Security is always on the minds of system administrators. As Intranets have evolved from glorified online cafeteria menus and corporate memos to robust information portals and mission critical applications, the bar has been raised to protect the castle from critters and other unwanted spooks that go bump in the night. . The link for this article located at Intranet Journal is no longer available. . Explore innovative tactics to protect contemporary infrastructures from internal threats and maintain the integrity of information management.. Intranet Security, Internal Threats, Security Enhancements, Data Protection, System Administration. . Brittany Day
There is a classic moment during the battle for Helm’s Deep in the epic film, Lord of the Rings, the Two Towers, when King Theoden stands atop the supposedly impregnable city. Rain sodden, he surveys the massed ranks of Saruman’s armies and defiantly shouts ‘Is this all you’ve got?’ A few fateful minutes, and a well placed explosive, later his confidence is shattered and replaced with fear as he realises that his fortress has been penetrated. Whilst this may have been a marvellous piece of celluloid drama, this scene could have been replicated in the IT departments of many enterprises throughout 2004. Replace Helm’s Deep with firewalls and the Orcs with trojans and viruses and you’ll soon appreciate the similarities. . In terms of security and protecting our organisations, we really are still in the dark ages, and these are the plague years. Many companies hit by the SQL Slammer, NetSky and Blaster worms - and any of last year's main viruses- learned the hard way about what worked when it came to their security defences. In the main, perimeter defences such as network firewalls, gateway signature antivirus devices, and patches just about coped, but the internal networks suffered badly. Certainly, traditional tactics are not working. Several operating systems vendors estimate that it can take approximately 20 - 30 days to deploy, implement and test a patch across an organisation’s network. This is more than enough time for a destructive virus or worm to deliver its payload. In fact many of the breaches caused last year were due to remote workers and authorised visiting contractors connecting to networks without the prescribed signature updates/patches being applied and subsequently infecting desktops and servers that were still to be secured. Firewalls, intrusion-detection systems and antivirus software all play a role in security, but as network managers have witnessed, networks are being attacked at all levels. The answer to the problem is becoming clearer. To provide a greaterlevel of security we have to consider both the external threats and the internal threats in tandem. The link for this article located at SecurityPark.co.uk is no longer available. . Contemporary businesses continue to grapple with antiquated protection strategies in response to advancing dangers.. Network Security, Internal Threats, Firewalls, Security Strategies, Comprehensive Security. . Brittany Day
If you're reading this on a Windows machine and you don't know if you have a personal firewall installed and running, then stop what you're doing and take care of that right now. At the very least, turn on the Windows firewall. This feature is available in the PC control panel, and enabling it only takes a few seconds. You can come back and read this once you've done that. I'll wait. . OK. You're back. Now breathe a big sigh knowing that you may have prevented a worm infestation that truly would have ruined your day. Feel better? I know I do. Let's continue. You've noticed by now that I believe personal firewalls are vital on Windows machines. While you may also have a firewall on your network, that's not enough protection. The reason is that while a firewall between you and the Internet will keep worms and hackers from entering down that path, it will do nothing to prevent attacks that come from within your network—or through paths that aren't blocked by the company firewall. And those can ruin your day just as effectively. There are a lot of personal firewalls options on the market to choose from. Most make similar claims, but there are differences, and depending on what you're doing with your computer, those differences can matter. But then, so can the cost, and that can matter a lot since some choices are free. The link for this article located at Wayne Rash is no longer available. . Selecting the appropriate personal firewall is critical for safeguarding your devices against both internal risks and external attacks.. Firewall Solutions, Personal Security, Network Protection. . Joe Shakespeare
Irish companies are aware of internal threats to security, but give higher priority to technological safeguards than they do to employee training.The 2004 Ernst & Young Global Information Security Survey found that Irish . . .. The 2004 Ernst & Young Global Information Security Survey found that Irish companies are more aware of security threats than their international counterparts. More than 70 percent of the 1,233 organisations surveyed in 51 countries failed to list training and employee awareness of security issues among their top five security initiatives. In contrast, Irish companies listed employee misconduct as a fourth priority, while viruses, Trojans and worms were collectively listed as the number one security priority. Spam and loss of customer data were the second and third priorities for Irish businesses. "There are a number of reasons why Irish companies might be more aware of internal security issues than other companies; part of it is the fact that regulatory requirements have become more important in recent years," said Mike Harris, manager of Ernst & Young's technology security risk service, speaking to ElectricNews.net. "Also, a lot of the companies surveyed would be subsidiaries of international companies, which makes them more aware of these issues than would be the case in other countries." The link for this article located at Ciaran Buckley is no longer available. . A study involving 1,500 companies indicates that British businesses prioritize cybersecurity education and recognize emerging technological risks.. Irish Business Security, Employee Awareness, Ernst & Young Survey. . LinuxSecurity.com Team
The deployment and maintenance of these technologies does take time and in some cases specialized knowledge, resulting in higher costs. Whether or not this price is worth paying depends on one factor: how much damage would a serious intrusion into the internal network cost your organization? . . .. Since at least 1998 (see Avolio), security experts have warned that a perimeter defence alone is insufficient, and the vast majority of networks are extremely vulnerable as soon as the firewall, proxy service or physical security layer at said perimeter has been breached. The situation today has not changed much since 1998. Most security initiatives still concentrate on the firewalls and other border devices, and virus defence is the only area where a low level of penetration has been achieved in securing each individual client. None of this is news, though the extent of the danger is beginning to surface slowly, as more and more security experts point to the problem. Nevertheless, I believe strongly that the threat is still being underestimated, even by those who condemn perimeter defences. I have recently pointed out in [Vogt] that even a large corporate network can be destroyed in minutes, once an entry point has been gained and malicious code of sufficient quality has been brought inside. [Hanson] elaborated and strengthened this point using past worms as the example. The entire point of this analysis is that any breach of the perimeter is potentially fatal, no matter how small it is, if the interior network is soft. In my paper, a single compromised machine brought down 98% of a class B network in less than a minute. I know of no current or under-development defence systems that could defend against this kind of attack. Most importantly, as the worm is saturating the network, any kind of central defence mechanism will be slowed down by the very attack it should be fighting. The entire scenario is a typical one-vs-many problem. A centralized defence against a clever worm optimized for private networks will simplybe overwhelmed by the sheer number of attackers, which are multiplying at dazzling speed. As with any disease, stopping it early is the only realistic defence. Immunization of the potential victim is the most reliable. The link for this article located at SecurityFocus is no longer available. . Cybersecurity analysts argue that relying solely on external defenses is inadequate; uncover internal system weaknesses and potential exploitation techniques.. Network Security, Perimeter Defense, Attack Methods, Internal Threats. . Anthony Pell
The security firm says cyber-attackers are refocusing their efforts on PCs inside the perimeter of corporate networks Corporations should be as concerned about personal computers inside the network perimeter as those riding its boundary, warns Symantec's security team. Vincent Weafer, senior . . . . The security firm says cyber-attackers are refocusing their efforts on PCs inside the perimeter of corporate networks Corporations should be as concerned about personal computers inside the network perimeter as those riding its boundary, warns Symantec's security team. Vincent Weafer, senior director of Symantec Security Response, said cyber-attackers are shifting their efforts from outside the intranet boundary to inside. The attackers are taking an increasing interest in intranet-facing private network services in common desktop personal computers. According to Weafer, the farms of desktops inside the network perimeter provide a rich picking ground for attackers. They are often less secure than systems that face the Internet directly, making them attractive recruits for orchestrated actions such as denial-of-service attacks, said Weafer. The link for this article located at ZDNet UK is no longer available. . Cybercriminals are steadily focusing their efforts on office computers inside business networks, threatening the integrity of internal system security.. Corporate Network Threats, Internal Security Risks, Cyber Attack Trends. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.