Thursday, July 23, 2009

Written for Lumension - Endpoint Security: Moving Beyond AV



"Application whitelisting is emerging as the security technology that gives IT a true defense-in-depth capability, filling in the gaps that anti-virus (AV) was never designed to cover. Organizations have invested heavily in traditional AV solutions, often stacking AV filters from multiple vendors along the data path in the desperate hope that one of the products would stop malware from infecting the corporate or government endpoints. While AV plays a crucial role in identifying known malware and cleaning infected systems, the reality is that relying on layers of the same defense mechanism leaves organizations completely exposed to attacks and data theft from unknown or designer malware that can be delivered in web-based active code, downloaded encrypted code fragments, and persistent botnets. Security teams that know they need more than AV are now deploying application whitelisting technology to protect laptops, desktops, server and Point-of-Sale endpoints from unidentified malicious code as well as undetected code injections - and they are finding significant operational benefits due to fewer interruptions responding to infected endpoints.

This Ogren Group Special Report, Endpoint Security: Moving Beyond AV, commissioned by Lumension, presents the market demand for application whitelisting with recommended actions for security decision makers. Information in this report derives from Ogren Group research and interviews with enterprise security executives of global organizations." ...

Wednesday, July 22, 2009

OPSWAT quote for press release

OPSWAT is a neat company that develops toolkits for embedding security into applications. The most common need is for a general purpose interface to make calls to an AV product, allowing the application vendor to pick and choose the right AV engine for the job. OPSWAT also includes logic to facilitate a clean removal of security - a welcome capability for those of us who have ever attempted to uninstall an AV product when switching vendors. They do interesting work with a refreshingly pragmatic approach. I am pleased to support their press release with a quote:

“As the IT need for embedding security solutions in the fabric of the infrastructure becomes an increasing necessity due to the growing number of Internet-based threats, so does the ability to manage these solutions in an efficient manner,” said Eric Ogren, founder and principal analyst at the Ogren Group. “OPSWAT, Inc.’s Metascan technology provides the capability to bolt anti-malware scanning engines directly onto third-party software. Together with OESIS application management features, the acquisition of Metadefender’s technology nicely positions OPSWAT to provide a comprehensive, all-inclusive anti-malware scanning engine, benefiting vendors of secure products.”

New hacker skills optimize revenue

The latest from SearchSecurity:

"Malware is evolving into a rewarding, mature high-tech market, and it's not surprising that the financial incentives of developing and peddling malware can outweigh the risk of penalties that include spending quality time in jail. Malicious code developers may not be business school graduates, but they appreciate basic business principles to expand their addressable market; optimizing revenue from the install base and leveraging technology. That was the takeaway from the Cisco 2009 Midyear Security Report, an excellent summary of the major malware activity written for a less-technical executive audience..."

Friday, July 17, 2009

Offering SaaS for securing mobile devices

The following has just been posted in TechTarget's SearchSecurityChannel:

"Intelligent mobile devices are revolutionizing the way remote users connect to their business, and thus are presenting unique security opportunities for solution providers. Blackberrys, iPhones, and the emerging category of promising Mobile Internet Devices (MIDs) are exploding in popularity, fueled by the availability of easy-to-use application interfaces to access information (both business and personal) in non-traditional ways..."

Monday, July 13, 2009

Cloud-based security services should start private

Posted on SearchSecurity.com this week:

"Many early stage cloud vendors have it backwards when it comes to offering cloud-based services. They implement Software as a Service (SaaS) first to demonstrate their vision and then develop enterprise integration features. But the right way to go about it is to support corporate clouds in early product releases. IT is typically conservative about business risk and likes to retain control over sensitive data and applications. Security SaaS vendors may be better served by allowing IT to start by hosting its own private cloud service, integrated with existing data repositories and administrative systems and then provide a path to the full cloud application environment"...

Wednesday, July 8, 2009

Ogren Group Impact: MokaFive LivePC at your service



MokaFive has the innovative idea of deploying virtual desktops as a service for remote users. The payoffs can be large for IT – centralized control of endpoint configurations for meeting compliance mandates, protection of sensitive data while working in remote locations, and end-user convenience of having ubiquitous access to their desktop. The Ogren Group believes that with performance concerns abating due to the virtual desktop running on the endpoint, virtual desktops will usher in new opportunities for IT to cost effectively service business users.

Wednesday, July 1, 2009

Tufin takes an operational view on firewall rules management

Tufin is one of the promising companies in the firewall rules management market. While security and managing compliance is of primary importance, Tufin also appreciates the operational cost savings benefits of controlling and automating firewall rules administration. The following is a quote for their Automatic Policy Generation press release that hit the wires on June 29th:

"Automating the creation of optimized firewall rule bases is critical to establishing an accurate baseline for increasing network security and reducing operational costs," said Eric Ogren, principal analyst of the Ogren Group. "Well defined firewall rules lower the risk of creating holes in network security, eliminate many of the business disruption issues that can accompany firewall deployments, and reduce the number of costly support calls. Automation ensures that firewall rule bases act on the intelligence discovered from actual observed business traffic."

Twitter risks, Facebook threats trouble security pros

Nice way to start July with a new SearchSecurity post!

"The explosive growth in social networking has positioned many security teams solidly between a rock and a hard place. On the one hand, conscientious security executives cannot ignore the data loss and regulatory compliance risks to the corporation; on the other hand, security cannot politically survive by categorically objecting to other organizations innovative use of new business tools...."

Thursday, June 18, 2009

If you were Check Point, who would you buy?

I gave this feedback to a senior editor at MergerMarket. Since they provide a subscription service I thought it would be interesting to also dream about Check Point M&A here.

Check Point is an interesting company with a healthy revenue stream, big bank account, and dominant market position. They haven't shown a great desire to grow by aquisition in the past, and the vision of the Zone Labs and Nokia deals doesn't particularly wow me. Still, they can print money so they're clearly doing a lot of things right!

Check Point Software Technologies is a software company specializing in network inspection and processing. I would think the first wave of merger activity would be to diversify from security into adjacent areas of networking. If you think about it, a firewall's job is to let traffic into the network so I tend to think Check Point can better use its checkbook to improve connectivity for its customers.Here are three areas I would recommend for Check Point corporate development:

WAN optimization. Performance over the Internet is critical to capturing new customers and improving business processes. Riverbed would be the number one target. RVBD would allow Check Point to combine security features with web access, accelerated storage, and more. Check Point is good at terminating WAN connections so this is a natural fit.

Virtual Desktop and Virtual Machine delivery. Virtualization will continue penetration in the datacenter and we will see more enterprises solving labor intensive endpoint complexity and security problems with virtualization. Picture a remote user connecting by VPN through a firewall to a network server to run or download a virtual application. Most of the companies in this space are small, with software implementations that Parallels and perhaps the smaller MokaFive and Ring Cube. It would be bold and cool if they could scarf up Citrix but I'm not sure that Checlk Point's pockets are that deep.

Network Management. An under-appreciated strength of Check Point is its management capability. The company gets great stickiness and loyalty from its base that shies away from command line interpretters and script-writing. The trick is to combine mergers in this area with WAN optimization of virtualization. I would look towards companies like Reflex Systems, DynamicOps, or FastScale to allow organizations to quickly take advatage of a compelling Check Point infrastructure. Those are tiny companies - I'm sure there are public ones that also fill this bill it is just too late for me to think of them ;)

I'm not big on Check Point acquiring hardware capability (e.g. Crossbeam) because Check Point is a software company and it is difficult for hardware product lines to thrive in a company with a software DNA - just look at McAfee's history with hardware. I also don't think it makes much sense to commoditize adjacent security vendors (been there with Sourcefire, and what does it really add for customers that can't be done through parternships?). Though maybe they'll score Imperva to get Shlomo Kramer back in the fold or put Code Green on one of their software blades.

Virtual appliances boost flexibility, improve security

The latest TechTarget post highlights the innovative use and device sharing possibilities afforded by virtual appliances.

"Security products purchased as virtual appliances give IT greater flexibility in deployment than traditional security hardware devices. The concept of treating network security as a software application has proven to be successful. Organizations can save money by re-purposing expensed servers as security devices, achieve a performance boost by placing network-oriented security on a faster processor and consolidate security functions on fewer servers to save on administration while making the security function a bit greener." ...

Monday, June 15, 2009

Security pros find corporate firewall rules tough to navigate

Posting on June 15th to SearchSecurity:

"Corporate firewalls usually contain a security-Pandora's box of rules, representing prioritized sequences of allow or deny decisions that only the most brave security operator dares to modify. Removing or re-sequencing firewall rules runs the risk of blocking approved business communications or of opening a hole exposing the business to unauthorized traffic. It is near impossible for a human to manually audit firewall rules across the enterprise to reduce risk, optimize firewall device performance, and streamline data paths through routers, switches and firewalls. Security teams are turning to firewall management tools to perform security audits of the infrastructure and automate operational control of the firewalls. ..."

Cloud security begins with infrastructure assessment

Posted June 10th on TechTarget's SearchSecurity:

"Security professionals are facing the difficult challenge of extending security requirements to take advantage of cloud computing and software-as-a-service applications. Particularly difficult is finding ways to secure the new boundaries between the enterprise, the cloud service and the end user while managing dependencies on off-premise infrastructure and privileged operators. And they have to do all this without inhibiting flexibility and agility. ..."

Sunday, June 7, 2009

Early Vibe: Triumfant

Triumfant is an up and coming endpoint security product vendor headquartered in the Washington, DC area. The company takes a holistic approach to endpoint security, detecting changes to the environment, auditing activity, and restoring the endpoint to a compliant state after an attack. This is a sharp contrast to traditional anti-virus approaches that can never catch all the exploits and behavioral approaches that fail to unwind from a detected attack. I believe the security experiences of Triumfant’s leadership team, and the uniqueness of its technology, give the company a promising future if it can navigate the pitfalls associated with growing an “A” round company.

The secret sauce for Triumfant is the capability to define and manage the drift of adaptive baseline configurations of endpoints under protection. This allows the technology to detect unauthorized changes, such as those caused by malicious code, and to reset the endpoint to the latest baseline. Agent software scans the local environment for changes, and also uses signature and behavioral techniques to increase the chance of detecting an attack. The centralized server allows IT to manage baseline definitions, to automatically allow for configuration drifts by auditing endpoints under Triumfant protection, and to reset a non-compliant endpoint to the latest pristine image without the need for an IT refresh. The approach is refreshing as most endpoint security vendors completely ignore the need to reset an endpoint without IT intervention.

Triumfant will face challenges as it grows, and must carefully choose product features that keep it ahead of the slower moving vendors. The two greatest impacts may come from anti-virus vendors and virtual desktop vendors. IT cannot conceive of an endpoint security world without AV, no matter how many times AV is proven to be effective. Triumfant should bundle an optional AV in its solution to be able to displace installed competitors with a more comprehensive endpoint security solution. Virtual desktops offer the ability to reset the desktop to pristine compliant images when an infection is detected. Triumfant can fill the gap for virtual desktop vendors by enabling desktop resets of virtual images.

Customers need to demand more from all endpoint security vendors and not just accept a status quo that does not work often enough. Triumfant is rising to this challenge with an innovative approach to protect servers and desktops from attacks, and to give IT relief from attack recovery procedures. It is an interesting play that lends itself well to servers and will inevitably become popular on desktops too.

Thursday, June 4, 2009

IT pros can detect, prevent website vulnerabilities, thwart attacks

Posted on SearchSecurity June 3rd.

"IT is left to its own ingenuity to weave diverse products into a Web security protection scheme. Security practitioners will have to categorize externally facing websites and then make security investment decisions among technologies such as scanners, penetration testers, Web application firewalls, source code scanning and security development lifecycle (SDL) investment. There is no one best practice when protecting websites, which is a worrisome state for businesses and helps explain why security vendors report that most attacks penetrate browsers through infected webpages."