Friday, December 01, 2006

Messaging System/Anti-Spam Service offer network security

FortiMail Secure Messaging Platform includes antivirus detection engine for virus and spyware protection and complete email scanning. It uses FortiGuard-Antispam, access policy filtering, content filtering, global and user black/white list filtering, and spam Real-time Blackhole List. FortiGuard-Antispam Service eliminates spam at network perimeter. It checks against known spammer IP addresses and email content with Universal Resource Identifier scanning.

Fortinet -- the confirmed market leader in Unified Threat Management and only provider of ASIC-accelerated, network-based antivirus firewall systems for real-time network protection -- today unveiled two powerful new additions to its network security solutions and services portfolio: FortiMail, a secure messaging system, and FortiGuard-Antispam, a managed antispam service. The FortiMail Secure Messaging Platform and FortiGuard-Antispam Service effectively layer antispam technology to offer antispam defense in-depth at the network perimeter and the mail server -- maximizing mail traffic performance by eliminating global spam at the network gateway, before it enters the corporate network.

Unwanted email or spam continues to present serious security challenges for enterprises and consumers alike. Increasingly, these messages contain spyware, grayware or other malicious attempts to adversely impact a customer's computing and networking resources. While many world governments have been writing legislation and enforcing penalties around spam creation and delivery, spam continues to be difficult to regulate and catch. Industry researchers suggest that 60 to 70 percent of all enterprise email is spam, and recent statistics suggest that a good portion of spam contains viruses or other types of attacks.

"As an industry leader in the design and manufacture of advanced semiconductors, we have many daily demands on our network and cannot sacrifice network performance due to spam, viruses or other unwanted network traffic," said Edward Huang, corporate IT infrastructure manager for Atmel. "Solutions such as Fortinet's network security platforms and FortiGuard-Antispam Service help to minimize unwanted and malicious network traffic, without network performance degradation or a lot of administrative overhead, which is essential for ensuring a productive business."

FortiMail Secure Messaging Platform

The FortiMail Secure Messaging Platform is a dedicated system based on Fortinet's award winning FortiOS technology and includes an antivirus detection engine for virus and spyware protection and complete email scanning. FortiMail uses advanced spam detection and filtering methods such as FortiGuard-Antispam, access policy filtering, content filtering, global and user black/white list filtering, spam Real-time Blackhole List (RBL), per user Bayesian filtering so that individual users can set their own profiles, heuristics filtering and denial-of-service.

The FortiMail-400 system is the first in a family of secure messaging platforms and is designed for medium to large enterprises and remote branch offices. Future FortiMail systems will be available to secure messaging for high-volume, mission-critical infrastructures such as large enterprises, universities and managed security service providers (MSSPs).

The FortiMail Secure Messaging Platform offers users three protective modes of operation:

-- Transparent mode: FortiMail platform is placed in front of the existing email server without any changes to the existing email topology to provide seamless integration into existing network environments.

-- Gateway mode: FortiMail platform is placed in front of the existing email server providing in-bound and out-bound email relay services, which allows for scanning of both in-bound and out-bound email messages.

-- Server mode: FortMail platform provides complete email server functionality in addition to antivirus and antispam functionality, which is ideal for medium sized companies and remote branch office locations.

FortiGuard-Antispam Service

FortiGuard-Antispam Service is a new fully managed service that helps companies of all sizes reduce the amount of spam by eliminating it at the network perimeter. Fortinet developed this service internally and optimized it for operation on Fortinet's FortiGate network security platforms and the new FortiMail system family. On either system deployment, FortiGuard-Antispam can significantly reduce the amount of unwanted and possibly malicious spam messages passing through corporate email servers.

Using Fortinet's "dual pass" scanning technology in either the FortiMail or FortiGate systems, the FortiGuard-Antispam Service checks against known spammer IP addresses and email content with Universal Resource Identifier (URI) scanning. URI scanning looks deep into each email message to scan for well-known spam content such as spam URL links. The pairing of this new service with Fortinet security systems will help increase spam detection rates, as spammers get more creative and use infected PCs to deliver spam.

Thursday, November 30, 2006

GFI LANguard Network Security Scanner 3.3

GFI LANguard Network Security Scanner 3.3 covers the basics of vulnerability scanning well, though it lacks some of the advanced capabilities found in more enterprise-focused products such as eEye's Retina Network Security Scanner and NetIQ's Security Analyzer 5.0. LANguard cannot take the in-depth look at CGI scripting that Retina can or scan some types of network hardware, such as routers. But it's also much less expensive than the products from eEye and NetIQ.

To perform a basic scan of your network, you simply enter an IP address or range and press Start. LANguard gives you many types of predefined security scan profiles. For example, you can scan using only ICMP for discovery, scan all available ports, or scan for open shares or missing patches. You can also define and save your own security scan profiles.

Without administrative privileges in a Windows domain, you can determine computer names, MAC addresses, open ports, operating system versions, and SNMP information, all reported in a tree structure of results sorted by IP address. With domain administrative privileges, you can determine significantly more information about each system, such as shares, user accounts, services, password policies, registry information, and installed patches. Your scan can also include testing for CGI abuses as well as FTP, DNS, mail, service, and registry vulnerabilities. The results are grouped by category and include either a recommendation for remediation or a BugTraq, CVE, or Microsoft Security Bulletin reference.

Within the report generator you can create and save custom reports to meet your individual security needs. For example, you can generate a report of all systems that have either TCP port 80 (Web) or port 21 (FTP) open. As with Retina and SAINT 5, an included utility lets you compare two reports for new, removed, or changed items, as well as alert and hot-fix changes.

LANguard is also marketed as a patch management and deployment solution. During a scan of a Windows network, LANguard determines which patches have been installed on your systems and which are missing, based on GFI's coordination with Microsoft. It deploys hot fixes as well as service packs.

Tuesday, November 28, 2006

Web Security Software protects mobile users outside network

Websense[R] Remote Filtering extends web filtering and web security technology to laptop users outside of organization's network to ensure secure internet use anytime and anywhere. Organizations can apply internet usage policies to remote users, protecting them from security threats and managing access to objectionable content. Specifically, software provides protection from accessing phishing sites, sites that contain spyware, or sites corrupted with malicious code.


New Functionality Will Extend Web Filtering and Web Security Policies to Remote Users, Regardless of Location or Type of Network Connection

SAN DIEGO, Sept. 19 -- Websense, Inc. (Nasdaq: WBSN), the world's leading provider of employee internet management solutions, today announced the upcoming release of Websense(R) Remote Filtering technology, extending Websense's industry-leading web filtering and web security technology to corporate laptop users outside of the organization's network. Remote Filtering capabilities will be seamlessly incorporated into the newest versions of Websense web filtering and web security software, expected to be available in October 2005.

With the growing rate of telecommuting and business travel, it has become critical for organizations to enable employees who work remotely to use their laptop computers effectively and safely. As broadband internet access becomes more pervasive in non-traditional settings such as airports, hotels or local coffee houses, the necessity to protect remote laptop users from malicious threats lurking in unknown networks intensifies exponentially. Websense Remote Filtering ensures secure employee internet use anytime and anywhere, becoming a critical component of any organization's endpoint security and protection strategy.

Wednesday, November 22, 2006

Performance Analysis: Network Security Scanners

PC Magazine Labs has taken an in-depth look at the six network vulnerability scanners in our roundup, as well as the tools included in our sidebars (the Foundstone FS1000 Appliance, Microsoft Baseline Security Analyzer (MBSA), Nmap, and Stealthbits Technologies' StealthAudit). When we tested how well they could catch basic network vulnerabilities, all the scanners performed adequately. But the quality—and more important, the ease of use of the reports the products generate—varied significantly.

Our test network comprised a Linksys BEFVP41 router and a mix of Microsoft Windows clients and servers (Windows 98, 2000 Workstation, 2000 Advanced Server, and XP). We also deployed Linux hosts (Red Hat 8 and 9 Professional, SuSE Enterprise Server 8, and SuSE 8.1 Professional) to test each application's cross-platform capabilities.

We updated all systems with all appropriate patches, but we did not fix a select number of critical vulnerabilities on the target hosts. On our Windows hosts we left vulnerabilities described in Microsoft Security Bulletins MS03-039 (Buffer Overrun In RPCSS Service, CAN-2003-0715, CAN-2003-0528, and CAN-2003-0605) and MS03-041 (Vulnerability in Authenticode Verification, CAN-2003-0660). Under the right circumstances, both can let hackers execute code on target systems.

We left our Linux machines vulnerable with an exploitable version of OpenSSH (CAN-2003-0682, CAN-2003-0693, and CAN-2003-0695), a file share (/usr) exported with no access restrictions (CAN 1999-0554), and a denial-of-service vulnerability in the Unix Domain Name Service BIND 9.1.3 (CAN-2002-0400). Such Linux vulnerabilities can create a severe security risk, compromising your network and data.

All the products correctly identified the Windows vulnerabilities, and their reports included references to the appropriate Microsoft Security Bulletins. But the Linux vulnerabilities posed a bigger challenge to some of the Windows scanners.

Saturday, November 18, 2006

Hitachi Software and KDDI Network & Solutions to Market English HIBUN Information Security Management Solutions Overseas

Hitachi Software Engineering Co. Ltd. (HitachiSoft) and KDDI Network & Solutions Inc. (KNSL) have agreed to collaborate on the overseas marketing of HitachiSoft's HIBUN series of information security management systems in North America, Europe and Asia, and will be releasing English-language versions effectively this month.

The implementation of Japan's Personal Information Protection Law has spurred the introduction of measures to enhance information security management in Japan and demand for security measures is growing among overseas branches and subsidiaries. Following this demand, KNSL and HitachiSoft will release the HIBUN series, already with 1,700 corporate users and 1.5 million licenses in Japan as of July 31, 2005, overseas.

HitachiSoft has developed English-language versions of three products in its HIBUN range of information security management solutions - HIBUN AE Information Cypher, which encrypts drives, media and files, HIBUN AE Information Fortress, which controls transfer to external media and printing, and HIBUN AE Server, which provides logging and user control functions - to be released in November. As primary agent, KNSL will provide support services in Japanese and English to overseas sales companies, 24 hours a day, 365 days a year. The products will be marketed by a US subsidiary of KDDI Corporation, while HitachiSoft's US subsidiary Hitachi Software Engineering America, headquartered in San Francisco, will handle sales, implementation and configuration and SE support services to customers.

The new solutions will initially be marketed from bases in the United States, Europe and Asia, targeting local subsidiaries of Japanese companies in the United States, the United Kingdom, France, Germany, the Netherlands, Belgium, Hong Kong, Taiwan, Korea, Singapore, Thailand, Malaysia,, Indonesia, the Philippines, Vietnam, Australia, while marketing activities will gradually be expanded. From September, promotional activities such as seminars will be conducted overseas, and the products will go on sale at promotional prices. KNSL and HitachiSoft aim to sell 200,000 licenses over a three-year period.

Tuesday, November 14, 2006

Security group warns of VPN vulnerabilities

The UK's National Infrastructure Security Coordination Center (NISCC) has warned of potential attacks on the IPSec protocol used in browser-based virtual private networks, which could render encrypted messages as plain text with only "moderate effort". This would affect many remote communications to enterprise networks via Wi-Fi and other networks, with IPSec becoming increasingly popular among mobile workers.

The NISCC describes the weakness as "severe" and says it applies to IPSec configurations that rely on Encapsulating Security Payload (ESP) in tunnel mode with confidentiality only, or with integrity protection offered by a higher layer protocol.

The attacks need to be carried out many times before they are successful, but once this phase is reached, "the results can be reused to efficiently recover the contents of further inner packets". The attacks are fully automatable.

The main safeguards that companies should take are to configure ESP to use both confidentiality and integrity protection; use the AH protocol alongside ESP to provide integrity protection; and filter ICMP messages at a firewall or security gateway.

Thursday, November 09, 2006

Network Security: Know Your Weaknesses

As the person responsible for your company's network security, you know you are sorely outnumbered. A seemingly infinite number of potential intruders are lurking out there, and there's never enough time to prepare.

Without a doubt, the costs of cyberattacks are significant, as shown by the 2003 Computer Crime and Security Survey, conducted by the Computer Security Institute and the FBI. The 250 organizations that participated in the eighth annual study reported combined losses of $202 million, with causes ranging from theft of proprietary information, denial-of-service attacks, and viruses to insider abuse of network access.

How do you improve your odds? Your obvious first step is to identify system weaknesses. Vulnerability assessment scanners not only automatically discover security flaws on a network but in some cases correct them, too. Such tools have been around for years, but only recently have they matured into more comprehensive and user-friendly—if still complex—products, with features like customized reporting, distributed threat assessment, and automatic correction of potential problems.

Among the things such scanners can identify are known software bugs, viruses, and weak access control policies. Commonly found workstation vulnerabilities include open NetBIOS ports for file and printer sharing, as well as users who run rogue Web servers or peer-to-peer file-sharing clients.

Vulnerability assessment scanners can also find improper configurations of applications, which can leave a network unprotected. For example, Microsoft Exchange's default configuration used to leave the server as an open SMTP relay, which could be exploited by spammers. This resulted in attackers hijacking servers and sending millions of e-mails that appeared to originate as legitimate traffic from the victims' networks.

Friday, November 03, 2006

Retina Network Security Scanner

Intelligent, out-of-the-box ESP 3000 solution consists of integrated layers of security technologies including IDS, IPS, behavioral analysis, event and global threat correlation, vulnerability scanning, vendor alerts, asset database, and security dashboard. Browser-based Master Control Unit acts as monitoring console, signature server, cluster manager, and Web server, while also containing Web portal housing all reports and graphs for appliance suite.

New SRM solution from a proven network security innovator arms organizations with more complete protection, cost savings and ability to preemptively avoid network attacks

DALLAS, TX. - September 26th, 2005 - Global DataGuard, the premier provider of Security Risk Management (SRM) solutions for midsize-to-enterprise organizations, today announced it is rolling out a fully integrated, groundbreaking suite of new SRM solutions that enable organizations to immediately and economically understand where their networks are vulnerable, who's trying to attack them and what they can do to prevent network security problems.

Global DataGuard's intelligent, out-of-the-box ESP 3000 solution consists of integrated layers of security technologies that together provide unmatched risk management: IDS, IPS, behavioral analysis, event and global threat correlation, vulnerability scanning, vendor alerts, an asset database and a security dashboard. Each layer complements and augments the others, with intelligent behavioral analysis and correlation capabilities comprising the GDG difference. The result is early warnings of threats other solutions cannot see; far fewer false positives; cost savings, more thorough compliance and the ability to manage security solutions with one console.

The installation process is straightforward, and upon start-up, Retina synchronizes its vulnerability signature databases with eEye's server. When Retina opens, the main user interface provides access to four modules: the browser, tracer, miner, and scanner. The integrated Web browser lists all page elements in a tree view, and the tracer creates a traceroute and displays response times. But the miner and scanner modules are the brains of the operation. With its proprietary artificial-intelligence engine, the miner tries to mimic a hacker's behavior by attacking security weaknesses.

Saturday, October 28, 2006

Network Security System offers fully integrated solution.

Intelligent, out-of-the-box ESP 3000 solution consists of integrated layers of security technologies including IDS, IPS, behavioral analysis, event and global threat correlation, vulnerability scanning, vendor alerts, asset database, and security dashboard. Browser-based Master Control Unit acts as monitoring console, signature server, cluster manager, and Web server, while also containing Web portal housing all reports and graphs for appliance suite.

New SRM solution from a proven network security innovator arms organizations with more complete protection, cost savings and ability to preemptively avoid network attacks

DALLAS, TX. - September 26th, 2005 - Global DataGuard, the premier provider of Security Risk Management (SRM) solutions for midsize-to-enterprise organizations, today announced it is rolling out a fully integrated, groundbreaking suite of new SRM solutions that enable organizations to immediately and economically understand where their networks are vulnerable, who's trying to attack them and what they can do to prevent network security problems.

Global DataGuard's intelligent, out-of-the-box ESP 3000 solution consists of integrated layers of security technologies that together provide unmatched risk management: IDS, IPS, behavioral analysis, event and global threat correlation, vulnerability scanning, vendor alerts, an asset database and a security dashboard. Each layer complements and augments the others, with intelligent behavioral analysis and correlation capabilities comprising the GDG difference. The result is early warnings of threats other solutions cannot see; far fewer false positives; cost savings, more thorough compliance and the ability to manage security solutions with one console.

Saturday, October 21, 2006

Guard your systems from network parasites with the WolfPac Security Suite - Top Technology Showcase

PSINet Europe, a leading provider of corporate IP-based communication services, recently conducted a little experiment: To prove the importance of network security, it set up an anonymous "dummy server" containing no data and no public profile. Within 24 hours it was attacked 467 times. This large number reflects the fact that computer hacking is no longer just a hobby for computer geeks--it is now a full-time job. Network professionals need to be aware of this growing problem and learn to protect themselves from uninvited guests.

NetWolves' latest offering is designed to prevent system robbery. It acts as a hacker's kryptornte making your servers secure from outside intrusions. The Security Suite acts as a link between large companies and remote offices or as a single gateway for small-to-medium size businesses. It provides companies with an option for shielding their intellectual property from information thievery.

The suite comes in two platforms: the WolfPac 2020 and the WolfPac 3020. They both come equipped with three Ethernet 10/100 interface cards for WAN, LAN and DMZ connections. The security suite is offered with either a 600MHz or 900MHz processor, 20- to 100GB hard drive, and up to 1,024MB of RAM.

Thursday, October 19, 2006

Web application assessment - Network monitoring and security - Weblnspect 3.0 Enterprise Edition - Brief Article

Discover where network security needs improvement with Weblnspect 3.0 Enterprise Edition, a product designed to automate the assessment of Web services security. Users can perform security assessments on any Web-enabled application, including specific assessment capabilities for Microsoft .NET, IBM WebSphere, Lotus Domino, Oracle Application Servers and MacroMedia ColdFusion. An intuitive, wizard-driven interface, and integrated tools and utilities provide easy access to Web application vulnerabilities. In addition, an expert mode allows advanced users to manually interact with the assessment process and create custom test scripts. The configurable XML export tool enables users to export any and all information found during the scan in a standardized XML format, including comments, hidden fields, Javascript, cookies, Web forms, URLs, requests and sessions.

Friday, October 13, 2006

Scan like a hacker - Network monitoring and security

ScanDo is a Web application scanner that assesses the entire Web application to identify security loopholes through comprehensive exploration and penetration of the Web application and its operating environments. The tool reveals Web application vulnerabilities using the same techniques used by hackers, including the manipulation of IT infrastructure vulnerabilities, parameter tampering, Web services and SOAP vulnerabilities, hidden field manipulation, cookie poisoning, stealth commanding, backdoor and debug options, database sabotage, buffer overflow attacks, data encoding, and protocol piggybacking. Weaknesses are pinpointed and the risk level assessed within the applications to be managed. The solution then generates reports in graphical or textual formats for novice or experienced security personnel.

Monday, October 09, 2006

Questioning the cost of compliance: some say a new network security rule puts an unfair burden on higher ed

WITH LEGISLATION TO reauthorize the Higher Education Act (HEA) lumbering toward enactment, although its final form remains uncertain, the higher education community in Washington is paying attention to new developments in other areas.

One issue: regulations issued by the Federal Communications Commission (FCC) to broaden law enforcement's ability to monitor electronic communications involving suspected terrorists and criminals.

The new regulations extend to universities, as well as libraries, airport public wireless networks, and commercial Internet service providers, provisions of the 1994 Communications Assistance for Law Enforcement Act. That measure directed telephone companies to redesign their networks to enable law enforcement agencies to have remote access to their systems.

The rules, newly issued by the FCC, extend the remote access requirements to computer networks. Implementation requires all Internet service providers, including IHEs, to upgrade network switches and routers by June 2007 to enable remote monitoring. The cost to upgrade computer networks at IHEs is estimated at $7 billion, according to the American Council on Education (www. acenet.edu), which quickly challenged the FCC's rules in the federal appellate court for the District of Columbia.

"Potentially, this is a huge deal over a complicated set of issues," says ACE Senior Vice President Terry W. Hartle. Some people would argue there is a broader privacy issue here. "What we have argued is simply that we will comply; we are anxious to do our part in the war on terror, but what the government is asking us to do is very expensive for very little return."

Higher ed institutions have long worked with law enforcement agencies pursuing criminal investigations, adds Sheldon E. Steinbach, ACE vice president and general counsel. He says that by filing suit, ACE hopes to convince the FCC that institutions "can provide the same access through alternative approaches" without having to shell out $7 billion.

"When you evaluate efficiency versus the incredible cost of compliance, we just don't think it makes a lot of sense," Steinbach says.

SHAPING THE FUTURE

In another development, U.S. Education Secretary Margaret Spellings kicked off a national commission established to shape the future of higher ed in the U.S. and asked it to submit specific recommendations by August 1, 2006, on four areas: accessibility, affordability, accountability, and quality.

The commission, made up of 19 business, foundation, and higher ed representatives, got an immediate taste of its mission when the College Board reported that there continue to be significant long-term concerns about college access and affordability.

Although average grant aid per student is growing, it's not by enough to prevent increased reliance on borrowing, the College Board stated. Low-income students receive more grant aid, on average, than higher-income students, but new student aid policies have benefited those in the upper half of the income distribution most.

HEA UPDATE

Meanwhile, the Senate and House are still moving in their own ways to reauthorize the HEA. At the outset of the congressional budget process last February, both bodies agreed to reduce the federal deficit by $35 billion over five years by cutting entitlement programs, a process known as reconciliation. The Senate Committee on Health, Education, Labor and Pensions must contribute one-third of the total cuts in the Senate.

In October, the Senate Committee approved budget reconciliation legislation that encompasses HEA reauthorization. The measure cuts $15.1 billion over five years from the federal student loan and pension programs. The House Education and Workforce Committee cut $20.8 billion.

Higher ed lobbyists continue voicing concerns over spending cuts. But Congress is under pressure to help pay for hurricane relief and the war in Iraq. Unsure when it will complete reauthorization, Congress extended programs under HEA as they stand until December 31.

Monday, October 02, 2006

Credit union serves up secure solution; password technology system provides members with authenticated, 24/7 network access - Network Security - State

More than 73,000 members. $530 million in assets. A fast-growing dial-in network where remote users can gain 24/7 access. A potential security nightmare.

That was the challenge facing the State Employees Credit Union (SECU) in Lansing, Mich., which, since its charter in 1952, has grown to become one of the leading credit unions in Michigan and the United States. With its burgeoning network, however, Mark Davis, SECU assistant vice president of data center operations, understood the dangers of unauthorized access, and wanted to be able to identify each individual user attempting to log on to the system.

"As far as remote dial-in, we were getting to the point where our network was too exposed and anybody would be able to get in," says Davis. "I realized that greater security would be needed as we basically just had someone dialing into a router to use NT security."

SECU underwent an exhaustive search to identify a cost-effective method to provide high-level security for its dial-in network.

Friday, September 29, 2006

Internet Security Gateway targets small network environments

Providing unified threat management, InstaGate 305 includes network intrusion prevention, and deep packet inspection firewall to detect and stop threats at all layers of network. IPSec VPN with 3DES/AES encryption and digital certificate support allows site-to-site security and remote-access connectivity. Based on user-definable keywords, full URLs, and regular expression matching, URL filtering allows organization to limit URLs accessible from behind firewall.

Device Raises the Bar for Sub-$1,000 Unified Threat Management (UTM) Solutions by Including Gateway Anti-Virus, URL Filtering and Intrusion Prevention

BROOMFIELD, Colo., Sept. 14 -- eSoft, Inc., a leading vendor of integrated Internet security and content management solutions, announced today the availability of its newest product, the InstaGate 305 integrated security gateway, which integrates Firewall, IPSec VPN, Gateway Anti-Virus, Web URL Filtering and Network Intrusion Prevention into a single, easy-to-deploy and manage solution.

The InstaGate 305, tailored for small network environments with critical security needs, is the latest addition to eSoft's award-winning line of unified threat management (UTM) solutions that integrate dynamic Deep Packet Inspection services such as Anti-Virus and Intrusion Prevention into traditional Firewall/VPN network security appliances. While many devices in the sub-$1,000 market provide stateful Firewall and VPN functionality, few provide the performance and depth of inspection of the InstaGate 305, which is based on a powerful Intel(R) XScale processor with a large memory footprint.

"The InstaGate 305 fills a critical gap in one of the most under-served areas of the market," said Scott Lukes, eSoft vice president of marketing. "Small organizations are exposed to the same Internet threats as large Fortune 500 enterprises -- the only difference is that they don't have the same resources to deal with them. The 305 was designed to provide all of the necessary tools to protect small networks from modern, dynamic threats -- like the recent Zotob virus -- with minimal requirements from IT."

Monday, September 25, 2006

Revamp your network security - now

Did you like to blow things up when you were little? Come on, be honest. I'll come clean. More than a few mailboxes fell under the onslaught of my juvenile pyromania. Being an adult means wanton destruction is frowned upon. But maybe there is something we can do to regain the thrill.

Try this on for size: You should blow up your network. That's right - over the next 18 months you'll be overhauling your campus network. It's time. You know you are tired of those old Layer 3 switches. Those are so five years ago. Aren't those boxes depreciated yet? Get the finance guys on the horn.

The business has changed. The insider threat is real. Folks connect to your network from conference rooms and over VPNs from unsafe environments. You can't stick your head in the sand anymore. Compliance has teeth and you need to segment networks and protect sensitive data. Acknowledging this is a huge change for me, since I used to laugh when told that people needed to secure internal networks.

I remember talking years ago to companies that were pitching that customers needed to extend the protection deeper into the network. I laughed. The moat is deep and wide. The bad guys cannot get in. Well, now the bad guys are us and they may already be on the network. We need to make the network much less hospitable to them.

Monday, September 18, 2006

Remote application console - Network security - Remote Console Server 3.0 - Brief Article

Providing remote access to console and DOS legacy applications, Remote Console Server 3.0 is an advanced remote-access server that runs as a regular network service for Windows NT/ 2000/XP. The solution dynamically displays a console panel (up to 255x255) without distortions, and supports a mouse, function keys and hot key combinations. Administration options include access time management, session monitoring and reviewing, capability to set restrictions by IP and domain address, sending messages to currently connected users, forced online session disconnection and termination, and overtaking control. The program features in-session file uploading and downloading support; every session has an independent clipboard on the server side; and for every process, the duration time limit is user defined.--Zilab Software

Tuesday, September 12, 2006

AT&T to upgrade network infrastructure for Internet Security Systems

Telecomms holding company AT&T Inc (NYSE:T) has signed a three year contract to upgrade the network infrastructure of enterprise security company Internet Security Systems Inc (ISS).

AT&T said the new contract, which follows ISS's adoption of AT&T's MPLS technology in 2004, which extends the MPLS services to ISS locations in the US, Europe and the Asia-Pacific region. ISS will use the network upgrade to add further company locations in the future.

According to AT&T, the network upgrade will provide ISS with disaster recovery services which use the fastest, most advanced any-to-any mesh connectivity, to ensure outages at centralised hubs do not disrupt the networks.

ISS will also use the upgraded network to introduce VoIP capabilities across its enterprise, enabling it to streamline internal voice communications and gain maximum cost-efficiencies. The new contract also covers dedicated Internet, long distance and AT&T ultravailable local access services

Thursday, September 07, 2006

THE NEED FOR INTERNAL SECURITY

To thwart viruses and worms, security controls need to be instituted at the wireless edge, so malicious TCP/IP traffic can be stopped before it spreads to other devices. Complementing the external security perimeter that protects wired networks, enterprises need to create an internal security perimeter to secure their WLANs.

One solution is to deploy WLAN security gateways, which are network appliances designed to secure, manage and power WLANs. Operating at the wireless edge, between access points and other devices upstream, WI,AN security gateways protect networks from security attacks launched from wireless devices.

These gateways should meet three key requirements:

1. Precise packet-filtering controls for blocking or redirecting traffic. The gateway should include precise packet-filtering controls that can distinguish malicious traffic from legitimate traffic, and take action to block or redirect malicious traffic. A network administrator should be able to read a security bulletin describing the characteristics of a virus or worm and then precisely define a filter that targets the traffic of that virus or worm. The filter should block malicious traffic without interfering with legitimate traffic. By detecting and blocking the traffic that viruses and worms depend on, the filtering capabilities of a WLAN security gateway contain airborne attacks.

2. Filtering at the wireless edge to manage traffic among devices. To contain an attack, packet filtering must occur at the wireless edge, as close as possible to the access point. For optimal protection of the network, WLAN security gateways should be installed between the access point and the next upstream network device.

3. Session logging and audit tools for identifying infected computers and accelerating repairs. WLAN security gateways should provide logging and audit tools to help administrators remediate an attack, once it is contained. By maintaining full session logs of network traffic and tracking Layer 3 traffic data, WEAN security" gateways facilitate the identification of users with infected computers and the MAC addresses of the computers themselves. Using this information, administrators can contact users directly and begin cleaning up any infected computers.

CENTRALIZED POLICY MANAGEMENT

A tiered solution that combines WLAN security gateways at the wireless edge with a centrally located policy server provides additional advantages for network administrators combating viruses and worms. By providing centralized control over filters, the central policy server allows administrators to define a policy that immediately takes effect across the network. The policy server automatically distributes filters to all the WLAN security gateways, providing immediate protection at every access point on the network. This centralization also reduces manual labor and the risk of error.

The central policy server can manage user accounts and user groups for wireless users. Administrators can use the server's group-management features to define a special user group for users with infected computers. The group characteristics would include redirecting users to a Web page with information about how to install security patches and clean up infections.

By temporarily assigning users with infected computers to this group, administrators can ensure that users with infected computers receive the information they need the next time they log in. Once administrators have verified that the infected computers have been cleaned, they can remove users from this group and restore their normal access rights.

Friday, September 01, 2006

Prevent viruses on enterprise WLANs: security gateways provide protection from within the network perimeter - Wireless

Before wireless LANs (WLANs) became popular, the only way viruses and worms could reach an organization's computers was through portable media, such as floppy disks, or through the network perimeter, which was secured by an increasingly complex battery of defenses, including firewalls, e-mail filters and antivirus engines. The use of floppies and other portable media is declining. E-mail attachments have become the preferred channel for transferring files. As a result, on a wired network, just about all potentially malicious data enters an enterprise through the network perimeter, where it will likely be detected and blocked.

WLANs undermine perimeter defenses. Wireless users are mobile. They take their computers to other networks. Some of these networks are se cure and well managed; others are not. Computers on these networks may become infected without their users knowing it.

When these users reconnect to the enterprise network-inside the perimeter-they bring their viruses and worms with them. Once loose on the network, viruses and worms can launch attacks against internal IT systems and the network itself, bypassing the network's perimeter defenses.

Viruses and worms typically use TCP/IP traffic to replicate themselves on a network and to unleash their attacks. Many send flurries of Internet control message protocol messages to locate other local devices that may be vulnerable to attack. Standard WLAN infrastructures (access points, network cards, RADIUS servers) have no means of identifying and stopping this traffic; wireless traffic, malicious or not, from authenticated users is simply passed through to the wired network.