Showing posts with label protection. Show all posts
Showing posts with label protection. Show all posts

Tuesday, October 13, 2009

In-the-Cloud Approach to Cyber Security


Security breaches or other unexpected interruptions can happen anytime to anyone -- whether you are a large enterprise or a small business. Fully maintaining communication network security is a demanding responsibility -- and typically not the best use of your limited IT resources, that would be better applied to delivering incremental new business technology benefits to your organization.

Fortunately, there are alternatives to a do-it-yourself comprehensive security solution. Skilled managed service providers continue to enhance their network security offerings.

AT&T announced the availability of Security Event and Threat Analysis and Security Device Management, two new managed security services available for businesses of all sizes.

Customized to Your Unique Business Needs

The services enable you to engage AT&T security professionals selectively and simply to provide customized security support. Services range from security event analysis and threat management analysis to targeted security device management including firewalls, intrusion detection sensors and VPN servers.

These new services use AT&T’s expertise in security analysis to evaluate, correlate, and report on information from multiple devices and device types, both on your premises and embedded in the AT&T network.

AT&T Managed Service Benefits Include:
  • Prioritizing security events based on threat and risk management methodologies using AT&T and customer-defined standards.
  • Rapid notification when security events are detected and identified as critical by the AT&T Security Network Operations Center.
  • Event mitigation and security analyst counseling during critical security incidents.
  • Global Security Operation Centers and 24X7 T1-T4 Analyst Coverage with portal access through AT&T’s BusinessDirect Portal.
With Security Device Management, AT&T provides complete, customizable monitoring and management of your security hardware and software, with a range of services including managing your organization’s current security capabilities up to assessing, designing and implementing a custom security infrastructure.

Full Suite of Professional Services
These new services are a natural complement to AT&T’s existing Security Consulting services, which include independent assessments of vulnerabilities inherent in customers’ networks, as well as the policy and procedures surrounding them. Security Consulting services include Log Management, Security Policy Management, Vulnerability Analysis, Application Security, Trusted Advisor services and Payment Card Industry Solutions.

AT&T delivers a suite of security and business continuity services to help assess vulnerabilities, protect infrastructure, detect attacks, and respond to suspicious activities and events. The upcoming AT&T Cyber Security Conference is an annual day-long conference offered by the AT&T Chief Security Office.

Thursday, February 19, 2009

How to Stay Ahead of Hackers and Cybercriminals


My conversation with Jonathan Nguyen-Duy, Director of Product Management for Verizon, ended up being very thought-provoking. We were supposed to talk about a new security offering, a backbone-based solution aimed at stopping Internet-based attacks even before they hit a company's network. (I'd spoken previously to Nguyen-Duy about Verizon's risk-correlation service.)

Nguyen-Duy is a fount of knowledge about the changing landscape of international cybercriminals. Verizon is expanding its denial-of-service (DOS) detection and mitigation capabilities into eight network management centers serving 24 countries with new levels of scalability -- in part because of an increase in international cybercrime, according to Nguyen-Duy.

"Our customers are telling us that the frequency and complexity of DOS attacks has grown. We're now seeing cyberattacks based on social and political activism. We're also seeing less sophisticated hackers getting access to attack methodologies."

A case in point: consider the following related events.

Item: The Bureau of Alcohol, Tobacco, and Firearms, he says, recently arrested "the eBay of cybercrime" in Phoenix, Arizona which was selling automated attack programs, called botnets.

Item: A CIA official said at a conference that the recent power outages in South Florida were results of an unauthorized probe of the utility network originating from China.

Item: Crime syndicates are more frequently attacking financial services firms, online retailers, and government agencies for extortion purposes, in countries where there may be no laws or no enforcement of the laws.

"If you're a global enterprise or agency with deep pockets and a brand to protect, the challenge is real," Nguyen-Duy says.

"This gives rise to a clear problem: If you have a DOS attack that floods a device with five times the normal amount of traffic, do you have the capacity on site to parse through it and separate the legitimate traffic, and can you do it in real time so you don’t have degradation in service?" Remember that typical consumers won't sit through a transaction if they experience latency of more than 10 seconds.

Protection: Around the Clock, Around the Globe
No, we're not trying to write the script for Die Hard V here. However, because globalization is increasingly driven by the ability to share information anywhere, companies that take advantage of it are also making themselves more vulnerable.

Unless you want to deploy high-priced security experts everywhere you do business, it would be prudent to consider how expanded managed security services can protect your multinational communications network. And, thereby prevent the unthinkable from becoming a reality.

Tuesday, February 3, 2009

Managed Security Services Growing Among SMBs


A new report from Forrester Research on the state of IT security at small to midsize businesses (SMB) in North America and Europe predicts ongoing growth in the managed security space.

In a result similar to that of enterprise respondents, SMB executives reported that the two top drivers for using managed security services is the demand for a specialized skill set that security requires (cited by 31% of the respondents) and the need to reduce costs (cited by 24%).

Other reasons cited for adopting managed security services include:
  • The need to reduce complexity (19%)
  • The need for 24/7 security coverage (19%)
  • The rest of the IT environment is outsourced (5%)
Managed Services Tops for Filtering and Monitoring
The report also revealed that the top two services SMBs ask from their managed security provider are e-mail or Web content filtering (36%) and network firewall monitoring (33%). Forrester believes that the biggest uptick in the next year, however, will come from increased use of vulnerability management and assessment. Some 20% of SMBs plan to deploy these services in the next twelve months.

The Forrester report clearly shows that SMBs have a strong interest in all facets of managed security services. Some 23% are already using it for identity and access management, and another 35% are interested in it, but either have no plans or no budget for adding it to their slate of services.

Similar proportions of SMB executives recognize these issues: host event log monitoring or management (31% are interested but have no plans or budget); IDS/IPS monitoring or management (30%); endpoint security (34%); and regulatory compliance monitoring and assessment (31%).

When To Add Managed Services
The Forrester survey didn't tackle one of the most interesting questions from a managed services standpoint (in fairness, the focus was on security, not managed services). That is, what will it take for SMBs to start adopting the services in which they express interest, but have not yet budgeted for?

Our recommendation is to be proactive and deliberate about adding services. Don't wait for the need to arise; develop a plan to takes into account your security needs and build capabilities into both your budget and deployment plans on an incremental basis. That way, you'll enjoy the highest level of protection with a minimum amount of disruption.

Monday, January 26, 2009

Eight Options for Managed Security Services


In the online network connected business environment, security is more critical -- and also more complex. Today, network security requires constant monitoring and management. All businesses now experience vulnerability on an infrastructure that often extends to many locations.

Managed service providers can create a comprehensive security offering that enables you to maintain the level of protection and control you require. They can manage some or all of your network security functions -- giving you access to their dedicated manpower, 24-hour safeguarding, as well as routine maintenance and management of disaster recovery.

Finding the right security solution for your organization begins with establishing your priorities and becoming informed about alternatives. The following describes typical managed security service offerings, and how you can apply them.

Managed Firewall
Firewalls protect internal and external networks by restricting the types of network protocols and traffic allowed on your network. Firewall appliances, which the service provider manages remotely, include dedicated hardware and software platforms located on your premises.

Managed Distributed Denial-of-Service Protection
This service involves protecting the network infrastructure and network-based resources from distributed denial-of-service (DDoS) attacks -- so that your business can operate without interruption. It also helps prevent worm propagation that can cause DDoS attacks. DDoS mitigation provides protection against emerging threats.

Managed Intrusion Prevention Systems
Intrusion prevention systems (IPSs) identify and stop inappropriate attempts to access your network, systems, services, applications, or data. Intrusion detection services (IDSs) rely on network-based or host-based monitors, and often match monitored traffic or activity against profiles of known attacks.

Managed Antivirus Protection
This service most often involves checking for viruses at the gateway or firewall as well as in your e-mail messages, attachments, and file transfers. The service often includes automatic updates to antivirus definition files.

Managed Endpoint Protection
This service detects and stops unusual behavior on your endpoint devices, such as desktops and servers. In this way, you can prevent damage from Day-Zero security threats whose signature has not yet been identified.

Managed Authentication
Authentication refers to a group of processes and technologies used to verify the identity of a user attempting to gain access to your systems or applications.

Managed Content Filtering
Filtering is used to isolate and block content deemed inappropriate according to your internal policies or regulatory policies.

Vulnerability Assessment
The service includes security risk assessments, network scanning, and probing to reveal vulnerabilities in your network, operating system, or applications that can be accessed from the public Internet.

Contact a managed service provider, to learn more about these security capabilities, and the associated cost savings or productivity benefits. Most providers will have customer case studies for your consideration.

Friday, January 23, 2009

Managed Security with a Strategic Twist


Managed services provider Verizon Business has added an interesting twist to its security toolbox. Traditionally, managed security services are tactical: they monitor a network for potential attacks, using virus signatures and other definitions.

Earlier this month, Verizon upgraded its customers' security capabilities with what it calls its "Risk-Correlation Service," designed to add strategic insight to security.

The RCS works with vulnerability scans -- either those it does for customers or those from vendors such as McAfee, Qualys, and others -- to determine where potential vulnerabilities exist. The service also documents your system to create a map of devices and the business processes that run on them. "It marries threat information with vulnerability information," says Jonathan Nguyen-Duy, Director of Product Management for Verizon.

Calculating Risks
The result is a Web-based scorecard that shows Verizon customers not only where potential problems exist, but rank the level of relative importance of those devices. "We can tell you the likelihood of an event on a particular device, but also the business process associated with that device," says Nguyen-Duy. "Using the information from the vulnerability scan, we can tell you about the impact on availability. Is the device running real-time transactions, or is it a database server that might have less sensitive information?"

Strategically, companies can use the information presented in the online scorecard to get a sense of where to improve their online protection. Not all information is created equal, and not every database server requires the same level of protection.

The scorecard is designed to help companies prioritize their security budgets and their business continuity programs. "With limited resources, it's important to understand the relative risk of each vulnerability," he says.

Protection from Attacks
The online scorecard also works when attacks are underway. In those instances, it helps customers work with Verizon to identify where remediation is most important. "Sometimes you have to work in real-time to figure out where attacks are happening," Nguyen-Duy says. "Your ability to respond is improved when you have better information on the threat and what business process might be affected."

Being proactive about security is like flossing your teeth; you know you should do it more often, but it doesn't always happen. Applying a methodology that combines both strategic and tactical security needs is very wise. Clearly, when it comes to security, it's easier to be reactive when you've already been proactive.

Besides, the complexity of providing comprehensive network security protection, and keeping it fully up to date, is something best left to the experts. That's why managed security is one of the most utilized managed service offerings.