Skip Links

Network World

Jamey Heary

Security Updates plus 46 Security fixes – iPhone Is Enterprise Ready Now!?

iPhone Enterprise Security finally comes into its own
Submitted by jheary on Sat, 06/20/09 - 7:15pm.

The recent disclosure of 46 new security fixes in iPhone 3.0 is just part of the proof the iPhone is ready for Enterprise adoption.

Read more

Cisco's CSO speaks out on ideas to secure the nation

Submitted by jheary on Thu, 06/11/09 - 2:10pm.

President Obama recently announced the results and his perspective of the 60-day cyber security review he requested earlier this year. This makes him the first president to ever put their name with such a report. Following the results of the 60 day cyber security review, the Obama administration has made clear the urgent need to upgrade our nation's information technology infrastructure with a particular focus on securing those systems.

Read more

2009 Top Urban Legends in IT Security

Submitted by jheary on Mon, 06/08/09 - 1:28am.

There are lots of IT Security related urban legends floating around the Internet. Some have malicious intent and others are just for fun. Some have been with us for years but still refuse to die. Here is a list of my top IT Security Urban Legend picks for this year.

1) Department of Homeland Security mandates that all PC manufacturers install keyboard-logging devices in all PC keyboards.

Read more

Upcoming Cisco Security Events Worth Noting

Submitted by jheary on Sun, 06/07/09 - 12:30am.

With all of the free webinars, VoD, IP/TV, and forum sessions available on the web it can be hard to find what you’re looking for. To that end I put together a list of some of the upcoming online security events that Cisco will be putting on in the next few months. The topics are wide ranging and the content varies from advanced to beginner and technical to marketing. Have a look and see if something catches your eye.

Email Security Events

Read more

Top 4 Tips to Fight Off Botnet Denial of Service Attacks

Submitted by jheary on Sun, 05/31/09 - 4:38pm.

In case you haven’t been paying attention Botnet DDoS attacks passed the 40 Gigabits/sec mark in 2008 according to Arbor Networks. The shear size of today’s Botnets has reached into the mind-boggling realm of 1.9 million bots in a single Botnet. Couple that with the fact that Botnet DDoS attacks are one of the hardest assaults to defend against and you have a real nightmare scenario on your hands.

Read more

PCI Standard or Not, Encrypting Internal PCI Network Traffic is a Good Thing

Submitted by jheary on Mon, 05/25/09 - 6:20pm.

Internal networks are notoriously insecure so why wouldn’t you encrypt PCI data end to end? What makes an Internal Network somehow so inherently secure that encryption is not needed? I would contend that even the idea of an Internal Network is inconsistent with today’s network architectures. Companies have moved to ubiquitous access, perimeter-less networks, rendering the concept of an Internal Network inappropriate.

Read more

Cisco ASA Innovation Tracks Botnet/Malicious Activity

Submitted by jheary on Sat, 05/23/09 - 4:58pm.

Are there Botnet controlled hosts on your network? Are your hosts infected with malware or spyware that is trying to “phone-home"? How would you know? One way to find out is to employ Cisco ASA’s new Layer 4 Traffic Monitoring (L4TM) feature. L4TM detects infected clients by tracking rogue “phone-home” traffic.

Read more

Cisco MARS NetPro Community forum

Submitted by jheary on Mon, 05/18/09 - 12:20am.

Ever run into a product that MARS doesn’t support but you wished it did? Have you ever created your own custom parser to support a product that MARS didn’t have natively? If you answered yes to either of those questions then this blog will be right up your alley.

Read more

A memoir of my journey to become an iPhone App Developer, how hard is it really?

Submitted by jheary on Sun, 05/10/09 - 5:08pm.

What is the real deal with iPhone application development? Is it easy, hard, or somewhere in between? I just took a weeklong iPhone development course to find out. Like many iPhone owners, I want to have my own App Store shot at fame and fortune (well at least the fortune part:). Ever since I purchased my iPhone I thought it would be cool (and maybe profitable!) to develop my own iPhone app for the App Store. When I heard that a developer class was coming to my hometown of Denver I decided to seize the opportunity to throw my hat in the ring.

Read more

Cisco Releases refreshed Security Best Practices Guide - SAFE

Submitted by jheary on Thu, 05/07/09 - 11:00pm.

Cisco’s SAFE Security Design and Implementation Guide is back. Cisco has given its SAFE Guide a complete makeover and brought it up-to-date with today’s threat environment. True to the legacy of the old SAFE Guide an updated version of the then popular SAFE Poster is available for your cube wall as well!

Read more

PCI Security Council votes Cisco onto its elite Board of Advisors

Submitted by jheary on Fri, 05/01/09 - 8:11pm.

Cisco Systems has been voted onto the twenty-one member PCI Security Standards Council (SSC) Board of Advisors. The official announcement from the council should come in early May. The Board of Advisors is elected every two years, with the last election being in 2007. In a nutshell, the PCI Security Standards consist of 12 main IT security requirements that work to reduce digital credit card fraud.

Read more

Cisco Introduces IPS Card for the ASA 5505

Submitted by jheary on Wed, 04/22/09 - 3:34pm.

Ever wondered what that blank slot in your ASA5505 is for? Well now you know, it’s for a modular IPS card. Adding full-blown IPS to the ASA5505 will substantially increase its ability to protect you. The AIP SSC-5 provides up to 75 Mbps of IPS or IDS throughput and supports both IPv4 and IPv6 networks. The 75Mbps performance with 4000 maximum connections per second should be able to accommodate just about any SOHO or branch office configuration, the sweet spot for the ASA5505.

Read more

Cisco makes several new security announcements at RSA

Submitted by jheary on Tue, 04/21/09 - 4:42pm.

Cisco announced a slew of new security offerings at RSA this morning. The most exciting is also an industry first, Cisco added reputation lookups to their IPS. This has resulted in a 2x better catch rate versus just IPS alone. The beauty of reputation is that it is fast, in fact Cisco is reporting it is 100 times faster than a normal signature match. I’ll be blogging on that topic in more detail later, but first here is list of all of the announcements Cisco made at RSA.

Here is Cisco’s RSA press release:

Read more

Boost your corporate security posture even if you don’t have any budget

Submitted by jheary on Sat, 04/18/09 - 6:41pm.

Corporate security teams around the world are seeing their budgets get hacked and slashed down to the bare bones (just like every other dept). Many of those that are tasked with the protection of their company’s digital data are frustrated and concerned. Without those dollars they will struggle to keep the shields up and perimeter secured. That’s when we need to turn to the old adage use what you have for support.

Read more

Cisco NAC Leads Industry with Vision and ability to Execute

Submitted by jheary on Fri, 04/10/09 - 7:24pm.

Gartner released its latest Network Access Control (NAC) magic quadrant results for 2009. Cisco’s NAC solution came out on top in both the completeness of vision category and the ability to execute category. This puts Cisco’s NAC solidly up and to the right on the magic quadrant. Gartner’s report also pointed out that Cisco’s NAC solution is deployed by significantly more customers than any of the other vendors ranked.

Read more

Need a bigger security budget? Star in your own hacking video!

Submitted by jheary on Mon, 04/06/09 - 1:16pm.

Over the years I’ve assisted many security directors in their process of justifying new security projects and budgets. I’ve seen countless techniques used by security teams in an effort to free up hard to attain dollars for security projects. There are two techniques I’ve seen work with a very high degree of success that I wanted to pass along to you all.

Read more

IT Security Jobs remain HOT, here's advice on landing a Security Sales Eng. Job

Submitted by jheary on Sat, 03/28/09 - 11:05pm.

One of the best places to be in almost any company is a job in or around their sales departments. Sales are a company’s lifeblood so those that can directly influence those sales usually enjoy higher pay and more job perks. However, nothing is for free right? So the trade-off is you typically have less job security and work longer hours. If you don’t bring in the numbers to meet your sales quota you’ll be out of the job before long. One thing you definitely can’t do is “coast” in a sales job. IT sales jobs are no exception to this rule.

Read more

Check out Cisco’s Free Weekly Risk Report

Submitted by jheary on Mon, 03/23/09 - 2:18pm.

On a weekly basis Cisco’s Intellishield group will post a free overview of what’s happening in the security world. The reports provide a high level overview of what’s happening in these areas:
*Vulnerability
*Physical
*Legal
*Trust
*Identity
*Human
*Geopolitical
*Miscellaneous
*Upcoming Security Activity

I find the geopolitical information very interesting, mostly because it is hard to find it elsewhere.

The risk reports are also available as podcast downloads or via RSS feed.

Take a look at their archive of Risk Reports here

Read more

Uh Oh, Exploit code targeting major Intel chip flaw to be posted 3/19/09

Submitted by jheary on Tue, 03/17/09 - 7:03pm.

This is the scariest, stealthiest, and most dangerous exploit I've seen come around since the legendary Blue Pill! No, I'm not just trying to sensationalize this or spread fear, uncertainty and doubt. This is serious and represents a massive new security threat for us all.

Read more

Welcome, visitor. Register Log in
Advertisement:
About Cisco Security Expert

Jamey Heary, CCIE No. 7680, is the author of the Cisco NAC Appliance: Enforcing Host Security with Clean Access book by Cisco Press. Jamey is a seasoned security technologist with over 15 years in the IT field with 10 years focused on IT security. His areas of expertise include network and host security design and implementation, security regulatory compliance, and routing and switching. His other certifications include CISSP, CCSP, and Microsoft MCSE. He is also a Certified HIPAA Security Professional. Jamey is currently a Security Consulting Systems Engineer with Cisco, though the opinions expressed here are his own. Jamey is a member of Network World's Cisco Subnet blog community.

Contact him.