Read up on the latest ideas and technologies from companies that sell hardware, software and services. Revolutionising Back-up and Recovery
Enterprise Wireless WLAN Security
Optimized Back-up and Recovery for VMWare for VMWare Infrastructure with EMC Avamar
Wireless LANs: Is my enterprise at risk?
A Guide to Next-Generation Backup, Recovery and Archive
Realizing the Value of Unified Communications
An EMC Perspective on Data De-Duplication for Backup
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
The Department of Defence has chimed in on the network security debate, stating organizations need to be more proactive if they expect to ward off attackers that readily exploit the high levels of trust usually reserved for employees and known systems.
Speaking at this year's AusCERT security conference, Paul Chamberlain from the Department of Defence said even if your organization doesn't have sensitive information "you still have people to pay and an attacker could end up on your payroll".
"Before you move to latest and greatest technology have all your bases covered," he said.
"Cyber criminals are generally motivated by profit or they could be issue-motivated groups that wish to penetrate your network for their own goals. There is the risk of a denial of service and theft of customer data, and there's also proprietary data your company will hold, for example, a press release you are about to release in a week or two."
What is the attacker going to do? Harvest as much information about the organization, and its people, for starters.
"They need to know all they can about your organization. It turns out it's easy to find out who works at your organization, there's Google, social networking Web sites, public company information, and what you post to your public Web site, like job ads."
In addition to gathering public information, attackers can still use technical measures, from DNS guessing, port scanning and service emulation, to cracking external services like Citrix gateways, VPNs, and Outlook Web Access.
"From there you take this information and look for entry points," Chamberlain said. "It doesn't need to be a zero-day exploit as it is more likely to be targeted at users. An attacker will rely on one user to receive a malicious word document for code execution to happen and the risk grows as the organization grows."
Chamberlain said even if there is only a 10 percent chance per user, a small organization may fail a user-targeted security incident over time, and, to make matters worse, an unsuccessful attempt may only look like spam, meaning users will most likely not be alerted to the danger.
"Once remote code has been executed all the person's e-mail and other information can be read," he said. "The attacker may move to another target once inside the organization by using Windows or Linux tools to move around so it's often built right in to the network."
As for dedicated security systems, these may also fail to stop penetration as the attack can use accepted protocols like HTTP, SSL, DNS and SMTP, so to a firewall it looks like regular traffic.
"An attack could use local admin privileges and the implicit trust your network will have inside your gateway," Chamberlain said.
Given attacks are likely to be multi-pronged, what do you do? Chamberlain said there is no one product or method so "it's all about managing your trust relationship".
"Do you need your intranet to be unauthenticated? It's about identifying your important data and how to protect it. It's about defence everywhere on your network. If a privilege isn't needed you shouldn't have it."
Chamberlain recommends organizations start with the security policy and develop a clear understanding of what users are meant to be doing because without a clear idea of who's allowed to do what "you won't be able to identify what has happened".
"For example, patch management is almost a solved problem, but you have to make sure it's turned on," he said. "Process whitelisting can cut down on code execution."
Other recommendations include knowing what to look for in log analysis.
"Look for abnormal patterns. How many e-mails does your network receive each week? If there is a spike there may be a compromise. When you know what your network traffic is you can identify anomalies."
Chamberlain said security should be everywhere in the organization's network as an attacker can get in one way or another.
Computerworld Member Login
Prioritizing Services with IT Service Management (ITSM)
Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)
To be repeated on:
Thursday 4th, September 2008
11:00am EST (Sydney Australia)
Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.
Attend and discover:
- How to deliver value to your business through ITSM
- Best practice ITSM implementation
- Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
- If service-oriented ITSM is best for your business
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Tumbleweed appoints O2 Networks to its Australian Channel Partner Program 2008-08-29 12:31:00+10
HP ProCurve Brings Big Business Gigabit Switching Features to Small Businesses 2008-08-29 12:00:00+10
Nortel and LG Electronics are First in World to Demonstrate Mobile LTE Handover 2008-08-29 11:30:00+10
GlobalConnect Provides Treatment for Healthcare Provider’s Contact Support Requirements 2008-08-29 09:59:00+10
Sybase and Logica Partner To Mobilise The Supply Chain 2008-08-29 09:47:00+10
Radicati Market Quadrant 2008 on Corporate Web Security
An Analysis of the Market for Corporate Web Security Solutions, revealing Top Players, Mature Players, Specialists and Trail Blazers. Read on to discover who makes the grade.












