Search This Blog

Showing posts with label threat. Show all posts
Showing posts with label threat. Show all posts

Saturday, March 31, 2012

Malware, Phishing Gather in North America

In its annual review of global security threats, Websense says a major trend it observed last year is that more malware connections, hosting and phishing appear to be occurring in the United States and Canada.

"50 percent of malware connections lead to the U.S.," says Charles Renert, vice president of Websense Security Labs. According to the 2012 Websense Threat Report, Canada's malware ranking has also zoomed upward in the past year, so the country now clocks in at No. 2 at 13.2 percent. The countries in the top five ranking include Germany at 5.4 percent, the Netherlands at 4.9 percent and China at 4.1 percent.
China and Russia used to be much bigger in the rankings, according to Websense, but since organizations have been more often blocking IP ranges for these countries, cybercriminals have turned to getting malware closer to their victims by exploiting trusted networks, such as social-networking sites. (See also "Best Security Suites: PC Bodyguards.")

For more, click the link below:


http://www.pcworld.com/article/252909/malware_phishing_gather_in_north_america.html#tk.nl_bdx_h_crawl

Friday, March 30, 2012

Dell SecureWorks Cited as a Leader in Managed Security Services

Date : 3/30/2012
Atlanta, Georgia
Dell SecureWorks has been cited as a “Leader” in “The Forrester Wave: Managed Security Services: North America, Q1 2012” report (March 2012). Dell SecureWorks was among nine Managed Security Services (MSS) providers that Forrester Research Inc. invited to participate in the study. 

Forrester states in the report that, “An increasing number of CISOs (chief information security officers) now view security outsourcing as a viable method for reducing costs and improving their security capabilities.”
 

Forrester evaluated the MSS providers’ current offerings and strategies against 60 criteria, and noted “SecureWorks remains a top player in the very competitive MSS market. Dell SecureWorks’ strongest asset is the quality of its analysts. SecureWorks’ correlation and logic engine technology, as well as its Counter Threat Unit research team, provide clients with the latest emerging threats and ensure that suspicious activity is detected and reported immediately.”
 

Dell SecureWorks’ proprietary, purpose-built security platform - the Counter Threat Platform (CTP) - filters, correlates and analyzes more than 20 billion events across the company’s customer base every day. Utilizing the CTP and knowledge of the applications and technology customers use, the Dell SecureWorks Counter Threat Unit security research team delivers early warnings and actionable security intelligence tailored to each of its customers so they can quickly protect themselves against threats and vulnerabilities before impact.

“We appreciate the recognition by Forrester as a leader in the highly regarded Forrester MSSP Wave” said Mike Cote, vice president of Dell SecureWorks. “Our success in the MSSP market is due to our focus on and relationship with our customers, and our elite, renowned security intelligence that we deliver to our customers,” said Mike Cote, vice president of Dell SecureWorks. “We believe this recognition reflects our more than 14-year dedication to information security services that help customers keep their critical assets safe while enabling them to conduct business more efficiently.”

Forrester mentions in the report that, “MSSPs leverage impressive economies of scale to offer clients an enhanced security environment, cost-effective security, and a scalable and flexible security platform capable of handling future expansion.”
 

Dell SecureWorks serves as an extension of an organization’s internal team to achieve its security objectives. The company helps organizations dramatically reduce the number of false alarms they have to respond to, helps fill gaps between their resources and their security demands, and watches over their IT systems and data 24 hours a day. Understanding the challenges organizations face with compliance, ever shrinking budgets and even smaller in-house security teams, Dell SecureWorks offers a broad range of information security services and service delivery options, including full outsourcing, co-management, monitoring, and on-demand software-as-a-service.
 

For a complimentary copy of “The Forrester Wave: Managed Security Services: North America, Q1 2012,” visit Dell SecureWorks’ website at
 www.secureworks.com. 

About Dell SecureWorks: Dell Inc. (NASDAQ: DELL) listens to customers and delivers innovative technology and services that give them the power to do more. Recognized as an industry leader by top analysts, Dell SecureWorks provides world-class information security services to help organizations of all sizes protect their IT assets, comply with regulations and reduce security costs. For more information, visit www.dell.com/secureworks.  

About Dell
Dell (NASDAQ: DELL) listens to its customers and uses that insight to make technology simpler and create innovative solutions that deliver reliable, long-term value. Learn more at
 www.dell.com.

Saturday, March 24, 2012

'Hacktivists' Lead Data Breach Threats, Study Finds

A tiny but motivated band of 'hacktivists' are supplanting professional criminals as the biggest single data breach threat to large enterprises, an analysis of hundreds of confirmed incident reports has found.

On the face of it, the numbers in Verizon's 2012 Data Breach Investigations Report (which covers 2011) suggest that hacktivism is more of a nuisance than a major threat, accounting for only 3 percent of the 855 recorded attacks looked at across several countries.

But despite the modest volume of attacks, hacktivist incidents often lead to far more spectacular losses. Verizon found that from a total of 174 million records (individual database entries as well as documents) compromised in the 855 incidents, 100 million were stolen by hacktivists.

This means that hactivism is a theme in only three out of every 100 incidents, but nearly six out of ten of the actual records that are compromised. (See also "Ten Best Practices to Prevent Data and Privacy Breaches.")

For more, click the link below:


http://www.pcworld.com/article/252429/hacktivists_lead_data_breach_threats_study_finds.html#tk.nl_bdx_h_crawl

Thursday, March 22, 2012

IBM X-Force Report: 2011 Shows Progress Against Security Threats But Attackers Adapt

IBM X-Force Report: 2011 Shows Progress Against Security Threats But Attackers Adapt

Emerging Attack Trends include Mobile Exploits, Automated Password Guessing, a Surge in Phishing and Shell Command Injection Attacks


ARMONK, N.Y. - 22 Mar 2012: IBM [NYSE:IBM] today released the results of its X-Force 2011 Trend and Risk Report, which shows surprising improvements in several areas of Internet security such as a reduction in application security vulnerabilities, exploit code and spam. As a result, the report suggests attackers today are being forced to rethink their tactics by targeting more niche IT loopholes and emerging technologies such as social networks and mobile devices.
The X-Force 2011 Trend and Risk Report revealed a 50 percent decline in spam email compared to 2010; more diligent patching of security vulnerabilities by software vendors, with only 36 percent of software vulnerabilities remaining unpatched in 2011 compared to 43 percent in 2010; and higher quality of software application code, as seen in web-application vulnerabilities called cross site scripting half as likely to exist in clients’ software as they were four years ago.  
In light of these improvements, it seems attackers are adapting their techniques. The report uncovers a rise in emerging attack trends including mobile exploits, automated password guessing, and a surge in phishing attacks. An increase in automated shell command injection attacks against web servers may be a response to successful efforts to close off other kinds of web application vulnerabilities.  
The IBM X-Force 2011 Trend and Risk Report is based on intelligence gathered by one of the industry’s leading security research teams through its research of public vulnerability disclosures findings from more than 4,000 clients, and the monitoring and analysis of an average of 13 billion events daily in 2011. 
“In 2011, we’ve seen surprisingly good progress in the fight against attacks through the IT industry’s efforts to improve the quality of software,” said Tom Cross, manager of Threat Intelligence and Strategy for IBM X-Force. "In response, attackers continue to evolve their techniques to find new avenues into an organization. As long as attackers profit from cyber crime, organizations should remain diligent in prioritizing and addressing their vulnerabilities." 
According to the report, there are positive trends as it appears companies implemented better security practices in 2011:  
·         Thirty percent decline in the availability of exploit code – When security vulnerabilities are disclosed, exploit code is sometimes released that attackers can download and use to break into computers. Approximately 30 percent fewer exploits were released in 2011 than were seen on average over the past four years. This improvement can be attributed to architectural and procedural changes made by software developers that help make it more difficult for attackers to successfully exploit vulnerabilities.  
·         Decrease in unpatched security vulnerabilities – When security vulnerabilities are publicly disclosed, it is important that the responsible software vendor provide a patch or fix in a timely fashion. Some security vulnerabilities are never patched, but the percentage of unpatched vulnerabilities has been decreasing steadily over the past few years. In 2011 this number was down to 36 percent from 43 percent in 2010. 
·         Fifty percent reduction in cross site scripting (XSS) vulnerabilities due to improvements in software quality - The IBM X-Force team is seeing significant improvement in the quality of software produced by organizations that use tools like IBM AppScan OnDemand service to analyze, find, and fix vulnerabilities in their code.  IBM found XSS vulnerabilities are half as likely to exist in customers' software as they were four years ago. However, XSS vulnerabilities still appear in about 40 percent of the applications IBM scans. This is still high for something well understood and able to be addressed. 
·         Decline in spam – IBM’s global spam email monitoring network has seen about half the volume of spam email in 2011 that was seen in 2010. Some of this decline can be attributed to the take-down of several large spam botnets, which likely hindered spammers’ ability to send emails. The IBM X-Force team witnessed spam evolve through several generations over the past seven years as spam filtering technology has improved and spammers have adapted their techniques in order to successfully reach readers.  
Attackers Adapt Their Techniques in 2011
Even with these improvements, there has been a rise in new attack trends and an array of significant, widely reported external network and security breaches.  As malicious attackers become increasingly savvy, the IBM X-Force documented increases in three key areas of attack activity: 
·         Attacks targeting shell command injection vulnerabilities more than double - For years, SQL injection attacks against web applications have been a popular vector for attackers of all types. SQL injection vulnerabilities allow an attacker to manipulate the database behind a website. As progress has been made to close those vulnerabilities – the number of SQL injection vulnerabilities in publicly maintained web applications dropped by 46 percent in 2011– some attackers have now started to target shell command injection vulnerabilities instead. These vulnerabilities allow the attacker to execute commands directly on a web server. Shell command injection attacks rose by two to three times over the course of 2011. Web application developers should pay close attention to this increasingly popular attack vector.  
·         Spike in automated password guessing – Poor passwords and password policies have played a role in a number of high-profile breaches during 2011. There is also a lot of automated attack activity on the Internet in which attacks scan the net for systems with weak login passwords. IBM observed a large spike in this sort of password guessing activity directed at secure shell servers (SSH) in the later half of 2011.  
·         Increase in phishing attacks that impersonate social networking sites and mail parcel services – The volume of email attributed to phishing was relatively small over the course of 2010 and the first half of 2011, but phishing came back with a vengeance in the second half, reaching volumes that haven’t been seen since 2008. Many of these emails impersonate popular social networking sites and mail parcel services, and entice victims to click on links to web pages that may try to infect their PCs with malware. Some of this activity can also be attributed to advertising click fraud, where spammers use misleading emails to drive traffic to retail websites.  
Emerging Technologies Create New Avenues for Attacks
New technologies such as mobile and cloud computing continue to create challenges for enterprise security.  
·         Publicly released mobile exploits rise 19 percent in 2011 – This year’s IBM X-Force report focused on a number of emerging trends and best practices to manage the growing trend of “Bring your Own Device,” or BYOD, in the enterprise. IBM X-Force reported a 19 percent increase over the prior year in the number of exploits publicly released that can be used to target mobile devices. There are many mobile devices in consumers' hands that have unpatched vulnerabilities to publicly released exploits, creating an opportunity for attackers. IT managers should be prepared to address this growing risk. 
·         Attacks increasingly relate to social media - With the widespread adoption of social media platforms and social technologies, this area has become a target of attacker activity. IBM X-Force observed a surge in phishing emails impersonating social media sites. More sophisticated attackers have also taken notice. The amount of information people are offering in social networks about their personal and professional lives has begun to play a role in pre-attack intelligence gathering for the infiltration of public and private sector computing networks.  
·         Cloud computing presents new challenges - Cloud computing is moving rapidly from emerging to mainstream technology, and rapid growth is anticipated through the end of 2013. In 2011, there were many high profile cloud breaches affecting well-known organizations and large populations of their customers. IT security staff should carefully consider which workloads are sent to third-party cloud providers and what should be kept in-house due to the sensitivity of data. Cloud security requires foresight on the part of the customer as well as flexibility and skills on the part of the cloud provider. The IBM X-Force report notes that the most effective means for managing security in the cloud may be through Service Level Agreements (SLAs) because of the limited impact that an organization can realistically exercise over the cloud computing service. Therefore, careful consideration should be given to ownership, access management, governance and termination when crafting SLAs. The IBM X-Force report encourages cloud customers to take a lifecycle view of the cloud deployment and fully consider the impact to their overall information security posture.  
"Many cloud customers using a service worry about the security of the technology. Depending upon the type of cloud deployment, most, if not all, of the technology is outside of the customer's control,” said Ryan Berg, IBM Security Cloud Strategist. “They should focus on information security requirements of the data destined for the cloud, and through due diligence, make certain their cloud provider has the capability to adequately secure the workload."  
IBM continues to work with its clients to step up security to address these new areas. Recommendations for helping clients improve the security of their IT department in light of these new threats include: performing regular security assessments; segmenting sensitive systems and information; training end users about phishing and spear phishing and secure computing principals in general, as well as examining the policies of business partners.  
To view the full X-Force 2011 Trend and Risk Report and watch a highlight video please visitwww.ibm.com/security/xforce.     
About the IBM X-Force Trend and Risk Report
The IBM X-Force Trend and Risk Report is an annual assessment of the security landscape, designed to help clients better understand the latest security risks, and stay ahead of these threats. The report gathers facts from numerous intelligence sources, including its database of more than 50,000 computer security vulnerabilities, its global Web crawler and its international spam collectors, and the real-time monitoring of 13 billion events every day for nearly 4,000 clients in more than 130 countries. These 13-billion events monitored each day – more than 150,000 per second – are a result of the work done in IBM's nine global Security Operations Centers, which is provided as a managed security service to clients. 
About IBM Security
With more than 40 years of security development and innovation, IBM has breadth and depth in security research, products, services and consulting. IBM has nine worldwide research labs innovating security technology and nine security operations centers around the world to help global clients maintain an appropriate security posture. IBM Managed Security Services delivers the expertise, tools and infrastructure clients need to secure their information assets from constant Internet attacks, often at a fraction of the cost of in-house security resources. The Institute for Advanced Security is IBM’s global initiative the help organizations better understand and respond to the security threats to their business. Visit the Institute community atwww.instituteforadvancedsecurity.com 
For more information on IBM Security Solutions, please visit: www.ibm.com/security.

Real Cost of a Cyber Attack

A new surbey reveals malicious hacking of government and corporate data accounted for more than half of all data thefts last year.  A CNBC interview provides insight on the cost of security threats, with Janet Napolitano, Department of Homeland Security secretary.


http://video.cnbc.com/gallery/?video=3000080031

Tuesday, March 13, 2012

News Release from Dell - Intent to Acquire SonicWALL

Dell Announces Intent to Acquire SonicWALL, Inc.

  • SonicWALL designs comprehensive security solutions combining advanced capability with ease of use, delivering a high return on investment for customers
  • SonicWALL expands Dell’s rapidly growing security software and services portfolio, which includes security services, cloud security solutions, data encryption solutions and vulnerability and patch management
Direct2Dell Community Blog@Dell on TwitterDell Announces Intent to Acquire SonicWALL, Inc. http://dell.to/ACiCnW #acquisitionsJoin the conversation.
#acquisitions


Dell today announced it has signed a definitive agreement to acquire SonicWALL, Inc., a leader in advanced network security and data protection. SonicWALL’s industry-leading Next-Generation Firewalls and Unified Threat Management (UTM) Firewalls complement Dell’s security solutions portfolio, enabling it to offer customers a broader range of enterprise offerings.

Customers of all sizes face increasing challenges in maintaining effective IT security, from the exponential growth of data and rapid adoption of cloud-based solutions, to the increased presence of consumer devices brought into the enterprise environment. SonicWALL expands Dell’s rapidly growing security portfolio, which includes Dell SecureWorks security services, cloud security solutions and data encryption solutions, and Dell KACE vulnerability and patch management.

Dell has taken significant steps to expand its enterprise solutions portfolio to offer customers a complete range of products and solutions to help customers simplify the management of their IT infrastructure. Dell remains committed to delivering complete security solutions using the most effective technologies and services from both Dell and from other providers.

SonicWALL Leadership
SonicWALL designs comprehensive security solutions that combine advanced capability with ease of use, delivering a high return on investment for their customers. The company has more than 130 patents, registered and pending, and develops all of its own key security gateway intellectual property. Today, more than 300,000 customers use SonicWALL security solutions, including firewalls, secure remote access, email security, backup and recovery, and policy, management and reporting. 

The increased frequency and diversity of security threats, requires customers to deploy more comprehensive security solutions. SonicWALL’s award-winning Global Management System allows network administrators to centrally manage and provision thousands of security appliances across a widely distributed network:
  • SonicWALL’s Unified Threat Management solution is comprehensive, easy to use, and affordable. It is ranked as a Leader in the Gartner Magic Quadrant for Unified Threat Management appliances.
  • SonicWALL’s SuperMassive provides Next-Generation Firewall specifically designed for the unique needs of enterprise, government, university and service provider deployments that require scalability, high availability and high performance. It was rated the most effective Next-Generation Firewall of those that achieved the NSS Labs “Recommended” status.
  • SonicWALL integrates advanced networking and remote access technologies to verify and defend the security of traditional and wireless networks, users and applications — and their endpoint devices — while scanning the entire data stream across platforms and perimeters.
Committed to Channel Partners
SonicWALL solutions are available for small, mid-sized business customers and large enterprise customers, and are deployed in large campus environments, distributed enterprise settings, government, retail point-of-sale and healthcare segments. The company has a strong channel program with 15,000 resellers providing extensive global coverage. Dell plans to take the very best of the SonicWALL channel programs and combine it with Dell’sPartnerDirect program to bring the best to channel members. Likewise, Dell’s existing PartnerDirect members will be able to sell SonicWALL solutions to meet their customers’ IT security needs. 

SonicWALL, founded in 1991, is headquartered in San Jose, Calif. and serves customers in 50 countries around the world. Thoma Bravo is the lead institutional investor in SonicWALL. Dell looks forward to welcoming SonicWALL’s approximately 950 employees to the Dell team, and plans continued investments to grow this business.

The transaction was approved by the board of directors of each company. Additional terms of the transaction were not disclosed. The transaction remains subject to customary conditions and is expected to close in the second quarter of Dell’s FY13. 

Quotes“We are building a strategic software portfolio to address the needs of our customers with key assets in the fast-growing and highly profitable IT security solutions business. Our customers see security as a key IT concern for the foreseeable future,” said John Swainson, president, Dell Software Group. “SonicWALL gives Dell access to unique intellectual property resources and technology that position us well in fast growing parts of the software security business.”

“Dell’s distribution, reach and brand are well-recognized across the industry. This transaction aligns well with Dell’s mid-market design focus and allows us to accelerate growth of our flagship SuperMassive Next-Generation Firewall solutions with Large Enterprise customers,” said Matt Medeiros, president and CEO, SonicWALL. “Additionally, SonicWALL is recognized as a leading security solutions provider for small and medium businesses through our UTM solutions. Dell’s phenomenal breadth and reach into small and midsize companies provides a significant opportunity to expand our customer base.”

An analyst call with John Swainson, president, Dell Software; Dave Johnson, senior vice president, Dell Corporate Strategy; and Matt Medeiros, president and CEO, SonicWALL; will be webcast live today at 8:45 a.m. CST and archived at www.dell.com/investor. 

Wednesday, February 22, 2012

News Release from IBM

IBM Advances Security Intelligence to Help Organizations Combat Increasing Threats

To help customers better predict, prevent and detect breaches across an organization, IBM to tap security analytics and threat intelligence from more than 400 sources, including the X-Force Threat Feed
ARMONK, N.Y. - 22 Feb 2012:  IBM (NYSE: IBM) today unveiled new capabilities planned for its security intelligence platform designed to combine deep analytics with real-time data feeds from hundreds of different sources to give organizations, for the first time, the ability to help proactively protect themselves from increasingly sophisticated and complex security threats and attacks using a single platform.
Organizations today are struggling to defend themselves against an onslaught of ever-evolving data breaches, such as theft of customer and employee information, credit card data and corporate intellectual property. To date, many corporations have been unable to create a security defense system because they have cobbled together technologies that don't integrate in an intelligent and automated fashion.  This patchwork approach has created loopholes that hackers can exploit.
The QRadar Security Intelligence Platform, designed by Q1 Labs and acquired by IBM last fall, tackles this problem head-on by serving as a control center that integrates real-time security intelligence data to include more than 400 different sources.
Major breakthroughs planned in the security platform include:
"Trying to approach security with a piece-part approach simply doesn't work," said Brendan Hannigan, general manager, IBM Security Systems. "By applying analytics and knowledge of the latest threats and helping integrate key security elements, IBM plans to deliver predictive insight and broader protection."
With new integrations to be made available, the analytics platform can quickly identify abnormal activity by combining the contextual awareness of the latest threats and methods being used by hackers with real-time analysis of the traffic on the corporate IT infrastructure. For example, the future integrations permit the platform to detect when multiple failed logins to a database server are followed by a successful login and access to credit card tables, followed by an upload to an unknown site.
"We chose the QRadar platform to build on and deliver our vision of a streamlined, highly intelligent platform to serve as our central nervous system for enterprise-wide monitoring," said Ken Major, Information Security Officer at AmeriCU Credit Union. "It enables us to achieve our goals, industry best practices and regulatory compliance."
Threat Intelligence
One of the significant planned integrations for the QRadar platform is IBM's X-Force Intelligence Threat Feed based on the real-time monitoring of 13 billion security events per day, on average, for nearly 4,000 clients in more than 130 countries. The QRadar platform will have visibility into the latest security trends worldwide to help protect enterprises against emerging risks. QRadar will present current IBM X-Force threat feeds in dashboard views for users, and correlate an organization's security and network events with these threats and vulnerabilities in real-time using automated rules.
Broad Coverage
Other planned integrations to allow the QRadar Security Intelligence Platform to help clients more rapidly identify threats by connecting events from the following categories:
QRadar integration modules are also planned for Symantec DLP, Websense Triton, Stonesoft Stonegate and other third-party products, increasing QRadar's ecosystem and continuing Q1 Labs' long-standing approach to multi-vendor heterogeneous environments.
Solutions to Analyze Big Data
In addition, the QRadar platform has been expanded with Big Data capabilities for storing and querying massive amounts of security information, and functionality for helping to secure virtualized infrastructures and providing a new level of visibility that helps clients reduce security risk and automate their compliance processes.
The expansion of security and network data sources is complemented by advanced functionality to help organizations keep pace with their exponential data growth. The new deliverables include:
The planned integration modules (device support modules) are expected to be included with QRadar SIEM and QRadar Log Manager at no additional cost, via automatic updates.
Availability
The Big Data and virtual infrastructure enhancements are available now.  QRadar integration modules for IBM Guardium Database Security are planned to be available in 1Q2012.
Integration modules for IBM X-Force Threat Intelligence, IBM Security Identity Manager, IBM Security Access Manager, IBM Security AppScan and IBM Endpoint Manager are planned to be available in 2Q2012.  For more information, please visit www.q1labs.com.