Gartner warns against sticking solely to Microsoft

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Exclusive reliance on Microsoft's Windows operating system could make companies vulnerable to greater damage during a cyberattack, according to an upcoming report from business-technology consultancy Gartner.

A draft copy of the Gartner research note seen by CNET News.com mirrors the conclusions of seven prominent security researchers, who released a paper stating that Microsoft's dominance in software could have serious consequences for national cybersecurity. The Gartner report is scheduled to be published on Friday.

Both reports argue that allowing the bulk of information infrastructure to rely on a single code base -- or monoculture -- could result in a cascading failure, taking down large parts of the Internet in a manner similar to an electrical blackout. The research note focuses on a corporate -- rather than national -- scale, arguing that for companies, diversifying desktop operating systems could be a good defence against such catastrophe.

"The recent upsurge in malicious-code attacks that target Windows, which is used on more than 90 percent of enterprise desktops, highlights the urgent need for enterprises to improve the security and survivability of their personal computers," says the draft copy of the report.

"By spreading critical business functions across multiple desktop platforms," the report adds, "or by maintaining key operating groups on separate platforms, you can enhance your ability to keep at least some of your key personnel and processes functioning and communicating during an attack."

The paper is the first indication that corporate America may be lending credence to a position paper written by seven well-respected security researchers and released on 24 September by the Computer and Communications Industry Association, which is a noted Microsoft critic. A lawsuit that charges Microsoft with making computer users' personal data vulnerable was filed against the company a week later, on behalf of a victim of identity fraud. The suit extensively uses the report's conclusions in its arguments.

The advice to businesses also arrives as Linux, widely seen as the major competitor to Microsoft, is making inroads among companies and governments, despite recent research that found Windows still on top in server operating systems. The United Kingdom and Russia both signed Linux deals with IBM on Wednesday. The State of Massachusetts has adopted a policy that will make it more likely that open-source software, such as Linux, will be considered for government systems.

Putting all your PCs in one basket
The Gartner research note does not argue that Microsoft operating systems are inherently less secure, just that absolute reliance on only Windows computers could result in a major failure. The note points out that the danger of monocultures is well accepted: a forest that only has a single species of tree could likewise be destroyed by a single virus; a greater diversity of trees means that many will survive.

However, Bob Muglia, senior vice president of Microsoft's Enterprise Storage and Enterprise Management divisions, said he didn't buy the monoculture argument. Even diverse information systems have to communicate through common interfaces, opening them to broad attacks. Moreover, forcing a company to diversify means reducing efficiency.

"When you do that, you introduce a great deal of complexity and... make it harder for people to do their job on a day-to-day basis," Muglia said.

The Gartner research note agrees that diversity comes at a cost, but it adds that companies that were hit by the SQL Slammer and MSBlast worms may need to consider diversifying as an additional defence against future attacks. Gartner points to the quickening pace at which attacks are created from newly discovered vulnerabilities, predicting that 30 percent of attacks in 2006 will occur before companies can patch their systems, up from 15 percent in 2003.

"Simply patching will never be good enough," the draft report notes.

By diversifying, companies gain key benefits, Gartner says. Businesses will gain some immunity to the majority of viruses and worms that target Windows systems. Moreover, widespread adoption of alternative operating systems will increase competitive pressure on Microsoft, forcing the company to better secure its software.

Bruce Schneier, chief technology officer of network-monitoring company Counterpane Internet Security and one of the seven authors of the original monoculture paper, said Gartner's advice is a good sign and that though diversifying may involve some difficulties, it's worth it.

"We've always said it's a trade-off," Schneier said. "There are security benefits to a store of never letting customers inside, but the trade-off is unacceptable." The trick is finding an acceptable trade-off that improves security, Schneier said. "If people are finally saying that the security benefits are worth the trade-off, then that's a good thing."

However, Gartner warned its clients to do it right, or don't do it at all. Companies may stumble dealing with diversity on the desktop, the research note says. Noting that two-thirds of successful attacks take advantage of misconfigured systems, the report stresses that companies shouldn't diversify unless they can do so properly.

"Tight administration of a single operating system provides more security than sloppy administration of multiple operating systems," the draft report says.

Talkback

How my blood pressure doesn't go through the roof i'll never know....

The likes of Gartner telling us that putting all our eggs in one basket isn't as safe as spreading them across mulitple baskets is a joke. Yes - it's common sense.

Hold on. But then they say unless you can handle all the baskets and maintenance, don't do it.

OK - so what do they advise? Pretty much, have multiple systems which are air tight, fully maintained and users know how to use properly - otherwise you'll get a decrease in efficiency and bottom line figures. Hmmm. So the direct cost to the business of implementing mulitple solutions, employing skilled systems admins and support, not to mention the (re)training to the users doesn't come into the equation?

Whichever ANALyst who sits in an office and thought this one up has obviously never worked in a real business. I can see the faces of a hundred managing partners of accounting firms across the UK as I advise them to AT LEAST double their annual IT spend to achieve POSSIBLE improved security. Right.

I advise accounting and legal firms on their IT strategy, direction and growth to meet the needs of the business. I'm just glad I don't subscribe (any more) to the likes of Gartner for this waste of time, money and effort.

What a joke.

via Facebook 30 October, 2003 07:42
Reply

Yes...this is nothing but empty rheotorical common sense that any grandma can say. No facts or figures or charts. No true direction or way towards solutions. It just says dont stick to one platform, and when you dont stick to it, do it correctly. Ahh...what wisdom

via Facebook 14 April, 2005 22:02
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

8 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

16 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

18 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

18 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

20 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

22 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

23 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

24 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

24 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

1 day ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

1 day ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint