November, 2009

Page 1 of 512345

Diffused Cybersecurity Responsibilities

In the cybersecurity realm, a number of professionals have advocated for a centralized approach. The U.S. military has stood up a Cyber Command to coordinate cybersecurity for the DoD and DHS has gained the lead role in securing civilian government networks. Yet, one expert questions this highly centralized approach to cybersecurity.

In a recent interview with Nextgov, Mischel Kwon, former head of USCERT and currently serving as VP…

Tagged with:         

Experts Question Perimeter Defense

In a recent article for Science magazine, William Wulf and Anita Jones, both computer science professors at University of Virginia, questioned the effectiveness of the perimeter defense model currently used in most cyber security models. The two professors questioned the method for a number of reasons, including the insider threat, fragility and that it has not worked in the past.

Instead of the perimeter defense, Wulf and Jones…

Tagged with:   

Good Cyber Hygiene for Cyber Monday

The business community has termed today, ‘Cyber Monday,’ as a number of sales have now gone online.  While more people are using the internet to purchase gifts during the holiday season, they would do well to keep in mind some good tips for keeping their data secure in cyberspace.

Shoppers should be particularly wary of phishing scams and ensure that they use established contact points to contact any businesses. Scammers…

ICANN Raises Issues with DNS Redirect

The International Corporation for Assigned Names and Numbers (ICANN) has denounced the use of domain name system redirect requests. ICANN raised significant questions about its exploitation by cyber criminals and privacy issues.

According to an article by ComputerWorld, the DNS redirect system operates as follows: “Rather than return an error message for DNS (Domain Name System) requests for nonexistent domains, some DNS operators send back the…

Tagged with:

Beware of the Insider Threat

A significant percentage of employees would be willing to steal data from their company, according to a recent survey conducted by Cyber-Ark.

More than 40 percent of respondents have already stolen information and brought it to a new company.

The survey found employees are feeling less loyal to their present employer, and as a result, appear more willing to purloin data if they believe it will benefit them. The…

Tagged with:

Incident Highlights Supply Chain Management Issues

One of the central worries for cyber security professionals is the issue of supply chain management, namely ensuring that hardware and software produced abroad is not pre-infected with added features to allow future access by a foreign power. This issue was highlighted recently when a California man plead guilty to charges that he sold counterfeit computer chips to the US Navy.

From 2007 to 2009, the man, along…

Chinese Respond to Allegations

Late last week, the U.S.-China Economic and Security Review Commission informed Congress in its annual report of the increasing number of cyber incidents by the Chinese against U.S. systems and networks.

Yesterday, the Chinese Foreign Ministry took the opportunity to respond to the allegations, claiming bias and incorrect reporting by the Commission.

Qin Gang, the Foreign Ministry spokesman, said on their website, “This report disregards the facts,…

Tagged with:   

Another Reason Not to Jailbreak Your iPhone

According to recent media reports, iPhones that have been illegally altered (know as Jailbreaking) are being targeted by malware. The malware then links the jailbroken iPhone into a mobile botnet, believed to be the first of its kind.

The worm, uncovered by security firm Intego, scans local networks for jailbroken iPhones and then copies itself onto the iPhone, adding the device to a growing mobile botnet. The worm…

Tagged with:     

Australian Cybersecurity Strategy

The Australian government has joined in moving forward cybersecurity, with a new Cyber Security Initiative.

The initiative contains several key goals, including education and awareness for individual citizens, securing government systems and securing private-sector infrastructures.

The Australian Attorney General’s office is the lead organization for cybersecurity issues in Australia. The strategy was put forth Nov. 23, 2009 and provides a definition of cybersecurity along with the goal…

Tagged with:   

How Secure is Cloud Computing?

With the recent movement towards a cloud computing model, many senior leaders and IT professionals are wondering just how secure the cloud is. The European Network and Information Security Agency recently published a report that seeks to provide a model of deciding if cloud computing meets the security an organization requires.

The report concludes that the flexibility and economies of scale available in cloud computing are good and…

Page 1 of 512345