Access Control
News
- +
Symantec takes cybercrime snapshot with new report 25/11/2008 07:31:00
Keystroke loggers going for just US$23The criminal market online for buying and selling stolen credit cards, pirated software and information about financial accounts is thriving, according to a report published Monday by Symantec. - +
Spyware case finally closed for teacher Julie Amero 24/11/2008 12:30:00
Former schoolteacher Julie Amero has paid a $100 fine to end her infamous spyware case. She had been facing 40 years in prison.The case against Julie Amero is finally closed. - +
Laid off sysadmin arrested for threatening company's servers 11/11/2008 11:13:00
Epmloyee "not satisfied with the terms" of his severance goes too far, gets arrested.A systems administrator was arrested in New Jersey Monday for allegedly trying to extort money and even good job references out of a New York-based mutual fund company that had just laid him off. - +
Sophos: Beware of Malware-Bearing Obama E-mail 06/11/2008 10:12:00
An e-mail touting the win of Democratic candidate Barack Obama directs users to a doctored election results pageAn e-mail touting the win of Democratic candidate Barack Obama directs users to a doctored election results page. - +
Report: 'Foreign entity' hacked Obama, McCain PCs 06/11/2008 09:19:00
Newsweek says feds told Obama's team it had 'a problem way bigger than you understand'Computer systems used by the election campaigns of both President-elect Barack Obama and his Republican rival John McCain were broken into earlier this year, and a large number of files related to the evolving policy positions of the two candidates were stolen, according to a story posted online Wednesday by Newsweek magazine. - +
IT worker let spammers into ex-employer's servers 05/11/2008 08:13:00
A man has been sentenced to a year in prison for turning his former employer's e-mail servers into open relay systems for spammers.An IT manager who logged onto to his former employer's computer network five months after being fired and opened the e-mail server up to spammers has been sentenced to one year in prison. - +
Sun exec: IT security should follow business needs 30/10/2008 09:04:00
Proscriptive adoption of information security standards like ISO27001 is bound to fail, Sun's chief technologist says.Proscriptive adoption of information security standards like ISO27001 is bound to fail, according to Joel Weise, principal engineer and chief technologist, Sun client services security program office, Sun Microsystems. - +
Tough economic climate can heighten insider threat 16/10/2008 07:09:00
As companies downsize, they need to keep an eye out for disgruntled employeesWith a faltering economy resulting in increased jobs cuts and corporate belt tightening, security analysts are warning companies to be especially vigilant about protecting their data and networks against disgruntled employees. - +
IBM, Secret Service, others study identity/cybercrime issues 09/10/2008 10:09:00
Center for Applied Identity Management Research organization teams experts in criminal justice, financial crime, biometrics, cybercrime and cyberdefense, data protection, homeland security and national defense.IBM, LexisNexis and the Secret Service are among a group of corporations, government agencies and academic institutions that has formed to study and help solve identity management challenges around cybercrime, terrorism and narcotics trafficking. - +
VMware partners demonstrate VMsafe security prototypes 18/09/2008 08:53:00
But VMware gives no word on when VMsafe products will be availableA major VMware security initiative announced more than six months ago has still not resulted in any new products, but VMware and partners this week are demonstrating several prototypes of technology that will better secure virtual machines. - +
Best Western downplays data breach 27/08/2008 08:06:00
Breach compromised a dozen records, not 8 million, hotel insistsBest Western International Monday acknowledged it suffered a data breach that exposed sensitive customer information at a European hotel, but strongly disputes claims that an attacker gained access to 8 million customer records with credit-card numbers. Best Western insists no more than a dozen customer records were compromised. - +
Cisco routers again take hacker spotlight 06/08/2008 08:41:29
Cisco router hacks will get some attention at this week's Black Hat conference in Las Vegas.The Cisco hacking scene has been pretty quiet for the past three years, but at this week's Black Hat hacker conference in Las Vegas, there's going to be a little noise. - +
Sorting out the facts in the Terry Childs case 31/07/2008 08:12:20
San Francisco's network-abuse claims raise more questions than answersIt's been nearly three weeks since Terry Childs was arrested on four counts of computer tampering and sent to jail on US$5 million bail. In those three weeks, this event has taken turns to the strange, and wound up firmly in the land of the absurd. From bombastic claims in the press to midnight visits by San Francisco Mayor Gavin Newsom to pages of functional usernames and passwords entered into the public record, this case has certainly proven engaging. - +
City missed steps to avoid network lockout 29/07/2008 08:37:33
Loss of administrative control of San Fran's routers and switches for over a week could have been avoided.The high-profile sabotage this month of the city of San Francisco's fiber backbone network clearly shows both the extent of damage a disgruntled employee can cause and the need for controls to mitigate the risk of such actions. - +
San Francisco's mayor gets back keys to the network 24/07/2008 08:07:06
Gavin Newsom meets with Terry ChildsSan Francisco Mayor Gavin Newsom met with jailed IT administrator Terry Childs Monday, convincing him to hand over the administrative passwords to the city's multimillion dollar wide area network.
Features
- +
Software-based NAC security useful despite drawbacks 13/11/2008 09:44:00
NAC price, scalability and reporting are all strong pointsDespite some shortcomings, software-based network access control technology that enforces policies on network endpoints is often the first choice of customers who adopt the technology. - +
Five ways to bulk up your network for telecommuters 23/10/2008 07:41:00
Tips for adapting your corporate network for people working from homeWhether they're in branch offices or home offices, workers are increasingly telecommuting instead of working in a traditional centralized office environment. - +
Cyber security threats grow in sophistication, subtlety 16/10/2008 08:26:00
Researchers say malware, botnets, cyber warfare, threats to VoIP and mobile devices, and the "evolving cyber crime economy" are ever-more sophisticated threatsThe annual report from Georgia Tech Information Security Center identifies five evolving cyber security threats, and the news is not good. - +
Anonymous proxy servers: Necessary or evil? 15/10/2008 07:13:00
Some security experts believe anonymous proxy servers are only necessary if you're up to no good, while others see them as a legitimate tool for research, pen testing and the like. Who's right?If there is truly a gray zone in the struggle between online good and evil, anonymous proxy servers live there. - +
Capabilities of Full-Fledged Role Management Systems 09/09/2008 10:34:00
Today's role management solutions include several or all of the following capabilities, according to Burton Group analyst Kevin KampmanRole mining and discovery: The ability to collect user access and authorization information from a variety of resources, associate this data with candidate roles and responsibilities, propose alternative roles and leverage decisions made about the data on an ongoing basis. - +
Role management software: Making it work for you 09/09/2008 09:44:00
Role management software enables the creation and lifecycle management of enterprise job roles, according to Forrester Research. It does this by discovering and logically grouping application-level, fine-grained authorizations and entitlements into enterprise job roles, which can then be assigned to people by rule-based provisioning or request-approval workflows. - +
Who's Who in Role Management? 09/09/2008 10:31:00
Burton Group breaks the market down into two important segmentsThe role management software vendor community is relatively young, and as such, Burton Group says there is no clear market leader. Vendors can be categorized into two segments: general purpose solutions and embedded solutions. - +
Security and the generational divide 11/08/2008 08:55:38
Why 'stay off my network, you rotten kids!' isn't a good coping strategyThe generation gap. It's a term that has been used for decades to describe the differences between people in various age groups. Corporations are constantly considering what makes different generations tick when it comes to recruiting and retaining employees. But security experts say companies also need to examine age-based perspectives and habits when it comes to risk assessment and policies. - +
How secure is secure enough? 29/07/2008 07:44:00
Are your information security plans too big, too small or just right? Here are five steps to help you decide.If there is a Holy Grail in the information security industry, it surely is the answer to the question, "How secure is secure enough?" - +
When security staffers fail up 23/07/2008 09:40:52
Containing the painfully unqualified or essentially overwhelmedThink your security staffers are trustworthy? Competent? Knowledgeable? Ask a security professional for horror stories and you might think again. - +
12 ways to visualize network security 15/07/2008 10:26:48
Is enterprise security like a stack of Swiss cheese? Or is it more like a Dirty Harry movie?Remember the old M&M analogy - security is like an M&M candy, hard shell on the outside, soft on the inside. In other words, put up firewalls, built a strong perimeter and you're good to go. Of course, nobody believes that M&M-type security is sufficient in today's world of insider threats, data leakage, mobile workers, thumb drives and sophisticated malware. So, what's the new metaphor? We asked around and came up with a number of interesting and useful ways to think about enterprise security. - +
Citibank debit card fraud highlights ATM vulnerabilities 08/07/2008 08:17:53
'Back-end servers are kind of a joke,' and the trouble doesn't end thereMalicious ATM intrusions, such as the late-winter breach that resulted in the compromise of Citibank debit card data, are not at all surprising given the vulnerable state of many of the servers and other components involved in processing such transactions, according to some industry representatives. - +
Four signs your security program's gone too far 25/06/2008 10:34:19
Our columnist suggests when it might be time to dial back a bitWhen risk is present it calls for treatment, and security is a never-ending process... right? Yes, but as a security professional, it's easy to become focused on the hard problems (download PDF) of security -- falling into the arms race for more, more, more security controls -- and lose sight of the impact of the controls themselves. - +
Six burning questions about network security 06/06/2008 09:56:44
Security issues often seem to smolder more than burn, but these six are certainly capable of lighting a fire under IT professionals at a moment's notice.Security issues often seem to smolder more than burn, but these six are certainly capable of lighting a fire under IT professionals at a moment's notice. Handle with care. - +
Five effective ways to burglar-proof your laptop 05/06/2008 07:55:35
Five easy - yet effective - strategies to protect your laptop and the valuable data stored in itTheft of laptops and other mobile devices is spiraling, and the consequences -- financial and other -- are getting increasingly dire.
Case Studies
- +
Employment firm trains staff in compliance with network management kit 05/03/2008 12:03:13
Console keeps 350 Windows machines in checkEmployment and training firm CVGT has installed a network management toolkit to enforce compliance and protect the financial and personal data of its 40,000-plus apprentices and trainees.
Opinions
- +
Strange account management at Amazon 09/10/2008 09:51:00
A careless login led to the discovery of some strange ccount management practices at one of the Internet's largest retailers.Via the RISKS mailing list comes an interesting tale of poor online account management at a major online retailer. According to Graham Bennett, accounts with Amazon display an odd behaviour that doesn't seem to have attracted much attention in the past. - +
Five lessons learned about computer security 16/07/2008 11:15:22
How a hacker turned an illegal hobby into a useful career.Reformed hacker-turned-security-consultant Kevin Mitnick served five years in federal prison for breaking into phone and software company networks. He talks about his past hacking exploits, computer security, and how he turned an illegal hobby into a useful career. - +
Hack a million systems - earn a job 16/07/2008 16:12:54
The idea of employing an admitted botnet creator and carding software author might not be palatable for many, but not so for an 18-year old New Zealander.It has been a number of years since the fantasy that hackers will be offered a job by those who they hacked was even a potential reality, but there are reports that this might still be the case in New Zealand. - +
When university research is responsible for that network probe 10/07/2008 10:08:45
ISC handlers recently noted odd network traffic on an unexpected port across many systems. It turned out that the traffic was the result of a Texas A&M research project.The Internet Storm Center, operated by SANS, is one of the leading sources when it comes to identifying emerging attacks against networks, through their DShield collaborative network analysis effort. Traffic spikes on network ports that are well above the normal rates of traffic flow can signify a rapidly spreading exploit or it could be a misconfigured network spewing rubbish across the rest of the Internet. One of the ISC's handlers noted a significant spike of traffic on port 7 recently and was surprised by what he found. - +
Hacking tools: A new version of BackTrack helps ethical hackers 30/06/2008 10:57:21
BackTrack is the quickest way to get access to hundreds of (legal) hacking toolsVersion 3.0 of BackTrack has been released. BackTrack is a Linux-based distribution dedicated to penetration testing or hacking (depending on how you look at it). It contains more than 300 of the world's most popular open source or freely distributable hacking tools. - +
Online poker cheating demonstrates insider risk 18/06/2008 15:55:02
Poker cheats are using insider knowledge to gain competitive advantage.When determining the risk to a system and the data stored on it, insider threats are generally regarded as lower risk. Despite the complete access (high risk) that insiders generally have, most of the time insiders are trusted agents (very low risk) on the network. When it breaks down, it can break down in a catastrophic manner, especially if there is money at stake. - +
A resurgent Denial of Service threat emerges 11/06/2008 19:12:24
Something new might be emerging from the underground.A less known part of the recent ARP attack against H D Moore's MetaSploit site was an attempted Denial of Service attack that coincided with the successful ARP attack. - +
Security in a bubble 19/03/2008 11:03:54
Security must be distributed, ubiquitous and pervasivePeople don't notice change when it's gradual. Sometimes, however, small, incremental changes add up in a way that isn't noticed until a change in degree becomes a change in kind. - +
How to limit what contractors can do on the network 17/07/2007 10:15:02
Some ways to implement controls for contractorsQuestion: We have contractors perform a number of critical services, such as managing our IBM blade servers. These staff have to be on the LAN, and they're long-time contractors, so trust levels run pretty high, but I know they shouldn't be able to go everywhere on the LAN. How can I limit their access while still letting them do their jobs, and most important, not making them feel like I don't trust them?
Reviews
- +
Check Point and Sygate corral end points 28/12/2005 07:00:13
Firewalls combine strong client security and flexible policy managementAt their core, Check Point Integrity and Sygate Enterprise Protection are effectively policy-based firewalls. That's the cake. The icing is their capability to monitor other applications for compliance with configuration requirements and send errant machines to quarantine until they can be updated with the latest anti-virus definitions, Windows patches, or other necessities.
Additional Resources
CSO Online Member Login
EXCOM scores back-to-back award trifecta 2008-12-01 10:46:00+11
“Just Graphics” isn’t enough any more 2008-11-28 15:02:00+11
Why Sealy’s management sleep soundly at nights... 2008-11-28 11:18:00+11
Capture and Digitize Your Treasure Moments ~ Compro VideoMate C200 USB A/V Capture Stick 2008-11-26 12:37:00+11
Net 24 slashes backup window by two-thirds 2008-11-26 10:28:00+11
Sponsored Links
PC World
Buying Guides
Latest Products
Good Gear Guide
Buying Guides
Computerworld
ARN


