Business organizations are embracing the use of Android and Apple iOS-based tablets and smartphones in a big way. And why not? - they are light, easy to use, easy to carry, and easy to personalize. Bring your own device may be one of those cases where the marketing hype actually lags customer adoption!
The challenge for security teams is how to say "yes" to this revolution in end-user computing while still protecting the business infrastructure. If your organization can mandate installation of a mobile security application, then by all means leverage that capability. If your business cannot dictate endpoint security software, then you can use network security to assess and audit each tablet or smartphone device as it joins the network. In fact, that is the only way you can pragmatically account for both managed and unmanaged devices with one security solution. ForeScout, Cisco, Juniper, Bradford, and StillSecure have intereesting ideas in this space. ForeScout in particular has a compelling BYOD story that they are starting to tell here.
Friday, March 30, 2012
Friday, March 16, 2012
SonicWALL or SonicBoom !
My rule of thumb on evaluating acquisitions is "How does the acquisition help customers in ways that cannot be achieved organically?”. Sometimes the answer lies in acquiring key technology such as with Trend Micro's acquisition of Third Brigade or Juniper's purchase of Mykonos; sometimes the answer lies in bringing solutions to new opportunities such as with IBM scoring Q1 Labs. It is extraordinarily hard to blend diverse corporate cultures even with beneficial common goals, which is one of the reasons that acquisitions often fall short of their potential.
It has been a few days since Dell and SonicWALL have announced their acquisition, and given time to think about it I still love the deal. I'm not passing judgment on the value of the deal, but on its potential impact on customers. This agreement promises to benefit customers in fundamental ways and looks to be everything that a good deal should be.
SonicWALL is reinventing themselves from a company servicing SMB markets to a company marketing application intelligent next generation firewall products that compete strongly in high performance service provider networks. However, their past brand identity as an SMB-oriented vendor makes it challenging for SonicWALL to achieve explosive growth with its SuperMassive product line in large enterprise markets. Now SonicWALL has major financial backing to continue their reanimation in enterprise security and an opportunity to launch a new brand.
Dell is in a similar position of selling efficiently to SMBs, but desiring entrees to larger deal sizes. Security tends to be driven by up-market revenues - in SonicWALL they have a flagship network security product that would be attractive to any large enterprise, and Dell also acquires security technology DNA that can only help beef up Dell's security product lines.
The only losers I can find in this deal are SonicWALL competitors. The space for next generation firewalls is heating up, and not everybody can be a winner – this will only get more interesting!
It has been a few days since Dell and SonicWALL have announced their acquisition, and given time to think about it I still love the deal. I'm not passing judgment on the value of the deal, but on its potential impact on customers. This agreement promises to benefit customers in fundamental ways and looks to be everything that a good deal should be.
SonicWALL is reinventing themselves from a company servicing SMB markets to a company marketing application intelligent next generation firewall products that compete strongly in high performance service provider networks. However, their past brand identity as an SMB-oriented vendor makes it challenging for SonicWALL to achieve explosive growth with its SuperMassive product line in large enterprise markets. Now SonicWALL has major financial backing to continue their reanimation in enterprise security and an opportunity to launch a new brand.
Dell is in a similar position of selling efficiently to SMBs, but desiring entrees to larger deal sizes. Security tends to be driven by up-market revenues - in SonicWALL they have a flagship network security product that would be attractive to any large enterprise, and Dell also acquires security technology DNA that can only help beef up Dell's security product lines.
The only losers I can find in this deal are SonicWALL competitors. The space for next generation firewalls is heating up, and not everybody can be a winner – this will only get more interesting!
Tuesday, February 21, 2012
Early Vibe: CO3 Systems
CO3 Systems is a new security company with an excellent position, seasoned management team, and a ton of potential.
CO3 provides a cloud-based service to help companies prepare for, and then navigate through the process of a disclosure event resulting from a breach of regulated data. It fulfills such an obvious need that I am surprised more vendors are not specializing here – every large company will suffer a serious incident and every exposure of regulated data invariably results in expensive pandemonium. CO3 aims to help businesses save significant expense by generating a custom-fit incident response strategy and then providing the tools to manage the complexities of the notification process.
Market need: Most enterprises are affected by several international, federal, and state regulations for regulated data. Furthermore, the regulations regarding consumer privacy and the best practices associated with those regulations can change. Most enterprises are also not in the disclosure security business so CO3 can help educate the business about the potential costs and expected organization and “fire-drill” process when an incident occurs.
Leadership ability: The management team is as strong as they come. In fact, I would feel better about CO3 if they had been thrown from a few more horses. The team lists @Stake, Arbor, Axent, Counterpane, and Symantec in their lists of credits. The only obvious clunker is Authentica and even there engineering was the strength of that company.
Opportunity: The cloud service approach makes a lot of sense as companies will run low-expense what-if exercises most of the time, and then will experience a massive spike in activity when the breach is detected. CO3 will have to figure out how to deliver continuous education/service to maintain a healthy steady-state revenue flow and then price the disclosure service to reflect its value during a breach – without appearing predatory. CO3 can also drive managed service revenues which would make it attractive to large systems integrators, MSSPs, and even insurance companies.
It will be interesting to see how CO3 executes. Most security startups promise to rid the world of an attack or an obsolete security technology, but then have nothing to offer their customers if their product gets beat by a clever attack. CO3 spends the time researching the regulatory disclosure requirements, working with their customers to have an actionable strategy in place, and then helping to coordinate the response. It is one of the few areas in security with clear ROI benefits. They are nicely positioned with an experienced team – look for good things from CO3.
CO3 provides a cloud-based service to help companies prepare for, and then navigate through the process of a disclosure event resulting from a breach of regulated data. It fulfills such an obvious need that I am surprised more vendors are not specializing here – every large company will suffer a serious incident and every exposure of regulated data invariably results in expensive pandemonium. CO3 aims to help businesses save significant expense by generating a custom-fit incident response strategy and then providing the tools to manage the complexities of the notification process.
Market need: Most enterprises are affected by several international, federal, and state regulations for regulated data. Furthermore, the regulations regarding consumer privacy and the best practices associated with those regulations can change. Most enterprises are also not in the disclosure security business so CO3 can help educate the business about the potential costs and expected organization and “fire-drill” process when an incident occurs.
Leadership ability: The management team is as strong as they come. In fact, I would feel better about CO3 if they had been thrown from a few more horses. The team lists @Stake, Arbor, Axent, Counterpane, and Symantec in their lists of credits. The only obvious clunker is Authentica and even there engineering was the strength of that company.
Opportunity: The cloud service approach makes a lot of sense as companies will run low-expense what-if exercises most of the time, and then will experience a massive spike in activity when the breach is detected. CO3 will have to figure out how to deliver continuous education/service to maintain a healthy steady-state revenue flow and then price the disclosure service to reflect its value during a breach – without appearing predatory. CO3 can also drive managed service revenues which would make it attractive to large systems integrators, MSSPs, and even insurance companies.
It will be interesting to see how CO3 executes. Most security startups promise to rid the world of an attack or an obsolete security technology, but then have nothing to offer their customers if their product gets beat by a clever attack. CO3 spends the time researching the regulatory disclosure requirements, working with their customers to have an actionable strategy in place, and then helping to coordinate the response. It is one of the few areas in security with clear ROI benefits. They are nicely positioned with an experienced team – look for good things from CO3.
Thursday, February 2, 2012
NAC and VDI work well together
I have spoken with a few companies lately that have made a nice security solution out of integrating NAC and VDI products.
Security officers have always liked most of the traditional NAC story – automatically assess the health of the endpoint, control access to applications at the port level, and have end-users bring their own devices into compliance. That has led to a resurgence of interest in NAC products from the likes of Cisco, ForeScout, Juniper and Microsoft.
However, the NAC problem has always been the concept of quarantining devices that fail health checks, are unmanaged because of device type (such as iPads or mobile devices), or are unmanaged because they are owned by business partners (and maybe do not run 802.1x). In many of these cases the devices cannot automatically be brought into a safe compliant state, but the user still needs to conduct business on the network. There are not many security officers that want to tell business executives that they have blocked access to the network – a better approach is to offer an alternative delivery of the application.
A solution for some is to host guest desktops in the datacenter and to use VDI from the likes of Citrix, Microsoft, Quest or VMware to allow the user to do their jobs. With VDI, the organization has far less concerns of valuable data residing on an infected endpoint since the data never leaves the datacenter in a persistent form, access to critical applications is still controlled by strong authentication, and security can recommend a safe, compliant means of using the network.
If you are running NAC for automated remediation and quarantining of non-compliant or unregistered endpoint, look into granting access to applications with VDI.
Security officers have always liked most of the traditional NAC story – automatically assess the health of the endpoint, control access to applications at the port level, and have end-users bring their own devices into compliance. That has led to a resurgence of interest in NAC products from the likes of Cisco, ForeScout, Juniper and Microsoft.
However, the NAC problem has always been the concept of quarantining devices that fail health checks, are unmanaged because of device type (such as iPads or mobile devices), or are unmanaged because they are owned by business partners (and maybe do not run 802.1x). In many of these cases the devices cannot automatically be brought into a safe compliant state, but the user still needs to conduct business on the network. There are not many security officers that want to tell business executives that they have blocked access to the network – a better approach is to offer an alternative delivery of the application.
A solution for some is to host guest desktops in the datacenter and to use VDI from the likes of Citrix, Microsoft, Quest or VMware to allow the user to do their jobs. With VDI, the organization has far less concerns of valuable data residing on an infected endpoint since the data never leaves the datacenter in a persistent form, access to critical applications is still controlled by strong authentication, and security can recommend a safe, compliant means of using the network.
If you are running NAC for automated remediation and quarantining of non-compliant or unregistered endpoint, look into granting access to applications with VDI.
Friday, December 30, 2011
AlgoSec introduces firewall management for virtualized environments
AlgoSec, Tufin and Firemon are the Big 3 for firewalls rules management with a few others (Skybox and Athena to name a couple) starting to catch on. AlgoSec has hired a really good marketing director who will have a noticable impact. Sam Erdheim's work started with this AlgoSec press release supporting virtual environments.
“The dynamic nature of virtualization, especially the rapid provisioning of new applications and desktops across data centers, presents a new set of security challenges for IT organizations,” said Eric Ogren, principal analyst of the Ogren Group. “Firewall rules management software is a critical must-have capability to control access and ensure tight security for companies evolving from physical to virtual environments.”
“The dynamic nature of virtualization, especially the rapid provisioning of new applications and desktops across data centers, presents a new set of security challenges for IT organizations,” said Eric Ogren, principal analyst of the Ogren Group. “Firewall rules management software is a critical must-have capability to control access and ensure tight security for companies evolving from physical to virtual environments.”
Friday, December 2, 2011
“The malware, a version of a toolkit available since 2005…”
The story of the RSA attacks, as Qualys recently posted a very detailed study of the Adobe Flash exploit that caused all of the trouble at RSA last spring. It is a very thorough study – right down to a couple of pages of code.
Loved the human angle of a security-conscious person yanking the offending email out of a spam folder so they could open the infected XLS attachment. Good stuff. There will always be cases where people just make a mistake and have a lapse of judgment.
Great observation that some of the new security features found in Windows 7, such as Data Execution Prevention, probably would have thwarted the attack. It goes to show how hard it is for IT to move forward with a new version of an OS. Heck, it is hard even to move forward with a safer version of Flash or to enforce safe browser settings.
We know the half-life of a vulnerability and the difficulty in patching endpoints. Perhaps we should add a Law of Vulnerability for the life expectency of unpatchable software.
Loved the human angle of a security-conscious person yanking the offending email out of a spam folder so they could open the infected XLS attachment. Good stuff. There will always be cases where people just make a mistake and have a lapse of judgment.
Great observation that some of the new security features found in Windows 7, such as Data Execution Prevention, probably would have thwarted the attack. It goes to show how hard it is for IT to move forward with a new version of an OS. Heck, it is hard even to move forward with a safer version of Flash or to enforce safe browser settings.
We know the half-life of a vulnerability and the difficulty in patching endpoints. Perhaps we should add a Law of Vulnerability for the life expectency of unpatchable software.
Thursday, September 29, 2011
VDI: it's about people
After participating in analyst events with the world’s leading VDI vendors (AppSense, Citrix, VMware) , it is increasingly apparent that the marketing of virtual desktops needs to get personal and emotional in a hurry if the industry expects to see explosive growth. For all of the VDI hype and messages of IT control, there are precious few deployments of more than 1000 seats. One possible reason is that end-users do not see what VDI does for them that cannot be easily done with the present physical approach of applications installed on laptops. Virtualization vendors trumpet the IT benefits while marketing to server teams - VDI is doomed to niche uses unless vendors can lead people to clamor for the new capabilities introduced by the technology.
Vendor marketing messaging and positioning targets IT decision makers with promises of enhancing data security, controlling application environments, saving operational expenses, and enabling business agility for existing applications. However, when it comes to re-inventing user experiences the user organizations participate in endpoint architecture decisions and it is personal demand for new capabilities that is going to drive explosive growth in virtualization at the endpoint.
One good start will be to shift the words virtual desktop infrastructure to the fine print of the back page of all market-oriented material. There is not one word in VDI that a user really wants: few people are comfortable with their understanding of anything virtual, a desktop is a necessary evil only to run desired programs, and do users rise to the edge of their seats when the conversation turns to infrastructure? There is amazing technology and potential in virtualization that is buried under IT-oriented technical jargon. It is critical that vendors tap into key user emotions related to making their computing lives easier. A few examples may be:
Imagine having business and personal applications at your fingertips not matter where you are or what computer you’re using – without painful software installations or generic browser user interfaces. You do not need the frustration of being unproductive on the road because you forgot to pre-install software, or you had to borrow a computer that doesn’t have your presentation on it. VDI can provide you access to more exciting programs at your fingertips than you can possibly install yourself.
Imagine relief from not getting upset waiting while Windows installs important updates and reboots your machine just when you’re ready to use your computer. System and application software is maintained by IT in the data center, meaning the most up to date versions are ready to run – before you need them! No more waiting like a second citizen while your computer manages itself; no more playing “IT” to configure security software or applications.
Imagine the freedom of not having to lug a laptop home from the office every day, and back again. There have to be better ways to exercise your upper body and back muscles. There is no need to include laptops, power cords and heavy-weight knapsacks in every commute. Virtualization allows you to run business applications – including Microsoft Office – on home computers, tablets, or mobile devices without having to install application software.
It is rare to find organizations that plan to be entirely VDI hosted in the data center - laptops are not going away anytime soon and even the early adopters seem to only envision a 20% penetration. For virtualization at the endpoint to move forward significantly, vendors need to find and promote visions of the technology that provide benefits that are not easily achieved in physical endpoints or through browsers. The present path of marketing solely IT benefits will result in organizations maintaining about 80% of their endpoints as physical desktop and laptop systems, VDI will be an additive expense, and the great opportunity to impact user lifestyles with virtualization will be lost. It is about people – let’s look for ways for virtualization to change user experiences.
Vendor marketing messaging and positioning targets IT decision makers with promises of enhancing data security, controlling application environments, saving operational expenses, and enabling business agility for existing applications. However, when it comes to re-inventing user experiences the user organizations participate in endpoint architecture decisions and it is personal demand for new capabilities that is going to drive explosive growth in virtualization at the endpoint.
One good start will be to shift the words virtual desktop infrastructure to the fine print of the back page of all market-oriented material. There is not one word in VDI that a user really wants: few people are comfortable with their understanding of anything virtual, a desktop is a necessary evil only to run desired programs, and do users rise to the edge of their seats when the conversation turns to infrastructure? There is amazing technology and potential in virtualization that is buried under IT-oriented technical jargon. It is critical that vendors tap into key user emotions related to making their computing lives easier. A few examples may be:
Imagine having business and personal applications at your fingertips not matter where you are or what computer you’re using – without painful software installations or generic browser user interfaces. You do not need the frustration of being unproductive on the road because you forgot to pre-install software, or you had to borrow a computer that doesn’t have your presentation on it. VDI can provide you access to more exciting programs at your fingertips than you can possibly install yourself.
Imagine relief from not getting upset waiting while Windows installs important updates and reboots your machine just when you’re ready to use your computer. System and application software is maintained by IT in the data center, meaning the most up to date versions are ready to run – before you need them! No more waiting like a second citizen while your computer manages itself; no more playing “IT” to configure security software or applications.
Imagine the freedom of not having to lug a laptop home from the office every day, and back again. There have to be better ways to exercise your upper body and back muscles. There is no need to include laptops, power cords and heavy-weight knapsacks in every commute. Virtualization allows you to run business applications – including Microsoft Office – on home computers, tablets, or mobile devices without having to install application software.
It is rare to find organizations that plan to be entirely VDI hosted in the data center - laptops are not going away anytime soon and even the early adopters seem to only envision a 20% penetration. For virtualization at the endpoint to move forward significantly, vendors need to find and promote visions of the technology that provide benefits that are not easily achieved in physical endpoints or through browsers. The present path of marketing solely IT benefits will result in organizations maintaining about 80% of their endpoints as physical desktop and laptop systems, VDI will be an additive expense, and the great opportunity to impact user lifestyles with virtualization will be lost. It is about people – let’s look for ways for virtualization to change user experiences.
Friday, September 23, 2011
Proactively addressing home and office PC security
Webroot’s extensive survey – over 2500 respondents that was summarized in a Sept 20th press release – reinforced the need for businesses to recognize the inevitable blurring between personal and professional computing. With anti-malware scanning and filtering shifting to the cloud it is easier for organizations to proactively help secure home PCs as well as those in the office. Vendors can do their part by providing services that makes it easy for users or IT to manage security policy for multiple devices - inside and outside of the office.
What caught my eye in the Webroot study was that more than 40% of respondents purchased non-work related items online. Combined with prior results that 46% of users visit their favorite social networking site several times a day, it is becoming clear that employees don’t think twice about blurring personal and professional browsing while in the office. That is not a real surprise, since hundreds of millions of users have been blurring the distinction between personal and professional computing while at home to read business mail, or connect to desktops via VPNs or products like GoToMyPC. And that does not even factor in the use of mobile devices which completely bypass corporate security. Security teams need to address home security for home computing.
Businesses can help by negotiating coverage of home computers in their anti-virus agreements, evaluating cloud-based endpoint security management that bridges the home and the office, or recommending to employees the best free anti-malware offerings (sometimes available from service providers). There is a train of thought that there should be a clear separation of duties between personal and professional devices, and it is up to the employee to shell out $50 per PC annually to help protect the business. But that train is leaving the station.
What caught my eye in the Webroot study was that more than 40% of respondents purchased non-work related items online. Combined with prior results that 46% of users visit their favorite social networking site several times a day, it is becoming clear that employees don’t think twice about blurring personal and professional browsing while in the office. That is not a real surprise, since hundreds of millions of users have been blurring the distinction between personal and professional computing while at home to read business mail, or connect to desktops via VPNs or products like GoToMyPC. And that does not even factor in the use of mobile devices which completely bypass corporate security. Security teams need to address home security for home computing.
Businesses can help by negotiating coverage of home computers in their anti-virus agreements, evaluating cloud-based endpoint security management that bridges the home and the office, or recommending to employees the best free anti-malware offerings (sometimes available from service providers). There is a train of thought that there should be a clear separation of duties between personal and professional devices, and it is up to the employee to shell out $50 per PC annually to help protect the business. But that train is leaving the station.
Friday, September 16, 2011
Intelligent Whitelisting and VDI
Check out my latest post on intelligent whitelisting titled "Working together in a virtual environment: application whitelisting and anti-virus". It is all about provisioning thinner virtual desktops for greater performance and density. Those requiring AV can run it as a security service on the virtual server.The article is right here.
Wednesday, September 14, 2011
RSA SBIC is worth checking out
You have to give RSA credit for the way they’ve responded to their phishing attack. Rather than being totally defensive about the incident, RSA has responded with a drive to educate the market about threats that start with a plausible email that begs for attention. It is a good effort by a mature security vendor.
Their Security for Business Innovation Council reports are interesting executive conversations that result in recommendations and conclusions for enterprise security officers. The latest edition, released Tuesday of this week, focuses on the serious problems in combating APTs.
Usually I take these things with more than a grain of salt because they can be overly slanted into “buy my product” pieces, but RSA does a nice job of letting the executives speak. I liked that recommendation #6 was to “Rearchitect IT”. This is an admission that instead stacking security products in costly (and futile) defense in depth architectures, perhaps the business might be safer with thin clients and virtualization, tighter network zones and access controls, and even use of cloud infrastructures to share costs. It is thought provoking and worth checking out – although having said that I am not convinced about enterprise needs for intelligence services.
RSA also publishes a series of phishing reports - the latest reminding us that though phishing is a global concern, there are security actions we can take here in the US that may help. That is certainly not new information, but while the above SBIC report spent time talking about foreign agents and foreign attacks, it seems like our government and service providers have responsibilities right here - the US hosted 53% of the world’s phishing attacks in July!
Their Security for Business Innovation Council reports are interesting executive conversations that result in recommendations and conclusions for enterprise security officers. The latest edition, released Tuesday of this week, focuses on the serious problems in combating APTs.
Usually I take these things with more than a grain of salt because they can be overly slanted into “buy my product” pieces, but RSA does a nice job of letting the executives speak. I liked that recommendation #6 was to “Rearchitect IT”. This is an admission that instead stacking security products in costly (and futile) defense in depth architectures, perhaps the business might be safer with thin clients and virtualization, tighter network zones and access controls, and even use of cloud infrastructures to share costs. It is thought provoking and worth checking out – although having said that I am not convinced about enterprise needs for intelligence services.
RSA also publishes a series of phishing reports - the latest reminding us that though phishing is a global concern, there are security actions we can take here in the US that may help. That is certainly not new information, but while the above SBIC report spent time talking about foreign agents and foreign attacks, it seems like our government and service providers have responsibilities right here - the US hosted 53% of the world’s phishing attacks in July!
Friday, September 2, 2011
Recent press release support
Summer is winding down and Q4 activities are picking up. I’ll post a short note Monday on some concepts from briefings that I found interesting. Meanwhile here are the top 3 quotes I gave recently for Watchguard, Damballa and eEye …
Watchguard
I like what Watchguard has been doing, particularly for companies looking to protect their networks against security issues associated with social networks. The quote is on DLP functionality that will help against unauthorized outbound data flows. My French stops with “merci” – Watchguard did the translating:
“Until recently, data loss prevention technology has been predominately relegated to enterprise organisations that have the staff or resources capable of managing the administrative complexities associated with DLP,” said Eric Ogren of the Ogren Group. “The new DLP features in this WatchGuard
release focus on providing mainstream business environments with the badly needed benefits of enterprise‐strength DLP in a simple to manage solution.”
"Jusqu’à récemment, la technologie de prévention des pertes de données était principalement réservée aux services de l’entreprise disposant du personnel ou des ressources capables de gérer les complexités d’administration inhérentes", déclare Eric Ogren d’Ogren Group. "Les nouvelles fonctionnalités DLP de cette mise à jour de WatchGuard visent à offrir aux principaux environnements professionnels les avantages indispensables d’une protection DLP d’entreprise éprouvée au sein d’une solution simple à gérer."
Damballa
I liked Damballa’s ISP approach to associating domains and IP addresses with botnets. This allows service providers to detect command and control communications in the cloud, blocking early attacks while AV can perform clean-up of existing threats.
“The designer malware used in today’s attacks is supremely capable of evading detection,” said Eric Ogren, principal analyst of The Ogren Group. “The weakest link for data-seeking malware is now the command and control infrastructure with its reliance on the DNS hierarchy. Being able to detect the criminal infrastructure in its early days, as it is being set up and long before the actual attacks are launched, gives businesses a fighting chance at staying ahead of these threats.”
eEye
eEye has been in security for a while, with both Retina and Blink products. I thought their approach to risk identification, vulnerability management, and patching to be interesting for small and medium businesses that can benefit from a community approach.
“Many organizations fail to address their most critical security weaknesses, spending time and money correcting relatively minor security problems,” said Eric Ogren, principal and founder of the Ogren Group. “Security risk prioritization is an indispensable element of any pragmatic IT security and compliance strategy. Enterprises need solutions that will allow them to prioritize so that they can quickly and easily close the most dangerous security gaps in their networks.”
Watchguard
I like what Watchguard has been doing, particularly for companies looking to protect their networks against security issues associated with social networks. The quote is on DLP functionality that will help against unauthorized outbound data flows. My French stops with “merci” – Watchguard did the translating:
“Until recently, data loss prevention technology has been predominately relegated to enterprise organisations that have the staff or resources capable of managing the administrative complexities associated with DLP,” said Eric Ogren of the Ogren Group. “The new DLP features in this WatchGuard
release focus on providing mainstream business environments with the badly needed benefits of enterprise‐strength DLP in a simple to manage solution.”
"Jusqu’à récemment, la technologie de prévention des pertes de données était principalement réservée aux services de l’entreprise disposant du personnel ou des ressources capables de gérer les complexités d’administration inhérentes", déclare Eric Ogren d’Ogren Group. "Les nouvelles fonctionnalités DLP de cette mise à jour de WatchGuard visent à offrir aux principaux environnements professionnels les avantages indispensables d’une protection DLP d’entreprise éprouvée au sein d’une solution simple à gérer."
Damballa
I liked Damballa’s ISP approach to associating domains and IP addresses with botnets. This allows service providers to detect command and control communications in the cloud, blocking early attacks while AV can perform clean-up of existing threats.
“The designer malware used in today’s attacks is supremely capable of evading detection,” said Eric Ogren, principal analyst of The Ogren Group. “The weakest link for data-seeking malware is now the command and control infrastructure with its reliance on the DNS hierarchy. Being able to detect the criminal infrastructure in its early days, as it is being set up and long before the actual attacks are launched, gives businesses a fighting chance at staying ahead of these threats.”
eEye
eEye has been in security for a while, with both Retina and Blink products. I thought their approach to risk identification, vulnerability management, and patching to be interesting for small and medium businesses that can benefit from a community approach.
“Many organizations fail to address their most critical security weaknesses, spending time and money correcting relatively minor security problems,” said Eric Ogren, principal and founder of the Ogren Group. “Security risk prioritization is an indispensable element of any pragmatic IT security and compliance strategy. Enterprises need solutions that will allow them to prioritize so that they can quickly and easily close the most dangerous security gaps in their networks.”
Friday, July 29, 2011
Virtualization accelerates firewall rules change requests
Just posted on Tufin's blog ...
The shift to virtualization, with most organizations virtualizing more than 30% of their applications, challenges the means by which security teams implement firewall-based foundational controls. Organizations are embracing virtualization for obvious cost savings benefits when applications share server and infrastructure resources. In fact, many enterprises continue to re-architect networks to consolidate data centers, applications and IT services. For instance, the rapid provisioning of applications - running in a matter of minutes on a virtual server for a task that would take weeks with physical architectures – necessitates a rapid evolution in the security lifecycle management of firewall rules.
The shift to virtualization, with most organizations virtualizing more than 30% of their applications, challenges the means by which security teams implement firewall-based foundational controls. Organizations are embracing virtualization for obvious cost savings benefits when applications share server and infrastructure resources. In fact, many enterprises continue to re-architect networks to consolidate data centers, applications and IT services. For instance, the rapid provisioning of applications - running in a matter of minutes on a virtual server for a task that would take weeks with physical architectures – necessitates a rapid evolution in the security lifecycle management of firewall rules.
Friday, June 17, 2011
Security and firewall management blog at Tufin

Firewalls are the heart of every organization's security strategy. Every compmany has firewalls, with rule sets that have grown to be a big can of worms. Tufin has very interesting technology that helps meet the scary challenge of keeping firewall rules consistent across the company and consistent across multiple vendors. Not only that, but I am finding security and network admin teams efficiently sharing Tufin's products for a secure network.
Tufin is taking a leadership position by hosting a discussion on security and firewall management. There will be guest analysts, and I am pleased to be able to contribute. You can check it out here.
My new post on IntelligentWhitelisting.com
It is important that application whitelist approaches make allowances for differences in individual PCs. Each device is slightly different – it is very unlikely that a “one size fits all” approach will be pragmatic.I mention this because I often hear the misperception that application whitelist vendors maintain a master list of every published software executable in the world, can query that database to validate the integrity of any given program, and that there is great value in this massive clearinghouse capability ...
You can read the entire post here.
You can read the entire post here.
Subscribe to:
Posts (Atom)



