The last time we discussed encryption we examined its role in enhancing and protecting personal privacy. This piece continues by discussing why organizations should employ encryption as a priority tool in their security framework.
The current depressed global economy has resulted in a burgeoning market for stolen data.
Companies have, in the recent past, been slow to employ encryption due to various reasons. It used to be hard to set up and would slow network performance. The primary fear was that if a company used encryption on critical data and something went wrong, then that data would be irretrievable.
These concerns were justified then but are no longer relevant today. The first fear we should dispel about encryption is that implementing it is insanely difficult. Enterprise encryption software is now easy to deploy and maintain. You need to first establish how critical data flows through and out of the company. You also need to locate where this data resides. You will then be able to identify who has or can gain access to the data. Deploying encryption in these areas therefore becomes easier.
The second concern has been that encrypted data compromises network performance. This was true when encryption technology was in its infancy. Today’s solutions have been developed to make the best use of available computing cycles. They extensively use background processing to minimize their impact on the network.
It is also widely believed that managing an enterprise encryption solution is excessively complicated. Today’s encryption solutions are centralized and fundamentally simplify the oversight and administration functions.
It is also feared that encryption negatively affects data availability. Encryption does not limit access to data. It will only do so if you encrypt your database without carefully examining your enterprise use patterns. You should determine which critical applications are accessing the database most often. This will help you optimize your encryption solution to remove any bottlenecks or access delays.
Encryption finally invokes one doomsday dread. This is where a technical or staffing problem makes it impossible to decrypt your data. Imagine if the IT manager suddenly leaves the organization in a huff. Enterprise encryption will not leave you in such a lurch. There are double-authentications which require more than one person to access the key. If the key somehow becomes unavailable you can use the built-in restoration tool to decrypt your data. And with the numerous checks and balances that are in the software, any encrypted data can be decrypted and restored without resorting to expensive external consultation.
Encryption is necessary for any company that handles customer details and other critical data. There is now no sensible fear that justifies delaying usage of this crucial defense tool.
Thursday, April 30, 2009
Tuesday, April 21, 2009
ARE WE PROTECTING OUR WIRELESS NETWORKS?
Not too long ago applying for a fixed-line phone used to fill one with dread. After being on a waiting list for eons, you would finally get the treasured land line connection. That, however, would not be the end of your troubles. The connection would constantly break down, bills were often wrong and maintenance service was pathetic.
It is against this backdrop that we have readily embraced wireless communication technologies. Cellular networks have experienced phenomenal growth in the recent past. Wireless computer solutions have also experienced substantial demand as we seek to become more flexible and productive.
Dependence on wireless computer networks is therefore increasing. Wireless Local area networks (WLANs) and Wireless Metropolitan area networks (WMANs) that connect several WLANs have become common in Nairobi. People and businesses use wireless networks to send or share data quickly whether it be in an office building or across the world.
Wireless networks are, however, inherently more vulnerable than wired ones. Denial of service (DoS) attacks against this type of network does not require a very sophisticated modus operandi.
These attacks can be launched from within or from outside using widely available standard wireless equipment. They can be carried out by a hacker using a standard laptop equipped with a high output wireless client card and a high gain antenna. There are many other methods of attack and protecting these wireless networks requires the implementation of defensive measures.
Deploying WLAN intrusion detection systems will assist in identifying Dos attacks. Strategically mounting the access points at sufficient height will deter hackers from easily reaching and destroying the access points.
It is also important to aim directional access point antennas towards the inside of the building. This will help to contain the RF (radio frequency) signal.
Making a building as resistive as possible to incoming radio signals is another crucial defensive measure. Installing metallic window tint instead of curtains or blinds can help prevent RF leakage and keep incoming radio signals out. Wi-Fi proof wallpaper and Wi-Fi paint also serve the same purpose.
Implementing the IEEE 802.11w standards that outlines the Protected Management Frames is advisable. WLANs send system management information in unprotected frames. This standard aims to increase security by providing data confidentiality of these frames.
Finally, it is good security practice to carry out wireless audits with the aim of determining how far the RF signal actually extends outside the building.
It is against this backdrop that we have readily embraced wireless communication technologies. Cellular networks have experienced phenomenal growth in the recent past. Wireless computer solutions have also experienced substantial demand as we seek to become more flexible and productive.
Dependence on wireless computer networks is therefore increasing. Wireless Local area networks (WLANs) and Wireless Metropolitan area networks (WMANs) that connect several WLANs have become common in Nairobi. People and businesses use wireless networks to send or share data quickly whether it be in an office building or across the world.
Wireless networks are, however, inherently more vulnerable than wired ones. Denial of service (DoS) attacks against this type of network does not require a very sophisticated modus operandi.
These attacks can be launched from within or from outside using widely available standard wireless equipment. They can be carried out by a hacker using a standard laptop equipped with a high output wireless client card and a high gain antenna. There are many other methods of attack and protecting these wireless networks requires the implementation of defensive measures.
Deploying WLAN intrusion detection systems will assist in identifying Dos attacks. Strategically mounting the access points at sufficient height will deter hackers from easily reaching and destroying the access points.
It is also important to aim directional access point antennas towards the inside of the building. This will help to contain the RF (radio frequency) signal.
Making a building as resistive as possible to incoming radio signals is another crucial defensive measure. Installing metallic window tint instead of curtains or blinds can help prevent RF leakage and keep incoming radio signals out. Wi-Fi proof wallpaper and Wi-Fi paint also serve the same purpose.
Implementing the IEEE 802.11w standards that outlines the Protected Management Frames is advisable. WLANs send system management information in unprotected frames. This standard aims to increase security by providing data confidentiality of these frames.
Finally, it is good security practice to carry out wireless audits with the aim of determining how far the RF signal actually extends outside the building.
Saturday, April 18, 2009
COMPUTER GAMES HAVE BECOME SECURITY THREATS
If you encountered computers at an early age then you most likely indulged in computer gaming. Can you ever forget the excitement when you first played Prince of Persia, Wolfenstein 3-D and Doom? Other memorable ones include Counter-Strike and Grand Theft Auto.
Gaming has evolved from solo playing in one computer to interacting with multiple online players from far flung locations. This has spawned a lucrative business with revenues from online games being estimated to be in the billions of dollars. This has obviously attracted cyber criminals.
The rise in massively multi-player online role playing games (MMOGs) has made computer games attractive targets. Crooks are able to exploit the vulnerabilities in MMOGs to commit identity theft and intrusions.
MMOGs require permanent internet connections and this access is used to steal user data from both real and virtual environments.
In these games, players often change or purchase virtual commodities. These may be weapons, clothes, medicine, money or property. The items are bought using real money which is converted into virtual currencies. These virtual funds are attracting crooks. Profits derived from illicit activities are hidden in the game economies of virtual worlds in a new form of money laundering.
Due to the competitive cut-throat business of computer gaming, vendors have overlooked security in their mission to be first to market the next big game hit. The result has been increased vulnerability to data stealing Trojans. These Trojans have the aim of recording user IDs and passwords together with the IP addresses of the servers these MMOGs are hosted. Keyloggers are also introduced which record all keystrokes.
After compromising a player's online account, the online crooks are able to convert the virtual objects and currencies they steal into real money.
Other vulnerabilities that are easily exploited are scripting holes. These are typically found in web applications which allow code injection by malicious users into the web pages viewed by other users. An example would be where you play an online game from a website that has a link to another site that exploits a scripting vulnerability. Upon clicking the line malicious scripts execute in your browser and steal sensitive information like passwords and billing information.
Games that require permanent internet connections and use some form of virtual economies need to be used with caution.
Gaming has evolved from solo playing in one computer to interacting with multiple online players from far flung locations. This has spawned a lucrative business with revenues from online games being estimated to be in the billions of dollars. This has obviously attracted cyber criminals.
The rise in massively multi-player online role playing games (MMOGs) has made computer games attractive targets. Crooks are able to exploit the vulnerabilities in MMOGs to commit identity theft and intrusions.
MMOGs require permanent internet connections and this access is used to steal user data from both real and virtual environments.
In these games, players often change or purchase virtual commodities. These may be weapons, clothes, medicine, money or property. The items are bought using real money which is converted into virtual currencies. These virtual funds are attracting crooks. Profits derived from illicit activities are hidden in the game economies of virtual worlds in a new form of money laundering.
Due to the competitive cut-throat business of computer gaming, vendors have overlooked security in their mission to be first to market the next big game hit. The result has been increased vulnerability to data stealing Trojans. These Trojans have the aim of recording user IDs and passwords together with the IP addresses of the servers these MMOGs are hosted. Keyloggers are also introduced which record all keystrokes.
After compromising a player's online account, the online crooks are able to convert the virtual objects and currencies they steal into real money.
Other vulnerabilities that are easily exploited are scripting holes. These are typically found in web applications which allow code injection by malicious users into the web pages viewed by other users. An example would be where you play an online game from a website that has a link to another site that exploits a scripting vulnerability. Upon clicking the line malicious scripts execute in your browser and steal sensitive information like passwords and billing information.
Games that require permanent internet connections and use some form of virtual economies need to be used with caution.
Subscribe to:
Posts (Atom)