In recent years, researchers have disclosed tens of thousands of new vulnerabilities every year, in everything from Internet-of-Things gadgets to IT management servers. The uncomfortable conclusion is that the likelihood of an enterprise network already being compromised, without anyone noticing, is high.
That changes what network security has to be. Waiting to react to an alert assumes you will get one, and an attacker who is already inside, moving carefully, may never trip it. A shift from reactive to proactive network security, one that assumes a breach and designs against it, is necessary.
An Innosuisse research project
In an applied research project funded by Innosuisse, narrowin and the Institute of Applied Information Technology (InIT) at ZHAW set out to make that abstract risk concrete. Together they developed an Expedition Node, a device built to demonstrate how easily, and how unnoticed, an attacker can operate once they are already inside a network, for example after exploiting a vulnerability like Log4Shell.