CloudPassage, a Bay area startup, has just exited stealth this week with a proposition to simplify security for cloud-based servers. The problem, according to the vendor, is that vulnerability management and firewall policy enforcement both suffer as application servers are dynamically launched and shuffled between data centers. For instance, the ability for enteprises to reach their applications in the cloud to frequently assess and manage server vulnerabilities or to enforce server-based security policies both suffer.
The secret sauce of the CloudPassage SaaS technology features a cloud-based analytic grid that continuously correlates server configurations with vulnerability information and customer security policies - offloading individual servers from that burden. CloudPassage initially offers two products, Halo SVM and Halo Firewall:
Halo SVM (Server Vulnerability Management), depends on a host-based agent to initiate communications with the CloudPassage grid. The agent profiles the Linux or Unix server, and uploads that information to the CloudPassage grid for analysis. The end benefit is a vulnerability management procedure that transparently evaluates applications for vulnerabilities and configuration drift with a higher frequency than scanning options can reasonably achieve.
Halo Firewall is a host based firewall that is designed to travel with cloud-based servers to enforce security policies. Similar to SVM, the Firewall product connects to the CloudPassage grid to download the most recent set of policies for the server.
The Ogren Group believes that CloudPassage is on the right track. Enterprise applications are evolving from customer premise-based services to hybrid environments and public clouds, yet the evolution of static security perimeters and scheduled vulnerability management isn’t evolving at the same pace. Placing the burden of analysis in the cloud as a SaaS allows CloudPassage to avoid distribution overhead to servers while assessing vulnerability information, server configurations, and customer policies for each server (and there will be plenty of opportunity to add additional security computations). CloudPassage does have challenges to overcome, starting with expanding its solution capability to include support for Windows servers and also an agentless option for those that can’t tolerate additional software on a server. The company is very young with a grid capability that provides potential for excellent flexibility in responding to securing the cloud.
Thursday, January 27, 2011
Wednesday, December 29, 2010
Catching the Wave
You have to admire the perseverance of a vendor whose vision is miles ahead of the market, and then fights, scratches, claws, and just hangs on until they find customer traction. This has been the case with Wave Systems, an early evangelist of placing and managing keys in secure hardware, particularly the TPM as defined by the Trusted Computing Group. For Wave there has always the lingering question of “if the idea is so good, why aren’t companies buying”? Well, it looks like the time has come and they’re now underway with two primary use cases:
Secure remote access with intrinsic two-factor authentication. Using the secret key from the TPM turns the laptop into the “something you have” factor to go along with the password (“something you know”). Enterprises not only save money by reducing token purchases, they also gain secure access while giving users and security administrators one less thing to worry about.
Transparently encrypt the hard drive of remote users. Enterprises that need to protect intellectual property or regulated data on laptops are getting tired of trying to administer DLP or DRM at the endpoint. A simpler solution is to transparently encrypt data on the hard drive using a secret key from the TPM. It is more secure, easier to manage, and may cost less. The most noteworthy implementations support Bitlocker and Samsung and Seagate self-encrypting hard drives.
Wave Systems sells software that makes administration of keys and TPMs practical for larger organizations that need to secure remote access and locally stored data. They’re moving forward and have some impressive references to their credit, including Mazda, Papa Gino’s, and Boston Medical Center. It’s nice to see their perseverance paying off.
Secure remote access with intrinsic two-factor authentication. Using the secret key from the TPM turns the laptop into the “something you have” factor to go along with the password (“something you know”). Enterprises not only save money by reducing token purchases, they also gain secure access while giving users and security administrators one less thing to worry about.
Transparently encrypt the hard drive of remote users. Enterprises that need to protect intellectual property or regulated data on laptops are getting tired of trying to administer DLP or DRM at the endpoint. A simpler solution is to transparently encrypt data on the hard drive using a secret key from the TPM. It is more secure, easier to manage, and may cost less. The most noteworthy implementations support Bitlocker and Samsung and Seagate self-encrypting hard drives.
Wave Systems sells software that makes administration of keys and TPMs practical for larger organizations that need to secure remote access and locally stored data. They’re moving forward and have some impressive references to their credit, including Mazda, Papa Gino’s, and Boston Medical Center. It’s nice to see their perseverance paying off.
Monday, July 26, 2010
Checking out PacketMotion
PacketMotion came by my office in Stow last week, leading to a lively discussion on the direction of network security. The company, founded in 2004 with its flagship PacketSentry product at version 4.0, has been around too long for Early Vibe status in this blog. However, PacketMotion is embracing a few unique ideas that may give security teams the flexibility they need to meet corporate functionality and cost-of-ownership requirements.
Corporate networks are dynamic as IT gains flexibility with wireless access, virtualizes applications and desktops, and increasingly relies upon browser-based cloud applications to support the business. This trend changes access paths between users and applications, and challenges security that is based on static addresses.
User Activity orientation allows IT to focus on securing business policies of users and applications. PacketSentry integrates with Active Directory to monitor user traffic to applications, with the option of killing non-compliant connections. Security policies are less dependent on the network infrastructure and are more easily mapped to business requirements.
Virtual Segmentation features provide a virtual PCI-compliance partitioning of resources by automatically monitoring and enforcing user activity to regulated applications and data repositories. That is, rather than deploying internal firewalls and replicating security mechanisms in the network, PacketMotion’s virtual segmentation helps assure that users and programs do not step out of bounds and access unauthorized business resources.
Automate compliance reporting with significant cost savings. Compliance mandates are designed to ensure the security of a business process and confidential data. Traditionally this has been done in a bottom-up manner starting with individual security products and then aggregating and correlating results into an overall business view. PacketMotion’s top-down approach reporting user and application activity across a broad range of protocols saves IT a lot of pain and can significantly reduce the burden of compliance reporting.
PacketMotion does a lot of things. In fact, one of their larger challenges is defining a strong position in the marketplace that also addresses priorities in security budgets. Since PacketSentry is a network appliance in the datacenter that looks at and records activity there will be pressure to place the company into a SIEM bucket (because it records activity), an NBAD bucket (because it can detect and terminate unauthorized behavior), or an automated GRC bucket (because it automates compliance). The company has good leadership and will find its way, but for now its differentiators are worth examining for forward-thinking security teams.
Corporate networks are dynamic as IT gains flexibility with wireless access, virtualizes applications and desktops, and increasingly relies upon browser-based cloud applications to support the business. This trend changes access paths between users and applications, and challenges security that is based on static addresses.
User Activity orientation allows IT to focus on securing business policies of users and applications. PacketSentry integrates with Active Directory to monitor user traffic to applications, with the option of killing non-compliant connections. Security policies are less dependent on the network infrastructure and are more easily mapped to business requirements.
Virtual Segmentation features provide a virtual PCI-compliance partitioning of resources by automatically monitoring and enforcing user activity to regulated applications and data repositories. That is, rather than deploying internal firewalls and replicating security mechanisms in the network, PacketMotion’s virtual segmentation helps assure that users and programs do not step out of bounds and access unauthorized business resources.
Automate compliance reporting with significant cost savings. Compliance mandates are designed to ensure the security of a business process and confidential data. Traditionally this has been done in a bottom-up manner starting with individual security products and then aggregating and correlating results into an overall business view. PacketMotion’s top-down approach reporting user and application activity across a broad range of protocols saves IT a lot of pain and can significantly reduce the burden of compliance reporting.
PacketMotion does a lot of things. In fact, one of their larger challenges is defining a strong position in the marketplace that also addresses priorities in security budgets. Since PacketSentry is a network appliance in the datacenter that looks at and records activity there will be pressure to place the company into a SIEM bucket (because it records activity), an NBAD bucket (because it can detect and terminate unauthorized behavior), or an automated GRC bucket (because it automates compliance). The company has good leadership and will find its way, but for now its differentiators are worth examining for forward-thinking security teams.
Monday, June 28, 2010
CoreTrace webcast on June 28th!
There has been a ton of interest in application whitelisting lately, especially with security-savvy organizations reacting to the Cisco Security Agent end of life scheduled for the end of 2010. Those folks know that they cannot rely totally on AV, but they also know they need a proactive approach that can be managed across the enterprise without breaking the bank.
CoreTrace is a leading application whitelisting vendor that does some pretty cool stuff at low levels. The webcast on Tuesday, June 28th is well worth an hour. Check out all of the details here:
http://www.coretrace.com/resources/webinars/CoreTrace_Webinar--Transitioning_from_Cisco_Security_Agent.aspx
CoreTrace is a leading application whitelisting vendor that does some pretty cool stuff at low levels. The webcast on Tuesday, June 28th is well worth an hour. Check out all of the details here:
http://www.coretrace.com/resources/webinars/CoreTrace_Webinar--Transitioning_from_Cisco_Security_Agent.aspx
Tuesday, June 1, 2010
Early Vibe: Armorize
Armorize is a web application security company that is being introduced to North America after gaining market traction in Asia/Pacific. The new management team is blessed with venture capital, noteworthy reference accounts, and an experienced engineering organization in Taipei. The focus on detecting actual malware residing on web sites addresses a critical security problem, where attacks such as drive-by downloads from trustworthy web sites infect customer endpoints. While vulnerability scanning is an important best practice, the Ogren Group believes malware scanning, if executed properly, addresses a sharper pain that gives enterprises a compelling reason to buy.
The main attraction for Armorize is a cloud-based service approach that finds the presence of malware on enterprise web sites. The HackAlert service is for security teams that need to react with a heightened sense of urgency to clean an infected web site to protect customers. Ferreting out vulnerabilities is good application hygiene to patch holes before exploits find them, but actually detecting infections solves more immediate customer needs. The cloud-based service approach makes perfect sense for organizations requiring continuous vigilance for malware.
Armorize also offers a code scanning product, CodeSecure, which examines web application software for security faults. This complements the malware scanning by offering Armorize customers a long-term end-to-end solution to hardening web applications. Organizations with custom developed applications will use this product early in the engineering cycle to ensure that web applications will be more resilient to attacks – and less likely to incur expensive emergency security fixes.
A significant challenge for Armorize will be to develop a pricing model that encourages customers to frequently scan for malware, while also being compensated for resources consumed by the Armorize data centers and a business model that aligns the HackAlert service with the CodeSecure offering. The Ogren Group believes the management team understands the web security space well enough to solve these problems, and will find a way to bundle code scanning with malware scanning for a comprehensive web security subscription service. Armorize has an interesting idea focusing on malware instead of vulnerabilities and with execution is well positioned to have a positive impact on improving enterprise’s web application security.
Friday, May 7, 2010
Live Web Seminar with Bit9
I will be talking about the failure of HIPS to provide a scalable endpoint security and the acceptance of application whitelisting as a foundational layer in conjunction with AV. One of the big problems with HIPS is that it is prohibitively expensive from an administrative standpoint. I think it is an interesting topic since I have some experience with with is now Cisco CSA. I hope you can join us on May 19th at 2:00ET.
"While significant enterprise security resources are devoted to prevention of malicious code infections, malware continues to frustrate security teams. Traditional anti-virus approaches have proven to be ineffective against modern attacks, and organizations that have tried host intrusion prevention find that technology is not an effective part of the endpoint security solution. Application whitelisting monitors endpoints in real time to ensure that only authorized programs can run, and that those programs have not been modified by malware."
"While significant enterprise security resources are devoted to prevention of malicious code infections, malware continues to frustrate security teams. Traditional anti-virus approaches have proven to be ineffective against modern attacks, and organizations that have tried host intrusion prevention find that technology is not an effective part of the endpoint security solution. Application whitelisting monitors endpoints in real time to ensure that only authorized programs can run, and that those programs have not been modified by malware."
Friday, February 26, 2010
Using user communities to bolster security offerings
Social networking ideas are coming to security, with efficiencies that are likely to .
Secure Passage is introducing a program whereby members can share configuration rules and policies to allow tight alignment between firewalls, routers, and other network devices. This is a really good idea that allows its customers to quickly tighten the security and compliance of their networks while reducing the chances of creating gaping holes in their security profiles. Secure Passage may also find that customers are extending the product into applications and server settings, which could lead SP to a nice growth path.
Secure Passage is introducing a program whereby members can share configuration rules and policies to allow tight alignment between firewalls, routers, and other network devices. This is a really good idea that allows its customers to quickly tighten the security and compliance of their networks while reducing the chances of creating gaping holes in their security profiles. Secure Passage may also find that customers are extending the product into applications and server settings, which could lead SP to a nice growth path.
Computerworld post ...
I thought the Alexa statistics on web site usage were pretty cool. I have always liked numbers and statistics. I did some exploring on US-China-India numbers on web site visitors for a Computerworld article and found the following (hopefully the formatting does not get screwed up):
Company USA India China
Check Point 22.3% 13.8% 4.8%
Cisco 32.2 12.5 4.7
EMC 39.8 13.2 9.8
IBM 18.4 12.5 19.3
Microsoft 20.6 7.5 7.0
NetApp 40.6 18.8 4.9
Symantec 25.3 13.3 3.2
Websense 30.3 7.8 23.9
Lockheed-Martin 49.5 7.0 11.3
Pfizer 47.6 12.9 5.7
Whitehouse.gov 65.7 3.4 3.9
There could be lots of business reasons for some of these numbers such as sales model, or amount of off-shore manufacturing partners, etc. However, the number of visitors from China and India is frequently significantly greater than the number from large industrialized countries including England, Germany and Japan.
If you are in security, you better know your business.
Company USA India China
Check Point 22.3% 13.8% 4.8%
Cisco 32.2 12.5 4.7
EMC 39.8 13.2 9.8
IBM 18.4 12.5 19.3
Microsoft 20.6 7.5 7.0
NetApp 40.6 18.8 4.9
Symantec 25.3 13.3 3.2
Websense 30.3 7.8 23.9
Lockheed-Martin 49.5 7.0 11.3
Pfizer 47.6 12.9 5.7
Whitehouse.gov 65.7 3.4 3.9
There could be lots of business reasons for some of these numbers such as sales model, or amount of off-shore manufacturing partners, etc. However, the number of visitors from China and India is frequently significantly greater than the number from large industrialized countries including England, Germany and Japan.
If you are in security, you better know your business.
Friday, January 22, 2010
Computerworld blog entry
After an 11 month hiatus, I have returned to the Computerworld blog. I had a lot of fun writing for them before and I am thrilled that they would have me back! Here is the first posting of 2010 ...
"Application service providers offer a centralized control point to deliver secure services for millions of its subscribers. Let’s hope that more social networking application providers follow Facebook’s and Comcast’s example by making it easy to acquire endpoint security software, and by enhancing its own internal vigilance. In the meantime, consumers with a paid anti-virus subscription are advised to act quickly in getting free protection from the likes of Avast!, AVG, or Microsoft..."
"Application service providers offer a centralized control point to deliver secure services for millions of its subscribers. Let’s hope that more social networking application providers follow Facebook’s and Comcast’s example by making it easy to acquire endpoint security software, and by enhancing its own internal vigilance. In the meantime, consumers with a paid anti-virus subscription are advised to act quickly in getting free protection from the likes of Avast!, AVG, or Microsoft..."
Tuesday, December 29, 2009
Web security strategy
Check out SearchSecurity.com for the latest:
If you haven't focused on an enterprise-wide Web security strategy then it's time for a reality check. It's safe to assume that various parts of your organization are using Web applications and a cloud computing infrastructure or services, and the time to wrap a security strategy around that is now.
If you haven't focused on an enterprise-wide Web security strategy then it's time for a reality check. It's safe to assume that various parts of your organization are using Web applications and a cloud computing infrastructure or services, and the time to wrap a security strategy around that is now.
Wednesday, December 16, 2009
Microsoft and EC settle their IE dispute
Good to see the European Union competition commissioner has finally come to its senses and settled its silly and costly business practices lawsuit against Microsoft over the bundling of Internet Explorer into Windows.
This seemed like pure harassment to me – browsers are free, users can easily download and install any browser they want, and service providers could have included or recommended browsers if their customers demanded help. In fact, you could even argue that ubiquitous feature-rich free browsers have worked to everyone’s benefit (though I do not believe Microsoft set the market price of free).
Anyway, Microsoft and the European Commission are now in agreement. Microsoft has agreed to give the user a choice of leading browsers in versions of Windows and presumably the EC can find better things to do.
This seemed like pure harassment to me – browsers are free, users can easily download and install any browser they want, and service providers could have included or recommended browsers if their customers demanded help. In fact, you could even argue that ubiquitous feature-rich free browsers have worked to everyone’s benefit (though I do not believe Microsoft set the market price of free).
Anyway, Microsoft and the European Commission are now in agreement. Microsoft has agreed to give the user a choice of leading browsers in versions of Windows and presumably the EC can find better things to do.
Tuesday, December 15, 2009
Lessons from CoreStreet
CoreStreet is the most recent security company fire sale – selling to ActivIdentity for “approximately” $20 million. Usually this means that the investors get some money back, the founders get some candy so they’ll bring their next idea back to the VC’s, and everyone else gets new business cards. CoreStreet gave it a good go – they had sharp mathematicians and a new idea for authentication, but could not find a sustainable and repeatable business. There are at least 2 things that other struggling security companies may be able to learn from CoreStreet:
Keep your messaging simple. CoreStreet is in the “distributed credential validation solutions” segment. You cannot expect a security team to evaluate, recommend or buy a product that they do not fully understand or have an expressed need for. When I first talked with them, CoreStreet described proofs and math models to authenticate signatures when a certificate authority was unavailable. I was in over my head in about 30 seconds, and I like to think I’m pretty good at authentication and math. If you are looking to increase sales traction, make sure your messaging is easily understood and directly addresses an important business need.
Try to diversify from government dominated customer base. When it comes to security, government agencies often have unique solution requirements that do not translate well into the commercial world. You can make a business serving the federal government if your company reaches a critical mass, but if you are not cash flow positive you need to have alternatives. While CoreStreet attracted business from defense-oriented agencies, it couldn’t translate its technology to the commercial sector. The company had no options and no place to grow, except perhaps by acquisition to a vendor that can service outstanding government contracts.
There is a tough year coming up and we will see more security vendors like CoreStreet with tired investors and shuttered doors in 2010.
Keep your messaging simple. CoreStreet is in the “distributed credential validation solutions” segment. You cannot expect a security team to evaluate, recommend or buy a product that they do not fully understand or have an expressed need for. When I first talked with them, CoreStreet described proofs and math models to authenticate signatures when a certificate authority was unavailable. I was in over my head in about 30 seconds, and I like to think I’m pretty good at authentication and math. If you are looking to increase sales traction, make sure your messaging is easily understood and directly addresses an important business need.
Try to diversify from government dominated customer base. When it comes to security, government agencies often have unique solution requirements that do not translate well into the commercial world. You can make a business serving the federal government if your company reaches a critical mass, but if you are not cash flow positive you need to have alternatives. While CoreStreet attracted business from defense-oriented agencies, it couldn’t translate its technology to the commercial sector. The company had no options and no place to grow, except perhaps by acquisition to a vendor that can service outstanding government contracts.
There is a tough year coming up and we will see more security vendors like CoreStreet with tired investors and shuttered doors in 2010.
Database activity monitoring lacks security lift
Posted to SearchSecurity ...
The IBM acquisition of Guardium Inc., a privately-held database activity monitoring (DAM) vendor, is far from a validation statement of DAM as a viable security market segment.
Vendors including Embarcadero Technologies Inc., IPLocks (acquired by Fortinet Inc.), Lumigent Technologies Inc., Symantec Corp. and Tizor Systems Inc. (acquired by Netezza Corp.), have already given up on the DAM space, leaving companies such as Application Security Inc., Imperva Inc., Secerno Inc. and Sentrigo Inc. fighting to divvy up a total annual market of well less than $100 million. The IBM acquisition of Guardium helps the company gain information management technology and a capability to drive professional service revenues in the data center.
The IBM acquisition of Guardium Inc., a privately-held database activity monitoring (DAM) vendor, is far from a validation statement of DAM as a viable security market segment.
Vendors including Embarcadero Technologies Inc., IPLocks (acquired by Fortinet Inc.), Lumigent Technologies Inc., Symantec Corp. and Tizor Systems Inc. (acquired by Netezza Corp.), have already given up on the DAM space, leaving companies such as Application Security Inc., Imperva Inc., Secerno Inc. and Sentrigo Inc. fighting to divvy up a total annual market of well less than $100 million. The IBM acquisition of Guardium helps the company gain information management technology and a capability to drive professional service revenues in the data center.
Tuesday, December 1, 2009
Health Net breach failure of security policy, technology
I'm back from vacation and Thanksgiving - hope you all had a nice break!
Here is the latest SearchSecurity posting:
"The recent Health Net data breach—affecting some 1.5 million users—is a failure of all aspects of IT security, including the ability to set appropriate policy, communicate that policy to employees and deploy the relevant security technology.
Health Net announced last week that unencrypted records, and the portable external hard drive containing those records, were lost. A loss of this magnitude from normal business practice suggests that either sensitive data accumulated over a long period of time and was not systematically erased when no longer needed, or the user worked on extremely large chunks of data without proper security controls. IT should have been aware of both possibilities and acted to protect the business." ...
Here is the latest SearchSecurity posting:
"The recent Health Net data breach—affecting some 1.5 million users—is a failure of all aspects of IT security, including the ability to set appropriate policy, communicate that policy to employees and deploy the relevant security technology.
Health Net announced last week that unencrypted records, and the portable external hard drive containing those records, were lost. A loss of this magnitude from normal business practice suggests that either sensitive data accumulated over a long period of time and was not systematically erased when no longer needed, or the user worked on extremely large chunks of data without proper security controls. IT should have been aware of both possibilities and acted to protect the business." ...
Subscribe to:
Posts (Atom)
