Friday, February 09, 2007

Why Most Wireless Network Security Advice Doesn't Really Work

Just about every day I read articles about wireless networks and what should be done to make them safer. Mostly I get a couple of lines in and then read no further. This is because the advice in a lot of these articles is a waste of time. Don't worry though because there's stuff you can do that's a lot less hassle and will work a whole lot better.

I'll get onto what you should do, but first of all I'm going to repeat what you'll probably read elsewhere and tell you why it doesn't help:

THINGS THAT DON'T REALLY WORK

Turning off SSID broadcast: This is often misleadingly referred to as "SSID hiding", but there's no such thing. It turns off SSID beaconing on your Wireless Access Point or wireless router, but there are other mechanisms that also broadcast the SSID over the wireless network and so you're disabling only 1 of many. Turning off SSID broadcast makes your network a lot less user friendly and won't do anything meaningful for network security.

MAC filtering: Frequently mentioned as a security mechanism and it can be used to keep leaching neighbours from using your broadband, but then encryption is a better way to achieve that and more. The problem with MAC filtering is that it can be hard to set up and maintain and the MAC address of your wireless card can be seen in the header of all wireless packets to and from your PC by anyone with a "sniffer" (a bit of traffic capturing software you can get for free on the Internet). It's then pretty easy to spoof the MAC address and gain access. It's really not worth the trouble to configure it.

Disable DHCP: Another big waste of time. DHCP allows the automatic assignment of IP addresses and other configurations. Many articles advise disabling DHCP and configuring static IP addresses to "increase security". It'll take a hacker about 10 seconds to figure out the IP scheme of any network and simply assign their own IP address. Just as with turning off SSID broadcast you're making your life harder for no gain. Anyone who tells you that this is a way to secure your wireless network doesn't know what they're talking about.

SO WHAT DOES WORK?

The good news is there are some simple things you can do that will improve the security of your wireless network. Here are three simple steps to improved wireless security:

Step 1 - Password protect your router

If you have a wireless or broadband router then it should allow you to access its config via a Web browser. To access your router’s setup, open a browser and enter the routers setup URL. The URL will be specified in the manual that came with the router.

The manual will also specify the default login details for your router. The problem here is that this means everyone knows what the default is so you need to change it. Once logged in it's usually pretty easy to find the link in the config to change the password.

If for any reason you don't have the manual for your router then you can search on the Internet using the term “default login for x”. Don’t be surprised to find quite a number of pages listing default login parameters for many different routers, even uncommon ones.

Step 2 - Disable router access from the Internet

If your router has the option then disable access to the router's configuration from the Internet. This will mean that you can still log in to the router to change the configuration from your internal network, but nobody from the Internet will be able to log in.

Step 3 - Add strong encryption

You need to encrypt your wireless network...really. Read that sentence again if you like, it's really important. Beyond that it's pretty important to use WPA encryption rather than WEP. WEP is better than no encryption at all, but it can be cracked in only a few minutes and the tools to do this are readily available.

Thursday, January 18, 2007

New online security solution ships from Clarity

Clarity Technology has released Internet Sheriff, a secure content management solution that is designed to protect an organisation from viruses and spam.

The new product lets IT administrators manage a company's Internet access, protect all of the users on the network from online attacks and reduce the impact of spam.

A spokesperson for the company said that the Internet sheriff product helps to reduce the chance of infection and minimises the amount of time that needs to be spent on dealing with unwanted marketing messages.

Network security sales top $1.1 billion in 2Q06

Worldwide network security appliance and software sales are up 2% to $1.1 billion between the first and second quarter of 2006, and is forecast to grow 30% between 2005 and 2009, when it will reach $5.1 billion, according to Infonetics Research's latest Network Security Appliances and Software report.

"It was a quiet quarter for the network security market once again, with most of the major players showing no or single-digit growth or small declines," said Jeff Wilson, principal analyst for network security at Infonetics Research. "Cisco had a down quarter overall, but posted gains in the secure router segment, which impacted their results in the price-banded appliance categories and in the intrusion detection and prevention categories. The market continues to commoditize as new vendors bring creative, affordable solutions to the table, driving costs down and competition up."

2Q06 Highlights

-- Cisco continues to lead in worldwide network security appliance and
software sales, with 36% of total revenue, a position they have more or
less maintained since 2002
-- For the first time, Juniper passes Check Point and is now in second
place for worldwide revenue at 10%
-- Check Point is now third for worldwide revenue at 9%
-- Integrated security appliances and software make up 85% of worldwide
network security revenue, IDS/IPS 15%


Infonetics' report provides worldwide and regional market size and forecasts and worldwide market share for integrated security appliances in 6 price categories, secure routers, SSL VPN gateways, VPN/firewall software, and host- and network-based IDS/IPS products.

Companies tracked include AEP, Array, Avaya, Aventail, Check Point, CipherOptics, Cisco, Citrix, CA, CyberGuard, D-Link, Enterasys, F5, Fortinet, Intel, Juniper, Lucent, McAfee, NETASQ, Netilla, Nokia, Nortel, Secure Computing, SonicWALL, Symantec, TippingPoint, WatchGuard, Whale, ZyXEL, and others.

Tarari to Speak at the Linley Group's "Embedded Network Security Design" Seminar

Tarari Inc., the award-winning hardware acceleration company, today announced that its CTO and co-founder, Jeff Carmichael has been invited to present during The Linley Group's Security Seminar "Embedded Network Security Design" on September 21, 2006, at the DoubleTree Hotel in San Jose, California. Tarari will present case studies on how to accelerate industry leading security applications such as Anti-Virus from Kaspersky Lab, Anti-Spam from Mail-Filters.com Inc., and Intrusion Prevention (IPS) from Intoto Inc., with Tarari's multi-core Content Processing ASICs. Tarari's "Content Processor" products are ASICs, production boards, and embedded software components that are designed to snap into networking, appliance, blades, and server systems.

Developers can immediately start building their designs using Tarari's silicon since Tarari supports a standard API across all of its software and silicon products. Tarari's Development kits enable customers to immediately develop cost-effective, leading-edge systems with enhanced functionality, proven interoperability and improved time-to-market.

Together Tarari Content Processors provide a scalable and comprehensive content inspection solution with a common application programming interface (API) all the way from 10 Megabits per Second (Mbps) to 10 Gigabits per second (Gbps.)

Tarari's family of T9000 Content Processor ASICs features the ability to concurrently support virus, intrusion, spam and compliance signatures -- while sustaining high line rates and are ideally suited for applications such as Unified Threat Management (UTM) appliances, content-based routing (CBR) and switching, application firewalls and security gateways, web acceleration, application networking, content filtering, anti-virus, regulatory compliance, database interfaces, and digital media.

The Linley Group's Security Seminar is the only dedicated security event for networking OEMs to help system developers who are designing security into routers and other networking equipment. The seminar is targeted at system designers, OEMs, network-equipment vendors, service providers, security vendors, media and the financial community.

F5's BIG-IP® Global Traffic Manager Receives Prestigious Global Product Excellence Award - Customer Trust from Info Security Products Guide; F5 Produc

the global leader in Application Delivery Networking, today announced that BIG-IP(R) Global Traffic Manager (GTM) has won Info Security Products Guide's 2006 Global Product Excellence Award for Customer Trust. More than 18,000 end-users and prospective customers worldwide were invited to vote for the products they trust the most when it comes to protecting their digital resources, and BIG-IP GTM was proclaimed "Winner of Excellence in Disaster Recovery."

The Global Excellence Awards are given to products designated "ahead of the curve" for their features and capabilities. BIG-IP GTM transparently routes end user application requests to the best performing site according to data center and network conditions or business policies to ensure the highest possible availability. Unlike its competition, F5's BIG-IP GTM offers best-in-class management tools. Its unique design helps mitigate the effects of disasters, attacks, and application infrastructure failures, safeguarding against the loss of customer revenue, satisfaction, and productivity. The device's comprehensive health monitoring provides a holistic view into application and data center health from a centralized location.

"We believe this award represents F5's commitment to helping organizations meet their business continuity goals," said Erik Giesa, Vice President of Product Management and Product Marketing at F5. "BIG-IP Global Traffic Manager one-click failover process eliminates the errors and inefficiencies related to manual failover management while giving organizations a unified, cohesive framework to manage all their application services across multiple sites."

BIG-IP GTM is built on F5's unique TMOS architecture that provides enterprises with a holistic way to solve the challenges of keeping their business-critical applications up and running in the event of a disaster or even during routine maintenance without affecting performance or placing an additional burden on administration. F5 is the only vendor in the industry to provide organizations with a programmatic approach for traffic distribution. Using programmable iRules, organizations can implement customized global traffic distribution policies that are more in line with their business goals.

For more about BIG-IP GTM, please visit www.f5.com/products/bigip/gtm/index.html or view its listing as part of the Info Security Products Guide at

Tuesday, January 09, 2007

Info to Go

A powerful office productivity tool that can cut your business chores down to size, Scopeware Small and Medium Business Server is marketed under the label of knowledge management. Certainly, the product facilitates collaboration and sharing of digital assets, but its reach doesn't stop there.

Scopeware organizes, indexes, and structures information that often falls through the cracks of other business applications. All documents, e-mails, spreadsheets, databases, presentations, and graphics files related to a single topic can be found in a keyword search and presented in a graphical stream, complete with thumbnail views.

Do you need to see all memos, purchase orders, and service records related to a single customer? Want to view an individual department's budget history? Simply enter your search criteria, then click on a thumbnail to begin working with the data.

The default install, ideal for small businesses, takes under 10 minutes and requires only a basic knowledge of networks; you must configure users, group rights, and permissions separately. Larger organizations should opt to install the prodOnce installed, Scopeware indexes all files on your network, including metatag information. It creates a Superuser account for a master administrator who can assign administration rights to other users to administer individual departments or groups. Using simple menu selections, administrators write rules to establish security equivalencies and permissions, as well as control the flow of information. Users can also write their own rules and add files to the stream.

Any company that needs a tool to structure its digital assets through an easy-to-use, practical application can count on Scopeware to handle the job. The software is best suited for consultants, resellers, and other IT professionals looking for ways to enhance systems competitively.uct over a directory service to centralize administration.

Monday, January 08, 2007

GLESEC and Insightix Bring Enterprise and Small-to-Medium Size Organizations Alike with Real-Time Network Knowledge and Security Access Control

GLESEC announces the addition of Network Access Control (NAC) technology to its portfolio of stat-of-the-art security technologies. With the addition of unique offering from Insightix (www.insightix.com) that combines its agentless, real-time element discovery technology with network-wide access controls, GLESEC brings a complete solution that provides organizations with visibility and control over their computer networks.

GLESEC's model provides a turnkey solution combining technology with its professional deployment and on-going support or managed services. This is intended to provide GLESEC Members with a comprehensive solution to their needs for knowing all the elements of a network for inventory/asset management, help-desk and security with network access control. GLESEC Members can focus on the usefulness of the technology while GLESEC focuses on its delivery and operations.

Insightix NAC provides complete contextual IT infrastructure information to serve as the basis of a network access control policy. Insightix NAC constantly monitors the network to provide accurate IT infrastructure information and detect in real-time any new device that connects to the network. Based on the wealth of information discovered on all the IT assets and their associated properties, including element type, MAC address, IP address, operating system, open services, switch and connected switch port, patch information and more, IT professionals can easily baseline their networks and define an enforceable network access control policy. Any device that does not comply with the network access policy is denied connectivity as it attempts to attach itself to the network.

Unlike existing network access control solutions, Insightix NAC simplifies the implementation of network access controls. Insightix NAC does not require network changes, specialized software and hardware or extended deployment efforts. Using Insightix NAC, IT professionals can define and begin enforcing a network access control policy in less then two hours.

"We are very excited to partner with Insightix in a continuous effort to bring the best technologies to the market. GLESEC Member-clients in the US and internationally expect this as a value added service," says Sergio Heker, CEO of GLESEC.

About Insightix

Insightix develops the only complete, real-time and agentless network discovery and network access control solutions. Insightix's solutions provide comprehensive network coverage and deliver an immediate return-on-investment for IT operations, network security and regulation compliance. Insightix solutions are simple to install and overcome the technical limitations of existing solutions.

Insightix's investors include Quest Software (NASDAQ: QSFT), several technology veterans and Blumberg Capital. The company's advisory members include industry leaders from IBM, Computer Associates, Citrix, Check Point, RSA, Comverse, ECI Telecom and AudioCodes.

Sunday, January 07, 2007

New Infoblox Network Services for VoIP Solution Dramatically Increases IP Phone System Reliability, Security and Manageability

Infoblox Inc., a developer of essential infrastructure for identity-driven networks (IDNs), today announced availability of the new Infoblox Network Services for VoIP package, which delivers highly reliable, secure and easy-to-deploy IP address assignment and management (DHCP/IPAM), file transfer (TFTP/HTTP), and network time (NTP) services -- all essential for the operation of an IP phone system.

By eliminating key problems that typically arise in IP telephony deployments and operations, the Infoblox solution -- ideal for mid-to-large distributed enterprise customers -- provides benefits to end users, integrators and VoIP equipment vendors while adding less than 5 percent to the IP phone system cost. It reduces IP phone system implementation effort, operational cost, downtime and security risk for end users. And, it greatly enhances effectiveness -- and profitability -- for VoIP system integrators by differentiating their offerings and enabling faster, easier deployments.

"Many organizations are choosing to implement IP phone systems based on the expectation of cost savings compared to traditional phone systems," said Jon Oltsik, senior analyst, Enterprise Strategy Group. "Unfortunately, many of the cost savings and supposed operational benefits of implementing VoIP are often compromised because customers underestimate the demands that IP telephony will place on their existing systems and personnel that supply and manage network identity services supporting the VoIP application. Enterprises and their VoIP integration partners can benefit greatly from upgrading these key systems as a part of their VoIP rollout."

Infoblox Network Services for VoIP Package

Infoblox appliances with the new Network Services for VoIP package deliver integrated, nonstop DHCP, IPAM, TFTP/HTTP, NTP and RADIUS proxy services. The hardened appliance design delivers these services with higher security and reliability and easier management than the traditional approach -- typically software deployed on general-purpose servers.

Further, the Network Services for VoIP package includes the Infoblox Keystone upgrade that links a group of distributed appliances into a unified, resilient ID grid. This enables customers to centrally manage all appliances and services and automates time-intensive tasks such as distributing IP phone firmware images to TFTP or HTTP servers at remote sites. For example, phone firmware files can be loaded once into a grid master device and automatically distributed to member appliances in each remote location one time over the WAN link. This reduces the need to deploy white-box servers and manage disparate software and operating systems at remote sites. It also greatly increases operational efficiency for firmware upgrades, which may be triggered every time a phone reboots and may also be required to address security vulnerabilities or add new features to phones.

The Network Services for VoIP package also provides diagnostic and troubleshooting capabilities that are especially useful for supporting VoIP deployments at remote sites that may be too small to staff with dedicated IT personnel. For example, file download attempt logging and correlation allows easy identification of failed or missing phone configuration downloads. The solution also provides extensive high-availability services that ensure local survivability and redundancy for enterprise-wide "dial-tone" like VoIP system reliability.

Saturday, January 06, 2007

Cisco Systems delivers NAC Appliance 4.0

Cisco Systems Inc (NASDAQ:CSCO), a provider of networking for the Internet, announced on Monday (10 July) the delivery of NAC Appliance 4.0, the latest edition of the company's Network Admission Control solution.

According to the company, the NAC Appliance 4.0 provides policy enforcement at network entry points throughout the enterprise, featuring policy enforcement capabilities for protecting local-area networks (LANs) as well as remote office, VPN, and wireless access points.

The solution is reportedly based on Cisco NAC's four basic elements - authentication/posture assessment, policy enforcement, quarantine/remediation, and centralized management. At each entry point, Cisco's NAC Appliance 4.0 identifies all users and networked devices, from employees, contractors, and guests to end points with various operating systems, PDAs, printers, and IP phones. The NAC Appliance assesses their role in accessing the network, verifies their compliance with corporate security policies, and grants appropriate network privileges, the company claims.

Friday, January 05, 2007

Crisp Thinking introduces Child Protection Gateway for ISPs

A system designed to provide Internet protection for children at the network layer has been introduced by Crisp Thinking Limited, a UK company developing solutions for the ISP marketplace to meet the needs of children, teenagers and parents.

According to Crisp Thinking, the Child Protection Gateway (CPG) enables parents to monitor all Internet traffic in the home and is intended to be installed by ISPs. It said the CPG provides protection at the network layer and claimed it is the first system which cannot be circumvented, resolving the problems presented by PC-based software.

The CPG is available to the entire family, does not need to be installed by the parent, and authenticates every user, recording all traffic including logging for instant messenger services such as AOL, ICQ, MSN and Yahoo. It enables parents to be alerted by text or e-mail when their child enters what might be a dangerous conversation.

The CPG provides a web-based control panel for each customer, enabling parents to set protection levels and view activity for each member of the family, and rates content and alerts for each session. It also offers a 'Dual Key' approach for older children, helping to protect the privacy of the child, and allowing actual content to be viewed by parents only after their child has consented.

Thursday, January 04, 2007

Encryption Issues: Moving Toward Higher Performance Network Security Subsystems - Industry Trend or Event

The Internet is an inherently insecure medium. Sensitive data must be encrypted before being dispatched, meaning that all Virtual Private Network (VPN) traffic must be encrypted before it is transmitted. This is particularly important for e-commerce involving credit card numbers, bank statements, corporate proprietary records, and other sensitive data.

The growing popularity of e-commerce and VPNs is making cryptographic security a critical gateway feature. But at the same time, it is creating a major gateway bottleneck. Internet gateways handle enormous volumes of traffic from many simultaneous sessions. Computational demands of security are greater compared to other gateway tasks. Consequently, as secure sessions become more common, the usual gateway architecture is increasingly less suitable.

Security functions are overly burdensome largely due to the nature of algorithms employed and the fact every byte in a packet must be processed. Most other gateway tasks only operate on packet headers. Cryptography works on the premise that an encrypted message is virtually impossible to decode by an unauthorized user, but is merely difficult to the authorized user. The algorithms used to implement security, encryption, compression, and authentication can be performed in software, which is ideal for systems handling small numbers of connections.

Wednesday, January 03, 2007

Network keeps students mobile: University of Georgia project uses authentication servers for security

Networked computers have become as much a part of the university experience as desks and chalkboards, and wireless network access is one of the ways universities keep score of who is best serving the needs of faculty and students. In this environment, the University of Georgia's PAWS Project (Personal Access Wireless/ Walkup System) is a major step toward keeping UGA, with its 33,000 student body, at the forefront of major institutions of higher learning.

The PAWS Project began as a single-site experiment that has grown to encompass the majority of more than 420 access points scattered across the university's Athens, Ga., campus. As the project grew from experiment to deployed infrastructure, administrators realized that several key user interface and security considerations had become requirements.

Security was key, as administrators wanted to be sure that network users were legitimate students and faculty who could authenticate their log-in names against a central database. A consistent user interface was a secondary consideration, as administrators knew that they could not so inconvenience users that they sought ways to circumvent the secure installation.

Tuesday, January 02, 2007

Official Rules For The Ziff Davis Media eWEEK Network Security Survey Sweepstakes

Official Rules For The Ziff Davis Media eWEEK Network Security Survey Sweepstakes ELIGIBILITY: Employees, officers, and directors of Ziff Davis Media, Inc., SurveyMonkey.com LLC, their subsidiaries and affiliated companies (collectively "Sponsors"), their immediate families and those living in their households, are not eligible. Employees and principals of the agencies of the Sponsors, their immediate families and those living in their households, are not eligible. Void where prohibited by law and subject to all applicable federal, state and local laws. NO PURCHASE NECESSARY: To enter the Sweepstakes, accept the invitation posted in a Ziff Davis Media publication newsletter to participate in a survey. Completion of the survey will automatically enter you in the Sweepstakes. The registration instructions that are a part of the survey will request you to submit your name, and e-mail address (if you have one) in order to be eligible to receive a prize. Participation in the survey is the only means of entering the Sweepstakes online. You may also enter the Sweepstakes by printing your name, address, daytime telephone number, e-mail address (if you have one) and the name of the Sweepstakes, Ziff Davis Media eWEEK Network Security Survey Sweepstakes, on a 3 x 5 card and mailing it to: Ziff Davis Media, Inc. Attention: Sweepstakes Department, Research Group, 28 East 28th Street, New York, NY 10016. The Ziff Davis Media eWEEK Network Sercurity Survey Sweepstakes begins at 12:00 a.m. Eastern Time (United States) on July 7, 2004 and ends at 11:59 p.m. Eastern Time (United States) on July 28, 2004. Online entries must be received by 11:59 p.m. Eastern Time (United States) on July 28, 2004. Mail-in entries must be postmarked between July 7, 2004 and July 28, 2004, and must be received by August 1, 2004. Only one (1) entry per person per household address is permitted. All entries become the exclusive property of the Sponsors and will not be acknowledged or returned. Sponsors and their agencies shall not be liable for (a) late, lost, damaged, incomplete, illegible, unintelligible, or postage-due entries; (b) telephone, electronic, program, network, Internet, or computer failures of any kind; or (c) failed, incomplete, garbled, unintelligible, or delayed computer messages. PRIZES: One Grand Prize winner will receive a $300 gift check payable in U.S. funds. No substitution or transfer of prizes is permitted by the winners. Sponsors reserve the right to substitute a prize of equal or greater value. Winners are responsible for payment of all federal, state or other tax liabilities (including income taxes) on any prize received, and must furnish Sponsors with his/her social security number. PRIZE DRAWING: The winner of the Ziff Davis Media eWEEK Network Security Survey Sweepstakes will be determined by a random drawing conducted by Ziff Davis Media, Inc. on or about August 1, 2004. The winner will be announced on or about August 5, 2004, and the winner will be notified by e-mail or by phone on or about the same date. The winner will have fourteen (14) days from notification to accept the prize by e-mail or by phone. Sponsors and their agencies shall not be liable for unsuccessful efforts to notify a winner. If a winner does not respond to notification of winner status within fourteen (14) days from notification, or if the winner does not meet qualification criteria, Sponsors reserve the right to select an alternate winner. In the event of a dispute regarding the identify of a person submitting an on-line entry, the entry will be deemed to be submitted by the Authorized Account Holder of the e-mail address at the time of entry. "Authorized Account Holder" is defined as the natural person who is assigned the e-mail address by an Internet access provider, on-line service provider, or other organization (e.g., business, educational institution, etc.) that is responsible for assigning e-mail addresses for the domain associated with the submitted e-mail address.

Monday, January 01, 2007

Yahoo and Symantec unveil joint consumer Internet security service

A joint consumer Internet security service has been unveiled by Internet company Yahoo Inc and security solutions company Symantec Corp.

The two companies will offer the Norton Internet Security product from Symantec to Yahoo's customers, while Symantec will gain access to the customers using Yahoo services. The agreement is expected to help the companies compete against competitors such as software company Microsoft Corp and Internet search engine Google Inc.

The co-branded Norton Internet Security product will be marketed by Yahoo and Symantec through the Yahoo network, which incorporates online services such as Yahoo Search, Yahoo Mail and Yahoo Toolbar. Symantec will offer its anti-virus and online firewall protection on Yahoo's Online Protection for broadband users and provide Norton Spyware scan for the Yahoo Toolbar.

Yahoo customers can sign up for a free 30 day trial of Norton Internet Security, which blocks viruses, spam and adware, and then purchase a USD49.99 12 month subscription, which includes a USD20 discount for Yahoo users.

Sunday, December 31, 2006

Skybox Security introduces Skybox View 3.0

Skybox Security, Inc, a company specialising in Security Risk Management (SRM), launched on Tuesday (25 July) Skybox View Suite version 3.0.

According to the company, Skybox View v3.0 enables security and IT operations teams to use a common platform to automate processes associated with risk exposure assessment, network policy compliance, firewall configuration audit, and change assurance.

Skybox View 3.0 reportedly features automated firewall audit; regulatory compliance reporting; intrusion prevention system (IPS) modelling; application and database vulnerability scanning support; zero-day worm attack simulation; as well as modular and scalable architecture.

No pricing details were disclosed.

Saturday, December 30, 2006

Travel Security Update

For more safety & security news, data and analysis, please go to: http://www.airguideonline.com/professional.htm Jul 31, 2006

Passports soon to be needed for Canada, Mexico, Caribbean. New laws will require U.S. travelers traveling by air or sea to the Caribbean, Mexico and Canada to have passports starting Jan. 1. The laws are intended to make it harder for terrorists to enter the U.S. Some lawmakers and travel organizations want to delay implementation for a few years and find an alternative system for U.S./Canadian border crossings. Jul 28, 2006

Waste, mismanagement plague DHS contracts, report finds. A bipartisan report has found widespread waste, abuse and mismanagement in many Department of Homeland Security contracts. The House Committee on Government Reform report says contracts were poorly planned and monitored and awarded without competition. It cites one case in which the Border Patrol paid $20 million for camera systems that either malfunctioned or were never installed. Jul 27, 2006

CACI wins DHS technology pact. Technology contractor CACI has landed a contract to provide information technology support to the Department of Homeland Security. The company will provide IT planning, network architecture and enterprise resource management. Jul 27, 2006

Friday, December 29, 2006

Homeland Security Briefing on U.K. Terror Arrests; DHS Secretary Michael Chertoff, Attorney General Alberto Gonzales, TSA's Kip Hawley

We'd like to provide you with the latest information we have on recent events in the United Kingdom and an update on the actions that we are taking to protect our citizens and to keep air travel safe and secure.

We want to be as open as possible with the public about the facts. At the same time, it's important, I'm sure you'll understand, that we preserve confidentiality of matters that are necessary in order to complete this investigation. And we also have to respect the demands of the British legal process, which puts certain restrictions on what can be said about ongoing cases.

As I think you're all aware, British authorities have arrested 21 individuals who are now in custody who are alleged to have engaged in a plot to detonate liquid explosives on board multiple commercial aircraft departing from the United Kingdom and bound for the United States.

Thursday, December 28, 2006

Cisco issues security warning

Cisco has issued a security warning about code published on the internet that targets weaknesses in its Internetwork Operating System (IOS).

The code was written by a group of teenagers in Italy calling themselves the Black Angels, and it exploits nine vulnerabilities in IOS, which runs on the Cisco Catalyst Ethernet switch, IP routers and other products.

The new program, called Cisco Global Exploiter, provides simple code streams to make it easier to exploit the weaknesses, most of which have been identified by Cisco over the past four years, and get round the vendor's workarounds.

"Customers should take steps to ensure that they have addressed each of these either via a software upgrade or workarounds in place as appropriate in order to mitigate any risk from this new exploit code," the company said on its web site.

Most of the vulnerabilities make Cisco routers and switches more susceptible to distributed denial of service attacks. These attacks occur when hackers take control of servers and flood the network with millions of packets, which eventually cripple devices like switches and routers that try to process all the packets.

Wednesday, December 27, 2006

Moving beyond managed security: providers are using network-based services to build more efficient enterprise productivity models

The face of business is changing, placing new demands on business' communications networks. Today's corporate network must not only reach mobile executives as they travel from city to city, it must also extend to the remote outposts that traditionally were not part of the network at all. Whether it is a 24-hour gas station in Tulsa, a parts supplier in Detroit, or car dealer located in another area of the world, an IT manager must figure out how to equip each remote user or locale with the full resources of the corporate network. Add to this the complexity of securing the entire network from today's myriad threats and you have a situation that is untenable to most enterprises. Faced with stagnant budgets and limited staffs, more and more IT departments are delegating the chore of protecting the corporate assets to their service providers.

Service providers, already tasked with managing some of the world's most complex networks, have the resources and expertise required for servicing the extended enterprise 24X7. For the provider, offering managed security services in addition to basic connectivity increases both revenue and customer penetration. However, many service providers view managed security as an incremental service as opposed to a strategic offering that will solidify the relationship with the enterprise. Services such as managed firewall or DoS (denial of service) protection are implemented in such a way that the provider is vulnerable to being displaced by either a competing carrier or a decision to move the service in-house.

Tuesday, December 26, 2006

Compact VPN appliance - Security appliances and VPNs - Advantech Network Computing FWA-230 - Brief Article - Product Announcement

The FWA-230 is a VPN/security appliance with three 10/100 Mbps autosensing Fast Ethernet ports in the front panel for WAN, LAN and DMZ connections. Also on the front panel is a nine-pin, RS-232 serial port for local system management, maintenance and diagnostics. The unit is preinstalled with the hardened Linux operating system and the latest Check Point VPN-1/FireWall-1 SmallOffice software. Accessible through a removable cover, a 128-MB compact flash card is used to avoid any potential service disruption caused by a hard disk's mechanical/magnetic failures. Each FWA-230 is equipped with a 566-MHz Intel Celeron processor, 128-MB PC-133/100 SDRAM, and an optional slim-type 2.5", 9.5 mm IDE HDD for storing event log and user data, all housed in a 8.8"x1.5"x6.7" desktop chassis.--Advantech Network Computing

Monday, December 25, 2006

Making security pay: savings generated by improved efficiency should not be offset by security losses - Network Management

Telecom did not need to wake up to security following tragic events last September. Security was a high priority before September 11 and remains so today, yet providers need a comprehensive strategy for proactive network element security. Increased deployment of TCP/IP has created new challenges. Some elements are now more vulnerable to intrusion, resulting in lost revenue, increased maintenance costs and reduced QoS.

The extent of security breaches and the associated costs are difficult to measure. Service providers are reluctant to disclose information about vulnerabilities for fear of encouraging more attacks. In addition, some security costs are not even being captured. Service disruptions or element malfunctions resulting from intrusions may be corrected without ever recognizing the intrusion, while theft of service can go undetected for years. Nevertheless, few knowledgeable professionals would deny that security is costing the industry millions of dollars each year.

Threats to TCP/IP-enabled network elements arise from both inside and outside the service provider organization, Certainly, outside attacks pose a real threat as hackers need only Internet access and an IP address to access unprotected network elements. Whether simply mischievous or truly malicious, hackers can steal or disrupt service and cause serious equipment malfunction.

Sunday, December 24, 2006

Securing network infrastructures: meshed topographies simultaneously preserve security and accessibility - Storage Networking

Over the past six years, malicious Internet attacks to corporate networks have increased 87%. This alarming growth of unauthorized network access clearly shows that the initial goal of creating shared, open infrastructures was not accompanied by an equally strong commitment to network security.

Let's take a pragmatic look at network security, while focusing on preventing network violations at the access point and discussing some practical recovery options.

Growing Security Threats

In the past, external security breaches represented a small percentage of violations, with most violations coming from within the network. From 1996 to 2001, the source of network attacks has shifted from internal to external violations.

While the number of intrusions by hackers has increased, internal security breaches--often by disgruntled employees--still represent the greatest number of computer crimes. Over the last two years, growth in the technology industry has slowed dramatically, resulting in large-scale layoffs. This, m turn, has made corporate networks the target of many disgruntled employees. In 2001, for example, technology and manufacturing companies reported $151 million in intellectual property theft, accounting for 41% of the losses related to computer crimes.

Saturday, December 23, 2006

Protect and survive: network monitoring tools, rather than traditional security measures of firewalls and IDSs , provide the strongest protection agai

The issue of network security has never been far from the top of the organisational agenda. However, it is pushed to the forefront when high-profile security attacks occur, such as the denial of service attack suffered by the Computer Emergency Response Team (CERT) last year. This made it clear that determined hackers can damage even the experts, and highlighted the fact that service providers and enterprises that depend on internet connections must take more stringent measures to protect themselves.

The notion that companies need to implement a full security policy is of course nothing new -- experts have been espousing the benefits of firewalls and intrusion detection systems (IDS) for years. However, as the CERT attack shows, anyone can get stung.

The CERT co-ordination centre is a hub of knowledge on internet security vulnerabilities and gives advice and training to improve network security. Last year the organisation was knocked offline for two days by a denial of service attack preventing anyone from accessing the CERT website. A spokesperson for CERT explained that connection to the internet had been totally saturated by the attack. The irony here is that the group was most probably targeted for attack in the first place because of its status as a champion for internet security issues.

Friday, December 22, 2006

Juniper focuses on network security: CEO sees system integrators emerging as key telecom players amid industry evolution

Juniper Networks has realigned its security focus after its acquisition of NetScreen, with a push toward integrated security instead of stand-alone point solutions. Juniper CEO Scott Kriens, in a recent interview with Group Editor Joseph Waring, notes that trusting the network is the key in the drive toward an all-IP, ubiquitous network.

America's Network: There's been a great deal of talk about ubiquity. How important will it be in the near-term?

Scott Kriens: We believe there's going to be a ubiquitous network, it will be a single infrastructure, it will carry multiple services, it will be very intelligent, it will enhance our lives. That will all be true some day. The observation that that it is true is meaningless. The issue is when will what elements within that grand claim be true and what will it mean when they are. It is the path to how one gets there that is where all the real opportunities lie.

One of the reasons for the acquisition of our security portfolio is that we believe that the key enabler to making it all happen faster is that you have to trust the network to use it more. That is one driver. It not only has to be secure, but it also has to be assured, it has to be reliable and has to be able to deliver the quality for the video signal that I'm going to drive across it.

Thursday, December 21, 2006

Intrusion Detector delivers open-source network security

Using proprietary Meta Traffic Processor, MTP-1G wire-speed Gigabit Ethernet Network Intrusion Detection and Prevention System supports open-source network security and monitoring applications. Cards pass Gigabit Ethernet traffic between system's 2 ports with 400 ns latency while performing wire-speed, stateful, packet inspection. When determining whether to capture or block packets, cards can apply up to 1,500 wire-speed stateful policies per packet.

Los Gatos, California - Metanetworks Technologies, Inc. (metanetworks.org), a leading provider of high-speed network security and monitoring hardware, announces its MTP-1G - the world's first wire-speed Gigabit Ethernet Network Intrusion Detection and Prevention System (IDPS) specifically designed to support open-source network security and monitoring applications. The MTP-1G uses Metanetworks' Meta Traffic Processor (MTP), a unique network processor that was partially developed using research grants from the National Science Foundation and the US Air Force Rome Laboratories. The MTP is specifically designed to exploit massive, fine-grain, instruction-level parallelism, which is intrinsic to IDPS processing loads. Livio Ricciulli, Metanetworks Technologies' chief scientist, states that, "our MTP cards offer the lowest IPS filtering latency in the world because of our breakthrough processing architecture."

Metanetworks' MTP-1G cards routinely pass Gigabit Ethernet traffic between its two ports with 400 ns latency while performing wire-speed, stateful, packet inspection. When determining whether to capture or block packets, the cards can apply up to 1500 wire-speed stateful policies per packet. When the MTP-1G captures packets, it presents them to the operating system as a standard NIC in promiscuous mode.

Wednesday, December 20, 2006

Messaging System/Anti-Spam Service offer network security

FortiMail Secure Messaging Platform includes antivirus detection engine for virus and spyware protection and complete email scanning. It uses FortiGuard-Antispam, access policy filtering, content filtering, global and user black/white list filtering, and spam Real-time Blackhole List. FortiGuard-Antispam Service eliminates spam at network perimeter. It checks against known spammer IP addresses and email content with Universal Resource Identifier scanning.

FortiMail(TM) Family and FortiGuard-Antispam Service Offer Enterprises Multi-Layered Protection to Eliminate Spam and Inline Network Viruses

SUNNYVALE, Calif., Feb. 7-- Fortinet -- the confirmed market leader in Unified Threat Management and only provider of ASIC-accelerated, network-based antivirus firewall systems for real-time network protection -- today unveiled two powerful new additions to its network security solutions and services portfolio: FortiMail, a secure messaging system, and FortiGuard-Antispam, a managed antispam service. The FortiMail Secure Messaging Platform and FortiGuard-Antispam Service effectively layer antispam technology to offer antispam defense in-depth at the network perimeter and the mail server -- maximizing mail traffic performance by eliminating global spam at the network gateway, before it enters the corporate network.

Unwanted email or spam continues to present serious security challenges for enterprises and consumers alike. Increasingly, these messages contain spyware, grayware or other malicious attempts to adversely impact a customer's computing and networking resources. While many world governments have been writing legislation and enforcing penalties around spam creation and delivery, spam continues to be difficult to regulate and catch. Industry researchers suggest that 60 to 70 percent of all enterprise email is spam, and recent statistics suggest that a good portion of spam contains viruses or other types of attacks.

Tuesday, December 19, 2006

Strong wireless security for the SOHO network

It's likely your home users haven't enabled security on their wireless networks. As the go-to guy you can configure security settings for them and hope those users don't mess those settings up, or add software that lets users add and remove new and visiting users (as for when your teen's friends come over) without much effort (or calling you on the phone).That's the idea behind Interlink Networks' LucidLink, which provides enterprise-level wireless security simply enough to use on the home network.

The software uses encryption based on Wi-Fi Protected Access (WPA), along with advanced authentication techniques to protect network traffic and initial access.lt uses a client/server model to authorize only those clients given specific permission to access the LAN.

WPA provides a higher level of protection than Wired Equivalent Privacy, but it doesn't address user authentication. Granting and revoking access to your wireless network, say, at the beginning and end of a LAN usage cycle, often involves changing the encryption key on every system on the network. LucidLink streamlines this process down to two button clicks.

Monday, December 18, 2006

Evolving Network Demands Improved Security, The

A decade ago, a company could effectively secure its network through perimeter protection such as a firewall. At that time, networks had definitive borders, making it easier to safeguard critical internal assets with perimeter security technology.

However, as organizations recognized the business benefits of extending network access to customers, partners and vendors, the once-distinct perimeter quickly dissolved. With this increase in credentialed users now accessing the network from the outside, safeguarding internal assets with security technology located solely at the perimeter proved insufficient. Nonetheless, within many organizations, internal security still placed second in priority to increasing business process efficiency.

There is an inherent trade-off between security and accessibility, but many organizations have sought to strike a balance between making it easy for people to access the systems they need while still remaining secure. Yet many organizations, including CRM centers, are still exposed to more risk than necessary because they have not addressed the security ramifications associated with extending their network to third parties. For an organization to be truly protected today, it must continue to mind the perimeter, but it must also turn its focus inward and secure the internal network.

Sunday, December 17, 2006

Weathering a Perfect Storm: Protecting your Email Network with a Layered Security Architecture

As an enterprise IT manager, your biggest email headache today is viruses. Yesterday it was Denial of Service attacks. Tomorrow it will be spam and phishing. Or perhaps customer privacy, regulatory compliance or employee misuse of email will consume your time and attention. You've responded to constant threats and risks with a variety of point products, both at your gateway and inside your network. The result: an email infrastructure that is enormously complex, costly to manage and not ready to protect your business when the next email security crisis inevitably hits. The truth is, no single product is a silver bullet. Large enterprises with complex networks need to take an architectural approach to email security. In this informative 50-minute eSeminar, Sendmail will explain the fundamental elements of email security architecture. Based on our experience implementing email systems for the world's largest enterprises, we'll explain: The four basic layers of email security architecture Typical security gaps in complex email networks, and how to fix them Best practices to improve email security in a multi-vendor environment If your email security architecture needs a closer look, join us for this revealing discussion, including an opportunity for live Q&A.

Saturday, December 16, 2006

Movin' On Up: Security Branches Off the Desktop and Onto the Network

Today's hackers are growing in their technological prowess and sophistication. Their extreme coding capabilities have allowed them to penetrate an Internet browser without a user ever opening up a corrupt e-mail file. To try and combat this, corporations are moving their security and antivirus efforts to the network level. This move to intrusion protection has resulted in a slew of new technologies and appliance-based security products that can be loaded on to networks and scan for viruses and other security threats. Whether your company is running a single vendor computing environment or, more commonly, a more complex multi-vendor environment, there are benefits to be realized by this security strategy. Join Larry Seltzer, editor of eWEEK.com's Security Center and a panel of experts as they discuss: The difference between security at the desktop level and at the network level The major benefits derived from securing the network What are the applications involved in this security strategy Should this strategy be managed by internal IT or a managed services company?

Friday, December 15, 2006

Cisco issues security warning

Cisco has issued a security warning about code published on the internet that targets weaknesses in its Internetwork Operating System (IOS).

The code was written by a group of teenagers in Italy calling themselves the Black Angels, and it exploits nine vulnerabilities in IOS, which runs on the Cisco Catalyst Ethernet switch, IP routers and other products.

The new program, called Cisco Global Exploiter, provides simple code streams to make it easier to exploit the weaknesses, most of which have been identified by Cisco over the past four years, and get round the vendor's workarounds.

"Customers should take steps to ensure that they have addressed each of these either via a software upgrade or workarounds in place as appropriate in order to mitigate any risk from this new exploit code," the company said on its web site.

Most of the vulnerabilities make Cisco routers and switches more susceptible to distributed denial of service attacks. These attacks occur when hackers take control of servers and flood the network with millions of packets, which eventually cripple devices like switches and routers that try to process all the packets.

Thursday, December 14, 2006

Network Security Services identify site vulnerabilities

Suited for Foxboro I/A Series automation systems, service is designed to protect against cyber attacks and other network intrusions at industrial sites. Site Security Review Service and System Security Hardening Service also help users develop effective security plan, identify specific site vulnerabilities, and protect against potentially catastrophic intrusions.

New services are designed to help identify site vulnerabilities and protect against cyber attacks and other network intrusions at industrial sites

HOUSTON, TEXAS, USA (ISA 2004 Conference and EXPO) - October 5, 2004 - Invensys Process Systems today introduced important new services designed to further enhance the security of the company's Foxboro-brand I/A Series automation systems. In development for more than two years, the new Site Security Review Service and the System Security Hardening Service are both part of Invensys' expanding suite of LifeTime Performance Improvement Services, which now also includes both Loop Management and Alarm Management services. These services work together to enable customers to maximize the performance of their installed automation assets.

"The industrial automation industry has been moving away from proprietary technology to more open and interoperable control systems. As underscored by a recent US government report , this trend clearly increases the potential vulnerability of these systems to cyber attacks via the Internet and from other external and internal network intrusions," said Ernest Rakaczky, director of process control network security at Invensys Process Systems.

Wednesday, December 13, 2006

Moving beyond managed security: providers are using network-based services to build more efficient enterprise productivity models

The face of business is changing, placing new demands on business' communications networks. Today's corporate network must not only reach mobile executives as they travel from city to city, it must also extend to the remote outposts that traditionally were not part of the network at all. Whether it is a 24-hour gas station in Tulsa, a parts supplier in Detroit, or car dealer located in another area of the world, an IT manager must figure out how to equip each remote user or locale with the full resources of the corporate network. Add to this the complexity of securing the entire network from today's myriad threats and you have a situation that is untenable to most enterprises. Faced with stagnant budgets and limited staffs, more and more IT departments are delegating the chore of protecting the corporate assets to their service providers.

Service providers, already tasked with managing some of the world's most complex networks, have the resources and expertise required for servicing the extended enterprise 24X7. For the provider, offering managed security services in addition to basic connectivity increases both revenue and customer penetration. However, many service providers view managed security as an incremental service as opposed to a strategic offering that will solidify the relationship with the enterprise. Services such as managed firewall or DoS (denial of service) protection are implemented in such a way that the provider is vulnerable to being displaced by either a competing carrier or a decision to move the service in-house.

Tuesday, December 12, 2006

Security Appliance ensures secure credit card processing

Developed to address Visa USA and MasterCard International's security requirements at application and content level, PCI Risk Assessment program provides visibility into network applications used by employees to transmit data such as credit card numbers. PacketSure PCI security appliance performs deep packet analysis at packet level to determine what communication protocol is being used and only allows authorized protocols to be used to transfer corporate data.

Risk Assessment Program Will Use Palisade's PacketSure PCI Appliance to Analyze Network Applications Being Used by Employees to Transmit Credit Card Data

AMES, Iowa, Aug. 8 -- Palisade Systems, a leading provider of content and network security appliances, announced today a PCI Risk Assessment program for organizations processing and/or storing credit card information. Palisade's PacketSure PCI security appliance was developed specifically to address Visa USA and MasterCard International's soon to be unveiled security requirements at the application and content level. The first of its kind program is being offered to companies on a seven day risk assessment period. PacketSure PCI provides the visibility into the network applications being used by employees to transmit data including credit card numbers.

PacketSure PCI performs deep packet analysis at the packet level, not port level, to determine what communication protocol is being used. PacketSure eliminates unwanted applications being used on an organization's network allowing only authorized protocols to be used to transfer corporate data. PacketSure provides an additional layer of security on the authorized protocols by analyzing the data within the packets traveling across the network giving unprecedented security and compliance to Visa and MasterCard's PCI standards. PacketSure has been used as an assessment tool before, acting as a test monitor for simulations and cyber competitions by the U.S. Department of Justice funded Internet-Simulation Event and Attack Generation Environment cyber security lab.

Monday, December 11, 2006

Trend Micro unveils 2007 Internet Security

Antivirus and content security firm Trend Micro Inc (NASDAQ: TMIC) announced on Wednesday (20 September) the 2007 version of its Internet security suite.

According to the company, the 2007 Internet Security release will incorporate Trend Micro's PC-cillin engine and anti-malware protection, as well as TrendSecure, Trend Micro's new online security services. The suite is reportedly designed to identify, block and automatically remove viruses, trojans and spyware; filter spam; warn about unauthorized wireless access to the network; block objectionable content; identify fraudulent phishing scams; and provide users with real-time defence against online and offline identity and data theft.

Trend Micro Internet Security comes with a household license for up to three PCs for one year at GBP49.95, including free email and online support and the TrendSecure online services

Sunday, December 10, 2006

Research center plugs physical security into its network

Keeping its huge data center humming is vital at NASA Ames Research Center, where 4,000 scientists are working on aeronautics and biotechnology projects. When a new custom-built air conditioning system couldn't keep the research outfit's network equipment at the right temperature, it was the IT department's equivalent of a space mission gone wrong.

"It failed miserably? says George Alger, assistant division chief of the applied information technologies division and IT services manager. He worried that the A/C fluctuations threatened to disrupt or even damage the 50 racks of servers and .switches housed in the Moffett Field,Calif.,data center.

"The air conditioning should have maintained 68 degrees to 70 degrees in the room, but it didn't," Alger says about the custom-built system, which cost about $800,000.

NASA Ames became aware of the high and low temperature spikes because two physical- security sensors from NetBotz continuously monitor the data center's environment.

Saturday, December 09, 2006

Security System strengthens phone authentication processes

With ability to automate and strengthen call center authentication to help financial institutions meet FFIEC guidance, RSA[R] Adaptive Authentication for Phone provides multifactor authentication for retail and commercial banking. It analyzes various phone channel-specific risk parameters, from phone number itself to biometric voiceprint and user behavior profiles. System generates risk and authentication score for every call received and every high-risk transaction conducted.

Leverages RSA's proven risk-based authentication expertise and live voice biometrics technology

Automates and strengthens call center authentication to help financial institutions meet FFIEC guidance

BEDFORD, Mass., Oct. 24 / - RSA, The Security Division of EMC (NYSE:EMC), today announced RSA[R] Adaptive Authentication for Phone. The product is designed to meet the financial industry's need for strong, automated and convenient caller authentication for telephone banking, given the nature of fraud migration and the regulatory requirements stated in the FFIEC's Authentication in an Internet Banking Environment guidance.

Designed with a focus on the end-user experience and strengthening phone authentication processes, RSA Adaptive Authentication for Phone leverages the core concept and expertise used in RSA Adaptive Authentication for Web, currently used by more than 35 of the top 100 US financial institutions and some of the largest banks in Europe. The new solution also incorporates RSA's voice biometric solution, based on the previously-acquired Vocent technology and integrated with the market-leading voiceprint engine from Nuance; the Vocent-Nuance solution is in production at several large banks in the United States today, with consumer-facing deployments planned for Q1 2007.

Friday, December 08, 2006

Keeping America out of harm's way: from a national health-surveillance network to better whistle-blower protection, security experts provide their com

U.S. leaders and our allies have made great strides in fighting terrorism and increasing homeland security. During the last seven months they have ousted the Taliban, frozen substantial assets used to fund Osama bin Laden and his associates, rounded up hundreds of likely terrorist "sleepers" and enacted a host of measures to try to stop the next attack before it happens.

This all comes at a price: The war on terrorism not only has cost billions of dollars, but precious lives as well. And every step along the way has required expenditure of political capital and high-level maneuvering of the sort that accompanies every initiative originating inside the Washington Beltway. The controversial USA PATRIOT Act, an attempt to balance security with concerns about civil liberties, and continued bickering about screening at the nation's airports show that the war on terrorism has been as divisive as many another war. Even when the United States is united, as polls indicate it is now, concerns about politics and money tend to slow the drive for reform.

Meanwhile, say Capitol Hill insiders, many of the nation's most vital structures remain vulnerable to attack, and measures to reform key institutions such as the Immigration and Naturalization Service still are being battered in bureaucratic turf wars. Does this mean the quest for a secure America has stalled? Not necessarily.

Thursday, December 07, 2006

Securing the network: Juniper Networks has realigned its security focus after its acquisition of NetScreen, with a push toward integrated security ins

Telecom Asia: There's been a great deal of talk about ubiquity. How important will it be in the near term?

Scott Kriens: We believe there's going to be a ubiquitous network, it will be a single infrastructure, it will carry multiple services, it will be very intelligent, it will enhance our lives. That will all be true some day. The observation that that it is true is meaningless. The issue is when will what elements within that grand claim be true and what will it mean when they are. It is the path to how one gets there that is where all the real opportunities lie.

One of the reasons for the acquisition of our security portfolio is that we believe that the key enabler to making it all happen faster is that you have to trust the network to use it more. That is one driver. It not only has to be secure, but it also has to be assured--it has to be reliable and has to be able to deliver the quality for the video signal that I'm going to drive across it.

How will it happen? The way the Internet got to scale was simply by dividing everywhere--that way it didn't have to happen in any one place. Ubiquity will happen in the same way. Pockets [of IP infrastructure build-outs] are popping up and establishing themselves and they will all look to connect. Major commitments to rolling out IP infrastructure already include moves by China Telecom, NTT East and West, Deutsche Telecom, MCI and Verizon. This peer-to-peer nature of the arrival of the Internet is going to be exactly the way the next generation of applications that will build on top of it will come into existence. Then we can create some standards to put some order to the chaos.

Wednesday, December 06, 2006

Technical advances expand the options available: urban rail operators face increased demands for greater security and safety. Advances in technology n

IF safety is seen as the guarantee of proper performance without accident, efficient signalling is the way to provide safe train organisation. If security is intended to defend against intentional and unlawful aggressions, closed-circuit television (CCTV) is a very useful tool to provide video surveillance.

Alcatel has used similar transmission technologies to combine fixed optical fibre networks and high-speed radio solutions to enhance both safety and security for urban rail. This is part of an integrated communication concept whereby a single multi-service platform supports the deployment of new advanced applications for a wide range of uses.

New digital systems have extended video surveillance from station platforms and concourses to trains on the move. Onboard equipment includes CCTV cameras, a digital video recorder (DVR), a mobile radio, and antennas. Access points at the wayside collect the video and interface it through the fixed backbone to the control centre. Thereby, on-board video is successively:

Tuesday, December 05, 2006

VoIP industry moves to bolster network security: new group to define requirements

Looking a decade ahead, the VoIP industry has taken its first steps towards foiling future attempts by Internet-style hackers to bring down a major IP phone service. A new group, the VoIP Security Alliance, or VOIPSA, recently launched two projects aimed at developing industrial-grade VoIP security methods.

VOIPSA members include manufacturers, service providers, research institutions and consultancies. The first two projects of the organization, which was formed in February, aim to develop a "threat taxonomy" and to define security requirements.

VOIPSA's efforts will be of particular interest to manufacturers of session border controllers, or SBCs, which will for a long time to come play a crucial role in defending VoIP networks from attack.

SBCs, which typically sit between the softswitches that control VoIP services and the public Internet, have a number of functions. One of the most important is firewall traversal. When a VoIP call has to go through a firewall, as most do, it can easily fail. Firewalls don't know how to deal with VoIP, which can involve as many as five separate data streams. SBCs know how to manuever both VoIP and video traffic through them.

Monday, December 04, 2006

Network security drives value

Many valuable business models depend vitally on secure networking. These business models include:

* Delivery of content (music, movies, TV, radio and interactive games);

* IP Network-enabled virtual enterprises, including work-at-home;

* E-commerce (retail, financial services, travel services and many transaction-oriented activities); and

* Messaging services such as e-mail and instant messaging.

Each model imposes its own unique security and performance requirements that influence economic success. Content delivery went nowhere until the RIAA (Recording Industry Association of America) was satisfied that the technology existed for secure content distribution. Network-enabled enterprise models are gaining favor now that IP traffic can be handled securely and privately in conformance with federal laws such as Gramm-Leach-Bliley and HIPPA.

Network security challenges include going beyond perimeter-based security, bad behavior by authorized applications, SPAM, patching, content filtering, vulnerability analysis and application traffic management.

Sunday, December 03, 2006

The coast is clear: security software lets you know who's on the network

Getting your Wi-Fi equipment set up for security isn't as troublesome as it once was, but it can still be a headache. That's where software like Interlink Networks' LucidLink (www.lucidlink.com) comes in, offering enterprise-strength security for small and midsize businesses.

Ease of use is a must, and LucidLink gets good marks in that area. The only major hardware requirement is a computer wired to your router to run the authentication server part of the package. That computer has to be on whenever you want to use the software, but it doesn't have to be dedicated to the task. A small client program is then installed and configured on each computer you want to connect to your wireless network. The administrator authorizes users and can keep track of who is accessing the network.

LucidLink supports automatic access-point configuration for some devices. For other devices, you might have to manually configure your access point or router following instructions available online. Check the website to see if your hardware is supported. LucidLink is free for three or fewer users. Otherwise, pricing starts at $549 for four to 10 users.

Saturday, December 02, 2006

Intrusion Detector delivers open-source network security

Using proprietary Meta Traffic Processor, MTP-1G wire-speed Gigabit Ethernet Network Intrusion Detection and Prevention System supports open-source network security and monitoring applications. Cards pass Gigabit Ethernet traffic between system's 2 ports with 400 ns latency while performing wire-speed, stateful, packet inspection. When determining whether to capture or block packets, cards can apply up to 1,500 wire-speed stateful policies per packet.

Los Gatos, California - Metanetworks Technologies, Inc. (metanetworks.org), a leading provider of high-speed network security and monitoring hardware, announces its MTP-1G - the world's first wire-speed Gigabit Ethernet Network Intrusion Detection and Prevention System (IDPS) specifically designed to support open-source network security and monitoring applications. The MTP-1G uses Metanetworks' Meta Traffic Processor (MTP), a unique network processor that was partially developed using research grants from the National Science Foundation and the US Air Force Rome Laboratories. The MTP is specifically designed to exploit massive, fine-grain, instruction-level parallelism, which is intrinsic to IDPS processing loads. Livio Ricciulli, Metanetworks Technologies' chief scientist, states that, "our MTP cards offer the lowest IPS filtering latency in the world because of our breakthrough processing architecture."

Metanetworks' MTP-1G cards routinely pass Gigabit Ethernet traffic between its two ports with 400 ns latency while performing wire-speed, stateful, packet inspection. When determining whether to capture or block packets, the cards can apply up to 1500 wire-speed stateful policies per packet. When the MTP-1G captures packets, it presents them to the operating system as a standard NIC in promiscuous mode.

The MTP-1G cards support existing, open-source network security and monitoring applications. They accomplish this by specifying capture and filtering policies using public-domain IDS signatures or standard network monitoring libraries. Metanetworks' MTP technology also provides developers a rich API for creating custom network security and monitoring applications.

Because the MTP-1G cards interface with the host operating system as standard NICs, they can seamlessly run a variety of standard application software at much faster speeds. For example, open-source Snort IDS software can monitor a few hundred megabits of traffic with a standard NIC. With the MTP-1G card, Snort can monitor a full gigabit of traffic without modification. The MTP-1G cards are also compatible with other popular libpcap-based network monitoring applications such as tcpdump.

The University of California, Santa Cruz (UCSC) will present the impressive capabilities of the MTP-1G PCI cards at the upcoming North American Network Operators' Group (NANOG) Conference from January 30th to February 1st in Las Vegas, Nevada. UCSC integrated a Metanetworks MTP into one of its production networks and has confirmed that it greatly enhanced their existing IDS capabilities. "The MTP enables a whole range of open source security applications that were not possible before," says Paul Tartarsky, the UCSC consultant network security engineer in charge of integrating the MTP-1G. "As far as I can tell, the MTP has eliminated a huge roadblock to developing high performance IDPS applications at a low cost."

Friday, December 01, 2006

Messaging System/Anti-Spam Service offer network security

FortiMail Secure Messaging Platform includes antivirus detection engine for virus and spyware protection and complete email scanning. It uses FortiGuard-Antispam, access policy filtering, content filtering, global and user black/white list filtering, and spam Real-time Blackhole List. FortiGuard-Antispam Service eliminates spam at network perimeter. It checks against known spammer IP addresses and email content with Universal Resource Identifier scanning.

Fortinet -- the confirmed market leader in Unified Threat Management and only provider of ASIC-accelerated, network-based antivirus firewall systems for real-time network protection -- today unveiled two powerful new additions to its network security solutions and services portfolio: FortiMail, a secure messaging system, and FortiGuard-Antispam, a managed antispam service. The FortiMail Secure Messaging Platform and FortiGuard-Antispam Service effectively layer antispam technology to offer antispam defense in-depth at the network perimeter and the mail server -- maximizing mail traffic performance by eliminating global spam at the network gateway, before it enters the corporate network.

Unwanted email or spam continues to present serious security challenges for enterprises and consumers alike. Increasingly, these messages contain spyware, grayware or other malicious attempts to adversely impact a customer's computing and networking resources. While many world governments have been writing legislation and enforcing penalties around spam creation and delivery, spam continues to be difficult to regulate and catch. Industry researchers suggest that 60 to 70 percent of all enterprise email is spam, and recent statistics suggest that a good portion of spam contains viruses or other types of attacks.

"As an industry leader in the design and manufacture of advanced semiconductors, we have many daily demands on our network and cannot sacrifice network performance due to spam, viruses or other unwanted network traffic," said Edward Huang, corporate IT infrastructure manager for Atmel. "Solutions such as Fortinet's network security platforms and FortiGuard-Antispam Service help to minimize unwanted and malicious network traffic, without network performance degradation or a lot of administrative overhead, which is essential for ensuring a productive business."

FortiMail Secure Messaging Platform

The FortiMail Secure Messaging Platform is a dedicated system based on Fortinet's award winning FortiOS technology and includes an antivirus detection engine for virus and spyware protection and complete email scanning. FortiMail uses advanced spam detection and filtering methods such as FortiGuard-Antispam, access policy filtering, content filtering, global and user black/white list filtering, spam Real-time Blackhole List (RBL), per user Bayesian filtering so that individual users can set their own profiles, heuristics filtering and denial-of-service.

The FortiMail-400 system is the first in a family of secure messaging platforms and is designed for medium to large enterprises and remote branch offices. Future FortiMail systems will be available to secure messaging for high-volume, mission-critical infrastructures such as large enterprises, universities and managed security service providers (MSSPs).

The FortiMail Secure Messaging Platform offers users three protective modes of operation:

-- Transparent mode: FortiMail platform is placed in front of the existing email server without any changes to the existing email topology to provide seamless integration into existing network environments.

-- Gateway mode: FortiMail platform is placed in front of the existing email server providing in-bound and out-bound email relay services, which allows for scanning of both in-bound and out-bound email messages.

-- Server mode: FortMail platform provides complete email server functionality in addition to antivirus and antispam functionality, which is ideal for medium sized companies and remote branch office locations.

FortiGuard-Antispam Service

FortiGuard-Antispam Service is a new fully managed service that helps companies of all sizes reduce the amount of spam by eliminating it at the network perimeter. Fortinet developed this service internally and optimized it for operation on Fortinet's FortiGate network security platforms and the new FortiMail system family. On either system deployment, FortiGuard-Antispam can significantly reduce the amount of unwanted and possibly malicious spam messages passing through corporate email servers.

Using Fortinet's "dual pass" scanning technology in either the FortiMail or FortiGate systems, the FortiGuard-Antispam Service checks against known spammer IP addresses and email content with Universal Resource Identifier (URI) scanning. URI scanning looks deep into each email message to scan for well-known spam content such as spam URL links. The pairing of this new service with Fortinet security systems will help increase spam detection rates, as spammers get more creative and use infected PCs to deliver spam.

Thursday, November 30, 2006

GFI LANguard Network Security Scanner 3.3

GFI LANguard Network Security Scanner 3.3 covers the basics of vulnerability scanning well, though it lacks some of the advanced capabilities found in more enterprise-focused products such as eEye's Retina Network Security Scanner and NetIQ's Security Analyzer 5.0. LANguard cannot take the in-depth look at CGI scripting that Retina can or scan some types of network hardware, such as routers. But it's also much less expensive than the products from eEye and NetIQ.

To perform a basic scan of your network, you simply enter an IP address or range and press Start. LANguard gives you many types of predefined security scan profiles. For example, you can scan using only ICMP for discovery, scan all available ports, or scan for open shares or missing patches. You can also define and save your own security scan profiles.

Without administrative privileges in a Windows domain, you can determine computer names, MAC addresses, open ports, operating system versions, and SNMP information, all reported in a tree structure of results sorted by IP address. With domain administrative privileges, you can determine significantly more information about each system, such as shares, user accounts, services, password policies, registry information, and installed patches. Your scan can also include testing for CGI abuses as well as FTP, DNS, mail, service, and registry vulnerabilities. The results are grouped by category and include either a recommendation for remediation or a BugTraq, CVE, or Microsoft Security Bulletin reference.

Within the report generator you can create and save custom reports to meet your individual security needs. For example, you can generate a report of all systems that have either TCP port 80 (Web) or port 21 (FTP) open. As with Retina and SAINT 5, an included utility lets you compare two reports for new, removed, or changed items, as well as alert and hot-fix changes.

LANguard is also marketed as a patch management and deployment solution. During a scan of a Windows network, LANguard determines which patches have been installed on your systems and which are missing, based on GFI's coordination with Microsoft. It deploys hot fixes as well as service packs.

Tuesday, November 28, 2006

Web Security Software protects mobile users outside network

Websense[R] Remote Filtering extends web filtering and web security technology to laptop users outside of organization's network to ensure secure internet use anytime and anywhere. Organizations can apply internet usage policies to remote users, protecting them from security threats and managing access to objectionable content. Specifically, software provides protection from accessing phishing sites, sites that contain spyware, or sites corrupted with malicious code.


New Functionality Will Extend Web Filtering and Web Security Policies to Remote Users, Regardless of Location or Type of Network Connection

SAN DIEGO, Sept. 19 -- Websense, Inc. (Nasdaq: WBSN), the world's leading provider of employee internet management solutions, today announced the upcoming release of Websense(R) Remote Filtering technology, extending Websense's industry-leading web filtering and web security technology to corporate laptop users outside of the organization's network. Remote Filtering capabilities will be seamlessly incorporated into the newest versions of Websense web filtering and web security software, expected to be available in October 2005.

With the growing rate of telecommuting and business travel, it has become critical for organizations to enable employees who work remotely to use their laptop computers effectively and safely. As broadband internet access becomes more pervasive in non-traditional settings such as airports, hotels or local coffee houses, the necessity to protect remote laptop users from malicious threats lurking in unknown networks intensifies exponentially. Websense Remote Filtering ensures secure employee internet use anytime and anywhere, becoming a critical component of any organization's endpoint security and protection strategy.

Wednesday, November 22, 2006

Performance Analysis: Network Security Scanners

PC Magazine Labs has taken an in-depth look at the six network vulnerability scanners in our roundup, as well as the tools included in our sidebars (the Foundstone FS1000 Appliance, Microsoft Baseline Security Analyzer (MBSA), Nmap, and Stealthbits Technologies' StealthAudit). When we tested how well they could catch basic network vulnerabilities, all the scanners performed adequately. But the quality—and more important, the ease of use of the reports the products generate—varied significantly.

Our test network comprised a Linksys BEFVP41 router and a mix of Microsoft Windows clients and servers (Windows 98, 2000 Workstation, 2000 Advanced Server, and XP). We also deployed Linux hosts (Red Hat 8 and 9 Professional, SuSE Enterprise Server 8, and SuSE 8.1 Professional) to test each application's cross-platform capabilities.

We updated all systems with all appropriate patches, but we did not fix a select number of critical vulnerabilities on the target hosts. On our Windows hosts we left vulnerabilities described in Microsoft Security Bulletins MS03-039 (Buffer Overrun In RPCSS Service, CAN-2003-0715, CAN-2003-0528, and CAN-2003-0605) and MS03-041 (Vulnerability in Authenticode Verification, CAN-2003-0660). Under the right circumstances, both can let hackers execute code on target systems.

We left our Linux machines vulnerable with an exploitable version of OpenSSH (CAN-2003-0682, CAN-2003-0693, and CAN-2003-0695), a file share (/usr) exported with no access restrictions (CAN 1999-0554), and a denial-of-service vulnerability in the Unix Domain Name Service BIND 9.1.3 (CAN-2002-0400). Such Linux vulnerabilities can create a severe security risk, compromising your network and data.

All the products correctly identified the Windows vulnerabilities, and their reports included references to the appropriate Microsoft Security Bulletins. But the Linux vulnerabilities posed a bigger challenge to some of the Windows scanners.

Saturday, November 18, 2006

Hitachi Software and KDDI Network & Solutions to Market English HIBUN Information Security Management Solutions Overseas

Hitachi Software Engineering Co. Ltd. (HitachiSoft) and KDDI Network & Solutions Inc. (KNSL) have agreed to collaborate on the overseas marketing of HitachiSoft's HIBUN series of information security management systems in North America, Europe and Asia, and will be releasing English-language versions effectively this month.

The implementation of Japan's Personal Information Protection Law has spurred the introduction of measures to enhance information security management in Japan and demand for security measures is growing among overseas branches and subsidiaries. Following this demand, KNSL and HitachiSoft will release the HIBUN series, already with 1,700 corporate users and 1.5 million licenses in Japan as of July 31, 2005, overseas.

HitachiSoft has developed English-language versions of three products in its HIBUN range of information security management solutions - HIBUN AE Information Cypher, which encrypts drives, media and files, HIBUN AE Information Fortress, which controls transfer to external media and printing, and HIBUN AE Server, which provides logging and user control functions - to be released in November. As primary agent, KNSL will provide support services in Japanese and English to overseas sales companies, 24 hours a day, 365 days a year. The products will be marketed by a US subsidiary of KDDI Corporation, while HitachiSoft's US subsidiary Hitachi Software Engineering America, headquartered in San Francisco, will handle sales, implementation and configuration and SE support services to customers.

The new solutions will initially be marketed from bases in the United States, Europe and Asia, targeting local subsidiaries of Japanese companies in the United States, the United Kingdom, France, Germany, the Netherlands, Belgium, Hong Kong, Taiwan, Korea, Singapore, Thailand, Malaysia,, Indonesia, the Philippines, Vietnam, Australia, while marketing activities will gradually be expanded. From September, promotional activities such as seminars will be conducted overseas, and the products will go on sale at promotional prices. KNSL and HitachiSoft aim to sell 200,000 licenses over a three-year period.

Tuesday, November 14, 2006

Security group warns of VPN vulnerabilities

The UK's National Infrastructure Security Coordination Center (NISCC) has warned of potential attacks on the IPSec protocol used in browser-based virtual private networks, which could render encrypted messages as plain text with only "moderate effort". This would affect many remote communications to enterprise networks via Wi-Fi and other networks, with IPSec becoming increasingly popular among mobile workers.

The NISCC describes the weakness as "severe" and says it applies to IPSec configurations that rely on Encapsulating Security Payload (ESP) in tunnel mode with confidentiality only, or with integrity protection offered by a higher layer protocol.

The attacks need to be carried out many times before they are successful, but once this phase is reached, "the results can be reused to efficiently recover the contents of further inner packets". The attacks are fully automatable.

The main safeguards that companies should take are to configure ESP to use both confidentiality and integrity protection; use the AH protocol alongside ESP to provide integrity protection; and filter ICMP messages at a firewall or security gateway.

Thursday, November 09, 2006

Network Security: Know Your Weaknesses

As the person responsible for your company's network security, you know you are sorely outnumbered. A seemingly infinite number of potential intruders are lurking out there, and there's never enough time to prepare.

Without a doubt, the costs of cyberattacks are significant, as shown by the 2003 Computer Crime and Security Survey, conducted by the Computer Security Institute and the FBI. The 250 organizations that participated in the eighth annual study reported combined losses of $202 million, with causes ranging from theft of proprietary information, denial-of-service attacks, and viruses to insider abuse of network access.

How do you improve your odds? Your obvious first step is to identify system weaknesses. Vulnerability assessment scanners not only automatically discover security flaws on a network but in some cases correct them, too. Such tools have been around for years, but only recently have they matured into more comprehensive and user-friendly—if still complex—products, with features like customized reporting, distributed threat assessment, and automatic correction of potential problems.

Among the things such scanners can identify are known software bugs, viruses, and weak access control policies. Commonly found workstation vulnerabilities include open NetBIOS ports for file and printer sharing, as well as users who run rogue Web servers or peer-to-peer file-sharing clients.

Vulnerability assessment scanners can also find improper configurations of applications, which can leave a network unprotected. For example, Microsoft Exchange's default configuration used to leave the server as an open SMTP relay, which could be exploited by spammers. This resulted in attackers hijacking servers and sending millions of e-mails that appeared to originate as legitimate traffic from the victims' networks.

Friday, November 03, 2006

Retina Network Security Scanner

Intelligent, out-of-the-box ESP 3000 solution consists of integrated layers of security technologies including IDS, IPS, behavioral analysis, event and global threat correlation, vulnerability scanning, vendor alerts, asset database, and security dashboard. Browser-based Master Control Unit acts as monitoring console, signature server, cluster manager, and Web server, while also containing Web portal housing all reports and graphs for appliance suite.

New SRM solution from a proven network security innovator arms organizations with more complete protection, cost savings and ability to preemptively avoid network attacks

DALLAS, TX. - September 26th, 2005 - Global DataGuard, the premier provider of Security Risk Management (SRM) solutions for midsize-to-enterprise organizations, today announced it is rolling out a fully integrated, groundbreaking suite of new SRM solutions that enable organizations to immediately and economically understand where their networks are vulnerable, who's trying to attack them and what they can do to prevent network security problems.

Global DataGuard's intelligent, out-of-the-box ESP 3000 solution consists of integrated layers of security technologies that together provide unmatched risk management: IDS, IPS, behavioral analysis, event and global threat correlation, vulnerability scanning, vendor alerts, an asset database and a security dashboard. Each layer complements and augments the others, with intelligent behavioral analysis and correlation capabilities comprising the GDG difference. The result is early warnings of threats other solutions cannot see; far fewer false positives; cost savings, more thorough compliance and the ability to manage security solutions with one console.

The installation process is straightforward, and upon start-up, Retina synchronizes its vulnerability signature databases with eEye's server. When Retina opens, the main user interface provides access to four modules: the browser, tracer, miner, and scanner. The integrated Web browser lists all page elements in a tree view, and the tracer creates a traceroute and displays response times. But the miner and scanner modules are the brains of the operation. With its proprietary artificial-intelligence engine, the miner tries to mimic a hacker's behavior by attacking security weaknesses.

Saturday, October 28, 2006

Network Security System offers fully integrated solution.

Intelligent, out-of-the-box ESP 3000 solution consists of integrated layers of security technologies including IDS, IPS, behavioral analysis, event and global threat correlation, vulnerability scanning, vendor alerts, asset database, and security dashboard. Browser-based Master Control Unit acts as monitoring console, signature server, cluster manager, and Web server, while also containing Web portal housing all reports and graphs for appliance suite.

New SRM solution from a proven network security innovator arms organizations with more complete protection, cost savings and ability to preemptively avoid network attacks

DALLAS, TX. - September 26th, 2005 - Global DataGuard, the premier provider of Security Risk Management (SRM) solutions for midsize-to-enterprise organizations, today announced it is rolling out a fully integrated, groundbreaking suite of new SRM solutions that enable organizations to immediately and economically understand where their networks are vulnerable, who's trying to attack them and what they can do to prevent network security problems.

Global DataGuard's intelligent, out-of-the-box ESP 3000 solution consists of integrated layers of security technologies that together provide unmatched risk management: IDS, IPS, behavioral analysis, event and global threat correlation, vulnerability scanning, vendor alerts, an asset database and a security dashboard. Each layer complements and augments the others, with intelligent behavioral analysis and correlation capabilities comprising the GDG difference. The result is early warnings of threats other solutions cannot see; far fewer false positives; cost savings, more thorough compliance and the ability to manage security solutions with one console.

Saturday, October 21, 2006

Guard your systems from network parasites with the WolfPac Security Suite - Top Technology Showcase

PSINet Europe, a leading provider of corporate IP-based communication services, recently conducted a little experiment: To prove the importance of network security, it set up an anonymous "dummy server" containing no data and no public profile. Within 24 hours it was attacked 467 times. This large number reflects the fact that computer hacking is no longer just a hobby for computer geeks--it is now a full-time job. Network professionals need to be aware of this growing problem and learn to protect themselves from uninvited guests.

NetWolves' latest offering is designed to prevent system robbery. It acts as a hacker's kryptornte making your servers secure from outside intrusions. The Security Suite acts as a link between large companies and remote offices or as a single gateway for small-to-medium size businesses. It provides companies with an option for shielding their intellectual property from information thievery.

The suite comes in two platforms: the WolfPac 2020 and the WolfPac 3020. They both come equipped with three Ethernet 10/100 interface cards for WAN, LAN and DMZ connections. The security suite is offered with either a 600MHz or 900MHz processor, 20- to 100GB hard drive, and up to 1,024MB of RAM.

Thursday, October 19, 2006

Web application assessment - Network monitoring and security - Weblnspect 3.0 Enterprise Edition - Brief Article

Discover where network security needs improvement with Weblnspect 3.0 Enterprise Edition, a product designed to automate the assessment of Web services security. Users can perform security assessments on any Web-enabled application, including specific assessment capabilities for Microsoft .NET, IBM WebSphere, Lotus Domino, Oracle Application Servers and MacroMedia ColdFusion. An intuitive, wizard-driven interface, and integrated tools and utilities provide easy access to Web application vulnerabilities. In addition, an expert mode allows advanced users to manually interact with the assessment process and create custom test scripts. The configurable XML export tool enables users to export any and all information found during the scan in a standardized XML format, including comments, hidden fields, Javascript, cookies, Web forms, URLs, requests and sessions.

Friday, October 13, 2006

Scan like a hacker - Network monitoring and security

ScanDo is a Web application scanner that assesses the entire Web application to identify security loopholes through comprehensive exploration and penetration of the Web application and its operating environments. The tool reveals Web application vulnerabilities using the same techniques used by hackers, including the manipulation of IT infrastructure vulnerabilities, parameter tampering, Web services and SOAP vulnerabilities, hidden field manipulation, cookie poisoning, stealth commanding, backdoor and debug options, database sabotage, buffer overflow attacks, data encoding, and protocol piggybacking. Weaknesses are pinpointed and the risk level assessed within the applications to be managed. The solution then generates reports in graphical or textual formats for novice or experienced security personnel.

Monday, October 09, 2006

Questioning the cost of compliance: some say a new network security rule puts an unfair burden on higher ed

WITH LEGISLATION TO reauthorize the Higher Education Act (HEA) lumbering toward enactment, although its final form remains uncertain, the higher education community in Washington is paying attention to new developments in other areas.

One issue: regulations issued by the Federal Communications Commission (FCC) to broaden law enforcement's ability to monitor electronic communications involving suspected terrorists and criminals.

The new regulations extend to universities, as well as libraries, airport public wireless networks, and commercial Internet service providers, provisions of the 1994 Communications Assistance for Law Enforcement Act. That measure directed telephone companies to redesign their networks to enable law enforcement agencies to have remote access to their systems.

The rules, newly issued by the FCC, extend the remote access requirements to computer networks. Implementation requires all Internet service providers, including IHEs, to upgrade network switches and routers by June 2007 to enable remote monitoring. The cost to upgrade computer networks at IHEs is estimated at $7 billion, according to the American Council on Education (www. acenet.edu), which quickly challenged the FCC's rules in the federal appellate court for the District of Columbia.

"Potentially, this is a huge deal over a complicated set of issues," says ACE Senior Vice President Terry W. Hartle. Some people would argue there is a broader privacy issue here. "What we have argued is simply that we will comply; we are anxious to do our part in the war on terror, but what the government is asking us to do is very expensive for very little return."

Higher ed institutions have long worked with law enforcement agencies pursuing criminal investigations, adds Sheldon E. Steinbach, ACE vice president and general counsel. He says that by filing suit, ACE hopes to convince the FCC that institutions "can provide the same access through alternative approaches" without having to shell out $7 billion.

"When you evaluate efficiency versus the incredible cost of compliance, we just don't think it makes a lot of sense," Steinbach says.

SHAPING THE FUTURE

In another development, U.S. Education Secretary Margaret Spellings kicked off a national commission established to shape the future of higher ed in the U.S. and asked it to submit specific recommendations by August 1, 2006, on four areas: accessibility, affordability, accountability, and quality.

The commission, made up of 19 business, foundation, and higher ed representatives, got an immediate taste of its mission when the College Board reported that there continue to be significant long-term concerns about college access and affordability.

Although average grant aid per student is growing, it's not by enough to prevent increased reliance on borrowing, the College Board stated. Low-income students receive more grant aid, on average, than higher-income students, but new student aid policies have benefited those in the upper half of the income distribution most.

HEA UPDATE

Meanwhile, the Senate and House are still moving in their own ways to reauthorize the HEA. At the outset of the congressional budget process last February, both bodies agreed to reduce the federal deficit by $35 billion over five years by cutting entitlement programs, a process known as reconciliation. The Senate Committee on Health, Education, Labor and Pensions must contribute one-third of the total cuts in the Senate.

In October, the Senate Committee approved budget reconciliation legislation that encompasses HEA reauthorization. The measure cuts $15.1 billion over five years from the federal student loan and pension programs. The House Education and Workforce Committee cut $20.8 billion.

Higher ed lobbyists continue voicing concerns over spending cuts. But Congress is under pressure to help pay for hurricane relief and the war in Iraq. Unsure when it will complete reauthorization, Congress extended programs under HEA as they stand until December 31.

Monday, October 02, 2006

Credit union serves up secure solution; password technology system provides members with authenticated, 24/7 network access - Network Security - State

More than 73,000 members. $530 million in assets. A fast-growing dial-in network where remote users can gain 24/7 access. A potential security nightmare.

That was the challenge facing the State Employees Credit Union (SECU) in Lansing, Mich., which, since its charter in 1952, has grown to become one of the leading credit unions in Michigan and the United States. With its burgeoning network, however, Mark Davis, SECU assistant vice president of data center operations, understood the dangers of unauthorized access, and wanted to be able to identify each individual user attempting to log on to the system.

"As far as remote dial-in, we were getting to the point where our network was too exposed and anybody would be able to get in," says Davis. "I realized that greater security would be needed as we basically just had someone dialing into a router to use NT security."

SECU underwent an exhaustive search to identify a cost-effective method to provide high-level security for its dial-in network.