea of abandoning IP-based detection in favor of what Juniper is proposing, their reaction was mixed.

Carter Lee, CSO at e-commerce company, said he was interested in the idea of device fingerprinting as an additional form of threat intelligence, but he was hesitant on the idea backed by Juniper that enterprises abandon IP-based detection altogether. He also expressed concern about whether device fingerprinting might be subject to vendor lock-in, as some technologies are. And he wondered about how resistant to malware attack such a device fingerprinting technology might be. "Would some malware figure out a way to defeat that?" Lee said.

Asked for its reaction to the Juniper announcement, Cisco also weighed in.

Cisco Vice President of Security Dave Frampton remarked the only way to make Juniper's device fingerprinting practical and effective would be to take feeds from multiple sources in order to have it scale on a global basis. Frampton also said Cisco disagreed with the notion that IP-based detection is somehow obsolete or ineffective, as Juniper appears to claim.

And he said Cisco does have its own kind of device fingerprinting but it's used to determine specifics about "the user device and the posture of that device, such as the application running on it, the server, the geo-location and IP address," and it's seen as part of monitoring devices on the move.

"We're not labeling something an attack device and publishing it out," said Frampton. He notes there could be possible drawbacks to labeling a device that way for the purposes of threat intelligence-sharing.

Ellen Messmer is senior editor at Network World, an IDG publication and website, where she covers news and technology trends related to information security. Twitter: MessmerE. E-mail:

Read more about wide area network in Network World's Wide Area Network section.

Join the CSO newsletter!

Error: Please check your email address.

Tags securityCIOWide Area Network

More about CiscoCSOEMC CorporationIDGJuniperOverstock.comRSA

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Ellen Messmer

Latest Videos

  • 150x50

    CSO Webinar: Will your data protection strategy be enough when disaster strikes?

    Speakers: - Paul O’Connor, Engagement leader - Performance Audit Group, Victorian Auditor-General’s Office (VAGO) - Nigel Phair, Managing Director, Centre for Internet Safety - Joshua Stenhouse, Technical Evangelist, Zerto - Anthony Caruana, CSO MC & Moderator

    Play Video

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

More videos

Blog Posts

Market Place