Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 1 December 2009

A Good Samaritan

Posted on 10:14 by Unknown

by Calum Macleod, Regional Manager for Tufin Techologies

It happens in a moment – playing with my mobile before going into a meeting; I put it down for a moment and suddenly my host is standing in front of me. Two hours later I’m desperately searching for my phone. Rush back to reception but it’s not there.

Here I am in Dubai and my phone is gone! I need to call my provider to block it but the provider’s number is in the phone. I have visions of my wife calling and suddenly panicking that the Somali pirates have got me – like the time I forgot to call from Dublin and she’s waiting for the ransom demand – still living that one down but that’s what happens when you go on a business trip to Dublin the week before Christmas!

My host comes up with all kinds of useful suggestions about who I should call but since my whole life is in that stupid thing I can’t remember any numbers. All my contacts, email addresses – like I said my life is in that stupid thing!

All it takes is a small distraction and before you know it you’ve disconnected your business critical applications. One small change on the firewall or the router and suddenly you’re users are disconnected. If you’re a service provider just imagine the revenue loss! If you’re an airline taking online bookings, or a bank, or any kind of business suddenly you are losing money and/or customers just because of a momentary distraction.

And like my phone, recovering the situation is not necessarily that simple. Logically I could say that my phone was somewhere, but where the somewhere is, is the other question. You would think that if one of your admins made a simple change to a firewall or a router you could just immediately reverse the process, but in reality it is often like looking for a needle in a haystack. Some organizations have hundreds or thousands of rules in their configurations and they are being changed and modified constantly. Maybe even worse they are being changed at weekends when everything is quiet and then the proverbial hits the fan on Monday morning!

Maybe you didn’t change anything, you only upgraded to the newest release from your supplier. Only to discover that there are problems because the new release has different defaults to the old release. So how do you now validate your baseline configuration against all the devices that have been upgraded?

And of course someone is always looking to place the blame! I have to say my initial suspicion was that my telephone was in the “careful keeping” of one of the guys at the security desk. Frequently I hear network and security administrators complaining that as soon as something doesn’t work the firewall guys are always the first to be accused. Network connectivity problems are some of the most common – and aggravating – for business users. With distributed systems, as soon as an application does not behave as expected, the firewall is suspect.There are many other possible points of failure – the client application, the user’sPC,intermediate switches, routers,filters, load balancers and the application itself. But, because of its nature (secretive and designed to keep people out) the firewall is a prime suspect. As a firewall administrator, you are guilty until proven innocent – like my thoughts about the guys at security.

You can of course take the usual approach to “solving the crime”. Start to analyze the firewall traffic logs. Contact the user, obtain his IP address and ask him to access the application again. Ideally, this should trigger the connection in question. Then you can review the firewall traffic logs and locate the droppedor accepted packets. How easy this is depends on the tools – unless you have a smart log browser, you may have to work with syslogs. Normally there will be a lot of logs so a filter on the source IP and, if possible, on the destination IP or port will make things easier. But this costs time, money, and above all the user with the problem is not always totally rational in the situation – just ask the guy who was trying to help “this user” find his mobile!

Using a Policy Analysis tool is like having a video of what is actually going on. It simply allows you to create a policyanalysis query and you will see exactly where the problem is. Policy Analysis will quickly determine whether the firewalls are allowing the user’s traffic or not. If it turns out that the firewall is, in fact, blocking traffic, Policy Analysis will point you to the rule that’s causing the problem as well as when it was last changed, and by whom. In fact if there was an equivalent “Lost Phone Analysis Tool” I would have been able to identify exactly who found the phone and where they were at that exact moment.

Providing network security for any organization has become an extremely complex operation involving many infrastructural components and security teams around the world. Regardless of how experienced someone might be it is impossible for them to be constantly up to date on what is going on. At the same time, organizations must comply with rigorous standards of transparency and accountability. Planning, implementing, enforcing and auditing organizational security policies are now business-critical.

Sometimes you happen to be in the right place at the right time and you get lucky. For example if you’re ever going to lose your mobile I highly recommend Dubai as the place to do it. It’s not everywhere that someone picks up a 16Gb iPhone, calls the last number dialed, drives 50 Km in heavy traffic, and then waits 45 minutes for someone to pick it up. And he didn’t even give his name – and my wife never knew!

You just might be lucky and spot the problem on your firewall immediately but the chances of doing so are about as slim as being in Dubai when you lose your mobile!

www.tufin.com

<>

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • DDoS-Attacks disable many shopping websites, including Amazon
    Just in time for last minute Christmas shopping major shopping sites disabled by Michael Smith (Veshengro) London, December 26, 2009: An...
  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • Cyber-Ark Expands RSA Secured Partner Program Certification Status
    Cyber-Ark Privileged Identity Management Suite, Inter-Business Vault and Sensitive Document Vault Now Formally Interoperable with RSA enVisi...
  • Infosecurity Adviser applauds forensics lab training facilities at key UK university
    London, UK. May 2009: Infosecurity Adviser, Infosecurity Europe’s online community for the information security industry, has published a r...
  • Scientific company discusses simultaneously protecting applications and data
    Simultaneously protecting applications and data: The next evolution in security? September 2009 (Eskenzi PR) – In a recent Imperva podcast...
  • TUFIN TECHNOLOGIES WINS the PRESTIGIOUS 2010 Computing Security Award for ‘Best bench tested solution of the Year’
    Network Computing and Computing Security Magazine Editors Select Tufin’s SecureChange Workflow as the Top Product Reviewed in 2010 Londo...
  • Brocade Service Could Help Reduce Billions in Data Centre Operations Costs
    New Energy Efficiency Review provides holistic assessment and remedial strategies to help companies optimise efficiency and reduce costs Ene...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • Tufin survey reveals the truth about fudging audits, IT cost cutting and buying equipment online
    Ramat Gan, Israel – May 27, 2009 – Tufin Technologies today announced the results of its “Reality Bytes” security survey. The survey parti...
  • ISACA’s EuroCACS Conference Demystifies the Cloud
    Event for IT Professionals Will Take Place 20-23 March, Manchester London, England, (8 th March 2011)— Global business and information ...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ►  2012 (1)
    • ►  January (1)
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ►  2010 (192)
    • ►  December (20)
    • ►  November (22)
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ►  June (22)
    • ►  May (13)
    • ►  April (11)
    • ►  March (13)
    • ►  February (27)
    • ►  January (27)
  • ▼  2009 (240)
    • ▼  December (25)
      • MBNA laptop fiasco could easily have been avoided
      • Networking technology set for growth
      • DDoS-Attacks disable many shopping websites, inclu...
      • Fortify Software Launches Hosted Software Security...
      • Launchpad Europe welcomes EITO predictions for ICT...
      • ISACA Launches Risk IT to Help Organizations Balan...
      • Parkeon Chooses Fortify Software To Keep Hackers A...
      • BridgeHead Software refutes suggestion that hospit...
      • Industrialisation of Hacking Will Dominate 2010
      • Mobile data problems? Switch to an encrypted hard ...
      • Hackers Claus havoc at Xmas – shows study!
      • Christmas shopping period worst time for leaving m...
      • Infosecurity Europe 2010 Hall of Fame nominations ...
      • 'EastEnders' laptop theft highlights failure to en...
      • Cloud vs conventional storage and computing in gen...
      • USBs : An Employees Dream- IT’s Worst Nightmare
      • A third of workers will Steal Data to help a frien...
      • VIRGIN MEDIA PARTNERS WITH TUFIN TECHNOLOGIES AND ...
      • DeviceLock now thwarts data leakage via iPhone and...
      • Novatel MiFi™ 2352 Intelligent Mobile Hotspot – Pr...
      • Bell introduces the award winning Novatel Wireless...
      • Recent issues with Skype shutting down
      • Royal Borough of Kensington & Chelsea Leverages Fa...
      • Serial train laptop thefts highlight need for encr...
      • A Good Samaritan
    • ►  November (9)
    • ►  October (21)
    • ►  September (19)
    • ►  August (30)
    • ►  July (35)
    • ►  June (30)
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile