<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: traditional]]></title>
    <link>http://securityratty.com/tag/traditional</link>
    <description></description>
    <pubDate>Mon, 28 Jul 2008 17:54:32 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[ScienceLogics 5-Year Anniversary]]></title>
      <link>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</link>
      <guid>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</guid>
      <description><![CDATA[August 2003. The largest blackout in U.S. history darkens the Northeast and Midwest, the Blaster worm has been unleashed and Madonna and Britney create a stir at the 2003 MTV Music Video Awards . In...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="164" alt="B-day Cake" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/b-day-cake1.jpg" width="244" align="left" border="0"> August 2003. The largest <a href="http://blogs.wsj.com/biztech/2008/08/13/celebrating-the-anniversary-of-the-big-blackout/?mod=djemTECH" target="_blank">blackout</a> in U.S. history darkens the Northeast and Midwest, the <a href="http://news.cnet.com/2010-1001-5117862.html" target="_blank">Blaster worm</a> has been unleashed and Madonna and Britney create a stir at the <a href="http://en.wikipedia.org/wiki/2003_MTV_Video_Music_Awards" target="_blank">2003 MTV Music Video Awards</a>. In the midst of this <a href="http://www.grid.unep.ch/product/publication/download/ew_heat_wave.en.pdf" target="_blank">hot summer</a> madness, ScienceLogic was founded.
<p>To kick off our celebration of our first five years, we asked <a href="http://www.sciencelogic.com/leadership.htm" target="_blank">ScienceLogic founders</a> Dave Link, Richard Chart and Chris Cordray for their thoughts and memories on events leading to today’s milestone. How and why did they set out on this venture? What happened along the way – expected and unexpected? Why were they successful in times when other new (and established) businesses have come and <a href="http://en.wikipedia.org/wiki/Category:2003_disestablishments" target="_blank">gone</a>?
<p><b>How did you three put together this team?</b>
<p>We all worked together at a large Managed Service Provider for a couple of years before leaving to start ScienceLogic, so we all knew each other and knew our collective strengths. More importantly, each of us had worked with network management tools on some level (sales and marketing, engineering and product development), and knew first-hand all of the customer pain points, from every perspective. So we left and began rapidly figuring out how to build a better network management solution based upon our real world operational experience..
<p><strong>Dave:</strong> One interesting aspect is that our areas of expertise don’t overlap, which has contributed to our success. Chris is excellent with developing the product front-end and interface, Richard handled the backend architecture and engineering and I focused on the technical business side of sales and marketing. Our roles have been to build a product that works well and that provides real value to operations teams that experience the same day to day frustrations that we felt.<b></b>
<p><b>Whose idea was it to start the company?</b>
<p><strong>Dave:</strong> It was really a collective effort. We were all passionate about “getting it right” and not just starting a company. We knew the industry need and between us, we had the knowledge and skill sets to address all of the right aspects of developing a product and a building a business around it.
<p><b>What process did you go through to get started?</b>
<p><strong>Richard:</strong> From the beginning we knew the type of solution the market needed and we knew that we wanted to build it as an appliance. From different vantage points, we had each experienced the effects of long, difficult and expensive installations that still exist with traditional network tools. Every install has unique variations: there are always different server types, varying hardware and software versions, different patches installed, and on and on. Every installation was time consuming and unpredictable. We knew that an appliance model would address all of these variables and save a lot of time on how quickly customers could achieve immediate value.
<p>The harder decisions were around actually starting the business, assessing the market and of course determining the product pricing.
<p><b>EM7 completely flips the traditional model of complex, lengthy and expensive deployments. How did you convince others that the EM7 Meta-Appliance product was valid?</b>
<p><strong>Dave:</strong> Yes, EM7 totally disrupts the traditional model for network management. While others take a narrow approach, we intentionally designed EM7 to focus on the broad problem – managing the data center. How do you cover a variety of technologies and make sure they work seamlessly together? The vision was to make it easier, not harder, for customers.
<p><strong>Chris:</strong> I have to give it to Dave – very early on, he realized the power of a demo. If Dave could get in front of someone, he’d make them a believer. He’d use the Peter Falk/Columbo technique of “let me show you one more thing.” It was very effective. It’s getting easier, but even today people sometimes have to see EM7 in action before they become believers.
<p><b>Can you describe the early days of running a new business?</b>
<p><strong>Dave:</strong> ScienceLogic is a classic case of entrepreneurship. For the first year we worked out of our basements. We kept the costs low in every conceivable way and spent the first year developing the product before we even made a sale.
<p><strong>Chris:</strong> We stayed at lots of odd places when we were on the road, took cheap flights with multiple layovers and purchased lots of our first test equipment on eBay. This was during the dot-com bust so there was lots of equipment for sale on eBay, really cheap!
<p><strong>Richard:</strong> The amount of equipment I had in my house was absolutely crazy. Back then, servers were huge – I had a Cisco 6509 Catalyst, a Compaq Proliant DL380, Brocade switch, IBM Netfinity 4500R, and tons of other machines.
<p><strong>Chris:</strong> I had to install a new circuit box at home because I was blowing breakers. I remember when that 6509 crashed, we revived it and it died again. The second death was final.
<p><b>So you started in your houses – what was your first office space?</b>
<p><strong>Dave:</strong> My friend, the CEO at Ernst &amp; Young Technology had a few extra cubes and a data center in their office that they graciously allowed us to use. Their help was an important step in helping us really formalize the business. We started doing well and adding people, but ironically, their company was downsizing. Before long, many of their original YET people were gone and the ScienceLogic team kept growing in to the open cubes.
<p>Our first leased space was converted warehouse space in Chantilly, VA that once housed an internet radio station. It was cool – it had a large salt water fish tank, a loft, a spiral staircase and a Star Trek door that retracted into the walls with the customary lights and “whooshing” sound.
<p>We outgrew the Chantilly space, leading to our current office in Reston, VA.
<p><b>Who was the first ScienceLogic customer?</b>
<p>Our first paying customer was <a href="http://martinspoint.com/" target="_blank">Martins Point Health Care</a>. We deployed there in July 2004 and are pleased to say they continue to be a ScienceLogic customer. Other early (and still) EM7 <a href="http://www.sciencelogic.com/customers.htm" target="_blank">customers</a> include Navy Knowledge Online and the Department of Transportation. Nearly all of our customers are still actively using EM7 and renewing their maintenance.
<p><b>Where do you see the company in the next 5, 10 or 15 years?</b>
<p>Well, our revenue has doubled year-over-year in each of the last three years, so of course we’d like to continue to grow like that or even faster. In five years we’ve gone from three founders to the point where Dave does not know everyone’s fondest childhood memory. We’ll continue to scale our growth to cover the demands of our growing customer base.
<p><b>Where do you see the industry going over the coming years?</b>
<p><strong>Chris:</strong> IT is always moving and gaining in complexity, so network management is also becoming more complicated. There’s increasing diversity, new standards, virtualization and cloud computing. All of these are today’s technologies. Customers have a mix of the old and the new, so EM7 has to accommodate and support both.
<p><strong>Richard:</strong> Each generation of products has a new set of ways to monitor, but the “old” doesn’t go away. Even when a new, hot technology comes along, the old technologies still need to be supported. We work to ensure EM7 keeps up with both.
<p><strong>Dave:</strong> After five years we’re just hitting our stride and we’re just now reaching the tipping point in awareness of ScienceLogic and EM7. We’re all still passionate about the product and as Chris and Rich said, there’s still a lot do. We’ll continue disrupting the market with EM7. Our vision hasn’t changed, and with the increasing levels of automation that customers demand, the market needs are greater than ever. Our future is as bright, or brighter, than ever and we’ll continue to be looking for smart ways to automate traditionally manual IT Operations processes.
<p><b>What’s your advice for someone interested in starting their own business?</b>
<p><strong>Chris:</strong> Be passionate. That’s what has gotten me through the tough times. I didn’t really appreciate this thought when I heard others say it before. But it’s very true.
<p><strong>Richard:</strong> I agree. We met and talked with lots of people who told us, “That’s been done before.” But we kept going because we truly believed in what we were doing and we knew that while our approach was different, that it would be successful.
<p><strong>Richard:</strong> Be fearless. You can’t be too nervous and you need to be able to expect and handle the stress because it will be there. You have to learn to accept the stressful times as a necessary part of the process of starting out on your own.
<p><strong>Dave:</strong> Know your niche from the beginning and give potential customers a compelling reason to trust you and really benefit from your solution. You have to know the problem, see the gap and have a clear and consistent vision of how to solve the problem. Then you have to execute. If you don’t build your team with “doers” you won’t make it.
<p><strong>Chris:</strong> It helps to have friends. ScienceLogic was built on friendships and relationships, starting with the three of us. If you look at our team, most of our hires are referrals – people who developed and maintained great connections with other great people throughout their careers. Maintain your connections and keep in touch with your network of friends.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 18:39:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7 completely flips">em7 completely flips</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/network management tools">network management tools</category>
      <category domain="http://securityratty.com/tag/em7 meta-appliance product">em7 meta-appliance product</category>
      <category domain="http://securityratty.com/tag/sciencelogic team">sciencelogic team</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <category domain="http://securityratty.com/tag/product front-end">product front-end</category>
      <source url="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008">ScienceLogics 5-Year Anniversary</source>
    </item>
    <item>
      <title><![CDATA[How I became a soldier in the Georgia-Russia cyberwar.]]></title>
      <link>http://securityratty.com/article/cb0690279b2cb6030191ba8c0c9a09d8</link>
      <guid>http://securityratty.com/article/cb0690279b2cb6030191ba8c0c9a09d8</guid>
      <description><![CDATA[As Russian and Georgian troops fight on the ground, there's a parallel war happening in cyberspace. In recent weeks, Georgia's government Web sites have been besieged by denial-of-service attacks and...]]></description>
      <content:encoded><![CDATA[As Russian and Georgian troops fight on the ground, there's a parallel war happening in cyberspace. In recent weeks, Georgia's government Web sites have been besieged by denial-of-service attacks and acts of vandalism. Just like in traditional warfare, there's a lot of confusion about what's going on in this technological battle—nobody seems to kno]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 04:20:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgian troops fight">georgian troops fight</category>
      <category domain="http://securityratty.com/tag/government web sites">government web sites</category>
      <category domain="http://securityratty.com/tag/traditional warfare">traditional warfare</category>
      <category domain="http://securityratty.com/tag/parallel war">parallel war</category>
      <category domain="http://securityratty.com/tag/technological battlenobody">technological battlenobody</category>
      <category domain="http://securityratty.com/tag/recent weeks">recent weeks</category>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/cyberspace">cyberspace</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <source url="http://digg.com/security/How_I_became_a_soldier_in_the_Georgia_Russia_cyberwar">How I became a soldier in the Georgia-Russia cyberwar.</source>
    </item>
    <item>
      <title><![CDATA[Reporters Tossed Out of BlackHat for Hacking Other Press Reps]]></title>
      <link>http://securityratty.com/article/9247e7106cfa1fd62a6d8c951ca64e5c</link>
      <guid>http://securityratty.com/article/9247e7106cfa1fd62a6d8c951ca64e5c</guid>
      <description><![CDATA[Security folks seem to enjoy their jobs making a game of penetration tests, hacking, and in good natured fun, reminding each other when theyre vulnerable online. So at the Black Hat conference this...]]></description>
      <content:encoded><![CDATA[<p>Security folks seem to enjoy their jobs &#8212; making a game of penetration tests, hacking, and in good natured fun, reminding each other when they&#8217;re vulnerable online. So at the Black Hat conference this week, wireless network users were warned that if they didn&#8217;t use an encrypted connection, their data, credentials and passwords would be projected on a wall for all to see.</p>
<p>The baaad folks who were listed up on this &#8220;Wall of Sheep&#8221; consisted largely of security professionals who should know better, though many of them were using iPhones or other types of mobile devices instead of traditional laptops. Apparently, users were warned ahead of time that this could happen, and this type of passive hacking was done good naturedly, as a lesson and a point of humor.</p>
<p>But the event turned a bit sour when some reporters set out to actively hack credentials and passwords from other well known press representatives (like eWeek and CNET), in order to post them on the Wall of Sheep, too. It&#8217;s a credit to the Black Hat organizers that they showed their commitment to security and confidentiality, and threw the reporter-hackers out of the conference for their &#8220;active&#8221; hack:</p>
<blockquote><p>With thousands of hackers milling around the Black Hat convention here, and widespread snooping on the public WiFi network, one place was supposed to be off limits: the press room.</p>
<p>But in a case of reporters spying on other reporters, three journalists working for the French publication Global Security Magazine were booted Thursday from the hackers&#8217; conference after they were allegedly caught hacking into the private computer network set up for the media.</p></blockquote>
<p>Read the <a rel="nofollow" target="_blank" href="http://www.washingtonpost.com/wp-dyn/content/article/2008/08/08/AR2008080800003.html">full article</a> here.</p>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 09:02:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/reporters">reporters</category>
      <category domain="http://securityratty.com/tag/press">press</category>
      <category domain="http://securityratty.com/tag/conference">conference</category>
      <category domain="http://securityratty.com/tag/black hat conference">black hat conference</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/credentials">credentials</category>
      <category domain="http://securityratty.com/tag/actively hack credentials">actively hack credentials</category>
      <category domain="http://securityratty.com/tag/reporters set">reporters set</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/359746131/">Reporters Tossed Out of BlackHat for Hacking Other Press Reps</source>
    </item>
    <item>
      <title><![CDATA[Traditional Disaster Recovery Services Are Dead]]></title>
      <link>http://securityratty.com/article/91a8e062482df48ac9d61748458d67d9</link>
      <guid>http://securityratty.com/article/91a8e062482df48ac9d61748458d67d9</guid>
      <description><![CDATA[If you still subscribe to fixed site recovery services using shared IT infrastructure from the likes of HP, IBM BCRS, or SunGard, among others, you will quickly become a dinosaur in the next 1 to 2...]]></description>
      <content:encoded><![CDATA[<p><img border="0" title="Stephanie Balaouras" alt="Stephanie Balaouras" src="http://www.forrester.com/role_based/images/author/imported/forresterDotCom/Analyst_Photos/Silhouette/Color/Stephanie-Balaouras.gif" style="margin: 0px 5px 5px 0px; float: left;" /></p>

<p><span style="font-size: 10pt; font-family: Arial;">If you still subscribe to fixed site recovery services using shared IT infrastructure from the likes of HP, IBM BCRS, or SunGard, among others, you will quickly become a dinosaur in the next 1 to 2 years. </span></p>

<p><span style="font-size: 10pt; font-family: Arial;">These types of shared infrastructure services involve lengthy restores from tape and a recovery time objective of 72 hours, at best. Plus, you'll be lucky if you recover at all because chances are, you've had trouble scheduling a test with your service provider and it's been a LONG time since the last one, if indeed you’ve ever tested. </span></p>

<p><span style="font-size: 10pt; font-family: Arial;"><a href="http://www.forrester.com/go?docid=46270">72 hours recovery just doesn't cut it anymore</a>. And frankly, understanding your provider's oversubscription ratio to shared infrastructure to determine the risk of multiple invocations, or attempting to negotiate exclusions zones and availability guarantees is a time suck. Most companies are either taking DR back in-house or, if they still rely on a DR service provider, they are using dedicated infrastructure.</span></p>

<p><span style="font-size: 10pt; font-family: Arial;">A dedicated infrastructure is attractive as it enables replication to improve recovery objectives. But it’s expensive, and puts advanced IT recovery out of the reach of many companies who can't measure downtime in millions of dollars.</span></p>



<p><span style="font-size: 10pt; font-family: Arial;">But, there are new services on the horizon that will make advanced IT recovery affordable for the masses. This month SunGard announced the availability of its new Virtual Server Replication Service. As I discussed in my most recent <a href="http://www.forrester.com/go?docid=44878">Forrester Wave™ of DR Service Providers</a> and <a href="http://www.forrester.com/go?docid=42944">other reports</a>, server virtualization is transforming IT recovery. With replication to a virtualized server infrastructure and shared storage infrastructure, customers can enjoy improved recovery-time and recovery-point objectives without the cost of dedicated and custom IT recovery solutions from the <span class="hilite">DR</span> services provider.SunGard is the first DR service provider to productize these virtual services. I expect other DR service providers to follow suit. <br /></span></p>

<p><span style="font-size: 10pt; font-family: Arial;">So, the next time your contract is up for renewal, you need to completely rethink your approach to IT recovery. Get off tape and move to these new virtual services. It will improve your recovery capabilities and you don't have to worry about the oversubscription issue with shared virtual infrastructure -- the DR provider can manage capacity much more easily in this environment. In fact, SunGard is offering an RTO SLA of 6 hours as part of the offering. To my knowledge, this is the first time a DR service provider is offering this as part of a standard contract. I'm looking forward to the day when vendors will offer most services with transparent, subscription-based pricing, and standard contract terms that don't take a team of procurement professionals to negotiate.<span face="Times New Roman">&nbsp;</span><span style="font-size: 10pt; font-family: Arial;"><street w:st="on"></street></span></span></p>]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 13:06:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/recovery">recovery</category>
      <category domain="http://securityratty.com/tag/recovery time objective">recovery time objective</category>
      <category domain="http://securityratty.com/tag/recovery-time">recovery-time</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/recovery affordable">recovery affordable</category>
      <category domain="http://securityratty.com/tag/recovery capabilities">recovery capabilities</category>
      <category domain="http://securityratty.com/tag/recovery solutions">recovery solutions</category>
      <category domain="http://securityratty.com/tag/provider">provider</category>
      <category domain="http://securityratty.com/tag/recovery-point objectives">recovery-point objectives</category>
      <source url="http://blogs.forrester.com/srm/2008/08/traditional-dis.html">Traditional Disaster Recovery Services Are Dead</source>
    </item>
    <item>
      <title><![CDATA[Security Through Visibility - Montego, Lancope and NetFlow]]></title>
      <link>http://securityratty.com/article/03c1f11d6787944e11b9ab1baec0352e</link>
      <guid>http://securityratty.com/article/03c1f11d6787944e11b9ab1baec0352e</guid>
      <description><![CDATA[We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments. This is because it is extremely challenging to see...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments.&nbsp; This is because it is extremely challenging to see what is going on at a micro vs. macro level within a virtual environments network.&nbsp; The virtualization vendors such as VMWare and Citrix have provided embedded tools into their management consoles that show a macro level of visibility but its not enough to identify security events in the environment.&nbsp; Take a look at the attached picture.&nbsp; It simply shows VMWare's ability to monitor virtual network performance statistics from a bits per second perspective.</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/performancescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Performancescreen" title="Performancescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/performancescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
<br />&lt;-Click To Enlarge</p>

<p>With only this level of detail how can one determine which network applications are causing spikes.&nbsp; Is it FTP traffic that is occuring at a high volume at an unuseal time of day?&nbsp; If that were occuring, could that be indicative of either a breach or some sort of problem? What if FTP isn't even an authorized service in the virtual environment but there is a high volume of it?&nbsp; Did someone install a rouge FTP service so they could steal information from the server at will? </p>

<p>These types of questions can't really be answered without a micro level of detail into the packets flowing in, out and within the virtual environment.&nbsp; Now, what I am highlighting is not security in the traditional sense of prevention but using visibility as a means to first identify, then pin point the source of an issue so that it can properly be mitigated.&nbsp; Having constant visibility can also ensure that other security products in the environment are performing as expected.&nbsp; What if a Montego HyperSwitch with firewalling enabled is configured with many policies but someone forgot to create an FTP block policy.&nbsp; One could think they are protected from rouge FTP services transmiting data out of the network, but without constant visibility monitoring, can you be certain?</p>

<p>Some vendors, namely Reflex Security will get you to believe that their IPS / IDS solution that is inline and running in the virtual environment is the right and only approach.&nbsp; Or they will tell you to hang a virtual IDS off a span port in the virtual environment and you will at least have visibility into the attacks that are taking place.&nbsp; Well, sure... You now have attack visibility but at the performance cost of your virtual environment.&nbsp; Signature matching technologies are great, I'm a huge believer; however they don't scale very well in shared computing environments such as virtual ones.&nbsp; IDS systems also don't typically track protocol and network service (FTP, HTTP, etc.) utilizations; which is another important part of visibility.</p>

<p>So, what do we do to gain visibility without the performance headache?&nbsp; Well, for starters its probably best to put your IDS/IPS solutions in the physical environment where performance will be less of a concern.&nbsp; In fact, you can span a virtual switch's traffic out to a physical NIC as easy as you can to a virtual one.&nbsp; So why do it virtual and have to pay a 60% CPU utilization tax?&nbsp; Another solution is to IDS inspect only the things you care about.&nbsp; Why IDS inspect SSL traffic if you know your solution can't unencrypt SSL.&nbsp; Its just a waste of compute cycles isnt it?&nbsp; Policy based switching helps you with directing only the things you care about to an IDS (attack visualization product).&nbsp; Montego's HyperSwitch also can help you with the traffic redirection of only the things you care about. </p>

<p>Another method of visibility which I tend to be a fan of is one of packet analysis (aka NetFlow).&nbsp; NetFlow was invented by Cisco some time ago and has gained popularity in the physical world and definately has a use in the virtual world.&nbsp; NetFlow is lightweight.&nbsp; Let me say that again, its light weight!&nbsp; It only sends a summation of packet detail to an analytical engine which can do some number crunching, packet comparison, etc. etc. to make some sense out of whats going on.&nbsp; <a href="http://www.lancope.com">Lancope</a>, an Atlanta based visibility company that provides Network Visibility, Security Visibility and User Visibility has this tool on their website that is a Netflow Bandwidth calculator.&nbsp; You'll see from playing with this ( <a href="http://www.lancope.com/netflowcalculator.aspx">http://www.lancope.com/netflowcalculator.aspx</a> ) calculator that it doesn't consume a lot of network bandwidth to transmit these network accounting records.&nbsp; It also doesn't cause a lot of CPU overhead to send these records to an analytical engine sitting somewhere in the network.</p>

<p>Lancope's analytical engines have the ability to do the following for you within your virtual environment:</p><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta name="ProgId" content="PowerPoint.Slide" /><meta name="Generator" content="Microsoft PowerPoint 11" /><title><p>&lt;p&gt;Slide 3&lt;/p&gt;</p></title><meta name="Description" content="7/30/2008" /><style>
.O
	{color:black;
	font-size:149%;}
a:link
	{color:#CC9900 !important;}
a:active
	{color:#9B2D1F !important;}
a:visited
	{color:#96A9A9 !important;}
</style><style media="print">
&amp;lt;!--.sld
	{left:0px !important;
	width:6.0in !important;
	height:4.5in !important;
	font-size:103% !important;}
--&amp;gt;
</style><o:shapelayout v:ext="edit"></o:shapelayout><o:idmap v:ext="edit" data="1"></o:idmap><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9">&nbsp;</p:colorscheme><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9"><div v:shape="_x0000_s1026" class="O">

<ol><li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor and Alert network behavior of VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Track Vmotion movement of VMs accross physical servers</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor and Alert on communication between VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Identify users accessing VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Identify unauthorized or rouge VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor and Alert when VM’s go online or offline
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Identify network services running on VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor Network / Application performance of VMs<br />Display active hosts accessing VMs</span></li></ol>















<div></div>

</div>

</p:colorscheme><p>...and probably a slew of other things I'm not aware of.&nbsp; A screen shot of their product is bellow:</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/lancopescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Lancopescreen" title="Lancopescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/lancopescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a> &lt;- Click to enlarge</p>

<p>You'll notice from the screenshot that you are able to visualize who is talking to who, how much traffic they have sent and received and something called a concern index (not seen on this screenshot).</p>

<p>Now, a concern index is a number that increases as Lancopes analytical engines monitor suspicious activity on a session.&nbsp; A high counter can be indicative of a security problem.&nbsp; Its another way of identifying (visualizing) compromised hosts (virtual machines) without having to do signature matching like a heavy weight IPS engine.&nbsp; Example:&nbsp; Lets say you have a VM that has a BOT on it and is &quot;owned&quot;.&nbsp; The Lancope product is monitoring this long life session.&nbsp; Let's say that session is established for several hours or maybe even days or months.&nbsp; Lets also say that the conversation appears to be mostly unidirectional from a public ip address not belonging to your enterprise.&nbsp; Lancope would increase a the concern index on this since this server hasn't typically had this type of behavior.&nbsp; Once the concern index reached a certain level it could then fire off an email, send you a text message or something saying:&nbsp; <strong>Warning, Warning, Danger, Danger Will Robinson!!! You're virtual server may be infected with a BOT, please investigate immediately!!!</strong></p>

<p>This example is VISIBILITY which helps you with SECURITY.&nbsp; There are a number of other things you can do with NetFlow and Lancope products that have less to do with security and more to do with operational efficiencies.&nbsp; Things like, helping you answer questions of:&nbsp; How do I know what network applications are taking up the most bandwidth?&nbsp; When should I move those applications over to a server with more horsepower?&nbsp; When did these VM's vmotion over here and was there a traffic condition / CPU condition that caused that to occur?&nbsp; I could go on and on but thats a topic for another blog entry.</p>

<p>So, my suggestion is to take a look at what NetFlow has to offer.&nbsp; Montego Networks supports NetFlow transmission and Lancope supports NetFlow analytics and with both you can regain what was lost visibility.</p>

<p>I hope this was helpful to you all!</p>

<p>-John Peterson</p></div>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 17:57:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network visibility">network visibility</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/environments">environments</category>
      <category domain="http://securityratty.com/tag/virtual environments network">virtual environments network</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/network bandwidth">network bandwidth</category>
      <category domain="http://securityratty.com/tag/bandwidth">bandwidth</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <source url="http://feeds.feedburner.com/~r/SecurityInTheVirtualWorld/~3/350982407/security-throug.html">Security Through Visibility - Montego, Lancope and NetFlow</source>
    </item>
    <item>
      <title><![CDATA[Security Through Visibility - Montego, Lancope and NetFlow]]></title>
      <link>http://securityratty.com/article/5b6ed1101dc183f8ebcfa1e481566982</link>
      <guid>http://securityratty.com/article/5b6ed1101dc183f8ebcfa1e481566982</guid>
      <description><![CDATA[We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments. This is because it is extremely challenging to see...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments.&nbsp; This is because it is extremely challenging to see what is going on at a micro vs. macro level within a virtual environments network.&nbsp; The virtualization vendors such as VMWare and Citrix have provided embedded tools into their management consoles that show a macro level of visibility but its not enough to identify security events in the environment.&nbsp; Take a look at the attached picture.&nbsp; It simply shows VMWare's ability to monitor virtual network performance statistics from a bits per second perspective.</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/performancescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Performancescreen" title="Performancescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/performancescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
<br />&lt;-Click To Enlarge</p>

<p>With only this level of detail how can one determine which network applications are causing spikes.&nbsp; Is it FTP traffic that is occuring at a high volume at an unuseal time of day?&nbsp; If that were occuring, could that be indicative of either a breach or some sort of problem? What if FTP isn't even an authorized service in the virtual environment but there is a high volume of it?&nbsp; Did someone install a rouge FTP service so they could steal information from the server at will? </p>

<p>These types of questions can't really be answered without a micro level of detail into the packets flowing in, out and within the virtual environment.&nbsp; Now, what I am highlighting is not security in the traditional sense of prevention but using visibility as a means to first identify, then pin point the source of an issue so that it can properly be mitigated.&nbsp; Having constant visibility can also ensure that other security products in the environment are performing as expected.&nbsp; What if a Montego HyperSwitch with firewalling enabled is configured with many policies but someone forgot to create an FTP block policy.&nbsp; One could think they are protected from rouge FTP services transmiting data out of the network, but without constant visibility monitoring, can you be certain?</p>

<p>Some vendors, namely Reflex Security will get you to believe that their IPS / IDS solution that is inline and running in the virtual environment is the right and only approach.&nbsp; Or they will tell you to hang a virtual IDS off a span port in the virtual environment and you will at least have visibility into the attacks that are taking place.&nbsp; Well, sure... You now have attack visibility but at the performance cost of your virtual environment.&nbsp; Signature matching technologies are great, I'm a huge believer; however they don't scale very well in shared computing environments such as virtual ones.&nbsp; IDS systems also don't typically track protocol and network service (FTP, HTTP, etc.) utilizations; which is another important part of visibility.</p>

<p>So, what do we do to gain visibility without the performance headache?&nbsp; Well, for starters its probably best to put your IDS/IPS solutions in the physical environment where performance will be less of a concern.&nbsp; In fact, you can span a virtual switch's traffic out to a physical NIC as easy as you can to a virtual one.&nbsp; So why do it virtual and have to pay a 60% CPU utilization tax?&nbsp; Another solution is to IDS inspect only the things you care about.&nbsp; Why IDS inspect SSL traffic if you know your solution can't unencrypt SSL.&nbsp; Its just a waste of compute cycles isnt it?&nbsp; Policy based switching helps you with directing only the things you care about to an IDS (attack visualization product).&nbsp; Montego's HyperSwitch also can help you with the traffic redirection of only the things you care about. </p>

<p>Another method of visibility which I tend to be a fan of is one of packet analysis (aka NetFlow).&nbsp; NetFlow was invented by Cisco some time ago and has gained popularity in the physical world and definately has a use in the virtual world.&nbsp; NetFlow is lightweight.&nbsp; Let me say that again, its light weight!&nbsp; It only sends a summation of packet detail to an analytical engine which can do some number crunching, packet comparison, etc. etc. to make some sense out of whats going on.&nbsp; <a href="http://www.lancope.com">Lancope</a>, an Atlanta based visibility company that provides Network Visibility, Security Visibility and User Visibility has this tool on their website that is a Netflow Bandwidth calculator.&nbsp; You'll see from playing with this ( <a href="http://www.lancope.com/netflowcalculator.aspx">http://www.lancope.com/netflowcalculator.aspx</a> ) calculator that it doesn't consume a lot of network bandwidth to transmit these network accounting records.&nbsp; It also doesn't cause a lot of CPU overhead to send these records to an analytical engine sitting somewhere in the network.</p>

<p>Lancope's analytical engines have the ability to do the following for you within your virtual environment:</p><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta name="ProgId" content="PowerPoint.Slide" /><meta name="Generator" content="Microsoft PowerPoint 11" /><title><p>&lt;p&gt;Slide 3&lt;/p&gt;</p></title><meta name="Description" content="7/30/2008" /><style>
.O
	{color:black;
	font-size:149%;}
a:link
	{color:#CC9900 !important;}
a:active
	{color:#9B2D1F !important;}
a:visited
	{color:#96A9A9 !important;}
</style><style media="print">
&amp;lt;!--.sld
	{left:0px !important;
	width:6.0in !important;
	height:4.5in !important;
	font-size:103% !important;}
--&amp;gt;
</style><o:shapelayout v:ext="edit"></o:shapelayout><o:idmap v:ext="edit" data="1"></o:idmap><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9">&nbsp;</p:colorscheme><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9"><div v:shape="_x0000_s1026" class="O">

<ol><li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor and Alert network behavior of VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Track Vmotion movement of VMs accross physical servers</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor and Alert on communication between VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Identify users accessing VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Identify unauthorized or rouge VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor and Alert when VM???s go online or offline
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Identify network services running on VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor Network / Application performance of VMs<br />Display active hosts accessing VMs</span></li></ol>















<div></div>

</div>

</p:colorscheme><p>...and probably a slew of other things I'm not aware of.&nbsp; A screen shot of their product is bellow:</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/lancopescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Lancopescreen" title="Lancopescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/lancopescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a> &lt;- Click to enlarge</p>

<p>You'll notice from the screenshot that you are able to visualize who is talking to who, how much traffic they have sent and received and something called a concern index (not seen on this screenshot).</p>

<p>Now, a concern index is a number that increases as Lancopes analytical engines monitor suspicious activity on a session.&nbsp; A high counter can be indicative of a security problem.&nbsp; Its another way of identifying (visualizing) compromised hosts (virtual machines) without having to do signature matching like a heavy weight IPS engine.&nbsp; Example:&nbsp; Lets say you have a VM that has a BOT on it and is &quot;owned&quot;.&nbsp; The Lancope product is monitoring this long life session.&nbsp; Let's say that session is established for several hours or maybe even days or months.&nbsp; Lets also say that the conversation appears to be mostly unidirectional from a public ip address not belonging to your enterprise.&nbsp; Lancope would increase a the concern index on this since this server hasn't typically had this type of behavior.&nbsp; Once the concern index reached a certain level it could then fire off an email, send you a text message or something saying:&nbsp; <strong>Warning, Warning, Danger, Danger Will Robinson!!! You're virtual server may be infected with a BOT, please investigate immediately!!!</strong></p>

<p>This example is VISIBILITY which helps you with SECURITY.&nbsp; There are a number of other things you can do with NetFlow and Lancope products that have less to do with security and more to do with operational efficiencies.&nbsp; Things like, helping you answer questions of:&nbsp; How do I know what network applications are taking up the most bandwidth?&nbsp; When should I move those applications over to a server with more horsepower?&nbsp; When did these VM's vmotion over here and was there a traffic condition / CPU condition that caused that to occur?&nbsp; I could go on and on but thats a topic for another blog entry.</p>

<p>So, my suggestion is to take a look at what NetFlow has to offer.&nbsp; Montego Networks supports NetFlow transmission and Lancope supports NetFlow analytics and with both you can regain what was lost visibility.</p>

<p>I hope this was helpful to you all!</p>

<p>-John Peterson</p></div>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 17:57:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network visibility">network visibility</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/environments">environments</category>
      <category domain="http://securityratty.com/tag/virtual environments network">virtual environments network</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/network bandwidth">network bandwidth</category>
      <category domain="http://securityratty.com/tag/bandwidth">bandwidth</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <source url="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/2008/07/security-throug.html">Security Through Visibility - Montego, Lancope and NetFlow</source>
    </item>
    <item>
      <title><![CDATA[The Impact of Dans DNS Debacle on Internet Risk]]></title>
      <link>http://securityratty.com/article/1fb63648aa29a459479e251e9609bd22</link>
      <guid>http://securityratty.com/article/1fb63648aa29a459479e251e9609bd22</guid>
      <description><![CDATA[Blogger: Pete Lindstrom
On July 8th, Dan Kaminsky of IOActive announced a major DNS vulnerability in conjunction with a number of major DNS vendors. The announcement was off the charts in fanfare and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Pete Lindstrom</p>

<p>On July 8th, Dan Kaminsky of IOActive announced a major DNS “vulnerability” in conjunction with a number of major DNS vendors. The announcement was off the charts in fanfare and attention, but what was the real impact on risk?</p>

<p>First, it is worth noting that this “bug” is more properly classified as a new attack technique invented by Dan. It combines two vulnerabilities that have been well-known for some time – the ability to guess non-random transaction IDs and the use of Additional RRs to insert new entries into the DNS cache. A fix against either of these vulnerabilities also negates the attack itself.</p>

<p>The fundamental question that determines the risk impact revolves around whether it is reasonable to expect fewer or more incidents that use this technique when comparing the period prior to disclosure -- or, more properly, before the date of Dan’s invention of the technique (this also assumes prior art) – with the period after invention/disclosure and into the future. If the disclosure reduces the number of those incidents, then risk is reduced; if the disclosure increases the number of those incidents, then risk is increased.</p>

<p>With that litmus test as our guideline, it is useful to break down the functional elements of risk and look at the impact on threats, vulnerabilities, and consequences (we will cover consequences, then vulnerabilities, and finally threat).</p>

<p><strong>Consequences</strong><br />Though the consequences are the same before and after disclosure, it is worth discussing the impact here, given that the implication was that the “entire web” could be taken down. The nature of the attack requires the following:</p>

<ol><li>An attacker must convince/trick a user into making a DNS request for a domain that doesn’t already exist in their DNS server’s cache. The expectation here is that s/he can be easily tricked into doing this.</li>

<li>Then, the attacker must simultaneously attack the DNS server by guessing the transaction ID. According to Kaminsky, the request/attack phase can be done reliably in about 10 seconds.</li>

<li>The attack is DNS server-specific. Only users on the same DNS server are affected.</li>

<li>Propagation: once the cache is poisoned, anyone requesting that domain will be routed to a malicious server.</li></ol>

<p>Without combining this attack with other attack techniques, there can be three results:</p>

<ol><li>Spoofing of a single website for multiple, perhaps many, users using the same DNS server. Presumably, this would be followed by more traditional phishing and malware attacks.</li>

<li>Denial-of-service by rerouting traffic from a legitimate site thereby taking potential customers or “eyeballs” away.</li>

<li>Denial-of-service be rerouting traffic from a legitimate high volume site to a legitimate low-volume site thereby overloading the servers on the low-volume site.</li></ol>

<p>Because of the point-to-point (user-to-website) nature of the attack, to do something that constitutes “taking over the entire web” is infeasible by a longshot.</p>

<p>The bottom line analysis for the effect on risk due to a change in consequences from pre-invention to post-invention: no change, and therefore no impact.</p>

<p><strong>Vulnerabilities</strong><br />These vulnerabilities have existed for years, and there have been workarounds for years. Along with this announcement, new patches were introduced in all major DNS server solutions. It is reasonable to assume that many DNS server implementations have been patched, though public accounts have suggested that number is in the 66%-75% range.</p>

<p>Bottom line analysis: the vulnerability level has been reduced, probably significantly, and the affect is positive for risk reduction. If 100% of DNS servers were patched, then overall risk would be reduced for this attack (assuming that there were actual attacks using this technique in the past.)</p>

<p><strong>Threats</strong><br />The real question regarding risk impact comes in the arena of the less-controllable manipulation of threat. The general threat equation revolves around an attacker’s willingness to attack, based on his/her own cost/benefit analysis that compares the cost to attack to the expected benefits, tempered by the potential for being caught and penalized.</p>

<p>Cost to attack – prior to disclosing the invention, there were likely few, if any attackers with “prior art” that mirrored this technique. It is anybody’s guess how many potential attackers might have figured it out eventually, but they would have had to come from the pool of folks with enough expertise to do so – I am going to guess 500,000 people.</p>

<p>After the disclosure, the hints provided in the press release, the podcast, the sorted stories, and the blog entries made it much easier to figure out. Let’s guess that 5 million people could execute the attack. With automated tools, that number goes up to 50 million.</p>

<p>These numbers are estimates that illustrate the nature of the exercise. You are welcome to fill in your own estimates and come to your own conclusions.</p>

<p>Bottom line analysis: a significant increase in threat and corresponding risk.</p>

<p><strong>Net Effect</strong><br />The risk manager's challenge is to weigh the decrease in vulnerable systems compared with the corresponding increase in threat, within the context of number of incidents and anticipated future incidents. Given the sheer size differential, it is difficult to conceive of a situation where risk is not increased. </p>

<p>Sometimes it &quot;feels&quot; like someone is taking action for the greater good, when that action actually creates a negative impact for all. For example, it is common for people to believe that raising prices of scarce resources during&nbsp; times of trouble (e.g. gasoline in the hurricane Katrina aftermath) is unconscionable even though a majority of economists recognize that raising prices actually provides for the greater public good. Vulnerability discovery and disclosure, and attack inventions, might feel like the right thing to do, but the net result is almost always a negative impact.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/350432472" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 04:11:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dns servers">dns servers</category>
      <category domain="http://securityratty.com/tag/servers">servers</category>
      <category domain="http://securityratty.com/tag/impact">impact</category>
      <category domain="http://securityratty.com/tag/dns">dns</category>
      <category domain="http://securityratty.com/tag/dns servers cache">dns servers cache</category>
      <category domain="http://securityratty.com/tag/risk impact revolves">risk impact revolves</category>
      <category domain="http://securityratty.com/tag/major dns vendors">major dns vendors</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/major dns vulnerability">major dns vulnerability</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/350432472/the-impact-of-d.html">The Impact of Dans DNS Debacle on Internet Risk</source>
    </item>
    <item>
      <title><![CDATA[Traditional vs. Non-Traditional Database Auditing]]></title>
      <link>http://securityratty.com/article/5a4ce0e047d08e8cdf84bf1d903609d4</link>
      <guid>http://securityratty.com/article/5a4ce0e047d08e8cdf84bf1d903609d4</guid>
      <description><![CDATA[Traditional native audit tools and methods are useful for diagnosing problems at a given point in time, but they typically do not scale across the enterprise. The auditing holes that are left in...]]></description>
      <content:encoded><![CDATA[Traditional native audit tools and methods are useful for diagnosing problems at a given point in time, but they typically do not scale across the enterprise. The auditing holes that are left in their...]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 07:27:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/enterprise">enterprise</category>
      <category domain="http://securityratty.com/tag/holes">holes</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/scale">scale</category>
      <category domain="http://securityratty.com/tag/methods">methods</category>
      <source url="http://www.net-security.org/article.php?id=1161">Traditional vs. Non-Traditional Database Auditing</source>
    </item>
    <item>
      <title><![CDATA[Monday merger-mania in security]]></title>
      <link>http://securityratty.com/article/bce33b1277b9cd2ece821973cc19a401</link>
      <guid>http://securityratty.com/article/bce33b1277b9cd2ece821973cc19a401</guid>
      <description><![CDATA[Not sure if it is because of the slumping market and economy or in spite of it, but there pace of merger activity has been picking up lately and the security industry has not been immune to it. Today...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Not sure if it is because of the slumping market and economy or in spite of it, but there pace of merger activity has been picking up lately and the security industry has not been immune to it.&nbsp; Today saw two meaningful deals announced that could have an impact on the security landscape:</p>

<p>1. <a href="http://www.internetnews.com/bus-news/article.php/3761786/Sophos+Utimaco+Buy+Targets+Endpoint+Security.htm">Sophos buys Utimaco</a> - Saw this one when I woke up today, as it is a European deal.&nbsp; UK based <a class="zem_slink" title="Sophos" href="http://www.sophos.com/" rel="homepage">Sophos</a> is buying German based Utimaco, makers of the SafeGuard line of data encryption/protection/DLP product line.&nbsp; Sophos is paying cash $340 million US for in this deal.&nbsp; This means they are substantially dipping into the credit market, as this is far more than they reported cash on hand. So like the Brocade/Foundry deal, the acquiring company feels strong enough about the acquisition to mortgage the house to get it.&nbsp; In this case, I think Sophos is making a smart deal. They clearly say that to compete with <a class="zem_slink" title="Symantec" href="http://www.symantec.com/" rel="homepage">Symantec</a>, <a class="zem_slink" title="McAfee" href="http://www.mcafee.com/" rel="homepage">McAfee</a> and <a class="zem_slink" title="Microsoft" href="http://www.microsoft.com/worldwide/" rel="homepage">Microsoft</a> they are going to need a full endpoint security suite. AV alone is not just going to cut it. This gives Sophos a real play in DLP and data storage space.&nbsp; </p>

<p>Yes they could have just done a partner deal for this type of technology, but I applaud them for going out and buying the technology.&nbsp; I wondered if they would use this as a reverse merger entry to the public markets but it doesn't look like that.&nbsp; In any event it looks like Sophos is making the play and spending the bucks to be a player in the endpoint security suite game.</p>

<p>2. <a href="http://www.networkworld.com/community/node/30411">Motorola buys AirDefense</a> - Well one of the air brothers finally found a taker. I always thought that for all of the press AirDefense, AirTight and AirMagnet receive, the revenue just didn't match the hype. Stand alone wireless security was a tweener.&nbsp; Would traditional security cover wireless or would traditional wireless cover wireless security.&nbsp; In any event a stand along wireless security play is a tough road.&nbsp; So with this answer <a class="zem_slink" title="Motorola" href="http://www.motorola.com/" rel="homepage">Motorola</a> says wireless handles wireless security.&nbsp; </p>

<p>My question is what does the future hold for Motorola.&nbsp; They are reportedly getting out of the cell phone business.&nbsp; Is their wireless business, even a secure one enough to support this giant?&nbsp; I don't know but there is a bit of &quot;dead man walking&quot; over there if you ask me.&nbsp; </p>

<p>I think the play is clear though that wireless providers are going to snap up wireless security companies. The real issue is at what prices.&nbsp; If anyone hears a price on this one, let me know. </p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Manta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-1009_3-10000548-83.html?hhTest=1&amp;part=rss&amp;subj=news">Sophi's bids on Utica to strengthen endpoint security</a> </li>

<li class="zemanta-article-ul-li"><a href="http://www.infoworld.com/article/08/07/28/Sophos_plans_to_acquire_data_security_company_1.html?source=rss&amp;url=http://www.infoworld.com/article/08/07/28/Sophos_plans_to_acquire_data_security_company_1.html">Sophi's plans to acquire data security company</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/b28c9731-f42d-42a3-b409-5a5c5b38b751/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=b28c9731-f42d-42a3-b409-5a5c5b38b751" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Mon, 28 Jul 2008 18:54:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wireless security play">wireless security play</category>
      <category domain="http://securityratty.com/tag/play">play</category>
      <category domain="http://securityratty.com/tag/sophos buys utimaco">sophos buys utimaco</category>
      <category domain="http://securityratty.com/tag/sophos">sophos</category>
      <category domain="http://securityratty.com/tag/deal">deal</category>
      <category domain="http://securityratty.com/tag/smart deal">smart deal</category>
      <category domain="http://securityratty.com/tag/wireless security">wireless security</category>
      <category domain="http://securityratty.com/tag/brocadefoundry deal">brocadefoundry deal</category>
      <category domain="http://securityratty.com/tag/motorola">motorola</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/monday-merger-m.html">Monday merger-mania in security</source>
    </item>
    <item>
      <title><![CDATA[Monday merger-mania in security]]></title>
      <link>http://securityratty.com/article/c19f4a038131d5dec9a148005e6b400e</link>
      <guid>http://securityratty.com/article/c19f4a038131d5dec9a148005e6b400e</guid>
      <description><![CDATA[Not sure if it is because of the slumping market and economy or in spite of it, but there pace of merger activity has been picking up lately and the security industry has not been immune to it. Today...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Not sure if it is because of the slumping market and economy or in spite of it, but there pace of merger activity has been picking up lately and the security industry has not been immune to it.&nbsp; Today saw two meaningful deals announced that could have an impact on the security landscape:</p>

<p>1. <a href="http://www.internetnews.com/bus-news/article.php/3761786/Sophos+Utimaco+Buy+Targets+Endpoint+Security.htm">Sophos buys Utimaco</a> - Saw this one when I woke up today, as it is a European deal.&nbsp; UK based <a class="zem_slink" title="Sophos" href="http://www.sophos.com/" rel="homepage">Sophos</a> is buying German based Utimaco, makers of the SafeGuard line of data encryption/protection/DLP product line.&nbsp; Sophos is paying cash $340 million US for in this deal.&nbsp; This means they are substantially dipping into the credit market, as this is far more than they reported cash on hand. So like the Brocade/Foundry deal, the acquiring company feels strong enough about the acquisition to mortgage the house to get it.&nbsp; In this case, I think Sophos is making a smart deal. They clearly say that to compete with <a class="zem_slink" title="Symantec" href="http://www.symantec.com/" rel="homepage">Symantec</a>, <a class="zem_slink" title="McAfee" href="http://www.mcafee.com/" rel="homepage">McAfee</a> and <a class="zem_slink" title="Microsoft" href="http://www.microsoft.com/worldwide/" rel="homepage">Microsoft</a> they are going to need a full endpoint security suite. AV alone is not just going to cut it. This gives Sophos a real play in DLP and data storage space.&nbsp; </p>

<p>Yes they could have just done a partner deal for this type of technology, but I applaud them for going out and buying the technology.&nbsp; I wondered if they would use this as a reverse merger entry to the public markets but it doesn't look like that.&nbsp; In any event it looks like Sophos is making the play and spending the bucks to be a player in the endpoint security suite game.</p>

<p>2. <a href="http://www.networkworld.com/community/node/30411">Motorola buys AirDefense</a> - Well one of the air brothers finally found a taker. I always thought that for all of the press AirDefense, AirTight and AirMagnet receive, the revenue just didn't match the hype. Stand alone wireless security was a tweener.&nbsp; Would traditional security cover wireless or would traditional wireless cover wireless security.&nbsp; In any event a stand along wireless security play is a tough road.&nbsp; So with this answer <a class="zem_slink" title="Motorola" href="http://www.motorola.com/" rel="homepage">Motorola</a> says wireless handles wireless security.&nbsp; </p>

<p>My question is what does the future hold for Motorola.&nbsp; They are reportedly getting out of the cell phone business.&nbsp; Is their wireless business, even a secure one enough to support this giant?&nbsp; I don't know but there is a bit of &quot;dead man walking&quot; over there if you ask me.&nbsp; </p>

<p>I think the play is clear though that wireless providers are going to snap up wireless security companies. The real issue is at what prices.&nbsp; If anyone hears a price on this one, let me know. </p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Manta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-1009_3-10000548-83.html?hhTest=1&amp;part=rss&amp;subj=news">Sophi's bids on Utica to strengthen endpoint security</a> </li>

<li class="zemanta-article-ul-li"><a href="http://www.infoworld.com/article/08/07/28/Sophos_plans_to_acquire_data_security_company_1.html?source=rss&amp;url=http://www.infoworld.com/article/08/07/28/Sophos_plans_to_acquire_data_security_company_1.html">Sophi's plans to acquire data security company</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/b28c9731-f42d-42a3-b409-5a5c5b38b751/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=b28c9731-f42d-42a3-b409-5a5c5b38b751" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=ujW6ul"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=ujW6ul" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=9LTeDJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=9LTeDJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=yIFCWJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=yIFCWJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=skJxZJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=skJxZJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=6vZwXJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=6vZwXJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=IQfuGj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=IQfuGj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=pYiVbj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=pYiVbj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/349022019" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 28 Jul 2008 17:54:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wireless security play">wireless security play</category>
      <category domain="http://securityratty.com/tag/play">play</category>
      <category domain="http://securityratty.com/tag/sophos buys utimaco">sophos buys utimaco</category>
      <category domain="http://securityratty.com/tag/sophos">sophos</category>
      <category domain="http://securityratty.com/tag/deal">deal</category>
      <category domain="http://securityratty.com/tag/smart deal">smart deal</category>
      <category domain="http://securityratty.com/tag/wireless security">wireless security</category>
      <category domain="http://securityratty.com/tag/brocadefoundry deal">brocadefoundry deal</category>
      <category domain="http://securityratty.com/tag/motorola">motorola</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/349022019/monday-merger-m.html">Monday merger-mania in security</source>
    </item>
  </channel>
</rss>
