Saturday | 4 July, 2009
CSO

Access Control

News
  • +

    Poll: Companies still worried about open-source security 09/06/2009 09:37:00

    But security concerns about SaaS are diminishing, according to a new Forrester study
    Businesses in North America and Europe remain broadly worried about the security of open-source software, according to new data from Forrester Research.
  • +

    As hacking hits home, China strengthens cyber laws 12/05/2009 12:12:00

    Cybercrime maximum sentences jump from three years to seven
    A year ago, when a Time Magazine reporter told Tan Dailin that he'd been identified as someone who may have hacked the Pentagon, he gasped and asked, "Will the FBI send special agents out to arrest me?"
  • +

    Panel calls for national dialog on gov't cyberattacks 01/05/2009 09:43:00

    The U.S. government lacks a comprehensive policy about cyberattacks, a group says
    The U.S. needs to engage in a national dialog about its government's use of cyberattacks against other nations, and the government lacks a comprehensive policy about how and when it will engage in cyberwarfare, a new study says.
  • +

    Business-critical e-mail needs improved integrity 27/04/2009 09:43:00

    Industry needs to address issue of legitimate business communications being blocked.
    The need for greater e-mail integrity has never been more important as e-mail has become the primary mode of communication for most connected businesses with, according to research firm IDC, an estimated 850 million commercial mailboxes worldwide.
  • +

    Conficker hype a 'problem,' says FBI cyber-chief 27/04/2009 09:41:00

    People may have a false sense of security following April 1 non-meltdown.
    Mainstream media hype leading up to the Conficker worm's April 1 software update may have distracted people from legitimate cyber threats, the U.S. Federal Bureau of Investigation's head of cyber security said Thursday.
  • +

    ForeScout doubles NAC management reach 15/04/2009 13:18:00

    Software simplifies control over guests accessing business networks
    A software upgrade for ForeScout's CounterACT NAC platform will enable it to manage 400,000 endpoints, double the number of previous software releases.
  • +

    Study: Most Organizations Hit by Cybercrime 26/03/2009 09:37:00

    A new Symantec survey finds 98 percent have dealt with the pain and loss of a recent cyber attack.
    A new Symantec survey finds 98 percent have dealt with the pain and loss of a recent cyber attack.
  • +

    Visa pilots new payment card security initiatives 23/03/2009 07:47:00

    In addition to OfficeMax and Fifth Third Bank pilots, Visa plans new alerting for consumers.
    Acknowledging the need for controls that go beyond those offered by the Payment Card Industry (PCI) Data Security Standard, a senior Visa executive Thursday described two new initiatives to reduce payment card fraud being tested by the company.
  • +

    Visa: Post-breach criticism of PCI standard misplaced 20/03/2009 07:37:00

    Chief risk officer: No breached companies have been compliant with the data security rules
    Visa's top risk management executive Thursday dismissed what she described as "recent rumblings" about the possible demise of the PCI data security rules as "premature" and "dangerous" to long-term efforts to ensure that credit and debit card data is secure.
  • +

    McAfee funds e-crime training in Europe, US 11/03/2009 10:09:00

    Security vendor McAfee will give grants to a European and a U.S. organization to better train law enforcement and legal officials in dealing with cybercrime.
    Security vendor McAfee will give grants to a European and a U.S. organization to better train law enforcement and legal officials to deal with cybercrime.
  • +

    Telegraph website hack exposes 700,000 subscriber details 11/03/2009 10:17:00

    UK newspaper The Telegraph compromised by Romanian hacking group.
    National UK daily newspaper The Telegraph was compromised by Romanian hacking group, Hackersblog late last week.
  • +

    IT pro gets four years for building botnets 09/03/2009 09:31:00

    A former Los Angeles IT professional has been sentenced to four years in prison for building a botnet army.
    An employee of search engine startup Mahalo has been sentenced to four years in prison for infecting as many as 250,000 computers with malicious botnet computer code.
  • +

    Insider theft at New York Police Dept. impacts 80,000 cops 06/03/2009 08:04:00

    Former pension fund executive is accused of stealing computer tapes.
    The New York Police Department (NYPD) is telling thousands of police officers that their personal information may be compromised due to a suspected data theft done by an insider in the police pension fund, according to reports in New York's daily newspapers Thursday.
  • +

    Visa: New payment-processor data breach not so new after all 02/03/2009 08:22:00

    Company says recent breach alerts involved ongoing probe of earlier system intrusion
    Days after Visa seemingly confirmed that a data breach had taken place at a third payment processor, following on the recent breach disclosures by Heartland Payment Systems and RBS WorldPay, the credit card company is now saying that there was no new security incident after all.
  • +

    Study: Hackers still enjoy vandalizing Web sites 27/02/2009 10:30:00

    A study of 57 Web site hacks from last year showed 24 percent were aimed at defacing a site rather than financial gain.
    A study of 57 Web site hacks from last year showed that 24 percent were aimed at defacing a site rather than financial gain.
Features
  • +

    Visa, NeuStar team on mobile payments and financial services 24/06/2009 01:06:00

    Services include bill payments, mobile transaction alerts and mobile money transfers
    Visa and NeuStar have joined forces and formed an alliance that it hopes will help accelerate the adoption of mobile financial services globally, they said on Tuesday.
  • +

    Experts: Gov't needs to spend more on cyber R&D 11/06/2009 06:32:00

    Money is also needed for cybersecurity education programs, a group of experts say
    The U.S. government needs to spend more money on cybersecurity research and development and on education programs in order to fight a rising tide of attacks against government and private groups, cybersecurity experts told U.S. lawmakers.
  • +

    Reading for Security Pros: Schneier Or Sagan? 10/06/2009 09:53:00

    In one of the more famous episodes of the original "Star Trek" series - "The Trouble With Tribbles" - Capt. Kirk confines Chief Engineer Montgomery Scott to his personal quarters for getting into a bar fight.
    In one of the more famous episodes of the original "Star Trek" series - "The Trouble With Tribbles" - Capt. Kirk confines Chief Engineer Montgomery Scott to his personal quarters for getting into a bar fight.
  • +

    Social Engineering: 5 Security Holes at the Office 10/06/2009 23:11:00

    Once a criminal is inside a building, there are limitless possibilities to what that person can access or damage.
    If you think the biggest threat to your sensitive information lies in network security, think again. Once a criminal is inside a building, there are limitless possibilities to what that person can access or damage. Take a look at your building's security. How easy is it to get inside?
  • +

    Social Engineering: The Fine Art of BS, Face to Face 08/06/2009 23:06:00

    A confrontation with a facilities manager demonstrates social engineers' complete comfort dealing with (and manipulating) conflict
    Chris Nickerson is willing to push it about as far as a person can go when it comes to security assessments. The founder of Lares, a security consultancy in Colorado, Nickerson conducts what he calls "Red Team Assessments" for clients. He is paid to try and dupe a client, and the client's employees, to give them a clear picture of the weak spots in their security plan. He then advises them on how to shore up defenses more effectively in the event a real criminal comes knocking.
  • +

    Web 2.0 security: things to know about the social web 06/06/2009 02:28:00

    As more and more companies adopt Web 2.0 functionality, and the use of social networking as a business tool increases, there are definitely risks to be aware of. Websense CTO Dan Hubbard discusses how companies can protect their information from threats and compromise on the social Web.
    Websense CTO Dan Hubbard outlines four ways companies can protect their information from threats and compromise on the social Web.
  • +

    Virtualization security: protecting unique IP 04/06/2009 09:34:00

    Universal Audio, a leading maker of music production and mixing tools, went almost fully virtualized to protect its valuable intellectual property. But it bumped up against the complex security problem of virtual switches. A chance meeting in a parking lot helped provide an answer.
    Moving to a nearly fully-virtualized infrastructure in 2008 made Joel Braverman a lot more confident in both the physical and digital IT infrastructure at his (relatively new) employer Universal Audio. As manager of IT and the guy responsible for security on that infrastructure-one that supports a company whose products are both expensive and almost entirely digital-it also made him extremely nervous, he says.
  • +

    Five Things You Can't See on Your Network 19/03/2009 10:05:00

    How business practices have changed the risky activity on your network
    How business practices have changed the risky activity on your network.
  • +

    Database Crime Scene Prevention 23/02/2009 08:51:00

    Imperva's Amichai Shulman looks at database attack and defense.
    Imperva's Amichai Shulman looks at database attack and defense.
  • +

    Your Identity: 'Costanza Style' 11/02/2009 10:53:00

    When it comes to identity, consider me your own, personal "Inner Jerry."
    Your identity is like George Costanza's wallet. Really. Think about it. Do you remember the classic Seinfeld episode? The one where George wouldn't give up his ever-expanding wallet filled with store credit cards, Irish money, a coupon for an Orlando Exxon gas station and several Sweet and Low packets. This, in spite of the obvious physical pain it caused and the security threat all of that imposed.
  • +

    Three years undercover with the identity thieves 21/01/2009 08:22:00

    Keith Mularski talks about his role as administrator of online fraud site DarkMarket.
    Salesmen and parents know the technique well. It's called the takeaway, and as far as Keith Mularski is concerned, it's the reason he kept his job as administrator of online fraud site DarkMarket.
  • +

    Software-based NAC security useful despite drawbacks 13/11/2008 09:44:00

    NAC price, scalability and reporting are all strong points
    Despite some shortcomings, software-based network access control technology that enforces policies on network endpoints is often the first choice of customers who adopt the technology.
  • +

    Five ways to bulk up your network for telecommuters 23/10/2008 08:41:00

    Tips for adapting your corporate network for people working from home
    Whether they're in branch offices or home offices, workers are increasingly telecommuting instead of working in a traditional centralized office environment.
  • +

    Cyber security threats grow in sophistication, subtlety 16/10/2008 09:26:00

    Researchers say malware, botnets, cyber warfare, threats to VoIP and mobile devices, and the "evolving cyber crime economy" are ever-more sophisticated threats
    The annual report from Georgia Tech Information Security Center identifies five evolving cyber security threats, and the news is not good.
  • +

    Anonymous proxy servers: Necessary or evil? 15/10/2008 08:13:00

    Some security experts believe anonymous proxy servers are only necessary if you're up to no good, while others see them as a legitimate tool for research, pen testing and the like. Who's right?
    If there is truly a gray zone in the struggle between online good and evil, anonymous proxy servers live there.
Case Studies
Opinions
  • +

    Sometimes, Security Theatre Really Works 11/12/2008 11:46:00

    Israeli security researchers Gadi Evron and Imri Goldberg find that security theatre can be about more than window dressing
    Israeli security researchers Gadi Evron and Imri Goldberg find that security theatre can be about more than window dressing.
  • +

    Strange account management at Amazon 09/10/2008 10:51:00

    A careless login led to the discovery of some strange ccount management practices at one of the Internet's largest retailers.
    Via the RISKS mailing list comes an interesting tale of poor online account management at a major online retailer. According to Graham Bennett, accounts with Amazon display an odd behaviour that doesn't seem to have attracted much attention in the past.
  • +

    Five lessons learned about computer security 16/07/2008 11:15:22

    How a hacker turned an illegal hobby into a useful career.
    Reformed hacker-turned-security-consultant Kevin Mitnick served five years in federal prison for breaking into phone and software company networks. He talks about his past hacking exploits, computer security, and how he turned an illegal hobby into a useful career.
  • +

    Hack a million systems - earn a job 16/07/2008 16:12:54

    The idea of employing an admitted botnet creator and carding software author might not be palatable for many, but not so for an 18-year old New Zealander.
    It has been a number of years since the fantasy that hackers will be offered a job by those who they hacked was even a potential reality, but there are reports that this might still be the case in New Zealand.
  • +

    When university research is responsible for that network probe 10/07/2008 10:08:45

    ISC handlers recently noted odd network traffic on an unexpected port across many systems. It turned out that the traffic was the result of a Texas A&M research project.
    The Internet Storm Center, operated by SANS, is one of the leading sources when it comes to identifying emerging attacks against networks, through their DShield collaborative network analysis effort. Traffic spikes on network ports that are well above the normal rates of traffic flow can signify a rapidly spreading exploit or it could be a misconfigured network spewing rubbish across the rest of the Internet. One of the ISC's handlers noted a significant spike of traffic on port 7 recently and was surprised by what he found.
  • +

    Hacking tools: A new version of BackTrack helps ethical hackers 30/06/2008 10:57:21

    BackTrack is the quickest way to get access to hundreds of (legal) hacking tools
    Version 3.0 of BackTrack has been released. BackTrack is a Linux-based distribution dedicated to penetration testing or hacking (depending on how you look at it). It contains more than 300 of the world's most popular open source or freely distributable hacking tools.
  • +

    Online poker cheating demonstrates insider risk 18/06/2008 15:55:02

    Poker cheats are using insider knowledge to gain competitive advantage.
    When determining the risk to a system and the data stored on it, insider threats are generally regarded as lower risk. Despite the complete access (high risk) that insiders generally have, most of the time insiders are trusted agents (very low risk) on the network. When it breaks down, it can break down in a catastrophic manner, especially if there is money at stake.
  • +

    A resurgent Denial of Service threat emerges 11/06/2008 19:12:24

    Something new might be emerging from the underground.
    A less known part of the recent ARP attack against H D Moore's MetaSploit site was an attempted Denial of Service attack that coincided with the successful ARP attack.
  • +

    Security in a bubble 19/03/2008 11:03:54

    Security must be distributed, ubiquitous and pervasive
    People don't notice change when it's gradual. Sometimes, however, small, incremental changes add up in a way that isn't noticed until a change in degree becomes a change in kind.
  • +

    How to limit what contractors can do on the network 17/07/2007 10:15:02

    Some ways to implement controls for contractors
    Question: We have contractors perform a number of critical services, such as managing our IBM blade servers. These staff have to be on the LAN, and they're long-time contractors, so trust levels run pretty high, but I know they shouldn't be able to go everywhere on the LAN. How can I limit their access while still letting them do their jobs, and most important, not making them feel like I don't trust them?
Reviews
  • +

    Check Point and Sygate corral end points 28/12/2005 07:00:13

    Firewalls combine strong client security and flexible policy management
    At their core, Check Point Integrity and Sygate Enterprise Protection are effectively policy-based firewalls. That's the cake. The icing is their capability to monitor other applications for compliance with configuration requirements and send errant machines to quarantine until they can be updated with the latest anti-virus definitions, Windows patches, or other necessities.
Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
 
Whitepaper

LANPlanner | Ensuring High Performance WLAN Networks

Learn how the Motorola LANPlanner facilitates prompt and precise planning and the design and measurement of robust 802.11a/b/g/n networks. Download this paper now to discover how to take wireless network performance to the next level.

Sponsored Links