Showing posts with label architecture. Show all posts
Showing posts with label architecture. Show all posts

Monday, June 18, 2012

The Exec-Disconnect on IT Security

Different Chiefs give Different Security Stories.

A recent survey shows that there is a wide gap between CEOs and Chief Security Officers when it comes to the origin and seriousness of security threats.  They differ on how they view threats to IT Infrastructure  and remain far apart on how to best address an issue that according to analyst reports, costs organizations more than $30 billion annually.  The survey of 100 CEOs and 100 CISO (or other C-levels with security responsibility), shows that the discrepancy is often due to lack of communication.  36% of CEOs said that they never get a security report from their CISO and only 27% receive updates on a regular basis.  Is it the CISO that doesn’t report back or the CEO that is not interested?  Let’s look at some more data.

The CISO felt that the biggest threat was from internal (their employees) due to lack of education and attention while the CEO felt that the biggest threat was from the outside, such as phishing attacks.   Thus, 61% of CEOs said they did have enough time and resources to adequately train the staff on how to mitigate threats while Only 27% of CISOs felt the same.  It’s opposite day.  When asked if their IT systems were ‘definitely’ or ‘probably’ under attack without their knowledge, 58% of CISOs said yes while only 26% of CEOs agreeing.  The chasm grows.  What percentage of each, do you think, said they were very concerned about their IT systems getting hacked?  30 seconds on the clock, please.  Don’t peek.  Only 15% of CEOs and ‘only’ 62% of CISOs are anxious about breaches.  15%?  That’s it?  Maybe they have great confidence in their security team…or, they don’t have the information.  65% of CEOs admitted to not having the sufficient data needed to interpret how security threats translate to overall business risk.  Wow, the very day-to-day operations.  Granted, the CEO is further removed from the specific threats and how they are handled but there is clearly a distance between how each views threats and the company’s ability to successfully mitigate them.

Lack of interest or lack of understanding/information?  Probably both.  An old adage was that a great boss hired people who were good at the things he/she wasn’t so good at.  Surround yourself with those who know their areas better.  Or maybe there is a culture that you don’t alert the top unless it’s dire, critical or unstoppable.   Communication or interest, it is evident that the C-suite isn’t really talking about these critical business issues especially when 3 times as many CEOs worried about losing their jobs following an attack than did CISOs.

ps

References

Technorati Tags: F5, security research, botnet, threat landscape, Pete Silva, security, business, technology, cloud,compliance,regulations, web,internet

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, December 20, 2011

Blog Roll 2011

It’s that time of year when we gift and re-gift.  And the perfect opportunity to re-post, re-purpose and re-use my 2011 blog entries.  If you missed any of the approximately 50 blogs, 11 audio whitepapers or 47 videos, here they are wrapped in one simple entry.  I read somewhere that lists in blogs are good. 

Have a Safe and Happy New Year.

And a couple special holiday themed entries from years past.

ps

Technorati Tags: blog, social media, 2011, f5, statistics, big-ip, web traffic, digital media, mobile device, analytics, video

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Monday, November 28, 2011

Cloud Copyright, Capital and The Courts

In 2006, Cablevision was developing a service which allowed customers to record, pause and replay their television content on/from servers located at Cablevision’s data center rather than on the customer’s Digital Video Recorder itself – in the cloud rather than on a local hard drive.  A consortium of U.S. television and copyright holders challenged Cablevision in court arguing that Cablevision’s Remote Storage Digital Video Recorder (RS-DVR) infringed on copyrighted content laws in that, they were making copies of protected works and infringing on exclusive right of reproduction; briefly buffering/storing that content also infringes on exclusive reproduction rights; and by transmitting the data back to the customer, they were infringing on exclusive rights to public performance.  In 2007, a district court found in favor of the copyright owner but in 2008, the decision was reversed by the Second Court of Appeals.  The court clarified that Cablevision was not directly infringing copyright by offering a remote DVR service outside the customer’s home.  Viewers could now record and save authorized TV content on a device within Cablevision’s infrastructure.

This ruling, according to Josh Lerner, Harvard Business School’s Professor of Investment Banking, had a huge impact on U.S. venture capital moving to cloud computing.  A risk was removed.  In Europe, where the ruling had no authority, the venture investments in the cloud were much less.  This is an important economic topic and ruling due to the relationship between venture, innovation and job growth.  The ruling might also be relevant in Australia where Optus is facing the same legal challenge today.  They started a service in July called Optus TV Now that does essentially the same thing as Cablevision’s.  Allowing customers to record and watch the 15 free-to-air stations that are available.  Customers can watch the content directly or over their smartphone or computer via the internet.  In their July announcement they even included, ‘it is a breach of copyright to make a copy of a broadcast other than to record it for your private and domestic use. Optus accepts no responsibility for copyright infringement.’  Well, the owners of the copyright material being stored and retrieved are saying breach, especially the AFL and NRL, the football and rugby leagues.  Optus is saying it’s no different than people recording on a personal DVR at home.  It’ll be interesting to follow this.

Back to the ‘funding the cloud’ story.  Lerner’s study, 'The Impact of Copyright Policy Changes on Venture Capital Investment in Cloud Computing Companies,' he examines the impact and effect of the US Second Circuit Court of Appeals decision.  The authors found that the decision led to additional incremental investment in U.S. cloud computing companies compared to Europe.  Figure 1 of their paper:
vc emea cloud

The same growth did not occur in Europe and in some cases, these types of services have been blocked from even getting to market.  Imagine how much different services from Amazon, Apple and Google would be if the court did not reverse the 2007 ruling.  

ps

Related:
Technorati Tags: F5, costs, integration, cloud computing, Pete Silva, security, business, venture capital, technology, application delivery, cloud, emea, infrastructure 2.0, web, internet

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, September 14, 2011

Hackers Hit Vacation Spots

Just when you were having all that fun running around the waterpark and playing those arcade games comes news that the card processing system of Vacationland Vendors Inc., a Wisconsin Dells firm that supplies arcade games and installs vending machines, was breached.  From the notice on their website, they say, ‘Vacationland Vendors recently discovered that an unauthorized person wrongfully accessed certain parts of the point of sales systems that Vacationland Vendors uses to process credit and debit transactions at the Wilderness Resorts.’  Up to 40,000 debit or credit cards that were used in the arcades any time between December 2008 to May 2011 at the Wilderness Waterpark Resort near Wisconsin Dells and a companion resort in Tennessee are potentially compromised.  The hackers, according to Vacationland Vendors, improperly acquired credit card and debit information and around 20 accounts have shown irregular activity.  Reservation and restaurant transactions were not involved in the breach, only the point-of-sale devices.  Malware was the apparent culprit.

Point-of-sale devices and the networks they are connected to are often the target of malicious hackers.  These ‘kiosks’ are typically unattended and might be in locations where observation is limited.  A couple years ago, Target’s breach was the result of hackers gaining access via the customer service kiosks and the huge hit at Heartland Payment Systems, resulting in tens of millions of exposed credit and debit cards was from a breach of the company's point-of-sale network.  After successful installation of malicious software, thieves are able to sniff and intercept payment card data as the information is transmitted within the internal network or to the bank for authorization.  It might not even be encrypted as it travels.  If it was, then the crooks wouldn’t have the info.  Many people may think these kiosk point-of-sale devices are safe since it is taking credit card data and merchants need to be PCI compliant.  While the overall deadline for PCI 1.2 compliance was a couple years ago (and PCI 2.0 at the end of this year), the deadline for unattended point-of-sale devices was July 2010, a little over a year ago.  That’s why you’ve seen a whole slew of new gas station pumps at your favorite fueling stations and just like regular compliance, it’s going to take time to update all the point-of-sale devices.  Now, I’m not insinuating that the arcade devices were not PCI compliant since nothing has been reported about that, but what I am saying is be careful with those since you may not know if it is or not.  If it looks a few years old, then most likely, it is not.

With this and other similar point-of-sale breaches, many security experts (and even the Heartland CEO) believe end-to-end encryption is necessary, even if transmitting on the internal network, from the time the card is swiped all the way until the data reaches the the processor or bank.   Many credit card swipe terminal vendors are building encryption into the hardware itself and F5 can help keep that information encrypted while it’s travelling the great unknown.  Our BIG-IP APM and BIG-IP Edge Gateway (voted Best Secure Remote Access Product by TechTarget Readers) can easily encrypt any traffic, internal or external.  Heck, even a couple BIG-IP LTM running our latest v11 code can initiate a secure tunnel between them, creating an instant, secure WAN connection.

With the advent of credit card swiping capabilities on mobile phones now in full force, I’m not sure if this is going to get better or worse.  The terminal might be fine but if you install a hacked mobile payment app, then you can skim credit card info like the pros.  Remember, humans will often trade privacy for convenience.

ps

Related blogs & articles:

Technorati Tags: F5, PCI DSS, virtualization, cloud computing, Pete Silva, security, cloud, credit card, compliance, web, internet, cybercrime, holiday shopping, identity theft,

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, August 23, 2011

SANS 20 Critical Security Controls

A couple days ago, The SANS Institute announced the release of a major update (Version 3.0) to the 20 Critical Controls, a prioritized baseline of information security measures designed to provide continuous monitoring to better protect government and commercial computers and networks from cyber attacks.  The information security threat landscape is always changing, especially this year with the well publicized breaches.  The particular controls have been tested and provide an effective solution to defending against cyber-attacks.  The focus is critical technical areas than can help an organization prioritize efforts to protect against the most common and dangerous attacks.  Automating security controls is another key area, to help gauge and improve the security posture of an organization.

The update takes into account the information gleaned from law enforcement agencies, forensics experts and penetration testers who have analyzed the various methods of attack.  SANS outlines the controls that would have prevented those attacks from being successful.  Version 3.0 was developed to take the control framework to the next level.  They have realigned the 20 controls and the associated sub-controls based on the current technology and threat environment, including the new threat vectors.  Sub-controls have been added to assist with rapid detection and prevention of attacks.  The 20 Controls have been aligned to the NSA’s Associated Manageable Network Plan Revision 2.0 Milestones.  They have added definitions, guidelines and proposed scoring criteria to evaluate tools for their ability to satisfy the requirements of each of the 20 Controls.  Lastly, they have mapped the findings of the Australian Government Department of Defence, which produced the Top 35 Key Mitigation Strategies, to the 20 Controls, providing measures to help reduce the impact of attacks.

The 20 Critical Security Controls are:

  1. Inventory of Authorized and Unauthorized Devices
  2. Inventory of Authorized and Unauthorized Software
  3. Secure Configurations for Hardware and Software on Laptops, Workstations, and Servers
  4. Secure Configurations for Network Devices such as Firewalls, Routers, and Switches
  5. Boundary Defense
  6. Maintenance, Monitoring, and Analysis of Security Audit Logs
  7. Application Software Security
  8. Controlled Use of Administrative Privileges
  9. Controlled Access Based on the Need to Know
  10. Continuous Vulnerability Assessment and Remediation
  11. Account Monitoring and Control
  12. Malware Defenses
  13. Limitation and Control of Network Ports, Protocols, and Services
  14. Wireless Device Control
  15. Data Loss Prevention
  16. Secure Network Engineering
  17. Penetration Tests and Red Team Exercises
  18. Incident Response Capability
  19. Data Recovery Capability
  20. Security Skills Assessment and Appropriate Training to Fill Gaps

And of course, F5 has solutions that can help with most, if not all, the 20 Critical Controls.

ps

Resources:

Technorati Tags: F5, SANS, integration, cloud computing, Pete Silva, security, business, education, technology, application delivery, cloud, context-aware, infrastructure 2.0, web, internet

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, July 19, 2011

The Best of…Me

imagePart shameless self promotion while taking a cue from Morning Radio shows, I’m out of the office this week and decided to post some of my most popular blogs – according to you, the viewer.  Or as Kent Brockman puts it, ‘this reporter places the blame for all of this squarely on YOU, the viewers!’

CloudFucius Shares: Cloud Research and Stats: Sharing is caring, according to some and with the shortened week, CloudFucius decided to share some resources he’s come across during his Cloud exploration in this abbreviated post.  A few are aged just to give a perspective of what was predicted and written about over time.

The New Certificate 2048 My Performance: Transactions handled over SSL can require substantial computational power to establish the connection (handshake) and then to encrypt and decrypt the transferred data.  If you need the same performance as non-secured data, then additional computing power (CPU) is needed.  SSL processing can be up to 5 times more computationally expensive than clear text to have the same level of performance, no matter which vendor is providing the hardwareSSL Offload takes much of that computing burden off the servers and places it on dedicated SSL hardware. SSL offloading can relieve the Web server of the processing burden of encrypting and/or decrypting traffic sent via SSL.

F5’s BIG-IP system with Oracle Access Manager: F5 and Oracle announced plans to unify access management for web applications.  Press release can be found here.  The solution combines F5’s BIG-IP system with Oracle Access Manager to enhance single sign-on (SSO) capabilities and simplify access control.  Unifying application delivery and web access management. 

26 Short Topics about Security: Stats, Stories and Suggestions: The crew at DevCentral has a great series called A to Z, and I decided to build upon (or steal, however you see it) the idea with ‘26 Short Topics about Security.’  Not too technically heavy or all encompassing but definitely areas of concern for IT. 

F5's BIG-IP with Oracle® Access Manager to enhance SSO and Access Control: Learn how F5's BIG-IP LTM/APM helps in conjunction with Oracle Access Manager centralizing web application authentication and authorization services, streamline access management, and reduce infrastructure costs Watch how BIG-IP APM can reduce TCO, lower deployment risk, and streamline operational efficiencies for customers along with having a unified point of enforcement to simplify auditing and control changes in configuring application access settings.

Bit.ly, Twitter, Security & You: I’ve been using bit.ly for a little while both to shorten links and be able to track clicks placed on twitter (and other social sites) – as many of you do.  When the twitter outage hit last week, and many folks found themselves ‘lost’ without it, I decided to review my stats on the bit.ly links I’ve sent and found something interesting; or frightening.

The Threat Behind the Firewall: I had a different name for this blog entry but just ‘Jump Drive’ is an awful blog title.  They go by many names; jump drive, USB drive, flash drive, memory stick and a few others, but removable media is a serious threat to IT organizations.  From consultants, to government employees, to Mortgage lenders, to the International Space Station, what used to be a giveaway staple at trade shows, these tiny less-than-two-inch drives can hit and hurt you in a multitude of ways.

Cybercrime, the Easy Way: The Dummies series is a great collection of ‘How to’ instructions on a wide array of topics and while they have not published a ‘Cybercrime for Dummies®’ booklet (and don’t think they will), DYI Cybercrime Kits are helping drive Internet attacks.  Gone are the days when you had to visit a dark alley to get a crook’s cookbook.  You can get a Cybercrime toolkit to go with your black ski mask, getaway car and evil lair hideout.

How Terms Have Changed over Time: Meanings and terms often change or get adjusted over time, especially with Information Technology.  While never walking 5 miles to school in two-feet of snow, I did live during an era of TV’s without remotes and vinyl record players. 

Have a great week!

ps

Technorati Tags: F5, data breach report, threats, Pete Silva, security, malware, technology, phishing, cyber-threat, social engineering, attacks, virus, vulnerability, web, internet, cybercrime, identity theft, scam, data breach

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]