05/14/2012 | Network Security
As difficult as it has been for many to accept, the computer security industry has finally conceded that focusing all efforts in securing endpoints is now futile. There has therefore been a recent emergence of network forensics tools and techniques to help with monitoring and analysis of network activity for gathering information, determining intrusions, and collecting data as
04/18/2012 | Network Security
The issues highlighting the need for network security analysis are clear. We cannot stop the attackers, so we have to plan for compromise. The difference between success and failure breaks down to how quickly you can isolate the attack, contain the damage, and then remediate the issue. Yet many organizations think aggregating some logs will provide the basis to really understand
04/18/2012 | Network Security
The issues highlighting the need for network security analysis are clear. We cannot stop the attackers, so we have to plan for compromise. The difference between success and failure breaks down to how quickly you can isolate the attack, contain the damage, and then remediate the issue. Yet many organizations think aggregating some logs will provide the basis to really understand
04/09/2012 | Network Security
Faculty member Kevin Johnson answers the question, "With all the press around hacktivism and Anonymous, what do we need to know, and what do we need to do differently?"
03/26/2012 | Network Security
The majority of today’s organizations detect and internally report on threats by relying on the static based signature protections provided by their security vendors. With the volume of high profile data breach headlines over the past couple of years and the detailed sophistication of many of these attacks, it is obvious that signature based protections are no longer adequate for
03/07/2012 | Network Security
Encryption of stored data was always a complicated and challenging problem, even before everything started moving to the cloud. Add cloud to the mix and the waters are further muddied because the type of cloud deployment model and the details of who maintains that deployment (and where) also change how encryption can be effectively applied. In this document, Ed Moyle introduces
11/29/2011 | Network Security
DLP continues to top the list of topics in which IANS client are interested and with which they are constantly struggling. Earlier this year at our New York Metro Information Security Forum, several senior security executives asked IANS to bring together a peer group to discuss the non-technical aspects of DLP. This document provides an overview of the day along with key findings
11/10/2011 | Network Security
While denial-of-service attacks are not necessarily new, the scale at which they can now be performed has increased and the barrier to entry for those coordinating these attacks has fallen. Since the first large-scale attacks were witnessed in the late 1990’s, enterprises have had to move from point solution-based approaches at the edge of their networks to holistic multi-
10/31/2011 | Network Security
This checklist details key features and functionalities of the offerings of some of the top Infrastructure as a Service (IaaS) Cloud Providers.
10/26/2011 | Network Security
A recent IANS end user Symposium on SIEM brought together attendees from a range of industries. Lead by IANS Faculty Dave Shackleford and Mike Rothman, the day-long roundtable involved lively discussions on SIEM use, challenges, vendors, managed service providers, metrics, audits, and much more. Here, find some of the day's discussions, conclusions, and tips.