Showing posts with label Infosecurity Europe 2009. Show all posts
Showing posts with label Infosecurity Europe 2009. Show all posts

Finjan Discovers 1.9 Million Corporate and Government Computers Controlled by Cybercriminals

Finjan Discovers a Network of 1.9 Million Malware-Infected Computers Controlled by Cybercriminals - Corporate and Government Computers Are Included

Findings show that the UK and the US top the list with the highest number of infected computers

Farnborough, United Kingdom, 22nd April 2009Finjan Inc., a leader in secure web gateway products and the provider of unified web security solutions for the enterprise market, announced that Finjan’s Malicious Code Research Center (MCRC) has discovered a network of 1.9 million malware-infected computers. Corporate, government and consumer computers around the world were infected by the malware.

This discovery is part of a research conducted by MCRC when investigating command and control servers operated by cybercriminals. The cybercrime server has been in use since February 2009, is hosted in the Ukraine and is controlled by a cybergang of 6 people. These cybercriminals established a vast affiliation network across the Web to successfully distribute and operate their malware install-base. They compromised computers in 77 government-owned domains (.gov) from the UK, US and various other countries.

The malware is remotely controlled by the cybercriminals, enabling them to instruct the malware to execute almost any command on the end-user computer as they see fit, such as: reading emails, copying files, recording keystrokes, sending spam, making screenshots, etc.

Since the discovery of its findings, Finjan has provided UK and US law enforcement with information about the server. Finjan has also contacted affected corporate and government agencies to let them know that they were part of the infected computer names.

“As predicted by Finjan at the end of last year, cybercriminals keep on looking for improved methods to distribute their malware and Trojans are winning the race. The sophistication of the malware and the staggering amount of infected computers proves that cybergangs are raising the bar,” said Yuval Ben-Itzhak, CTO of Finjan. ”As big money drives today’s cybercrime activities, organizations and corporations need to protect their valuable data to prevent theft by these kind of sophisticated cyberattacks.”

The research also revealed that the malware is installed on computers when visiting compromised websites serving malicious code. Information found by MCRC on the command and control server includes the IP addresses of the infected computers as well as the computers’ name inside corporate and government networks that are running the malware.

The global spread of infected computers in percentages is as follows:

· US: 45%
· UK: 6%
· Canada: 4%
· Germany: 4%
· France: 3%
· Other: 38%

The malware is infecting computers running the Windows XP operating system and using the following Web browsers:

· Internet Explorer - 78%
· Firefox - 15%
· Opera - 3%
· Safari - 1%
· Other - 3%

As recommended by leading analysts, a unified Web security solution is the preferred solution for corporate and government agencies against today’s cyber attacks. Finjan’s Unified Secure Web Gateway product combines multi-layered Web security, utilizing real-time content inspection technologies, with data leakage prevention (DLP) solutions. Finjan’s product also provides Web 2.0, productivity, liability and bandwidth control via URL categorization, content caching and applications control technologies on one dedicated appliance. This enables companies and governmental agencies alike to enjoy optimal multi-layered protection in real-time, with lower Total Cost of Ownership (TCO) and higher Return on Investment (ROI).

Screenshots and examples taken from the command and control server can be found on Finjan’s MCRC blog post at: www.finjan.com/mcrcblog

Finjan’s team will be available for questions regarding the discovery at Infosecurity Europe conference, Earls Court, London, UK on 28-30 April (Booth H20, Hall EC1). Finjan also invites you to come to the Business Strategy Theatre, when Finjan’s UK Regional Director Mr. Tim Warner will hold the seminar “How Organisations can protect themselves against the current Cybergeddon” on Wednesday April 29, starting at 15:20 hrs.

Finjan’s Malicious Code Research Center (MCRC) specializes in the detection, analysis and research of web threats, including Crimeware, Web 2.0 attacks, Trojans and other forms of malware. Its goal is to be ahead of hackers and cybercriminals, who are attempting to exploit flaws in computer platforms and applications for their profit. In order to protect Finjan’s customers from the next Crimeware wave and emerging malware and attack vectors, MCRC is a driving force behind the development of Finjan's next generation of security technologies used in its unified Secure Web Gateway solutions. For more information please also visit MCRC’s info center and blog.

Finjan is a leading provider of secure web gateway solutions for the enterprise market. Finjan Secure Web Gateway provides organizations with a unified web security solution combining productivity, liability and bandwidth control via URL categorization, content caching and applications control technologies. Crimeware, malware and data leakage are proactively prevented via patented active real-time content inspection technologies and optional anti-virus modules. Powerful central management enables intuitive task-based policy management, excellent drill-down reporting capabilities and easy directory integration for all network implementation options. By integrating several security engines in a single dedicated appliance, Finjan’s comprehensive and integrated web security solution enables quick deployment, simplified management and reduction of costs. Business benefits include real-time web security (no patches or updates needed), lower total cost of ownership (TCO), cost savings in administration efforts, lower maintenance costs, and reduction in loss of productivity. Finjan's security solutions have received industry awards and recognition from leading analyst houses and publications, including Gartner, IDC, Butler Group, SC Magazine, eWEEK, CRN, ITPro, PCPro, ITWeek, Network Computing, and Information Security. With Finjan’s award-winning and widely used solutions, businesses can focus on implementing web strategies to realize their full organizational and commercial potential. For more information about Finjan, please visit: www.finjan.com.

Neil Stinchcombe
Eskenzi PR
<>

Optenet to Provide Complimentary Web Filtering Solution to Infosec Attendees

Socially Responsible Organisation to Give Away Free WebFilter PC Solution Worth €39 on Stand H82

London UK, April 21 2009 - Optenet, a global IT security company and provider of high-performance content filtering solutions, will be providing free, one-year licenses for its popular Optenet WebFilter PC product to delegates at Infosecurity Europe 2009.

Optenet first undertook such an initiative to support February’s Safer Internet Day – the annual event to promote safe and responsible use of online technologies particularly among children – where free versions of WebFilter could be downloaded from its website.

Optenet has been prompted to repeat this offer by the alarming rise in Cyber-bullying among children and adolescents through interactive technologies (online games, emails, Internet forums, text messaging, mobile and other electronic devices). Optenet’s WebFilter PC helps parents monitor their children’s Web browsing activity at home and avoid cases of online harassment. Visitors to Optenet’s stand (H82) during the show will receive a complimentary one-year license worth €39.

“Providing free copies of Optenet’s WebFilter PC is a significant step towards protecting children online, in conjunction with awareness and education of the problem itself,” says Optenet’s Regional Director Northern Europe, Kevin Roberts. “We are firmly committed to the protection of surfers of all ages. As an organisation, we cooperate with and support the efforts of the European Commission, as evidenced by our collaboration with CEOP in the UK and recent activity around February’s Safer Internet Day.”

Infosecurity Europe 2009 is taking place at London’s Earls Court exhibition centre from April 28-30.

Optenet is a global IT security company that provides high-performance content filtering solutions to service providers and large enterprises worldwide. Optenet’s technology protects 75 million end users around the globe, including the customers of many of the world’s leading ISPs and mobile operators, as well as employees of global enterprise organizations. The Company is a socially conscious organization, committed to eliminating illegal content on the Internet, protecting children and supporting government agencies and non-profit organizations that share the same goal. For more information, visit www.optenet.com.

Rise in Unisys Security Index sets the scene for Infosecurity Europe

London, 20th April 2009 - The organisers of the Infosecurity Europe show, which takes place in London next week, say that increased consumer worries over ID theft and fraud need to be addressed by the IT security industry.

"The latest Unisys Security Index for Internet security shows that worries about ID theft and online fraud is soaring, as reports of electronic fraud continue to hit the headlines," said Tamar Beck, Group Event Director, Infosecurity Europe, "The index confirms industry observations that criminals are increasingly moving online, which explains why 69 per cent of UK consumers say they are concerned about computer security, with 65 per cent worried about their safety and security when banking or shopping online," she added.

According to Beck, the latest edition of the twice-yearly analysis of European attitudes towards a variety of security topics makes for interesting reading, not least because 72 per cent of UK citizens say they are at greater risk from identity theft and related crimes such as credit card fraud, as a result of the economic downturn.

The economic downturn, he explained, has undoubtedly forced cybercriminals to diversify into new areas of fraud, and this trend is one that will be discussed by a leading team of professionals at the Infosecurity show in London later this month.

The show organisers have assembled several of the industry's leading figures in IT to discuss the latest trends on cybercrime, as well as explain to audiences how to better protect their IT resources from the ensuing problems.

Speakers lined up to keynote at next week's IT security event include Jeff Brooker, Head of Security & Business Continuity with HMRC who, along with Julia Harris, Head of Information Security with BBC Future Media & Technology, will be looking at who got caught out on the IT security front in the last 12 months.

Charlie McMurdie, Detective Superintendent with the Police Central e- crime Unit of New Scotland Yard - along with Philip Virgo, Secretary General of EURIM and the RT Hon Alun Michael, MP - meanwhile, will be looking at who should police the global Internet and who is ultimately responsible for Internet crimes.

It's against the backdrop of the increased Unisys Security Index that professionals should be encouraged to attend the Infosecurity Europe event, which offers one the UK's largest free education programmes on Information security issues.

"We have assembled some of the UK and Europe's finest professionals to explain to IT and business managers how they can better protect their company IT resources," said Beck.
"At this time of economic uncertainty, good advice is always to be welcomed, and the fact that this advice is being offered free of charge, makes Infosecurity Europe a must-attend event for anyone concerned about the rise in cybercrime worries," she added.

Infosecurity Europe, running for its 14th year in 2009, is Europe’s number one Information Security event. Featuring over 300 exhibitors, the most diverse range of new products and services, an unrivalled education programme and visitors from every segment of the industry, it is the most important date in the calendar for Information Security professionals across Europe. Infosecurity Europe is one of five Infosecurity events around the world with events also running in Belgium, Netherlands, Russia, and France. Infosecurity Europe runs from the 28th – 30th April 2009, in its new venue Earls Court, London.

To register to attend or for more information please visit www.infosec.co.uk

For more on the Unisys Security Index: http://preview.tinyurl.com/dxfc3z

© Infosecurity PR
<>

Automating Network Configuration Management and Ensuring Network Compliance, Security

By V Balasubramanian, Marketing Analyst, ManageEngine DeviceExpert, AdventNet Inc.

Modern enterprises depend on network availability for business continuity. In heterogeneous networks, administrators face numerous challenges in properly managing device configurations, carrying out changes, and in minimizing network downtime triggered by human errors. Ensuring that device configurations remain compliant to various standard practices and regulations could aid in minimizing network downtime and thereby help the network remain in top shape. Automating the Network Configuration Management is the means to achieve the above goal.

Networks form the backbone of the modern IT and other enterprises. The components of the backbone - the network infrastructure, are quite complex and varied with the presence of hundreds or even thousands of mission-critical edge devices such as switches, routers, firewalls and others from dozens of hardware vendors. Enterprises make huge investments on procuring network infrastructure and employ highly skilled professionals to manage and administer the network infrastructure. Typically, a few administrators manage a large infrastructure.

Managing the network is a challenging task as business continuity directly depends on network availability. Even a few minutes of network outage could have a rippling effect on the revenue stream as critical business services get affected. And as business needs grow, network complexity also grows up exponentially. The enterprise naturally puts the squeeze on the few network administrators mandating them with the responsibility of ensuring network availability. Not just network availability, but also ensuring security and reliability, optimizing performance, capacity and utilization of the network fall under the ambit of the administrators.

Business needs are in a constant state of flux and administrators are required to respond to the needs often by configuring the network devices, which is a sensitive and time-consuming task. It requires specialized knowledge, familiarity with all types of devices from different vendors, awareness on the impact of changes, precision and accuracy. Naturally, the highly skilled network administrators carry out the configuration changes.

Ironically, most of the configuration changes are repetitive, labor-intensive tasks - for instance, changing passwords and Access Control Lists. Yet, as even minor errors in configuration changes to the devices in production carry the risk of causing network outage, the skilled network administrators spend a significant part of their time on configuring the devices. They find it hard to concentrate on strategic network engineering and administration tasks.

Besides, with increasing security threats to mission-critical network resources and serious legal consequences of information mis-management, enterprises everywhere are required not just to follow standard practices, internal security policies, stringent Government regulations and industrial guidelines, but also demonstrate that the policies are enforced and network devices remain compliant to the policies defined. Ensuring compliance has become a priority for network administrators nowadays. This drives them take extra care while changing configurations.

Administrators also have to continuously monitor the changes carried out to the devices, as any unauthorized change can wreak havoc to the network.

It is evident that administrators face pressures from multiple angles; but, how do they normally manage configurations? Let us have a look at some of the traditional network configuration management practices:

  • While carrying out changes, most of the administrators document the proposed changes. They login to each device separately and carry out the change. In case, the configuration changes are not successful, they will turn the configuration to the previous working state by undoing the changes as recorded by them in the documentation.
  • In big enterprises with a large number of devices, the administrators cannot follow the 'change documentation' process. Instead, they develop custom scripts to push configurations to multiple devices. With the enormous diversity of hardware vendors, the administrators develop numerous custom scripts to suit the syntax of each device type.
  • Some others juggle with fragmented tools to do specific tasks in configuration management. They correlate the output from each tool manually.
  • Still worse, some administrators follow the haphazard way of carrying out changes to live equipment without any management plan. When errors in configuration cause network outage, they end up wishing that they could move the configuration back to a proper working version. They manually troubleshoot the cause.
The Limitations of the Traditional Approach
  • The manual way of configuring the devices suffer various disadvantages and serious limitations. The following are prominent among the many:
  • The highly skilled network administrators spend most part of their precious time on doing repetitive, time-consuming configuration tasks. They get little time to focus on strategic network administration plans and tasks. This amounts to wastage of resource, cost and time.
  • There is no provision to apply configuration changes in bulk to many devices at one go. Administrators have to logon to devices separately or at best execute many custom scripts to get the work done, which would be time consuming.
  • Even simple tasks like rotating passwords of devices, viewing access lists etc. could prove uphill.
  • As the number of devices grows, administrators find it difficult to respond to the business priorities that require frequent configuration changes. Possibilities of committing errors become bright.
  • A trivial error in a configuration could have devastating effect on network security giving room for malicious hackers. The traditional approach has no provision to check configurations before deployment from the standpoint of security.
  • Administrators lose track of configuration changes. As a result, configuration management becomes a daunting task. In the face of a network outage, troubleshooting becomes laborious. The mean time to repair (MTTR) climbs significantly.
  • There is no way to control the access to device configurations based on user roles. No way to check/prevent unauthorized configuration changes either.
  • The traditional practice has no scope to ensure accountability for user actions. When something goes wrong due to faulty configuration change or when a security breach occurs, it would not be possible to trace the actions to a particular individual in the absence of audit trails.
  • There is no provision to monitor and ensure compliance to government regulations, industry best practices and standards.

Issues at a Glance
  • Wastage of skilled resources in repetitive configuration tasks
  • Administrators require lot of time to do configuration changes
  • Troubleshooting in the face of outages becomes monumental
  • No provision to monitor unauthorized changes, security and compliance
  • Unable to keep track of configuration changes
  • No centralized control
  • Lack of accountability for actions


The Way Out
Conquering the complex, multifaceted operational and technological challenges of network configuration management is getting simpler nowadays with the availability of Network Change and Configuration Management (NCCM) solutions.

The NCCM solutions are designed to automate the entire lifecycle of device configuration management. The process of changing configurations, managing changes, ensuring compliance and security are all automated and the NCCM solutions prove to be powerful at the hands of network administrators.

Industry best practices such as Cisco’s ‘Gold Standard’ (which explains the recommended security settings for Cisco devices) and Government and other regulations such as HIPAA, Sarbanes-Oxley, EPHI, GLBA, PCI Data Security Requirements etc. prescribe a lot of ‘best practices’ . By complying to the best practices and compliance policies, enterprises can avoid most of the network security issues.

By leveraging NCCM solutions, administrators can automate the entire compliance monitoring process, which will happen at all levels - on demand, automatically at regular intervals and whenever a change happens. Violations would immediately be escalated to the security personnel. Besides, comprehensive compliance reports could be generated for submission to compliance auditors. In addition, in the case of violations, remediation tips will also be offered. During planned configuration changes, NCCM solutions help check the syntax of the configuration changes for correctness before uploading them to the device.

NCCM solutions will also help put in place both proactive and reactive configuration management strategies. Proactively, administrators can reduce manual errors and prevent unauthorized changes; when something goes wrong, they can react to the contingency within minutes by getting to the root cause or by rolling-back to the previous working version.

Automating NCCM will not only help Networks remain compliant to the policies, but also make the network remain in top shape. Compliance to best practices will just become a way of life.

With a good NCCM solution in place, enterprises can make best use of their network infrastructure. They can achieve increased network uptime and reduced degradation and performance issues.

ManageEngine is exhibiting at Infosecurity Europe 2009, the No. 1 industry event in Europe held on 28th – 30th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Courtesy: Infosecurity PR
<>

The Impact of the Consumerization of IT on IT Security Management

By Alexei Lesnykh, DeviceLock

The age of consumerization of IT, defined as the blurring of lines between corporate IT and consumer technology, is well and truly upon us. Driven by the proliferation of consumer technology such as PDAs, MP3 players and Smartphones, we have seen increasing adoption of consumer technology in the corporate environment. Thanks to the growth of endpoint device capabilities and the corresponding changes in security threat profiles, this new era has significant ramifications for the management and enforcement of corporate IT.

Personal mobile devices have already been proven to increase productivity. According to a Osterman Research, 15 per cent of the corporate workforce used employee-supplied mobile devices in 2007, and a survey from TechTarget forecasts that this figure will exceed 25 per cent in 2008.

From an IT security perspective, the task of managing ‘rogue’ or disgruntled employees in a consumobilized enterprise will become a real art – especially as a high degree of co-operative behavior and self-discipline will be expected and required from all employees including those who are discontented, malicious, negligent, or forgetful. The same technology advancements and social trends that drive consumerization will also cause a sharp increase in information security risks, based on the development of ‘production quality’ mobile malware, and the growth of corporate data leakage from and through employees’ mobile devices.

The typical size of a mobile device’s removable flash memory (currently 4 - 8GB) is already sufficient for storing and running a standard Operating System. The threat of corporate data leakage through personal mobile devices is unavoidable and immediate. Unavoidable because certain features of human nature will not change: since there is no ultimate cure for accidental errors, negligence or malicious intent, mobile devices will continue to be lost and stolen. Immediate because nothing new is required for exercising the threat and it is happening right now.

So what is the scale of this threat, in these early stages of IT consumerization? In-Stat has estimated that in the US over eight million mobile devices went missing in 2007; and for Smartphone users, the people with the most access to sensitive information, the probability of loosing a device was 40 per cent higher. According to the 2007 CSI Computer Crime and Security Survey, seven per cent of total financial losses incurred by US corporations from IT security incidents were related to the loss of proprietary or confidential data resulting from mobile device theft. Projecting these figures onto the latest predictions on mobile device market growth made by Tim Bajarin, President of Creative Strategies, one can anticipate an alarming figure of about five and 14 million Smartphones being lost in 2008 and 2010 respectively. This will equate to about 14 per cent of the total financial losses caused by attacks on corporate IT resources in 2008, rising to 21 per cent in 2010.

Developing the solution
So what should the security industry be doing to address the mobile security threats brought about by IT consumerisation? The key part of the architecture for preventing data leakage needs to be local sync parsing. The local sync data leakage prevention architecture should be built as a stack of integrated security mechanisms including bottom-up endpoint device/port control, local sync application parsing, file type filtering, and content-based filtering technologies. In addition, a central policy-based management console integrated with a major systems management platform, comprehensive centralized logging, reporting and evidence enablement components need to be put in place.

Every layer of the architecture controls those parameters of a local connection it is designed to deal with by blocking or filtering prohibited elements out, and detecting and marking the types of objects to be controlled by a higher-layer architecture component to which the classified data flow is then passed for further processing.

The device/port control component of the architecture is responsible for detecting and controlling the presence of a locally connected mobile device, the type of connection interface or port type, device type and ideally the device model and its unique ID. The output can then be passed to the local sync parsing component, which parses the sync traffic, detects its objects (e.g. files, pictures, calendars, emails, tasks, notes, etc.) filters out those prohibited, and passes allowed data up to the file type filter. The file type filtering component checks the input flow, deletes those files not allowed, and filters information data to detect and block the pieces of human-understandable data failing to comply with the corporate security policy.

The security threat brought about by the consumerization of IT and the consequent mobilization of the workforce is real and upon us. Organizations need to take immediate steps to ensure that they address this threat before it gets out of control and the infosecurity market needs to continue to develop solutions to mitigate the unavoidable risk brought about by the growth of consumer technology in the corporate environment.

DeviceLock is exhibiting at Infosecurity Europe 2009, the No. 1 industry event in Europe held on 28th – 30th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

DeviceLock is a worldwide leader in endpoint device control security. For more information please see: www.devicelock.com.

Courtesy: Infosecurity PR
<>

WHO’S READING YOUR DATA WHILE YOU READ THIS?

By Colin Tankard, Managing Director, Digital Pathways Limited

Security of data has been an issue for as long as … well, as long as there has been data. As that data is stored in more and more sophisticated ways, so the security systems need to run to keep up. It’s not just the MoD that needs to know who’s reading their files; there can’t be a single commercial concern that doesn’t need to shield confidential material from prying eyes.

The nub of the problem revolves around the ability to very accurately control access to data. Knowledge is power, as they say, and accidentally giving knowledge to the wrong people can be highly debilitating.

It’s not just protecting data from external threats though; protective software needs to be simultaneously inward-facing. Companies need to be absolutely sure that staff cannot gain access to confidential data such as salaries and HR files – or, as importantly, the data of the firm’s clients or customers.

It might be a question of straight forward commercial confidentiality, or it may be that companies have a legal obligation for compliance with the Data Protection Act, or the PCI standard; or it may well be that the company has outsourced its digital support, and they want that sub-contractor to manage their infrastructure but not have access to their data.

When it comes to protecting data, information, files – call it what you will - there are three fundamental elements which need to be understood and addressed.

Firstly you need to know who or what is accessing the information being disseminated from your own network; what is required is a comprehensive audit of who is logged on and where, and what data they have access to. That might sound obvious but it’s a crucial first step; if a big network is getting a large number of logs then the log data needs to be carefully analysed, and then be presented in a manageable format. There is often a gap in the ability to link the log data to any undesirable event. That ‘event’ might be a chain of occurrences which would trigger concern, such as a number of log-ons from the same IP address, using different passwords with each log-on.

It is the view of Colin Tankard – Managing Director of Digital Pathways, that the biggest challenge is for companies to log the data that is flying around in their networks. Once that has been managed they can then move on to put the necessary protocols in place.

The second step is to identify what data needs to be protected. Digital Pathway’s clients include international law firms handling highly sensitive information, car manufacturers who have an absolute imperative to protect new designs, and financial houses who need an impenetrable stockade around their own clients’ acquisitions and disposals.

The third step, obviously, is then to protect the data which has been identified as sensitive. Simple solutions such as encryption are just not good enough; encryption only protects you against physical theft. What needs to be controlled is access, and application to the data. A good start is to tighten access by software and user, so that employee A running Word can see those files, but employee A running SAP, or employee B running Word has no access to that data’.

These security systems need to be both active and reactive; protecting against breaches in security cover, every hour of every day, and responding to specific threats or attack. The access to data needs to be monitored constantly, and be presented in a managed and coherent fashion. There might be a large and highly technical report for the IT Manager, and a much more succinct précis for the Managing Director. This level of reporting will often be required by an external auditor (if, the firm in question needs to show compliance to, say, the Financial Services Authority), or for a third-party client who requires reassurance that his data is secure. Having that in place as a part of the security solution saves both time and money.

At the end of the day there is a balance to be reached. For some organisations having their staff operating with user names and passwords isn’t enough, and you start to move into very high levels of security, such as biometrics. For most applications though it’s more about an understanding of the problems, and any potential disasters. A lot of Digital Pathway’s clients start off thinking that they know who has access to their data - before we ruin their day by showing them otherwise!

Digital Pathways Limited is exhibiting at Infosecurity Europe 2009, the No. 1 industry event in Europe held on 28th – 30th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Courtesy: Infosecurity PR
<>

How to protect Network Security in the Social Networking Age

By Dr. Anton Grashion, EMEA Security Strategist, Juniper Networks

Productivity tool or security headache? Like instant messaging and e-mail before it, social networking can be a great tool but can also cause concern in companies that haven’t learned to adapt - and real trouble to companies that haven’t learned how to manage it.

Enterprises are beginning to adopt social networking applications to offer a fast, easy-to-use way to keep in touch, organize activities and share ideas.

Whether businesses like it or not, employees (especially younger ones) are signing up for these tools regardless of whether it’s company policy or not, and forcing the businesses to play catch up.

Because of this, there are three major concerns that are keeping IT up at night. First, consumer applications can cut into employee productivity for hours at a time. Second, social networking sites can become vectors for viruses, hacker attacks and phishing. Finally, social networking image, audio and video traffic steal bandwidth from business uses.

So, how are IT administrators supposed to control this problem? There aren’t many model companies to follow in terms of company-wide social networking deployments. A few pioneering companies have opened their doors to social networking on corporate networks such as Shell Oil, Procter & Gamble and General Electric maintain social networking accounts. An exclusive Citigroup Facebook network has almost 2,000 members.

When you look at the usage statistics, peer-to-peer (P2P) networks have millions of users sharing photos, software, music and video. Social networking reaches even further: MySpace claims more than 61 million active users; Facebook more than 65 million. The Pew Research Center estimates that half of online adults have used these services to connect with people they know.

There are also organizations actively working against social networking. As the nature of government information is often sensitive, social media tools are a big concern for many government organizations. For instance, in May 2007, the U.S. Army blocked URLs for MySpace and 12 other “entertainment” sites from their U.S. and overseas networks, referring bandwidth and security concerns. Interactive communities such as YouTube, LinkedIn, Facebook and many others are a perfect target for hackers to plant malicious worms and viruses masked as legitimate user content, and present the potential for inadvertent leakage or misuse of mission-critical data. But these tools can be important for instant communication to spread government information internally and between the organizations, yet monitoring public opinion, there is a long way to pass over these concerns. For this reason, rather than rushing into new decisions to implement these social networking tools, there should be a cautious approach to ensure the right technology pieces are in place to enforce appropriate protection, access and use. There are many technology solutions available to organizations to let them support access to social media tools while enforcing strict control over network traffic to protect information assets and avoid data loss.

The decision to block or allow consumer applications is not black or white. Policies vary according to user, application, security requirements and network infrastructure. There are steps that organizations can take to let social networking into the network securely.

1. Application-based policies Blocking applications may address this issue. However, modern consumer applications are designed to work on many different network infrastructures. This makes them hard to detect and regulate. The policies should also enable applications that offer business value - without compromising quality of service (QoS)

2. Corporate policies
Although few organizations will apply policies without exception across their entire network, most start by establishing general guidelines. Blanket policies that block or regulate all peer-to-peer traffic can then be adapted to support authorized exceptions, while continuing to regulate or block the rest.

3. User policies
Even when policies are consistent across a network or network leg, they may vary from one user category to the next. Users can be categorized many ways. For example, categories of users can be employees, contractors and/or partners. In general, policies for employees may resemble overall network permissions, contractors will likely have access to a subset of those applications, and partners may have access only to specific applications. The challenge is where and how to enforce user-based policies.

Balancing requirements
Whether your company has identified a business need for social networking applications or simply decided to get ahead of the trend, managing consumer applications on corporate networks is a matter of balancing four priorities: Security, Quality of Service, Visibility and Control.

No single set of policies can meet these requirements for every business. By deploying a combination of policy-centric and interoperable technology solutions, organizations can customize their security profile and reflect their uniqueness of individual networks, and they can grant access when, where and to whom they want adapting permissions and defenses as required to counteract internal and external threats.

Now is the time to put these controls in place because, like entropy, the pace of technological change is always increasing. No sooner have we become accustomed to the ideas of Web 2.0 than we are turning our attention to Web 3.0 and beyond. With these changes we are faced with opportunities and challenges, don’t let evolution pass you by.

Juniper Networks is exhibiting at Infosecurity Europe 2009, the No. 1 industry event in Europe held on 28th – 30th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Courtesy: Infosecurity PR
<>

Are we heading for Internet Lockdown?

By Greg Day, Security Analyst, McAfee International Ltd

Those with responsibility for managing appropriate use of an organisation’s IT systems have a greater challenge than ever before on their hands. Years ago, employees’ interaction with IT was limited to the few ‘techies’ working with complicated mainframes and central computer systems. Now, almost every employee spends the majority of their working day in front of a PC, and the Internet plays a pivotal role in much that they do.

One major issue that has emerged in recent years is how to manage the use of technology in businesses so that efficiency is kept at an optimum without compromising security. In today’s technology-driven world, locking down employees’ desktops and internet gateways would be almost akin to tying their hands behind their backs, as many rely on the web for almost every facet of their job. Therefore the internet, the very thing that can make us quicker, better and more productive, can also be a major headache, and with the range of applications now being legitimately used, it can be hard to understand the full scope of what is being made use of and how.

Recent McAfee research has highlighted how today’s IT managers are being tasked to manage not only the use of information technology within their organisations but also to consider the impact those technologies can have on the productivity of staff.

McAfee’s research highlights how many popular web technologies are not being blocked in organisations, although they are known to present serious issues regarding security and productivity. In some cases, these technologies have no legitimate business purpose, yet this is not always the case. Only one in five businesses in Europe block access to social networking sites such as Facebook and MySpace, despite almost half of them wishing they could, as they fear that they could spread viruses and encourage spam. This is made worse when you consider that it is well-known among IT professionals that they also present an increased exposure to security risks such as ID theft and unintentional exposure of sensitive information.

The situation becomes even more complex when looking at applications that, despite posing a risk from a security perspective, can also have a valid use within the business. Instant messenger and web mail are two prime examples of this and as a result, restricting access to these technologies is not as simple as it may seem. This is where employee education, helping staff to understand and prevent security threats, and policies defining acceptable use of technology on corporate systems must come into play.

IT decision makers often have the difficult job of making a choice between what they know are serious security threats and other business priorities such as productivity and employee morale. Usage policies can bridge the gap between what IT departments would ideally like to block and what is functionally realistic.

McAfee’s research also highlights that the top potentially risk-laden sites blocked by European IT managers are Internet dating (36%) and music downloads (36%). These certainly fall into the category of technologies that limit productivity but can also increase an organisation’s exposure to security threats, and are therefore clearly more straightforward to identify as “blockable”. Attitudes towards restricting access to different technologies varies considerably across Europe, with Sweden proving to be the most lenient, with 57% of IT professionals not limiting access for their employees, while in the UK, only 28% of IT departments allow employees to roam free on the Internet.

In conclusion, today’s workplace has seen a major blurring of the lines between the personal and professional. In many cases, this is a positive evolution but it should never put a company at risk. IT professionals clearly have the difficult job of balancing the security needs of a business and the functional requirements needs of the workforce, but putting fair usage policies in place and educating people on how to be safe on these sites is the most realistic option.

McAfee International Ltd is exhibiting at Infosecurity Europe 2009, the No. 1 industry event in Europe held on 28th – 30th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Courtesy: Infosecurity PR
<>

The end of the line for security…

By Sacha Chahrvin, Managing Director DeviceLock

Journalists love to write about IT security breaches and scares, even though they have been happening for a while. Virus attacks, lost laptops, hackers or individuals having their bank accounts emptied will always make the news. The example of the TK Maxx security breach, where hackers compromised the payment card details of over 45 million customers over a 16–month period, has refocused attention on the importance of data protection.

But it’s much rarer that malicious employees and the havoc they can cause makes it into the papers. Admittedly, the press do report on county councils losing laptops containing confidential employee information. But it is unusual that the public hears of security breaches that are deliberate insider attacks.

But that certainly shouldn’t make anyone think that it doesn’t happen. With the proliferation of high-speed CD drives and USB ports Wi-Fi and Bluetooth, there are many ways for a disgruntled employee to steal or replicate private company information. And with USB drives of 4GB costing less than £301, iPods that go up to 80GB and even larger external hard drives not much bigger than a pack of playing cards, it is very easy for a user to leave the office with the organisation’s entire customer database or its future product development plans in their pocket.

When key employees are about to leave an organisation they are frequently put on ‘gardening leave’ as soon as it is agreed they are going, so that they have no further access to corporate systems. But can you find out what they accessed the previous day? Or what they might have copied onto their digital camera memory card or MP3 player just last week?

These are deliberate attacks with malicious intent. But they’re not the only thing that companies should worry about. I wonder how many sales executives have copied product details or customer information onto a USB memory stick so they can access it while travelling between client organisations? Mobile working at its best – until the device gets lost.

Many organisations now realise that they need to control any user device that connects to the network, as part of their wider endpoint security policy. Indeed some companies have gone as far as disabling all ports and devices that allow users to copy data from the network. But this universal blocking of users isn’t necessarily the most effective ongoing solution for the business, despite the additional security it provider.

Treading the fine line between security and system usability will probably always be a problem for IT security managers. It is possible to build a secure database that can never be hacked or breached. But it would probably be isolated in a bunker underground with 24-hour armed guard and no connection to the outside world.

Undoubtedly this is a good solution for the security team, but that doesn’t ring true for the employees who need to view and update the data it contains on an ongoing basis. However, as soon as you open a system for legitimate users and allow them access, there is the potential for a security breach.

However, USB sticks and CD drives have not grown in popularity because they make data theft easier, but for the real difference they can make to people conducting their daily business. Information is the company’s life blood, and people need to access and move it around, copy it or take it out of the office as part of their job. Simply removing that option isn’t a realistic solution.

Organisations must start to take a proactive, flexible approach to endpoint security. This includes both the tools necessary to manage the system and the policies and employee training required to make it work. The IT security team should be able to add and remove layers of security as required by users so that they can do their jobs effectively, without making systems vulnerable. And employees need to be aware of the risks of corporate data theft and ensure that they act as the eyes and ears of the organisation, flagging up potential problems before they become reality.

If a company’s people and information are its two most valuable assets, the organisation needs to find a way of working with both so that they deliver the maximum possible value.

DeviceLock is exhibiting at Infosecurity Europe 2009, the No. 1 industry event in Europe held on 28th – 30th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

DeviceLock is a worldwide leader in endpoint device control security. For more information please see: www.devicelock.com.

Courtesy of Infosecutity PR
<>

IT Security Gets a Boost as Survey Shows Spending Up

The Majority of Organisations expect to increase spending on Information Security

London, UK 14th April 2009 - A survey by Infosecurity Europe has found that spending on Information security is likely to increase according to 55% of the 1010 respondents they asked and 34% expected their spending to remain the same as last year. Only 8% expect minor reductions of less than 5% of last years spending and 2% expect significant reductions of more than 5%. This contrasts significantly with overall spending on IT as 36% of respondents expect minor reductions from last years IT Spending and a third expect to see major reductions compared to last years IT Spending. A fifth expect overall IT spending to be higher than last year and 10% expect their overall IT spend to be the same as last year.

“Even though overall IT budgets may be reduced and the economic crisis continues to deepen, spending on information security will continue to grow driven by the increase in security threats and the fact that many organisations are still in catch up mode. IAM projects are still on a catch-up mode, so more work is needed. In addition, new areas call for additional spending. Mobile users and remote access are still poorly protected against very agile threats. ” said Eric Domage, Research Manager - Security Products & Services, IDC EMEA Software Group.

Domage continued, “We expect to see an increase in “Frustration Hacking” when people opportunistically attack their own company because they have been fired or frustrated, these first-time-last-time attacks are almost impossible to prevent. They are called first-time-last-time attacks because the people committing them have never done anything wrong before and it is done on their last day in the job. Attacks of this nature are complex to detect, prevent and remedy, for example if someone deletes all the data on servers in a company it can take weeks to correct. Prevention requires security policy, encryption and access control, these are large projects which need to be implemented before a Frustration hacking attack takes place and this is one factor that is driving spending on information security.”

He then proceeded to say: “Our prediction for the Western European Software Information Security market is that it will grow by 7% in 2009 driven by concerns about holes in information security such as Data Leakage Prevention, data integrity attacks and mobile security which are all new areas that many organisations are still getting to grips with.”

According to Tamar Beck, Group Event Director, Infosecurity Europe, “The threat from cyber crime has increased significantly in the past 12 months with predictions of the cost of cybercrime reaching hundreds of billions of dollars a year and our own research found that 90% of organisations expect security breaches to increase in 2009. The economic climate, lack of effective legislation and under resourced crime prevention have created a time bomb for cybercrime, cyber terrorism and cyber activism all of which are stretching IT departments in the government and commercial sectors. There is still a huge requirement to invest in information security which is resulting in robust budgets for information security even if overall IT budgets may remain static or even shrink slightly. At Infosecurity Europe we have brought together all the top infosecurity providers from across the globe so that organisations can compare and select the latest technology to protect your organisation and an education programme packed with outstanding experts.

In the keynote programme Dr. Nigel P Brown, Lead for Resilient Telecommunications Strategy, Cabinet Office chairs the panel on the “Global Credit Crunch & the IT Security Market: The Impact To Market & Solutions For Recovery”. In uncertain financial times, any investment in technology is likely to be severely curtailed, but there are still areas of significant growth within the Information Security industry. In this keynote the ways in which security can support IT development in a tough investment climate are explored, and technology classes that can still deliver highlighted will be investigated by:

  • Nick Coleman, Co-Founder, The Technology Den
  • Jason Creasey, Head of Research, Information Security Forum
  • Eric Domage, Research Analyst IDC
  • Jeremy Garside, Head Of Technology, The London Symphony Orchestra
  • Ed Gibson, Fellow, British Computer Society
Infosecurity Europe, running for its 14th year in 2009, is Europe’s number one Information Security event. Featuring over 300 exhibitors, the most diverse range of new products and services, an unrivalled education programme and visitors from every segment of the industry, it is the most important date in the calendar for Information Security professionals across Europe. Infosecurity Europe is one of five Infosecurity events around the world with events also running in Belgium, Netherlands, Russia, and France. Infosecurity Europe runs from the 28th – 30th April 2009, in its new venue Earls Court, London.

To register to attend or for more information please visit www.infosec.co.uk

Source: Eskenzi PR
<>

Smaller Companies Are Just As Likely To Be Hacked According To Business Crime Reduction Centre

London, UK – April 2009: Infosecurity Adviser, the online community for the information security industry, in association with Infosecurity Europe, has secured an exclusive interview with David Stockdale, the head of the Business Crime Reduction Centre (BCRC), an initiative that seeks to assist SMEs in tackling problems caused by crime.

According to Mike Barwise, blogger for Infosecurity Adviser, the exclusive interview with the BCRC is interesting, since it highlights the efforts the Centre is undertaking to educate SMEs on the topic of crime generally and, of course, cybercrime.

"The Centre is carving out a name for itself as a highly responsive organisation that seeks to listen to what small businesses are looking for on the crime advice front, and provide that service," he said.

"The BCRC has just completed a national survey on SME's attitudes to electronic crime which has revealed that smaller companies are just as likely to be hacked or similarly mistreated by electronic criminals," he added.

"At the same time, however, researchers found that many smaller firms lack the in-house ability to tackle the problem of hacking and other forms of electronic crime."

According to Barwise, it's grass-roots research like this that reveals the real state of cybercrime in the UK, as well as showing the variety of responses that companies take to the problem.

The interview, he says, reveals a worrying lack of understanding about cybercrime in the SME business community, and also highlights the need for education about the problem.
In many ways, he explained, the BCRC interview confirms the reasoning behind the need for educational seminars on cybercrime at major events such as the Infosecurity Show, which takes place in London later in April.

"With survey results showing that 21 per cent of MDs of smaller firms being unaware what IT security resources they have in place, it's clear that a lot of education is needed on the topic of protection from cybercrime," he said.

"It's good to know that the Centre is doing its bit to educate the SME community in this regard, as well as confirming the Infosecurity Europe show plans for a comprehensive education programme at the three day event," he added.

To read the Infosecurity Adviser interview with David Stockdale: http://www.infosecurityadviser.com/view_message?id=109

For more on the Infosecurity Europe event: http://www.infosec.co.uk

Source: Infosecurity PR
<>

Preventing Employee Cyber Slacking – Handling the Soft Issues

By Asa Davidson, International Marketing Coordinator, WebSpy

As today’s business environment becomes increasingly web-enabled, organizations worldwide continue to display a growing interest in understanding and managing their employees’ Internet and email use. Blocking and filtering solutions are often implemented to eliminate or reduce employee Internet access in order to minimize the risk of malicious virus exposure, network overload and productivity losses. However, limiting or denying employees’ Internet access can create employee resentment, hostility and even reduce productivity further by complicating and delaying the accomplishment of Internet related tasks.

Big Brother is watching
Many organizations that recognize blocking and filtering limitations have turned to monitoring and reporting solutions. In essence, an effective monitoring solution will assist in maximizing employee productivity, identifying download issues, improving network management and minimizing litigation risks. However, no matter how innovative the monitoring solution may be, in order to fully leverage the intuitive benefits provided, businesses must establish, and effectively communicate, comprehensive acceptable Internet usage policies.

The effectiveness of employee monitoring directly relates to employees’ awareness of the content of the policy and corresponding breach consequences. Thus, organizations must develop appropriate policies, publish and communicate them so employees understand exactly what is expected of them and the conditions of their working environment.

Recent research clearly indicates substantial benefits in obtaining employee consensus regarding the organization’s monitoring activities. It is when employees do not fully comprehend the organizational motives and objectives behind monitoring activities that the relationship can turn sour. Trust between employees and the employing organization is imperative for employee wellbeing but also because of the potential economic savings derived from increasing trust. Research shows that there is an inverse relationship between cost and trust, thus, as trust increase costs decrease. It has been established that in organizations with high levels of trust, productivity consistently exceeds other businesses where trust is low or latent.

Do they trust me?
In recent years, organizations’ monitoring practices have raised increasing concern regarding individual privacy at work and employee trust. Research in the employee monitoring area has correspondingly attempted to understand the policy and monitoring program characteristics that can enhance employee acceptance, trust and thus effectiveness. It has been demonstrated that Internet and email monitoring systems designed to provide workers with performance feedback influences the monitored individual’s perception of fairness, satisfaction and task performance. Research also suggest that when monitoring work related activities, such as Internet usage, and allowing those who are being monitored the opportunity for feedback and input into the process can reduce fear of invasion of privacy and enhances procedural justice. Hence, employees feel affirmed if procedures are adopted to treat them with respect and dignity and the likelihood of acceptance is increased, even for outcomes they do not like.

Get everyone involved
Frequently IT Managers and Administrators are given the ultimate responsibility of managing, enforcing and communicating acceptable Internet usage for an entire organization. This approach warrants concerns and its effectiveness is questionable.

John Stewart, Chief Security Officer at Cisco, is one of many leading ICT professionals that have recognized the importance of mutual responsibility in organizational security. He recently made the following statement:

“What I’d rather never say is that a security team is responsible for security at a company... That means that 99 percent of the company somehow isn’t... I’d rather be helpful to the business, towards it understanding that we’re all responsible”.

It is apparent that here is an emerging trend in many countries where companies are recognizing that issues relating to inside threats need a two pronged attack – protection of the internal IT resources through reliable security systems and education of the workforce to drive responsible behaviour.”

TOP 5 TIPS FOR EFFECTIVE MONITORING AND OVERCOMING THE SOFT ISSUES

1. Allow a certain amount of online recreation
Allowing a certain amount of (monitored) online recreation can enhance many workplaces and ultimately make employees more productive.

2. Establish Acceptable Usage Polices
Establish policies around the use of the Internet and email and make staff aware that you are monitoring and reporting on usage. Ensure the amount of acceptable online recreation time is specified. This alone is an effective step towards reducing inappropriate usage, but if it’s not backed by actual reporting, employees will soon learn what they can get away with.

3. Allow Employees Access to their Individual Internet Usage Behaviour
Allow employee access to conduct their own ad-hoc analysis to view, for example, their productive and non-productive activity. This can help foster and drive responsible Internet usage behaviour. Employees who understand the organizational costs of their personal unproductive activities are more likely to accept the organization’s monitoring activities and modify their own behaviour.

4. Protect Employee Privacy
Most log analysis solutions, trying to address issues related to decreased productivity due to recreational surfing or illegal online activities, lack any protection of employee privacy. They provide open or shut access, meaning that anyone with access to their monitoring solution can view anyone else’s activity.

To protect employee’s personal data it is essential for organizations to use monitoring software that provide functionalities designed to protect employees’ privacy rights by only allowing authorized users to see the employee’s identity. For instance, Network Administrators may need to investigate all traffic going to a particular site but should not need to know the user names – in this case user names should be anonymous for them but available for HR.

5. Assign and Distribute Responsibilities
Identify roles and responsibilities for taking action on events, remembering that responsibility is not only the IT managers or security administrator’s domain. Distributing employee internet activity reports to managers or department heads will allow them to see how internet usage affects the security and performance of their own department and distributes the responsibility of enforcing acceptable usage with the managers themselves.

WebSpy is exhibiting at Infosecurity Europe 2009, the No. 1 industry event in Europe held on 28th – 30th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Courtesy of Infosecurity PR
<>

Five Steps to prevent terminated and unauthorized employees from accessing sensitive data

By Adam Bosnian – Director at Cyber-Ark

Redundancies and corporate re-organisations are an unfortunate reality in today’s economic climate. Too often, businesses leave themselves vulnerable to a data breach or serious security incident during the redundancy cycle by not immediately revoking the network and application access points of terminated employees.

Security threats from inside the organisation are not a new phenomenon, but layoffs and economic uncertainty can significantly exacerbate the problem. A recent Cyber-Ark survey, “The Global Recession and its Effect on Work Ethics,” found that 71 percent of the employees surveyed declared they would definitely take company data with them to their next employer. The study further stated that "Top of the list of desirable information is the customer and contact databases, with plans and proposals, product information, and access/password codes all proving popular choices.” Moreover, the “Jobs at Risk = Data at Risk” survey published by the Ponemon Institute, found that 59 percent of employees who were laid off, terminated, or who quit their jobs in the last 12 months admitted to stealing company data, and sixty-seven percent admitted to using their former company’s confidential information to leverage a new job.

When a security incident of this nature occurs, we tend to file it away as an example of an “employee gone bad.” In reality it constitutes a failure of the organisation to uphold their responsibility on behalf of the business to manage, control and monitor the power it provides to its employees and systems. At a basic level, the organisation and its management has a fiduciary responsibility to ensure that access to critical information and applications is authorised and that it is continually monitored to make sure the resulting activity is authorised as well. The failure stems from the ‘perception of control’ an organisation has over their most sensitive networks, systems and devices.

The threat to an organisation is increased exponentially when the access is through administrative, shared or privileged accounts – these represent the most powerful IT users in an organisation, often providing wide-ranging access to most systems, application or database within the enterprise. These privileged identities, which exist on virtually every one of the thousands of servers and applications within a typical enterprise, very rarely get changed, due to the presumed extra IT effort involved and the need to communicate the new settings to the IT staff, which if not done effectively could potentially impede or slow down an administrator doing a time-critical task.

This type of uncontrolled access can lead to dire situations. In fact, failure to control these privileged identities led to two of the more critical security incidents in the past year. Last year, the city of San Francisco was brought to its knees because an employee locked down the city’s IT system through a privileged account. And more recently, a Fannie Mae employee implanted a logic bomb on the company’s network because access to his privileged accounts was immediately revoked upon his termination.

If you’re concerned about this happening at your organisation, here are specific steps you can take to help prevent severe security incidents:

  1. Improve internal security controls around privileged accounts via encryption, password protection, and auditing of system access;
  2. Reduce the risk of internal data misuse by implementing policies and technologies which provide special treatment for privileged identities and ensure compliance with regulatory requirements;
  3. Ensure administrative and application identities and passwords are changed regularly, highly guarded from unauthorized use and closely monitored, including full activity capture and recording;
  4. Avoid sloppy habits when exchanging privileged and sensitive information, such as sending sensitive or highly confidential information via email or writing down privileged passwords on post-it notes;
  5. Ensure provisioning, and more importantly deprovisioning of user access in an immediate timeframe after employee status or role changes.
Remember, trust is not a security policy, and the damage that insiders can do should not be underestimated. To thwart this threat, the first big step is making that key decision to effectively manage these privileged accounts, and then doing so in a streamlined manner that makes it efficient and transparent to the user. Streamlining the management of privileged accounts by controlling who has access, when access was gained, what is being done with the sensitive data and why access is needed is critical in preventing a major security incident from occurring at your company.

The Author, Adam Bosnian is the Vice President of Products, Strategy and Sales at Cyber-Ark Software. He is responsible for the global product and business strategy of the company as well as for managing the North American sales organization and growing the business in this area.

For more information visit www.cyber-ark.com

Cyber-Ark on stand H90 will be exhibiting at Infosecurity Europe 2009, the No. 1 industry event in Europe held on 28th – 30th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Courtesy: Eskenzi PR
<>

Crashing Cars and Firewall Management – a similar chain reaction

by Calum Macleod, Regional Manager, Tufin Technologies

With all the doom and gloom of the past few months and billions of whatever currency you like being poured into the economy I have to report on a ray of hope. I think my son may have hit on the solution completely inadvertently. He’s not a renowned economist, just an honest, hard working car mechanic.

However having written off the fifth car in the last three years, although credit where it’s due, this time it was his fiancĂ©e that managed it, not only is he trying to save the motor industry single handedly but at the same time his insurance premiums have reached a level where he may be also saving the financial sector. Not only that, but out of sympathy I’ve had to break open the reserves and help finance number six which of course means that what money I had left is now circulating.

But what may you ask does this have to do with IT. Actually quite a lot because his latest accident triggered a chain reaction that we’re all too familiar with.

Firstly a lack of Risk Assessment resulted when according to his fiancĂ©e “a woman driver decided to stop on orange” with the result that she plowed into the back of the car. Mind you had the mechanic bothered fixing his brakes, as everyone was telling him to do, it all might have been avoided! And as is so often the case in IT security, improper risk assessment can have disastrous consequences. Not enforcing information security policies or firewall policies can very often result in failed audits, and network breaches, etc.

Secondly it had major business continuity impact. Having no car meant having to borrow somebody else’s car. Everybody was impacted. A very common problem in many organizations is the impact on day to day business because of errors being made in translating service requests into structured firewall changes ,or failing to adhere to information security policy, or placing firewall rules were they should not be, brings everything to a grinding halt.

Thirdly the failure to deal with the risk resulted in a problem, with the result that the financial impact on the family organization was significant. I’m not saying the accident would not have happened but had the brakes been working it might have resulted in what became a “right-off” being no more than a small dent. Bottom line failure to deal with the risk in order to save money eventually ended up costing a lot more than it should have.

So what should you do?

1. Use Automated Risk Assessment Tools – Fix The Brakes!

One of the key reasons why Risk Assessment is not done is simply that it is extremely time consuming if it is done manually. When I ask companies the question, the responses vary from “we have never done” a risk assessment to so far we’ve gotten away with it because the auditors have never asked!. Additionally it is surprising even among financial institutions that Auditors are not addressing this problem. This is likely to be due to the fact that they do not know what to look for. Relying on specialist consultancy companies to do this job for you can also be a very hit and miss affair because you are at the mercy of a consultant who may or may not have the necessary skills to do this. And in any case if they haven’t got the right tools the chances are they’re no better than anyone else.

The only effective way to really assess if your firewalls are protected is to use tools that are able to examine your firewall configuration based on known best practices. Additionally, the better tools allow the firewall administrator to address new vulnerabilities in real time. Since this process is fully automated it takes the manual, subjective approach away from this task and it ensures that you can analyze in minutes what would normally take weeks or months to do manually. And this has to be a continuing process.

2. Communicate with the business and know what are your business critical applications

Maybe not surprisingly but many IT administrators and firewall administrators do not know which applications are business critical. The result frequently is that either rules are left in firewalls because no one dares touch them, which in turn results in poor firewall performance. The other situation that often occurs is that rules or services are removed because they do not appear to be used. Again the problem is frequently due to the fact that manual processes are used to examine usage and very often services can be unused for months simply because the applications that use them are not run on a regular basis but may be business critical.

Again the only effective way to ensure you avoid these mishaps is to use technology. Firewall Policy Management technology allows an organization to define business critical applications so that any changes which impact these applications can be identified quickly. In fact some tools allow you to model scenarios before making changes. The modeling allows you to identify if a change will impact business continuity so that you can avoid making the errors in the first place.

Another key use of FPM tools is being able to translate business requests into actual changes. In a recent meeting a customer told me that they spent two days trying to activate a service for a client because they were not able to identify that changes were required on two firewalls to enable the service. An FPM tool that provides “What If” capability will ensure that all necessary changes are shown before implementation is necessary.

Rule Usage analysis is also a major problem without the proper tools. Administrators can very often take days to analyze a single rule because as rules move in the rule base, without automated tracking tools it is virtually impossible to follow the rules and their contents in a large rule base.

Choosing to deal with the risk or leaving it in the hope that it doesn’t happen to you is a choice you make. Not dealing with it is hoping that your colleagues don’t make mistakes. So like my son, if you’re going to let somebody else “drive” your firewall, you’d better be sure that the “brakes” are working.
www.tufin.com

Tufin is exhibiting at Infosecurity Europe 2009 on Stand J96, on 28th – 30th April at Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Courtesy of Eskenzi PR
<>

Latest US Internet crime report recommendations applicable to the UK

Infosecurity Adviser says US Internet crime report recommendations applicable to the UK

London, UK – 7th April 2009 - Tamar Beck, Group Event Direct, Infosecurity Europe and Infosecurity Adviser, the Web portal of the Infosecurity Europe show, says the recommendations of the recently released Internet crime report from the Internet Crime Complaint Center (IC3) in the US are highly applicable to the UK.

"The US report makes some very useful recommendations, especially in Appendix 2, when it talks about the best practices to prevent Internet crime," she said.

"We suggest that business users of the Internet download the report from the Internet and read through the recommendations, especially those that relate to business usage," she added.
According to Beck, comments such as not judging a company based on their `fancy Web site' are very appropriate to UK businesses, since it is now possible to assemble a very slick Web site using one of the several Internet site hosting kits now available.

This means, she explained, that it is perfectly possible for a rogue trader to create a Web site that purports to be a large and well established company, when in fact the site kit has cost the trader around 40 pounds including a year's Web site hosting.

Suggestions that firms do not place orders on the Internet unless the trader publishes their full address and phone number, she went on to say, are very valid.

A lot of Internet users, including businesses, she says, are unaware that any UK company with a Web site must publish this information on their pages, as well as on all emails sent out to customers.

This has been a provision of the Companies Act and has been in place since the start of 2007, she explained, adding that since 01/01/07, firms must include their full details on their Web sites and in their email footers, or face a hefty fine.

The recommendation that businesses try to obtain a physical address, rather than a Post Office box is also very valid, she said, adding that, although it costs upwards of 100 pounds a year to rent a PO box, it is common for firms to rent out their boxes to third party firms, so opening the door to possible fraud.

"It's also now possible to register a limited UK company electronically for 25 pounds or less, go to the bank and set up a free business bank account, and cash cash cheques immediately. Add in the ability to access card payments through a number of Internet services, and you have a perfect recipe for fraud," she said.

"Many companies trade quite legitimately on the Internet, but firms wanting to save money - especially in these tough economic times - may end up buying from a company whose prices look too good to be true. Our advice is to download this report, read it thoroughly and apply the recommendations on a company-wide basis," she added.

For a copy of the OC3 2008 Internet Crime report:
http://infosecurity.us/public_docs/2008_IC3_Annual%20Report_3_27_09_small.pdf

For more on the Infosecurity Adviser: http://www.infosecurityadviser.com

Neil Stinchcombe, Infosecurity PR
<>

New DLP Drive launched by Origin Storage

London, 7th April 2009 - Origin Storage, a leading manufacturer and distributor of IT storage solutions, has today announced the launch of their Amacom Data Locker. The Data Locker Secure Drive gives users peace of mind in the event that that their data storage device is lost or stolen. The data is secured by a 6-18 digit PIN number which is entered directly on the device itself. The Data Locker will be demonstrated on stand D57 at Infosecurity Europe from 28th – 30th April 2009 at Earls Court, London.

With security breaches and data loss stories frequently appearing in headlines, the need to secure data has become more essential in order to avoid such incidents. Data Locker allows the portable drive to mount an operating system only when the correct PIN has been entered on the LCD keypad. You can also use the LCD screen to change the Data Locker PIN, dismount the drive, toggle the encryption on or off, or wipe the drive clean.

The Data Locker utilizes a hardware based encryption chip to seamlessly encrypt and decrypt your data using military grade AES / CBC mode encryption.

The Data Locker will allow you to store and protect all of your highly sensitive data, and personal files. It is available in three different capacities, 160GB, 320GB and 500GB and will be a vital piece of equipment for local governments and businesses alike.

Andy Cordial, Managing Director at Origin Storage comments, “Data Locker is the first device of its kind with PIN protection and AES hardware encryption. High profile data loss is on the increase due to the large amounts of unprotected electronic data on the move in the public and private domain. The Data Locker can lock down your portable data and ensure safe transportation of your most sensitive information.”

Three different levels of security are available:

  • Data Locker Personal: Consumer and Education
  • Data Locker Pro AES: Corporate and Local Government
  • Data Locker Enterprise: Military and transportation of mission critical data
The Data Locker offers state of the art features which include:
  • Brute Force Attack Detect / Self Destruct Response
  • One touch drive erase for rapid re-deployment using admin password
  • Hardware Based Malware Detection / Deflection
  • Unattended Auto Lock Function
  • 100% Platform Independent Security and Authentication
  • Hardware Based AES Encryption (CBC mode)
  • No Software or pop-up password entry screens
The Data Locker® measures 3.13" x 5.11" x 0.91" (W x D x H)
Power Supply: Bus Powered Via USB Port
Compatible HDD: 2.5’’ SATA
Operating Systems: Windows 2000, XP, Vista & Mac OS 10+

Founded in 2001 and based in Hampshire, UK, Origin Storage Ltd. is fast becoming one of Europe's leading IT storage manufacturers. Its wide-ranging product portfolio includes branded hard disk drive solutions, RAID solutions and OEM parts.

Origin Storage is a main supplier for all Tier one manufacturers, providing matched storage upgrades and has held a Pan European Agreement with Dell™ for the past five years. The business has grown year on year and now supplies to main distribution and reseller partners across EMEA.

In January 2006 Origin Storage acquired the brand and assets of Amacom and began to manufacture the Amacom range of portable storage solutions including the Flip2disk, IOdisk and Portable Optical solutions. It is also a distributor for some of the most respected storage enclosure manufacturers and offers a full range of rack, desktop and RAID products and accessories.

The company’s emphasis on superior customer service, UK-based assembly and stock-holding that delivers competitive pricing and unbeatable turn-around times makes Origin Storage the ideal partner for all storage management needs.

Darshna Kamani, Eskenzi PR
<>

Infosecurity Europe says US national cybersecurity plans should be supported

London UK 3rd April 2009 - Infosecurity Europe says a bill just presented to the US Congress - which seeks to introduce mandatory security standards to private and public sector companies that control the critical infrastructure of the US - should be actively supported.

"The proposal to create a National Cybersecurity Advisor (NCA) position with direct reporting to the President will allow one person and their team to act as a focal point in the event of an electronic attack on the US infrastructure," said Tamar Beck, Group Event Director, Infosecurity Europe, "This is an important step in securing the cybersecurity of the US and is in keeping with President Obama's stated aim of securing the IT infrastructure of the United States," she added.

According to Beck, the NCA will have the power to shut down any aspect of the US infrastructure, such as power, telephony or environmental supplies, if an electronic attack takes place.

In addition, she says, the NCA would be able to enforce common security standards - such as those from National Institute of Standards and Technology - across the national infrastructure.
The plan with the NCA program, she explained, is to create state and regional cybersecurity centres that will provide local advice to businesses, as well as working with universities to supply - and tap - their educational resources.

In parallel with the creation of the NCA position and team, Beck said that the bill seeks to create a Cybersecurity Advisory Panel made up of representatives from the private and public sector, with the eventual aim of licensing cybersecurity professionals.

"This really is excellent news, since it creates a private-public framework that will foster IT security education and professionalism at all levels," she said.

"In time, not only will the national US infrastructure be much better protected, but we could even see a better understanding of the need for cybersecurity amongst all Internet users. And that is no bad thing," she added.

For more on the US Cybersecurity bill: http://preview.tinyurl.com/dyeudq

Infosecurity Europe, running for its 14th year in 2009, is Europe’s number one Information Security event. Featuring over 300 exhibitors, the most diverse range of new products and services, an unrivalled education programme and visitors from every segment of the industry, it is the most important date in the calendar for Information Security professionals across Europe. Infosecurity Europe is one of five Infosecurity events around the world with events also running in Belgium, Netherlands, Russia, and France. Infosecurity Europe runs from the 28th – 30th April 2009, in its new venue Earls Court, London. To register to attend or for more information please visit www.infosec.co.uk

Neil Stinchcombe, Eskenzi PR
<>

‘Classified Information’ … Can companies learn from Government?

Dr. Bernard Parsons, CEO, BeCrypt.

Historically, Governments has well understood the need for data classification as a tool for protecting information. The UK Government has a well established scheme of protective marking that applies from state secrets, to information that would cause only embarrassment if lost. However, systems and processes that have worked well for decades, have failed to meet today’s demands. In the UK Ministry of Defence report commissioned following last year’s data losses, Sir Edmund Burton describes how the well developed processes ingrained during the Cold War have not translated in to the Information Age.

The mind set of today’s “Face book Generation” is as applicable to the Public Sector as it is elsewhere, and they expect easy access to and sharing of data. However, even for those familiar with technology, security risks are non-intuitive: a single CD struggles to command the same respect as a box of paper personnel records.

The UK Government data security policies have historically prioritised confidentiality at the expense of availability and data integrity, with this in-balance frequently detracting from system usability. At the same time, there has been a growing need to store personally identifiable information. Much of this data has not fitted within existing data classification regimes, and significantly, there has been little inclination to consider the impact of the accumulation of large quantities of such data. As a consequence, many systems at the lower end of data sensitivity have not had adequate safeguards (both system and procedural) in place, creating a new and arguably more significant Information Assurance challenge to Government. Gartner highlight the relevance of this to the private sector by stating ‘Organizations that do not have an effective data classification program usually fail at their data encryption projects’.

A “critical mass” of public sector data breaches occurred in the UK around the beginning of ’08, typically relating to personal data, after which, events that would previously have gone un-noticed, caused public dismay. This provided a catalyst for change that has been seized upon by the Information Assurance community to drive home widespread improvements. Recognition that the solution was cultural and not prescriptive has lead to the establishment of a risk management culture aimed at rebuilding the citizens’ confidence in the storage and management of their data.

The risk management culture has involved a shift in focus from protective marking, to the consideration of business impact levels. This encourages consideration of the value of data; risks associated with loss of confidentiality, integrity or availability; and the corresponding impact to the business. With an inclusion of data accumulation and aggregation elements, personal data can now be required to receive the same treatment previously reserved for higher levels of classification.

A set of new minimum mandatory measures including reporting and compliance mechanisms is described within the recently published Government Security Policy Framework. As a public domain document, this replaces the protectively marked Manual of Protective Security. This underlines a new level of openness, as well as illustrating the increasing similarity in data and risks to data across the public and private sectors. A public domain Information Assurance Maturity Model has been published by Government, providing a practical framework for IA compliance. This is consistent with and builds upon existing standards and regulation relevant to the private sector, such as ISO 27001 and the UK Data Protection Act.

There is increasing commonality between assurance schemes for technological solutions between public and private sectors, allowing products to be developed and deployed for common goals. This factor assists in keeping solution costs low for Government. This is key, as the requirement for departments to comply has not been accompanied by additional budget.

An example of a common goal addressed at low-cost relates to the mandatory requirement to provide “Urgent consideration ….of simple, affordable solution to enable the safe, authorised, use of privately owned computers for limited Government tasks..”.

Through an agile public-private consultation process, technology has been developed and certified to allow the secure use of un-managed machines for remote working. CSC is an example of an organisation using this and Virtualisation technology to allow dynamic secure remote access to corporate resources.

Irrespective of the need to protect national secrets, intellectual property or personal information, today’s technology has placed similar demands on all sectors, and each sector has provided examples of best and worst practice. The UK Government reacted with a framework to encourage a culture change. This contains effective guidelines that are open to review by all, the lessons for Corporations are there to be learnt and adopted.

BeCrypt is exhibiting at Infosecurity Europe 2009, the No. 1 industry event in Europe held on 28th – 30th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Source: InfosecurityPR
<>

Security Implications Of The Virtualised Datacentre

By Bill Beverley - Security Technology Manager, F5 Networks

Introduction
The concepts behind application and operation system virtualisation are not new. The recent rate of virtualisation adoption however, especially that of software operating system virtualisation, has grown exponentially in the past few years. Virtual machines have finally come into their own, and are quickly moving into the enterprise data centre and becoming a universal tool for all people and groups within IT departments everywhere.

So what exactly is a virtual machine? VMware defines a virtualisation as “an abstraction layer that decouples the physical hardware from the operating system...”. Today, we commonly think of virtual machines within the scope of one hardware platform running multiple software operating systems. Most often this concept is implemented in the form of one operating system on one hardware box (the host platform) running multiple independent operating systems on virtual hardware platforms in tandem (the guests).

Platform virtualisation usually relies on full hardware segmentation: allowing individual guest platforms to use specific portions of the physical host hardware without conflicting or impacting the host platform, allowing the host and guest(s) to run in tandem without stepping on top of each other.

There are two primary types of platform virtualisation: transparent and host-aware. Transparent virtualisation is implemented so that the guest is not aware that it’s running in a virtualised state. The guest consumes resources as if it were natively running on the hardware platform, oblivious to the fact that it’s being managed by an additional component, called the VMM (Virtual Machine Monitor), or hypervisor. The more standard forms of virtualisation today, such as those by VMware, implement transparent hypervisor systems. These systems can be thought of as proxies: the hypervisor will transparently proxy all communication between the guest and the host hardware, hiding its existence from the guest so the guest believes it’s the only system running on that hardware.

Host-aware implementations differ in that the guest has some form of virtualised knowledge built into the kernel. There is some portion of the guest operating system kernel that knows about the existence of the hypervisor and communicates with it directly. Xen (pronounced ‘zen’), a popular virtualisation implementation for Linux, uses a host aware architecture, requiring special hypervisor command code actively running in both the host and all running virtualised guests.

One of the driving factors in virtualisation adoption is the open nature of hardware support for VMMs: Hardware platforms, which run and manage the primary host operating system, and the VMM are not specialized devices or appliances. This flexibility, the move of virtualisation software to everyday hardware, has allowed everyone direct and inexpensive access to run virtualised environments. Virtualisation allows a company to purchase one high end hardware device to run 20 virtual operating systems instead of purchasing 20 commoditized lower-end devices, one for each single operating platform.

Virtualised Threat Vectors
The benefits of virtualisation are obvious: more bang for your buck. But everything has a pro/con list, and virtualisation is no exception. The pro column is a large one, but the con list isn’t so obvious. What could be bad about running 20 servers for the price of one? Although by no means considered to be a large threat today, security of virtual machines and environments is typically not considered, not because the security of these implementations is a technological mystery, but because it is generally an unknown vector by the groups that are implementing wide-spread virtualisation. In other words, virtualisation is usually implemented with no specific regard to the new security risks it brings.

Virtualisation brings an entire new set of security issues, problems, and risks. Security administrators are familiar with phrases such as “hardened operating system,” “walled garden,” and “network segmentation” in the one-box-for-one-application world, but how do administrators apply these concepts to the uncharted waters of the virtual data centres? How can we protect ourselves in new environments we don’t understand? Today’s system and security administrators need to begin focusing on virtual security, preparing for a new threat arena for distributed and targeted attacks.

There are many, many security risks and considerations that virtual infrastructure administrators should be aware of and prepared for, many of which were not covered in this discussion. And there are many questions that still need to be addressed before moving to a fully virtualised environment, such as:

  • How will our current analysis, debugging, and forensics tools adapt themselves to virtualisation?
  • What new tools will security administrators be required to master between all of the virtualisation platforms?
  • How does patch management impact the virtual infrastructure for guests, hosts, and management subsystems?
  • Will new security tools, such as hardware virtualisation built into CPUs, help protect the hypervisor by moving it out of software?
  • How will known security best practices, such as no-exec stacks, make a difference when fully virtualised? Will hardware virtualisation pave the way to a truly secure VMM?
  • Virtualisation and shared storage: What happens if we virtualised all the way down to the iSCSI transport layer? Are we opening up a floodgate which bypasses built-in SAN security?
These are all questions that need to be addressed before the enterprise world moves full-on into virtualisation. More than anything, we should be thinking today about where virtualisation security will take us tomorrow. We all agree that virtualisation is for the better and it’s here to stay, but security administrators need to make sure they keep ahead of the threats and think about virtualised threat vectors before attackers have already coded for them.

F5 Networks is exhibiting at Infosecurity Europe 2009, the No. 1 industry event in Europe held on 28th – 30th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Source: Infosecurity PR
<>