by Paul Korzeniowski

Live long, and prosper

Feature
Dec 27, 20045 mins

From defending Star Trek game code to shielding financial data, security content management tools protect early adopters.

At Perpetual Entertainment, protecting intellectual property is no game. But given the long lead times between the beginning of software development and product announcement, source code leakage is a huge concern for this online gaming start-up.

After signing a contract with Viacom Consumer Products, for example, Perpetual had to wait more than a year before it could talk about the “massively multiplayer” online Star Trek game it had been licensed to develop. Imagine the madness – and business problems – that would have ensued should word of or source code from this project have hit the streets earlier than intended. “With the type of products we deliver, it is imperative that we protect all of our intellectual property,” says Mark Rizzo, vice president of network operations at the San Francisco company.

Perpetual is not alone in its fear that confidential data could, either maliciously or through carelessness, be sent out. And with potential impact from leaked information including plunging share prices, decreased customer trust, loss of competitive positioning and potential legal sanctions, the concerns are warranted.

Fortunately, a handful of start-ups have begun delivering tools aimed at addressing this security issue. Secure content management (SCM) products, from vendors such as Reconnex, Tablus, Verdasys, Vericept and Vontu, protect corporate data by detecting, and sometimes blocking, messages containing confidential information. Company policies enable SCM tools to deduce whether information should stay inside or go beyond the corporate boundary. The tools scan information as it leaves, comparing it to a list of file names and key terms stored in a database, and then identify any matches. Some tools block questionable data from leaving the network, while others simply note each instance. They range in price from $25,000 to $100,000, depending on a company’s size.

An alarming problem

For Perpetual, Rizzo prefers the unobtrusive nature of Content Alarm from Tablus, a product he learned about two years ago while examining SCM options for a former employer. Within a few months of joining Perpetual in the summer of 2003, Rizzo added Content Alarm to the company’s security palette. He set it up to look for specific types of file attachments, such as source code and business plan spreadsheets, or words, like “Star Trek,” in e-mails. Content Alarm sits on the network and watches information as it flows out of the firm.

Although setting up the SCM tool was easy, company policies required some tinkering to solve a problem with false positives, Rizzo says. “We didn’t have to spend a lot of time customizing the system because we had already segmented our servers so the confidential information was stored on a few systems. As a result, we only had to point the Tablus system at those servers,” he says.

Perpetual also benefited from its small size, Rizzo adds. “If a company has multiple network exit points, then it could be difficult to set up SCM systems at the various locations, collect the outbound transmissions and then make sense of what is being transmitted,” he says. This is not to say that SCM tools aren’t useful for larger companies, just that for now they’re easier to configure for smaller deployments.

Tools to protect and secure content
Company Product
Reconnex G2 Content Analyzer
Tablus Content Alarm
Verdasys Digital Guardian
Vericept Vericept Intelligence Platform
Vontu Vontu Protect

The products monitor information coming from a variety of applications, including e-mail, instant messaging, peer-to-peer connections and even spam. “One firm discovered that confidential data was being transmitted via a Trojan horse that made its way past the firewall and was replicating itself within the network,” Rizzo says.

Help with the law

For First Financial Credit Union (FFCU), which has 300 employees and manages more than $500 million in assets, SCM serves a legal purpose. The company must abide by the Gramm-Leach-Bliley Act, which mandates privacy and protection of customer records maintained by financial institutions. FFCU counts on its SCM tool, Vidius’ Port Authority, to make sure customer account and credit information stays protected.

At the end of 2001, the financial institution began using Port Authority to monitor outgoing transmissions. Once the system was in place, FFCU discovered that employees were making a few mistakes. For example, some employees were sending confidential information to themselves so they could work at home or from the road. But they weren’t using encrypted links, says Janet Beanke, network manager at FFCU in West Covina, Calif. With information from Vidius, Beanke now can make sure that employees in these situations only use secure connections.

“With the Internet’s success, companies are finding more information is being transmitted electronically,” Beanke says. “In many cases, corporations have no visibility into what information is being sent out of the firm, so these tools provide a necessary service.”

Korzeniowski is a freelance writer in Sudbury, Mass. He can be reached at paulkorzen@aol.com .