Alerts This Week
Warning Icon 1 770
Alerts This Week
Warning Icon 1 770

Linux Network Security - Page 46

Discover Network Security News

Maximizing Security and Budget with IT Outsourcing Solutions

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

With a clear knowledge gap among many IT professionals and security specialists demanding salaries in excess of £50,000, many organisations since the recent downturn in the economy have looked to outsource all or part of their IT security. The main benefits being to deliver improved value across the board and importantly increase profits. With lower investments being made in staff and contracts agreed up front, this becomes entirely feasible. . . .

Maximize Security Efficiency Using Unix/Linux Across Various Roles

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It is a rare organization that has the money to deploy best of breed or integrated commercial software for every security role. Whether your job is perimeter protection, incident response or email server administration, there may be an opportunity to use your favorite Unix system with some additional tools to get the job done faster and cheaper than what you do now. . . .

Effective Data Preservation Methods in Digital Forensics Analysis

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Computer forensics involves the preservation, identification, extraction, documentation and interpretation of computer data. It is often more of an art than a science, but as in any discipline, computer forensic specialists follow clear, well-defined methodologies and procedures, and flexibility is expected and encouraged when encountering the unusual. It is unfortunate that computer forensics is sometimes misunderstood as being somehow different from other types of investigations. . . .

Managing Data Security Risks In Networked Environments Effectively

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Anything short of keeping a computer locked in a room with no network connection represents a security risk. From the moment the device is plugged in and connected to a network, you begin to trade security for functionality. It's always a balancing act, and one that requires you to determine how much functionality you are willing to sacrifice for increased security or vice versa. "Wireless, remote access and outsourcing solutions present many key barriers to security and, if not managed correctly, can expose a corporate network to unlawful intrusion. These threats, however, can be avoided if the proper precautions are taken," says Wreski. . . .

Key Reasons To Justify Security Training For Unix Administrators

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

A few days ago, a reader asked if I could help him justify the cost of security training that he and his fellow Unix system administrators felt they needed. I gave the reader a variety of ideas, one of which is sure to resonate with his manager. When making your pitch, you might want to try these reasons. . . .

Understanding Defense In Depth Concepts for Information Security

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Perhaps the best way to visualize Defense in Depth as it relates to Information Security is to view the recent blockbuster movie: "The Two Towers". When the antagonists approached the perimeter defenses at Helm's Deep, they were first greeted by a volley of arrows. As they approached closer, rocks and boiling oil was thrown on their heads. Then there was the actual wall to contend with. As they brought up siege ladders, they were thrust back with long poles. As they jumped on the tower ramparts they were engaged hand to hand. But despite of the defenses due to the perceived value attached to defeating Rohan, evil nearly prevailed. As of late when one considers network and especially Internet security one might wonder if good will prevail in the real world. . . .

Outsourcing Cyber Security Strategies For Effective Business Management

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

As last summer's virus attacks vividly demonstrated, companies of every size are finding themselves hard pressed to maintain around-the-clock network security. Arriving nearly simultaneously, the Blaster, Welchia, and Sobig.F worms invaded hundreds of thousands of corporate computers, resulting in billions of dollars of damages and lost productivity. In this new atmosphere, where crippling attacks arrive almost immediately after vulnerabilities are announced, how can enterprises maximize their IT investments and successfully manage security? They can tackle the job with their in-house IT staff, of course, or they can outsource the task to a managed security services provider (MSSP). This article will look at certain key issues for determining when outsourcing security is the best approach to take. . . .

Cisco Patent Proposal: TCP Reset Attack Mitigation Strategy

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This concerns us all. Cisco is trying to patent the idea of demanding a confirmation-to-reset packet from an allegedly resetting host. This not only attempts to patent something that fails the 'non-obvious' test (really, is there a more obvious solution?), but it also opens up the door to a new "confirm reset? acknowledge" DoS attack. We all have a stake in making sure that basic TCP/IP security measures do not become proprietary. . . .

AirDefense Research on Wireless LAN Threats at Networld+Interop

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

AirDefense is one of the more respected companies producing wireless LAN security software. AirDefense performed a research experiment at the recent Networld+Interop conference in Las Vegas. Their monitoring software scanned for vulnerabilities and network attacks during the conference producing some astonishing results. . . .

Understanding Rogue Access Points and Their Threat to Network Security

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

A rogue access point is not authorized by an organization's IT department for operation.) Setting up an access point is child's play. In addition to plugging the access point into a power source, all one has to do is connect one end of an Ethernet cable to an available Ethernet port, connect the other end to an access point and voila! A new Wi-Fi WLAN is born. . . .

Developing Trusted Network Connect: Enhancing Wireless Security Compliance

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The Trusted Computing Group said Monday that it is working on a specification to ensure that wireless clients connecting to a network won't serve as a back door to worms and crackers. Officials within the TCG, based in Portland, Ore., said the industry standards body is developing a "Trusted Network Connect" specification, designed to audit wireless-enabled PCs when they first make contact with an enterprise's wireless network. . . .

Understanding TCP Reset Attacks: Risks And Defense Techniques

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

To better understand the reality of this threat, KernelTrap spoke with Theo de Raadt [interview], the creator of OpenBSD, an operating system which among other goals proactively focuses on security. In this article, we aim to provide some background into the workings of TCP, and then to build upon this foundation to understand how resets attacks work. . . .

Your message here