<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CoreTrace WhiteSpace&#187; CoreTrace WhiteSpace</title>
	<atom:link href="http://www.coretraceblogs.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.coretraceblogs.com</link>
	<description>The Application Whitelisting and Security Weblog</description>
	<lastBuildDate>Thu, 18 Mar 2010 19:57:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Cyber attacks top terrorism as biggest concern for Indian companies</title>
		<link>http://www.coretraceblogs.com/2010-03/cyber-attacks-top-terrorism-as-biggest-concern-for-indian-companies/</link>
		<comments>http://www.coretraceblogs.com/2010-03/cyber-attacks-top-terrorism-as-biggest-concern-for-indian-companies/#comments</comments>
		<pubDate>Thu, 18 Mar 2010 18:04:12 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[enterprise security]]></category>
		<category><![CDATA[social networks]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1408</guid>
		<description><![CDATA[Escalating revenue losses from cyber crimes and understaffed network security teams have Indian companies more concerned about cyber attacks than terrorism.
In the article, &#8220;Cyber attacks worry firms more than terrorism,&#8221; the &#8220;2010 State of Enterprise Security Study&#8221; conducted by Symantec Software Solutions Pvt. Ltd. found that 42% of companies representing industries such as telecom, hospitality, [...]]]></description>
			<content:encoded><![CDATA[<p>Escalating revenue losses from cyber crimes and understaffed network security teams have Indian companies more concerned about cyber attacks than terrorism.</p>
<p>In the article, <a href="http://newshyderabad.wordpress.com/2010/03/13/cyber-attacks-worry-firms-more-than-terrorism/">&#8220;Cyber attacks worry firms more than terrorism,&#8221;</a> the &#8220;2010 State of Enterprise Security Study&#8221; conducted by Symantec Software Solutions Pvt. Ltd. found that 42% of companies representing industries such as telecom, hospitality, manufacturing, retail and technology perceive cyber attacks as the biggest threat to their enterprises.</p>
<p>One reason cited was the lack of adequate network security. Over the past year, 66% of companies surveyed said they had experienced cyber intrusions while 51% reported repeated attacks. The study also pointed out that deployment of enterprise security has turned into a difficult task for many organizations. Said Vishal Dhupar, managing director at Symantec:</p>
<blockquote>
<p>&#8220;Enterprise security is understaffed and the most affected areas in organizations are network security, web security and data-loss prevention. To tackle the issue, companies need to secure their messaging and web environments and defending critical internal servers. They should also have the ability to back up and recover data and respond to threats rapidly.</p>
</blockquote>
<p>With the rise in malicious attacks targeting sectors that can have a significant impact on India’s economy, one has to wonder if cyber attacks and terrorism weren&#8217;t one in the same. As I mentioned in a recent blog, <a href="http://www.coretraceblogs.com/2010-03/are-we-in-a-cyberwar-or-not/">&#8220;Are we in a cyberwar or not?&#8221;</a> cyber threats continue to have a growing impact on our nation&#8217;s economy and global competitiveness. Although U.S. Cyber Czar, Howard Schmidt, may not think we are engaged in cyber warfare, the impacts from targeted attacks are being felt everywhere, and are top IT concerns for many organizations and nations around the world.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-03/cyber-attacks-top-terrorism-as-biggest-concern-for-indian-companies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NSS test demonstrates 86% anti-virus fails to protect against Operation Aurora variants</title>
		<link>http://www.coretraceblogs.com/2010-03/nss-test-demonstrates-86-anti-virus-fails-to-protect-against-operation-aurora-variants/</link>
		<comments>http://www.coretraceblogs.com/2010-03/nss-test-demonstrates-86-anti-virus-fails-to-protect-against-operation-aurora-variants/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 07:22:51 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[rational transition to whitelisting]]></category>
		<category><![CDATA[antivirus software]]></category>
		<category><![CDATA[AV software]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware variants]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1377</guid>
		<description><![CDATA[A recent study by NSS Labs revealed just how ineffective some of today&#8217;s top anti-virus software solutions are at stopping one of the most highly profiled and successful cyber attacks of 2010. According to the article, &#8220;More Anti-Virus Fail,&#8221; NSS Labs created variants of the Operation Aurora attack to see how many AV products caught [...]]]></description>
			<content:encoded><![CDATA[<p>A recent study by NSS Labs revealed just how ineffective some of today&#8217;s top anti-virus software solutions are at stopping one of the most highly profiled and successful cyber attacks of 2010. According to the article, <a href="http://www.informationweek.com/blog/main/archives/2010/03/more_antivirus.html;jsessionid=54UXHSZ5K3DPBQE1GHRSKH4ATMY32JVN">&#8220;More Anti-Virus Fail,&#8221;</a> NSS Labs created variants of the Operation Aurora attack to see how many AV products caught the malicious code. The result: Only one out of the seven products tested correctly thwarted multiple exploits and malicious code payloads.</p>
</p>
<p>This says a lot about the current state of the AV industry. With so many new viruses and malware variants successfully bypassing security solutions, it is time to shift our way of thinking about how to protect our networks from new and unknown forms of malware and viruses.</p>
<p>With <a href="http://www.v3.co.uk/v3/news/2259467/fbi-reports-online-crime-losses">online crime losses doubling in 2009</a>, we simply can&#8217;t afford to rely solely on AV software to protect our critical infrastructures from the countless number of malware variants out there. If these solutions are already losing the battle against highly visible malware, I can’t imagine the success rate of stopping unknown attacks would be any better.</p>
<p>As an example of how the industry currently looks at these problems, NSS Labs&#8217; CTO, Vikram Phatak, said: <em>&#8220;There are many ways to possibly exploit a vulnerability, and rather than focusing on every attack method, vendors need to focus on [shielding] the vulnerability itself.&#8221;</em></p>
<p>Vikram is correct in pointing out that you can&#8217;t defend against every attack method, but focusing on protecting against exploitation of the vulnerability is reactive, and a failure as well. This still leaves companies open to newly discovered vulnerabilities, relies on reactive patching and security system updates, and will ultimately fall on its face. We need to completely rethink our approach to endpoint security that begins with a foundation of whitelisting that would defeat new malware completely independently of the vulnerability or attack.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-03/nss-test-demonstrates-86-anti-virus-fails-to-protect-against-operation-aurora-variants/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are we in a cyberwar or not?</title>
		<link>http://www.coretraceblogs.com/2010-03/are-we-in-a-cyberwar-or-not/</link>
		<comments>http://www.coretraceblogs.com/2010-03/are-we-in-a-cyberwar-or-not/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 17:16:29 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber czar]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyberwar]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1358</guid>
		<description><![CDATA[I continue to hear various viewpoints about whether or not we are in a cyberwar. Recently, our friend, Howard Schmidt was quoted in the article, &#8220;White House Cyber Czar: &#8216;We are not in a cyberwar&#8217;,&#8221; that we are not in a cyberwar. His stance is cyberwar is &#8220;a terrible metaphor&#8221; where there are no winners. [...]]]></description>
			<content:encoded><![CDATA[<p>I continue to hear various viewpoints about whether or not we are in a cyberwar. Recently, our friend, Howard Schmidt was quoted in the article, <a href="http://www.wired.com/threatlevel/2010/03/schmidt-cyberwar/">&#8220;White House Cyber Czar: &#8216;We are not in a cyberwar&#8217;,&#8221;</a> that we are not in a cyberwar. His stance is cyberwar is &#8220;a terrible metaphor&#8221; where there are no winners. While I can certainly respect that, there are also a number of opposing views and supporting statistics that say otherwise.</p>
<p>One comes from the former director of national intelligence, Michael McConnell, who recently testified in Congress by saying the country is already in the midst of a cyberwar &#8212; and losing it at that. This comes on the heels of growing speculation from experts that say the Chinese government was behind the recent cyberattacks targeting U.S. government Web sites, Google, and dozens of other U.S. companies. This, of course, raises the question: &#8220;If we aren’t already in a cyberwar, are we headed toward one?&#8221;</p>
<p>Larry Wortzel, a member of the U.S.-China Economic and Security Review Commission, said in the article, <a href="http://www.infoworld.com/d/security-central/expert-says-chinese-government-likely-behind-massive-cyberattacks-258?source=rss_infoworld_news">&#8220;Expert says Chinese government likely behind massive cyberattacks,&#8221;</a> that whether the Chinese government or independent hackers in China were responsible for the recent attacks, we are seeing &#8220;persistent, systematic and sophisticated attacks&#8221; that are clearly targeting U.S. military, technical and scientific information. Similar trends released at RSA Conference and reported in the story, <a href="http://www.pcworld.com/article/190963/chinese_hack_attacks_said_likely_to_recur.html">&#8220;Chinese hacks attacks said likely to recur,&#8221;</a> said an increase in Internet attacks from China could double if the pace during the first two months of 2010 continues.</p>
<p>People often ask me, given my military background and experience fighting cyber crime, are we in a cyberwar or not? To me, whether or not we are is irrelevant. What defines cyber warfare? What&#8217;s important is that we are aware of what is going on and our government and the private sector are doing everything they can to ensure our cyber security. I commended President Obama last October when he said that cyber threats were one of the most serious economic and national security challenges we face as a nation. The fact is, cyber crime has already cost U.S. companies billions of dollars. If these trends aren&#8217;t stopped, cyber crime will continue to have a growing impact on both our economy and global competitiveness.</p>
</p>
<p>Ensuring our cyber security comes down to one thing &#8212; preparedness. The more we understand, and the more proactive steps the government and private sector take independently and collectively, are vital to defending our networks, national assets and critical infrastructures from any type of attack, whether we are in a cyberwar or not.</p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-03/are-we-in-a-cyberwar-or-not/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>New exploit technique could mean more Microsoft headaches</title>
		<link>http://www.coretraceblogs.com/2010-03/new-exploit-technique-could-mean-more-microsoft-headaches/</link>
		<comments>http://www.coretraceblogs.com/2010-03/new-exploit-technique-could-mean-more-microsoft-headaches/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 18:42:02 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[whitelisting]]></category>
		<category><![CDATA[application whitelisting]]></category>
		<category><![CDATA[data compromise]]></category>
		<category><![CDATA[exploit technique]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[security enhancement]]></category>
		<category><![CDATA[security software]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1337</guid>
		<description><![CDATA[Last week, a new exploit technique was disclosed that bypasses a critical Windows security feature, DEP (data execution prevention), as well as an ASLR security enhancement for address space layout randomization.
In the article, &#8220;New exploit technique nullifies major Windows defense,&#8221; some researchers worry that a proof-of-concept code published by Google security software engineer, Berend-Jan Wever, [...]]]></description>
			<content:encoded><![CDATA[<p>Last week, a new exploit technique was disclosed that bypasses a critical Windows security feature, <a href="http://en.wikipedia.org/wiki/Data_Execution_Prevention" target="_blank">DEP</a> (data execution prevention), as well as an ASLR security enhancement for address space layout randomization.</p>
<p>In the article, <a href="http://www.computerworld.com/s/article/9165378/New_exploit_technique_nullifies_major_Windows_defense?taxonomyId=17&#038;pageNumber=2" target="_blank">&#8220;New exploit technique nullifies major Windows defense,&#8221;</a> some researchers worry that a proof-of-concept code published by Google security software engineer, Berend-Jan Wever, could actually lead to more successful attacks against Microsoft&#8217;s newer operating systems.</p>
<p>While Wever claims the proof-of-concept doesn&#8217;t do any harm because it&#8217;s wrapped around an exploit of a bug in Internet Explorer 6 (IE6) that was patched years ago, MicroTrend&#8217;s Ria Rivera wrote in the company&#8217;s malware blog that the exposure could be used to further enhance exploits, and expects to see it used within exploits soon.</p>
<blockquote>
<p>&#8220;After Wever released his <a href="http://en.wikipedia.org/wiki/Heap_spraying" target="_blank">heap-spraying</a> exploit codes in 2005, a lot of new exploits started using that technique. It would thus be not far-fetched that the release of this new proof-of-concept could lead to the same scenario &#8212; new exploits could start using &#8216;return-to-libc&#8217; to achieve DEP bypass.&#8221;</p>
</blockquote>
<p>With so many data compromises arising from the latest disclosed vulnerability it seems so clear that now is the time to completely re-evaluate the way we approach desktop security. Vulnerabilities lose their power when you address the core issue of controlling what applications are allowed to run on your system in the first place whether these applications were added by a user or by malicious code exploiting a security hole.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-03/new-exploit-technique-could-mean-more-microsoft-headaches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Observations from RSA &#8211; 100% compliant does not mean 100% secure</title>
		<link>http://www.coretraceblogs.com/2010-03/observations-from-rsa-100-compliant-does-not-mean-100-secure/</link>
		<comments>http://www.coretraceblogs.com/2010-03/observations-from-rsa-100-compliant-does-not-mean-100-secure/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 21:08:58 +0000</pubDate>
		<dc:creator>Dan Teal</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[application whitelisting]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[security compliance]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1334</guid>
		<description><![CDATA[Yesterday, I sat in the RSA panel titled, &#8220;Cyber Security: An Arms Race.&#8221; It was an interesting panel because, of course, cyber security is an arms race. One of the recurring comments from the audience was centered around, &#8220;Who should be responsible for defending our networks?&#8221; This is a question that has been debated for [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday, I sat in the RSA panel titled, &#8220;Cyber Security: An Arms Race.&#8221; It was an interesting panel because, of course, cyber security is an arms race. One of the recurring comments from the audience was centered around, &#8220;Who should be responsible for defending our networks?&#8221; This is a question that has been debated for some time now. The answer kept leading back to government and compliance. However, members of the audience did not realize that one of the fundamental axioms of computer security is: Compliance does not mean secure.</p>
<p>We are familiar with the above statement. We all know that security compliance may increase security, but not completely provide it. A great example of this occurred in the fall of 2008 within the DOD. Systems running in the DOD networks were compliant with FIPS 140-2, common criteria, and other standards. The systems and networks were operated by a staff of trained professionals. But even with all of the compliant security measures in place, Conficker still propagated throughout the DOD networks causing over $100 million in cleanup costs.</p>
<p>A similar problem occurred at Heartland Payment Systems. Even though Heartland was fully PCI compliant, hackers still stole information on the 100 million credit card transactions that are processed each month.</p>
<p>Compliance is important, but we must remember that compliance standards may take years to create and are never updated fast enough to stay current with today&#8217;s threats. Organizations must protect against the threats of the past by being compliant. They must also defend against the threats of today by being proactive.  Application whitelisting is the proactive solution against today&#8217;s threats and must become the cornerstone of any security strategy.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-03/observations-from-rsa-100-compliant-does-not-mean-100-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
