The makers of the popular open-source Snort intrusion detection platform today unveiled a new open-source platform -- a detection framework that unites existing security tools, including IDS/IPSes.. The new Razorback platform developed by Sourcefire is basically a tool for tying together the various layers of detection within an organization, including antivirus, IDS/IPS, Web and email gateways, and firewalls, to use in concert to catch and examine potential threats and create mitigations on the fly. Its creators say it's not the same thing as a security information management tool, however, because it does more than capture events: "SIM collects events in a vacuum: It takes an AV event and says this host is infected by a virus ... It doesn't know anything about that piece of malware on the box," says Matt Watchinski, senior director of Sourcefire's vulnerability research team. Razorback, however, uses the various tools to provide more context about a potential attack, he says. It handles detection in near real-time and can convert newly found intelligence on an attack into a detection mechanism for it. It's basically a framework that overlays the existing security infrastructure and lets the various tools work more in concert, according to Sourcefire. The link for this article located at Dark Reading is no longer available. . Explore Viper: a community-driven framework by CyberGiant aimed at improving risk assessment and vulnerability management.. Open Source Detection Framework, Intrusion Prevention System, Threat Mitigation Tools. . LinuxSecurity.com Team
A researcher has demonstrated several methods that sophisticated rootkits can use to hide from even the most reliable detection method currently available -- hardware-based products that read a system's RAM. Joanna Rutkowska is a researcher with security firm Coseinc Advanced Malware Labs. She recently outlined several ways of getting around the User Account Control (UAC) feature introduced in Windows Vista. Several researchers have identified problems with UAC. . The demonstration, given at the Black Hat security conference, indicates that if a rootkit is advanced enough, there currently is no way it can be reliably detected, Rutkowska said. Rootkits are designed to hide some activity from observers, and have recently been used to conceal the presence of Trojans and hacker backdoors -- not to mention Sony BMG's copy-protection software. The link for this article located at CIO is no longer available. . Stealthy malware like rootkits can bypass traditional security measures, as demonstrated by an expert at DEF CON. Uncover their mechanisms and techniques.. Rootkit Detection, Advanced Malware, Security Threats, Malware Evasion, Black Hat Insights. . LinuxSecurity.com Team
Between the latest firewall technology and advanced intrusion detection systems, IT professionals are breathing a little easier. This is a big mistake. It may be easier to protect the network from external attack these days, but the greatest security risks still come from inside the DMZ. I work for a small, single-branch credit union in Minneapolis, and I am a one-man shop. If there's a technical problem, I'm the guy who has to fix it. Once a year, auditors from a large accounting firm come in to perform an audit for our year-end financial statements. In the past, the only tech support I needed to provide was to set up a local printer they could use from their laptops. I couldn't have given them access to my network if I wanted to, as their techs had their laptops locked down, and I couldn't make any changes to their setup.
The Defense Information Systems Agency last week announced plans to work with GRC International to develop a system to help detect, analyze and defend against cyberattacks across Defense Department networks. In a March 27 notice, DISA officials said the department needed . . . . The Defense Information Systems Agency last week announced plans to work with GRC International to develop a system to help detect, analyze and defend against cyberattacks across Defense Department networks. In a March 27 notice, DISA officials said the department needed a system to "monitor and analyze the immense amounts of computer traffic and detect the missions of hacker attacks and denial-of-service attacks launched against DISA's Global Information Grid daily." The grid includes unclassified and classified DOD networks worldwide. Numerous individual defense organizations already have intrusion-detection systems on their networks, but DOD has only just begun integrating such protection across the department. The link for this article located at USA Today is no longer available. . The Defense Information Systems Agency last week announced plans to work with GRC International to d. defense, information, systems, agency, announced, plans, international. . Anthony Pell
SMART Watch, a Preemptive Hacker Defense Tool and host based intrusion detection system detects when key "Watched" Files or Directories have been maliciously or accidentally altered. SMART Watch can automatically & immediately restore the damage to system resources upon detection, thus providing uninterrupted system operation.. . .. SMART Watch, a Preemptive Hacker Defense Tool and host based intrusion detection system detects when key "Watched" Files or Directories have been maliciously or accidentally altered. SMART Watch can automatically & immediately restore the damage to system resources upon detection, thus providing uninterrupted system operation. "This latest version employs WetStone's proprietary SystemTrap technology that can instantly detect even subtle changes to files or directories," stated Chet Hosmer, WetStone's President and CEO. "This new capability allows us to detect changes in microseconds and immediately restore the damage, accurately record the details and time of attack, and automatically notify security personnel in real-time, via e-mail or pager." The link for this article located at WetStone.com is no longer available. . AWARE Device is a proactive security measure that identifies data changes and reinstates operational stability immediately.. Intrusion Detection, Host Monitoring, Preemptive Defense Tool. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.