Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Friday, July 23, 2021

What is Mutual TLS (mTLS)?

Mutual Transport Layer Security (#mTLS) establishes an encrypted TLS connection in which both parties use X.509 digital certificates to authenticate and verify each other. MTLS can help mitigate the risk of moving services to the cloud, and prevent malicious third parties from imitating genuine apps. So, let’s start the clock for What is mTLS?

Read the Article on F5 Labs.

Not only does F5 Labs provide freely available Threat Intelligence, they also have an Educational series covering many types of attacks, threats, and essential security concepts. If you are getting started in cyber security or there’s always been that one topic you’ve never quite understood, #F5Labs will help you learn the basics.

Thursday, April 4, 2019

TLS 1.3 Enterprise Adoption

With the new TLS 1.3 specification published by the IETF in August 2018, many organizations are adopting plans for the new specification. F5, together with Enterprise Management Associates, conducted research to better understand how enterprises are impacted by the growing use of encryption.

Get your copy today at: https://interact.f5.com/TLS-13-adoption-in-enterprise.html

 

ps

Tuesday, October 18, 2016

Your SSL Secrets Uncovered

Get Started with SSL Orchestrator

SSL and its brethren TLS is becoming more prevalent to secure IP communications on the internet. It’s not just financial, health care or other sensitive sites, even search engines routinely use the encryption protocol. This can be good or bad. Good, in that all communications are scrambled from prying eyes but potentially hazardous if attackers are hiding malware inside encrypted traffic. If the traffic is encrypted and simply passed through, inspection engines are unable to intercept that traffic for a closer look like they can with clear text communications. The entire ‘defense-in-depth’ strategy with IPS systems and NGFWs lose effectiveness.

F5 BIG-IP can solve these SSL/TSL challenges with an advanced threat protection system that enables organizations to decrypt encrypted traffic within the enterprise boundaries, send to an inspection engine, and gain visibility into outbound encrypted communications to identify and block zero-day exploits. In this case, only the interesting traffic is decrypted for inspection, not all of the wire traffic, thereby conserving processing resources of the inspecting device. You can dynamically chain services based on a context-based policy to efficiently deploy security.

This solution is supported across the existing F5 BIG-IP v12 family of products with F5 SSL Orchestrator and is integrated with such solutions like FireEye NX, Cisco ASA FirePOWER and Symantec DLP.

Here I’ll show you how to complete the initial setup.

A few things to know prior – from a licensing perspective, The F5 SSL visibility solution can be deployed using either the BIG-IP system or the purpose built SSL Orchestrator platform. Both have same SSL intercept capabilities with different licensing requirements.

To deploy using BIG-IP, you’ll need BIG-IP LTM for SSL offload, traffic steering, and load balancing and the SSL forward proxy for outbound SSL visibility. Optionally, you can also consider the URL filtering subscription to enforce corporate web use policies and/or the IP Intelligence subscription for reputation based web blocking. For the purpose built solution, all you’ll need is the F5 Security SSL Orchestrator hardware appliance.

The initial setup addresses URL filtering, SSL bypass, and the F5 iApps template.

URL filtering allows you to select specific URL categories that should bypass SSL decryption. Normally this is done for concerns over user privacy or for categories that contain items (such as software update tools) that may rely on specific SSL certificates to be presented as part of a verification process.

Before configuring URL filtering, we recommend updating the URL database. This must be performed from the BIG-IP system command line. Make sure you can reach download.websense.com on port 80 via the BIG-IP system and from the BIG-IP LTM command line, type the following commands:
modify sys url-db download-schedule urldb download-now false modify sys url-db download-schedule urldb download-now true
To list all the supported URL categories by the BIG-IP system, run the following command:
tmsh list sys url-db url-category | grep url-category

Next, you’ll want to configure data groups for SSL bypass. You can choose to exempt SSL offloading based on various parameters like source IP address, destination IP address, subnet, hostname, protocol, URL category, IP intelligence category, and IP geolocation. This is achieved by configuring the SSL bypass in the iApps template calling the data groups in the TCP service chain classifier rules. A data group is a simple group of related elements, represented as key value pairs. The following example provides configuration steps for creating a URL category data group to bypass HTTPS traffic of financial websites. 


For the BIG-IP system deployment, download the latest release of the iApps template and import to the BIG-IP system.

Extract (unzip) the ssl-intercept-12.1.0-1.5.7.zip template (or any newer version available) and follow the steps to import to the BIG-IP web configuration utility.

From there, you’ll configure your unique inspection engine along with simply following the BIG-IP admin UI with the iApp questionnaire. You’ll need to select and/or fill in different values in the wizard to enable the SSL orchestration functionality. We have deployment guides for the detailed specifics and from there, you’ll be able to send your now unencrypted traffic to your inspection engine for a more secure network.

ps

Resources:




Tuesday, November 3, 2015

Ask the Expert – Why SSL Everywhere?

Kevin Stewart, Security Solution Architect, talks about the paradigm shift in the way we think about IT network services, particularly SSL and encryption. Gone are the days where clear text roams freely on the internal network and organizations are looking to bring SSL all the way to the application, which brings complexity. Kevin explains some of the challenges of encrypting all the way to the application and ways to solve this increasing trend. SSL is not just about protecting data in motion, it’s also about privacy.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, July 16, 2013

20,000 For Every 1

On average. 

Earlier this month, the State of California released its first annual data breach report showing that in 2012, 131 data breaches were reported putting more than 2.5 million Californians personal data at risk.  The real kicker is that of the 2.5 million, 1.4 million would have been fine if the companies had simply encrypted the data.  Yup, over half would've been safe if proper care was taken to protect the data.  A bit aggravating isn't it?  With all the basic solutions available and data breach media attention you'd think encryption was a no brainer.  Add to that, if it was scrambled, it wouldn't have even needed to be reported according to state law!  Companies can even avoid data breach lawsuits (in California) for encrypting data.  So many reasons.

Retail had the most intrusions with 26% followed closely by finance and insurance with 23% of the total.  Health care accounted for 15% with education and government both taking 8%.  The remaining 15% represented the ever popular 'other.'  Over half included included compromised social security numbers and 5 involved more than 100,000 citizens. 

Security and computer failures, including skimmed point-of-sale devices, accounted for the majority of the intrusions with outsiders doing the most damage.  Always check those ATMs, gas station pumps, unattended kiosks and other machines you slide with your cards.  Sadly, even with personal diligence, once the company has it, they seemingly still let it roam free.  I guess the good news is the requirement to report the breaches so individuals are aware and can take action.

This is is the first state-based, state-specific review of reported data breaches and the California Attorney General's Office recommends that companies focus on improving the following areas of privacy and security:

  • Encryption - If you have unencrypted personal information, you'll probably be next.
  • Security Training – Review and update security procedures, as well as provide regular training to maintain compliance.
  • Readability of Consumer Breach Notifications – Companies should ensure that recipients actually understand the content of such notices.
  • Offering Credit Monitoring Assistance – When offered to consumers, it can limit future issues.

Hopefully, in the near future other states will release their own reports to better understand their situations in context to the all the yearly, national reports.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, April 18, 2012

Complying with PCI DSS–Part 2: Protect Cardholder Data

According to the PCI SSC, there are 12 PCI DSS requirements that satisfy a variety of security goals.  Areas of focus include building and maintaining a secure network, protecting stored cardholder data, maintaining a vulnerability management program, implementing strong access control measures, regularly monitoring and testing networks, and maintaining information security policies.  The essential framework of the PCI DSS encompasses assessment, remediation, and reporting.  We’re exploring how F5 can help organizations gain or maintain compliance and today is Protect Cardholder Data which includes PCI Requirements 3 and 4.  To read Part 1, click: Complying with PCI DSS–Part 1: Build and Maintain a Secure Network

Requirement 3: Protect stored cardholder data.
PCI DSS Quick Reference Guide description
: In general, no cardholder data should ever be stored unless it’s necessary to meet the needs of the business.  Sensitive data on the magnetic stripe or chip must never be stored.  If your organization stores PAN, it is crucial to render it unreadable, for instance, [by] obfuscation [or] encryption.

Solution: The spirit of this requirement is encryption-at-rest—protecting stored cardholder data.  While F5 products do not encrypt data at rest, the BIG-IP platform has full control over the data and network path, allowing the devices to secure data both in and out of the application network.  F5 iSession tunnels create a site-to-site secure connection between two BIG-IP devices to accelerate and encrypt data transfer over the WAN.  With BIG-IP APM and BIG-IP Edge Gateway, data can be encrypted between users and applications, providing security for data in transit over the Internet.  BIG-IP APM and BIG-IP Edge Gateway can also provide a secure access path to, and control, restricted storage environments where the encryption keys are held (such as connecting a point-of-sale [POS] device to a secure back-end database to protect data in transit over insecure networks such as WiFi or mobile).   With BIG-IP Application Security Manager (ASM), data such as the primary account number (PAN) can be masked when delivered and displayed outside of the secure ADN.  BIG-IP ASM also can mask such data within its logs and reporting, ensuring that even the administrator will not be able to see it.

Requirement 4: Encrypt transmission of cardholder data across open, public networks.
PCI DSS Quick Reference Guide description
: Cyber criminals may be able to intercept transmissions of cardholder data over open, public networks, so it is important to prevent their ability to view this data.  Encryption is a technology used to render transmitted data unreadable by any unauthorized person.

Solution: The modular BIG-IP system is built on the F5 TMOS full-proxy operating system, which enables bi-directional data flow protection and selective TLS/SSL encryption.  All or selective parts of the data stream can be masked and/or TLS/SSL encrypted on all parts of the delivery network.  The BIG-IP platform supports both SSL termination, decrypting data traffic with the user for clear-text delivery on the ADN, and SSL proxying, decrypting data traffic on BIG-IP devices for content inspection and security before re-encrypting the data back on the wire in both directions.  The BIG-IP platform, along with the F5 iRules scripting language, also supports specific data string encryption via publicly tested and secure algorithms, allowing the enterprise to selectively encrypt individual data values for delivery on the wire or for secure back-end storage.  The BIG-IP® Edge Client software module, offered with BIG-IP APM and BIG-IP Edge Gateway or as a mobile application, can encrypt any and all connections from the client to the BIG-IP device.  Customers have customized and installed BIG-IP Edge Client on ATMs and currency or coin counting kiosks to allow those devices to securely connect to a central server.  In addition, two BIG-IP devices can create an iSession tunnel to create a site-to-site connection to secure and accelerate data transfer over the WAN.

image
iSession tunnels create a site-to-site secure connection to accelerate data transfer over the WAN

Next: Maintain a Vulnerability Management Program

ps

Related:
Technorati Tags: F5, PCI DSS, virtualization, cloud computing, Pete Silva, security, cloud, credit card, compliance, web, internet,cybercrime, holiday shopping, identity theft,
Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, September 14, 2011

Hackers Hit Vacation Spots

Just when you were having all that fun running around the waterpark and playing those arcade games comes news that the card processing system of Vacationland Vendors Inc., a Wisconsin Dells firm that supplies arcade games and installs vending machines, was breached.  From the notice on their website, they say, ‘Vacationland Vendors recently discovered that an unauthorized person wrongfully accessed certain parts of the point of sales systems that Vacationland Vendors uses to process credit and debit transactions at the Wilderness Resorts.’  Up to 40,000 debit or credit cards that were used in the arcades any time between December 2008 to May 2011 at the Wilderness Waterpark Resort near Wisconsin Dells and a companion resort in Tennessee are potentially compromised.  The hackers, according to Vacationland Vendors, improperly acquired credit card and debit information and around 20 accounts have shown irregular activity.  Reservation and restaurant transactions were not involved in the breach, only the point-of-sale devices.  Malware was the apparent culprit.

Point-of-sale devices and the networks they are connected to are often the target of malicious hackers.  These ‘kiosks’ are typically unattended and might be in locations where observation is limited.  A couple years ago, Target’s breach was the result of hackers gaining access via the customer service kiosks and the huge hit at Heartland Payment Systems, resulting in tens of millions of exposed credit and debit cards was from a breach of the company's point-of-sale network.  After successful installation of malicious software, thieves are able to sniff and intercept payment card data as the information is transmitted within the internal network or to the bank for authorization.  It might not even be encrypted as it travels.  If it was, then the crooks wouldn’t have the info.  Many people may think these kiosk point-of-sale devices are safe since it is taking credit card data and merchants need to be PCI compliant.  While the overall deadline for PCI 1.2 compliance was a couple years ago (and PCI 2.0 at the end of this year), the deadline for unattended point-of-sale devices was July 2010, a little over a year ago.  That’s why you’ve seen a whole slew of new gas station pumps at your favorite fueling stations and just like regular compliance, it’s going to take time to update all the point-of-sale devices.  Now, I’m not insinuating that the arcade devices were not PCI compliant since nothing has been reported about that, but what I am saying is be careful with those since you may not know if it is or not.  If it looks a few years old, then most likely, it is not.

With this and other similar point-of-sale breaches, many security experts (and even the Heartland CEO) believe end-to-end encryption is necessary, even if transmitting on the internal network, from the time the card is swiped all the way until the data reaches the the processor or bank.   Many credit card swipe terminal vendors are building encryption into the hardware itself and F5 can help keep that information encrypted while it’s travelling the great unknown.  Our BIG-IP APM and BIG-IP Edge Gateway (voted Best Secure Remote Access Product by TechTarget Readers) can easily encrypt any traffic, internal or external.  Heck, even a couple BIG-IP LTM running our latest v11 code can initiate a secure tunnel between them, creating an instant, secure WAN connection.

With the advent of credit card swiping capabilities on mobile phones now in full force, I’m not sure if this is going to get better or worse.  The terminal might be fine but if you install a hacked mobile payment app, then you can skim credit card info like the pros.  Remember, humans will often trade privacy for convenience.

ps

Related blogs & articles:

Technorati Tags: F5, PCI DSS, virtualization, cloud computing, Pete Silva, security, cloud, credit card, compliance, web, internet, cybercrime, holiday shopping, identity theft,

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, January 20, 2011

Audio White Paper: F5 BIG-IP WAN Optimization Module in Data Replication Environments

Data loads are constantly on the rise: where transmissions once included only plain-text email and a few static web hits, people now send rich text email, dynamic web pages including multiple AJAX requests per page, replication data, and a host of other data types.  Replication data in particular is critical, especially to businesses. Businesses need their replication data to arrive at the appropriate destination, in a timely manner and with no doubt of delivery. The slower and less reliable your replication is, the less useful it is to your original purpose.  Using the F5® BIG‑IP® WAN Optimization Module™ (WOM), enterprises can increase efficiency, decrease backup windows, offload encryption, and improve wide area network throughput to distributed data centers.  Running Time: 22:36  Read full white paper here.  And click here for more F5 Audio.

ps

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1] o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, integration, disaster recovery, Pete Silva, security, business, education, technology, application delivery, data replication, cloud, backup, WAN, web, internet, security, hardware, audio, whitepaper,, big-ip

Posted via email from psilva's prophecies

Wednesday, January 19, 2011

The New Wallet: Is it Dumb to Carry a Smartphone?

When I was a teenager, I used to have one of those cool nylon surfer wallets with the Velcro close, you remember those don’t ya?  While pumping diesel (had a VW Rabbit) one day at an old Gulf station, I left the wallet on top of the car and drove off.  Realizing that my wallet was not snug in the sun visor when I got home, I retraced my path and found it - parts of it - scattered all over Route 1.  Luckily, I got most of my belongings back but had that sickened feeling of almost losing my most precious possession at the time, my fake I……um, my driver’s license.  I then got a leather wallet and shoved so many things in there I could have been mistaken for George Costanza, not to mention the hole that evolved right at the bottom point of my back pocket.  Not liking the bump on my butt, I eventually moved to ‘money-clip’ type holders, you know those money holder things you carry in your front pocket.  I felt ‘safer’ knowing it was in my front pocket and I only carried the essentials that I needed, rather than the reams of receipts I’d have in my wallet.  When I was younger, I’d use tie clips, metal binder clips, and other things until I got a nice Harley-Davidson one which holds credit cards and clips currency.  I’d still feel sick if I lost it however.

Not having a wallet, purse, money clip or other currency container at all, may eventually be our new reality.  You see, our smartphones are starting to carry all that digital information for us and according to a recent CNNMoney article, our smartphones are becoming one of our most dangerous possessions.  We can do banking, make payments, transfer money, use the phone for loyalty card swipes along with credit card transactions.  At the same time, mobile users more vulnerable to phishing attacks, some banking apps for Android, iPhone expose sensitive info, Android Trojan Emerges In U.S. Download Sites and how IPv6: Smartphones compromise users' privacy.  We knew it would eventually happen but the crooks are now adapting to the explosive mobile growth, the rise of mobile banking and our never ending connection to the internet.  Don’t get me wrong, like many of you, I love having email, contacts, calendar and entertainment at my fingertips along with the convenience of having all my stuff with me; but the chances of losing much more greatly increase since you have the equivalent, or even more, of all your credit cards, personal and private information and other sensitive stuff right on your smartphone.  Sure there are backup programs but how many of you actually backup your computer on a weekly basis?  How many have wipe or lock software installed to destroy everything on the smartphone if it is stolen?  How many have tracking software if it is lost?  How many have your actual home address in the GPS navigator so the offender can find where you live and visit while you are away?  How many have sensitive corporate information stored on the smartphone since you use it for both personal and business use?  Now I’m starting to spook myself. 

Many people will willingly trade some personal info for personal convenience.  You might never give a total stranger your home address and phone number but if they add, ‘in exchange, we’ll give you this branded card and you’ll get 10% off every purchase,’ more than likely, we’ll turn that personal info over.  If you understand that every purchase will be scanned, sent to a database and used for marketing or as the merchant describes, to ‘provide you with the best service and offerings,’ then you might accept that.  If you accept and understand the risks of doing mobile banking, transferring money, making payments and carrying around your entire life on your mobile device….and take actions to mitigate those risks, like using encryption, backups, wipe/locate software, antivirus, OS updates and other mobile security precautions along with practicing the same discretion as you would with your home computer (like not clicking links from strangers) then you should stay relatively safe.  Unless, of course, you leave that digital wallet on the top of your vehicle and drive off.

ps

Resources

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, banking, trojan, Pete Silva, security, business, education, technology, application delivery, ipad, cloud, context-aware, mobile, iPhone, web, internet, security, android, privacy, smartphone