- BlackBerry Storm vs. the iPhone
- Digg's Kevin Rose: "We have to do better"
- Blogger warns: "Nortel doesn't make it out alive"
- Financial quagmire bringing out the scammers
- Verizon plays with the wrong e-mail addresses
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:Application Performance Solutions | App Performance | Networking Solution | SafeGuard Enterprise Solution Center | SOA | Test your Web Filter | Value of WDS
Having just returned from my first Black Hat experience, I can say it was outstanding. From the engagement of the crowd to the quality of the speakers to the controversy of the subject matter, my only regret was leaving after the first day.
The most striking thing to me about Black Hat was something I knew: If a skilled penetration specialist (how about that on your business card?) wants to get into your network, he can and will. Period. All of my conversations with folks in the trade drew that same conclusion. There are an infinite number of ways to compromise your defenses, and some of these folks seem to know every one.
What we need to focus on is containment. Remember, if you do networks and/or security, your first priority is to keep the applications up.
If there is good news, it's that there is little money in causing a network to fail outright anymore. So much of what took place at Black Hat was about getting into a machine under the radar and then using it for malicious intent. So we need to change tactics a bit, meaning you want to make sure that you find out about the issue and figure out a way to minimize the damage before your data is compromised.
First, you need to look at activity on your network. The main objective of today's bad guys is to harvest private information. They can do it in one fell swoop by attacking your databases, or they can get it one user at a time by turning those devices into zombies (otherwise known as bots).
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment