RSA Security’s security problems, as evidenced by recent intrusions into defense contractor networks, are causing more than a few organizations to not only re-evaluate their commitment to SecurID authentication, but also to re-evaluate the role of authentication in their security programs. I have already heard of large companies that have embarked on a multi-year program to transition from premium-priced SecurID to cheaper alternatives.
RSA desperately needs to disclose more information about the nature of the breach, and what actions RSA customers should be taking to protect themselves. In the absence of information, security organizations should assume the worst – that their business is next in line for a breach – and should be prepared to detect and act upon an intrusion.
If you are a SecurID customer there are a few things that you may consider to help keep your business secure:
Add the device as part of the “something you have” authentication factor. Users would need SecurID from an approved device to gain access to applications and the network. This can be done either directly with PKI keys on the chip (e.g. Wave Systems using the TPM in Intel machines) or by evaluating the device (e.g. iovation assessing the machine fingerprint). Only a few users will ever need to access resources from unauthorized computers, so narrow this exposure by also authenticating the device.
Heighten efforts to detect APTs and intrusions. It is actually easier to avoid getting caught by launching a spear-phishing attack, penetrating corporate defenses with malware, and letting the APT deliver secrets than it is impersonating a user and bumbling around a network like Diogenes looking for secrets. Step up automated efforts to catch configuration drifts out of compliance and non-compliant network traffic – signs that you may be under attack.
With increased diligence, you can verify your trust in SecurID.
Friday, June 3, 2011
Friday, May 20, 2011
Endpoint Security: Become Aware of Virtual Desktop Infrastructures!
I completed a pretty neat whitepaper for Trend Micro just before leaving for a couple of weeks of travel. Here is an abstract of the exec summary and you should be able to get the rest at Trend Micro.

Virtual desktops infrastructures, VDI, present IT with the unique opportunity to fundamentally improve the way desktops are purchased, deployed, managed, and secured. Organizations are attracted to VDI’s promise to reduce operating costs, provide users with wide choices of devices, improve application performance, and enhance corporate security against malware and loss of sensitive data. The benefits are compelling, with survey data showing approximately 70 percent of CIOs reporting VDI projects planned for 2010.
However, enterprises find while scaling from proof-of-concept projects to full deployment that desktop security software that is not optimized for VDI causes storage and network contention that significantly degrades virtual machine densities. The Ogren Group recommends the following guidelines in selecting endpoint security to help organizations preserve the benefits of VDI:
Choose endpoint security that is specifically designed for VDI performance. Endpoint security needs an architecture that avoids performance drags from storage and network resource contention.
Require intelligent use of cloud-based security to keep agent bloat from affecting VDI density. Evaluate approaches that scale by blocking attacks in the cloud, and do not steadily increase processor demands for VM-based endpoint security.
Insist on VDI-aware approaches allowing endpoint security to simplify administration of virtual and physical desktops. Since organizations will need to operate a mix of physical and virtual endpoint security, the security software should be optimized for each environment for user satisfaction, and ease of administration.
Trend Micro’s OfficeScan and Deep Security products are designed for use in VDI environments. The Ogren Group finds that Trend Micro exceeds requirements for protecting the business while enabling IT to realize the benefits of virtual desktop infrastructures.
Virtual desktops infrastructures, VDI, present IT with the unique opportunity to fundamentally improve the way desktops are purchased, deployed, managed, and secured. Organizations are attracted to VDI’s promise to reduce operating costs, provide users with wide choices of devices, improve application performance, and enhance corporate security against malware and loss of sensitive data. The benefits are compelling, with survey data showing approximately 70 percent of CIOs reporting VDI projects planned for 2010.
However, enterprises find while scaling from proof-of-concept projects to full deployment that desktop security software that is not optimized for VDI causes storage and network contention that significantly degrades virtual machine densities. The Ogren Group recommends the following guidelines in selecting endpoint security to help organizations preserve the benefits of VDI:
Choose endpoint security that is specifically designed for VDI performance. Endpoint security needs an architecture that avoids performance drags from storage and network resource contention.
Require intelligent use of cloud-based security to keep agent bloat from affecting VDI density. Evaluate approaches that scale by blocking attacks in the cloud, and do not steadily increase processor demands for VM-based endpoint security.
Insist on VDI-aware approaches allowing endpoint security to simplify administration of virtual and physical desktops. Since organizations will need to operate a mix of physical and virtual endpoint security, the security software should be optimized for each environment for user satisfaction, and ease of administration.
Trend Micro’s OfficeScan and Deep Security products are designed for use in VDI environments. The Ogren Group finds that Trend Micro exceeds requirements for protecting the business while enabling IT to realize the benefits of virtual desktop infrastructures.
Wednesday, May 4, 2011
Wedge Networks
I commented on the content-focused approach of Wedge Networks and was pleased to support their BeSecure announcement.
Eric Ogren, analyst and founder, Ogren Group, said:
"The trend towards moving applications and data into private and public clouds introduces a new realm of very real security risks. Critical to identifying and remediating new threats will be a content-based approach offering deep inspection and clear visibility into network traffic. Wedge Networks is well positioned to meet these challenges with its BeSecure Web Gateway that enables organizations to protect sensitive data and have a clear view of content as it traverses the cloud."
Recent white papers ... ForeScout
Recent white papers ... SenSage
VDI Security: Centralized Control
One of my favorite articles I wrote for TechTarget’s Information Security Magazine was published last year. It turned out to be pretty popular with a huge number of downloads. I recently received the following mail from SearchMidmarketSecurity.com with a link you can check out.
Virtual desktop infrastructure implementation provides security pros with a perfect opportunity to re-architect their organization’s endpoint security and management. The fact that virtual desktops are managed via centralized services means that an entirely new approach can be taken with respect to endpoint security and desktop configurations, giving security teams much more control over their company’s data.
http://go.techtarget.com/r/13746997/6224113/1
This complimentary IT Decision Checklist explores the most significant security opportunities coming out of VDI solutions and how you can leverage them to fortify your own organization’s security posture.
Explore how to achieve the following in a VDI environment:
-- Control endpoint configurations
-- Isolate sensitive and regulated data
-- Enhance antimalware strategy
-- And more
Saturday, April 2, 2011
Application whitelisting: an extra layer of malware defense

I am a big fan of whitelisting as a complement to attack-centric approaches, and as a foundational layer of defense. Even though it is not called whitelisting, I see Apple successfully using this method for ensuring compliance for iPad, iPhone and iTunes. It is a technology that also works in the corporate environment, even if it is not an AV killer.
I was excited when Information Security Magazine asked me to write an article on AWL. I enjoyed talking to the major vendors and my enterprise security contacts about whitelisting, and am happy with the final result. I hope you also find it to be an interesting read.
“Application whitelisting makes too much pragmatic sense to not have appeal as an antimalware mechanism. Intuitively, a technology operating in the kernel that detects suspicious changes in an IT-controlled software configuration should be easier to scale than a technology that looks at all files to identify and clean attacks.” The rest of the story can be found here.
Friday, March 25, 2011
Vineyard Networks Application Intelligence and Classification
Vineyard Networks is a pretty cool company that supplies high performance application intelligence logic to vendors of firewalls, WAN optimization appliances, and other network communications equipment. Vineyard has an interesting perspective on how security and operations teams both get the most out of application intelligence.
My contribution to their press release reads, “Organizations require the next generation of networking products to leverage application intelligence for greater visibility and control of the cyber-infrastructure. Security and networking vendors that hope to compete for enterprise business better offer a solid foundation of high performance application awareness and classification.”
My contribution to their press release reads, “Organizations require the next generation of networking products to leverage application intelligence for greater visibility and control of the cyber-infrastructure. Security and networking vendors that hope to compete for enterprise business better offer a solid foundation of high performance application awareness and classification.”
Wednesday, March 23, 2011
RSA Caught in a Compromised Position

There has been a lot written about the breach of RSA Security and the effect the advanced persistent threat has on SecurID users. The Open Letter to RSA Customers is so vague that it is hard to figure out exactly what the exposure is, and more importantly what to recommend to corporations relying on SecurID for two-factor authentication. I used worked with Security Dynamics, maker of SecurID before changing their name to RSA, as Director of Product Management from 1993-1998, so let me add to the discussion (I no longer have any financial interests in RSA Security).
The big risk is theft of source code that would allow an intruder to design a custom attack against servers installed on customer premises. For instance, all the attacker would need to do is exploit a weakness in the management protocol to be able to insert a backdoor or impersonate a privileged user to steal secrets. This scenario would be very serious as RSA would not be in a position to assure customers of the integrity of their authentication system, and wouldn’t even know how the attack manifests itself until customers are infected.
The lesser risk is theft of serial numbers and seed values. An attacker would still need to associate the exposed seed and serial number with the company that the purchased the token and the user possessing the token. That is really hard for an outsider to do, and if successful all an attacker achieves is one random user to impersonate. Yes, it is a concern but it seems like a manageable one.
If you are a SecurID customer there are a couple of procedural things you should do while RSA conjures up an explanation that may reduce the risk of an infected authentication system:
Audit IPS and firewall policies to ensure that there are no unauthorized communications with SecurID servers. This includes outbound connections that could signal a successful penetration of malware. This communication to the attacker might be the only way to detect a devastating breach of security.
Scale back on remote management of SecurID, including IT service desk procedures. Management operations that originate from outside the server perimeter are particularly dangerous. Consider assigning a member of your security team to perform privileged operations from a physically connected console, and disallow privileged operations over the Internet.
Finally, voice your displeasure at RSA in no uncertain terms and send them the bill for you extra security precautions. If you are a bank using SecurID for high-roller customers, then you are responsible for disclosure and re-imbursement if the system is compromised – RSA owes you more guidance than what I have seen.
It is ironic that enterprises have to disclose security incidents to consumers, but here we have a one of the most trusted security companies on the planet keeping business in the dark. Hopefully, RSA Security soon issues another open letter that is more enlightening on how customers should protect themselves.
Monday, March 21, 2011
Proofpoint Email Security Service
Cloud-based security services can help drive down the operational costs of securely handling corporate information, especially securing the large volume of information contained in saved email. Proofpoint attacks this problem with a service approach that delivers cost benefits without jeopardizing obedience to compliance mandates. Their full release includes my supporting quote:
"The IT landscape is changing at a rapid pace, and organizations are struggling to keep up with regulatory and security pressures," said Eric Ogren, principal analyst of the Ogren Group. "By leveraging secure business services in the cloud, organizations may be able to alleviate the increased compliance burdens they are facing without having to make large investments in on-premise deployments and without having to give up control of their sensitive data."
"The IT landscape is changing at a rapid pace, and organizations are struggling to keep up with regulatory and security pressures," said Eric Ogren, principal analyst of the Ogren Group. "By leveraging secure business services in the cloud, organizations may be able to alleviate the increased compliance burdens they are facing without having to make large investments in on-premise deployments and without having to give up control of their sensitive data."
Tuesday, March 15, 2011
Does compliance inhibit security innovation?
I had some fun with a SearchSecurity.com podcast on the impact of compliance on security innovation. For me, there is no question that compliance stifles innovation, but people I really respect feel differently. It's an interesting question to think about ... or even listen to here.
Friday, March 11, 2011
Be comfortable with key management to secure your data
Encrypting sensitive data on premise before the data gets to the cloud or gets on a truck is a best practice when utilizing offsite storage. I have talked with many organizations that insist they will never store regulated data in the cloud. In fact, when asked what it would take to make them more comfortable they do not even spend 3 seconds of think time before shuddering at the prospect of their CEO appearing on TV to explain a major data loss incident. Many cannot envision any confidence in data security that will enable off-site storage of sensitive data. However, with proper key management organizations can safely reduce expenses by using storage services for encrypted data only.
Seagate announced that it has sold more than one million self-encrypting drives. This is important to security officers because disk drives, and the regulated data they contain, do not stay in the data center forever. Seagate claims that 80% of the disk drives that are sent out for repair, or returned at the expiration of a lease, contain readable data. Furthermore, disks that are retired undergo expensive physical cleaning and shredding processes – unless that is overlooked due to human error. Self-encrypting drives automatically encrypt all data on disk to reduce the risk of data loss without adversely affecting performance or requiring incremental security procedures.
There are also many vendors offering to use shared cloud-based resources to drive down the costs of handling sensitive data for such activities as backup/restore (IBM, i365), email archiving (AppRiver, ProofPoint), and world-wide availability (RSA Security, Trend Micro). The critical element for cloud-based services is also to encrypt and decrypt the data on premise so it is not at risk of exposure in the cloud. This also reduces the IT burden of auditing service provider security policies and allows the organization to leverage efficient storage services.
Both of the physical and cloud-based secure storage objectives require organizations to manage their own cryptographic keys. That is a core competency that every security-aware corporation must have, especially if they choose to enable the use of external service providers. Companies effectively use services with sensitive data all the time (e.g. payroll services, 401K programs, health networks, sales force information, etc) so they should feel more comfortable with evaluating secure storage services knowing that the company still controls the data.
Seagate announced that it has sold more than one million self-encrypting drives. This is important to security officers because disk drives, and the regulated data they contain, do not stay in the data center forever. Seagate claims that 80% of the disk drives that are sent out for repair, or returned at the expiration of a lease, contain readable data. Furthermore, disks that are retired undergo expensive physical cleaning and shredding processes – unless that is overlooked due to human error. Self-encrypting drives automatically encrypt all data on disk to reduce the risk of data loss without adversely affecting performance or requiring incremental security procedures.
There are also many vendors offering to use shared cloud-based resources to drive down the costs of handling sensitive data for such activities as backup/restore (IBM, i365), email archiving (AppRiver, ProofPoint), and world-wide availability (RSA Security, Trend Micro). The critical element for cloud-based services is also to encrypt and decrypt the data on premise so it is not at risk of exposure in the cloud. This also reduces the IT burden of auditing service provider security policies and allows the organization to leverage efficient storage services.
Both of the physical and cloud-based secure storage objectives require organizations to manage their own cryptographic keys. That is a core competency that every security-aware corporation must have, especially if they choose to enable the use of external service providers. Companies effectively use services with sensitive data all the time (e.g. payroll services, 401K programs, health networks, sales force information, etc) so they should feel more comfortable with evaluating secure storage services knowing that the company still controls the data.
Tuesday, March 8, 2011
Intelligent Whitelisting
Intelligent Whitelisting is a new site encouraging an open discussion on all things related to whitelisting, and application whitelisting. There are some really good security ideas being expressed in there – including a new one my me on VDI and AWL working together. Check it out when you get a chance, and make it a resource for security discussions.
Even though Lumension is sponsoring the site and panel of posters, they have made it clear that this is not the place for product review discussions. They are looking to build a community of thinkers and doers for the next generation of endpoint security and endpoint management. It’s a great concept that is gaining momentum!
Friday, February 18, 2011
Last thoughts from RSA Conference
The RSA Conference is now over. I’ve been coming to a lot of these and I have to say that this is one of the better ones. I saw a lot of innovation, new ideas, and general buzz at the show. It felt great to see security starting to get out of its doldrums.
I loved seeing Art Coviello on stage again. I liked Art a lot when he was at RSA and he has played a major role in building a $700M business. It is a personal note, but it was pretty cool this afternoon seeing a Security Dynamics alum (via CrossComm) sitting with a President!
I also liked the fact that security is starting to catch on to the concept of providing information to IT and network operations teams. Security sees everything so why not communicate some of what it sees to the rest of the IT organization? The next-gen firewall conversations, usually centered on Palo Alto Networks is a perfect example of this. Another is a whitepaper that Qualys was featuring that emphasizes the strategic business efficiencies to be gained from secure cloud services.
SonicWALL also surprised me with a big honkin’ box that is loaded with application level logic. That company has come a long ways from the one that averaged 1.6 boxes per small business when I first met them.
Time to run for the airport. It was a good week – catching up with lots of friends, having great security conversations, and contributing to the Trusted Computing Group and Anti-malware sessions!
Subscribe to:
Posts (Atom)
