My computer did not show any network connection after I installed my computer with all 9 security patches. After some search, MS also noticed this problem and the update is below. http://support.microsoft.com/?kbid=909444 This experience prompt me for 2 issues (one technical , one management) 1. MS recommend one setting "Everyone group should have Bypass Traverse Checking permission". But this violated the default server built standard at some companies. The servers before put into production was hardened and this permission was changed to Domain User or Authenticated User. Should we ask ourselves "Are we doing too much security hardening?" or "Why Everyone is need this permission?" 2. While it took 5 days for malicious hacker to publish exploit code, MS took 4 days to resolve their buggy patch. How IT admin is going to manage their internet facing server if running MS IIS ? Patch too soon, we are at risk of MS bug. Patch too late, we are at risk of exploi...
There is a few paper on the net discuss how to divert and mitigate the damages caused by network attacks, in particular DDOS. Both papers describe a means to create a “black hole” on the network. One is on the network layer and one is on the web server layer Cisco Black Hole Filtering Cisco's paper explain a specifically built infrastructure can help ISP to route malicious packets to a null interface(blackhole filtering). Microsoft Beat Hackers At Their Own Game With A Hackerbasher Site Utilizing the principle that all vistors must know my name. This method divert incoming traffic using IP address not hostname. These papers give a good illustration that security can be achieved by thoughtful design. All the tools and technology is available to everyone or what they call built-in. By good designing, we increase the effectiveness of our security investment.
Yesterday, PISA invited security experts to have a discussion forum and share the challenges in management IT security. 3 keynotes speakers are coming from banking, telecom and public organization respectively. Below are the key points of the 2 hours discussions: Both banking and telecom are highly regulated industries. IT security planning and management are driven by regulators. And both security managers in these industries believe more regulation will come!! Be prepared. But WHY the regulator wants more regulations? (An interesting question although knowing the answer will not stop them) IT security managers sometimes need to educate business manager about risk and sometimes need to control them. It is a delicate relationship. In other word, IT security manager need to control our customer. The following were shared: One organization has a security steering committee and it is a collective decision on whether to implement a control. Security manager’s role is to advice and advocate...
Comments