Monday, June 19, 2006

Network Security Solution can be deployed non- intrusively

CleanTraffic(TM) defends enterprises and service providers from targeted DDoS attacks, active zombies, and rapid malware. Within hours of deployment, product automatically learns about all network endpoints and detects, tracks, and mitigates outside-in or inside-out attacks to or from any endpoints. Solutions can be deployed using appliances that scale from 1 Gbps of traffic for smaller organizations, to over 10 Gbps of traffic for very large organizations.

PALO ALTO, Calif., March 20 / -- netZentry, a leader in advanced network security today announced the immediate availability of CleanTraffic(TM), a breakthrough solution designed to defend enterprises and service providers from the triple threat of targeted DDoS attacks, active zombies, and rapid malware. Unlike other forms of network attacks, triple threat attacks are signature-less, have zero-day characteristics, and are distributed in nature. These attacks cannot be effectively solved by traditional security offerings, including Intrusion Prevention Systems (IPS) and Application Firewalls.

netZentry's CleanTraffic(TM) solution uses patented technology to detect, track, and mitigate all forms of triple threat. CleanTraffic is deployed non- intrusively, as a sideline device, without disrupting existing infrastructure or affecting network performance. Within hours of deployment, CleanTraffic automatically learns about all the endpoints of the network, detects, tracks, and mitigates outside-in or inside-out attacks, to or from any of the endpoints. These include many-to-one DDoS attacks, one-to-many malware outbreaks, and active zombie traffic. CleanTraffic features a powerful, unified, real-time user-interface that simplifies defense management by providing rich analytics on a per-endpoint basis. CleanTraffic solutions are deployed using appliances that scale from 1 Gbps of traffic for smaller organizations, to over 10 Gbps of traffic for very large organizations.

"Enterprises and service providers alike are very vulnerable to the triple threat. These attacks, if not stopped, can result in substantial loss of revenue because of either loss of productivity or loss of customers caused by the outages. CleanTraffic is the only complete solution that detects triple threat attacks, and also neutralizes them before they can cause damage," said Vasu Vasudevan, President and CEO of netZentry.

The CleanTraffic solution is versatile and offers value to several market segments. For example, it enables service providers to protect not only their infrastructure but also their customers from outside-in DDoS attacks.

"The intuitive user interface and the attack mitigation capabilities of netZentry's CleanTraffic product make it easy for us to both save money and sleep better at night," said Ethan Burnside, Principal at Kattare Internet Services.

Chris Shaffer of 1-800-HOSTING added, "The CleanTraffic solution also helps detect active zombies within internal networks as has been the case at 1-800-HOSTING. netZentry's CleanTraffic products allow us to maintain a greater level of service availability during attacks by filtering the malicious traffic both to and from our customers' environment, allowing their businesses to continue uninterrupted."

Wednesday, June 14, 2006

The coast is clear: security software lets you know who's on the network

Getting your Wi-Fi equipment set up for security isn't as troublesome as it once was, but it can still be a headache. That's where software like Interlink Networks' LucidLink (www.lucidlink.com) comes in, offering enterprise-strength security for small and midsize businesses.

Ease of use is a must, and LucidLink gets good marks in that area. The only major hardware requirement is a computer wired to your router to run the authentication server part of the package. That computer has to be on whenever you want to use the software, but it doesn't have to be dedicated to the task. A small client program is then installed and configured on each computer you want to connect to your wireless network. The administrator authorizes users and can keep track of who is accessing the network.

LucidLink supports automatic access-point configuration for some devices. For other devices, you might have to manually configure your access point or router following instructions available online. Check the website to see if your hardware is supported. LucidLink is free for three or fewer users. Otherwise, pricing starts at $549 for four to 10 users.

Friday, June 09, 2006

Network security tools

Assuming familiarity with C, Perl, and the use of assessment tools, this guide introduces techniques for modifying open source assessment tools and testing security vulnerabilities in networks and web applications. The authors, who are managers at Ernst & Young's advanced security center, discuss Nessus, Ettercap, Hydra, Nikto, the Metasploit framework, the PMD tool, Linux kernel modules, network sniffers, and packet injectors.

Saturday, June 03, 2006

Hiring Network Security Professionals

The most important qualification for any security professional to have is experience. Five or more years of experience directly related to security is enough to have seen the trends, understand the mind-set of hackers, and see the common uses and mis-uses of networks.

With the high demand for network security professionals, and the drought of experienced candidates, businesses have been willing to settle for less experienced candidates. A number of organizations have assembled training courses and certification exams to help bring novices to a reasonable level of security understanding.

Certifications

There are a number of certifications offered for security professionals. No one standard has been generally accepted throughout the community, and it will be a while before one emerges at the top of the heap. The top contenders are:

* CISSP. This exam is considered to be the most difficult, and most comprehensive security exam.
* Security+. This exam was developed jointly between government, educational and business. It tests many important aspects of the security professional's knowledge.
* TICSA. Offered by TruSecure, a security services vendor, this exam is being heavily promoted. Check for discounts on exam fees.
* SANS GIAC Certification. The Global Incident Analysis Center offers a baker's dozen certifications in the security arena. These certifications are, for the most part, vendor neutral. However, they do offer Unix and Windows specific certifications.

There are a number of vendor-specific exams. These include some for Cisco and Microsoft. In general these exams only show competence in implementing and using vendor-specific hardware and network architectures, and are not broad enough for most business security needs.

Above all, ensure that any security professional you are looking to retain has substantial experience and good references. Look at what they've done for other companies similar to yours, how many years of experience they have and get references.

Sunday, May 28, 2006

An Open Door To Your Home Wireless Internet Network Security?

This is not some new fangled techno-speak, it is a real tool to be used for the protection of your wireless internet network and LAN. African American SMBs have to realize that if your Internet connection is on 24/7 then your network, and it is a network that your computer is connected to, is at risk. Any business that uses the Internet to share or exchange information, news, or ideas with clients, vendors, partners, or other locations look in the reflection of your monitor and realize that your business is an unintentional (or intentional) target.

You should already be aware of all the thousands of bugs, viruses, denial of service attacks and other unfriendly items that lurk on the internet and virtually try attacking every second. It's like having a screen door on your most valuable assets. Let's not repeat what you know about, let's look at a larger picture that should concern everyone - the unknown. There are attacks that go unreported for various reasons, these are the ones that the major software and hardware vendors have no clue about and can only warn you after an attack is reported.

If your files, email, identity, client or product information are important to your african american business and you cannot afford a network being down for 24 hours. Then a firewall is what should be between the internet and everything else. You need to expect an intrusion if you have a small amount or no network protection. Hackers have tools that search the Internet 24/7 looking for a vunerable point to destroy. Overzealous marketers use similar tools to harvest information to use for spamming and unfortunately no one currently calls that a crime that we know as identity theft.

Monday, May 22, 2006

Internet/Network Security

1 Introduction

Many security experts would agree that, had it not been for voice-over-IP, the simulation of the transistor might never have occurred. On the other hand, robots might not be the panacea that computational biologists expected [15]. Next, the basic tenet of this approach is the simulation of the Ethernet. Such a claim at first glance seems counterintuitive but has ample historical precedence. On the other hand, extreme programming alone cannot fulfill the need for embedded modalities.

Two properties make this solution different: our algorithm is based on the deployment of the Turing machine, and also our framework is copied from the principles of e-voting technology. The usual methods for the improvement of reinforcement learning do not apply in this area. In the opinions of many, the basic tenet of this solution is the development of rasterization. It should be noted that Eale explores thin clients. Obviously, we validate that the infamous multimodal algorithm for the development of e-commerce by Kobayashi et al. [14] is Turing complete.

We explore a novel solution for the emulation of DHCP, which we call Eale. daringly enough, we view software engineering as following a cycle of four phases: management, storage, visualization, and synthesis. Even though conventional wisdom states that this issue is mostly overcame by the refinement of I/O automata, we believe that a different approach is necessary. It should be noted that Eale synthesizes Bayesian information. Combined with the partition table, such a hypothesis evaluates a flexible tool for controlling Boolean logic.

Our contributions are twofold. Primarily, we describe new extensible models (Eale), which we use to confirm that voice-over-IP can be made mobile, Bayesian, and scalable. We explore an application for Byzantine fault tolerance (Eale), verifying that the well-known wireless algorithm for the refinement of cache coherence by Lee [16] runs in W(n!) time [1].

The rest of this paper is organized as follows. We motivate the need for erasure coding. Further, to realize this purpose, we confirm not only that local-area networks and voice-over-IP are largely incompatible, but that the same is true for evolutionary programming. Third, to address this issue, we motivate a novel algorithm for the emulation of simulated annealing (Eale), which we use to show that red-black trees can be made heterogeneous, modular, and event-driven. On a similar note, to achieve this purpose, we discover how lambda calculus can be applied to the understanding of journaling file systems. In the end, we conclude.

2 Related Work

While we are the first to explore active networks in this light, much existing work has been devoted to the improvement of multi-processors [3]. Although Christos Papadimitriou also constructed this method, we studied it independently and simultaneously. Unfortunately, these approaches are entirely orthogonal to our efforts.

We now compare our solution to prior autonomous theory solutions [2]. J. Smith [21] originally articulated the need for symbiotic epistemologies. This is arguably fair. The original approach to this question by Wilson and Maruyama [24] was good; however, this finding did not completely fulfill this goal. Further, Watanabe suggested a scheme for controlling the improvement of access points, but did not fully realize the implications of optimal epistemologies at the time. In this position paper, we surmounted all of the obstacles inherent in the previous work. A recent unpublished undergraduate dissertation proposed a similar idea for introspective symmetries [10,4,17,18,12]. The original solution to this quandary [23] was considered typical; on the other hand, this did not completely surmount this grand challenge [19]. This solution is even more costly than ours.

Eale builds on related work in self-learning configurations and algorithms. Along these same lines, Bose and Zheng introduced several stochastic methods, and reported that they have profound impact on multi-processors [6,9,8]. Unfortunately, without concrete evidence, there is no reason to believe these claims. Along these same lines, Martinez developed a similar heuristic, on the other hand we validated that our approach is maximally efficient [20]. Further, Wu et al. developed a similar system, unfortunately we validated that Eale follows a Zipf-like distribution [23]. As a result, the system of Watanabe and Wilson is a private choice for adaptive symmetries [17].

3 Eale Investigation

Consider the early architecture by J. Lee et al.; our design is similar, but will actually answer this question. We hypothesize that each component of Eale locates knowledge-based algorithms, independent of all other components. Similarly, we assume that each component of our application emulates virtual communication, independent of all other components. This is a compelling property of our application. The question is, will Eale satisfy all of these assumptions? Unlikely.

Figure 1: A design plotting the relationship between Eale and interposable information.

We executed a trace, over the course of several months, verifying that our methodology is unfounded [16]. We consider a framework consisting of n robots. Along these same lines, we hypothesize that each component of our methodology prevents encrypted modalities, independent of all other components. We use our previously visualized results as a basis for all of these assumptions.

Figure 2: A novel system for the analysis of robots.

Reality aside, we would like to simulate a framework for how our algorithm might behave in theory. We executed a trace, over the course of several years, demonstrating that our framework is unfounded. We show the diagram used by Eale in Figure 1. We postulate that each component of our algorithm emulates homogeneous symmetries, independent of all other components. Along these same lines, we consider a framework consisting of n checksums.

4 Implementation

In this section, we construct version 7b of Eale, the culmination of years of programming. Continuing with this rationale, it was necessary to cap the complexity used by Eale to 968 connections/sec. It was necessary to cap the interrupt rate used by Eale to 4756 celcius. The codebase of 41 Simula-67 files and the centralized logging facility must run in the same JVM. Next, since Eale runs in Q(logn) time, programming the centralized logging facility was relatively straightforward. We plan to release all of this code under BSD license.

5 Results

We now discuss our evaluation. Our overall evaluation seeks to prove three hypotheses: (1) that USB key speed behaves fundamentally differently on our decommissioned Commodore 64s; (2) that tape drive space is more important than an application's effective API when optimizing energy; and finally (3) that scatter/gather I/O has actually shown weakened median time since 2001 over time. Only with the benefit of our system's ROM speed might we optimize for simplicity at the cost of security. Second, the reason for this is that studies have shown that mean power is roughly 43% higher than we might expect [5]. Third, our logic follows a new model: performance might cause us to lose sleep only as long as scalability constraints take a back seat to average sampling rate. Our evaluation approach holds suprising results for patient reader.

5.1 Hardware and Software Configuration

Figure 3: The mean distance of our system, as a function of instruction rate. This follows from the visualization of DHCP.

Many hardware modifications were mandated to measure our heuristic. We performed a quantized prototype on Intel's metamorphic testbed to quantify symbiotic communication's influence on G. Sundararajan's visualization of DNS in 1980. we removed 3MB/s of Internet access from our network to quantify the randomly symbiotic behavior of random communication. Configurations without this modification showed exaggerated median signal-to-noise ratio. We added some FPUs to our XBox network to understand the effective RAM space of our sensor-net testbed. Third, we tripled the effective tape drive space of our network [1]. In the end, we removed 10MB of NV-RAM from our probabilistic cluster to better understand CERN's desktop machines. Had we emulated our network, as opposed to simulating it in hardware, we would have seen improved results.

Figure 4: The average distance of our methodology, as a function of throughput.

Eale runs on patched standard software. Our experiments soon proved that interposing on our SCSI disks was more effective than reprogramming them, as previous work suggested. This is an important point to understand. our experiments soon proved that exokernelizing our exhaustive sensor networks was more effective than monitoring them, as previous work suggested. We note that other researchers have tried and failed to enable this functionality.

5.2 Dogfooding Eale

Figure 5: These results were obtained by Wilson [7]; we reproduce them here for clarity. Our purpose here is to set the record straight.

We have taken great pains to describe out evaluation setup; now, the payoff, is to discuss our results. We ran four novel experiments: (1) we dogfooded our algorithm on our own desktop machines, paying particular attention to flash-memory throughput; (2) we dogfooded Eale on our own desktop machines, paying particular attention to RAM throughput; (3) we dogfooded Eale on our own desktop machines, paying particular attention to effective ROM throughput; and (4) we asked (and answered) what would happen if opportunistically lazily wireless linked lists were used instead of Lamport clocks [22]. We discarded the results of some earlier experiments, notably when we deployed 08 UNIVACs across the underwater network, and tested our access points accordingly.

We first shed light on all four experiments as shown in Figure 5. The key to Figure 4 is closing the feedback loop; Figure 4 shows how Eale's work factor does not converge otherwise. Second, we scarcely anticipated how wildly inaccurate our results were in this phase of the evaluation. Note the heavy tail on the CDF in Figure 4, exhibiting exaggerated latency.

We have seen one type of behavior in Figures 4 and 4; our other experiments (shown in Figure 3) paint a different picture. Note how emulating Web services rather than simulating them in hardware produce less discretized, more reproducible results. Along these same lines, the results come from only 2 trial runs, and were not reproducible. Along these same lines, operator error alone cannot account for these results.

Lastly, we discuss experiments (3) and (4) enumerated above. Gaussian electromagnetic disturbances in our 1000-node testbed caused unstable experimental results. Furthermore, the curve in Figure 3 should look familiar; it is better known as h*Y(n) = logloglogn. Error bars have been elided, since most of our data points fell outside of 27 standard deviations from observed means.

Thursday, May 18, 2006

3 Ways Computers Can Hurt Your Ministry - Part 2 - Weak Network Security

Our computers have become almost indispensable ministry tools. What would you do if the worst happened and you had to function without your computers? Would your ministry survive?

This article is the second in a 3-part series on how to protect your ministry from serious computer-related loss. This time we’re going to focus on the basics of securing your network against potential inside and outside threats. In the final installment, we’ll cover what every ministry should know about software license compliance.

Good network security is an area many people in ministry neglect, simply because it can be so overwhelming. Even though there are lots of technical details involved with adequately securing your ministry’s network, if you focus on the handful of key areas presented in this article, you can prevent many of the potential threats you might face.

Passwords

The cornerstone of securing your network is to make sure you use strong, secure passwords. This is your first line of defense, and it’s often the weakest link in the chain. If someone can guess your password, they can impersonate you on the network and get to everything you have access to. Even worse, a hacker can use your password to try to “escalate” his level of access and possibly take over the whole network. Most ministries would suffer great loss if sensitive data (like donor information) was leaked out to the Internet by a hacker or disgruntled employee. Making sure your passwords are secure will help prevent this from happening.

Start by putting a password policy in writing. Some good practices to include in the policy are:

•Make all passwords at least 6 characters long, and require a mixture of numbers & upper/lowercase letters. They should be hard to guess, but still pretty easy for the users to remember.

•Require everyone to change their passwords on a regular basis and enforce a password history. This keeps users from recycling their old passwords again and again.

•Make sure no one writes their password on a “sticky note” and posts it in plain sight. This is a common security problem, and it’s almost as bad as having no password at all.

A good IT consultant can help with more suggestions, and these items can all be automatically enforced by your servers, so that everyone on the network will be protected.

Security Updates and Patches

Have you ever noticed that annoying message popping up at the bottom of your computer screen saying “New Updates Are Ready to Install”? Have you ever been tempted to ignore it? Don’t! Every month Microsoft releases security updates for many of their products, and the only way to stay secure is to install them faithfully.

As soon as software companies become aware of security problems, they release patches and updates to correct the issues. It’s your responsibility to download and install the patches so your system will stay up-to-date. I recommend configuring Automatic Updates on all your machines so this process will happen automatically. In a server environment, installing the latest updates can be automated for all your computers and managed from a central location. Just like maintenance on your car, you should plan to apply security patches and updates regularly to keep out potential hackers and viruses.

Monday, May 15, 2006

Firewall

If your ministry uses a dedicated high-speed Internet connection, make sure you have a good firewall in place. This device serves as a barrier to keep hackers out of your internal network. You would never dream of leaving your building at night without locking all the doors, and you should always make sure that the “doors” to your computer network are locked, as well. There are hardware and software firewalls available, but we usually recommend purchasing a hardware-based firewall for security and reliability reasons. Some good firewall manufacturers to check into include Cisco, SonicWall and WatchGuard.

Regular Security Audits

Another benefit of having a relationship with a good IT consultant is that they can perform ongoing security audits on your ministry network. Securing your passwords and applying all the current updates will help, but to make sure everything is locked down you should perform a thorough security audit at least once a year.

A competent, trusted IT consultant can approach your network like a hacker would, using many of the same hacker tools and techniques. He or she can try to penetrate your Internet firewall, test the strength of your passwords, verify the physical security of your data and backups, scan your whole network for security holes and vulnerabilities and provide a detailed report of the findings. They will also be able to give you recommendations and cost estimates on what it would take to fix any issues they find and thus increase the security of your ministry’s network.

Making sure your network is secure is still only another part of the solution. In the final installment of this series we’ll talk about some simple steps you can take to protect your ministry from huge fines and potential prosecution by making sure you comply with software licensing laws.

Monday, May 08, 2006

Network Security 101

As more people are logging onto the Internet everyday, Network Security becomes a larger issue. In the United States, identity theft and computer fraud are among the fastest rising crimes. It is important to protect your network and ensure the safety of all computers and users in that network.

What is a Network?

In order to fully understand network security, one must first understand what exactly a network is. A network is a group of computers that are connected. Computers can be connected in a variety of ways. Some of these ways include a USB port, phone line connection, Ethernet connection, or a wireless connection. The Internet is basically a network of networks. An Internet Service Provider (ISP) is also a network. When a computer connects to the internet, it joins the ISP’s network which is joined with a variety of other networks, which are joined with even more networks, and so on. These networks all encompass the Internet. The vast amount of computers on the Internet, and the number of ISPs and large networks makes network security a must.

Common Network Security Breeches

Hackers often try to hack into vulnerable networks. Hackers use a variety of different attacks to cripple a network. Whether you have a home network or a LAN, it is important to know how hackers will attack a network.

One common way for a hacker to wreak havoc is to achieve access to things that ordinary users shouldn’t have access to. In any network, administrators have the ability to make certain parts of the network “unauthorized access.” If a hacker is able to gain access to a protected area of the network, he or she can possibly affect all of the computers on the network. Some hackers attempt to break into certain networks and release viruses that affect all of the computers in the network. Some hackers can also view information that they are not supposed to see.

Destructive Attacks

There are two major categories for destructive attacks to a network. Data Diddling is the first attack. It usually is not immediately apparent that something is wrong with your computer when it has been subjected to a data diddler. Data diddlers will generally change numbers or files slightly, and the damage becomes apparent much later. Once a problem is discovered, it can be very difficult to trust any of your previous data because the culprit could have potentially fooled with many different documents.

The second type of data destruction is outright deletion. Some hackers will simply hack into a computer and delete essential files. This inevitably causes major problems for any business and can even lead to a computer being deemed useless. Hackers can rip operating systems apart and cause terrible problems to a network or a computer.

The Importance of Network Security

Knowing how destructive hackers can be shows you the importance of Network Security. Most networks have firewalls enabled that block hackers and viruses. Having anti-virus software on all computers in a network is a must. In a network, all of the computers are connected, so that if one computer gets a virus, all of the other computers can be adversely affected by this same virus. Any network administrator should have all of the essential files on back up disks. If a file is deleted by a hacker, but you have it on back up, then there is no issue. When files are lost forever, major problems ensue. Network security is an important thing for a business, or a home. Hackers try to make people’s lives difficult, but if you are ready for them, your network will be safe.

Wednesday, May 03, 2006

Wireless Network Security

Working from home has its advantages, including no commute, a more flexible work schedule and fresh coffee and home-cooked meals whenever you want.

But working from home while using a wireless local area network (WLAN) may lead to theft of sensitive information and hacker or virus infiltration unless proper measures are taken. As WLANs send information over radio waves, someone with a receiver in your area could be picking up the transmission, thus gaining access to your computer.

They could load viruses on to your laptop which could be transferred to the company's network when you go back to work.

Up to 75 per cent of WLAN users do not have standard security features installed, while 20 per cent are left completely open as default configurations are not secured, but made for the users to have their network up and running ASAP.

It is recommended that wireless router/access point setup be always done though a wired client.

Change default administrative password on wireless router/access point to a secured password.

Enable at least 128-bit WEP encryption on both card and access point. Change your WEP keys periodically. If equipment does not support at least 128-bit WEP encryption, consider replacing it.

Although there are security issues with WEP, it represents minimum level of security, and it should be enabled.

Change the default SSID on your router/access point to a hard to guess name. Setup your computer device to connect to this SSID by default.

Setup router/access point not to broadcast the SSID. The same SSID needs to be setup on the client side manually. This feature may not be available on all equipment.

Block anonymous Internet requests or pings.

On each computer having wireless network card, network connection properties should be configured to allow connection to Access Point Networks Only. Computer to Computer (peer to peer) Connection should not be allowed.

Enable MAC filtering. Deny association to wireless network for unspecified MAC addresses. Mac or Physical addresses are available through your computer device network connection setup and they are physically written on network cards. When adding new wireless cards / computer to the network, their MAC addresses should be registered with the router /access point.

Network router should have firewall features enabled and demilitarized zone (DMZ) feature disabled.

You can test your hardware and personal firewalls using Shields Up test available at http://www.grc.com

All computers should have a properly configured personal firewall in addition to a hardware firewall.

Update router/access point firmware when new versions become available.

Locate router/access point away from strangers so they cannot reset the router/access point to default settings.

Locate router/access point in the middle of the building rather than near windows to limit signal coverage outside the building.

While none of the measure suggested above provides full protection as counter measures exist, a collection of suggested measures will act as a deterrent against attacker when other insecure networks represent easier targets.

Saturday, April 29, 2006

Network Security - Not With a P2P Network!

Most small business networks grow and evolve as the business grows. In one way, this is good. It shows the business is growing, becoming stronger. Unfortunately, from a network perspective, it can be a disaster in the making.

Most small business networks are setup in a peer-to-peer (P2P) format. In contrast, large corporate networks are setup in a domain format. What does this mean to you?

First, let us define the two network formats. In a P2P format every PC is responsible for its own security access. Basically, each PC is equal to every other PC in the network. These networks generally consist of less than ten computers and require a large amount of administrative overhead to function securely.

In this format the attitudes of the user population is of prime importance. If they have a high level of security conscience then your network will be more secure, if they don’t your network will be wide open to insider exploitation.

You can see the problem. Ten computers and ten administrators equal little accountability.

In a domain system there is a single point of administration, your network administrator. He is responsible for maintaining the network.

A network setup in this format consists of at least one server, a domain controller, to administrate the rest of the network. This domain controller manages user and computer access, freeing the network administrator from the necessity of touching every PC in the network.

When a user logs onto her PC in a P2P network she only authenticates on it, in a domain system it is a little more complicated.

In a domain system she logs onto her computer, her login ID is first checked with the domain controller. If it is found she is granted access to the network resources assigned to her. Then she is allowed to log on to her desktop. If her ID isn’t found then she only has access to her local PC.

Now that you know a little about the two network structures you can see the advantages of the domain design.

As stated earlier this format requires planning to achieve. You must sit down and outline what you want your network to accomplish.

Consider what access your users really need to do their jobs. In the computer security world this is called granting the least amount of access required to do the job. Do your sales reps really need access to your financial files? What about external vendors?

All of this needs to be thought out and addressed.

Here’s an example of how I setup a small sales organization. This business consisted of about eight employees and the two owners. With the assistance of the owners we defined three user groups.

The owners group was granted full and complete access, while each of the other groups received lesser and different accesses. The admin group received access to the financial and administrative functions, and the sales groups receive assess to the sales and customer management data. Specifically, they were excluded from the financial and administrative and the owner’s functions.

Additionally, we setup auditing of both successful and unsuccessful attempts to view certain types of data. We did this to add a layer of accountability to the network. This increases the security of their customer’s data because we can now tell who and when the data was accessed.

Network security personnel know that most network security breaches occur from the inside! In my experience most small businesses use the P2P format because it is the easiest to implement and because they don’t know the security compromises they are working under.

This can be a ticking time bomb for your business. Eventually, you will experience a security lapse that could land you in court.

For instance, you have an employee leave your business. This employee downloaded all of your customer data before he left. Next, he sells this data to someone who uses it to steal the identity of several of your customers. Eventually, this theft is discovered and traced back to your employee.

Your former customers in fully justifiable outrage take you to court charging you with negligence. Specifically, they hold you responsible for failing to safeguard their personal information.

Your case will be much stronger if you can show you have positive control of your network. You can point out your security procedures. Employee logon auditing, security updates, acceptable use agreements, etc. In short you can show that you have taken the steps that a reasonable person would take to secure your network and customer data.

Hopefully, your lawyer can then place the blame directly where it belongs. On the employee who stole the information in the first place. Ask your attorney about this! Don’t just take my work for it, I’m not a lawyer.

Remember, network security is a result of through planning, not hap hazard improvisation. Give your network the same attention you give to the rest of your business.

If you do not have the skills or the time to be your own network administrator, you can contract with someone to handle this for you on a part-time basis. Just make sure they are reputable, you are putting your business in their hands.

Friday, April 21, 2006

7 Simple Reasons Why You Need a Network Security Camera for Your Home

Pros

1. Easy to install: Most of the network cameras on the market are plug and play and/or have very simple to follow instructions for both the hardware and software end.

2. Comparatively cheaper than other security systems: Instead of paying a highly trained technician to install a complex CCTV system, and pay him on an ongoing maintenance arrangement- you can have a network camera security system that can stand on it's own against CCTV and traditional security systems.

3. Works with your existing computer network: If you already have a home network, then the network camera works with your settings, so you don't need to pay more for the proper security infrastructure.

4. Provides peace of mind: watch your home, watch your childs room, watch your vacation home, watch your pets while you are on vacation, etc

5. See remote areas: as far away as across the globe, or your own front porch from a centralized area. Can even remotely view your children at the nursery (depending on the nurseries policies though this is becoming more standard)

6. Flexibility: Prefer not to be tethered to the security control panel or hire a full time security professional to monitor things, then get security alerts which you can view from cell phone, laptop, or PDA device, and provide multiple users access to the various security assets.

7. Receive alerts via email when detects motion, either when someone visits your home, or when your children leave home to hang out.

Cons

1. May have poor image quality depending on model and configuration, and wireless cameras in general have poorer image quality on the lower to mid range.

2. For more bells and whistles, like sound recording, scheduled emails, and motion capture, it varies greatly from model and software description.

3. Generally, outdoor surveillance equipment is more costly, especially if you want the ability to remotely pan/tilt, zoom in, zoom out, and want a waterproof camera. However for a home system this is probably not as urgent as opposed to for a business situation.

4. Drains computer network resources, so if you don't have a speedy computer, then there's a chance of a slight slow down in your collective resources.

Remember that despite the cons, the benefits outweigh them as they provide great security results at a lower installation and maintenance cost than traditional Closed Circuit Television systems.

Wednesday, April 19, 2006

Network Security - Methods For Controlling Threats

Since firewalls are so commonly used it is worth exploring them in greater depth. Corporations often set up rules for managing their Web connections using firewalls. A firewall enables a company to designate how all end users can use their network and decide what information is passed through Web servers and other servers.

There are several methods a firewall uses to control traffic that comes into and goes out of the network. One way firewalls do this is through packet filtering. During this process a firewall analyzes small packets of information against pre-designated filters. All data is sent via small packets of information through filters. Safe information is passed through and unsafe information is generally removed.

Another way firewalls mitigate traffic is through proxy service. This means the firewall retrieved information from the Web and sends it to the requesting computer. Still another method of traffic control used by firewall is stateful inspection. This technique allows the firewall to compare certain parts of the data packet to information gathered from trusted sources. Information going to the firewall from the Internet is monitored to determine whether it contains key characteristics that suggest the information is safe rather than harmful. Information designated as safe passes through freely and other information is blocked.

The methods a company selects will depend on a number of factors including personal preferences. Regardless of the method a firewall uses however a company or network administrator can customize the firewall to filter information based on a pre-established set of criteria.

Thursday, April 13, 2006

Network Security - All About Firewalls

The Importance of Firewalls to Network Security

Most networks should have a firewall in place before they are up and running. A firewall is the most common form of network security employed by companies large and small. If you own a personal computer your anti-virus software company may at one time or another have offered you firewall protection.

A firewall on a home network is just as important as one on a corporate network. Why? Most smaller networks have as many security issues that larger corporate networks have. A firewall helps protect a network against potential data loss, corruption and hackers.

What Is A Firewall

A firewall is nothing more than a fancy term used to describe a blockade that prevents outside forces from accessing your network. It is called a firewall because it prevent information or data loss from one place to another. Typically a firewall is some program or hardware that you have to install in your computer that helps filter information coming from the Web to your computer network. A firewall provides a series of filters that screens information allowing only safe information to pass through to your network.

In a large company, multiple computers are often linked using network cards. Companies usually provide multiple connections to the Internet. In order to protect all of these computers a firewall is necessary so that only certain people can access corporate computers through the Web (those that are authorized to do so). While a firewall is not foolproof it basically does a good job of protecting computers from Internet threats at their connection points.

Sunday, April 09, 2006

Network Security - Little Known Threats

Little Known Network Security Threats

There are a number of common network security threats that can damage your network. Some prime examples include remote login capability, SMTP hijacking and backdoor entry to a computer network. There are however dozens of other ways someone can inadvertedly access your network and steal or damage your data. Here are just a few network security threats you should be aware of, whether you operate a private or corporate network.

DNS – DNS or denial of service involves a major attack on Websites. Usually this threat is reserved for large computer networks. When a denial of service attack occurs there is often little a company can do immediately to recover from the attack. When this happens a hacker connects to the server multiple times purposefully even though the hacker is denied access. Over time these repeated requests cause the system to slow and crash.

Macros – This is an application that allows someone to create a script of commands that can run on your network. These macros are capable of crashing computers and destroying data.

Virus – A computer virus is one of the most common threats any private or corporate network user faces. Fortunately viruses can usually be prevented using modern anti-viral software.

OS bugs – Operating system bugs occur when backdoors are accessed to operating systems. Usually a backdoor is left open to attacks when inadequate network security systems are in place. Fortunately adequate network security including use of firewalls can help limit ones exposure to this security threat.

Wednesday, April 05, 2006

Threats Network Security Protects Against

Top Reasons You Need Network Security

Whether you engage in global commerce or have a network established simply to communicate with others on the Web, there are a number of threats that exist when operating in the realm of the World Wide Web. Network security is an important function that ultimately will protect your computer and data from multiple threats. Here are some examples of common threats networks are exposed to every day:

Session Hijackers – Hijackers can access your computer in a number of ways. One way they can do this is through SMTP hijacking. This means a hijacker can gain access to your list of e-mail addresses through an SMTP server of an unprotected host. By doing so a hijacker is able to send spam to any users listed in the e-mail address book. This is actually a frequent problem networked computers have to deal with. It is usually very difficult to track the origin of a spammer in this case as email is usually redirected through various hosts.

Backdoors – Certain programs allow remote access through application backdoors. Still others have glitches or bugs in the system that allow someone to gain access to the network via a backdoor. This is very dangerous as the interloper can then take control of multiple programs.

Remote login – In some situations a person can connect to your computer network from a remote location and take control of certain computer functions. They may for example view or change files and run programs unbeknownst to you on your computer network.

Tuesday, March 28, 2006

Is your Network Security and User Access in the Right Balance?

The whole meaning of networking is to share programs, but granting others to access a computer device reveals an open window for those with foul motives, too. In the early days networks were quite secure because they were closed in systems, and to do any harm you had to get physical access to a server wired to the LAN. Remote access and Internet possibility to hook up has changed that. Broader availableness and less cost of broadband (DSL and cable) connections means that even home computers remain linked up to the Internet round-the-clock, which add the chances for hackers to gain access to computers.

Computer operating systems were originally planned for stand-alone computers only, not networked ones, and security was not an issue. When computer networking became known, applications and operating systems concentrated on easy accessibility rather than security. Because of this earlier focus on accessibility; security are now retrofitted into a lot of hardware systems. Modern operating systems such as Windows XP are planned with security in mind, but they still have to operate using conventional networking protocols, which can result in security problems.

Security versus access. The users want easy access to network resources. Administrators want to remain the network secure. These two goals are at odds, because access and security are always on conflicting ends of the scale; the more you have of one, the less you have of the other.

For business computer networks, the key is to hit a balance so that employees are not annoyed by security measures, while trying to maintain a level of protection that will keep unauthorized individuals from getting access.

Internal network security threats are those that come from within the organization, as opposed to those that come through the Internet. Internal threats include employees who on purpose attempt to nick data or bring in viruses or attacks on the computer network. Other internal threats are posed by outside employees (contract workers, janitorial services and people posing as utility company employees) who have physical access to the LAN computers. Though, many internal threats are unintended. Employees may install or use their own software or hardware for a private purpose, unaware that it poses a security threat to their computers and the complete network.

External security threats are those that come from outside the LAN, typically from the Internet. These threats are the ones we usually think of when we talk about hackers and computer network attacks. Such people can make use of flaws and characteristics of computer operating systems and software applications. They take advantage of the way various network communications protocols work to do a range of things, including the following: Enter a system and access (read, copy, change or delete) its data. Break down a system and harm or destroy operating system and application files so they do not work anymore. Install virus and worms that can spread to other systems across the LAN. Or use the system to start attacks against other systems or other network.

Thursday, March 23, 2006

"Network Security" -Compliance

Most of the industries such as health care and financial institutions are mandated to be compliant with HIPAA and SOX acts. These acts enforce stringent rules in all aspects of the enterprise including the physical access of information. (This section concetrates on the software requirement of the acts) There are quite a number of agencies that offer the compliance as a service for an enterprise. But it all depends on whether you want to handle compliance yourself or employ a third party vendor to ensure compliance to the acts.


HIPAA Compliance:
HIPAA defines the Security Standards for monitoring and auditing system activity. HIPAA regulations mandate analysis of all logs, including OS and application logs including both perimeter devices, such as IDSs, as well as insider activity. Here are some of the important reports that need to be in place:

1. User Logon report: HIPAA requirements (164.308 (a)(5) - log-in/log-out monitoring) clearly state that user accesses to the system be recorded and monitored for possible abuse. Remember, this intent is not just to catch hackers but also to document the accesses to medical details by legitimate users. In most cases, the very fact that the access is recorded is deterrent enough for malicious activity, much like the presence of a surveillance camera in a parking lot.

2. User Logoff report: HIPAA requirements clearly state that user accesses to the system be recorded and monitored for possible abuse. Remember, this intent is not just to catch hackers but also to document the accesses to medical details by legitimate users. In most cases, the very fact that the access is recorded is deterrent enough for malicious activity, much like the presence of a surveillance camera in a parking lot.

3. Logon Failure report: The security logon feature includes logging all unsuccessful login attempts. The user name, date and time are included in this report.

4. Audit Logs access report: HIPAA requirements (164.308 (a)(3) - review and audit access logs) calls for procedures to regularly review records of information system activity such as audit logs.

5. Security Log Archiving Utility:Periodically, the system administrator will be able to back up encrypted copies of the log data and restart the logs.


SOX Compliance:
Sarbanes-Oxlet defines the collection,retention and review of audit trail log data from all sources under section 404's IT process controls. These logs form the basis of the internal controls that provide corporations with the assurance that financial and business information is factual and accurate. Here are some of the important reports to look for:

1. User Logon report:SOX requirements (Sec 302 (a)(4)(C) and (D) - log-in/log-out monitoring) clearly state that user accesses to the system be recorded and monitored for possible abuse. Remember, this intent is not just to catch hackers but also to document the accesses to medical details by legitimate users. In most cases, the very fact that the access is recorded is deterrent enough for malicious activity, much like the presence of a surveillance camera in a parking lot.

2. User Logoff report:SOX requirements (Sec 302 (a)(4)(C) and (D) clearly state that user accesses to the system be recorded and monitored for possible abuse. Remember, this intent is not just to catch hackers but also to document the accesses to medical details by legitimate users. In most cases, the very fact that the access is recorded is deterrent enough for malicious activity, much like the presence of a surveillance camera in a parking lot.

3. Logon Failure reportThe security logon feature includes logging all unsuccessful login attempts. The user name, date and time are included in this report.

4. Audit Logs access report:SOX requirements (Sec 302 (a)(4)(C) and (D) - review and audit access logs) calls for procedures to regularly review records of information system activity such as audit logs.

5. Security Log Archiving Utility:Periodically, the system administrator will be able to back up encrypted copies of the log data and restart the logs.

6. Track Account management changes:Significant changes in the internal controls sec 302 (a)(6). Changes in the security configuration settings such as adding or removing a user account to a admistrative group. These changes can be tracked by analyzing event logs.

7. Track Audit policy changes:Internal controls sec 302 (a)(5) by tracking the event logs for any changes in the security audit policy.

8. Track individual user actions:Internal controls sec 302 (a)(5) by auditing user activity.

9. Track application access:Internal controls sec 302 (a)(5) by tracking application process.

10. Track directory / file access:Internal controls sec 302 (a)(5) for any access violation.

GLBA Compliance:
The Financial Services Modernization Act (FMA99) was signed into law in January 1999 (PL 106-102). Commonly referred to as the Gramm-Leach-Bliley Act or GLBA, Title V of the Act governs the steps that financial institutions and financial service companies must undertake to ensure the security and confidentiality of customer information. The Act asserts that financial services companies routinely collect Non-Public Personal Information (NPI) from individuals, and must notify those individuals when sharing information outside of the company (or affiliate structure) and, in some cases, when using such information in situations not related to the furtherance of a specific financial transaction.

1. User Logon report:GLBA Compliance requirements clearly state that user accesses to the system be recorded and monitored for possible abuse. Remember, this intent is not just to catch hackers but also to document the accesses to medical details by legitimate users. In most cases, the very fact that the access is recorded is deterrent enough for malicious activity, much like the presence of a surveillance camera in a parking lot.

2. User Logoff report:GLBA requirements clearly state that user accesses to the system be recorded and monitored for possible abuse. Remember, this intent is not just to catch hackers but also to document the accesses to medical details by legitimate users. In most cases, the very fact that the access is recorded is deterrent enough for malicious activity, much like the presence of a surveillance camera in a parking lot.

3. Logon Failure report:The security logon feature includes logging all unsuccessful login attempts. The user name, date and time are included in this report.

4. Audit Logs access report:GLAB requirements (review and audit access logs) calls for procedures to regularly review records of information system activity such as audit logs.

5. Security Log Archiving Utility:Periodically, the system administrator will be able to back up encrypted copies of the log data and restart the logs.

Saturday, March 18, 2006

"Network Security" -Forensics

The most important features you need to lookout,when you short list a network security forensic product is the ability to archive the raw records. This is a major factor when it comes to acts and laws. So in the court of law, the original record has to be produced as proof and not the custom format of the vendor. The next one to lookout for is the ability to create alerts, i.e the ability to notify whenever some criteria happens ex: when 3 unsuccessfull login attempts mail me kind of stuff, or better still if there is a virus attack for from the same host more than once, notify me etc. This will reduce the lot of manual intervention needed in keeping the network secure. Moreover the ability to schedule reports is a big plus. You don't have to check the reports daily. Once you have done your ground work as to configure some basic alerts and some scheduled reports. It should be a cakewalk from then on. All you need to do is check out the information(alerts/reports) you get in your inbox. It is recommended that you configure reports on a weekly basis. So that it is never too late to react to a potential threat. And finally a comprehensive list of reports is a vital feature to lookout for. Here is a list of reports that might come in handy for any enterprise:

Reports to expect from edge devices such as a firewall:

1. Live monitoring

2. Security reports

3. Virus reports

4. Attack reports

5. Traffic reports

6. Protocol usage reports

7. Web usage reports

8. Mail usage reports

9. FTP usage reports

10. Telnet usage reports

11. VPN reports

12. Inbound/Outbound traffic reports

13. Intranet reports

14. Internet reports

15. Trend reports


Reports to expect from compliance and internal monitoring: ( see compliance sub-heading for reports on compliance)

1. User Audit reports (successfull/unsuccessful login attempts)

2. Audit policy changes (ex: change in privileges etc)

3. Password changes

4. Account Lockout

5. User account changes

6. IIS reports

7. DHCP reports

8. MSI reports( lists the products installed/uninstalled)

9. Group policy changes

10. RPC reports

11. DNS reports

12. Active directory reports

The gating factor for choosing a monitoring product is to cross verify whether the devices you have in your network are supported by the vendor you choose. There are quite a number of products which address this market, you might want to search for "firewall analyzer" and "eventlog analyzer" in google.

Sunday, March 12, 2006

"Network Security" -Monitoring

No matter how fine your defense systems are, you need to have someone to make sense out of the huge amount of data churned out of a edge device like firewall and the system logs. The typical enterprise logs about 2-3GB/day depending upon the enterprise the size might vary. The main goal of the forensic software is to mine through the vast amount of information and pull out events that need attention. The "Network security" softwares play a major role in identifying the causatives and security breaches that are happenning in the enterprise.

Some of the major areas that needed to be addressed by any network security product is to provide a collective virus attacks across different edge devices in the network. What this offers for an enterprise is a holistic view, of the attacks happening across the enterprise. It offers a detailed overview of the bandwidth usage, it should also provide user based access reports. The product has to highlight sescurity breaches and misuse of internet access, this will enable the administrator to take the necessary steps. The edge devices monitoring product has to provide other stuffs like Traffic trends,insight into capacity planning and Live traffic monitoring, which will help the administrator to find causes for network congestion.

The internal monitoring product has to offer the audit information of users, system security breaches and activity audit trails (ex: remote access) As most of the administrators are ignorant of the requirements for the compliance acts, it is better to cross reference which acts apply to their enterprise and ensure that the product supports reporting for the compliance acts

Thursday, March 09, 2006

What is Network Security?

network security: the protection of a computer network and its services from unauthorized modification, destruction, or disclosure

Network security is a self-contradicting philosophy where you need to give absolute access and at the same time provide absolute security. Any enterprise needs to secure itself from two different access of information/transaction for that matter(ex:ftp,http etc.), internal access and external access. Securing the access of information or resources from the external world(WWW) is quite a task to master, that is where the firewalls pitch in. The firewalls act as gatekeepers who seggregate the intrusive and non-intrusive requests and allow access. Configuring & maintaining a firewall is by itself a task which needs experience and knowledge. There are no hard and fast rules to instruct the firewalls, it depends on where the firewall is installed and how the enterprise intends to provide access to information/resources. So, the effectivity of any firewall depends on how well or how bad you configure it. Please be informed many firewalls come with pre-configured rules, which intend to make the job of securing the information access from external sources. In short firewall gives you information about attacks happenning from the external world.

The toughest job is to secure information from the internal sources. More than securing it, managers need to track the information flow, to identify possible casuatives. The tracking of information flow will come in handy in case of legal situations. Because what seemingly to be a sharing of information could be held against you in the court of law. To enforce this, acts such as HIPAA, GLBA, SOX have been putforth, to ensure that the scam(s) like that of "Enron" does not happen. In short the tracking of information and audit gives you information abouot security breaches and possible internal attacks.

There are a variety of network security attacks/ breaches:

* Denial of Service

* Virus attacks

* Unauthorized Access

* Confidentiality breaches

* Destruction of information

* Data manipulation


Interestingly , all these information are available across the enterprise in the form of log files. But to read it through and making sense out of it, will take a life time. That is where the "Network Security" monitoring also known as "Log Monitoring" softwares pitch in. They do a beautiful job of making sense out of the information spread across various locations and offer the system administrators a holistic view of what is happening in their network, in terms of Network Security. In short they collect,collate,analyze & produce reports which help the system administrator to keep tabs on Network Security.


"Network Security" -Monitoring

No matter how fine your defense systems are, you need to have someone to make sense out of the huge amount of data churned out of a edge device like firewall and the system logs. The typical enterprise logs about 2-3GB/day depending upon the enterprise the size might vary. The main goal of the forensic software is to mine through the vast amount of information and pull out events that need attention. The "Network security" softwares play a major role in identifying the causatives and security breaches that are happenning in the enterprise.

Some of the major areas that needed to be addressed by any network security product is to provide a collective virus attacks across different edge devices in the network. What this offers for an enterprise is a holistic view, of the attacks happening across the enterprise. It offers a detailed overview of the bandwidth usage, it should also provide user based access reports. The product has to highlight sescurity breaches and misuse of internet access, this will enable the administrator to take the necessary steps. The edge devices monitoring product has to provide other stuffs like Traffic trends,insight into capacity planning and Live traffic monitoring, which will help the administrator to find causes for network congestion.

The internal monitoring product has to offer the audit information of users, system security breaches and activity audit trails (ex: remote access) As most of the administrators are ignorant of the requirements for the compliance acts, it is better to cross reference which acts apply to their enterprise and ensure that the product supports reporting for the compliance acts(please refer

href="#Compliance">here for details on compliance)

In altoghether they will have to support archiving, scheduling of reports and a comprehensive list of reports. please follow the next section for more details.

Saturday, March 04, 2006

Wireless Network Security: How to Use Kismet

Kismet is a wireless network detector / sniffer which can give you a vast amount of information about wireless networks. Wireless network security flaws are well documented but often very hard for the common person to understand. I will be showing you how to use kismet with out even having to install Linux, or compile kismet.

First you need to proceed to remote-exploit.org and download and burn their Auditor CD. (IF you don’t know how to burn an ISO image, go to Google). This version of Linux doesn’t install or modify your hard drive; it will boot from the CD and use a Ram Drive (On your Memory).

Auditor is not only a great tool for testing wireless network security with kismet but it also has many other computer security tools on it as well.

Client Window

Next, to start Kismet proceed to the Linux version of the start menu, and press Auditor. Now proceed to the wireless /scanning/kismet tools/kismet.

Once you click on Kismet it will ask you for a default location to place the Kismet log files for analyzing later, just press the desktop or temp file.

Now I will show you how to use Kismet. When kismet initially opens you will see a greenish box with numbers and network names (If any are near you) clicking away don’t be overwhelmed. (Also I can’t show you how to use kismet if you don’t have the correct wireless adapter, get an ORINICO Gold Classic Card off EBAY.) The Orninco gold classic card will be automaticly detected by auditor linux.

The Kismet columns will show the wireless networks SSID (Name), Type of device (Access point, gateway) Encryption or no Encryption, an IP range and number of packets. Kismet will pick up hidden networks with SSID broadcast Disabled also, Netstumbler will not.

Now Press H, to bring up the Help Menu. This will give the nuts and bolts on how to use kismet. If you tab down to the network you are auditing and press “C”, Kismet will show you all the computers that are using that wireless access point / gateway. This Kismet screen will show you the clients MAC address, Manufacture of Wireless Adapter, IP address range and traffic.

Kismet: Help Menue

Now to get out of that screen press “Q”. Tab Down on the Main Kismet Screen to another SSID and press “I”. This Kismet window will show detailed information about the wireless network. The Kismet detail screen will show the type of network (Infrastructrure / Adhoc), signal strength, channel, encryption type, and much more.

Kismet will also give you sound alerts when new wireless networks are discovered or security alerts or suspicious clients are in range. Suspicious clients would be people like you who are using Kismet or Networkstumbler. Unlike you these could be Wardrivers looking for venerable networks to hack into.

Kismet Alert Page

You can prevent War drivers from discovering your wireless network by performing a proper site survey which will help limit signal bleed off to unneeded areas. You should write down the suspicious MAC address and keep an eye on your access logs. If the War Drivers are really stupid just look out your window and look for cars with weird antennas.HA HA HA.

Kismet is more than just a tool to discover wireless networks; it can be used in conjunction with other tools to crack WEP/WPA. Many websites will claim that WEP can be cracked in less that five minutes. This is only half the truth because it could take many hours,days,months to gather enough packets to crack. Good luck and have fun learning the more advanced applications of kismet.

Tuesday, February 28, 2006

Home Wireless Network Security Issues

Running a business from home has its advantages, including no commute, a more accommodating work schedule, fresh coffee and home-cooked meals at any time you want.

But running a business from home using a home wireless local area network (WLAN) with your computer may lead to thievery of confidential information and hacker or virus penetration unless proper actions are taken. As WLANs send information back and forth over radio waves, someone with the right type of receiver in your immediate area could be picking up the transmission, thus acquiring access to your computer.

Here is a list of things that you should consider as a result of implementing a home wireless network setup used your business:

Viruses could be loaded onto your laptop which could be transferred to the company's network when you go back to work.

Up to 75 per cent of home wireless network WLAN users do not have standard security features installed, and 20 per cent are left completely open as default configurations and are not secured, but are made for the users to have their network up and running ASAP.

It is recommended that home wireless network router/access point system setups be always done though a wired client.

Always change the default administrative password on your home wireless network router/access points to a secured password.

Enable at least 128-bit WEP encryption on both card and access point. Change your WEP keys periodically. If equipment does not support at least 128-bit WEP encryption, consider replacing it. Although there are security issues with WEP, it represents minimum level of security, and it should be enabled.

Change the default SSID on your router/access point to a hard to guess name. Setup your computer device to connect to this SSID by default.

Setup router/access points so as to not broadcast the SSID. The same SSID needs to be setup on the client side manually. This feature may not be available on all equipment.

Setup your home wireless network router to block anonymous internet requests or pings.

On each computer having a wireless network card, network connection properties should be configured to allow connection to Access Point Networks Only. Computer to computer (peer to peer) connections should not be allowed.

Enable MAC filtering. Deny connection to wireless network for unspecified MAC addresses. MAC or physical addresses are accessible through your computer device wireless network connection setup and they are physically written on network cards. When adding new wireless cards / computer to the network, their MAC addresses should be registered with the router /access point.

Your home wireless network router should have firewall features enabled and demilitarized zone (DMZ) feature disabled. Periodically test your hardware and personal firewalls using Shields Up test available at http://www.grc.com. All computers should have a properly configured personal firewall in addition to a hardware firewall.

Update router/access point firmware when new versions become available.

Locate router/access points away from strangers so they cannot reset the router/access point to default settings. Also, locate router/access points in the middle of the building rather than near windows to limit signal coverage outside the building.

You should know that nothing is 100%. While none of the actions suggested above will provide full 100% protection, countermeasures do exist that will help. The good collection of suggested preventative actions contained herein can help you deter an intruder trying to access your home wireless network. This deterrant then makes other insecure networks easier targets for the intruder to persue.

Wednesday, February 22, 2006

Network Security Journal Guide

The term ‘Virus’ has not just created havoc in life of living beings but also in the world of computers. Though the two kinds of viruses are completely different from each other yet both can prove extremely fatal.

Virus in computers can be defined as a program or a piece of code that is loaded onto your computer without your knowing it and it runs against your wishes. The computer viruses are manmade and can easily replicate themselves. A simple virus can duplicate itself time and again and it is quite easy to produce. Even a simple virus can swallow the entire memory of your system and stop it’s working while a slightly more dangerous or strong virus can transmit it across networks and bypass the security systems. Viruses can be transmitted as attachments to an e-mail note or in a download file, or be present on a diskette or CD. Some viruses cast their effect as soon as their code is executed; other viruses lie inactive until circumstances cause their code to be executed by the computer.

But gone are the days when viruses and diseases caused by them were left untreated. Just as people have developed cures to protect themselves, they have also invented something to safeguard their computer against the devastating threat of virus. The device that is meant to detect virus is called anti-virus.

An anti-virus program can be defined as a utility that searches a hard disk for any known or potential viruses and eliminates any that are found. Anti-virus software comprises of computer programs that attempt to identify, obstruct and eradicate computer viruses and other harmful software.

Every anti-virus software functions according to two techniques with a special focus on the first one –

(1) Examining i.e. scanning files to check familiar viruses that match the definitions in a virus dictionary.

(2) Identifying any malfunctioning software that indicates infection. Such analysis includes data captures, port monitoring and other methods.

While examining any file, the anti-virus software refers to a dictionary of known viruses that are already identified by the authors of the anti-virus software. The moment the code of a virus matches with the virus detected in the dictionary, the anti-virus software at first tries to repair the software by removing the virus itself from the file. If the virus is not removed at this stage then the software quarantines the file in a way that file remains inaccessible to other programs and the virus ceases to harm the system any more. Finally if the virus still continues to exist, the software deletes the infected file.

In order to function correctly and in a right manner the virus dictionary approach needs regular updates that involves downloads of updated virus dictionary entries. The anti-virus software that works in accordance to a dictionary typically scrutinizes files and spontaneously detects a virus when the operating system of the computer creates, opens, and closes or e-mails them. However a System Administrator can program the anti-virus software to examine or scan all the files on the user’s hard disk on a routine basis.

Sunday, February 19, 2006

Network Security – The Real Vulnerabilities

Scenario: You work in a corporate environment in which you are, at least partially, responsible for network security. You have implemented a firewall, virus and spyware protection, and your computers are all up to date with patches and security fixes. You sit there and think about the lovely job you have done to make sure that you will not be hacked.

You have done, what most people think, are the major steps towards a secure network. This is partially correct. What about the other factors?

Have you thought about a social engineering attack? What about the users who use your network on a daily basis? Are you prepared in dealing with attacks by these people?

Believe it or not, the weakest link in your security plan is the people who use your network. For the most part, users are uneducated on the procedures to identify and neutralize a social engineering attack. What’s going to stop a user from finding a CD or DVD in the lunch room and taking it to their workstation and opening the files? This disk could contain a spreadsheet or word processor document that has a malicious macro embedded in it. The next thing you know, your network is compromised.

This problem exists particularly in an environment where a help desk staff reset passwords over the phone. There is nothing to stop a person intent on breaking into your network from calling the help desk, pretending to be an employee, and asking to have a password reset. Most organizations use a system to generate usernames, so it is not very difficult to figure them out.

Your organization should have strict policies in place to verify the identity of a user before a password reset can be done. One simple thing to do is to have the user go to the help desk in person. The other method, which works well if your offices are geographically far away, is to designate one contact in the office who can phone for a password reset. This way everyone who works on the help desk can recognize the voice of this person and know that he or she is who they say they are.

Why would an attacker go to your office or make a phone call to the help desk? Simple, it is usually the path of least resistance. There is no need to spend hours trying to break into an electronic system when the physical system is easier to exploit. The next time you see someone walk through the door behind you, and do not recognize them, stop and ask who they are and what they are there for. If you do this, and it happens to be someone who is not supposed to be there, most of the time he will get out as fast as possible. If the person is supposed to be there then he will most likely be able to produce the name of the person he is there to see.

I know you are saying that I am crazy, right? Well think of Kevin Mitnick. He is one of the most decorated hackers of all time. The US government thought he could whistle tones into a telephone and launch a nuclear attack. Most of his hacking was done through social engineering. Whether he did it through physical visits to offices or by making a phone call, he accomplished some of the greatest hacks to date. If you want to know more about him Google his name or read the two books he has written.

It’s beyond me why people try and dismiss these types of attacks. I guess some network engineers are just too proud of their network to admit that they could be breached so easily. Or is it the fact that people don’t feel they should be responsible for educating their employees? Most organizations don’t give their IT departments the jurisdiction to promote physical security. This is usually a problem for the building manager or facilities management. None the less, if you can educate your employees the slightest bit; you may be able to prevent a network breach from a physical or social engineering attack.

Saturday, February 04, 2006

Emails And Network Security

With the number of small, home-based businesses at present, computers and the internet are fast establishing themselves as essential tools for business management. But the active use of computers in business as means of banking and other financial transactions has attracted unscrupulous individuals. These individuals come up with programs and viruses that are threats to network security in hopes of intercepting important files from home computers. The Computer Emergency Response Team (CERT) at Carnegie Mellon University says that there are several ways how internet criminals threaten network security through emails. These methods seem harmless and are virtually undetectable until it is too late.

These threats include: email spoofing and email viruses. All these are classified as intentional computer misuses but are unwittingly spread by people who are not aware of their possible effects on network security. CERT explains that the writers of the viruses and malicious programs usually exploit the ignorance of most computer users to spread their viruses.

Email spoofing happens when emails display sources other than the original source. The virus writer or the original source manipulates the virus program to make it appear that the source written on the "From" box is the actual sender of the message. Most cases involve "messages" from network system administrators asking the users to modify and send them new passwords or other important information. Others report receiving strange emails from banks or telephone companies. The recipient opens the email, thinking that it is an urgent reminder. The virus then starts spreading in the computer system. The usual function of viruses like this is to weaken network security in order for the virus writer to infiltrate the system.

Viruses can also infiltrate systems by email attachments. This happens when a virus writer programs a virus and sends it to people disguised as a harmless email or attachment. The criminal usually attaches a funny picture or story in the email to entice recipients to open it. The recipient, thinking that the message is harmless and funny, sends it to other people. The virus spreads and disables network security with minimum effort from the writer. Email viruses usually come as attachments with hidden or concealed file extensions. Most victims open attachments thinking that these are harmless text documents or images taking note only of the ".txt" or ".jpg" in the filename. CERT advises that the first file extensions are not important in an attachment or file. The important attachment is the last because it indicates how the attachment functions. Extensions like ".exe" or ".vbs" means that the attachment will run as a program once the recipient opens it.

There are no foolproof ways on how to prevent the spread of malicious programs and viruses. To maintain network security, CERT recommends ignoring strange emails even if these are sent by an authority. Verify the messages' origin by calling the agency that "sent" them. For best protection, CERT advises email users to avoid downloading and saving attachments in their computers unless they have verified its source. Installing firewalls and other anti-virus software also strengthens network security.

Monday, January 30, 2006

Network Security Paramount to Large Corporate Entities

Standards-based VoIP and IP telephony software applications are becoming the reality of modern business communications. However, network security is paramount for all corporate entities with the prevalence of secure data traveling over a variety of communications mediums.

Tracking call data is a necessary and important part of a business enterprise’s operations and efficiency, and by choosing a secure call accounting system, sensitive information like corporate assets, trade secrets and other proprietary data, won’t fall into the wrong hands.

It’s important that a serious call accounting software application provide security in the following areas: Operating System Security, Program Security and Data Security. Each of the three zones should operate with independent settings that can be set to a business’ specific needs. An administrator should be able to limit the operations available to a specific user and can place restrictions on call data records that a user can view or edit.

Additionally, a call accounting system that has the ability to limit users to their respective areas (divisions, departments, cost centers, etc…) via user IDs provides multi-user access and affords managers the ability to run reports that can aid with>telecom expense management. The overall result is a high-efficiency call accounting system that can be configured for any number of network users, and has the highest security encryption rate.

Sunday, January 29, 2006

Wireless Network Security

Why Use Security?
If someone is able to wireless connect to your network from the road, near by parking lot, or adjacent house here are some things to consider. If they use your Internet connection for illegal activity, YOU are liable, not them. Also, once they are on your network, they may be able to open, delete, or change every file on your computers. There is also the possibility that the unauthorized user could spread viruses without them even realizing it.

So What Should I Do?
There are many ways to secure your connection. We are focusing on wireless security, so we will make a simple adjustment to your router. The simplest way to secure your connection is by using WEP (Wireless Encryption Protocol). Before I go any further, many hackers can find ways around this protection. It is not the best choice for large businesses (over 100 employees), but for home and small business users, this will work just fine.

Step 1 (Configure router):
Depending on your router, the specifics of this step will differ. You need to log into your router. This is done by opening your Internet Browser (Internet Explorer, FireFox, Safari, etc.) and putting the IP Address of the router in the address bar (the address bar is where you type web sites such as google.com). This IP address will either be 192.168.0.1 or 192.168.1.1; if you are unsure try both. Once you type the correct one in (and press 'Enter'), a pop-up will ask you for your user name and password. If you have never changed your password, then a default was set for you by the manufacturer. This is not the same user name and password as your computer or Internet Service Provider. If you do not know your default password, find it by clicking here.
Once logged in, look for the wireless section. This is often a button or tab found on the main page. For DLink routers there will be a button on the left menu. Now look for wireless security. For DLink routers it will be on this page. You should see a drop-down-menu. Select WEP (you may also see other choices such as WAP). Depending on your router, you will see some or all of these options. Set them as follows:


Authentication: Open
WEP Encryption: 64bit
Key Type: Hex
Key1: PICK A 10 DIGIT NUMBER


The above 'Key' is your wireless network password. Anyone that uses your wireless connection will need to know it. Normally, you are only required to put it in your computer once and then it will remember it.

Step 2 (Computer Setup):
Now go to your wireless computer and try to connect to the network, it will ask you for the key. Enter it just as you did in the router.

Step 3 (Advanced Security):
If you would like more security then you can change some of the other options in the router. For example, instead of 64bit choose 128bit. Or instead of HEX choose ASCII. All routers are different and offer different levels of security. Basically, going to 128bit requires a longer password so it is harder for others to guess and going to ASCII requires a password with letters, not just numbers, so there are more possible passwords. You can change this around as much as you like and I do suggest changing to either 128bit or ASCII.

Wednesday, January 25, 2006

Computer & Network Security: Two Anti Virus Strategies

Rootkits and advanced spyware have fundamentally changed the playing field says Mike Danseglio, Program Manager in the Security Solutions group at Microsoft, according to Fox News’ “Microsoft Official: Malware Recovery Not Always Possible” by Ryan Naraine, reporting from InfoSec World on April 5th, 2006. “When you are dealing with rootkits and some advanced spyware programs, the only solution is to rebuild from scratch. In some cases, there really is no way to recover without nuking the systems from orbit," states Mr. Danseglio.

He cites a recent instance where an unnamed branch of the U.S. government struggled to design an automated process to wipe and rebuild 2,000 infected client machines. "In that case, it was so severe that trying to recover was meaningless.” While training costs can be high, they pale in comparison to the mounting expenses incurred by detecting damage, recovering lost work and rebuilding compromised systems--let alone “nuking” and starting all over again from scratch.

Rootkits, for example, use kernel hooks which often make them undetectable. Because of this, they are able to hide malware programs, making them the weapon of choice to compromise computer systems. Mr. Danseglio adds that IT administrators may never even know if the entire rootkit has been successfully removed. The cleanup process is "just way too hard."

"We've seen the self-healing malware that actually detects that you're trying to get rid of it. You remove it, and the next time you look in that directory, it's sitting there. It can simply reinstall itself," he said. "Detection is difficult, and remediation is often impossible," Danseglio declared. "If it doesn't crash your system or cause your system to freeze, how do you know it's there? The answer is you just don't know," he explained. "Lots of times, you never see the infection occur in real time, and you don't see the malware lingering or running in the background.

Fortunately, however, the alternative, training, is easier than it ever was, thanks to new online technologies such distance learning. The important point to remember is that, with today’s viruses. all employees--not just IT people--must be trained.

Wednesday, January 18, 2006

Home Network Security Revealed

Some home computer users have become experts without knowing it. Just a short time ago terms such as "wireless" and "router" were only known by computer professionals and experts. Not so any more. These days switches, hubs, Ethernet cards, firewalls, routers, and other buzzwords related to networking have become common in many homes.

Vendors have created new sources of income for themselves by making the installation of network devices cost efficient and easy. This is great value to home PC users by allowing more than one home computer to share resources with others without having to move the files physically or having to move the connections on printers. The entire family can now use one network to connect to the Internet, many times without having to drag wires all around the house.

The one thing that home users are lacking is education is how to secure themselves from hackers.

However, there is no need to panic. Settings that come from the vendor are very good. Now, here's a bit of guidance...

A common acronym for computer experts is "RTFM". You can just ignore the middle letter for now. The first letter stands for "read", the T for "the" and the last letter stands for "Manual". Doing this will give you information about standard settings that are useful about configuration. Don't forget to reread it.

PORTS FOR ROUTERS

The first thing that you should do is change your password. You should also rename the account for the administrator. This is because the next person who bought the same computer model as you did has the same information and might not be as trustworthy as you would like to think.

A standard port of HTTP is Port 80. This port is needed if you plan on browsing the Internet. A port is number for the network that is used by software to keep track of Internet traffic. You'll need to have this port open for IP addresses and any ranges that are going out of your computer. By doing this only those computers you know can generate any Internet traffic on your home network.

If you get your IP address in an automatic fashion the above tip will won't be useful for you. For example, most use DHCP. However, there are other service providers who will let you buy one static IP address for the router. It's this address that should have access going out to the Internet.

But just why should you care about traffic that is going out? For the simple reason that you might infect other computers. This is why you need to practice networking that is safe so that you don't spread any viruses. If you have Internet access that is wireless you won't always know who is on your same network. And even if you're not at home anyone can sneak in through your network.

You'll need to have Port 80 open for all traffic coming in from the Internet. Or you might want to track only those websites that have an IP address. This might be impossible though.

You need to open up Port 25 for outgoing mail if you're going to be using an email client that is a desktop application rather then being browser based. As well, you'll have to open up port 110 for incoming mail.

And most of the time, that will be all....

If you're using a client that is a desktop FTP or manual (both of which should be avoided if you can due to poor security) you'll need other ports. Most of the time these port numbers are easy to find. Try to limit their use. The general rule for network security is that you should keep as many ports as you can closed and only use those that you really need to use.

The above may sound a bit like the settings in a firewall. This is because firewalls and routers have some of the same functions. A firewall will allow or prevent Internet traffic while a router will direct it.

WIRELESS NETWORKS

There's a bit more that you have to do if you have a wireless network. Default settings will sometimes let anyone in range of the network have access. This means that not only someone in your household will be on the Internet, the neighbour across the street will as well. And this includes the hacker.

What you need to do is lock down the wireless network. You can learn how to do this by reading the manual and then configuring your passwords as well as any other security features that are included.

You don't need to devote your life to becoming a security or network expert just so that you keep your resources safe. However, when you're connected to the Internet through a router there is more risk than if you were connected through dial-up or as a single user.

Take some time today to learn what you can about network security so that you don't spend that time after your network is broken into.

Friday, January 13, 2006

Wireless Network Security

Have you ever wondered how you can protect your home from intruders? There are various wireless network security gadgets installed in homes. But how safe really are you when at home? Here are six steps to ensure security in your home using wireless network security gadgets.

First, you should change the system’s identification. Security devices come with a default system ID called the Service Set Identifier. Hackers will find it easy to learn the default identifier of each manufacturer, so it is safer for you to change it. Use something unfamiliar. Avoid using your name or other codes that are easily identified.

Second, you should disable the identifier broadcasting. You need not announce that you have wireless connection since this will be enticing to hackers. Check your manual to learn how to disable broadcasting.

Third, it is important to enable encryption. The Wired Equivalent Privacy and the Wi-Fi Protected Access have the ability to encrypt data so that only the intended recipient can read it.

Fourth, you must restrict unnecessary traffic. A lot of wireless routers have their own built-in firewalls. Read the manual of the hardware and find out how to reconfigure your router so that only your approved incoming and outgoing traffic can be allowed.

Fifth, change the default password of the administrator. Since this password can easily be obtained and many people do not go to trouble of changing it, the system falls prey to a lot of hackers. Be sure to change the password to something that cannot easily be guessed.

Lastly, patch and protect your personal computers. You must have a personal firewall and anti-virus software installed on your computers. Be sure to always keep them up to date. Also, keep updates of famous security vulnerabilities.

Monday, January 09, 2006

Network Security Software

Networking is all about sharing programs and is highly important in a company's computer system. Before, networks were secure because they were closed-in systems. But nowadays, hackers can easily access these networks due to broader availability and inexpensive broadband connections, such as DSL and cable. That is why companies should have network security software.

Network security software is used to protect sensitive data and information on your company's system. It also works wonders in securing your system, and ensures that it functions effectively and at maximum capacity. Some types of network security software are network security software scanners, network monitoring software and network-wide software used for monitoring an event log.

The network security software scanner is used to check your computer system for possible security vulnerabilities by scanning the entire network for missing security areas, service packs, open shares, open ports and user accounts that are unused. When this software detects all this information, you can lock down your computer system against intruders and hackers.

Another type of network security software is network-monitoring software. This is used to monitor your server and the entire computer system for failures, and to allow administrators to fix and identify these failures before the computer users report them. If there is a failure, the user can be alerted via email, SMS or pager. After this, the software reboots the machine, restarts a service or automatically runs a script.

Lastly, the software used for monitoring an event log is used to detect intrusion on the event log and management. What this software does is analyzes and archives the event logs of all machines in the computer system, at the same time sending alerts of attacks, critical events and other issues on security.

All these are necessary to secure your company's computer system. But keep in mind that one of the most important features that your network security software should have is ease of use. So, you must take time and carefully select the software that you will use in managing your network and keeping it secured.

Wednesday, January 04, 2006

Wireless Network Security

With a wireless network, however, you have a radio signal that permeates the very air around us. Because of the broadcast nature of WLANs, it is far easier to access this sort of network, especially when the signal is usually powerful enough to emanate outside of a building and so potentially provide network access to those outside.

Another benefit of a cabled network is that the transfer of data between computers remains within the wires themselves. Contrast this with a Wireless network, in which the data is now easier to intercept and/or corrupt.

As a result you need to secure your wireless network in the following ways:

* Request user authentication to prevent unauthorized access to your network.
* Use data privacy to protect the integrity and privacy of the data being transmitted.


How do you secure your Wireless network?

1. Change the SSID When you configure your WAP change the default SSID (Service Set IDentifier). Don’t pick something that easily identifies you, like your name, street address, etc. Instead pick something complicated that is difficult to guess and is made up of a mixture of letters and numbers e.g. m6jvUm9mHuQfA4h5tgCH

2. Disable SSID broadcasting In addition, make sure your WAP isn’t configured to broadcast your SSID. Although this is not a secure method of protecting your network, it does mean your WLAN is not so openly available to intrusion.

3. Configure WPA or WPA2 To authorize access to your Wireless network you should choose a security setting of WPA-PSK (Wi-Fi Protected Access Pre-Shared Key) or better yet WPA2-PSK if available.

Although Windows XP supports both of these security methods, you still need a wireless adapter that supports WPA as well.

NOTE: WEP (Wired Equivalent Privacy) is the earlier attempt to secure wireless connections and it is not secure enough. If this is all your WPA has to offer then you should either upgrade the firmware on it, if this will then give you WPA, or purchase a newer device.

You also need to choose a password for WPA-PSK. Like your SSID, this too needs to be complicated and so not easy to guess.

4. Restrict access based on MAC authentication Your wireless network adapter has a physical address called a MAC (Media Access Control) address. You can take advantage of this by configuring your WAP to only allow access to those MAC addresses you want to give access to your network and so restrict which computers can get connected. Although a MAC address can still be spoofed, this is yet another obstacle to deter the casual hacker.

5. Change the administrator account/password Your WAP will come with a standard administrator account and password. So anyone who has bought the same device will know what these are. Change the password to one that isn’t easy to guess and if possible change the name of the administrator account as well.