Wednesday, May 8, 2013

Interop2013: F5 Certification Program

I catch up with F5 Certification Manager Ken Salchow to talk about how the Certification Program has grown over the last year since the announcement at Interop 2012. Ken discusses the new exams, his certification philosophy and how this all fits within the tech industry. F5's New Technical Certification Program Helps Define and Measure the Skills Required for Today's IT Complexities.

 

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, May 7, 2013

Interop2013: F5 in the Interop NOC

For the 3rd year in a row F5 has a key role in the Interop NOC and this year we are showing how the F5 Application Delivery Firewall solution can protect against a DDoS attack against the Interop infrastructure. Ken Bocchino, Sr Consultant with F5 shows the architecture along with both a network layer DDoS attack against the infrastructure and a layer 7 DDoS attack against Interop.com and how the F5 solution stops it cold.

 

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Interop2013: Find F5

For the 200th time, ALOHA! I show you how to find F5 Booth #2127 at Interop 2013. I also share F5’s activities during the show, demo the F5 giveaways and play the Big Claw Challenge. Reporting from Las Vegas at the Mandalay Bay Convention Center.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, April 30, 2013

Wednesday, April 24, 2013

Targets of Opportunity

#dbir

...Is one of the findings in #Verizon's 2013 Data Breach Investigations Report, which is chuck full of interesting data.  75% of the attack victims were selected because they had a weakness that an attacker knew how to exploit rather than being specifically chosen.  The difficulty of the initial compromise was low for 68% of the breaches meaning the attackers used basic methods or automated tools and scripts.  It also means that there are sloppy configurations, needless services and exposed vulnerabilities that are bringing this attention.

Overall, the report covers 47,000 reported security incidents, of which, there were 621 confirmed data breaches.  This is important since they focus on the 621 confirmed data loss incidents rather than the 47,000 reports.  There will probably be a ton of articles reporting the results but a good place to start is securosis.com with their How to Use the 2013 Verizon Data Breach Investigations Report.  This is a great primer for the document.

There is a pretty even distribution of industries hit from financial to retail and restaurants to manufacturing, transportation and utilities to government and defense contractors.  The overwhelming majority of attacks are perpetrated by outsiders at 92% of the confirmed data breaches with insiders at 14%.  Interestingly, for all reports (the 47,000 not just the 621 confirmed) insiders accounted for 69% of the incidents.  Typically this was due to carelessness rather than criminal misuse.  76% of the network intrusions exploited weak or stolen credentials and most often, the attack was driven by financial motives at 75%.

Some other interesting data for me was that 66% of the breaches remained undiscovered for months or more and 69% of those were discovered by outside entities.  So organizations are in the dark about their intrusions, and it takes an outsider to point it out.  It's like those people who drive away with the gas hose still hooked to their tank. 

I was also curious about breaches as a result of BYOD.  Not many.  In 2011 they only saw 1 breach that involved personally owned devices and only a couple more in 2012.  They will keep watching and do expect that it may increase but for now, so far so good.  Could be because while BYOD is a hot topic, most surveys indicate that only around half the organizations are digging in.

There is a ton more valuable data in the report and it is an easy, fun read for 63 pages of stats.  Right on page 2 they say, 'Some organizations will be a target regardless of what they do, but most become a target because of what they do.  If your organization is indeed a target of choice, understand as much as you can about what your opponent is likely to do and how far they are willing to go.'  Put it on your list.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, April 23, 2013

The Prosecution Calls Your Smartphone to the Stand

Or Bring-Your-Own-Defendant

A very real legal situation is brewing is the wake of the bring your own device phenomena. #eDiscovery.  You might be familiar with some of the various legal or liability issues that should be addressed with a BYOD policy, like privacy, the loss of personal information, working overtime or the fact that financial responsibility may dictate legal obligation. 

Now, technology law experts are saying that if your company is involved in litigation, criminal or civil, personal mobile devices that were used for work email or other company activity, could be confiscated and examined for evidence as part of the investigation or discovery process.   So if you use your personal smartphone for work related activities and your company is involved in a lawsuit, there may come a point where the court might subpoena your phone to see what relevant evidence might be contained.  During litigation, the organization itself may have the legal obligation to sift through your mobile device for related information. If sued, companies are required to make a good-faith effort to retrieve data - where ever that may be.  That includes your email, GPS history, text messages, cell phone records, social media accounts, pictures and any other info that could be pertinent to the case.  This is proprietary company owned data that resides on my personally owned device.  This is especially true of your corporate email co-mingles with your personal email - meaning delivered through the same email app or program.  In fact, according to this article, a judge recently sanctioned a company for a discovery violation because it did not search the BYOD devices during discovery.

Some people seem to lose all sense of daily human functioning when social networks like Facebook, Twitter and others are unavailable for a short period of time.  We've become so attached to our mobile devices and they have become the center of our lives...imagine not having that pacifier for a few days.  OMG, I've time-traveled the 1980's and have no way of announcing it to the world!!  What am I going to do now that I can't re-tweet that funny cat picture!  I'm so lost without you, oh electronic appendage.

As more organizations embrace or even require BYOD in the workplace, it becomes even more critical to be able to separate personal and work profiles.  It is important that the corporate data and apps do not mingle with the already present personal data.  Solutions like F5's Mobile App Manager provides a fully enclosed virtual enterprise workspace and creates a secure footprint on the device for enterprise data and access only.  MAM allows organizations to safely separate personal data and usage from corporate oversight and controls how employees access key corporate information.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, April 17, 2013

Most of the Time We Get it Wrong

A colleague relayed this story:

At a recent toastmasters meeting, they did a survey.

They were asked what does each of the following words mean, when represented as a percentage?

  • Sometimes
  • Frequently
  • Rarely
  • Often
  • Usually

For example, my friend interpreted “Frequently” to mean “about 60% of the time”....more than half for sure.  I agreed.

We thought that we “knew” how these were interpreted by other people, but when they reviewed the survey, they found that people interpreted these words in such different ways as to make them all interchangeably meaningless.  The percentages are the range of what people 'thought' were the accurate occurrences.

Survey Word

(Equals)

Sometimes

10-60%

Frequently

30-95%

Rarely

1-10%

Often

50-90%

Usually

50-98%

Only “Rarely” seems to have a common understanding. 'Frequently' had such a giant range as to be completely useless, with some people thinking that it mean less than half the time and others feeling that it was a near certainty. 

With that in mind, from now on I will frequently write stories that are rarely covered often in the media and it will usually involve some stats that I'll sometimes understand. 

Perfect.

ps

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]