Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Wednesday, August 5, 2009

Next-Generation Managed Security Services


Reports of network attacks and stolen data are commonplace. Consumers routinely undergo the stress of fraudulent charges or compromised credit cards. Computer hacker terms like "botnet" are becoming a part of our everyday vocabulary.

As a result, enterprise security and risk professionals find themselves on a never-ending quest to maintain the integrity of their communication networks, according to the latest study by Forrester Research. Fortunately, managed service providers offer solutions to help relieve the burden.

In its latest initiative to help businesses protect their vital assets from cyber threats and other online attacks, Verizon Business is now offering its next-generation managed security services (MSS) platform, complete with new options.

This enhanced platform is designed to safeguard corporate networks by proactively identifying vulnerabilities and prioritizing threats across the extended enterprise -- resulting in better visibility, enhanced security and reduced risk.

Businesses can now identify the threats that could do the most damage, and then respond quickly. The Verizon Business platform is available immediately to customers throughout the U.S., Europe and Asia-Pacific.

Risk-Based Approach to Network Security
Going beyond first-generation threat and vulnerability strategies to address underlying risk, Verizon’s new platform enables the management of multiple security platforms, changing business requirements and increased security compliance requirements.

It also enables enterprises that lack in-house security expertise and have limited resources to effectively secure their networks while obtaining a consistent quality of service at an affordable, predictable cost.

"The Verizon Business risk-based approach to network security gives enterprise customers a better understanding of the threats to their businesses so they can plan accordingly," said Amy DeCarlo, principal analyst - Managed IT Services at Current Analysis. "This pragmatic approach, coupled with the global availability of this service platform, makes this a compelling managed security offering for the enterprise."

Benefits of Flexible Service Levels
Verizon customers can choose from one of the following three new service tiers to address individual requirements -- including providing effective security solutions across multiple networks in different parts of the world, each with country-specific requirements.
  • Basic Monitoring: Allows customers to outsource only the monitoring of security devices to while leveraging in-house staffing and retaining management control.
  • Premium Monitoring: Provides continuous monitoring of security devices with analytical support. Security logs and alerts generated by security devices are analyzed and interpreted by security analysts located in one of the company's global security operations centers.
  • Premium Monitoring and Management: Incorporates the Premium Monitoring service, and also proactive management of all devices. This includes installing security patches, managing security policies and restoring devices.

Thursday, February 19, 2009

How to Stay Ahead of Hackers and Cybercriminals


My conversation with Jonathan Nguyen-Duy, Director of Product Management for Verizon, ended up being very thought-provoking. We were supposed to talk about a new security offering, a backbone-based solution aimed at stopping Internet-based attacks even before they hit a company's network. (I'd spoken previously to Nguyen-Duy about Verizon's risk-correlation service.)

Nguyen-Duy is a fount of knowledge about the changing landscape of international cybercriminals. Verizon is expanding its denial-of-service (DOS) detection and mitigation capabilities into eight network management centers serving 24 countries with new levels of scalability -- in part because of an increase in international cybercrime, according to Nguyen-Duy.

"Our customers are telling us that the frequency and complexity of DOS attacks has grown. We're now seeing cyberattacks based on social and political activism. We're also seeing less sophisticated hackers getting access to attack methodologies."

A case in point: consider the following related events.

Item: The Bureau of Alcohol, Tobacco, and Firearms, he says, recently arrested "the eBay of cybercrime" in Phoenix, Arizona which was selling automated attack programs, called botnets.

Item: A CIA official said at a conference that the recent power outages in South Florida were results of an unauthorized probe of the utility network originating from China.

Item: Crime syndicates are more frequently attacking financial services firms, online retailers, and government agencies for extortion purposes, in countries where there may be no laws or no enforcement of the laws.

"If you're a global enterprise or agency with deep pockets and a brand to protect, the challenge is real," Nguyen-Duy says.

"This gives rise to a clear problem: If you have a DOS attack that floods a device with five times the normal amount of traffic, do you have the capacity on site to parse through it and separate the legitimate traffic, and can you do it in real time so you don’t have degradation in service?" Remember that typical consumers won't sit through a transaction if they experience latency of more than 10 seconds.

Protection: Around the Clock, Around the Globe
No, we're not trying to write the script for Die Hard V here. However, because globalization is increasingly driven by the ability to share information anywhere, companies that take advantage of it are also making themselves more vulnerable.

Unless you want to deploy high-priced security experts everywhere you do business, it would be prudent to consider how expanded managed security services can protect your multinational communications network. And, thereby prevent the unthinkable from becoming a reality.

Tuesday, October 14, 2008

Online Security in a Global Networked Economy


Because of the expanding growth and complexity of communication networking, and the risks presented by a new breed of skillful hackers, serious security threats are an unfortunate certainty within the highly interconnected office environment of today.

These threats are very real and the results are costly to those businesses that have been affected. Apparently, the victims aren't entirely at random, which is often assumed to be the case.

According to the 2007 CSI Computer Crime and Security Survey, almost one-fifth (18 percent) of those respondents who suffered one or more kinds of security incident further said they had suffered a "targeted attack" -- defined as a malware attack aimed exclusively at their organization or at organizations within a small subset of the general population.

Beyond the Virus Threat
Moreover, financial fraud overtook virus attacks as the source of the greatest financial losses. Virus losses, which had been the leading cause of loss for seven straight years, fell to second place.

In today's global marketplace, every business needs to be vigilant in pro-actively protecting its corporate assets. Gone are the days of simply scanning for viruses. Today a comprehensive, layered approach is required to secure the network and company resources from multiple types of threats.

Small and medium-sized businesses (SMBs) are particularly vulnerable because they typically do not have expert resources on staff to ensure the network is secure, that regulatory compliance issues are being properly addressed, and that network monitoring and updates are effectively maintained 24 hours a day.

Alternative to the In-House Solution
Managed service providers can help SMBs secure their network by deploying a layered approach that uses various advanced technologies and solutions, protecting the network, and anticipating multiple types of potential security breaches -- from Trojan horse attacks and spyware, to data tampering and information theft.

Managed security services create a resilient multilayer defense:
  • Prevention -- proactively keeps the intrusions out
  • Detection -- identifies when an intrusion is occurring or has occurred
  • Response -- takes action to defeat a potential intrusion once detected
The advantage of working with a managed security provider is that services can be scaled to meet an organization's exact security requirements. This flexibility allows companies to minimize service outages and operational expenses, thereby reducing the overall financial impact.

The Challenge to Stay Current
Frankly, a large enterprise IT team can also benefit from an out-tasked network security solution, as the demands to ensure that in-house staff is staying current increases exponentially over time.

Ask a managed service provider to help you assess your security needs and design the best solution for your business. A comprehensive security audit is often the first step in this process.

By all means, be prepared for the unexpected, and keep your business safe. However, this is a complex task that's best left to the experts, while you free-up time to focus on your core business objectives.