Everyday there is news of a security breach. A hacker has attacked a website with a DDoS or malicious code has infected an employees' computer and has spread to the rest of the office. These types of security breaches may not have happened to you, but they do happen and eventually they will happen to your network. The question is: Are security events such as these or others completely preventable? The answer is no, however what we can do is help mitigate these types of events by applying a simple security axiom I have taught for many years in my security classes. "Ease of Use vs. Secure"
IT security departments constantly are torn between business directives and security directives. On one hand administrators need to balance the needs of users with the needs of security. The two work in a vacuum most of the time in IT. If something is done in IT that is considered "Ease of Use" meaning its easy for the administrator to create or implement then it probably is not very "Secure". On the other hand if something is "Secure" it is likely to be more intensive to create or implement and not very easy for users to use.
As you can see in diagram above, with "Ease of Use" on one end and "Secure" on the other, business needs for users tend to be less restrictive while IT needs tend to be more secure. If IT implements things that satisfy user needs and not security needs, eventually there will be a breach. However there can be a happy medium between the two so that security breaches are less likely to happen.
Lets take a look at an IT practice to see how this really works.
Last month Vodafone learned a hard lesson about users sharing passwords that access a customer database. Vodafone's Breach
Vodafone's practice of allowing shared passwords with the company (Ease of Use) was easier for users and administrators, however it was not a secure practice. Although Vodafone rectified the issue, it should have never been allowed to happen in the first place. Does your company practice "Ease of Use or Secure"?
Wednesday, February 16, 2011
Wednesday, February 2, 2011
Eccouncil is now offering a chance to be a part of the new CEH v.7 course.
Register for the new Eccouncil Certified Ethical Hacker v.7 http://bit.ly/eOdgv6
Register for the new Eccouncil Certified Ethical Hacker v.7 http://bit.ly/eOdgv6
Thursday, December 23, 2010
What exactly is a Zero Day attack?
This is a question I get all the time from clients and students. I tell them a "zero day attack" is when a vulnerability is discovered in an application or an OS and is unknown to the vendor or general public and a patch has yet to be released to fix it. The term zero day indicates basically that the attack could happen anytime because the system does not have a patch to fix the vulnerability.
Zero day attacks are the worst situation for security folks because we just do not know when said attack will happen. We are left in kinda of a limbo wondering if and when the attack might happen to our systems.
Here is a current example:
1) Microsoft has a known vulnerability in IE 8 for certain OS's. The vulnerability may allow an attacker to create a cross site scripting (XSS) attack to gain access to a system. Microsoft has not issued a patch but is investigating the issue. link:
2) Vuepen Security has confirmed that this is a vulnerability. link:
3) Metasploit also has included this vulnerablity and the actual code to exploit it in there latest release of Metasploit as well. link:
(By the way if you are not familiar with Metasploit check out my video. link)
The only good news is that we can use Metasploit to test if our systems are vulernable to the attack, the bad news is hackers can also use Metasploit to attack a system. This is what makes a zero day attack so dangerous.
Only time will tell on a zero day attack.
Zero day attacks are the worst situation for security folks because we just do not know when said attack will happen. We are left in kinda of a limbo wondering if and when the attack might happen to our systems.
Here is a current example:
1) Microsoft has a known vulnerability in IE 8 for certain OS's. The vulnerability may allow an attacker to create a cross site scripting (XSS) attack to gain access to a system. Microsoft has not issued a patch but is investigating the issue. link:
2) Vuepen Security has confirmed that this is a vulnerability. link:
3) Metasploit also has included this vulnerablity and the actual code to exploit it in there latest release of Metasploit as well. link:
(By the way if you are not familiar with Metasploit check out my video. link)
The only good news is that we can use Metasploit to test if our systems are vulernable to the attack, the bad news is hackers can also use Metasploit to attack a system. This is what makes a zero day attack so dangerous.
Only time will tell on a zero day attack.
Monday, November 8, 2010
Now is the time to start thinking about 2011 goals for the year
As we approach the end of the year, its that time again when when we all look back over the year and see if we accomplished our goals for the year. What goals did you set for yourself? What goals do you want to accomplish for next year?
I am hoping in the next few weeks myself to get my 2011 business plans ready as well as some of my personal goals.
Good luck...Tom
I am hoping in the next few weeks myself to get my 2011 business plans ready as well as some of my personal goals.
Good luck...Tom
Friday, September 17, 2010
Remote Training: The Training Solution You May Be Missing Out On - An instructors point of view. http://bit.ly/cMGzwy
Remote training has changed over the years. Come read about it from an instructors point of view.
Saturday, September 11, 2010
Security+ - Do you really need this certification?
In the past year I have been asked a couple of questions regarding the Security+ certification. "I already have experience, why do I need to get Security+ certified? or "Is the Security+ certification worth anything anymore?" The answer to both questions is a definite yes.
Over the past 10 years security has become a very prominent part of IT. The need for well qualified individuals in security has increased. There is not not one company that is not thinking about security. Security has come to the forefront of IT due to the increased exposure to networks. The exposure comes from the internet. With all of this exposure comes the need to protect our personal and company assets.
So, how does the Security+ certification play a role helping protect our personal and private networks? Knowlege knowledge and more knowledge. That is the answer.
IT security is not just limited to single area of knowledge. It actually encompasses all areas of IT. Think about all the different systems, applications and OS's your company has running? All of those have different needs for security. So to be in security means to be knowledgeable in a lot of areas of IT.
Security+ certification provides you with exposure to all of the different areas of security for different systems, application and OS's. No, it does not mean you will be an expert in security for all of these systems, but it does mean you will have exposure and an understanding of what it means to secure these systems.
Security is a journey not a destination. There is not one person who knows everything about security. Security knowledge comes from knowing how to defend your systems against different types of threats.
However for some, network defense comes from knowing how a system or OS works.
Security+ provides that base knowledge for security, network defense and hardening systems. You could say it is a mile wide and a 2 inches deep. Once you have the exposure to this knowledge then you can go into one of many areas of security such as: ethical hacking, firewalls, IDS, IPS, security policies, Cisco routers and switches or internet security.
As for the question is the Security+ certification worth anything? Just ask anyone in the military or government who has to work on a secure system. They are now required to be Security+ certified to work on said systems.
So if you are looking to get into security or need to start getting certified in security for other areas. The Security+ certification is the place to start.
If you have any questions about Security+ certified, please feel free to contact me.
For more information on Security + click here.
Over the past 10 years security has become a very prominent part of IT. The need for well qualified individuals in security has increased. There is not not one company that is not thinking about security. Security has come to the forefront of IT due to the increased exposure to networks. The exposure comes from the internet. With all of this exposure comes the need to protect our personal and company assets.
So, how does the Security+ certification play a role helping protect our personal and private networks? Knowlege knowledge and more knowledge. That is the answer.
IT security is not just limited to single area of knowledge. It actually encompasses all areas of IT. Think about all the different systems, applications and OS's your company has running? All of those have different needs for security. So to be in security means to be knowledgeable in a lot of areas of IT.
Security+ certification provides you with exposure to all of the different areas of security for different systems, application and OS's. No, it does not mean you will be an expert in security for all of these systems, but it does mean you will have exposure and an understanding of what it means to secure these systems.
Security is a journey not a destination. There is not one person who knows everything about security. Security knowledge comes from knowing how to defend your systems against different types of threats.
However for some, network defense comes from knowing how a system or OS works.
Security+ provides that base knowledge for security, network defense and hardening systems. You could say it is a mile wide and a 2 inches deep. Once you have the exposure to this knowledge then you can go into one of many areas of security such as: ethical hacking, firewalls, IDS, IPS, security policies, Cisco routers and switches or internet security.
As for the question is the Security+ certification worth anything? Just ask anyone in the military or government who has to work on a secure system. They are now required to be Security+ certified to work on said systems.
So if you are looking to get into security or need to start getting certified in security for other areas. The Security+ certification is the place to start.
If you have any questions about Security+ certified, please feel free to contact me.
For more information on Security + click here.
ISC2 - CISSP Exam - Kansas City
The CISSP exam has been put on the schedule for Nov 6, 2010. This is great news because I will be teaching a CISSP review course at Centriq Training the week of Oct 25th.
If you are thinking about trying for the exam this fall, this will be your last chance for the exam to be Kansas City this year.
Subscribe to:
Posts (Atom)
