ps
Resources:
| Connect with Peter: | Connect with F5: |
| |
Peter Silva covers security for F5’s Technical Marketing Team. Bringing the slightly theatrical and fairly technical together, he covers training, writing, speaking, along with overall product direction and evangelism for F5’s security line.
| Connect with Peter: | Connect with F5: |
| |
It’s not named dough, melted cheese, mushrooms and pepperoni balancing. Its called Pizza Delivery. The user makes a request either over the phone or on-line with all the context of the ingredients and specifics of the request. The Pizza Parlor then confirms the delivery location, gets to work and tries to deliver it to the destination as fast as they can. The request arrives, both parties validate the order sometimes with a two-person handshake and the user consumes the content that was delivered. Somewhat similar but much faster is what happens when a user makes a request from a web application. They type in the location they want to go to, the ADC considers such contextual information like user, IP address, browser type, location and other variables to then deliver the specific content that is being requested – as fast as possible. It’s not about load balancing an application, it’s about Application Delivery.
If you’ve lost your balance, then your equilibrium might be off and that is not a good thing. You might have blurred vision, trouble hearing, dizziness and headaches and your decision making process could be off kilter. You are slow to react, misunderstand requests, and give someone something they didn’t ask for or something different than what they asked for. You are unable to take requests, process the information load and deliver an answer.
Load balancing an application is no longer sufficient to ensure that the right users are receiving the right information at the right time, quickly, efficiently and securely. Load balancing almost seems like an afterthought, or late in the process of delivering an application. You need to take into context the various variables of the user request and deliver that application based on the contextual information. We use contextual information all the time to make our little daily decisions. Which jacket to wear? Well, what’s the temperature; is it raining; what am I doing; what’s the forecast; does it have pockets; does it have a hood; is it zipper or pull over and so forth. Of course all this happens in an instant and we select what is needed. You can’t make application delivery decisions simply based on ‘next in line,’ those judgments need to consider all the available information to make an informed application delivery decision.
ps
Resources:
Technorati Tags: F5,F5 News,Interop,NOC,IPv6,BIG-IP,application delivery,network,Pete Silva, event, #50waystousebigip,50 Ways,availability,BIG-IP
| Connect with Peter: | Connect with F5: |
| |
Just kidding…partially. Have you seen the latest 2011 Verizon Data Breach Investigations Report? It is chock full of data about breaches, vulnerabilities, industry demographics, threats and all the other internet security terms that make the headlines. It is an interesting view into cybercrime and like last year, there is also information and analysis from the US Secret Service, who arrested more than 1200 cybercrime suspects in 2010. One very interesting note from the Executive Summary is that while the total number of records compromised has steadily gone down – ‘08: 361 million, ‘09: 144 million, ‘10: 4 million – the case loads for cybercrime is at an all time high – 141 breaches in 2009 to a whopping 760 in 2010. One reason may be is that the criminals themselves are doing the time-honored ‘risk vs. reward’ scenario when determining their bounty. Hey, just like the security pros! Oh yeah….the crooks are pros too. Rather than going after the huge financial institutions in one fell swoop or mega-breach, they are attempting many more low risk type intrusions against restaurants, hotels and smaller retailers. Hospitality is back on the top of the list this year, followed by retail. Financial services round out pole position, but as noted, the criminals will always have their eye on our money. Riff-raff also focused more on grabbing intellectual property rather than credit card numbers.
The Highlights:
You may ask, ‘what about mobile devices?’ since those are a often touted avenue of data loss. The Data Breach Report says that data loss from mobile devices are rarely part of their case load since they typically investigate deliberate breaches and compromises rather than accidental data loss. Plus, they focus on confirmed incidents of data compromise. Another question might have to do with Cloud Computing breaches. Here they answer, ‘No, not really,’ to question of whether the cloud factors into the breaches they investigate. They say that it is more about giving up control of the systems and the associated risk than any cloud technology.
Now comes word that subscribers of Sony’s PlayStation Network have had their personal information stolen. I wonder how this, and the other high profile attacks this year will alter the Data Breach Report next year. I’ve written about this type of exposure and felt it was only a matter of time before something like this occurred. Gamers are frantic about this latest intrusion but if you are connected to the internet in any way shape or form, there are risks involved. We used to joke years ago that the only way to be safe from attacks was to unplug the computers from the net. With the way things are going, the punch line is not so funny anymore.
ps
Resources:
Technorati Tags: F5, data breach report, threats, Pete Silva, security, malware, technology, Verizon, cyber-threat, social engineering, attacks, virus, vulnerability, web, internet, cybercrime, identity theft, scam, data breach, psn, Sony, PlayStation
| Connect with Peter: | Connect with F5: |
| |
A little over two years ago I blogged Do you Splunk? about the reporting integration with our FirePass SSL VPN and BIG-IP ASM. The Splunk reports have provided customers valuable insight into application access and user behavior along with deep analysis of application violations, web attacks and other key metrics. Recently, Splunk and F5 have been working behind the scenes and now you can also get 22 different templates for detailed reporting on the BIG-IP Access Policy Manager. BIG-IP APM is a flexible, high-performance access and security solution that runs as a module on BIG-IP LTM.
Splunk is the data engine for IT. It collects, indexes and harnesses the fast-moving IT data generated by all of your IT systems and infrastructure - whether physical, virtual or in the cloud and correlates various pieces of data sources to provide new views and new insights. Splunk makes it possible to search and navigate data from any application, server or network device from a web browser, in real time. Logs, configurations, messages, traps, alerts, and scripts: if a machine generates it, Splunk will index it. The Splunk for F5 App provides real-time dashboards for monitoring key performance metrics. Reports from Splunk support long-term trending and can be downloaded in PDF or Excel formats or scheduled for email delivery. The F5 App supports core Splunk functionality such as deep drill-down from graphical elements, robust role-based access controls and Splunk’s award-winning search capabilities.
The following are a sample of the reports available in this version of Splunk for F5 using ASM, APM and FirePass data:
Splunk also has the unique ability to augment data from FirePass and ASM by connecting to and gathering data from Active Directory or LDAP and asset management databases that can highlight asset or application owner information.
Businesses are faced with competing challenges when it comes to granting their mobile workforce access to company data. The data must be readily accessible to users on the go but at the same time companies must protect and safeguard their internal systems that contain sensitive information. Robust monitoring controls are a must for maintaining auditing access, enabling dynamic application access and preventing data loss and availability issues.
Resources:
Technorati Tags: Pete Silva,F5,security,application security,network security, business, splunk, education, reports, technology, metrics, compliance, data analysis, partners
| Connect with Peter: | Connect with F5: |
| |
People Make The Difference.
One thing I’ve noticed with a few of the recent high profile attacks and breaches is that the human element played a significant role. The technology used to stop, thwart, defend and otherwise render these attacks useless can be the best in the world but if people make mistakes, then that can be the chink in the armor. While many companies focus on deploying infrastructure services to block malicious activity, there still needs to be continuing education for the fallible humans that we are. We often talk about how the attacks are evolving, network to application and everything in between, along with how technology needs to adapt to the changing threat landscape. So if the attacks are getting better, more sophisticated and ever changing, then people need to be aware that behaviors need to adjust also.
RSA has said that their breach was due to a spear phishing attack. The thieves sent emails to various RSA employees with the subject: 2011 Recruitment Plan. While the email itself went directly in the spam/junk folder, it was intriguing enough for one person to move it out of junk and open the infected excel attachment. From there, a remote access tool called ‘Poison Ivy’ went to work, looking for various employee credentials. They finally found their target, stole the data and sent it to another infected machine for transmission. Luckily for RSA, they noticed this anomaly and stopped the attack. It probably could have been much worse.
With HBGary, we’ve learned that many human factors played a role in this situation – social engineering, weak passwords and poorly written code. Technology really can’t defend against easy to crack passwords or people giving up information. These were not highly sophisticated attacks but basic errors that people made along the way. It should remind us to look at our own passwords and maybe make a few changes. It should remind us that if an authoritative-sounding someone contacts you asking for sensitive information, to be very cautious. There is nothing wrong with saying, ‘I don’t feel comfortable sharing that,’ or even ‘I’m not sure; I don’t know,’ especially if you have not verified who that person is. Personally, I’d rather make an IT admin’s job a little harder than make a malicious hacker’s job easier.
To be fair, I’m not picking on those companies or the people involved, I’m sure they wish they could go back and do things differently. It should, however, be a lesson to us all that good security involves both technology and people and that a good security policy also includes education. Sometimes technology can save us from ourselves but if you don’t lock your front door, you can’t expect your house to be safe.
ps
Resources:
Technorati Tags: F5, passwords, threats, Pete Silva, security, malware, technology, people, cyber-threat, social engineering, attacks, virus, vulnerability, web, internet, cybercrime, identity theft, scam, data breach
| Connect with Peter: | Connect with F5: |
| |
Almost half the total population of this planet. At this rate, we’ll all have our own personalized malware in the coming years, specifically tailored for our various behaviors. I built this infection especially for you. Symantec recently released their annual Internet Security Threat Report for 2010 and noted that the cyber threats are increasing both in sophistication and frequency. They found more than 286 million new threats last year with social networks and mobile devices being a favorite targets. Mobile vulnerabilities were up 42% with 163 discovered last year. The U.S. actually topped the list in many nasty categories: Most targeted country by DoS attacks (65% of total), most bot command and control servers (37% of total), most infected computers (14% of total) and most overall malicious activity (19% of total).
As you may know, I like numbers and statistics and there were a couple supplemental reports that I found interesting. The Year in Numbers and The 2010 Timeline. Each is a single page report with highlights from the year. The highlights, or lowlights depending on your view are:
Lastly, if you are looking for porn, then more than likely you’ll find malware and the leading culprit of a breach which could lead to identity theft was a lost/stolen computer or data storage device. One of the cool things about the data offered is the ability to build your own custom report. You can select various topics or trends to customize the report specifically to your area of interest.
ps
Resources
Technorati Tags: F5, mobile, threats, Pete Silva, security, malware, technology, Symantec, cyber-threat, cloud, attacks, virus, vulnerability, web, internet, cybercrime, identity theft, scam, data breach
| Connect with Peter: | Connect with F5: |
| |
Check out some of the new features in Enterprise Manager v2.2 like Predefined Reports, SSL TPS Utilization, Custom Views, Custom Monitors, Alerts and Reports, EM Virtual Edition, Bulk actions and more.
Enterprise Manager is a centralized management appliance for F5 BIG-IP® devices that gives you a consolidated, real-time view of your entire F5 application delivery infrastructure, plus the tools you need to quickly optimize performance and scale your infrastructure to meet business needs.
ps
Resources:
Technorati Tags: F5, enterprise manager, Pete Silva, security, business, education, technology, video, management, In 5 series, VE, virtual edition, cloud computing, ssl management, infrastructure
| Connect with Peter: | Connect with F5: |
| |