NSS Labs Research Reveals That Only 3% of Security Product Combinations Successfully Blocked 1,711 Known Exploits in First Empirical Testing of Layered Security Defenses
AUSTIN, TX--(Marketwired - May 23, 2013) - NSS Labs today released new research showing that the common security strategy of "defense in depth" -- layering multiple security products within a single security category (such as intrusion prevention from two different vendors) or even across multiple categories (intrusion prevention systems plus next generation firewalls, for example) -- doesn't always provide the level of protection most enterprises expect. NSS' findings raise fundamental questions about the performance and value layered security products deliver for CIOs and CISOs concerned with cost and complexity in addition to the risk of compromise and data breaches.
In the past 18 months, NSS Labs tested the security effectiveness of typical defense technologies such as next generation firewall (NGFW), intrusion prevention systems (IPS), and end point protection suites (EPP -- also known as antivirus/malware detection) and found that there are significant correlations in their failure to block against known exploits. While layered security remains a best practice in principle, NSS research reveals that the real key to effective protection lies in an organization's choice of protection technologies to combine and documents wide variances in the security effectiveness of different product combinations.
View the NSS Lab Analyst Brief - Correlation of Detection Failures
NSS research found the following key conclusions:
Commentary: NSS Labs Research Director Stefan Frei
"Security professionals have long believed that deploying 'defense in depth' in any product combination uniformly improves protection by default -- but our latest research shatters this traditional assumption and we were surprised to find that a mere 3% of the 606 unique security product combinations tested were able to detect all exploits," said Stefan Frei, Research Director at NSS Labs. "To derive real value from layered security -- offsetting the assumed cost and complexity -- it's imperative for organizations to carefully compare their assets and an array of products' performance in our tests, in order to tailor their security layers for optimal protection. Ignoring this correlation leads to an overestimation of the security effect of combining multiple protection technologies by orders of magnitude."
The NSS Group Tests used for this analysis include:
About NSS Labs, Inc.
NSS Labs, Inc. is the world's leading information security research and advisory company. NSS is both an analyst firm specializing in security technologies and a testing laboratory widely recognized as the "go to" company for research and unbiased reporting. We deliver a unique mix of test-based research and expert analysis to provide our clients with the right information they need to make IT decisions. CIOs, CISOs, and information security professionals from many of the largest and most demanding enterprises rely on NSS. The company is located in Austin, Texas. For more information, visit www.nsslabs.com.
© 2013 NSS Labs, Inc. All rights reserved. All brand, product and service names are the trademarks, registered trademarks, or service marks of their respective owners.
Contact Information:
Contact:
ReseAnne Sims
Sr. Marketing Manager, Public Relations
NSS Labs
Phone: +1 (832) 741-7373
rsims@nsslabs.com