Thursday, 16 February 2012

Video: Stopping Reflective Memory Injection


Today’s cyber attackers have added a new weapon into their arsenal: a sophisticated memory attack known as “Reflective Memory Injection”. Reflective Memory Injection goes beyond traditional memory exploits like skape/jt to easily compromise and own a victim computer.
Most security professionals today know that CoreTrace Bouncer provides advanced threat protection based on its adaptive application whitelisting technology. But Bouncer goes well beyond simple whitelisting–including extensive memory protection capabilities.
At CoreTrace, we believe actions are always better than words. So I recorded a video that shows how an attacker would use Reflective Memory Injection to compromise a victim computer, then demonstrates how Bouncer automatically prevents the attack.

Take a look and feel free to let me know if you have any questions.
by Greg Valentine

Wednesday, 15 February 2012

What I Don’t Love About SharePoint

A recent article in Fierce Content Management entitled “Survey finds many users blow by SharePoint security” reveals how cavalier some Microsoft SharePoint users are about maintaining security within the widely used Enterprise collaboration and content management solution.  According to the SharePoint security survey conducted by Cryptzone, an IT threat mitigation company, 92% of respondents said they knew that taking content out of SharePoint created a security risk; still 30% were willing to take that risk for the sake of convenience.  Even more eye-opening was that 43% took sensitive content out of SharePoint to work at home and 55% said they did that to give material to someone without access to SharePoint.
There’s a clear need to be able to share files externally from SharePoint that is not currently being addressed in many organizations.
To effectively collaborate today, users need to easily share content securely within their organization and with external partners across the firewall. But in order to securely share data with outside parties, organizations need to create a secure file sharing system within their SharePoint environment.  Unfortunately, it is not easy or inexpensive to build an external-facing SharePoint server farm.
In order to open up content in SharePoint to external users, IT needs to provision a license and also set up external facing SharePoint servers on the DMZ.  This is an expensive proposition. So organizations usually bypass setting up external SharePoint servers.  This often leads employees to create work-arounds rather than taking the time to put in IT requests.  However, this is a data breach waiting to happen.  Once a document leaves SharePoint “illegally” the ability to track and manage the file is compromised.  This is particularly important in industries subject to HIPAA and other regulatory compliance.
There is a solution to this problem for organizations who want to make the most of their SharePoint investment.  Accellion offers a plug-in for SharePoint that enables users to quickly, easily, and securely share any size file from within the SharePoint Document Library to both internal and external recipients.  The plug-in not only makes it easy to share files across the corporate firewall but also provides easy-to-use file tracking and reporting required to meet industry and government regulations such as HIPAA, SOX and GLBA.
So if your organization has made an investment in SharePoint but you haven’t yet implemented external sharing of SharePoint documents for your users please give us a call.   As the Cryptzone survey illustrated if a solution isn’t provided for external file sharing from SharePoint then users will come up with their own solution and security isn’t typically top of their list of requirements.
by Nina Seth


Tuesday, 7 February 2012

The human factor

News of a data breach at the UK’s Scotland Yard has pushed the issue of data management and control back into the public eye. The Yard admitted accidentally sharing the personal email addresses of more than a thousand crime victims with other victims on its database. It was an easy mistake to make: In the course of sending a survey to 1,136 people, email addresses were entered in the wrong box, making them visible to all recipients.
In a worst case scenario, the maximum penalty for a data breach in the UK is £500,000.
No one sets out to lose data, but a glance at some of the most recent incidents reveals a common thread: human error. At a time when organisations across sectors are under increasing pressure to adhere to the often competing demands of transparency, cost-effectiveness, privacy and collaboration, data leak incidents are in danger of undermining reputations, brands, revenues and effective business strategies. It’s a high price to pay for an accident and if government privacy agencies are increasingly less forgiving of mistakes, customers – both existing and potential – are even less tolerant. According to research undertaken by the Ponemon Institute in October 2011, data leaks cost a minimum loss of 12 per cent in terms of brand damage; in some instances, this rose to an almost 25 per cent loss of brand value as a direct result of a data leak incident. As I’ve said, it’s a high price to pay for an accident that could easily have been prevented.
Data leak prevention, Web and Email Gateways and strong, flexible policy-based encryption work in tandem with effective education and management policies to reduce the potential for costly human error. Encryption and decryption, for example, can be performed automatically and centrally within flexible policy parameters and without the need for user interaction.
This doesn’t mean limiting end user ability to share and communicate – recognising the content is important, but so too is the ability to apply context to the data before making the decision to encrypt whether or not the end user selects that option.
It’s all about striking a balance between risk and real-world working requirements – and making sure that human error doesn’t get in the way.
by Alyn Hockey


Even at Shmoocon, Security Can’t Be Taken for Granted


Shmoocon labs is a group of vendors and attendees who get together before Shmoocon begins for a learning experience. The task – build a stable and SECURE network infrastructure to meet the needs of the convention. The idea is to teach people how to use the hardware from various vendors and make it all work together as a network that remains secure, stable and functional throughout the conference, no matter what.
This year, AirTight’s® SpectraGuard® wireless intrusion prevention system (WIPS) was handed the responsibility to protect this network from wireless threats. As soon as I deployed the AirTight wireless Sensors in the convention center and fired up the SpectraGuard management console to give a demo at the AirTight booth, I noticed an unusual number of Rogue APs had popped up. More concerning was one Rogue AP that was unencrypted and on the main management network of the conference. Although AirTight’s WIPS had automatically detected and blocked the device immediately, a little detective work was in order. I used SpectraGuard’s location tracking to pinpoint the exact placement of the device.
A quick physical search revealed an Apple Airplay device plugged into the management network. These devices are small and look just like normal Apple power plugs, however, they can also connect to wired networks, create wireless networks, and stream music! The AP was quickly removed from the management network (and placed on the hacker’s playground network). However, the AP was on the management network for over 5 hours of the convention; who knows what would have happened if SpectraGuard was not around to take care of business – switches, firewalls, Wi-Fi, almost anything on the network could have been reconfigured.
I guess it can happen to the best of us, but, once again, it makes the case for layered security – having someone watching your back. As a security professional your job is never done
by Rick Farina

Thursday, 2 February 2012

There's opportunity in difficulty



Faced with increased penalties and significant reputation damage for serious data or information compliance breaches, it’s hardly surprising to find data protection topping TechTarget's list of enterprise IT priorities in 2012.

Challenging times lie ahead for organisations that don’t adapt to the new risks and opportunities that come with new ways of communicating but organisations that focus only on network security risk taking their eye off the ball. IT consumerisation, smart device proliferation, web-based services and workplace mobility all call for a data-centric approach to information management and protection.
Information is only as good as your ability to use it effectively; organisations looking to achieve high-quality data protection need to know, manage and understand the value of all the data entering and leaving their networks, as well as how it’s being used and by whom. The organisations that meet this challenge will be the ones that are most able to make effective use of their data while mitigating the risks inherent in information exchange.
To this end, more traditional, network-based data protection approaches should be implemented in tandem with contextual information management systems. This allows organisations to simultaneously control and empower their data without impeding its flow. Stopping and blocking might seem like the easiest route to take, but it simply isn’t up to the task and doesn’t reflect the technological realities of the way we do business today – or in the future.
by Alyn Hockey

Wednesday, 1 February 2012

A tale of the two WLAN controllers, do we need to be chasing our tail for the WLAN security?


Right when the Wi-Fi access and security management are moving towards the controller-less architecture, another interesting architecture seems to have evolved at the other extreme. This architecture seems to be advocating not one, but two WLAN controllers in tandem – and that too from two different vendors. And, some optional (additional?) security management servers on top of the tandem. You think I am kidding? Then check this announcement from Aruba Networks, which is a leading controller-based WLAN vendor: http://www.arubanetworks.com/solutions/by-application/byod-services-on-your-existing-wi-fi/. The stated business case seems to be to put a band-aid on the Cisco WLAN’s (another leading controller-based WLAN vendor) insufficient security features.
In this case, the tandem is only for BYOD security, but as a matter of fact there are many more security gaps that will still remain to be addressed even after the twin tandem controllers are deployed. Would we need a third WLAN controller in the tandem to fill the remaining security gap, and who might provide that? Or, is it just easier to deploy a controller-less comprehensive WIPS solution (and that too with the onsite or cloud option) and secure the Cisco WLAN once and for all. Just a practical thought.

Security Earthquake That Nobody Felt: McAfee Endorses Application Whitelisting


Folks in California are so used to earthquakes that sometimes they barely notice when one happens. Folks in the security business are so busy and swamped with the noise of the market that we often miss tectonic shifts in our own world. Let me help you with that last one:
BREAKING NEWS“Endpoint Security Earthquake Hits: McAfee Actively Endorses Application Whitelisting. Magnitude & Ramifications Are Significant.”
This week, McAfee, one of the two dominant forces in reactive, blacklist-based endpoint security,actively and unequivocally endorsed Application Whitelisting. Ironically, in hard coverage of Symantec’s recent problems with pcAnywhere, the industry is actively recommending application whitelisting too.
First, let’s cover the major quake: McAfee’s active endorsement of application whitelisting—for corporate desktops and laptops. In a series of videos on the popular video sharing site, YouTube, McAfee joins CoreTrace in educating the market about the shortcomings of traditional blacklist-based solutions, the advantages of application whitelisting, and McAfee Application Control’s purported advantages (most of which are unique compared to other whitelisting solutions but are not unique compared to CoreTrace (e.g., trusted change and memory protection)). You can view the initial video here here . While you are at YouTube, make sure to check out CoreTrace’s video channel too.
While CoreTrace has successfully competed with our friends from McAfee on application whitelisting projects on fixed function systems (e.g., critical infrastructure, POS terminals, servers), the antivirus giant has never publically announced that whitelisting can and should be used on corporate desktops and laptops—until now. In the introductory video, McAfee senior product manager Swaroop Sayeram directly states: “Simplistic whitelisting might fit just fixed function systems… Dynamic whitelisting is a great fit for servers… and it is now a good fit for corporate desktops as well. These days, most of the deals we are seeing are to secure servers and corporate desktops.”
Second, let’s cover the story of the related tremors: The industry’s recommendations to utilize application whitelisting to solve problems like those created by Symantec’s pcAnywhere code theft. While Symantec’s own advisory to pcAnywhere users only includes its boilerplate old-school recommendations, experts throughout the industry are recommending whitelisting as one of the main solutions. As an example, as a part of his recommendations in a FoxNews.com interview , Anup Ghosh, founder and CEO of Virginian security firm Invincea, told FoxNews.com “Businesses should deploy application ‘whitelisting.’ This will prevent unauthorized malware from running on computers.”
So, McAfee has dramatically shifted the endpoint anti-malware landscape. Now the question is, with the ground shifting beneath its feed, what will Symantec do? Stay tuned for future coverage of this developing story…
by JT Keating