VMworld brings me back to the Moscone this week. The VMware conference has drawn over 12,500 people and the exhibit hall was absolutely hopping yesterday. There is a lot of excitement about new technology and the vision of a dynamic IT service. Most of what I’ve seen so far is in CAPEX reduction such as layering shared OS images, application packs, and personification settings to reduce storage and administration costs. I like the prospects of VDI to change the security model, but it looks like VDI may stay poised waiting for a breakout for a bit longer.
Most of the security here is tied to multi-tenancy. For example, if an Exchange VM is launched on a new server to meet capacity demand, then make sure a DLP VM is also launched to meet compliance mandates. I can’t say I’ve seen much of innovative use of VMsafe even though big security vendors Check Point, McAfee, Symantec, and Trend Micro are all here. Reflex Security may be interesting when I talk with them tomorrow.
It has come to my attention that www.ogrengroup.com returns a “not found” error message. My blog is hosted by Google so I’ll have to see what changed there. If you are reading this, then you know how to get to my blog directly. Bad timing with the conference going on - I’ll get this fixed as soon as I can!
Tuesday, September 1, 2009
Thursday, August 20, 2009
VMware AppSpeed moves virtualization forward

This is an Ogren Group Impact I wrote a few weeks ago for VMware AppSpeed. The product is a pretty good idea and should do well for VMware's customers.
"VMware is bolstering its vCenter management capability with AppSpeed 1.0 software enabling organizations to confidently control performance as applications transition to a virtualized infrastructure. AppSpeed allows IT organizations to manage memory, network, and system resources for applications across the physical and virtual corporate infrastructure, assuring predictable VM performance under peak workloads. The Ogren Group believes establishing visibility and control of performance as applications become virtualized is a critical capability for organizations advancing their strategy of cost savings and dynamic IT service management through data center virtualization. The introduction of vCenter AppSpeed is an innovative move by VMware, and positions VMware customers to rely more upon ESX virtualization in the data center..."
Wednesday, August 19, 2009
Hacker charges also an indictment onPCI, expert says
Just posted to SearchSecurity ...
"The federal indictment this week of three men for their roles in the largest data security breach in U.S. history also serves as an indictment of sorts against the fraud conducted by PCI – placing the burden of security costs onto retailers and card processors when what is really needed is the payment card industry investing in a secure business process.
A federal grand jury has indicted Albert Gonzalez of Miami and two yet unnamed Russian hackers for their alleged roles in the Heartland Payment Systems Inc. and Hannaford Brothers Co. thefts of 130 million credit and debit card data, plus the 40 million credit cards grabbed from TJX.
SQL Injection still a major problem:
SQL Injection troubles firms, errors lead to breaches: Security experts see the secure software development lifecycle improving, but legacy applications and Web server flaws continue to offer a rich treasure trove for attackers.
Three indicted for Hannaford, Heartland data breaches: A grand jury has charged three men for their role in stealing more than 130 million credit and debit cards from Heartland Payment Systems and several other companies.The indictment makes for good reading, with references to SQL injection, distributed data collection servers, QA against major AV products and temporary messaging accounts to elude detection..."
"The federal indictment this week of three men for their roles in the largest data security breach in U.S. history also serves as an indictment of sorts against the fraud conducted by PCI – placing the burden of security costs onto retailers and card processors when what is really needed is the payment card industry investing in a secure business process.
A federal grand jury has indicted Albert Gonzalez of Miami and two yet unnamed Russian hackers for their alleged roles in the Heartland Payment Systems Inc. and Hannaford Brothers Co. thefts of 130 million credit and debit card data, plus the 40 million credit cards grabbed from TJX.
SQL Injection still a major problem:
SQL Injection troubles firms, errors lead to breaches: Security experts see the secure software development lifecycle improving, but legacy applications and Web server flaws continue to offer a rich treasure trove for attackers.
Three indicted for Hannaford, Heartland data breaches: A grand jury has charged three men for their role in stealing more than 130 million credit and debit cards from Heartland Payment Systems and several other companies.The indictment makes for good reading, with references to SQL injection, distributed data collection servers, QA against major AV products and temporary messaging accounts to elude detection..."
Webinar coming up - 3 Tactics for Securing Your Website and Driving Trust, Customers and Revenue

I have the pleasure of conducting a VeriSign-sponsored, IT Security-hosted, webinar next Wednesday on web site security. Given the prevalence of web site attacks, this is pretty timely. I hope you can check it out.
3 Tactics for Securing Your Website and Driving Trust, Customers and Revenue
Date: Wednesday, August 26, 2009
Time: 1PM ET / 10AM PT
If your customers visit your website and don’t think it’s secure, they won’t buy from you. Secure your transactions. Join this FREE live webinar to learn 3 ways your company can ensure your website is secure and you can improve transactions with your customers.
Get 3 easy tactics to secure your website now and drive trust, customers and revenue:
• Strategy to drive trust, customers and revenue by securing your website
• What are the costs and risks to online customers and your business
• Why you need to secure your e-commerce site
• 3 easy tactics to secure your website NOW
A Chance to Win
Live attendees will be entered for a chance to win an iPod Nano. One winner will be selected from the audience by random drawing.*
If you’re interested but can’t attend the live event, register today and we will send you a link to the on-demand archive when available.
We look forward to having you join us.
________________________________________
Featured Speakers:
Eric Ogren is the founder and principal analyst of the Ogren Group. Ogren’s background features over 15 years of enterprise security experience, becoming a highly regarded industry analyst. Coverage areas include virtualization security, alignment of security technologies with business requirements, evolution of endpoint security, authenication and user identity protection, application security, managing security in large enterprise environments, and consumer privacy issues. Prior to starting The Ogren Group, Ogren served as security analyst for the Yankee Group and ESG. Ogren has also served as vice president of marketing at security startups Okena, Sequation and Tizor. Additional vendor-side experience includes product leadership roles at RSA Security and Digital Equipment. Ogren holds a B.S. degree in mathematics from the University of Massachusetts and an M.S. degree in Computer Science from Boston University.
Ryan White is SSL Product Marketing Manager at VeriSign, Inc. Ryan has been at VeriSign for over 3 years helping to educate businesses about how to protect their site and customers with encryption technology.
Michael Oliver-Goodwin is a Contributing Editor of IT Security. He is a widely published writer and an experienced editor for publications, including PC World, MacWeek and InfoWorld.
*Employees of associated companies are not eligible for drawing. Person must live in the US to be eligible. Winner is chosen at random. Winner will be notified at the conclusion of the live webinar. One prize will be given out per person selected from the drawing.
Thursday, August 13, 2009
Patch management study shows IT taking significant risks
Posted to SearchSecurity.com -
"The latest research around patch management is a good reminder for security teams to move patch diligence up the stack to applications and to resist disabling signature checking for performance in UTMs.
Qualys Inc. presented an update at the recent Black Hat USA 2009 briefings to their Laws of Vulnerabilities research, a timely statistical review in light of the increase in Microsoft Internet Explorer, Microsoft Office, Adobe Reader, and Apple QuickTime application level attacks. The study, first conducted in 2004, is based on years of accumulated vulnerability scanning data of the Qualys installed base..."
"The latest research around patch management is a good reminder for security teams to move patch diligence up the stack to applications and to resist disabling signature checking for performance in UTMs.
Qualys Inc. presented an update at the recent Black Hat USA 2009 briefings to their Laws of Vulnerabilities research, a timely statistical review in light of the increase in Microsoft Internet Explorer, Microsoft Office, Adobe Reader, and Apple QuickTime application level attacks. The study, first conducted in 2004, is based on years of accumulated vulnerability scanning data of the Qualys installed base..."
Tuesday, August 11, 2009
Microsoft Security Essentials (MSE) shows no vision, expert says
Posted today on SearchSecurity.com.
"Microsoft's security program is lost in time.
While it works diligently to bring yesterday's antimalware solution to market with Microsoft Security Essentials (MSE), the company is completely losing the future of security definition to competitors, with recent evidence supplied courtesy of Google's Chrome OS announcement and Check Point's browser sandboxing feature. There are a few points where Microsoft security is losing time." ...
"Microsoft's security program is lost in time.
While it works diligently to bring yesterday's antimalware solution to market with Microsoft Security Essentials (MSE), the company is completely losing the future of security definition to competitors, with recent evidence supplied courtesy of Google's Chrome OS announcement and Check Point's browser sandboxing feature. There are a few points where Microsoft security is losing time." ...
Thursday, July 23, 2009
Written for Lumension - Endpoint Security: Moving Beyond AV

"Application whitelisting is emerging as the security technology that gives IT a true defense-in-depth capability, filling in the gaps that anti-virus (AV) was never designed to cover. Organizations have invested heavily in traditional AV solutions, often stacking AV filters from multiple vendors along the data path in the desperate hope that one of the products would stop malware from infecting the corporate or government endpoints. While AV plays a crucial role in identifying known malware and cleaning infected systems, the reality is that relying on layers of the same defense mechanism leaves organizations completely exposed to attacks and data theft from unknown or designer malware that can be delivered in web-based active code, downloaded encrypted code fragments, and persistent botnets. Security teams that know they need more than AV are now deploying application whitelisting technology to protect laptops, desktops, server and Point-of-Sale endpoints from unidentified malicious code as well as undetected code injections - and they are finding significant operational benefits due to fewer interruptions responding to infected endpoints.
This Ogren Group Special Report, Endpoint Security: Moving Beyond AV, commissioned by Lumension, presents the market demand for application whitelisting with recommended actions for security decision makers. Information in this report derives from Ogren Group research and interviews with enterprise security executives of global organizations." ...
Wednesday, July 22, 2009
OPSWAT quote for press release
OPSWAT is a neat company that develops toolkits for embedding security into applications. The most common need is for a general purpose interface to make calls to an AV product, allowing the application vendor to pick and choose the right AV engine for the job. OPSWAT also includes logic to facilitate a clean removal of security - a welcome capability for those of us who have ever attempted to uninstall an AV product when switching vendors. They do interesting work with a refreshingly pragmatic approach. I am pleased to support their press release with a quote:
“As the IT need for embedding security solutions in the fabric of the infrastructure becomes an increasing necessity due to the growing number of Internet-based threats, so does the ability to manage these solutions in an efficient manner,” said Eric Ogren, founder and principal analyst at the Ogren Group. “OPSWAT, Inc.’s Metascan technology provides the capability to bolt anti-malware scanning engines directly onto third-party software. Together with OESIS application management features, the acquisition of Metadefender’s technology nicely positions OPSWAT to provide a comprehensive, all-inclusive anti-malware scanning engine, benefiting vendors of secure products.”
“As the IT need for embedding security solutions in the fabric of the infrastructure becomes an increasing necessity due to the growing number of Internet-based threats, so does the ability to manage these solutions in an efficient manner,” said Eric Ogren, founder and principal analyst at the Ogren Group. “OPSWAT, Inc.’s Metascan technology provides the capability to bolt anti-malware scanning engines directly onto third-party software. Together with OESIS application management features, the acquisition of Metadefender’s technology nicely positions OPSWAT to provide a comprehensive, all-inclusive anti-malware scanning engine, benefiting vendors of secure products.”
New hacker skills optimize revenue
The latest from SearchSecurity:
"Malware is evolving into a rewarding, mature high-tech market, and it's not surprising that the financial incentives of developing and peddling malware can outweigh the risk of penalties that include spending quality time in jail. Malicious code developers may not be business school graduates, but they appreciate basic business principles to expand their addressable market; optimizing revenue from the install base and leveraging technology. That was the takeaway from the Cisco 2009 Midyear Security Report, an excellent summary of the major malware activity written for a less-technical executive audience..."
"Malware is evolving into a rewarding, mature high-tech market, and it's not surprising that the financial incentives of developing and peddling malware can outweigh the risk of penalties that include spending quality time in jail. Malicious code developers may not be business school graduates, but they appreciate basic business principles to expand their addressable market; optimizing revenue from the install base and leveraging technology. That was the takeaway from the Cisco 2009 Midyear Security Report, an excellent summary of the major malware activity written for a less-technical executive audience..."
Friday, July 17, 2009
Offering SaaS for securing mobile devices
The following has just been posted in TechTarget's SearchSecurityChannel:
"Intelligent mobile devices are revolutionizing the way remote users connect to their business, and thus are presenting unique security opportunities for solution providers. Blackberrys, iPhones, and the emerging category of promising Mobile Internet Devices (MIDs) are exploding in popularity, fueled by the availability of easy-to-use application interfaces to access information (both business and personal) in non-traditional ways..."
"Intelligent mobile devices are revolutionizing the way remote users connect to their business, and thus are presenting unique security opportunities for solution providers. Blackberrys, iPhones, and the emerging category of promising Mobile Internet Devices (MIDs) are exploding in popularity, fueled by the availability of easy-to-use application interfaces to access information (both business and personal) in non-traditional ways..."
Monday, July 13, 2009
Cloud-based security services should start private
Posted on SearchSecurity.com this week:
"Many early stage cloud vendors have it backwards when it comes to offering cloud-based services. They implement Software as a Service (SaaS) first to demonstrate their vision and then develop enterprise integration features. But the right way to go about it is to support corporate clouds in early product releases. IT is typically conservative about business risk and likes to retain control over sensitive data and applications. Security SaaS vendors may be better served by allowing IT to start by hosting its own private cloud service, integrated with existing data repositories and administrative systems and then provide a path to the full cloud application environment"...
"Many early stage cloud vendors have it backwards when it comes to offering cloud-based services. They implement Software as a Service (SaaS) first to demonstrate their vision and then develop enterprise integration features. But the right way to go about it is to support corporate clouds in early product releases. IT is typically conservative about business risk and likes to retain control over sensitive data and applications. Security SaaS vendors may be better served by allowing IT to start by hosting its own private cloud service, integrated with existing data repositories and administrative systems and then provide a path to the full cloud application environment"...
Wednesday, July 8, 2009
Ogren Group Impact: MokaFive LivePC at your service

MokaFive has the innovative idea of deploying virtual desktops as a service for remote users. The payoffs can be large for IT – centralized control of endpoint configurations for meeting compliance mandates, protection of sensitive data while working in remote locations, and end-user convenience of having ubiquitous access to their desktop. The Ogren Group believes that with performance concerns abating due to the virtual desktop running on the endpoint, virtual desktops will usher in new opportunities for IT to cost effectively service business users.
Wednesday, July 1, 2009
Tufin takes an operational view on firewall rules management
Tufin is one of the promising companies in the firewall rules management market. While security and managing compliance is of primary importance, Tufin also appreciates the operational cost savings benefits of controlling and automating firewall rules administration. The following is a quote for their Automatic Policy Generation press release that hit the wires on June 29th:
"Automating the creation of optimized firewall rule bases is critical to establishing an accurate baseline for increasing network security and reducing operational costs," said Eric Ogren, principal analyst of the Ogren Group. "Well defined firewall rules lower the risk of creating holes in network security, eliminate many of the business disruption issues that can accompany firewall deployments, and reduce the number of costly support calls. Automation ensures that firewall rule bases act on the intelligence discovered from actual observed business traffic."
"Automating the creation of optimized firewall rule bases is critical to establishing an accurate baseline for increasing network security and reducing operational costs," said Eric Ogren, principal analyst of the Ogren Group. "Well defined firewall rules lower the risk of creating holes in network security, eliminate many of the business disruption issues that can accompany firewall deployments, and reduce the number of costly support calls. Automation ensures that firewall rule bases act on the intelligence discovered from actual observed business traffic."
Twitter risks, Facebook threats trouble security pros
Nice way to start July with a new SearchSecurity post!
"The explosive growth in social networking has positioned many security teams solidly between a rock and a hard place. On the one hand, conscientious security executives cannot ignore the data loss and regulatory compliance risks to the corporation; on the other hand, security cannot politically survive by categorically objecting to other organizations innovative use of new business tools...."
"The explosive growth in social networking has positioned many security teams solidly between a rock and a hard place. On the one hand, conscientious security executives cannot ignore the data loss and regulatory compliance risks to the corporation; on the other hand, security cannot politically survive by categorically objecting to other organizations innovative use of new business tools...."
Subscribe to:
Posts (Atom)
