<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CoreTrace WhiteSpace&#187; CoreTrace WhiteSpace</title>
	<atom:link href="http://www.coretraceblogs.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.coretraceblogs.com</link>
	<description>The Application Whitelisting and Security Weblog</description>
	<lastBuildDate>Thu, 11 Mar 2010 20:36:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Are we in a cyberwar or not?</title>
		<link>http://www.coretraceblogs.com/2010-03/are-we-in-a-cyberwar-or-not/</link>
		<comments>http://www.coretraceblogs.com/2010-03/are-we-in-a-cyberwar-or-not/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 17:16:29 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber czar]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyberwar]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1358</guid>
		<description><![CDATA[I continue to hear various viewpoints about whether or not we are in a cyberwar. Recently, our friend, Howard Schmidt was quoted in the article, &#8220;White House Cyber Czar: &#8216;We are not in a cyberwar&#8217;,&#8221; that we are not in a cyberwar. His stance is cyberwar is &#8220;a terrible metaphor&#8221; where there are no winners. [...]]]></description>
			<content:encoded><![CDATA[<p>I continue to hear various viewpoints about whether or not we are in a cyberwar. Recently, our friend, Howard Schmidt was quoted in the article, <a href="http://www.wired.com/threatlevel/2010/03/schmidt-cyberwar/">&#8220;White House Cyber Czar: &#8216;We are not in a cyberwar&#8217;,&#8221;</a> that we are not in a cyberwar. His stance is cyberwar is &#8220;a terrible metaphor&#8221; where there are no winners. While I can certainly respect that, there are also a number of opposing views and supporting statistics that say otherwise.</p>
<p>One comes from the former director of national intelligence, Michael McConnell, who recently testified in Congress by saying the country is already in the midst of a cyberwar &#8212; and losing it at that. This comes on the heels of growing speculation from experts that say the Chinese government was behind the recent cyberattacks targeting U.S. government Web sites, Google, and dozens of other U.S. companies. This, of course, raises the question: &#8220;If we aren’t already in a cyberwar, are we headed toward one?&#8221;</p>
<p>Larry Wortzel, a member of the U.S.-China Economic and Security Review Commission, said in the article, <a href="http://www.infoworld.com/d/security-central/expert-says-chinese-government-likely-behind-massive-cyberattacks-258?source=rss_infoworld_news">&#8220;Expert says Chinese government likely behind massive cyberattacks,&#8221;</a> that whether the Chinese government or independent hackers in China were responsible for the recent attacks, we are seeing &#8220;persistent, systematic and sophisticated attacks&#8221; that are clearly targeting U.S. military, technical and scientific information. Similar trends released at RSA Conference and reported in the story, <a href="http://www.pcworld.com/article/190963/chinese_hack_attacks_said_likely_to_recur.html">&#8220;Chinese hacks attacks said likely to recur,&#8221;</a> said an increase in Internet attacks from China could double if the pace during the first two months of 2010 continues.</p>
<p>People often ask me, given my military background and experience fighting cyber crime, are we in a cyberwar or not? To me, whether or not we are is irrelevant. What defines cyber warfare? What&#8217;s important is that we are aware of what is going on and our government and the private sector are doing everything they can to ensure our cyber security. I commended President Obama last October when he said that cyber threats were one of the most serious economic and national security challenges we face as a nation. The fact is, cyber crime has already cost U.S. companies billions of dollars. If these trends aren&#8217;t stopped, cyber crime will continue to have a growing impact on both our economy and global competitiveness.</p>
</p>
<p>Ensuring our cyber security comes down to one thing &#8212; preparedness. The more we understand, and the more proactive steps the government and private sector take independently and collectively, are vital to defending our networks, national assets and critical infrastructures from any type of attack, whether we are in a cyberwar or not.</p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-03/are-we-in-a-cyberwar-or-not/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New exploit technique could mean more Microsoft headaches</title>
		<link>http://www.coretraceblogs.com/2010-03/new-exploit-technique-could-mean-more-microsoft-headaches/</link>
		<comments>http://www.coretraceblogs.com/2010-03/new-exploit-technique-could-mean-more-microsoft-headaches/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 18:42:02 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[whitelisting]]></category>
		<category><![CDATA[application whitelisting]]></category>
		<category><![CDATA[data compromise]]></category>
		<category><![CDATA[exploit technique]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[security enhancement]]></category>
		<category><![CDATA[security software]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1337</guid>
		<description><![CDATA[Last week, a new exploit technique was disclosed that bypasses a critical Windows security feature, DEP (data execution prevention), as well as an ASLR security enhancement for address space layout randomization.
In the article, &#8220;New exploit technique nullifies major Windows defense,&#8221; some researchers worry that a proof-of-concept code published by Google security software engineer, Berend-Jan Wever, [...]]]></description>
			<content:encoded><![CDATA[<p>Last week, a new exploit technique was disclosed that bypasses a critical Windows security feature, <a href="http://en.wikipedia.org/wiki/Data_Execution_Prevention" target="_blank">DEP</a> (data execution prevention), as well as an ASLR security enhancement for address space layout randomization.</p>
<p>In the article, <a href="http://www.computerworld.com/s/article/9165378/New_exploit_technique_nullifies_major_Windows_defense?taxonomyId=17&#038;pageNumber=2" target="_blank">&#8220;New exploit technique nullifies major Windows defense,&#8221;</a> some researchers worry that a proof-of-concept code published by Google security software engineer, Berend-Jan Wever, could actually lead to more successful attacks against Microsoft&#8217;s newer operating systems.</p>
<p>While Wever claims the proof-of-concept doesn&#8217;t do any harm because it&#8217;s wrapped around an exploit of a bug in Internet Explorer 6 (IE6) that was patched years ago, MicroTrend&#8217;s Ria Rivera wrote in the company&#8217;s malware blog that the exposure could be used to further enhance exploits, and expects to see it used within exploits soon.</p>
<blockquote>
<p>&#8220;After Wever released his <a href="http://en.wikipedia.org/wiki/Heap_spraying" target="_blank">heap-spraying</a> exploit codes in 2005, a lot of new exploits started using that technique. It would thus be not far-fetched that the release of this new proof-of-concept could lead to the same scenario &#8212; new exploits could start using &#8216;return-to-libc&#8217; to achieve DEP bypass.&#8221;</p>
</blockquote>
<p>With so many data compromises arising from the latest disclosed vulnerability it seems so clear that now is the time to completely re-evaluate the way we approach desktop security. Vulnerabilities lose their power when you address the core issue of controlling what applications are allowed to run on your system in the first place whether these applications were added by a user or by malicious code exploiting a security hole.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-03/new-exploit-technique-could-mean-more-microsoft-headaches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Observations from RSA &#8211; 100% compliant does not mean 100% secure</title>
		<link>http://www.coretraceblogs.com/2010-03/observations-from-rsa-100-compliant-does-not-mean-100-secure/</link>
		<comments>http://www.coretraceblogs.com/2010-03/observations-from-rsa-100-compliant-does-not-mean-100-secure/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 21:08:58 +0000</pubDate>
		<dc:creator>Dan Teal</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[application whitelisting]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[security compliance]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1334</guid>
		<description><![CDATA[Yesterday, I sat in the RSA panel titled, &#8220;Cyber Security: An Arms Race.&#8221; It was an interesting panel because, of course, cyber security is an arms race. One of the recurring comments from the audience was centered around, &#8220;Who should be responsible for defending our networks?&#8221; This is a question that has been debated for [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday, I sat in the RSA panel titled, &#8220;Cyber Security: An Arms Race.&#8221; It was an interesting panel because, of course, cyber security is an arms race. One of the recurring comments from the audience was centered around, &#8220;Who should be responsible for defending our networks?&#8221; This is a question that has been debated for some time now. The answer kept leading back to government and compliance. However, members of the audience did not realize that one of the fundamental axioms of computer security is: Compliance does not mean secure.</p>
<p>We are familiar with the above statement. We all know that security compliance may increase security, but not completely provide it. A great example of this occurred in the fall of 2008 within the DOD. Systems running in the DOD networks were compliant with FIPS 140-2, common criteria, and other standards. The systems and networks were operated by a staff of trained professionals. But even with all of the compliant security measures in place, Conficker still propagated throughout the DOD networks causing over $100 million in cleanup costs.</p>
<p>A similar problem occurred at Heartland Payment Systems. Even though Heartland was fully PCI compliant, hackers still stole information on the 100 million credit card transactions that are processed each month.</p>
<p>Compliance is important, but we must remember that compliance standards may take years to create and are never updated fast enough to stay current with today&#8217;s threats. Organizations must protect against the threats of the past by being compliant. They must also defend against the threats of today by being proactive.  Application whitelisting is the proactive solution against today&#8217;s threats and must become the cornerstone of any security strategy.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-03/observations-from-rsa-100-compliant-does-not-mean-100-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top endpoint security stories for February 2010 &#8211; Security professionals don’t feel the love</title>
		<link>http://www.coretraceblogs.com/2010-02/top-endpoint-security-stories-for-february-2010-security-professionals-don%e2%80%99t-feel-the-love/</link>
		<comments>http://www.coretraceblogs.com/2010-02/top-endpoint-security-stories-for-february-2010-security-professionals-don%e2%80%99t-feel-the-love/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 17:43:27 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[endpoint protection]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1323</guid>
		<description><![CDATA[In a month known for love, February was filled with more heartbreaking stories of security problems and problematic fire drill patching. Is it me, or does it seem like everybody&#8217;s experiencing security compromises stemming from patching flaws and vulnerabilities within their system? Instead of resulting in more secure networks, what these and other recent stories [...]]]></description>
			<content:encoded><![CDATA[<p class="margin_bottom_2em">In a month known for love, February was filled with more heartbreaking stories of security problems and problematic fire drill patching. Is it me, or does it seem like everybody&#8217;s experiencing security compromises stemming from patching flaws and vulnerabilities within their system? Instead of resulting in more secure networks, what these and other recent stories point out is that malware only highlights the fact that existing desktop security isn’t working properly. Check out some of the top stories from February 2010.</p>
<h3>Security patches cripple Windows XP computers</h3>
<p>Windows customers were up in arms over a <a href="http://www.computerworld.com/s/article/9155419/Windows_patch_cripples_XP_with_blue_screen_users_claim" target="_blank">Microsoft security patch that left their PCs locked down</a> with the notorious Blue Screen of Death.  This was yet another glaring example of the problems organizations experience when rolling out patches quickly.<span id="more-1323"></span></p>
<p>In a follow-up article to Microsoft&#8217;s patching problems, <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1381423,00.html?track=sy160&#038;utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+techtarget%2FSearchsecurity%2FSecurityWire+%28SearchSecurity+%3A+Security+Wire+Daily+News%29" target="_blank">evidence suggested that a rootkit infection was behind problems</a> Windows users experienced after installing several security updates. According to the computer expert who discovered the infection:</p>
<blockquote class="margin_bottom_2em">
<p>&#8220;This particular rootkit can be very difficult to detect. Atapi.sys is an important driver for all Windows systems and it loads very early during the boot process, so infecting this file can make it very hard to detect or remove the rootkit before it loads.&#8221;</p>
</blockquote>
<h3>Zeus Trojan found on 74,000 PCs in global botnet</h3>
<p>It was reported that over <a href="http://news.cnet.com/8301-27080_3-10455525-245.html" target="_blank">74,000 computers at nearly 2,500 organizations around the world were compromised over the past year and a half</a> in a botnet infestation designed to steal login credentials to bank sites, social networks and email systems. While Operation Aurora had its own success with popular networks internationally, the number of corporate and government systems infected paled in comparison to the Zeus Trojan.</p>
<p>The Wall Street Journal reported that Merck, Cardinal Health, Paramount Pictures and Juniper Networks were among the targets in the attack.</p>
<p class="margin_bottom_2em">To make matters worse, a <a href="http://www.theregister.co.uk/2010/02/09/spyeye_bots_vs_zeus/" target="_blank">competing crimeware toolkit called SpyEye is waging a turf war against the mighty Zeus bot</a>. For $500, aspiring rival cybercriminals can use the tool to uninstall Zeus from an infected system and keep SpyEye running on the system to steal credit cards and email accounts. Talk about cyber gang warfare.</p>
<h3>Malicious PDF files comprised 80% of all exploits in 2009</h3>
<p class="margin_bottom_2em">In the often-seen case where hackers gravitate to the most popular Internet applications, it was reported that <a href="http://blogs.zdnet.com/security/?p=5473&#038;tag=col1;post-5473" target="_blank">rogue PDFs accounted for 80% of all exploits by the end of 2009</a>.  And much like other leading technology companies, Adobe continues to patch several critical vulnerabilities in Adobe Reader and Adobe Acrobat for Windows, Mac and Linux.</p>
<h3>Google teams up with NSA to fight cybercrime</h3>
<p>As a result of Operation Aurora, The Washington Post reported that <a href="http://www.washingtonpost.com/wp-dyn/content/article/2010/02/03/AR2010020304057.html" target="_blank">Google has teamed up with the National Security Agency</a> (NSA) to help the Internet research firm defend itself and its users from future attacks. The Director of National Intelligence call the Google attacks a &#8220;wake-up call,&#8221; and that cyberspace cannot be protected without a &#8220;collaborative effort that incorporates both the U.S. private sector and our international partners.&#8221;</p>
<p>Unfortunately, what we are continuing to see in early 2010 is that patching and other traditional antivirus software are failing to adequately defend our systems. In fact, if anything they appear to be causing more problems. Organizations are better off focusing on ways to effectively stop Web-malware and malicious code from executing in the first place.  This is where a solution such as application whitelisting can defend even flawed networks from running malware within their operation systems. If it’s not an authorized application, it does not run in the system. It&#8217;s that simple.</p>
<p>As always, I thank you for stopping by to read this blog. I hope it continues to bring to light some of the important issues we all face as security professionals. Come back soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-02/top-endpoint-security-stories-for-february-2010-security-professionals-don%e2%80%99t-feel-the-love/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Guest Blog By GlobalSCAPE&#8217;s COO: Defending Cyberspace&#8230;</title>
		<link>http://www.coretraceblogs.com/2010-02/guest-blog-by-globalscapes-coo-defending-cyberspace/</link>
		<comments>http://www.coretraceblogs.com/2010-02/guest-blog-by-globalscapes-coo-defending-cyberspace/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 19:05:30 +0000</pubDate>
		<dc:creator>Craig Robinson</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[application whitelisting]]></category>
		<category><![CDATA[CoreTrace]]></category>
		<category><![CDATA[endpoint protection]]></category>
		<category><![CDATA[GlobalSCAPE]]></category>
		<category><![CDATA[proactive]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1307</guid>
		<description><![CDATA[There is no question that cyberspace is a new frontline in traditional and untraditional conflict. Many nations and organizations have the ability, directly and by proxy, to target and attack critical infrastructure within the US and worldwide. The recent cyber attacks launched within China against Google and several other companies raised questions about the state [...]]]></description>
			<content:encoded><![CDATA[<p>There is no question that cyberspace is a new frontline in traditional and untraditional conflict. Many nations and organizations have the ability, directly and by proxy, to target and attack critical infrastructure within the US and worldwide. The recent <a href="http://blog.globalscape.com/2010/01/china-vs-google-the-policy-strategy-and-technology-perspective" target="_blank">cyber attacks launched within China against Google</a> and several other companies raised questions about the state of industry preparedness to help defend cyberspace.</p>
<p>The US government relies on commercial industry to safeguard the Internet, telecommunications, power, water, and other critical infrastructure that underpin our national economy. Elements of this infrastructure also directly support our ability to project military power worldwide.<span id="more-1307"></span></p>
<p>Industry works closely with the government to advance the ‘state of the possible’ in cyber defense. As a former CIO and military systems analyst, I have witnessed several generational cycles of defensive technology developments in the cyber arena. In the mid-90s, for example, system administrators configured firewalls (from standard computer systems) by hand, and reviewed log files (either manually or through then-clever application of scripts) to detect, characterize, assess, and potentially contain cyber intrusions. Today, automated intrusion prevention systems are available as commercial-off-the-shelf (COTS) products, integrated with firewalls and incident management solutions to allow very rapid detection and blocking of cyber attacks. This is just one example of how industry has worked closely with the government to deliver significant advances in cyber defense technologies.</p>
<p>Unfortunately, our cyber adversaries today have proven relentless and highly flexible in their endless pursuit of effective attacks (for an entertaining perspective on the topic, please read Toney Jenning&#8217;s <a href="http://blog.globalscape.com/2010/02/caddyshack-the-defense-of-cyberspace-no-more-%e2%80%9cwack-a-mole%e2%80%9d/" target="_blank">&#8220;Caddyshack &#038; The Defense of Cyberspace: No More “Wack-a-Mole”&#8221;</a> post on GlobalSCAPE&#8217;s blog site). Those of us in the information security industry understand that the next major terrorist strike very well may come from the cyber domain or, at a minimum, include cyber attacks as part of a broader operation. From a traditional national security perspective, it is a near certainty that future adversaries will continue to develop their cyber attack capabilities. Such asymmetric warfare capabilities are increasingly attractive, given the overwhelming superiority of US forces in conventional, force-on-force combat.</p>
<p>As a result, GlobalSCAPE, our partners and many others in the industry are working tirelessly to deliver next-generation cyber defense capabilities and stay one step ahead of our adversaries. Our continued development in this area is a national imperative. We are excited by the prospects for transformational solutions like application whitelisting to allow more assured defense of the cyber frontier. We’ll be addressing a variety of cyber defense topics in future posts. Stay tuned!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-02/guest-blog-by-globalscapes-coo-defending-cyberspace/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
