Freitag, 24. April 2009

www.security-press.com for SALE



After 3 years of publishing security-related news we are sorry to tell you that we`ve decided to sell Security Press. Due other projects within the security industry we are not able anymore to keep the content up to date.

We did not fix the price for our website, so we'll wait until we will receive an acceptable offer.

In case of any questions or offers please get in contact with us via email.
Email contact

Security Press (www.security-press.com & www.securitypress.blogspot.com)

Dienstag, 27. Januar 2009

Pentura launches new Firewall Risk Assessment

Pentura, a leading IT security consultancy and the UK’s first Risk Management Service Provider, has today launched a new firewall security risk assessment. Pentura’s Firewall Risk Assessment will audit and analyse router and firewall configuration to ensure the highest level of protection is achieved and to identify any system vulnerabilities.

The Firewall Risk Assessment provides corporate security managers with a detailed report of the threats to corporate security, ranking and prioritising the dangers to business critical assets based on system vulnerabilities. The risk assessment also exposes complex firewall configurations that lead to security risks being hidden within firewall rules and highlights duplicated, disabled, unused or expired rules in order to increase the performance and speed of firewall security.

Steve Smith, managing director of Pentura comments, “Monitoring and updating firewall security is crucial in helping organisations remain well protected from IT threats. The Firewall Risk Assessment offers a powerful auditing and analysis tool to identify the risks facing any organisation and the steps that need to be taken to eliminate each risk. By offering a granular level of visibility into firewall and router configurations, enterprise customers can enhance their level of security, increase operational efficiency, and maintain compliance with corporate policies and regulatory requirements.”

Mittwoch, 12. November 2008

GROTECK: Exclusive Survey of Russian Security Market was presented at Security Essen



According to Russian Prime Minister - Vladimir Putin, Russia will take the 7th place in the rating of the biggest economics of the world in 2008.

Russian Economics is characterized by a big degree of concentration and decisive role of the Government. In 2007 a new tendency appeared. Government corporations started creating.

Owing to this fact, a role of Government in politics continues to grow. Russian Security market is one the most dynamic growing markets in the world. The total values of Purchases of the equipment and services in the area of security in 2008 will exceed $17 mlrd.

In 2006-2008 The Russian market for electronic physical security equipment (EPS) shows a 20% rate of annual grows rate. Over 80% of technical security equipment sales take place in 4 out of 85 of the Russian Federation areas: Moscow and Moscow region, Saint Petersburg and Leningrad region.

The number of solid customers of the EPS market in Russia is relatively small. Approximately 500 state and corporate customers comprise 80% of EPS purchases in Russia.

Of that, the share of the three largest Russian monopolies-CJSC “Gasprom”, RAO Unified Energy Systems of Russia and CJSC “RZHD”- constitute about 18% of the total supply share. The total number of prominent players in the market (producers, resellers and fitters) dealing with technical security systems does not exceed 1,000.

A maximum of 20 companies control at least 50%, and in some cases, up to 90% of the total volume in each segment of the Russian EPS market. Demand for technical security equipment in the private sector falls below 5%. In the course of update researching the security market experts has formulated three scenarios of security market growth in 2009 - 2011.

All the three scenarios rely on the expert’s forecasts in the area of two fundamental causes, having an influence on the Russian market growth and it’s additional segments: Oil price, Economic politics of Russian Government. Majority of experts has inclined towards the optimistic scenario with 20% growth of Russian security market per year.


Source: Russian Security Market Survey 2008
GROTECK Business Media
www.groteck.com

All rights reserved.

Full version of the survey you can see here

To order any special surveys from Groteck Research Dept contact us at int@groteck.ru

Mittwoch, 15. Oktober 2008

Survey reveals dangerous lack of knowledge about virtualization

More than forty per cent of IT directors and managers that have implemented server virtualization may have left their IT networks open to attack because they wrongly believe that security was built in.

These shock findings were revealed today when network security vendor Clavister published a survey it commissioned from international research and consulting organisation, YouGov*.

With virtualization now one of the boom technologies of the IT world, the extent of the problem was emphasized when 38 per cent of survey participants admitted that they had already implemented the technology. Virtualisation brings environmental benefits, cost savings and management efficiencies.

“When companies implement virtualization, it is very dangerous for them to believe that everything is automatically secure because they can actually face new security threats,” explains Andreas Asander, VP product management at Clavister.

“Virtualization offers new points of attack and gives access to a far wider number of applications than a traditional physical server. It is vital that IT staff take steps to achieve the same level of security in their virtualized environment that they had in their traditional environment.”

Clavister has developed a five-point check-list for IT managers and directors who are considering the adoption of virtualization. They should:

Re-define the security policy to include the virtualization aspect
Use virtual security gateways which run inside the virtual infrastructure
Protect the virtual administration center and only allow access to this from a separate network
Limit the number of administrators who have access to the virtualization administration tools to a minimum
Evaluate and test the security level on a regular basis. Replicating the production environment to a test environment is easy with virtualization and this should be utilized.

To find out more about security virtualization, please visit www.clavister.com

CRYPTOCard Launches Password Amnesty

CRYPTOCard, a leading developer of two-factor authentication (2FA) technology for multi-vendor environments, today announces a ‘Password Amnesty’, calling on UK businesses to hand-in their obsolete single passwords and replace them with a free two-factor managed authentication service for up to 200 users, per business. The initiative, launched in support of National Identity Fraud Prevention Week, aims to highlight the dangers of ‘single password’ strategies that leave organisations wide open to hackers, and urges business leaders to rise to the challenge of protecting their information assets.

Neil Hollister, CEO of CRYPTOCard, explains; “The government estimates that costs of over £1bn per year can be attributed to identity fraud, but this is just the tip of the iceberg. For example, nearly every week we hear of laptops being lost or stolen, but it is not just the data stored on these devices that we should be concerned about.

“Most laptops provide remote access to a company’s corporate network, with username and password stored for ease of connection, and thereby allowing hackers easy access to a company’s entire internal network. Many businesses have yet to implement some form of password validation strategy and many hold back because of cost and complexity. But what cost the price of stolen identities and the brand damage that ensues?”

Hollister concludes; “Today, we’re offering all UK businesses an amnesty on their password, and will replace their insecure existing password system with our proven managed 2FA service, CRYPTO-MAS, free of charge, for up to 200 users.”

Jason Hart, former ethical hacker and now VP Europe for CRYPTOCard, adds; “Most businesses already recognise the need to implement a firewall or anti-virus solution, but few do anything to verify the identity of users accessing the network. I’ve seen hackers crack passwords in a matter of minutes, using a variety of methods, most of which are available free on the internet. Unless you lock the door, then anyone can walk into your company and literally destroy your reputation or the integrity of your data.”

CRYPTO-MAS is a unique managed service which provides a flexible, affordable solution using 2FA technology, and positively identifies individuals before giving them access to applications, data and networks. The service requires users to input something they know, such as a password, and something they don’t, such as a one-time generated PIN, delivered via hardware or software token, SMS, or smartcard.

CRYPTO-MAS simply sits in front of a company’s remote access or VPN network – no hardware or software installation is required. High levels of security can be provided in a matter of minutes.

To hand-in your password and register for a free managed two-factor authentication service, please visit: www.cryptocard.com/howtobuy/passwordamnesty.

Terms & Conditions:
The Password Amnesty applies only to UK businesses (referred to from this point forward as the ‘Business’). The service, CRYPTO-MAS, is available for this promotion from 08.10.08, and will expire on 31.12.08. On registration, the Business must provide the name and contact details of a nominated project leader. CRYPTOCard will supply the service and up to 200 software tokens (PC or BlackBerry), with the option to take an additional SMS token, free of charge, per registered Business. The Business will be contacted within 24 hours of registration to confirm and coordinate CRYPTO-MAS set-up.

To ensure eligibility of the promotion, upon registration, the Business commits to the following: the Business agrees that its contact details can be forwarded to a selected agent or partner of CRYPTOCard for the fulfilment of the service; the Business commits to trialling the service; the Business will provide feedback to CRYPTOCard following the expiry date of the service; the Business acknowledges that the service will expire on 31.12.08.

Freitag, 29. August 2008

Aboundi Inc. debuts the first of its VersatileWire™ series of Ethernet over long distance Coaxial Cable Solution

Innovative solution enabling high speed Ethernet packets to traverse over 2.5 Km on existing Coaxial Cable infrastructure



Nashua, NH – August 28, 2008 – Aboundi Inc. today announced the release of its APL2400 series of VersatileWire™ Quad Ethernet CoaxBridge™ products which enables commercial and business users the confidence and reliability of extending the new IP based devices and application to run over their existing long distance coaxial cable infrastructure.



Aboundi has introduced its innovative “VersatileWire™” technology to enable the extension of the ubiquitous Ethernet applications through coaxial cable deployment already in existence. It is specifically designed to minimize the obsolescence of the pre-existing coaxial cabling where upgrading from the older analog based devices such as analog CCTV cameras to the newer IP based cameras for the ease of remote video surveillance monitoring and smart management applications. Hence, allowing both maximum capital investment preservation and minimum Total Cost of Deployment (TCD) associating with the migration to the new IP technology oriented applications. The

‘VersatileWire™’ family of products allows a very simple plug and play installation with any new high speed Ethernet based devices to the existing cabling infrastructure. The customary requirement for the need to rewire “home run” Ethernet CAT5 cables in order to replace these older analog devices is no longer necessary.



The APL2400-200 UltraSpeed ™ Quad Ethernet CoaxBridge™ provides four (4) shielded MDI/MDIX RJ45 auto-detect full/half duplex Ethernet ports that can be connected to any 10/100 Mbps Ethernet ports on PCs and other peripheral devices such as Point of Service (POS), IP cameras, monitors, serial servers and etc.



“The APL2400-200 CoaxBridge™ has proven its immediate value with great savings in deployment cost for Bolton, Massachusetts.” said Bob Johnson, President of Bolton Access Television. “The distance from Town Hall to Emerson High School is over 1000 meters and we needed a cost effective Ethernet connection between these facilities over lines already in use for video connections” said Johnson. “Aboundi’s APL2400-200 took no time to install and it provided us with instant high speed Ethernet connectivity.”



“We are most delighted our VersatileWire™ solution has expanded our Electric

Connect® capability to reach beyond just the AC electric wiring networking infrastructure for commercial business applications”, stated Hong Yu, President and CEO of Aboundi

Inc. “It is surprisingly easy to bring the new Ethernet applications to an existing coaxial cable plant that is already in place and ‘synergistically’ co-exist with active video applications.”



The APL2400-200 series product is available now from Aboundi’s authorized Distribution

Partners and the listed MSRP is $330.

Sonntag, 6. April 2008

Application Security Testing Should Be Mandatory For Outsourced Development

Response to Quocirca report "Why application Security is crucial"

A new report published today by European technology analysis group, Quocirca, based on a survey of 250 C Level executives in UK, Germany and the UK suggests that 90% of organisations are outsourcing more than 40% of their code. Other findings in the survey are:

* 78% of organisations state that software development is business critical for them yet
* at the same time 60% of companies that outsource the coding of their critical applications do not demand that security is built into their applications.

Matt Moynahan, CEO of Veracode, responds to this survey by highlighting the need for application security testing of code to become mandatory:

"With almost £100 billion in custom code being developed in locations such as India, China, Eastern Europe and South America, many businesses have rushed to take advantage of cost savings and flexibility in their striving for competitive advantage....At the same time attacks on applications - the weakest links in the corporate security chain - have grown exponentially. Organisations relying on outsourcing application development need to demand independent verification of applications as part of their formal software acceptance criteria. Users are in a position to call the shots. As application security becomes the most pressing issue on the security agenda, users should veto service providers who cannot demonstrate that a full independent security audit has been conducted on their final deliverable to ensure proper security quality has been achieved, " said Matt Moynahan, CEO at Veracode.

According to Gartner, 75% of new attacks target the application layer directly while software vulnerabilities have reached an all time high with over 7,000 new software vulnerabilities disclosed over the last year according to the National Vulnerability Database.

The conventional approach at attempting to solve this issue has been to either conduct costly and time-consuming manual penetration testing or to use source code testing tools. Testing at the source code level not only is unpractical as offshore code often is unavailable to the enterprise but also insufficient. Offshore development is a multi-tier process with many parties involved where growing types of threats - such as those coming from backdoors - are impossible to spot with traditional tools. Additionally tools are typically run by the very same developers who are building the code, potentially implementing backdoors. Research from the US Department of Homeland Security points to a significant risk from backdoors and 23% of software packages used by US government employees have backdoors built into them.

Technology now exists - from organisations such as Veracode - that allows enterprises to conduct proper security audits by a trusted entity on the final application code as part of an organisation's formal software acceptance, without the need for source or costly on-site consultants. Veracode inspects application code at the same level at which it is attacked - the binaries. By assessing the final application code, Veracode ensures that all threats, including vulnerabilities and malicious code are detected, thereby providing the most complete security audit across internally developed applications, third-party commercial off-the-shelf software and offshore code. Additionally Veracode delivers its offerings on a software-as-a-service basis, ensuring that application code can be independently verified and validated, irrespective of their source.