Friday, December 01, 2006
Messaging System/Anti-Spam Service offer network security
Fortinet -- the confirmed market leader in Unified Threat Management and only provider of ASIC-accelerated, network-based antivirus firewall systems for real-time network protection -- today unveiled two powerful new additions to its network security solutions and services portfolio: FortiMail, a secure messaging system, and FortiGuard-Antispam, a managed antispam service. The FortiMail Secure Messaging Platform and FortiGuard-Antispam Service effectively layer antispam technology to offer antispam defense in-depth at the network perimeter and the mail server -- maximizing mail traffic performance by eliminating global spam at the network gateway, before it enters the corporate network.
Unwanted email or spam continues to present serious security challenges for enterprises and consumers alike. Increasingly, these messages contain spyware, grayware or other malicious attempts to adversely impact a customer's computing and networking resources. While many world governments have been writing legislation and enforcing penalties around spam creation and delivery, spam continues to be difficult to regulate and catch. Industry researchers suggest that 60 to 70 percent of all enterprise email is spam, and recent statistics suggest that a good portion of spam contains viruses or other types of attacks.
"As an industry leader in the design and manufacture of advanced semiconductors, we have many daily demands on our network and cannot sacrifice network performance due to spam, viruses or other unwanted network traffic," said Edward Huang, corporate IT infrastructure manager for Atmel. "Solutions such as Fortinet's network security platforms and FortiGuard-Antispam Service help to minimize unwanted and malicious network traffic, without network performance degradation or a lot of administrative overhead, which is essential for ensuring a productive business."
FortiMail Secure Messaging Platform
The FortiMail Secure Messaging Platform is a dedicated system based on Fortinet's award winning FortiOS technology and includes an antivirus detection engine for virus and spyware protection and complete email scanning. FortiMail uses advanced spam detection and filtering methods such as FortiGuard-Antispam, access policy filtering, content filtering, global and user black/white list filtering, spam Real-time Blackhole List (RBL), per user Bayesian filtering so that individual users can set their own profiles, heuristics filtering and denial-of-service.
The FortiMail-400 system is the first in a family of secure messaging platforms and is designed for medium to large enterprises and remote branch offices. Future FortiMail systems will be available to secure messaging for high-volume, mission-critical infrastructures such as large enterprises, universities and managed security service providers (MSSPs).
The FortiMail Secure Messaging Platform offers users three protective modes of operation:
-- Transparent mode: FortiMail platform is placed in front of the existing email server without any changes to the existing email topology to provide seamless integration into existing network environments.
-- Gateway mode: FortiMail platform is placed in front of the existing email server providing in-bound and out-bound email relay services, which allows for scanning of both in-bound and out-bound email messages.
-- Server mode: FortMail platform provides complete email server functionality in addition to antivirus and antispam functionality, which is ideal for medium sized companies and remote branch office locations.
FortiGuard-Antispam Service
FortiGuard-Antispam Service is a new fully managed service that helps companies of all sizes reduce the amount of spam by eliminating it at the network perimeter. Fortinet developed this service internally and optimized it for operation on Fortinet's FortiGate network security platforms and the new FortiMail system family. On either system deployment, FortiGuard-Antispam can significantly reduce the amount of unwanted and possibly malicious spam messages passing through corporate email servers.
Using Fortinet's "dual pass" scanning technology in either the FortiMail or FortiGate systems, the FortiGuard-Antispam Service checks against known spammer IP addresses and email content with Universal Resource Identifier (URI) scanning. URI scanning looks deep into each email message to scan for well-known spam content such as spam URL links. The pairing of this new service with Fortinet security systems will help increase spam detection rates, as spammers get more creative and use infected PCs to deliver spam.
Thursday, November 30, 2006
GFI LANguard Network Security Scanner 3.3
To perform a basic scan of your network, you simply enter an IP address or range and press Start. LANguard gives you many types of predefined security scan profiles. For example, you can scan using only ICMP for discovery, scan all available ports, or scan for open shares or missing patches. You can also define and save your own security scan profiles.
Without administrative privileges in a Windows domain, you can determine computer names, MAC addresses, open ports, operating system versions, and SNMP information, all reported in a tree structure of results sorted by IP address. With domain administrative privileges, you can determine significantly more information about each system, such as shares, user accounts, services, password policies, registry information, and installed patches. Your scan can also include testing for CGI abuses as well as FTP, DNS, mail, service, and registry vulnerabilities. The results are grouped by category and include either a recommendation for remediation or a BugTraq, CVE, or Microsoft Security Bulletin reference.
Within the report generator you can create and save custom reports to meet your individual security needs. For example, you can generate a report of all systems that have either TCP port 80 (Web) or port 21 (FTP) open. As with Retina and SAINT 5, an included utility lets you compare two reports for new, removed, or changed items, as well as alert and hot-fix changes.
LANguard is also marketed as a patch management and deployment solution. During a scan of a Windows network, LANguard determines which patches have been installed on your systems and which are missing, based on GFI's coordination with Microsoft. It deploys hot fixes as well as service packs.
Tuesday, November 28, 2006
Web Security Software protects mobile users outside network
New Functionality Will Extend Web Filtering and Web Security Policies to Remote Users, Regardless of Location or Type of Network Connection
SAN DIEGO, Sept. 19 -- Websense, Inc. (Nasdaq: WBSN), the world's leading provider of employee internet management solutions, today announced the upcoming release of Websense(R) Remote Filtering technology, extending Websense's industry-leading web filtering and web security technology to corporate laptop users outside of the organization's network. Remote Filtering capabilities will be seamlessly incorporated into the newest versions of Websense web filtering and web security software, expected to be available in October 2005.
With the growing rate of telecommuting and business travel, it has become critical for organizations to enable employees who work remotely to use their laptop computers effectively and safely. As broadband internet access becomes more pervasive in non-traditional settings such as airports, hotels or local coffee houses, the necessity to protect remote laptop users from malicious threats lurking in unknown networks intensifies exponentially. Websense Remote Filtering ensures secure employee internet use anytime and anywhere, becoming a critical component of any organization's endpoint security and protection strategy.
Wednesday, November 22, 2006
Performance Analysis: Network Security Scanners
Our test network comprised a Linksys BEFVP41 router and a mix of Microsoft Windows clients and servers (Windows 98, 2000 Workstation, 2000 Advanced Server, and XP). We also deployed Linux hosts (Red Hat 8 and 9 Professional, SuSE Enterprise Server 8, and SuSE 8.1 Professional) to test each application's cross-platform capabilities.
We updated all systems with all appropriate patches, but we did not fix a select number of critical vulnerabilities on the target hosts. On our Windows hosts we left vulnerabilities described in Microsoft Security Bulletins MS03-039 (Buffer Overrun In RPCSS Service, CAN-2003-0715, CAN-2003-0528, and CAN-2003-0605) and MS03-041 (Vulnerability in Authenticode Verification, CAN-2003-0660). Under the right circumstances, both can let hackers execute code on target systems.
We left our Linux machines vulnerable with an exploitable version of OpenSSH (CAN-2003-0682, CAN-2003-0693, and CAN-2003-0695), a file share (/usr) exported with no access restrictions (CAN 1999-0554), and a denial-of-service vulnerability in the Unix Domain Name Service BIND 9.1.3 (CAN-2002-0400). Such Linux vulnerabilities can create a severe security risk, compromising your network and data.
All the products correctly identified the Windows vulnerabilities, and their reports included references to the appropriate Microsoft Security Bulletins. But the Linux vulnerabilities posed a bigger challenge to some of the Windows scanners.
Saturday, November 18, 2006
Hitachi Software and KDDI Network & Solutions to Market English HIBUN Information Security Management Solutions Overseas
The implementation of Japan's Personal Information Protection Law has spurred the introduction of measures to enhance information security management in Japan and demand for security measures is growing among overseas branches and subsidiaries. Following this demand, KNSL and HitachiSoft will release the HIBUN series, already with 1,700 corporate users and 1.5 million licenses in Japan as of July 31, 2005, overseas.
HitachiSoft has developed English-language versions of three products in its HIBUN range of information security management solutions - HIBUN AE Information Cypher, which encrypts drives, media and files, HIBUN AE Information Fortress, which controls transfer to external media and printing, and HIBUN AE Server, which provides logging and user control functions - to be released in November. As primary agent, KNSL will provide support services in Japanese and English to overseas sales companies, 24 hours a day, 365 days a year. The products will be marketed by a US subsidiary of KDDI Corporation, while HitachiSoft's US subsidiary Hitachi Software Engineering America, headquartered in San Francisco, will handle sales, implementation and configuration and SE support services to customers.
The new solutions will initially be marketed from bases in the United States, Europe and Asia, targeting local subsidiaries of Japanese companies in the United States, the United Kingdom, France, Germany, the Netherlands, Belgium, Hong Kong, Taiwan, Korea, Singapore, Thailand, Malaysia,, Indonesia, the Philippines, Vietnam, Australia, while marketing activities will gradually be expanded. From September, promotional activities such as seminars will be conducted overseas, and the products will go on sale at promotional prices. KNSL and HitachiSoft aim to sell 200,000 licenses over a three-year period.
Tuesday, November 14, 2006
Security group warns of VPN vulnerabilities
The NISCC describes the weakness as "severe" and says it applies to IPSec configurations that rely on Encapsulating Security Payload (ESP) in tunnel mode with confidentiality only, or with integrity protection offered by a higher layer protocol.
The attacks need to be carried out many times before they are successful, but once this phase is reached, "the results can be reused to efficiently recover the contents of further inner packets". The attacks are fully automatable.
The main safeguards that companies should take are to configure ESP to use both confidentiality and integrity protection; use the AH protocol alongside ESP to provide integrity protection; and filter ICMP messages at a firewall or security gateway.
Thursday, November 09, 2006
Network Security: Know Your Weaknesses
Without a doubt, the costs of cyberattacks are significant, as shown by the 2003 Computer Crime and Security Survey, conducted by the Computer Security Institute and the FBI. The 250 organizations that participated in the eighth annual study reported combined losses of $202 million, with causes ranging from theft of proprietary information, denial-of-service attacks, and viruses to insider abuse of network access.
How do you improve your odds? Your obvious first step is to identify system weaknesses. Vulnerability assessment scanners not only automatically discover security flaws on a network but in some cases correct them, too. Such tools have been around for years, but only recently have they matured into more comprehensive and user-friendly—if still complex—products, with features like customized reporting, distributed threat assessment, and automatic correction of potential problems.
Among the things such scanners can identify are known software bugs, viruses, and weak access control policies. Commonly found workstation vulnerabilities include open NetBIOS ports for file and printer sharing, as well as users who run rogue Web servers or peer-to-peer file-sharing clients.
Vulnerability assessment scanners can also find improper configurations of applications, which can leave a network unprotected. For example, Microsoft Exchange's default configuration used to leave the server as an open SMTP relay, which could be exploited by spammers. This resulted in attackers hijacking servers and sending millions of e-mails that appeared to originate as legitimate traffic from the victims' networks.
Friday, November 03, 2006
Retina Network Security Scanner
New SRM solution from a proven network security innovator arms organizations with more complete protection, cost savings and ability to preemptively avoid network attacks
DALLAS, TX. - September 26th, 2005 - Global DataGuard, the premier provider of Security Risk Management (SRM) solutions for midsize-to-enterprise organizations, today announced it is rolling out a fully integrated, groundbreaking suite of new SRM solutions that enable organizations to immediately and economically understand where their networks are vulnerable, who's trying to attack them and what they can do to prevent network security problems.
Global DataGuard's intelligent, out-of-the-box ESP 3000 solution consists of integrated layers of security technologies that together provide unmatched risk management: IDS, IPS, behavioral analysis, event and global threat correlation, vulnerability scanning, vendor alerts, an asset database and a security dashboard. Each layer complements and augments the others, with intelligent behavioral analysis and correlation capabilities comprising the GDG difference. The result is early warnings of threats other solutions cannot see; far fewer false positives; cost savings, more thorough compliance and the ability to manage security solutions with one console.
The installation process is straightforward, and upon start-up, Retina synchronizes its vulnerability signature databases with eEye's server. When Retina opens, the main user interface provides access to four modules: the browser, tracer, miner, and scanner. The integrated Web browser lists all page elements in a tree view, and the tracer creates a traceroute and displays response times. But the miner and scanner modules are the brains of the operation. With its proprietary artificial-intelligence engine, the miner tries to mimic a hacker's behavior by attacking security weaknesses.
Saturday, October 28, 2006
Network Security System offers fully integrated solution.
New SRM solution from a proven network security innovator arms organizations with more complete protection, cost savings and ability to preemptively avoid network attacks
DALLAS, TX. - September 26th, 2005 - Global DataGuard, the premier provider of Security Risk Management (SRM) solutions for midsize-to-enterprise organizations, today announced it is rolling out a fully integrated, groundbreaking suite of new SRM solutions that enable organizations to immediately and economically understand where their networks are vulnerable, who's trying to attack them and what they can do to prevent network security problems.
Global DataGuard's intelligent, out-of-the-box ESP 3000 solution consists of integrated layers of security technologies that together provide unmatched risk management: IDS, IPS, behavioral analysis, event and global threat correlation, vulnerability scanning, vendor alerts, an asset database and a security dashboard. Each layer complements and augments the others, with intelligent behavioral analysis and correlation capabilities comprising the GDG difference. The result is early warnings of threats other solutions cannot see; far fewer false positives; cost savings, more thorough compliance and the ability to manage security solutions with one console.
Saturday, October 21, 2006
Guard your systems from network parasites with the WolfPac Security Suite - Top Technology Showcase
NetWolves' latest offering is designed to prevent system robbery. It acts as a hacker's kryptornte making your servers secure from outside intrusions. The Security Suite acts as a link between large companies and remote offices or as a single gateway for small-to-medium size businesses. It provides companies with an option for shielding their intellectual property from information thievery.
The suite comes in two platforms: the WolfPac 2020 and the WolfPac 3020. They both come equipped with three Ethernet 10/100 interface cards for WAN, LAN and DMZ connections. The security suite is offered with either a 600MHz or 900MHz processor, 20- to 100GB hard drive, and up to 1,024MB of RAM.
Thursday, October 19, 2006
Web application assessment - Network monitoring and security - Weblnspect 3.0 Enterprise Edition - Brief Article
Friday, October 13, 2006
Scan like a hacker - Network monitoring and security
Monday, October 09, 2006
Questioning the cost of compliance: some say a new network security rule puts an unfair burden on higher ed
One issue: regulations issued by the Federal Communications Commission (FCC) to broaden law enforcement's ability to monitor electronic communications involving suspected terrorists and criminals.
The new regulations extend to universities, as well as libraries, airport public wireless networks, and commercial Internet service providers, provisions of the 1994 Communications Assistance for Law Enforcement Act. That measure directed telephone companies to redesign their networks to enable law enforcement agencies to have remote access to their systems.
The rules, newly issued by the FCC, extend the remote access requirements to computer networks. Implementation requires all Internet service providers, including IHEs, to upgrade network switches and routers by June 2007 to enable remote monitoring. The cost to upgrade computer networks at IHEs is estimated at $7 billion, according to the American Council on Education (www. acenet.edu), which quickly challenged the FCC's rules in the federal appellate court for the District of Columbia.
"Potentially, this is a huge deal over a complicated set of issues," says ACE Senior Vice President Terry W. Hartle. Some people would argue there is a broader privacy issue here. "What we have argued is simply that we will comply; we are anxious to do our part in the war on terror, but what the government is asking us to do is very expensive for very little return."
Higher ed institutions have long worked with law enforcement agencies pursuing criminal investigations, adds Sheldon E. Steinbach, ACE vice president and general counsel. He says that by filing suit, ACE hopes to convince the FCC that institutions "can provide the same access through alternative approaches" without having to shell out $7 billion.
"When you evaluate efficiency versus the incredible cost of compliance, we just don't think it makes a lot of sense," Steinbach says.
SHAPING THE FUTURE
In another development, U.S. Education Secretary Margaret Spellings kicked off a national commission established to shape the future of higher ed in the U.S. and asked it to submit specific recommendations by August 1, 2006, on four areas: accessibility, affordability, accountability, and quality.
The commission, made up of 19 business, foundation, and higher ed representatives, got an immediate taste of its mission when the College Board reported that there continue to be significant long-term concerns about college access and affordability.
Although average grant aid per student is growing, it's not by enough to prevent increased reliance on borrowing, the College Board stated. Low-income students receive more grant aid, on average, than higher-income students, but new student aid policies have benefited those in the upper half of the income distribution most.
HEA UPDATE
Meanwhile, the Senate and House are still moving in their own ways to reauthorize the HEA. At the outset of the congressional budget process last February, both bodies agreed to reduce the federal deficit by $35 billion over five years by cutting entitlement programs, a process known as reconciliation. The Senate Committee on Health, Education, Labor and Pensions must contribute one-third of the total cuts in the Senate.
In October, the Senate Committee approved budget reconciliation legislation that encompasses HEA reauthorization. The measure cuts $15.1 billion over five years from the federal student loan and pension programs. The House Education and Workforce Committee cut $20.8 billion.
Higher ed lobbyists continue voicing concerns over spending cuts. But Congress is under pressure to help pay for hurricane relief and the war in Iraq. Unsure when it will complete reauthorization, Congress extended programs under HEA as they stand until December 31.
Monday, October 02, 2006
Credit union serves up secure solution; password technology system provides members with authenticated, 24/7 network access - Network Security - State
That was the challenge facing the State Employees Credit Union (SECU) in Lansing, Mich., which, since its charter in 1952, has grown to become one of the leading credit unions in Michigan and the United States. With its burgeoning network, however, Mark Davis, SECU assistant vice president of data center operations, understood the dangers of unauthorized access, and wanted to be able to identify each individual user attempting to log on to the system.
"As far as remote dial-in, we were getting to the point where our network was too exposed and anybody would be able to get in," says Davis. "I realized that greater security would be needed as we basically just had someone dialing into a router to use NT security."
SECU underwent an exhaustive search to identify a cost-effective method to provide high-level security for its dial-in network.
Friday, September 29, 2006
Internet Security Gateway targets small network environments
Device Raises the Bar for Sub-$1,000 Unified Threat Management (UTM) Solutions by Including Gateway Anti-Virus, URL Filtering and Intrusion Prevention
BROOMFIELD, Colo., Sept. 14 -- eSoft, Inc., a leading vendor of integrated Internet security and content management solutions, announced today the availability of its newest product, the InstaGate 305 integrated security gateway, which integrates Firewall, IPSec VPN, Gateway Anti-Virus, Web URL Filtering and Network Intrusion Prevention into a single, easy-to-deploy and manage solution.
The InstaGate 305, tailored for small network environments with critical security needs, is the latest addition to eSoft's award-winning line of unified threat management (UTM) solutions that integrate dynamic Deep Packet Inspection services such as Anti-Virus and Intrusion Prevention into traditional Firewall/VPN network security appliances. While many devices in the sub-$1,000 market provide stateful Firewall and VPN functionality, few provide the performance and depth of inspection of the InstaGate 305, which is based on a powerful Intel(R) XScale processor with a large memory footprint.
"The InstaGate 305 fills a critical gap in one of the most under-served areas of the market," said Scott Lukes, eSoft vice president of marketing. "Small organizations are exposed to the same Internet threats as large Fortune 500 enterprises -- the only difference is that they don't have the same resources to deal with them. The 305 was designed to provide all of the necessary tools to protect small networks from modern, dynamic threats -- like the recent Zotob virus -- with minimal requirements from IT."
Monday, September 25, 2006
Revamp your network security - now
Try this on for size: You should blow up your network. That's right - over the next 18 months you'll be overhauling your campus network. It's time. You know you are tired of those old Layer 3 switches. Those are so five years ago. Aren't those boxes depreciated yet? Get the finance guys on the horn.
The business has changed. The insider threat is real. Folks connect to your network from conference rooms and over VPNs from unsafe environments. You can't stick your head in the sand anymore. Compliance has teeth and you need to segment networks and protect sensitive data. Acknowledging this is a huge change for me, since I used to laugh when told that people needed to secure internal networks.
I remember talking years ago to companies that were pitching that customers needed to extend the protection deeper into the network. I laughed. The moat is deep and wide. The bad guys cannot get in. Well, now the bad guys are us and they may already be on the network. We need to make the network much less hospitable to them.
Monday, September 18, 2006
Remote application console - Network security - Remote Console Server 3.0 - Brief Article
Tuesday, September 12, 2006
AT&T to upgrade network infrastructure for Internet Security Systems
Telecomms holding company AT&T Inc (NYSE:T) has signed a three year contract to upgrade the network infrastructure of enterprise security company Internet Security Systems Inc (ISS).
AT&T said the new contract, which follows ISS's adoption of AT&T's MPLS technology in 2004, which extends the MPLS services to ISS locations in the US, Europe and the Asia-Pacific region. ISS will use the network upgrade to add further company locations in the future.
According to AT&T, the network upgrade will provide ISS with disaster recovery services which use the fastest, most advanced any-to-any mesh connectivity, to ensure outages at centralised hubs do not disrupt the networks.
ISS will also use the upgraded network to introduce VoIP capabilities across its enterprise, enabling it to streamline internal voice communications and gain maximum cost-efficiencies. The new contract also covers dedicated Internet, long distance and AT&T ultravailable local access services
Thursday, September 07, 2006
THE NEED FOR INTERNAL SECURITY
One solution is to deploy WLAN security gateways, which are network appliances designed to secure, manage and power WLANs. Operating at the wireless edge, between access points and other devices upstream, WI,AN security gateways protect networks from security attacks launched from wireless devices.
These gateways should meet three key requirements:
1. Precise packet-filtering controls for blocking or redirecting traffic. The gateway should include precise packet-filtering controls that can distinguish malicious traffic from legitimate traffic, and take action to block or redirect malicious traffic. A network administrator should be able to read a security bulletin describing the characteristics of a virus or worm and then precisely define a filter that targets the traffic of that virus or worm. The filter should block malicious traffic without interfering with legitimate traffic. By detecting and blocking the traffic that viruses and worms depend on, the filtering capabilities of a WLAN security gateway contain airborne attacks.
2. Filtering at the wireless edge to manage traffic among devices. To contain an attack, packet filtering must occur at the wireless edge, as close as possible to the access point. For optimal protection of the network, WLAN security gateways should be installed between the access point and the next upstream network device.
3. Session logging and audit tools for identifying infected computers and accelerating repairs. WLAN security gateways should provide logging and audit tools to help administrators remediate an attack, once it is contained. By maintaining full session logs of network traffic and tracking Layer 3 traffic data, WEAN security" gateways facilitate the identification of users with infected computers and the MAC addresses of the computers themselves. Using this information, administrators can contact users directly and begin cleaning up any infected computers.
CENTRALIZED POLICY MANAGEMENT
A tiered solution that combines WLAN security gateways at the wireless edge with a centrally located policy server provides additional advantages for network administrators combating viruses and worms. By providing centralized control over filters, the central policy server allows administrators to define a policy that immediately takes effect across the network. The policy server automatically distributes filters to all the WLAN security gateways, providing immediate protection at every access point on the network. This centralization also reduces manual labor and the risk of error.
The central policy server can manage user accounts and user groups for wireless users. Administrators can use the server's group-management features to define a special user group for users with infected computers. The group characteristics would include redirecting users to a Web page with information about how to install security patches and clean up infections.
By temporarily assigning users with infected computers to this group, administrators can ensure that users with infected computers receive the information they need the next time they log in. Once administrators have verified that the infected computers have been cleaned, they can remove users from this group and restore their normal access rights.
Friday, September 01, 2006
Prevent viruses on enterprise WLANs: security gateways provide protection from within the network perimeter - Wireless
WLANs undermine perimeter defenses. Wireless users are mobile. They take their computers to other networks. Some of these networks are se cure and well managed; others are not. Computers on these networks may become infected without their users knowing it.
When these users reconnect to the enterprise network-inside the perimeter-they bring their viruses and worms with them. Once loose on the network, viruses and worms can launch attacks against internal IT systems and the network itself, bypassing the network's perimeter defenses.
Viruses and worms typically use TCP/IP traffic to replicate themselves on a network and to unleash their attacks. Many send flurries of Internet control message protocol messages to locate other local devices that may be vulnerable to attack. Standard WLAN infrastructures (access points, network cards, RADIUS servers) have no means of identifying and stopping this traffic; wireless traffic, malicious or not, from authenticated users is simply passed through to the wired network.