By John P. Mello Jr. TechNewsWorld Part of the ECT News Network
06/21/05 9:05 AM PT
Vernier President and CEO Simon Khalaf said that the survey revealed some "shocking" findings about companies' knowledge level about internal network security. "Companies did not realize how open their network and their systems are to attacks from within the company," he said.
Most companies depend exclusively on perimeter defenses to protect their computer networks from intruders, a practice that appears to be more sieve than stone wall, according to a survey released yesterday by Vernier Networks, a network access management firm in Mountain View, Calif.
Surveyors found that 51 percent of those sampled said they relied on strong perimeter security, or the "doorman" approach to network protection. Once past the doorman, users have unlimited access to information on the company's network.
The doorman, though, appears to be leaving his portal unattended, as 62 percent of the security execs admitted that intruders had occasionally gained access to their networks.
Opening Doors
The survey sampled some 140 chief security officers (CSOs) and security executives who attended a recent nationwide seminar series on network security held by Vernier and Qualys, a vulnerability management firm in Redwood Shores, Calif.
"The perimeter isn't as deigned as it used to be," Qualys CEO and Chairman Philippe Courtot told TechNewsWorld. "If you let people connect to your network from the outside, you're opening doors."
Vernier President and CEO Simon Khalaf said that the survey revealed some "shocking" findings about the knowledge level of companies when it comes to internal network security.
"Companies did not realize how open their network and their systems are to attacks from within the company," he told TechNewsWorld. "This has been talked about for the last year and a half, but the response has been [to do] more of the same, which is strengthening the defenses around the network versus putting security inside the network."
Marc Borbas, product manager for e-mail security at Sophos in Vancouver, British Columbia, Canada, agreed that many organizations might be emphasizing perimeter security to the exclusion of other security layers.
Desktop No Answer
"We've noticed, especially in the e-mail segment of our business, there's a huge amount of investment that's gone into the perimeter and an underinvestment in the constituent layers of the e-mail system," he told TechNewsWorld.
"Companies have a good hard shell in many cases, but they're very vulnerable in that middle spot, he added.
At most companies, internal security controls are placed at the desktop level, which is inadequate, Khalaf contends. "If a desktop or a laptop has been hacked into, the security on the desktop ain't going to do much," he said.
He explained that intruders attempting to break into a network from outside the system usually must go through a firewall, an antivirus gateway and an intrusion prevention system. If they're breaking into the system from a compromised desktop or laptop connected to the system, they don't go through anything.
"The reaction to securing the network from the inside has been, let us put more security software on the desktop," Khalaf said. "I believe that is a bit flawed. What needs to happen is that the connection between the laptop or desktop and the network needs to go through the same rigorous security as a connection between the Internet and the intranet.
Reluctant To Quarantine
Security officers participating in the survey appear to agree with Khalaf. An overwhelming number of them -- 88 percent -- said that tighter user access to internal networks would improve overall security.
Ironically, while companies are leaning on local measures to thwart internal security problems, they are reluctant to take steps to strengthen those measures. A large portion of the survey's respondents -- 64 percent -- refuse to quarantine most devices on their systems that do not have the latest security patches from their software vendors.
Nevertheless, Khalaf noted that there's a growing awareness of the need to bolster the security layer between the firewall and the desktop, an awareness driven by factors like outsourcing.
Everyone on Same Page
He explained that many U.S.-based organizations have outsourced a lot of their functions outside the network. Those outsourcers often need access to resources inside the network, which has prompted companies to beef-up internal control.
Don Bowman, co-founder and chief architect of Sandvine in Waterloo, Ontario, Canada, explained that problems can occur with outsourcing when external partners haven't implemented the same security standards as the company hiring them.
"If you're expanding your border security to outside contractors, you should take steps to make sure that a contractor has the same level of diligence that you do," Bowman told TechNewsWorld. "You don't want a corrupt employee or an incompetent one exposing your data."
File Sharing Controversy Continues To Pack Heat June 21, 2005
The OECD report seeks to convince policymakers to take a measured approach to file sharing, but, lawyers note that the Supreme Court may make policy all by itself this week, if it rules broadly on the case of Grokster and MGM.
Related Stories
Combating ID Theft on the Internet June 18, 2005
Business analysts estimate that U.S. consumers lost US$2.4 billion from online fraud scams in 2003, with most fraud carried out by people obtaining access to account numbers and passwords. One major corporation reported receiving more than 1,400 phishing attacks in June 2004. Other surveys report that more than 57 million consumers think they received phishing e-mails last year.
Security with E-Mail: The Human Factor June 05, 2005
Prepare for the possible future disclosure of e-mail communication in a non-contextual atmosphere. In a 2004 study, 21 percent of employers reported that they had had employee e-mail and instant messages subpoenaed for a lawsuit or regulatory investigation. Be aware often e-mail is written in a type of "corporate shorthand."
Evil Twins a Menace to Wireless Security June 04, 2005
Once the wireless victim has connected to the illegitimate WiFi hotspot, the Evil Twin attacker can gain access to the user's log-on details, along with personal and confidential information that aids the attacker in identity theft and other illegal activities.
Related News Alerts
More by John P. Mello Jr.
FileMaker Pro Goes to 11 March 15, 2010
FileMaker has pushed out the 11th version of its Pro database product, and its new charting capabilities top the list of new features. Pie, bar and area charts can be created instantly and will change dynamically as the data underlying them changes. In addition, FileMaker 11 includes more than 30 "Start Solutions" that address the kind of real-world information needs for which business people buy a database.
Corel's X3 Photo Editor Paints a Pretty Picture March 11, 2010
Corel has packed its latest version of PaintShop Photo Pro, X3, with a boatload of new features, many of which are aimed at smoothing out the photographer's workflow. It's tied in a new batch processing feature as well as Express Lab, which gives photo editors the power of combined tools. There's also better support for RAW files and a bonus Painter Photo Essentials 4 app for adding an artistic flourish.
Aperture's Makeover Delights Photogs March 08, 2010
While Aperture's new features make it more attractive than ever to professional photographers, its main selling point appears to be its superior ability to automate a photographer's workflow. "For me, the most important thing about Aperture -- always has been and remains -- is that it is simply the most powerful archiving tool available," said photographer Bill Frakes.