Cisco"s CSO talks IOS exploits, open source

24.10.2005
Von Rodney Gedda

"The exploits have been sensationalized and such attacks are possible on any operating system not just ours."

On the black market availability of the IOS source code, Stewart is adamant that IP theft, and not exploits, is a bigger concern.

"When it comes to exploits, people are going to take a box and try to exploit it, not look at the code and find a vulnerability," Stewart said. "Customers want to align with a vendor that can deal with exploits when they are found."

Cisco itself is using open source software from the BSD and Linux ecosystems, which Stewart attributed to customer demand.

"We use OpenSSH because that"s what customers want," he said. "Using Linux, Windows, or Solaris will depend on what you are trying to do. Each has its strengths and weaknesses."

Stewart has been in the security industry for 15 years, both inside and out of Cisco. The 36-year-old was with Cisco between 1994 and 1997, and returned in 2002.