Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Defending the Core

    Written by

    Dennis Fisher
    Published March 1, 2004
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      After a decade of focusing nearly exclusively on defending the perimeter, security vendors have begun to divert more of their attention to the last frontier of digital security: the soft, chewy center of corporate networks.

      The problem for these vendors isnt so much about keeping attackers out; they leave that to the firewall and IDS (intrusion detection system) crowd. Instead, a growing number of software and hardware vendors, including Sanctum Inc., Kavado Inc., Application Security Inc. and Intrusic Inc., are concerned with limiting the damage caused by intruders who slip past those other defenses.

      The ways that these companies approach the problem vary widely, and two good examples of this diversity are the solutions unveiled last week at the RSA Conference by Intrusic and Application Security.

      Intrusic took the wraps off its Zephon system, which is designed to pick up where todays existing security technologies leave off. The solution does not attempt to detect or block scans, attacks or intrusions. Instead, it combs networks for evidence of successful compromises and then provides detailed statistics and recommendations on how to remediate the problems. The idea is to eradicate the actual problem, not just its symptoms.

      “Because were doing compromise detection, we can stop things completely rather than doing one-off fixes,” said Bruce Linton, CEO of Intrusic. “If somebodys already inside the network, whats their driver to do more attacks? There isnt one, so you probably wouldnt see them with normal security products once theyre in.”

      Intrusic, based in Waltham, Mass., is the brainchild of Justin and Jonathan Bingham. But the man drawing attention to the company is Mudge, also known as Peiter Zatko, one of the original members of L0pht and @Stake Inc. Mudge left @Stake two years ago and has since been semiretired. Hes now Intrusics chief scientist.

      The companys solution sits on a network tap in passive mode and records every packet that moves between users and the various hosts on the network. At the beginning of its operation, the system takes a snapshot of the network to establish its current security state. Zephon copies all the packets and analyzes the traffic in three distinct phases. It first examines the packet, searching for signs of an internal compromise. The system then looks at the traffic on the session level and, finally, on the hot level, with each inspection performed independently of the others. Any data showing evidence of a compromise is moved to the Master Confidence Table, a database where a second analysis is done.

      All positively identified compromises then end up in the GUI, where administrators can see statistics showing the total number of compromised hosts, total compromises and other vital data.

      Zephon has three levels of reports, from executive overviews to detailed, host-level descriptions for administrators. But its meant to be simple enough for users with no security background.

      Application Security, based in New York, introduced a new version of its AppDetective software, which performs continuous risk assessment of a network. The solution includes collectors on hosts throughout a network that vacuum up data from perimeter devices such as firewalls, routers and IDSes. The collectors send that information to the main AppDetective server, which develops a model of the network and performs attack simulations against internal hosts to find exploitable weak spots.

      The results of the attacks then go to the user interface.

      In addition, the company just released a solution, called AppRadar, which acts as a kind of internal IDS to protect databases. The system is capable of detecting the most common attacks against databases, including buffer overruns, password attacks and privilege escalation attempts.

      Meanwhile, Application Security and Kavado, along with Sanctum, SPI Dynamics Inc. and WhiteHat Security Inc., have formed a consortium to help define and promote application security standards.

      The groups initial goal is to create a classification system for application security vulnerabilities, attacks and other threats. Many of the attacks that are used against Web applications are quite complex, and much of the terminology is outside the realm of most security specialists expertise. The group hopes to simplify the explanation of things such as cross-site scripting.

      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×