Networking infrastructure, and the software and hardware that it consists of, is critical infrastructure of the utmost importance. Failing to protect these systems carries not only a heightened business risk but also a risk to the technologies that our entire society relies on to function. Today, misconfigured or end-of-life products represent a massive attack surface for adversaries, and communication gaps between product vendors and consumers add additional challenges.

To that end, the Network Resilience Coalition makes several recommendations on best practices for both vendors and users of network products. The Coalition believes that any potential additional costs incurred by these practices are outweighed by the downstream mitigation of disruptive or damaging incidents and further justified by the broad impact of increasing network resilience across the board.

The NRC recommends that vendors of network products:

  • Align their software development practices with the NIST Secure Software Development Framework (SSDF)
  • Provide clear and concise details on product “end-of-life” by providing specific dates, date ranges, and details on what level of support to expect for each date range
  •  Avoid combining critical security fixes from updates with new features or functionality enhancements
  • Consider participation in the OpenEoX effort in OASIS, a cross-industry effort to standardize the way end-of-life information is communicated and to provide it in a machine-readable format.

The NRC recommends that consumers and purchasers of network products:

  • Align their product procurement requirements with the above recommendations by favoring vendors that are aligned with the SSDF, that provide clear end-of-life information, and that plan to provide separate critical security fixes
  • Increase cybersecurity vigilance (vulnerability scanning, configuration management) on products they elect to rely upon outside of their support period
  • Periodically ensure that product configuration is aligned with vendor recommendations, with increasing frequency as products age
  • Consider participation in the OpenEoX effort in OASIS, a cross-industry effort to standardize the way end-of-life information is communicated and to provide it in a machine-readable format.

Coalition members, both vendors and consumers, agree that these recommendations, if broadly implemented, would lead to a more secure and resilient global network infrastructure. It is the opinion of the group that this is mutually beneficial to all participants of the network product market, and that it also makes major strides in better protecting the critical infrastructure that people rely on for their livelihoods and well-being. 

Stephen Banghart

Read Next

A Partial Win for AI Red-Teaming from the Copyright Office

The U.S. Copyright Office clarified legal rules for AI trustworthiness research and red-teaming under Section 1201 of the Digital Millennium Copyright Act and AI red-teamers have cause to celebrate, however, there is some not-so-great news too.

Building PQC and Crypto Resiliency Across the Public and Private Sectors

A webinar that featured industry leaders from AT&T, the National Institute of Standards and Technology (NIST), InfoSec Global, The White House, and Venable LLP, focused on cryptographic resilience and post-quantum transition.‍

NTIA Report Reveals Support for Open AI Models

The NTIA released a report examining the risks and benefits of dual-use foundation models with publicly available model weights, also examining the impact of openness on innovation and how to evaluate and quantify risk for these models.