- Anti-virus software
- Firewalls
- Spam filtering
- Virtual Private Networks - VPN
- Web content filtering/monitoring
- Intrusion Detection Systems - IDS
- Anti-spyware software
- Directory servers
- Encryption
- Intrusion Prevention Systems - IPS
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Tuesday, February 10, 2009
Top 10 Security Technologies
This top ten list may not appear on Letterman's Late Night Show but it's interesting for the enterprise computer environment - the ten most popular security technologies have been identified in Deloitte's 6th Annual Global Security Survey, as referenced by Baseline magazine:
Thursday, January 22, 2009
Windows Infection - Possible Botnet
The worm has a few names - the most common are: Downandup, Downadup, Conficker. The underlying problem (vulnerability) was found some time ago and Microsoft released an update in mid October. The worm came about by the turn of the year and the infection rate has been something extraordinary - estimated at about 9 million about a week ago.
It's not terribly hard to fix an infection with removal tools provided by a number of companies but the purpose of this worm in unclear and it has a remote-control mechanism. Consequently, the worm can produce a very large botnet. Huge. Much bigger than anything we have seen.
The original infection was somewhat new by installing from memory devices and tricking the user to actually do the installation. The worm is then spread automatically from the infected machine.
The worm is a mutating code piece of code - this is not a new technique but it's used to disguise the control mechanism making it harder to shutdown. The worm is also packed with self-defense measures making modifications to security and network settings.
Now what? Well, we'll see if the worm will in fact be used to marshal a botnet. If so, this sucker may pump a good deal of spam or conduct other mischief such as powerful distributed-denial-of-service (DDoS) attacks.
It's not terribly hard to fix an infection with removal tools provided by a number of companies but the purpose of this worm in unclear and it has a remote-control mechanism. Consequently, the worm can produce a very large botnet. Huge. Much bigger than anything we have seen.
The original infection was somewhat new by installing from memory devices and tricking the user to actually do the installation. The worm is then spread automatically from the infected machine.
The worm is a mutating code piece of code - this is not a new technique but it's used to disguise the control mechanism making it harder to shutdown. The worm is also packed with self-defense measures making modifications to security and network settings.
Now what? Well, we'll see if the worm will in fact be used to marshal a botnet. If so, this sucker may pump a good deal of spam or conduct other mischief such as powerful distributed-denial-of-service (DDoS) attacks.
Friday, January 2, 2009
Watch Out with Secure Certificates
You may have heard it, there is a problem with an aspect of SSL - namely MD5 hashes. The practical implication - it's possible for an attacker to "impersonate" a site with what would appear to be a valid https certificate or eavesdrop on the traffic (MiM - Monkey in the Middle). Vulnerabilities in MD5 have been known for years but exploiting this has now been done and demonstrated in public.
The problem and the remedy for rest with the Certificate Authorities (CA) issuing and verifying certificates. The fix is simply to use the SHA1 hashes instead and that is already done in many cases but the problem is that as long as MD5 hashes are accepted is there a risk that a false MD5 hash can be used.
How easy is this to do? Well, it requires some effort - the demonstration in Berlin involved 200 Playstatation3 machines working for a few days. Of course, any kind of computer power can be used for this kind of work, even (and maybe in particular) rough computer power such as hijacked computers forming bot nets.
It's noteworthy that other things relying on SSL, besides https certificates, may be affected such as SSL VPNs.
The problem and the remedy for rest with the Certificate Authorities (CA) issuing and verifying certificates. The fix is simply to use the SHA1 hashes instead and that is already done in many cases but the problem is that as long as MD5 hashes are accepted is there a risk that a false MD5 hash can be used.
How easy is this to do? Well, it requires some effort - the demonstration in Berlin involved 200 Playstatation3 machines working for a few days. Of course, any kind of computer power can be used for this kind of work, even (and maybe in particular) rough computer power such as hijacked computers forming bot nets.
It's noteworthy that other things relying on SSL, besides https certificates, may be affected such as SSL VPNs.
Tuesday, May 27, 2008
The State of Web 2.0 in the Enterprise
eWeek (May 19, 2008) published a survey on Web 2.0 deployments and plans for such technologies among enterprise IT managers. The population was somewhat limited (282 individuals) but it made some interesting findings.
It's apparent that the current deployments focus more on internal staff than the needs of the customer.
Blogs (49%), wikis (48%), and RSS (43%) were listed as the most deployed technologies. Social networks come as the forth technology (27%) but was viewed with some level of concern.
Security (41%) and concerns for leaks of sensitive company information (35%) were listed as the two top worries when pursing these technologies.
The article correctly concludes that there are no particular security concerns with these technologies. They add some complexity and a few new attack techniques will probably crop up but, while security concerns may be warranted, is it a more fundamental matter.
It's apparent that the current deployments focus more on internal staff than the needs of the customer.
Blogs (49%), wikis (48%), and RSS (43%) were listed as the most deployed technologies. Social networks come as the forth technology (27%) but was viewed with some level of concern.
Security (41%) and concerns for leaks of sensitive company information (35%) were listed as the two top worries when pursing these technologies.
The article correctly concludes that there are no particular security concerns with these technologies. They add some complexity and a few new attack techniques will probably crop up but, while security concerns may be warranted, is it a more fundamental matter.
Subscribe to:
Posts (Atom)
