Showing posts with label SIEM. Show all posts
Showing posts with label SIEM. Show all posts

Tuesday, April 7, 2015

Why You Need to Audit and Test Your Network

Security is a moving target. What’s acceptably secure today might not be tomorrow.

On the product side, even firewalls may have an undiscovered vulnerability lurking in the code. Recently announced vulnerabilities – such as HeartBleed, ShellShock and recent Windows fixes – were for things that had been sitting in the code for a decade or more and just hadn’t been found yet.

As discussed in last week’s post, threats on networks are intensifying, and your efforts to protect your business need to step up to that challenge.

Penetration Testing

To see how secure your network is, consider one of today’s security tests:

  • External: Attack from the outside and attempt to breach the network perimeter.
  • Internal: Attack from within to see what is possible if an intruder (or insider) got inside.
  • Social Engineering: Focus on whether your employees say or do something that could open a door to a breach.
  • Physical: Attempt to enter the premises under false pretenses and gain enough access to implant a remote access device, install software/malware or grab data without being detected.

Our CTG team regularly conducts either individual or a combination of security tests, working with our clients on the best approach to identify any vulnerabilities.

Monitoring, Detection and Incident Response

No matter how well you patch, secure and maintain your systems, ever-changing threats can thwart the best-laid plans and efforts. Putting your detection systems to work is just the first step.

Good detection without a solid incident response capability is nearly worthless. Just ask Target and Home Depot: These companies’ systems both detected breaches, buth their response protocols were not followed or were not fully tested.

An incident response plan mirrors many of the characteristics in disaster recovery planning:

  • Foresight to consider what can go wrong,
  • Written processes and procedures to avoid the “seat of pants” activities when it does,
  • Chain of command and reporting processes so management at all levels can remain informed and make appropriate business decisions. 
  • And practice, practice, practice.

Vulnerability Scanning

Vulnerability scanning is not a penetration test, however a penetration test includes vulnerability scanning. A vulnerability scan is an automated testing tool for basic probes and simulated attacks. With penetration testing, our highly skilled team uses our knowledge to attempt to bypass your security controls and gain access. An automated scanner can’t make tactical decisions based on responses.

That said, vulnerability scans are useful for helping to determine a device’s susceptibility to recently discovered exploits. For example, ShellShock and Heartbleed were long unknown vulnerabilities discovered in 2014. Vulnerability scanners were some of the first to release signatures and automated tests to help discover whether your systems included those risks.

Policy Audits

A policy audit often completes an Internal Penetration test. We’ll look at your written security policies (you do have written security policies, right?) and validate that they meet your targeted security posture and are implemented consistently.

Reporting and Remediation

Clients come to CTG to identify issues, and we complete each penetration testing and related analysis with comprehensive executive and technical briefings. We’ll tell you exactly what we uncovered, and, more importantly, we’ll offer specific recommendations on how to enhance your network security.

Jeff Garell is co-founder of Convergent Technologies Group.

Friday, March 27, 2015

Evolving Security Threats

Zero Day. Spear-Phishing. Heartbleed. ShellShock. These are a small handful of terms that would have once been limited to the lexicon of IT people. You’ve most likely heard these in evening news, but as the Internet has become more deeply ingrained into our everyday lives, the threats are getting closer to home.

Less than 15 years ago, having a good firewall, an anti-virus package on the desktop and some user education about clicking links in e-mails was enough to have a moderate expectation of safety. Those were the good old days.

Today, we face threats conducted by evolving and sophisticated attackers. Organized crime, nation states and politically motivated groups (hacktivists) have replaced the youngster in his parents’ basement and the uber-nerd whose code just got away from him. Attackers are now well funded, highly motivated and have access to unannounced exploits (a.k.a. Zero Day). In fact, there’s an entire market based on finding those vulnerabilities, writing the code to exploit it and selling the code for as much as six figures. It’s enough financial incentive to not tell the manufacturer about the vulnerability.

The Network Has Evolved 

The firewall – once the consummate guardian of our computer resources – has become just a single layer of a security program. Society and computing has become more mobile, with laptops, tablets, mobile phones, cloud services and “always-on” Internet access.

While these advances offer convenience and productivity, they also expand the threat vectors that your IT department must consider in its management, security and response plans.

Yes, Products Have Evolved 

The tech industry has evolved with a variety of product categories aimed at defending against threats. Vulnerability Scanners, Next-Gen Firewalls, Intrusion Detection/Prevention Appliances, and Security Information and Event Management (SIEM) are all built and updated to help a security team deal with potential threats.

But products alone are not the panacea. As Bruce Schneier said in 2000, “Security is a process, not a product.” Putting products in place and checking the box labeled “secure me” will not provide the protection you need. A repeatable process to deal with the alerts that these products generate is key to keeping your systems safe.

The 2013-14 Target breach is a perfect example: Alerts were generated about the breach, but the process to research and respond was not followed. As a result, personal data and millions of credit cards were stolen and sold.

Too Small to Be Targeted 

“Too small to be targeted” and “no one would want our data” are a couple of the misconceptions we often hear.

Smaller companies offer easy targets with computers, storage, bandwidth and little-to-no auditing. They also make great reflector points to directly attack the real targets.

Beside the annoyance and possible public embarrassment of being part of an attack, if your systems are part of a large enough attack, you could find your equipment and data confiscated as evidence in an official investigation.

But there are steps you can take now to ensure the security of your IT systems, and we’ll look at those in a follow-up blog post next week.

Jeff Garell is co-founder of Convergent Technologies Group