
<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Savid Insight &#187; Network security</title>
	<atom:link href="http://www.savidtech.com/blog/category/network-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.savidtech.com/blog</link>
	<description>Savid Technologies thoughts on technology, IT, information security, and business</description>
	<lastBuildDate>Sun, 08 Jan 2012 22:27:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<div id='fb-root'></div>
					<script type='text/javascript'>
						window.fbAsyncInit = function()
						{
							FB.init({appId: null, status: true, cookie: true, xfbml: true});
						};
						(function()
						{
							var e = document.createElement('script'); e.async = true;
							e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js';
							document.getElementById('fb-root').appendChild(e);
						}());
					</script>	
						<item>
		<title>Sony didn&#8217;t have log management either?</title>
		<link>http://www.savidtech.com/blog/network-security/sony-didnt-have-log-management-either/</link>
		<comments>http://www.savidtech.com/blog/network-security/sony-didnt-have-log-management-either/#comments</comments>
		<pubDate>Wed, 27 Apr 2011 03:33:11 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[Network security]]></category>
		<category><![CDATA[credit card]]></category>
		<category><![CDATA[log management]]></category>
		<category><![CDATA[risk assessment]]></category>

		<guid isPermaLink="false">http://www.savidtech.com/blog/?p=673</guid>
		<description><![CDATA[While reading through the blog post that discusses how Sony&#8217;s Playstation network was breached, was I the only one that noticed that playstation network usernames AND passwords were stolen. Perhaps they left out the specifics but, why were the passwords stored using encryption thereby increasing the amount of time and effort required to decrypt the [...]]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/sony-didnt-have-log-management-either/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fsony-didnt-have-log-management-either%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fsony-didnt-have-log-management-either%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>While reading through the blog post that discusses how <a href="http://blog.us.playstation.com/2011/04/26/update-on-playstation-network-and-qriocity/">Sony&#8217;s Playstation network was breached</a>, was I the only one that noticed that playstation network usernames AND passwords were stolen. Perhaps they left out the specifics but, why were the passwords stored using encryption thereby increasing the amount of time and effort required to decrypt the passwords?</p>
<p>Nevertheless, this breach is rather interesting in that the blog post states &#8220;While there is no evidence at this time that <a href="http://www.savidtech.com/blog/tag/credit-card/" class="st_tag internal_tag" rel="tag" title="Posts tagged with credit card">credit card</a> data was taken, we cannot rule out the possibility.&#8221; One point of doing proper <a href="http://www.savidtech.com/blog/tag/log-management/" class="st_tag internal_tag" rel="tag" title="Posts tagged with log management">log management</a> and risk assessments is to be able to see how far the rabbit hole goes when a breach occurs. The ability to know that only a portion of records were affected during a breach can save thousands of even hundreds of thousands of dollars.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.wired.com/gamelife/2011/04/playstation-network-hacked/">PlayStation Network Hack Leaves Credit Card Info at Risk</a> (wired.com)</li>
<li class="zemanta-article-ul-li"><a href="http://technologizer.com/2011/04/26/playstation-network-breach-data-stolen/">Playstation Network Breach: It&#8217;s Really, Really Bad</a> (technologizer.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=e08e2d6d-d925-480c-894e-632c7b456237" alt="" /></div>

	Tags: <a href="http://www.savidtech.com/blog/tag/credit-card/" title="credit card" rel="tag">credit card</a>, <a href="http://www.savidtech.com/blog/tag/log-management/" title="log management" rel="tag">log management</a>, <a href="http://www.savidtech.com/blog/tag/risk-assessment/" title="risk assessment" rel="tag">risk assessment</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/sony-didnt-have-log-management-either/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When the Mill Slows, Sharpen Your Saw</title>
		<link>http://www.savidtech.com/blog/network-security/when-the-mill-slows-sharpen-your-saw/</link>
		<comments>http://www.savidtech.com/blog/network-security/when-the-mill-slows-sharpen-your-saw/#comments</comments>
		<pubDate>Wed, 09 Mar 2011 20:32:57 +0000</pubDate>
		<dc:creator>tczarnik</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Savid Technologies]]></category>

		<guid isPermaLink="false">http://www.savidtech.com/blog/?p=574</guid>
		<description><![CDATA[With the reduction in IT budgets and security tools these days, many times IT security professionals are forced to deal with maintenance type tasks that leave them feeling bored and overworked.  It doesn't have to be that way. Get excited about technology again! Savid offers many opportunities to take advantage of free information for educational purposes such as webinars, lunch &#038; learns, and whitepapers.]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/when-the-mill-slows-sharpen-your-saw/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fwhen-the-mill-slows-sharpen-your-saw%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fwhen-the-mill-slows-sharpen-your-saw%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<div class="zemanta-img" style="margin: 1em; display: block;">
<div class="wp-caption alignleft" style="width: 224px">
	<a href="http://commons.wikipedia.org/wiki/File:Higher_learning.png"><img title="Achieving higher learning through the use of c..." src="http://www.savidtech.com/blog/wp-content/uploads/2011/03/300px-Higher_learning3.png" alt="Achieving higher learning through the use of c..." width="224" height="285" /></a>
	<p class="wp-caption-text">Image via Wikipedia</p>
</div>
</div>
<p>You don’t need a 6th sense to detect when a fellow <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">IT</a> <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> pro is engaged in a hot project, like implementing a defense in depth strategy, DLP tool or a PenTest project, when for 10 hours a day they can role play as a nefarious, ethical <a href="http://www.savidtech.com/blog/tag/hacker/" class="st_tag internal_tag" rel="tag" title="Posts tagged with hacker">hacker</a>. They spring out of bed without an alarm, their ipod rocks as they think of their project on the way to work, and usually work while others sleep. And as they sense the success of their project is in reach, there is a gleam in their eye like Melvin Purvis knowing Dillinger will be at the Biograph theatre that night. Yes, that’s you. The details are different, but you act with the same focused purpose when you are engaged with a hot project.</p>
<p>Unfortunately, “productive you” has been dulled by the recession. You look at the clock. It’s <em>9:03</em>- Your hot project lost budget. <em>9:07</em>- You start to feel like you’re just hanging out at the office, daydreaming about the receptionist or what you’re going to do this weekend. <em>9:13</em>- “Will I be the next budget cut?” Or maybe you’re forced into endless, mindless, maintenance and you begin to feel like the same worthless, infinite loop that “victim you” is attempting to debug. Maybe you’ve become a cash cow and you’ve lost touch with the leading edge you once steered like a snowboard. If you resent, but resemble this description, <strong>STOP</strong>. It’s time to wake up the <strong>“pro-active you”</strong>.</p>
<p><span style="text-decoration: underline;"><strong>Learn and Grow</strong></span>. It even sounds healthy and positive, like water and sunlight to a plant. I’m not going to try and talk you out of investing in night school, but you don’t need money, homework and someone else’s schedule to learn. There’s a lot of negativity about our current economy. Want a silver lining? There has never been a time when you and I could take advantage of the plethora of free information for educational purposes as we can today. Think about it. “How would you like your free industry knowledge, miss? For here (seminar)? To go (white paper)? or delivered into cyberspace (webinar)?”</p>
<p><strong>Complimentary subject matter expertise </strong>and contributing back to the community are key foundational components of the <strong><a href="http://www.savidtech.com/blog/tag/savid-technologies/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Savid Technologies">Savid Technologies</a> </strong>business model. In my Security Practice Manager role, I am deep into developing an immense library of <a href="http://www.savidtech.com/blog/tag/it-security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT Security">IT security</a> and <a href="http://www.savidtech.com/blog/tag/compliance/" class="st_tag internal_tag" rel="tag" title="Posts tagged with compliance">compliance</a> literature. It’s already pretty solid. Savid’s Marketing team, in conjunction with our Web Development team, has created an easy and efficient self service system for your convenience. Just check it out at <a href="http://www.savidtech.com/">www.savidtech.com</a>. Look for new, relevant and insightful information every month on technology, methodology and industry metrics. On our website, you can also <a title="Savid Events" href="http://www.savidtech.com/savid-events/" target="_blank">view the upcoming complimentary, educational events</a>, or <a title="Savid Whitepapers" href="http://www.savidtech.com/resources" target="_blank">download our informative whitepapers</a>. If what you are looking for is not there yet, just contact Kelly or Angela in Marketing (877-307-0444). They’ll hook you up with free industry knowledge, for here, to go, or delivered into cyberspace. I will also make time to discuss IT security with you. If I don’t know it, I will connect you with the right resources.</p>
<p>One last note. Consider attending our monthly Chicago IT Security Meetup. Next meeting’s topic and registration can be found at: <a href="http://www.meetup.com/The-IT-Security-Group-of-Chicago/">http://www.meetup.com/The-IT-Security-Group-of-Chicago/</a>. I gotta go now and finish my week’s work; I’ve got a long list of research topics for Saturday morning.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="float: right; border-style: none;" src="http://img.zemanta.com/pixy.gif?x-id=32376885-26f8-4748-ba62-ff09bf94edd0" alt="" /></div>

	Tags: <a href="http://www.savidtech.com/blog/tag/compliance/" title="compliance" rel="tag">compliance</a>, <a href="http://www.savidtech.com/blog/tag/hacker/" title="hacker" rel="tag">hacker</a>, <a href="http://www.savidtech.com/blog/tag/it/" title="IT" rel="tag">IT</a>, <a href="http://www.savidtech.com/blog/tag/it-security/" title="IT Security" rel="tag">IT Security</a>, <a href="http://www.savidtech.com/blog/tag/savid-technologies/" title="Savid Technologies" rel="tag">Savid Technologies</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/when-the-mill-slows-sharpen-your-saw/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RSA 2011 Wrap-up: Mostly Mobile and Cloud talk but progress nonetheless</title>
		<link>http://www.savidtech.com/blog/network-security/rsa-2011-wrap-up-mostly-mobile-and-cloud-talk-but-progress-nonetheless/</link>
		<comments>http://www.savidtech.com/blog/network-security/rsa-2011-wrap-up-mostly-mobile-and-cloud-talk-but-progress-nonetheless/#comments</comments>
		<pubDate>Fri, 18 Feb 2011 19:48:47 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Cloud computing]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[risk management processes]]></category>
		<category><![CDATA[RSA Conference]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://www.savidtech.com/blog/?p=541</guid>
		<description><![CDATA[I attended the RSA conference this year, as I always do, and spent most of the time talking with attendees and clients about what they were learning and trends they were seeing.  Here is a summary of what we discussed. Mobile Security Although mobile security concerns seems to be a theme, I tried to dig [...]]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/rsa-2011-wrap-up-mostly-mobile-and-cloud-talk-but-progress-nonetheless/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Frsa-2011-wrap-up-mostly-mobile-and-cloud-talk-but-progress-nonetheless%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Frsa-2011-wrap-up-mostly-mobile-and-cloud-talk-but-progress-nonetheless%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<div class="zemanta-img" style="margin: 1em; display: block;">
<div class="wp-caption alignleft" style="width: 245px">
	<a href="http://www.crunchbase.com/company/facebook"><img title="Image representing Facebook as depicted in Cru..." src="http://www.savidtech.com/blog/wp-content/uploads/2011/02/4561v1-max-450x4502.png" alt="Image representing Facebook as depicted in Cru..." width="245" height="100" /></a>
	<p class="wp-caption-text">Image via CrunchBase</p>
</div>
</div>
<p>I attended the <a href="http://www.savidtech.com/blog/tag/rsa-conference/" class="st_tag internal_tag" rel="tag" title="Posts tagged with RSA Conference">RSA conference</a> this year, as I always do, and spent most of the time talking with attendees and clients about what they were learning and trends they were seeing.  Here is a summary of what we discussed.</p>
<p><strong>Mobile <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">Security</a></strong></p>
<p>Although mobile security concerns seems to be a theme, I tried to dig deeper, and <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> seems that more than a few people are concerned about the upcoming changes to <a href="http://www.savidtech.com/blog/tag/facebook/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Facebook">Facebook</a>’s currency model. <a href="http://www.savidtech.com/blog/tag/facebook/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Facebook">Facebook</a> plans to force all users to use “<a href="http://www.savidtech.com/blog/tag/facebook/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Facebook">Facebook</a> Credits”. The worry is that since <a href="http://www.savidtech.com/blog/tag/facebook/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Facebook">Facebook</a> is on virtually every smartphone in the world, the digital wallet may come to the consumer faster than expected via <a href="http://www.savidtech.com/blog/tag/facebook/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Facebook">facebook</a>. The <a href="http://www.savidtech.com/blog/tag/facebook/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Facebook">Facebook</a> credits system is similar to <a href="http://www.savidtech.com/blog/tag/paypal/" class="st_tag internal_tag" rel="tag" title="Posts tagged with paypal">PayPal</a> or Google Checkout; however, since mobile phones don’t normally contain identity information they haven’t really been targeted. Once faceobok account can store credits, like a bank account, having a mobile virus or Trojan that steals your <a href="http://www.savidtech.com/blog/tag/facebook/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Facebook">facebook</a> login/password will be akin to stealing your bank account username and password. I think we have heard this story before…</p>
<p><strong>Cloud</strong></p>
<p>The cloud is always a hot topic but it seems as if nothing has changed. It is all about cost savings and whatever cost to security. As Dave, CSO from eBay put it. Vivek Kundra, whitehouse CIO, plans to save over 20billion by moving to the cloud and when you are saving 20 billion, who lets security get in the way?</p>
<p>Other people were more realistic and have conceded that the cloud will happen and they need to have data classification and <a href="http://www.savidtech.com/blog/tag/risk-management-processes/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk management processes">risk management processes</a> in place to ensure the *right* date moves to the cloud. A couple cloud vendors mentioned that they will need to educate their customers on how to do risk management and data management so that their customers can securely move to the cloud. This is a departure from the “We don’t talk or tell you about our <a href="http://www.savidtech.com/blog/tag/security-processes/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security processes">security processes</a>” stance the cloud vendors had last year.</p>
<p>Also, <a href="http://www.savidtech.com/blog/tag/symantec/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Symantec">Symantec</a> is making a big splash with their .cloud initative which is a marketing rebranding of all their cloud offerings including cloud based endpoint protection, cloud email encryption and filter, and cloud based web filtering. While the moniker may be funny and many have laughed at it, it is simple and effective. AV.cloud sounds much better than “cloud based anti-virus”. Marketing changes aside, not much has changed in terms of the technology behind the solution but <a href="http://www.savidtech.com/blog/tag/symantec/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Symantec">Symantec</a> is committed to heavily investing into .cloud and becoming the premier cloud security services provider in the world.</p>
<p>As I met with attendees and vendors, I asked if CIOs were adding cloud security services into their ROI analysis when moving their data to the cloud, almost everyone said no. Is this an indicator that cloud services don’t apply to the enterprise or perhaps the security CIOs want is ”real security controls” on the platforms, operating systems, and databases in the cloud rather than just moving their security tools from on-premise to the cloud? It seems to me the only people looking at cloud security services is the SMB.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=29a61d47-3d9e-4ca6-98a1-aeb303421792" alt="" /></div>

	Tags: <a href="http://www.savidtech.com/blog/tag/cloud-computing/" title="Cloud computing" rel="tag">Cloud computing</a>, <a href="http://www.savidtech.com/blog/tag/facebook/" title="Facebook" rel="tag">Facebook</a>, <a href="http://www.savidtech.com/blog/tag/paypal/" title="paypal" rel="tag">paypal</a>, <a href="http://www.savidtech.com/blog/tag/risk-management-processes/" title="risk management processes" rel="tag">risk management processes</a>, <a href="http://www.savidtech.com/blog/tag/rsa-conference/" title="RSA Conference" rel="tag">RSA Conference</a>, <a href="http://www.savidtech.com/blog/tag/symantec/" title="Symantec" rel="tag">Symantec</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/rsa-2011-wrap-up-mostly-mobile-and-cloud-talk-but-progress-nonetheless/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability Management Can Work Across Multiple Enterprises</title>
		<link>http://www.savidtech.com/blog/network-security/vulnerability-management-can-work-across-multiple-enterprises/</link>
		<comments>http://www.savidtech.com/blog/network-security/vulnerability-management-can-work-across-multiple-enterprises/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 02:55:27 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Business process]]></category>
		<category><![CDATA[enterprise vulnerability]]></category>
		<category><![CDATA[legal contracts]]></category>
		<category><![CDATA[management program]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security processes]]></category>
		<category><![CDATA[supply chain]]></category>
		<category><![CDATA[Supply chain management]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=465</guid>
		<description><![CDATA[Security teams that manage security at single company think their job is hard (it is!) but imagine if you have 10 partners accessing your network all day everyday! Learn the 3 steps to implement multi-enterprise vulnerability management the right way.]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/vulnerability-management-can-work-across-multiple-enterprises/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fvulnerability-management-can-work-across-multiple-enterprises%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fvulnerability-management-can-work-across-multiple-enterprises%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>I just released a report for Dark Reading on how to build a multi-enterprise <a href="http://www.savidtech.com/blog/tag/vulnerability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with vulnerability">vulnerability</a> <a href="http://www.savidtech.com/blog/tag/management-program/" class="st_tag internal_tag" rel="tag" title="Posts tagged with management program">management program</a>. If you are dealing with outsourced vendors, or an outsourced <a href="http://www.savidtech.com/blog/tag/supply-chain/" class="st_tag internal_tag" rel="tag" title="Posts tagged with supply chain">supply chain</a>, you should definitely <a href="http://www.darkreading.com/vulnerability_management/security/management/showArticle.jhtml?articleID=224300024">give the article a read</a>.</p>
<p>To summarize the article:</p>
<ol>
<li>Get your <a href="http://www.savidtech.com/blog/tag/legal-contracts/" class="st_tag internal_tag" rel="tag" title="Posts tagged with legal contracts">legal contracts</a> in order. So many firms don&#8217;t put what they need from their partners into a contract. How do you expect to get what you need then?</li>
<li>Establish Communication channels that work for everyone. If you don&#8217;t get the right people on the &#8220;phone&#8221;, nothing will get done &#8211; including your <a href="http://www.savidtech.com/blog/tag/security-processes/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security processes">security processes</a></li>
<li>Find the person with authority at your partner and ensure they are involved, otherwise your efforts will be useless.</li>
</ol>
<p>I offer many more details and tips within the article but step #1 is so critical that an entire article should be dedicated to just that!</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/business-process/" title="Business process" rel="tag">Business process</a>, <a href="http://www.savidtech.com/blog/tag/enterprise-vulnerability/" title="enterprise vulnerability" rel="tag">enterprise vulnerability</a>, <a href="http://www.savidtech.com/blog/tag/legal-contracts/" title="legal contracts" rel="tag">legal contracts</a>, <a href="http://www.savidtech.com/blog/tag/management-program/" title="management program" rel="tag">management program</a>, <a href="http://www.savidtech.com/blog/tag/security/" title="security" rel="tag">security</a>, <a href="http://www.savidtech.com/blog/tag/security-processes/" title="security processes" rel="tag">security processes</a>, <a href="http://www.savidtech.com/blog/tag/supply-chain/" title="supply chain" rel="tag">supply chain</a>, <a href="http://www.savidtech.com/blog/tag/supply-chain-management/" title="Supply chain management" rel="tag">Supply chain management</a>, <a href="http://www.savidtech.com/blog/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a>, <a href="http://www.savidtech.com/blog/tag/vulnerability-management/" title="vulnerability management" rel="tag">vulnerability management</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/vulnerability-management-can-work-across-multiple-enterprises/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Obama Twitter account hacked..it was a 1 in 80 chance</title>
		<link>http://www.savidtech.com/blog/network-security/obama-twitter-account-hacked/</link>
		<comments>http://www.savidtech.com/blog/network-security/obama-twitter-account-hacked/#comments</comments>
		<pubDate>Thu, 25 Mar 2010 18:58:04 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=455</guid>
		<description><![CDATA[President Obama's Twitter account was easily hacked because of problems in the way security questions are asked. A new paper released talks about how an average person has a 1 in 80 chance of guessing your secret account question.]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/obama-twitter-account-hacked/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fobama-twitter-account-hacked%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fobama-twitter-account-hacked%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>According to the Wall Street Journal:</p>
<blockquote><p>A 24-year-old living with his mother in France was arrested for &#8216;hacking&#8217; into Obama&#8217;s twitter accounts in April 2009. Apparently he guesses the answer to a question related to password recovery in order to break into the accounts of famous people; he has no computer science training or financial motive. He posted screenshots to a few online forums and twitter found out within a few hours, either from a tip or from noticing when someone from France logs onto twitter as the President of the United States. (He did not actually tweet as POTUS, but just wanted to show he could break into the account.)</p></blockquote>
<p>Now, this is news in and of itself but the interesting part is that the following academic paper, released about three weeks ago, told how easy this hack really is to implement. In this paper, Joseph Bonneau of the University of Cambridge and two colleagues from the University of Edinburgh show how hackers stand a <strong>1 in 80 chance </strong>of guessing common <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> questions such as someone&#8217;s mother&#8217;s maiden name or their first school within three attempts.</p>
<p>According to the blog post announcing the paper&#8217;s release, Joseph Bonneau states:</p>
<blockquote><p>There’s finally been a surge of academic research into the area in the last five years. <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">It</a>’s been shown, for example, that these questions <a href="http://cups.cs.cmu.edu/soups/2008/proceedings/p13Rabkin.pdf">are easy to look up online</a>, often <a href="http://www.informatics.indiana.edu/markus/papers/mmn.pdf">found in public records</a>, and <a href="http://research.microsoft.com/pubs/79594/oakland09.pdf">easy for friends and acquaintances to guess.</a></p></blockquote>
<p>This is probably what happened to President Obama&#8217;s account. It would be interesting to know what the answer was to Obama&#8217;s secret question is, but it is very difficult to find the screenshots referenced in the WSJ article. The academic paper continues:</p>
<blockquote><p>It turns out the majority of personal knowledge questions ask for proper names of people, pets, and places, and the rest are trivially insecure (eg “What is my favourite day of the week?”).</p></blockquote>
<p>Which is why your system should never ask for things like that. Companies are starting to try and solve this problem. At RSA there was a new company, RavenWhite, which seemed to have a unique new approach which you can learn about at <a href="http://www.ravenwhite.com/iforgotmypassword.html">http://www.ravenwhite.com/iforgotmypassword.html</a></p>
<p>People really need to rethink the way they implement security to the end user. There is no way any automated technology could have prevented Obama&#8217;s account from being attacked simply because they were using the system in the perfectly intended way. It is what the user did afterword that differentiated the attacker from an actual twitter user.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/obama-twitter-account-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>7 consecutive errors equals a Security Breach</title>
		<link>http://www.savidtech.com/blog/network-security/7-consecutive-errors-equals-a-security-breach/</link>
		<comments>http://www.savidtech.com/blog/network-security/7-consecutive-errors-equals-a-security-breach/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 05:01:41 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Christian Moldes]]></category>
		<category><![CDATA[exploitation]]></category>
		<category><![CDATA[gladwell]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[moldes]]></category>
		<category><![CDATA[plane crashes]]></category>
		<category><![CDATA[privileged account]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[security breaches]]></category>
		<category><![CDATA[security program]]></category>
		<category><![CDATA[verizon]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=450</guid>
		<description><![CDATA[Even with many controls in place you cannot always prevent a security breach. This is the exact reason why we recommend that incident response policies and processes (Which should be tested like you test your Disaster Recovery processes!) should be the FIRST THING you implement when building a security program at an organization followed by detective controls such as logging to detect a breach as soon as possible.]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/7-consecutive-errors-equals-a-security-breach/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2F7-consecutive-errors-equals-a-security-breach%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2F7-consecutive-errors-equals-a-security-breach%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.savidtech.com/blog/tag/verizon/" class="st_tag internal_tag" rel="tag" title="Posts tagged with verizon">Verizon</a> Business Christian <a href="http://www.savidtech.com/blog/tag/moldes/" class="st_tag internal_tag" rel="tag" title="Posts tagged with moldes">Moldes</a> as a great post about <a href="http://securityblog.verizonbusiness.com/2010/03/11/plane-crashes-and-security-breaches">Plane Crashes and Security Breaches</a> and how they are very similar. He hits <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> right on the head! During our engagement wrap-up meetings where we explain the various potential scenarios an attacker can use to break into a client’s network we are always asked to put a specific ranking on a specific risk. I argue that that almost doesn&#8217;t matter because normally the big breaches are not from a single <a href="http://www.savidtech.com/blog/tag/vulnerability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with vulnerability">vulnerability</a> but many chained together.</p>
<p>Christian quotes Malcom <a href="http://www.savidtech.com/blog/tag/gladwell/" class="st_tag internal_tag" rel="tag" title="Posts tagged with gladwell">Gladwell</a>, and says:</p>
<blockquote><p>The typical [plane] accident involves seven consecutive human errors.</p></blockquote>
<p>When we work with clients we normally see that breaches are caused by a chaining of at least three errors: <a href="http://www.savidtech.com/blog/tag/exploitation/" class="st_tag internal_tag" rel="tag" title="Posts tagged with exploitation">exploitation</a> of a vulnerability, then a mis-configuration is used to find a <a href="http://www.savidtech.com/blog/tag/privileged-account/" class="st_tag internal_tag" rel="tag" title="Posts tagged with privileged account">privileged account</a> user name and password, and then data is found on the network somewhere it wasn&#8217;t supposed to be that the <a href="http://www.savidtech.com/blog/tag/privileged-account/" class="st_tag internal_tag" rel="tag" title="Posts tagged with privileged account">privileged account</a> has access too.</p>
<p>Even with many controls in place you cannot always prevent a <a href="http://www.savidtech.com/blog/tag/security-breach/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security breach">security breach</a>. This is the exact reason why we recommend that <a href="http://www.savidtech.com/blog/tag/incident-response/" class="st_tag internal_tag" rel="tag" title="Posts tagged with incident response">incident response</a> policies and processes (Which should be tested like you test your Disaster Recovery processes!) should be the FIRST THING you implement when building a <a href="http://www.savidtech.com/blog/tag/security-program/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security program">security program</a> at an organization followed by detective controls such as logging to detect a breach as soon as possible.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/christian-moldes/" title="Christian Moldes" rel="tag">Christian Moldes</a>, <a href="http://www.savidtech.com/blog/tag/exploitation/" title="exploitation" rel="tag">exploitation</a>, <a href="http://www.savidtech.com/blog/tag/gladwell/" title="gladwell" rel="tag">gladwell</a>, <a href="http://www.savidtech.com/blog/tag/incident-response/" title="incident response" rel="tag">incident response</a>, <a href="http://www.savidtech.com/blog/tag/moldes/" title="moldes" rel="tag">moldes</a>, <a href="http://www.savidtech.com/blog/tag/plane-crashes/" title="plane crashes" rel="tag">plane crashes</a>, <a href="http://www.savidtech.com/blog/tag/privileged-account/" title="privileged account" rel="tag">privileged account</a>, <a href="http://www.savidtech.com/blog/tag/security-breach/" title="security breach" rel="tag">security breach</a>, <a href="http://www.savidtech.com/blog/tag/security-breaches/" title="security breaches" rel="tag">security breaches</a>, <a href="http://www.savidtech.com/blog/tag/security-program/" title="security program" rel="tag">security program</a>, <a href="http://www.savidtech.com/blog/tag/verizon/" title="verizon" rel="tag">verizon</a>, <a href="http://www.savidtech.com/blog/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/7-consecutive-errors-equals-a-security-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Survive a DDoS Extortion Attack</title>
		<link>http://www.savidtech.com/blog/network-security/how-to-survive-a-ddos-extortion-attack/</link>
		<comments>http://www.savidtech.com/blog/network-security/how-to-survive-a-ddos-extortion-attack/#comments</comments>
		<pubDate>Wed, 24 Feb 2010 18:58:09 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[ddos attack]]></category>
		<category><![CDATA[Denial of Service]]></category>
		<category><![CDATA[Denial-of-service attack]]></category>
		<category><![CDATA[extortionist]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[ransomware]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=383</guid>
		<description><![CDATA[Before the DDoS attack, the extortionist will contact the site webmaster and offer to spare them from the attack for a payment.  If the payment is not made by the given date, then the attack begins and the price usually increases.  ]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/how-to-survive-a-ddos-extortion-attack/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fhow-to-survive-a-ddos-extortion-attack%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fhow-to-survive-a-ddos-extortion-attack%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Although I think DDoS extortion is declining due to the rising lucrative <a href="http://www.savidtech.com/blog/tag/ransomware/" class="st_tag internal_tag" rel="tag" title="Posts tagged with ransomware">ransomware</a> and scareware tactics, DDoS extortion remains interesting to me due to its sheer supervillainary.  (plus the stories sound cool when you tell them). I was giving the example to a CSO I met today and after telling the story he asked, &#8220;How do I survive a DDoS Extortion Attack&#8221;, so here is how:</p>
<p>Businesses hit with these attacks have almost no reprisal to fight back and even have a disincentive to alert authorities who could work to defend against them.</p>
<p>DDoS, distributed <a href="http://www.savidtech.com/blog/tag/denial-of-service/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Denial of Service">denial of service</a>, extortion occurs when a <a href="http://www.savidtech.com/blog/tag/hacker/" class="st_tag internal_tag" rel="tag" title="Posts tagged with hacker">hacker</a> threatens to utilize a vast <a href="http://www.savidtech.com/blog/tag/botnet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with botnet">botnet</a> of many infected computers to bombard a single target online.  By using up the target’s resources to accommodate the <a href="http://www.savidtech.com/blog/tag/botnet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with botnet">botnet</a> traffic, legitimate traffic is unable to access the site, causing a denial of service.  This prevents businesses from using their website, which may be integral to their business operations.</p>
<p>Before the <a href="http://www.savidtech.com/blog/tag/ddos-attack/" class="st_tag internal_tag" rel="tag" title="Posts tagged with ddos attack">DDoS attack</a>, the <a href="http://www.savidtech.com/blog/tag/extortionist/" class="st_tag internal_tag" rel="tag" title="Posts tagged with extortionist">extortionist</a> will contact the site webmaster and offer to spare them from the attack for a payment.  If the payment is not made by the given date, then the attack begins and the price usually increases.</p>
<p>Companies have three ways to retaliate:  pay the attacker, use DDoS protection, or go to the authorities.  Unfortunately, most companies choose to simply pay the attacker since <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> is the easiest and least expensive way to fix the problem.  This only emboldens these kinds of attacks, causing more extortion on other companies.</p>
<p>It is possible to use DDoS protection to block bots, but in the extortionist will warn that if such an attempt is made then they will only increase the number of bots attacking the website, making it much more expensive to deal with.</p>
<p>Going to the authorities can be so ineffective that extortionists will not even discourage their target from doing so.  Extortion attacks usually come from other countries, usually Eastern Europe, where the FBI has little recourse.  Furthermore, businesses are afraid of reporting the crime because it could damage their brand if it got out that they were helpless against extortionists.  This makes it harder for any countermeasures to be developed since it is impossible to tell how often extortion occurs, how much money is extorted, and who are the targets of extortionists.  According to experts, every online gambling site is paying an extortion, usually around $40,000.</p>
<p>For these, reasons too often companies will simply remain quiet about the extortion and pay their fee.  The ransom is much less than the costs incurred from a denial of service attack.  Sometimes, the extortionist even gives their victim the opportunity to pay for an attack on a competitor.  Why not?  It gives the victim a chance to level the playing field and the extortionist a chance to make even more money.</p>
<p>The best way to combat attacks like these is for businesses to put aside competitive differences and share their information regarding <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> and cyberattacks with industry peers and law enforcement authorities.  But that’s never going to happen and businesses are likely to continue to fight an every-man-for-themselves battle.</p>
<p>Until then, it’s up to companies to build up internal protections and beef up their security to protect against botnet attacks. Also, if this ever starts to happen to your business you can always contact me and I can see how I can help!</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/botnet/" title="botnet" rel="tag">botnet</a>, <a href="http://www.savidtech.com/blog/tag/ddos-attack/" title="ddos attack" rel="tag">ddos attack</a>, <a href="http://www.savidtech.com/blog/tag/denial-of-service/" title="Denial of Service" rel="tag">Denial of Service</a>, <a href="http://www.savidtech.com/blog/tag/denial-of-service-attack/" title="Denial-of-service attack" rel="tag">Denial-of-service attack</a>, <a href="http://www.savidtech.com/blog/tag/extortionist/" title="extortionist" rel="tag">extortionist</a>, <a href="http://www.savidtech.com/blog/tag/hacker/" title="hacker" rel="tag">hacker</a>, <a href="http://www.savidtech.com/blog/tag/ransomware/" title="ransomware" rel="tag">ransomware</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/how-to-survive-a-ddos-extortion-attack/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Petition Congress to Step Up and Act</title>
		<link>http://www.savidtech.com/blog/network-security/petition-congress-to-step-up-and-act/</link>
		<comments>http://www.savidtech.com/blog/network-security/petition-congress-to-step-up-and-act/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 23:39:24 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=434</guid>
		<description><![CDATA[I received an email from John Zurawski at Authentify that I thought was worth posting. I personally am tired of bailing out the banks and continuing to spend tax payer money so I want to ask Congress to Step Up, start using our money for things that matter, and start to protect the end user&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/petition-congress-to-step-up-and-act/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fpetition-congress-to-step-up-and-act%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fpetition-congress-to-step-up-and-act%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>I received an email from John Zurawski at Authentify that I thought was worth posting. I personally am tired of bailing out the banks and continuing to spend tax payer money so I want to ask Congress to Step Up, start using our money for things that matter, and start to protect the end user&#8217;s by requiring the banks that don&#8217;t properly implement <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> controls to pay. John asked in his email for me to repost his email and ask others for help. Read below and if you are heading to RSA stop by the booth and sign the petition if you agree.</p>
<blockquote><p>I’m emailing to ask for your help in something that can make a difference at the <a href="http://www.savidtech.com/blog/tag/rsa-conference/" class="st_tag internal_tag" rel="tag" title="Posts tagged with RSA Conference">RSA Conference</a>.  In recent months <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a>’s become apparent that many smaller banks, credit unions and ultimately small businesses are being victimized by organized cyber criminals.  We at Authentify, along with many others, believe <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a>’s time to stop the bleeding.  The regulatory oversight of the financial services industry has plenty of “guidance”, but few actual requirements to protect their customers from sophisticated online criminals.  The breaking point has come with a bank suing <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a>’s customer for being a “cyber-victim” and asking the courts to declare its security procedures as “commercially reasonable”.  The technologies exist to prevent most malware inflicted financial losses.  <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">It</a>’s time to get Congress to get involved.  Just as the federal government is making funds available to healthcare to get health records digitized and online, <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a>’s time to use TARP funds or other sources &#8211; to REQUIRE that financial services firms protect their customers.</p>
<p>Authentify will be seeking signatures on a petition to Congress in its booth at the RSA Conference next week.  We have put this effort ahead of our new product introductions and other RSA promotions.   Please stop by Booth #732 on the Expo floor if you believe it’s never commercially reasonable to let a bank’s customer’s be victimized by malware.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/petition-congress-to-step-up-and-act/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Honeypot Reveals Password Weaknesses</title>
		<link>http://www.savidtech.com/blog/network-security/honeypot-reveals-password-weaknesses/</link>
		<comments>http://www.savidtech.com/blog/network-security/honeypot-reveals-password-weaknesses/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 16:55:27 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[honeypots]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[auditing software]]></category>
		<category><![CDATA[password crackers]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=393</guid>
		<description><![CDATA[The honeypot gathered hundreds of user names and tens of thousands of password that have been used in automated attacks.  The data told us a few things we already knew, basically that the most common password hack attempts resemble the most commonly used passwords.  But the data told us one new thing that we did not already know about password cracking.  That is, simply having a long password isn’t good enough anymore if it is still dictionary-based.  The honeypot attackers routinely used passwords 8-10 characters in length and would even try passwords 10, 15, or 20 characters long.  Also, hackers are persistent, even for using automated systems.  One tenacious attacker attempted 400,000 passwords to crack the fake FTP.
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/honeypot-reveals-password-weaknesses/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fhoneypot-reveals-password-weaknesses%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fhoneypot-reveals-password-weaknesses%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Honeypots are a lot of fun for <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> professionals.  We get to trick the tricksters who try to trick <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> systems.  These opportunities give us whitehats a chance to be a little devious for once and get in the heads of those we are protecting against.</p>
<p>So Microsoft conducted a little honeypot of their own to collect some data on the kinds of automated password attacks hackers are using to break into user accounts.  They created a fake FTP server and allowed hackers to go to town trying to crack the password for about a year.  The FTP logged and processed the information gathered by login attempts.</p>
<p>The honeypot gathered hundreds of user names and tens of thousands of password that have been used in automated attacks.  The data told us a few things we already knew, basically that the most common password hack attempts resemble the most commonly used passwords.  But the data told us one new thing that we did not already know about password cracking.  That is, simply having a long password isn’t good enough anymore if <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> is still dictionary-based.  The honeypot attackers routinely used passwords 8-10 characters in length and would even try passwords 10, 15, or 20 characters long.  Also, hackers are persistent, even for using automated systems.  One tenacious attacker attempted 400,000 passwords to crack the fake FTP.</p>
<p>The emphasis on password strengthening is now more relevant than ever with the reemergence of “L0phtCrack” – a password <a href="http://www.savidtech.com/blog/tag/auditing-software/" class="st_tag internal_tag" rel="tag" title="Posts tagged with auditing software">auditing software</a>.  L0phtCrack attempts to crack passwords at swift speeds by scanning through a dictionary of words and forming probable password guesses.  Basically, it does the exact same thing as the automated <a href="http://www.savidtech.com/blog/tag/password-crackers/" class="st_tag internal_tag" rel="tag" title="Posts tagged with password crackers">password crackers</a> the hackers use, but for whitehat purposes.  Of course, critics are worried that L0phtCrack is a double-edged sword since it could be used for that very purpose.</p>
<p>Passwords are actually the easiest security measure to ensure protection.  As long as your password follows the basic password strengthening guidelines – length, alphanumerical, case variance, special characters, etc – it should never be cracked.  At least, not by an automated tool.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/auditing-software/" title="auditing software" rel="tag">auditing software</a>, <a href="http://www.savidtech.com/blog/tag/password-crackers/" title="password crackers" rel="tag">password crackers</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/honeypot-reveals-password-weaknesses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NASA Security Embarrassment</title>
		<link>http://www.savidtech.com/blog/network-security/nasa-security-embarrassment/</link>
		<comments>http://www.savidtech.com/blog/network-security/nasa-security-embarrassment/#comments</comments>
		<pubDate>Sat, 20 Feb 2010 03:51:12 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Government Accountability Office]]></category>
		<category><![CDATA[National Aeronautics and Space Administration]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=373</guid>
		<description><![CDATA[As the report states, “NASA’s high profile and cutting edge technology makes the agency an attractive target for hackers seeking recognition, or for nation-state sponsored cyber spying.”  NASA’s security gaps make the administration susceptible to stolen data by competing space programs or private sector networks who wish to gain a competitive advantage.  At the same time, terrorist groups may use cyber attacks to disrupt or destroy NASA missions.  Still, attacks could come from identity thieves who could access sensitive employee information on NASA’s nearly 20,000 employees.
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/nasa-security-embarrassment/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fnasa-security-embarrassment%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fnasa-security-embarrassment%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>We bid for some <a href="http://www.savidtech.com/blog/tag/fisma/" class="st_tag internal_tag" rel="tag" title="Posts tagged with FISMA">FISMA</a> work at NASA so I thought I would share with everyone what NASA hasn&#8217;t been doing properly&#8230;.You might think that out of all U.S. federal agencies, NASA would be among the top ranking in cybersecurity defense.  But according to a report issued by the <a href="http://www.savidtech.com/blog/tag/government-accountability-office/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Government Accountability Office">Government Accountability Office</a>, the <a href="http://www.savidtech.com/blog/tag/national-aeronautics-and-space-administration/" class="st_tag internal_tag" rel="tag" title="Posts tagged with National Aeronautics and Space Administration">National Aeronautics and Space Administration</a> has been hit with 1,120 <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> incidents in 2007 and 2008.</p>
<p><a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">It</a> seems at NASA, malware installations, data breaches, stolen laptops, and <a href="http://www.savidtech.com/blog/tag/botnet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with botnet">botnet</a> infections are commonplace.  Among the stolen information were unencrypted data on a prototype hypersonic jet and plans for a lunar orbiter space telescope.  Some time ago, 82 NASA computers were found to be part of a Ukranian <a href="http://www.savidtech.com/blog/tag/botnet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with botnet">botnet</a> and 86 computers were infected by the Zoneback Trojan.</p>
<p>Since then, NASA was told to plug up its security holes, but the new report by the GAO says NASA has not done enough.  Apparently, it isn’t difficult for intruders to infiltrate NASA networks and steal, delete, or modify mission critical information.</p>
<p>As the report states, “NASA’s high profile and cutting edge technology makes the agency an attractive target for hackers seeking recognition, or for nation-state sponsored cyber spying.”  NASA’s security gaps make the administration susceptible to stolen data by competing space programs or private sector networks who wish to gain a competitive advantage.  At the same time, terrorist groups may use cyber attacks to disrupt or destroy NASA missions.  Still, attacks could come from identity thieves who could access sensitive employee information on NASA’s nearly 20,000 employees.</p>
<p>I believe the security gaps at NASA put our national interests at risk and weaken the strategic technological advantage of the US.  But, simply the existence of these security holes creates an embarrassing situation which may embolden hackers to increase their attacks on other government agencies.  After all, if security is so poor at NASA then how much better could it be at crucial military organizations?</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/fisma/" title="FISMA" rel="tag">FISMA</a>, <a href="http://www.savidtech.com/blog/tag/government-accountability-office/" title="Government Accountability Office" rel="tag">Government Accountability Office</a>, <a href="http://www.savidtech.com/blog/tag/national-aeronautics-and-space-administration/" title="National Aeronautics and Space Administration" rel="tag">National Aeronautics and Space Administration</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/nasa-security-embarrassment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
