Sensitive Data Protection (Part 2)
Posted on July 1st, 2008 at 2:13 pm by Avatar

datasec2.jpgEncryption is also now being applied extensively in offices so if ever information does get out and falls into the wrong hands it is rendered useless without the proper cipher key. The use of military-grade encryption has random generators and multi level encryption technologies which were previously available only to the military forces. Hardware based encryption is also another developing technology where hardware components such as hard disks, network cards and other such peripherals are embedded with encryption technology on a chip thus preventing unauthorized data being useable that is transmitted or contained within them. All these technologies along with promising technologies in development such as faster multi-processors allow higher encryption levels without sacrificing performance as today�s technologies are limited to (the faster the processor, the faster the coding/decoding of information that would become almost unperceivable with future computers).

Data Classification : The Key to true security over the web
Posted on June 1st, 2008 at 9:25 am by Avatar

With the advent of VoIP or a revised name for a P2P (peer to peer) connection using the internet for use with voice calls while simultaneously sharing and moving file across the vast area that is the internet, more and more information that is within your computer and the information that you send through the net is at risk.
So what can we do to boost the already anti-virus protected environment that is the net and the data that may become lost? Traditionally IT experts and analysts have recommended the use of perimeter protection for a network which has sentinels or programs that defines who can access where and when. Data mining software, scans all the files on the network and determines who gets to see and use which and prevents data loss by storing them securely in servers. Software like InfoScape from the EMC Corp is just one of the many software products along with Kazeon Systems Inc.
The key is to de-centralize and distribute the security solution along with the files themselves which follows the approach that the traditional network with walls has been thrown out the window.

Network Intrusion Protection Systems
Posted on April 9th, 2008 at 2:15 pm by Avatar

ips.jpgPreviously we discussed the importance of having an intrusion detection system to handle the growing number of attacks on corporate networks with Intrusion Detection Systems. A better solution would be to give some form of control to the detection system giving it teeth to execute actions that would prevent intrusion such as denying access or deleting errant file attachments. This comes in the form of Intrusion Prevention Systems which have the ability to detect, analyze and take appropriate action as programmed to do so by the systems administrators who then gets a detailed report on what was done. This allows them to review and take further action if the file was simply quarantined and not deleted by the system. They can then be submitted to the software vendor so they can analyze and formulate a solution to the threat providing feedback to prevent further infections.

Network Intrusion Detection Systems
Posted on April 5th, 2008 at 2:13 pm by Avatar

ids.jpgNetwork Intrusion Detection Systems have a sole purpose which is to analyze data packets entering a network while looking for signatures of known malware. These signatures are constantly updated as new threats are detected so they are always on the lookout for a growing number of threats that keep on getting better and better at what they do. A detection system checks for any suspicious activity and then notifies the right people who then do the desired actions that have been laid out. Much like a citizen who calls the cops to report a criminal, it works the same way with the system being the caller and the dispatcher in detection side, and the cops on the System Administration side who takes action and apprehends the suspected criminal. They are however quite dependent on the ability of their handlers (System Administrator’s) to handle the threat as it should be. Miscalculations or lack of action can render it useless defeating its purpose. A better solution will be discussed in the next post that is more pro-active in the quest to protect the corporate network.

FBI Biometrics Database
Posted on February 5th, 2008 at 2:14 pm by Avatar

biometrics.jpgUnited States law enforcement agencies have long used the centralized database systems for storing information on criminals and other law breaking activities for inter-agency cooperation. The FBI has proposed a new system which would also contain more biometric information included with the old photos, rap sheets and biographical information in hopes to boost the capability of crime prevention and investigation units in getting information. The said plan gets many critics due to many problems that are foreseen to come with a new system such as the fact that the agency’s network and computers are some of the most attacked computers on earth. The transmission of all information regarding an investigation is to be sent to the FBI first before all other agencies, which raises questions on the transmission security of the said information. The system in place that has been modified for Homeland Security has a lot of flaws wherein many people with misdemeanors get arrested as “terrorists”. There is no contesting the fact that there is a need for such a system but further testing and development should be done as many experts see the plan. The security and reliability of the government should be prioritized and developed to the full capability of current technology for it to remain acceptable and adaptable for the times to come.

Sensitive Data Protection (Part 1)
Posted on January 25th, 2008 at 2:11 pm by Avatar

datasec.jpgThis has bearing for information that is dealt with locally but also with data that is used on the internet as well. Security experts agree that there is no so-called silver bullet that would be able to provide all the security needs of information but rather a mix of technologies. These technologies such as ERM�s or Enterprise Rights Management, allows companies to determine how information is to be used and who gets to send and receive them based on the sensitivity level of the said information in question. For email applications, software that offer S/MIME or Secure/Multipurpose Internet Mail Extensions are the best bet in controlling which email can be or cannot be sent by a
certain individual out through the internet.

Cisco-Servers with Built-in Protection
Posted on January 17th, 2008 at 9:28 am by Avatar

Cisco, one of the world�s leading producers of network servers that are deployed on the internet and in large corporations has announced the release of their Self-Defending Network version 3.0. This is after they have finalized the acquisition of security software Ironport Systems Inc. Ironport is responsible for the development of a powerful e-mail and web monitoring service called SenderBase. The said system collects information from almost 100,000 internet providers, schools, universities and corporations globally. Checking for more than 110 parameters for any available active web server connected to the internet which allows it to verify, inspect and check e-mail that passes through them (their massive database/s are reported to get at least 5 billion requests per day).

Sophos
Posted on January 13th, 2008 at 9:28 am by Avatar

One of the leaders in the data protection business has produced a report that highlights the inability of most software to do what they should be doing which is protecting the networks and the information that goes through it. Sophos Their software, offered for large enterprise and small businesses allows them unsurpassed protection from a broad range of threats. It gets viruses, filters spam, prevents access to phishing sites and classifies e-mail (and their attachments) applying security as needed.
These types of multi-level software allow easy deployment of some of the best and latest security tools out on the market to date giving companies the best protection.

Enterprise Rights Management
Posted on January 9th, 2008 at 9:28 am by Avatar

ERM as it is known in enterprise has long been a standard applied in large-scale businesses. This holds some promises for some of the biggest software giants like Symantec are moving to include the said approach directly combined with their anti-virus , anti-spam and firewall technologies already in place.
The invocation of DLP’s gives these already established systems more robust security capabilities eliminating the need for third or fourth party software purchases having one product that is capable of doing all of them. Software from these software giants are scalable and flexible for deployment in businesses from all scopes making it the best bet as the next generation of protection for networks and the information that travels through them.

Broad spectrum DLP’s
Posted on January 5th, 2008 at 9:27 am by Avatar

Data Loss Prevention is a term used to define and enforce data classification and uses robust encryption and security. Vendors like Vontu , Reconnex and Titus Labs, all produce software that is classified as data mining technologies and gives the user the function/ability to include the security option which they can define the level that should be applied.
These types of software scans email and their attachments along the files users already have and create giving the users a sign that the said files are in need of protection. They then assign the level/s of protection that are assigned and the file is encrypted with a key. Only authorized clients and users with the right access levels get the key and thus access to the said information eliminating the reliance on the traditional walls for protection.