Friday | 4 July, 2008
CSO

Access Control

News
  • +

    Malware, spam, botnets growing faster than ever before 25/06/2008 11:23:53

    More doom and gloom from security companies.
    The spam and malware tsunami continues to cast a mounting shadow over the Internet this week.
  • +

    CNET employees notified after data breach 24/06/2008 10:07:05

    CNET employees and relatives are being notified after a data breach at the company's health plan administrator.
    More than 6,500 CNET Networks employees and relatives are being notified of a possible data breach after burglars stole computer systems from the offices of the company that administers the Internet publisher's benefit plans.
  • +

    Major security sites hit by XSS bugs 12/06/2008 08:43:15

    Security sites could be used to spread malware, finds report.
    The Web sites of three of the security industry's best-known companies include security flaws that could be used to launch scams against customers, according to a new report.
  • +

    Security firm asks for help cracking ransomware key 10/06/2008 08:38:52

    New blackmailing Trojan encrypts files using high-grade 1024-bit RSA key
    A security company on Friday asked for help cracking an encryption key central to an extortion scheme that demands money from users whose PCs have been infected by malware.
  • +

    Gov grants $1.2M to train luddites 06/06/2008 15:41:25

    AusCERT caters for home users
    The federal government has today launched a $1.2 million national security alert service to round-out its plans to sanitise Internet feeds to families and small businesses.
  • +

    Five reasons SocGen did not detect that $7 billion fraud 29/05/2008 09:36:47

    How Société Générale ended up in the soup
    Paris-based bank Societe Generale made headlines when it disclosed that one of its traders made a series of unauthorized transactions over the previous few years that ultimately cost the financial institution a staggering US$7.2 billion in losses.
  • +

    Most retailer breaches are not disclosed, Gartner says 25/05/2008 08:07:19

    Most retailers do not disclose data breaches after they happen, Gartner says.
    While nearly half of U.S. retailers have been hit with some kind of information security attack, only a small percentage of them have actually reported breaches to their customers, research company Gartner reports.
  • +

    Payment collaboration to curb Internet fraud: banker 21/05/2008 14:20:33

    Internet banking an evolving landscape.
    With the business of Internet banking changing and online threats growing, the industry needs to adapt and integrate security technology across more channels and be more collaborative to reduce fraud, according to one electronic payments specialist.
  • +

    Cover all bases for proactive network security: Defence 20/05/2008 11:36:29

    Don't assume trust within the network perimeter.
    The Department of Defence has chimed in on the network security debate, stating organizations need to be more proactive if they expect to ward off attackers that readily exploit the high levels of trust usually reserved for employees and known systems.
  • +

    Senate intercepts wiretapping bill 19/05/2008 12:25:34

    Bugged devices will need a warrant
    A controversial bill to make wiretapping easier for law enforcement was shot down by Senate last week.
  • +

    Phishing botnet expands by hacking legit sites 15/05/2008 08:10:59

    Plants SQL injection attack tool on bots, hacks business, education sites
    A botnet is now using a SQL-injection attack tool designed to hack legitimate Web sites, a move meant to add more hijacked PCs to its collection, according to a security researcher.
  • +

    Hacker writes rootkit for Cisco's routers 15/05/2008 07:07:51

    A hacker has written rootkit software that works on Cisco's routers.
    A security researcher has developed malicious rootkit software for Cisco Systems' routers, a development that has placed increasing scrutiny on the routers that carry the majority of the Internet's traffic.
  • +

    Icy encryption tool protects laptops from "cold boot" attack, vendor says 14/05/2008 08:36:43

    Vulnerable encryption keys erased by HyBlue's IceLock
    The vendor HyBlue says it can prevent the "cold boot" encryption hack discovered by Princeton researchers with a laptop security product announced Tuesday.
  • +

    How one site dealt with SQL injection attack 02/05/2008 08:34:08

    SQL injection attacks claim a victim
    The massive wave of SQL injection attacks that started striking Microsoft-based Web sites around the world more than a week ago claimed as one of its victims Autoweb, a UK-based advertising and marketing site.
  • +

    INTEROP - US Bank suffers Web 2.0 security headaches 01/05/2008 08:01:05

    iPhones and smartphones invade the security perimeter
    It used to be easy for US Bank to determine which users and systems could be trusted, and which should be viewed with suspicion. Then along came Web 2.0.
Features
  • +

    Four signs your security program's gone too far 25/06/2008 10:34:19

    Our columnist suggests when it might be time to dial back a bit
    When risk is present it calls for treatment, and security is a never-ending process... right? Yes, but as a security professional, it's easy to become focused on the hard problems (download PDF) of security -- falling into the arms race for more, more, more security controls -- and lose sight of the impact of the controls themselves.
  • +

    Six burning questions about network security 06/06/2008 09:56:44

    Security issues often seem to smolder more than burn, but these six are certainly capable of lighting a fire under IT professionals at a moment's notice.
    Security issues often seem to smolder more than burn, but these six are certainly capable of lighting a fire under IT professionals at a moment's notice. Handle with care.
  • +

    Five effective ways to burglar-proof your laptop 05/06/2008 07:55:35

    Five easy - yet effective - strategies to protect your laptop and the valuable data stored in it
    Theft of laptops and other mobile devices is spiraling, and the consequences -- financial and other -- are getting increasingly dire.
  • +

    Six hours to hack the FBI (and other pen-testing adventures) 28/05/2008 08:03:59

    White-hat hacker pros dish on top traumas and shocking snafus
    It takes a lot to shock Chris Goggans; he's been a pen (penetration) tester since 1991, getting paid to break into a wide variety of networks. But he says nothing was as egregious as security lapses in both infrastructure design and patch management at a civilian government agency -- holes that let him hack his way through to a major FBI crime database within a mere six hours.
  • +

    Five steps to successful and cost-effective penetration testing 28/05/2008 08:57:20

    Spending your time and money well
    Whether you hire outside consultants or do the testing yourself, here are some tips for making sure your time and money are well spent.
  • +

    Five free pen-testing tools 28/05/2008 09:04:38

    The best things in life are ...
    Security assessment and deep testing don't require a big budget. Some of most effective security tools are free, and are commonly used by professional consultants, private industry and government security practitioners. Here are a few to start with.
  • +

    20 useful IT security Web sites 08/04/2008 09:50:41

    How to foil hackers, protect users and prepare for the inevitable robot uprising
    Bookmarking these sites will help you protect your network, comply with government regulations and stay ahead of all the latest threats.
  • +

    How to fashion a 'security first' enterprise 19/03/2008 10:29:45

    When security pros think business, the business thinks security
    These forward-thinking IT managers are working at dismantling the stereotype of the risk-averse security professional-cum-business foe. How? By showing business colleagues they understand company operations and appreciate corporate goals.
  • +

    The top 10 security land mines 18/03/2008 10:45:07

    The 10 most common security land mines that experts say you need to avoid.
    Many companies spend a small fortune and deploy a small army to secure themselves from the many security threats lurking these days. But all those efforts can come to naught when making any of these common mistakes. The results can range from embarrassing to devastating, but security experts say that all are easily avoidable.
  • +

    Casino insider tells (almost) all about security 10/03/2008 07:56:55

    Engineer built systems used by up to half the world’s casinos
    Jeff Jonas knows the Las Vegas gambling industry inside and out. As the founder and chief scientist of Systems Research & Development (SRD), Jonas helped build numerous casino systems before 2005 when his company was purchased by IBM.
  • +

    Integration problems arise with DLP tools 15/02/2008 09:19:32

    Early adopters of data leakage prevention systems, including financial services giants, are having problems enforcing security policies consistently across the different areas of DLP.
    Vendors of data leakage prevention (DLP) systems claim that customers will avoid integration issues by using packaged tools that encompass all the different elements of the technology, but some early adopters of DLP are already running into serious problems.
  • +

    Entitlement management: Access control on steroids 04/12/2007 10:47:33

    Entitlement management tools bring fine-grained access control to another level
    Faced with looming regulations such as the Health Insurance Portability and Accountability Act and the Sarbanes-Oxley Act, Craig Shumard, chief information security officer for healthcare provider Cigna, knew he needed better tools for role-based access control.
  • +

    The top 10 reasons Web sites get hacked 05/10/2007 10:27:37

    Web developers ignore security flaws at customers' peril
    Web security is at the top of customers' minds after many well-publicized personal data breaches, but the people who actually build Web applications aren't paying much attention to security, experts say.
  • +

    FAQ on NAC 04/01/2007 08:00:37

    Explanations that may clarify some of your questions about network access control
    Network access control stands out as one of the most promising security technologies, but it also is one of the most misunderstood. Here are explanations that may clarify some of your questions.
  • +

    E-commerce in crisis: When SSL isn't safe 17/05/2006 12:24:59

    A secure connection between browser and back end underlies Internet commerce. But what if it's already compromised?
Case Studies
Opinions
  • +

    Hacking tools: A new version of BackTrack helps ethical hackers 30/06/2008 10:57:21

    BackTrack is the quickest way to get access to hundreds of (legal) hacking tools
    Version 3.0 of BackTrack has been released. BackTrack is a Linux-based distribution dedicated to penetration testing or hacking (depending on how you look at it). It contains more than 300 of the world's most popular open source or freely distributable hacking tools.
  • +

    Online poker cheating demonstrates insider risk 18/06/2008 15:55:02

    Poker cheats are using insider knowledge to gain competitive advantage.
    When determining the risk to a system and the data stored on it, insider threats are generally regarded as lower risk. Despite the complete access (high risk) that insiders generally have, most of the time insiders are trusted agents (very low risk) on the network. When it breaks down, it can break down in a catastrophic manner, especially if there is money at stake.
  • +

    A resurgent Denial of Service threat emerges 11/06/2008 19:12:24

    Something new might be emerging from the underground.
    A less known part of the recent ARP attack against H D Moore's MetaSploit site was an attempted Denial of Service attack that coincided with the successful ARP attack.
  • +

    Security in a bubble 19/03/2008 11:03:54

    Security must be distributed, ubiquitous and pervasive
    People don't notice change when it's gradual. Sometimes, however, small, incremental changes add up in a way that isn't noticed until a change in degree becomes a change in kind.
  • +

    How to limit what contractors can do on the network 17/07/2007 10:15:02

    Some ways to implement controls for contractors
    Question: We have contractors perform a number of critical services, such as managing our IBM blade servers. These staff have to be on the LAN, and they're long-time contractors, so trust levels run pretty high, but I know they shouldn't be able to go everywhere on the LAN. How can I limit their access while still letting them do their jobs, and most important, not making them feel like I don't trust them?
Reviews
  • +

    Check Point and Sygate corral end points 28/12/2005 07:00:13

    Firewalls combine strong client security and flexible policy management
    At their core, Check Point Integrity and Sygate Enterprise Protection are effectively policy-based firewalls. That's the cake. The icing is their capability to monitor other applications for compliance with configuration requirements and send errant machines to quarantine until they can be updated with the latest anti-virus definitions, Windows patches, or other necessities.
Additional Resources

Newsletter Subscription

Sign up for our CSO Online newsletters!
CSO Online's weekly briefing for data security executives helps identify the data security factors that put business success at risk, and offers technical, operational or procedural safeguards.
RSS Feeds
Market Place

CSO Online Member Login

 
Sponsored Links