Thursday, May 27, 2010

Internal Threats to Your Network

Internal Threat Landscape

In today's world, more and more customer data is being found on servers, desktops and laptops which contain critical information that can promote a company's growth or destroy the company in an instant. Furthermore, the risk extends beyond the private sector to the public sector and anyone in their homes receiving services from one of these infrastructure entities.

A study performed by Promisec, Inc., a company that regularly conducts comprehensive security audits across a number of industries - including finance, healthcare, insurance, manufacturing, etc., found that:

Use of unauthorized removable storage continues to rise in organizations.

The number of endpoints that do not apply threat management agents or are not updated with the latest build or signatures continues to rise.
Instances of unauthorized instant messaging continue to increase in all organizations.

The study also discovered that -

12% of infected computers had a missing or disabled anti-virus program.
10.7% had unauthorized personal storage like USB sticks or external hard drives.
9.1% had unauthorized peer-to-peer (P2P) applications installed.
8.5% had a missing 3rd party desktop agent.
2.6% had unprotected shared folders.
2.2% had unauthorized remote control software.
2% had missing Microsoft service packs.

Without application awareness, both perimeter and defensive island systems were easily defeated. For example, SQL Slammer was able to enter organizations quickly because:

Firewalls and anti-virus solutions that rely on signatures didn't view the traffic as a threat.

Often, SQL Slammer bypassed perimeter defenses and entered at the network edge through laptops and mobile devices whose traffic never traversed the firewall.

Like firewalls, without a signature to identify it, anti-virus software and most HIDS did not recognize it as a threat.

SQL Slammer was memory resident. Most anti-virus software completely missed it because their scanning engines are often focused on detecting exploits written to disk drives.

Within minutes of an initial SQL Slammer infection, nearly all vulnerable computers on the inside of the network were compromised. Depending on the number of infected devices, this often resulted in massive denial of service on the internal LAN. Furthermore, newer types of attacks are designed not to make "noise" in order to stay undetected.

Product Substitute Availability

Firewalls are a necessary security control for policy enforcement at any network trust boundary, but changing business and threat conditions are putting pressure on growth in the firewall market. Enterprises are redesigning their demilitarized zones (DMZs) to react to the business realities of how staff and customers connect, which drives firewall demand up. However, the increasing requirement for network defense against more-complex threats has increased the deployment of network intrusion prevention, and driven vendors to provide products that support complex deployments and rule sets that mix traditional port/protocol firewall defense with deep-packet inspection intrusion prevention.

At one point in time, Cisco had the best firewall on the market. As the years passed, competitors of all sizes were vying for Cisco's market share. Vendors, such as Juniper, Checkpoint, McAfee and others, have challenged and even taken market share from Cisco. In the Gartner's 2008 magic quadrant, only two vendors are residing in the upper right hand "leaders" quadrant - Juniper and Checkpoint.

In the latest Gartner report, dated 12 October 2009, large enterprises will be replacing stateful firewalls with the Next Generation firewalls during the natural lifecycle replacement. And there are very few vendors that have upgraded their respective product lines to reflect the new attack vectors. Gartner believes that the changing threat conditions and changing business and IT processes will drive network security managers to look for NGFW capabilities at their next firewall/IPS refresh cycle. The key to successful market penetration by NGFW vendors will be to demonstrate first-generation firewall and IPS features that match current first-generation capabilities while including NGFW capabilities at the same or only slightly higher price points.

More coming later - but until then, look at our website for open source software @ http://www.oss4win.com

Mike Millslagel
Security System Consultant
B.S. Information Systems, MBA, MCSE, CNE, CCNP Security Specialist
http://www.oss4win.com

Wednesday, May 12, 2010

What is a Denial-Of-Service Attack?

A denial-of-service (DoS) attack attempts to prevent legitimate users from accessing information or services. By targeting your computer and its network connection, or the computers and network of the sites you are trying to use, an attacker may be able to prevent you from accessing email, websites, online accounts, banking, root name servers, or other services that rely on the affected computer.

One common method of attack involves saturating the target machine with communications requests, so that it cannot respond to legitimate traffic, or responds so slowly that it is effectively unavailable.

During normal network communications using TCP/IP, a user contacts a server with a request to display a web page, download a file, or run an application. The user request uses a greeting message called a SYN. The server responds with its own SYN along with an acknowledgment (ACK), that it received from the user in initial request, called a SYN+ACK. The server then waits from a reply or ACK from the user acknowledging that it received the server's SYN. Once the user replies, the communication connection is established and data transfer can begin.

In a DoS attack against a server, the attacker sends a SYN request to the server. The server then responds with a SYN+ACK and waits for a reply. However, the attacker never responds with the final prerequisite ACK needed to complete the connection.

The server continues to "hold the line open" and wait for a response (which is not coming) while at the same time receiving more false requests and keeping more lines open for responses. After a short period, the server runs out of resources and can no longer accept legitimate requests.

A variation of the DoS attack is the distributed denial of service (DDoS) attack. Instead of using one computer, a DDoS may use thousands of remote controlled zombie computers in a botnet to flood the victim with requests. The large number of attackers makes it almost impossible to locate and block the source of the attack. Most DoS attacks are of the distributed type.

An older type of DoS attack is a smurf attack. During a smurf attack, the attacker sends a request to a large number of computers and makes it appear as if the request came from the target server. Each computer responds to the target server, overwhelming it and causes it to crash or become unavailable. Smurf attack can be prevented with a properly configured operating system or router, so such attacks are no longer common.

DoS attacks are not limited to wired networks but can also be used against wireless networks. An attacker can flood the radio frequency (RF) spectrum with enough radiomagnetic interference to prevent a device from communicating effectively with other wireless devices. This attack is rarely seen due to the cost and complexity of the equipment required to flood the RF spectrum.

Some symptoms of a DoS attack include:

  • Unusually slow performance when opening files or accessing web sites
  • Unavailability of a particular web site
  • Inability to access any web site
  • Dramatic increase in the number of spam emails received

To prevent DoS attacks administrators can utilize firewalls to deny protocols, ports, or IP addresses. Some switches and routers can be configured to detect and respond to DoS using automatic data traffic rate filtering and balancing. Additionally, application front-end hardware and intrusion prevention systems can analyze data packets as they enter the system, and identify if they are regular or dangerous.

The author is a computer security professional with experience protecting small business and home networks. He also teaches the basics of computer network security at 365 Computer Security Training where he blogs regularly and creates video training and educational materials related to information security. Learn more at http://www.365ComputerSecurityTraining.com

Saturday, April 24, 2010

Top 4 Threats to Your Wireless Network

If you are like most online business owners that are using a wireless network, you are likely unaware of the potential dangers to both your business and the safety of you and your customers data. In this article, I'm going to discuss 4 different threats that you must be aware of when it comes to operating a business over a wireless network.

Many think that if they have the latest router, combined with the latest in security software, they are all set and having nothing to worry about. Unfortunately, that's not the case. Any type of equipment or security measures you take only act as deterrents. If someone really wants to break into your network, they'll come up with a way to do so. The good news is that most hackers will go after sites that have lax security procedures.

The top 4 threats to your wireless network that you need to be aware of include:

1. Sniffing

This type of threat involves hackers that use software programs called sniffers that are able to scan the traffic on a network. All the hacker that has this software has to do is use it in areas with many networks until they lock onto an unsecured wireless network.

2. War Driving

With this threat, the hacker only needs a wireless device - such as a laptop or PDA. They simply drive around until they pick up an unprotected wireless signal from homes our businesses. These people will record your wireless id information, along with your physical address and post it in online databases so that others will know where there is an unsecured network, ripe for the taking.

3. Evil Twin

In this threat, your access to a legitimate wireless access point is blocked. Then, without your knowing it, you're redirected to a second access point that is managed by a hacker. Any information you transmit is accessible to the hacker. Keystrokes are also able to be captured, which means any passwords you type in are now in the hands of the hackers. This type of threat is most common in public access points, such as restaurants and airports.

4. Wi-fishing

This is similar to the evil twin threat in that it takes you to what looks like a safe access point. By utilizing common SSIDs of public Wi-Fi spots, your computer will automatically connect to the hacker's network. Same situation with the evil twin set up - the hacker can grab all of your information that you type in while connected to their network.

Needless to say, the real threat with these and other wireless network threats is that the risk to your bottom line is in danger. While some hackers only do what they do to see if they can do it, or to be a simply annoyance, thieves that get involved in wireless threats are not of the harmless variety. They can cost you plenty.

Warren has been writing articles and producing how to courses online since 2005. He specializes in online business issues and currently operates a number of websites in a number of different niches. You can check out his latest website here: Youth Motorcycle Helmet featuring the Full Face Helmet.

Wednesday, April 7, 2010

Internet Filter Programs and IP Changer

Do you think that just because you have installed Internet filter programs you can now freely and safely browse the internet and disregard other security measures such as the use of an IP Changer? Well, you are thinking wrong. While Internet filters surely have their advantages, they still have that one disadvantage that can be your computer system's downfall in the future or loss of privacy on the internet. That is that Internet filters are far from providing complete protection or being hundred percent reliable. By incorporating other internet security features and by browsing anonymously with the help of IP Changer a software program, that also encrypts your data sent over the internet you will be able to browse the internet more securely and privately.

Internet filters, or web filters, are also known as content-control programs or software, which control the kinds of content that can be accessed by a user. The software or program is especially designed to restrict specific websites or content that the user sets to block beforehand.

Internet filtering programs are now being used at various levels of the community. The government, for example, uses more sophisticated programs to restrict access to the confidential records. Companies use it to control the sites that their employees can have access to or not. Schools also use it to block sites that may influence their students dangerously, as do parents with their children. Even individual users can use it for their own purpose, to block off sites that are deemed dangerous for the computer system.

The main purpose of the content-control software is to prevent people from viewing sites and content that can be harmful or just plain objectionable for the owner. Companies, for example, may want to restrict their employees from venturing to websites not related to their work. These websites may not be harmful, but as they distract the employees from their work at hand the company may deem it necessary to block these websites.

Another purpose of the Web filters is to protect the users from dangerous and corrupting sites. Students and children are especially being protected from these sites, which is why Internet filters are growing in usage at homes and schools. But as stated above, these Internet filters are not entirely reliable. It is especially not going to be of any help if the sites not included in the filter can be accessed by malicious users to the children.

We can also look at it in the same way we look at spam email filters. Spam filters help in sending useless spam emails to the spam section but we still see a spam email in our inbox from time to time. As it was said, it really is not a hundred percent spam filtered or protected system. Internet site and content filters are the same? They are not fool proof.

Furthermore, you need the protection of a complete internet security software that includes, firewall, anti virus, anti spyware anti phishing and anti malware features. After these security features are in place you have to realize that you still can't browse the internet totally securely. You are still vulnerable to sophisticated hackers and cyber criminals that can find your IP address and hack into your computer to steal your personal and financial information. You are very vulnerable to identity theft. If you are using wireless networks to access the internet you have to take a whole range of security measures including data encryption to be safe on the net.

This is why in order to achieve a higher level of protection, changing your IP addresses will provide that extra and most important level of security. IP Changer is software that directs your internet connection through different anonymous web servers that have their own IP addresses. IP changer thus can frequently change that IP address as well. This way your real IP address is hidden and allows you to surf the internet anonymously. Some IP Changers come with high level encryption capabilities further protecting you and your sensitive data over the internet.

Thus by browsing anonymously, you are able to protect yourself and your kids from sites and content and malicious users who can get through the filters and other security features you had before. Your privacy and sensitive financial and personal information is much safer now than ever before if you use IP Changer.

Having learnt some important information about a new technology that uses and IP Changer to make wired and wireless networks safer and more secure go to http://www.change-ip-proxy.com to get an in depth information about the technology and systems that will best help you to enhance the security of your networks.

Thursday, March 18, 2010

Five Things You Need to Know to Spot a Con Game

Internet scams. They are becoming more and more advanced and plaguing everyone's email. My mom, an epic sucker, likes to send me email after email about African princesses who need our help and new instant money surveys constantly. So now not only am I blocking the daily spam that fills my email account everyday, I'm screening my own mother's emails. The incredible stories and lies are never ending. How are we supposed to know what is real or fake anymore.

Any email, even from someone we may trust like our bank, PayPal, or even our own parents who don't understand what SPAM is, could potentially be a computer bomb. Even worse, how are legitimate companies supposed to communicate with their clientele. The internet was made to be a free and easy form of communication. However, free and easy includes communication from both the honest and the dishonest.

Here are a few red flags to always be weary of when looking for a legitimate company online.

1) Never give away any information via email that you are not comfortable with. For example, your social security number, banking number, credit card, mother's maiden name, or any information that would compromise your identity or your money.

2) If an email says it is from a certain website like MySpace, Facebook, PayPal, etc. don't follow the link directly on your email. Enter the original site address into your search bar and go from there. Have you ever been phished? It is not a fun experience.

3) If anything about a website seems off or different don't enter your personal information or any passwords until you're sure you are on a secure site.

4) When ordering anything online, always look for little key phrases and avoid checking boxes to contracts that entail sharing your information with other companies. This is a way for companies to make money simply off of your email address, and why your inbox is full of things you've never even heard of and have absolutely no interest in. If you order online frequently do what I do and get more than one email address - one for legitimate sites and friends and one for SPAM. If something seems fishy send it to the SPAM address

5) IF IT SEEMS TOO GOOD TO BE TRUE, IT IS! No one gives away free money unless you've been picked for a game show, and guess what? They won't send you an email about it. Avoid making any large investment into anything until you have researched it and you know what you are doing. Always look for more than one site about whatever you are considering, and most importantly, have some common sense.

Everyone is looking for a way to make themselves rapid cash. The problem is they turn to these scams to find it. If one really wants to make themselves rapid cash then they have to find a good company and work it hard and smart. Then they will find that not only does the rapid cash come but its stays forever.

There are great opportunities online. The Internet is an amazing tool for businesses. If you keep a clear head and follow your intuition it is easy to spot the scams and the real opportunities.

If you want more information click here http://www.rapidcashstrategy.com.

Wednesday, March 3, 2010

Recommended and Credible E-Signature Services

An E-Signature is a highly sought and recommended way of not only saving on paperwork shipping and handling costs, but it is also a safe and secure way that one can assent to contracts and documents in record time as one does not have to wait one's documents to be posted. One can also store all documents in an archive in a variety of readable formats and make quick and easy copies of parties involved. An E-Signature is a scanned handwritten signature, Morse code, symbol or even sound that only the use has access to that can be recognized as a sound consent to a given agreement.

One of the top services includes Echo Sign that has over 14,000 clients and a million users. It has been given a 'thumbs up' form firms like the Wall Street Journal, New York Times, British Telecom and Red Herring as the way to go when it comes to generating an E-Signature with a competent company. All one has to do is sign up on their website by sending ones documents with the recipients address to Echo Sign and then they, you and any other involved party will receive a PDF format copy of the document. They offer and archive that one can view all contracts and set reminders for events and important work. One can visit their site, which is http://www.echosign.com.

Arx Cosign is an E-Signature service that allows one to either receive the signature software for large organizations or for small companies one can get a desktop interface that does not need any installation. Both are offered on trial basis and can be used on documents of any format, be it Word or Excel spreadsheets. Its high security features are able to detect if the software has been tampered with and this means that one can be assured of a forgery-proof signature service. Visit their website at http://www.arx.com for more details.

Looking for more information on obtaining an Electronic Signature? Be sure to check out our link below as TurboSignature is the quickest, most efficient way to get a document signed.

Digital Signature

Wednesday, February 10, 2010

Want to Change Your IP Address and Surf Anonymously? Your Best Option - Free Proxy Or Paid Software

Changing your IP address is important these days to protect yourself from identity theft and scammers online. But what is the best option online for protection against identity theft and hackers?

In this article I will be comparing free proxy sites with paid IP address software based on my own personal experience.

Free Proxy

Free proxies are a very fast way for you to surf anonymously without restrictions. But one thing is worthy of note, never try using them for anything that requires you to give up your personal data.

Not too long ago I lost some money to hackers because I used a free proxy site to access my online digital currency account- Liberty reserve account to be specific.

After that experience I conducted a research to find out other people experiences with some proxy changing sites and I discovered I was not alone, so many people were falling victims to the same ploy used by hackers to lure unsuspecting victims to their traps.

Paid IP Address Software

Ever since my bad experience with free proxies, I have started using paid software to "hide my IP address" and I've never had any problem whatsoever.

What I discovered is that the sites that offer paid software to hide your IP address are professional and go out of their way to make good impressions. They value repeat business and referrals so they don't do shady stuff like free proxies do.

Now I am not saying all proxies are bad but some of them are run by hackers and scammers out to rob unsuspecting victims of their identity and ultimately their hard earned cash.

So don't make the same mistake I did, go for a reliable paid software that will give you peace of mind!

Want want to safely surf anonymously, protecting your identity while browsing the net without limitations? CLICK HERE!.

For more useful tips and reliable IP changing options that protects you from identity theft, visit http://anonymousinternetbrowsing.com/.