Who Is Guarding Your Assets?

author-image
DQC News Bureau
New Update

Who represents the greater risk to your customer's business-a disgruntled
employee attempting to leak information to the outside world, or an external
hacker seeking to penetrate his network and steal corporate information? That is
a tricky question.

Advertisment

These days, no one wants to be exposed to either type of threat. “Many
businesses spent the 1990s building digital walls that stopped questionable
outsiders from getting in. But somewhere along the way, they forgot to stop
information from leaking from the inside out,” said Ed Golod, President, Revenue
Accelerators, a technology-consulting firm in New York.

Now that is about to change. In their quest to comply with Sarbanes-Oxley,
HIPAA and other privacy regulations, businesses must now focus on comprehensive
inbound and outbound data protection.

A tall challenge

For many chief information officers (CIOs) and also solution providers (SPs)
of enterprises, espe­cially those that are SMB, that is a tall challenge. Fact
is many IT security vendors provide point products that only address one
component of security-ie protection from inbound threats. More recently, some
security companies have focused on point products that halt certain forms of
outbound information leakage.

Advertisment

Paul A Henry

Rather than cobbling toge­ther these point products, CIOs and SPs need
comprehensive solutions that provide total inbound and outbound protec­tion. For
inbound protection, the solution has to safeguard enterprises from viruses,
trojans, spam and would-be intruders. For outbound protection, businesses need
solutions that stop sensitive data, intellectual property and liable content
from 'leaking' onto the Internet.

This commitment to inbound and outbound protec­tion is part of a broader
dimensional security strategy. Unfortunately, many point security products
either fall short on capabilities or completely miss the intend marks. It is as
if these point products were designed in a vacuum with only one or two features
in mind, rather than an entire suite of required services.

Modern day solutions

The messaging security gateway neutralizes inbound threats such as spam,
viruses and hacker attacks, and protects the business house from data leaks. A
company's network security gateway protects against known and unknown
threats-offering anti-virus and anti-spy ware capabilities plus traffic anomaly
detection, protection from zero-day threats and IDS/IPS challenges.

Advertisment

To understand these modern-day solutions, you have to understand the
evolution of computer security products. First, there were signature-based
security products like anti-virus software that protected networks from known
threats. It is similar to an FBI watch list, where airport security guards are
on the lookout for known criminals. But that is a reactive approach and does not
protect against new or unknown threats.

Next came behavior-based systems. These second-gene­ration products look for
strange or unanticipated behavior and can create false-positives. The result:
You wind up shooting some legitimate traffic dead in its tracks.

First and second-generation products remain important. But they need to be
complimented by a third-generation solution known as an Internet reputation
system. The reputation system relies on a global database of information.

Advertisment

Third-generation security

The third-generation reputation solution should also determine who could be
trusted-and who cannot-using comprehensive data culled from the Internet. The
system should pinpoint an IP address, domain, URL, Internet entity or sender
reputation based on their domain, IP address and what they are doing in
real-time.

The reputation-based solution starts with signature-based information for
anti-virus, IDS and anti-spam capabilities (much like a police officer placing
an identity band on known criminals). Next, the system checks the user's local
behavior, similar to how intelligence agents look for suspicious behavior in
airports. Finally, the system generates a reputation score, similar to how
intelligence agents around the world use a global database to track criminals
and share their background information with other trusted investigators.

With a third-generation reputation system in place, external hackers,
spammers, phishers and other attackers/attacks are halted in their tracks-often
well before they connect to a company's network. This is beyond proac­tive or
zero-day protection. It is a truly advanced protection, so perhaps the term
'sub-zero' works best.

Advertisment

Lingering challenges

Despite these advancements, many businesses continue to leverage point
products rather than comprehensive inbound and outbound security solutions. At
the same time, many businesses have yet to effectively address outbound security
risks.

In recent months, numerous companies have accidentally transmitted financial
infor­mation, R&D data and compe­titive reports to external sources. In some
cases, the accidental information leaks have influenced financial markets or
violated privacy regulations.

For every information leak reported by the media, there are surely dozens
more that go completely unnoticed. Fortu­nately, comprehensive inbound and
outbound security measures can mitigate such risks.

Advertisment

The author is VP-Technology Evangelism, Secure Computing Corporation