By Shaul Efraim  Managing access to confidential information and application resources via firewalls is the foundation of network security, and firewall audits are central to any mature network security process. However, relying on security and network experts to review rules across multiple firewall z... Jan. 30, 2012 07:30 AM EST Reads: 1,083 |
By Vincent M. Schiavo  Companies across all industries are fighting to secure their proprietary and confidential data behind firewalls and complex passwords; unfortunately, the reality is that this data is most likely still slipping through the cracks. The introduction of employee-owned devices and the consu... Jan. 14, 2012 02:00 PM EST Reads: 1,011 |
By David Dodd  The purpose of this article is to describe some tools and techniques in performing the planning, scoping, and recon portion of a penetration test. In covering these tools and techniques the reader will learn how to use them to find vulnerabilities in their organization and help improve... Jan. 9, 2012 04:00 AM EST Reads: 1,292 |
By Dana Gardner  Joe Menn explores the current cyber-crime landscape, the underground cyber-gang movement, and the motive behind governments collaborating with organized crime in cyber space.
Maybe you can make your enterprise a little trickier to get into than the other guy’s enterprise, but crime pa... Jan. 6, 2012 08:00 AM EST Reads: 1,490 |
By Tim Matthews  There are some technological concepts that simply go better together. Consider the cloud and information explosion; the cloud offers the potential for unlimited storage for a torrent of ever-increasing data. Another example is virtualization and IT agility; strategic virtualization imp... Jan. 4, 2012 05:15 AM EST Reads: 1,988 |
By Gorka Sadowski  We saw what typically happens when trying to use static rule-based log correlation to perform real-time incident management... combinatory explosion and lack of scalability. How do you automate non-deterministic attacks in a few discrete steps???
Today, we'll look at more scenarios fo... Dec. 20, 2011 09:00 AM EST Reads: 1,607 |
By Dana Gardner  In just the past year, the number of attacks are up, the costs associated with them are higher and more visible, and the risks of not securing systems and processes are therefore much greater. Some people have even called the rate of attacks a pandemic.
The path to reducing these risk... Dec. 2, 2011 06:45 AM EST Reads: 1,387 |
By Michael Podszywalow  You’ve spent months fixing the red items on an internal audit report and just passed a regulatory exam. You’ve performed a network vulnerability assessment and network pen test within the last year and have fixes in place. You’ve tightened up your information security policy and recent... Nov. 24, 2011 03:00 PM EST Reads: 1,577 |
By Georgiana Comsa  In a recent blog post, Gary Sevounts, VP of marketing at Zetta, looks at the most popular offsite backup solutions for organizations with smaller budgets that can't afford a data center, but need their mission-critical data to be protected. Sevounts lists four options: tape, USB, mirro... Oct. 28, 2011 11:51 AM EDT Reads: 1,048 |
By David Dodd  The goal of the scanning phase is to learn more information about the target environment and discover openings by interacting with that target environment. This article will look at some of the most useful scanning tools freely available today and how to best use them. During this proc... Oct. 12, 2011 01:00 PM EDT Reads: 1,416 |
By Jim Kaskade  The security community has a growing number of influential and important people, especially as the industry rises to meet the need to address more advanced security threats, such as targeted attacks. But how does a company in the security industry truly identify the influential people?... Sep. 8, 2011 02:50 PM EDT Reads: 16,375 Replies: 4 |
By Marc Chanliau  The recent spike in insider threats, coupled with a rise in compliance considerations, has forced organizations to ensure only authorized users access sensitive application functionality and data. Historically, user entitlements or authorization logic has been embedded inside an applic... Aug. 25, 2011 10:15 AM EDT Reads: 6,319 |
By Dana Gardner  How can all the players in a technology ecosystem gain assurances that the other participants are adhering to best practices and taking the proper precautions? Jul. 29, 2011 10:00 AM EDT Reads: 8,497 |
By David Dodd  We are using the local port forwarding bound on a victim host so when we execute the route command and exploit internal hosts we can map them back to our initial victim, through the meterpreter connection and back to us.
The Metasploit Framework is a penetration testing toolkit, explo... Jun. 29, 2011 10:00 AM EDT Reads: 3,102 |
By Gorka Sadowski  Last week we saw that a proper Log Management tool is a powerful tool to catch the bad guys.
Advertise your use of such a tool and you will send a clear signal to would-be attackers that they will be caught, which will act as a powerful deterrent, and curb bad behaviors.
A 2004 study... Jun. 16, 2011 02:15 PM EDT Reads: 1,684 |
By Dana Gardner  The OTTF’s purpose is to shape global procurement strategies and best practices to help reduce threats and vulnerabilities in the global supply chain.
The framework outlines industry best practices that contribute to the secure and trusted development, manufacture, delivery and ong... Feb. 23, 2011 11:20 AM EST Reads: 2,138 |
By Dana Gardner  This is really not about adding some security band-aid onto a technology or a product. It's really about the fundamental attributes or assurance of the product or technology that’s being produced.
The OTTF is a group that came together under the umbrella of The Open Group to identify ... Feb. 22, 2011 02:54 PM EST Reads: 2,866 |
By Bill Roth  The major theme of this year’s RSA Conference is, guess what, security. This is the largest security show of the year, and its clearly a big deal, since it covers both sides of the Moscone Center in San Francisco. As of 10 a.m. on Monday, preparations are still being made. The show off... Feb. 14, 2011 03:24 PM EST Reads: 2,429 |
By Christos K. Dimitriadis  As enterprises struggle to remain profitable in an ever-changing risk environment, the current economic crisis has elevated the need for effective business risk management. Information security is a key parameter that affects business risk. The academic definition of information securi... Feb. 9, 2011 06:00 AM EST Reads: 3,549 |
By Peter Weger  The WikiLeaks security fiasco has shed a lot of light on document security and its inherent irony: namely that the more confidential a document is, the more it’s likely to be shared.
Web Security Journal reached out to the CEO of Brainloop, Peter Weger, to discuss the notion of so-... Feb. 5, 2011 05:15 AM EST Reads: 2,548 |
By Gorka Sadowski  Over the next few weeks, we'll investigate how the expression "An ounce of prevention is worth a pound of cure" could also be applied to the IT world, and what are the tools to foster preventive security through behavior modification.
When looking at IT security, it seems that most of... Feb. 1, 2011 07:00 PM EST Reads: 2,559 |
By David Rowe  Users are the weakest link when it comes to information security. Without intending to, they cost more money in security breaches than outside hackers. This is why all regulations require the demonstration of strong access security. But focusing purely on regulatory compliance proofs a... Jan. 12, 2011 12:15 PM EST Reads: 2,938 |
By Security News Desk  There's been a flurry of discussion this week among Internet and Web standards heavy-hitters around WebSocket, the new communications protocol supported in Chrome 4 and Safari 5. What was the main issue? Is there some kind of fundamental security vulnerability with the WS protocol? Web... Dec. 12, 2010 02:30 AM EST Reads: 12,531 |
By Maureen O'Gara  Right before Christmas, the White House tapped Microsoft’s long-ago chief security officer, the CEO of the non-profit Information Security Forum Howard Schmidt as head of US cyber security.
Despite the national priority, between pressure from US companies and reported infighting am... Dec. 28, 2009 11:30 AM EST Reads: 4,377 |
By Peter Silva  I had a different name for this blog entry but just ‘Jump Drive’ is an awful blog title. They go by many names; jump drive, USB drive, flash drive, memory stick and a few others, but removable media is a serious threat to IT organizations. Graduating from floppy disks, as early as 20... Sep. 12, 2009 06:30 PM EDT Reads: 5,865 |
By Mark O'Neill  Joe McKendrick kicks off a thread on the current state of SOA Security. As usual, most discussion of SOA Security applies to "how SOA can be made secure". This is understandable. And, as some commentators have pointed out, there is a body of Best Practice out there on how to secure ser... Sep. 8, 2009 01:00 PM EDT Reads: 5,095 |
By Devi Gupta  You don't have to be a chief information officer to realize that security is becoming a corporate concern as more business is transacted on the Web. The mounting fears are well founded. Web attacks are growing in sophistication. Data is flowing faster and to more applications and more ... Mar. 9, 2009 10:15 AM EDT Reads: 6,490 |
By Prat Moghe  There are many reasons why a data security strategy could self-destruct, not the least of which is a new breed of highly motivated data thieves who stand to make a considerable profit on customer and other sensitive information in data centers. We're often so mired with putting out dat... Nov. 10, 2008 01:08 PM EST Reads: 3,952 |
By SOA News Desk Layer 7 Technologies announced its go-to-market partnership with Steria Benelux. Steria will act as a channel partner for Layer 7's SOA gateway products in Belgium to offer leading SOA security, governance solutions and support to its current and prospective customers. May. 28, 2008 03:30 PM EDT Reads: 6,819 |
By Erika Delgado  Spending time with my parents over the holidays got me thinking about the differences between this generation and the previous one. My parents expect to spend a certain amount of time and effort managing certain aspects of their lives. For example, when they drive to an unfamiliar vaca... May. 22, 2008 08:00 AM EDT Reads: 7,280 |
By Mike Pellegrini  Composite applications are made up of discreet services that have been tried and proven reliable, but building an orchestration that incorporates services that come from several sources, some of them outside of the company, could introduce testing hazards beyond just bad output. For ex... May. 5, 2008 06:00 PM EDT Reads: 5,092 |
By Scott Morrison  Is SOA ready to move from the whiteboards and into production IT? As you might have guessed, the answer remains a disappointing sort of. The issue comes down to tools and infrastructure, and the fact that only some SOA components are mature and easy to source. Aug. 20, 2007 08:45 AM EDT Reads: 14,507 Replies: 1 |
By Rajiv Gupta  As the name suggests, a Service Oriented Architecture is one where application functionality is packaged as autonomous services that adhere to industry standard interfaces (WSDL, SOAP), and the services are then deployed in an IT architecture that makes for their most effective use. T... Apr. 14, 2007 04:15 PM EDT Reads: 20,515 |
By Kevin Smith  When SOAP-based Web Services solutions began appearing five years ago, one of the major challenges was securely propagating end-user identity in Web Service chaining scenarios. Certainly a user could authenticate to a portal, and that portal could talk to a Web Service that talks to an... Oct. 19, 2006 01:15 PM EDT Reads: 12,072 Replies: 1 |
By Sean Blanton  Developing under a Service Oriented Architecture (SOA) is different from traditional development. A large set of business changes will now be funneled through a relatively small number of enterprise services. An inefficient or bad build system can impact a greater number of business ch... Oct. 16, 2006 12:00 PM EDT Reads: 10,458 |
By Kevin Smith  Over the past five years, the promise of enterprise information sharing has made great strides with the evolution of Web Services and the promise of Service Oriented Architectures (SOA). An architectural shift that moves us away from point-to-point client/server systems. Aug. 10, 2006 12:45 PM EDT Reads: 25,948 Replies: 4 |
By SOA News Desk McAfee the leading dedicated security company, announced that Foundstone Professional Services will launch a series of free tools that teach developers, programmers, architects and security professionals how to create more secure software. The tools will also review the root causes of ... Jun. 15, 2006 11:00 AM EDT Reads: 14,666 Replies: 1 |
By Francois Lascelles; Aaron Flint  The WS Secure Conversation specification describes a mechanism letting multiple parties establish a context (using the WS Trust Request Security Token standard) and secure subsequent SOAP exchanges. Each WS Secure Conversation session has an associated shared secret. Instead of using t... Apr. 17, 2006 11:15 AM EDT Reads: 17,615 Replies: 2 |
By Jeremy Epstein  As organizations move to service-oriented architecture (SOA), security becomes one of the key concerns impacting deployment. After all, a company's most sensitive information is frequently stored in the business systems that are now being accessed by the Web services employed within an... Dec. 3, 2005 08:30 PM EST Reads: 18,936 Replies: 1 |
By Security News Desk 'The best approach to selecting the optimal Web services security solution is to assess the needs to be met and then to identify a solution that best fits those needs, precisely and affordably,' according to Forum Systems. Key to this approach is the avoidance of one-size-fits-all solu... Jun. 19, 2005 09:00 PM EDT Reads: 12,658 |