Monday, January 10, 2011

Audio Tech Brief - Secure iPhone Access to Corporate Web Applications

The way corporations operate around mobile devices is currently shifting—employees are starting to use their own devices for business purposes, rather than company-owned devices. With no direct control of the endpoints, IT departments have generally had to prohibit this or risk insecure access inside the firewall. But as more mobile devices appear on the corporate network, mobile device management has become a key IT initiative.  This technical brief describes how the BIG-IP Edge Portal app for iOS devices provides simple, streamlined access to web applications that reside behind BIG-IP APM, without requiring full VPN access, to simplify login for users and provide a new layer of control for administrators.  Running Time: 18:54  Read full white paper here.  And click here for more F5 Audio.

ps

Resources:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, ipad, cloud, context-aware, infrastructure 2.0, iPhone, web, internet, security, hardware, audio, whitepaper, apple, itunes

Posted via email from psilva's prophecies

Thursday, January 6, 2011

PCI Turns 2.0

…Or 6 years old in human time.  When PCI DSS was born, it was actually five different procedures from each of the major credit card issuers: Visa, MasterCard, American Express, JCB and Discover.  Each program was comparable in that they wanted merchants to have minimum security requirements when handling (process, transmit, store) cardholder data as a protection mechanism.  The industry came together and formed the PCI Security Standards Council (SSC) which aligned the distinctive policies and then released the Payment Card Industry Data Security Standard (PCI DSS) v1.0.  Over the years there have been clarifications, slight revisions, wireless guidelines, the addition of PIN Entry devices and of course, version updates – 1.1, 1.2 and 1.2.1, the most recent standard.  PCI DSS v2.0 was released on Oct 28, 2010 and went into effect January 1, 2011.  Organizations have until New Year’s Eve 2011 to implement and comply with the new changes and can actually still validate compliance against v1.2 until the ball drops again in 360 days.

It’s been an interesting ride for PCI with supporters hailing it’s mission and others complaining that it’s expensive, confusing and subjective.  If nothing else, it’s made business focus on and consumers more aware of Data Security, which is a good thing.  PCI v2.0 does not have any extensive new requirements but it does clarify some requirements for easier understanding and makes adoption, especially for small merchants, simpler and easier.  Some of the important updates include the need for a comprehensive audit prior to assessment to understand where all the cardholder data resides within the infrastructure.  Knowing all the locations and flows of sensitive data can help in protecting those assets.  An evolving requirement is allowing merchants to execute a risk-based approach, based on business circumstances, for ranking, addressing and prioritizing vulnerabilities.  I’ve mentioned before that Security is really about Risk-Management, and while I’m not sure that merchants with limited IT security experience could determine if they are more susceptible to Forceful Browsing, Hidden Field Manipulation, or SQL Injection, I do think it’s a step in the right direction in terms of an exercise.  It encourages organizations to conduct a risk-assessment and focus on areas that are the most vulnerable.  This can help a smaller merchant target their limited resources to a specific area of concern. 

Another evolving requirement is the need for more effective and centralized log management.  Scouring logs from various systems looking for that one nasty IP address can be cumbersome and the ability to centralize log management is important whether you’re trying to be PCI compliant or not.  Cloud Computing comes to mind as a big beneficiary of centralized management.  And speaking of the Cloud, there is also some guidance on virtualization – not much – but some.  For one, they’ve included virtualization in that, they’ve expanded the definition of system components to include virtual components.  You can only implement one primary function per server, so functions like web, app, db, DNS and so forth should be running on separate virtual machines.  They want to avoid situations where different functions that may have different security levels are cohabitating on the same server.  Also, since VMs can move around, if only one of your VMs is handling cardholder data, then the entire virtual infrastructure must comply.

The following is taken directly from the PCI DSS 2.0 and PA-DSS 2.0 Summary of Changes – Highlights document.

image

image

And so begins the new 3 year lifecycle for standards development but minor revisions can be added, if necessary, during that time.  While the temptation is to wait until you absolutely have to comply or just test against the old standard, it’s better to get going on two-dot-oh sooner than later.  You really don’t want to be worried about implementing PCI updates when the 2011 holiday shopping season is in full swing or when staff is limited due to the holidays.  If you need to comply, do yourself a favor and get it done early.

ps

Resources:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, PCI DSS, virtualization, cloud computing, Pete Silva, security, cloud, credit card, compliance, web, internet, cybercrime, holiday shopping, identity theft,

Tuesday, January 4, 2011

In 5 Minutes or Less Video - F5's iHealth System

Maintaining your system and troubleshooting issues can be time-consuming and tedious.  Whether you want to fix a problem, improve performance, or view your system’s running configuration, F5 BIG-IP iHealth™ can help you accomplish your task quickly and accurately. BIG-IP iHealth consists of BIG-IP iHealth Diagnostics and BIG-IP iHealth Viewer.  BIG-IP iHealth Diagnostics identifies issues, including common configuration problems and known software issues. It also provides solutions and links to more information.  With BIG-IP iHealth Viewer, you can see the status of your system at-a-glance, drill down for details, and view your network configuration.

F5 iHealth system, an exclusive online support service available to F5 customers and partners, is designed to proactively improve the performance of application delivery infrastructures.  iHealth is a web-based application that provides insight into BIG-IP product deployments through performance monitoring and automated analysis.  iHealth gives users a succinct description of identified issues along with F5's recommendations for addressing them.  This comprehensive analysis validates current product configurations against best practices, and displays heuristics data in an easy-to-understand format based on the familiar BIG-IP interface.  In offering a proactive approach to troubleshooting, iHealth significantly decreases the time and effort necessary to diagnose and address technical issues.

F5’s iHealth System

ps

Resources:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

 

Technorati Tags: F5, infrastructure 2.0, integration, big-ip, Pete Silva, security, business, education, technology, application delivery, diagnostics, cloud, context-aware, support, automation, web, video, blog, F5 iHealth

Monday, January 3, 2011

Audio White Paper - Application Delivery Hardware A Critical Component

Application Delivery Controllers (ADCs) come in a variety of hardware and software combinations, but mission-critical application delivery demands mission-critical ADC hardware.  Running Time: 17:58  Read full white paper here.  And click here for more F5 Audio.

ps

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, security, hardware, audio, whitepaper,

Posted via email from psilva's prophecies

Friday, December 17, 2010

e-card Malware

I’ve gotten some e-cards this holiday season from organizations that I know, and you might even receive one from F5.  I just wanted to post a short reminder to be careful of these, especially if you get one from someone you don’t know.  This is, and has been for several years, one of cybercriminals favorite ways of distributing malware, infecting your computer and stealing your info.  Usually, the e-card arrives in your email with a link to view it online.  Once you click that link and visit the purported e-card site, you can become infected.  In fact, if you get one and don’t know the sender at all, I’d delete it right away.  Often you don’t need to visit a site to get infected since the payload might in the email itself.

The Better Business Bureau is also warning of another phishing scam with cybercriminals masquerading as a shipping company.  You’ll get an email with a tracking number in the subject line.  The note says that the package could not be delivered and asks the user to print the attached document.  At that point, if you do open the attachment, then a virus is installed on your computer.  There have also been charitable giving scams, coupon code scams, too good to be true sale scams and other rip-offs to swindle you of your money and sensitive info.

You might be thinking, ‘ahh, geeze – not another,’ but this is the time of year those cybercriminals like to prey on people’s holiday spirit and general preoccupation with with other things festive.  Keep anti-virus updated, use a firewall, be suspicious, use common sense and enjoy the holidays.

ps

Resources:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, cybercrime, security, holiday shopping, identity theft, scam, email, data breach

Wednesday, December 15, 2010

2010 Year End Security Wrap

Figured I’d write this now since many of you will be celebrating the holidays over the next couple weeks and who really wants to read a blog when you’re reveling with family and friends.  It’s been an interesting year for information security, and for me too.  I started the year with New Decade, Same Threats? and wondered if the 2010 predictions of: social media threats, smarter malware/botnets, using the cloud for crime, financial DDoS, rogue software, Mac and Mobile malware, more breaches and a whole host of others would come through.  And boy did they. 

Social media was a prime target for crooks with the top sites as top targets.  Users were tricked to accepting and sharing friends that really weren’t friendly and social networks became a new hotbed for malware distribution.  As for malware, while many botnets and spam outfits got taken down this year, Stuxnet was certainly the most sophisticated piece of malware researches have seen in a while.  Targeting industrial & utility systems along with the ability to reprogram itself, no longer was it my single laptop or a company’s system that had a bull's-eye, although the initial infection is with those systems, it was nuclear facilities, oil refineries and chemical plants that were the ultimate objective. For Cloud Computing, was it Cloud 9 or Cloud Crime when it came to using the cloud for nefarious activities?  Many people thought that with the cloud offering a slew of computing power, that it would be a prime way to initiate an attack.  We really didn’t see much pertaining to ‘cloud breaches’ even though almost every survey throughout the year indicated that security in the cloud was everyone’s ichiban concern.  I covered many of these surveys in my CloudFucius Series, now playing in a browser near you.  This article talks about that, the reason we might not have seen much in the way of cloud specific breaches is that many of the data loss repositories do not differentiate between a cloud based and non-cloud attack.  In addition, cloud providers are not that willing to spill vulnerabilities that have led to crimes.  Share please. 

Banks and financial institutions were certainly targets this year, why wouldn’t they be, that’s where all the money is.  In one incident, about $3 million was stolen from various banks around the world using viruses and more than 100 crooks suspected of running the global cybercrime ring were arrested in the US and UK this September.  A 16 year old Dutch kid was arrested last week for a Distributed Denial of Service attack on the MasterCard and Visa websites.  And, merging malware, mobile and money stores, the ZeuS Trojan could infect a desktop, capture the user’s bank credentials next time they logged in to their financial institution, popped a dialogue box for the user to ‘include’ their mobile phone for SMS payments, send the phone a fake message & certificate for acceptance and then installed another Trojan on the phone to monitor messages via SMS.  Lots of trickery and luck to be successful but still a very scary exploit.  And if you think those mobile banking apps are secure, think again.  Just last month, a number of those apps were found to have serious vulnerabilities, flaws and holes.  Many of those apps have been patched in light of the research but as with any ‘new-ish’ type technology, mobile banking must be locked down before the masses adopt.  Too late now.

I wrote about corporate espionage both in Today’s Target: Corporate Secrets (2010) and The Threat Behind the Firewall (2009) and this year did not disappoint.  Social engineering or convincing someone to give up their info is alive and well but throughout 2010, employees stole secrets from the companies they worked for: Former Goldman Programmer Found Guilty of Code Theft, Greenback engineers guilty of corporate espionage, Ford secrets thief caught red handed with stolen blueprints, and SEC Bares Text of Inept Suspects As They Sold Disney Earnings Info To FBI AgentsThese insider events can often be more costly than an external breach.

This is by no means an exhaustive list of the breaches, attacks, vulnerabilities, hijacks, frauds, or other cybercriminal activities from 2010.  I’d probably be writing through the holidays to get them all.  These were just some of the things I found interesting when looking back at my initial blog entry for the year.  With 2011 being the Year of the Rabbit, just how much will cybercrimes multiply?

ps

Resources:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1]  o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, cybercrime, security, holiday shopping, identity theft, scam, email, data breach